← All writingHome
Regional cybersecurity2 July 2026 · 9 min read

Nineteen startups in eleven countries

The mapping of early-stage cybersecurity startups across Southeast Europe, and why only two confirmed active product startups sit in Serbia.

I went looking for the early-stage cybersecurity startup scene in Southeast Europe and the Balkans, expecting to find something thin. What I found was thinner than that: across eleven countries, roughly nineteen early-stage companies that are genuinely building a cybersecurity product. In Serbia, two confirmed active product startups.

The number needs a definition, because the definition is where most regional counts go wrong. I was not counting integrators, resellers, managed service providers, consultancies, or outsourcing shops with a security practice. Those exist in real numbers and they employ a lot of very good people. I was counting companies whose own product is the thing they sell.

That distinction matters because the two paths need completely different support. A services company needs clients and a pipeline. A product company needs design partners, patient capital, and a first reference customer willing to be named. Programs in the region are mostly built for the first and then surprised when the second does not appear.

Why so few? Three reasons keep showing up in conversations. The first is that security expertise here sits inside banks, telcos, and large integrators, where compensation is good and the risk of leaving is high, so the people most capable of founding a product company are the least likely to. The second is that the local market is too small to validate against and the enterprise buyers who could validate you demand references you cannot have yet. The third is that almost nobody has seen a regional peer do it, which loops back to the first two.

The uncomfortable implication for anyone designing programs: an accelerator cohort call aimed at cybersecurity startups in this region will not fill from the existing pool, because the pool is nineteen companies wide and most are not at your stage. You either widen the definition, which quietly turns your security program into a general tech program, or you go upstream and create founders instead of recruiting them.

Upstream is slower and it is the only honest option. It looks like student camps that put real offensive and defensive work in front of people early, meetups where practitioners show what they actually shipped, sector-specific rooms where CISOs say out loud what they would buy, and alliances that let a two-person company stand next to a bank without being dismissed.

Upstream work has a measurement problem, which is why so few organizations choose it. You cannot report founders created this quarter. What you can report is how many people did serious hands-on security work for the first time, how many practitioners presented real production experience to a room instead of a vendor deck, and how many enterprise buyers said out loud what they would actually purchase. Those are leading indicators of a pipeline, and they are the only ones available at this stage.

The other thing worth saying plainly: the region's strongest security people are not missing, they are employed. Any serious attempt at building a product pipeline here has to make it thinkable for a senior person inside a bank or a telco to spend two evenings a week on something of their own, without it looking like disloyalty. That is a cultural problem more than a financial one, and it is solved by visible examples rather than by grants.

What would change my number? A first regional product company with a named enterprise reference outside its home market. That single event does more for the count than any cohort, because it converts an abstract possibility into a thing a colleague did.

I keep publishing the number because it reframes the conversation. The regional problem is not that our startups cannot compete. It is that there are almost no startups to compete, and that is a pipeline problem with a decade-long horizon. Better to name it than to keep announcing programs for companies that do not exist yet.

If you are building a security product anywhere in the region, or you know someone who is, tell me. I would genuinely like the number to be wrong.

Reply

If any of this is wrong, or right in a way you can add to, I would rather hear it. Write to antanaskoviczarko@gmail.com or find me on LinkedIn.

Newsletter

Get new pieces by email

Occasional essays on AI adoption, regional cybersecurity, and building small products. No schedule, no marketing, unsubscribe whenever.

More writing

AI adoption

The gap is not the technology, it is the readiness

What I keep seeing between what frontier tools can already do and what organizations here are set up to absorb, and what actually closes that gap.

Building without code

Non-technical, on purpose

Notes from shipping small products with AI tooling: what these tools genuinely do, where they stop, and why I would rather find out from the inside.

AI adoption

The 95 percent number, and what it actually says

MIT's NANDA researchers found that 95 percent of enterprise generative AI pilots produce no measurable return. Read closely, that is not a verdict on the technology.

Regional ecosystem

398 million euro, 109 deals, and what that means from Belgrade

Southeast Europe attracted 398.3 million euro of venture capital across 109 transactions in 2025, up nearly 40 percent. Here is what that scale actually implies for founders here.

Founders

How to build a startup from scratch

The honest sequence, written from the side of the table where I sit: what to do in the first ninety days, what to ignore, and where most people here actually lose the year.

Serbian ecosystem

One in three Serbian startups made no revenue at all

The 2026 Startup Scanner numbers are blunt: a third of startups here earned nothing last year, another third earned up to 50,000 euro, and a quarter are planning to raise over a million.

Serbian ecosystem

43 million dollars, and who actually got it

Serbian startups raised around 43 million dollars in 2025. Fewer deals, bigger cheques, and a selection filter worth understanding before you plan your own round.