Qubit Conference®

QUBIT CISO CLUB

Security is solved at the round table.

An exclusive club for information and cyber security managers - intimate meetings and open round-table discussion.

Attendance is subject to approval. Your first approved attendance makes you a CISO Club member.

30

expert meetings
since 2019

Next meeting 8 December 2026 · Kafé Lampy, Bratislava View meeting

About CISO Club

An independent community of security leaders

CISO Club is an independent Slovak-Czech community of people in the Chief Information Security Officer role or a similar position that fulfils CISO duties.

Its mission is to create an exclusive space for intimate meetings and open round-table discussion about the most important information and cyber security topics of organisations and to find shared, effective solutions.

01

Independent Slovak-Czech CISO community

02

Intimate round-table discussions

03

Solving real problems from practice

04

Guests from Slovakia and abroad

CISO Club is a platform for exchanging information on topics every CISO has to deal with in their organisation. Sharing information within the CISO community in Slovakia is an important step in raising both awareness and the level of measures against cyber threats.

It was my first attendance, not counting Qubit in Prague. I welcome an informal forum and the chance to exchange views and real-life experience with experts in this field.

As my first meeting it was a new experience. Usually you attend marketing conferences where everything is offered as the best. At this meeting I noticed that problems, observations and ideas are discussed instead. A big plus for me.

The club is a valuable space for exchanging practical experience. The discussion at the meeting is open, expert and to the point.

Marián Klačo

František Boda

Boris Schneider

R. Varga

CISO Club membership

How membership works

Registration is not yet membership. You become a member only after your approved attendance at the first meeting.

Who the club is for

  • CISO / CSO
  • Global Head of Cyber Security
  • Head of Business Continuity Risk
  • Global Privacy Officer
  • Director of Security & Enterprise Risk
  • Security and Compliance Manager
  • VP Security and Operational Risk
01

Choose a meeting

Submit a separate registration for a specific date.

02

We review it

Attendance is approved by professional relevance after consulting the chairman.

03

Attend for the first time

Membership begins with your first approved attendance at a meeting.

04

Stay in the community

As a member you receive further invitations and access to CISO Club Teams / WhatsApp.

Transparent terms. The attendance fee covers the venue, refreshments, organisation and technical facilities.

Active membership. Membership and Teams / WhatsApp access depend on regular attendance; not attending in-person meetings for a year leads to a review of membership.

Martin Kupči, CISO Club chairman

Martin Kupči

CISO

Tatra banka

Expert leadership

Experience from practice, not from slides.

Martin Kupči leads the team responsible for information security management at Tatra banka and has worked in practically every area of cyber security.

CISO

leads the information security team at Tatra banka

Cloud Security

architect for public cloud platforms

IAM / PAM

identity management and application security

The chairman prepares and presents the most important topics of the current CISO role, moderates the debate and invites inspiring guests from Slovakia and abroad. The role is voluntary and unpaid.

Marek Zeman, founding chairman of CISO Club

Founding chairman

Marek Zeman

Researcher · FIIT STU Bratislava · KCCKB

Information and cyber security expert, Director General of the Competence and Certification Centre for Cyber Security and lecturer at FIIT STU. He managed information security at a large financial institution as CISO for more than 20 years. He founded CISO Club and led it as its first chairman.

Next meeting

Next CISO Club meeting

The date and topics of the next CISO Club meeting are being prepared. Register and we will get in touch as soon as the date is confirmed.

Meetings are held in Slovak.

Meeting 31

8 December 2026 · 14:00 – 18:00

Venue

Kafé Lampy · Bratislava

Chairman

Martin Kupči · Tatra banka

Standard attendance

144 € excl. VAT

With subscription

126 € excl. VAT

Register

Meeting topics

Topics are being prepared

We will publish the meeting topics together with the invitation.

Registration

Request to attend a meeting

We review each registration by professional relevance. Once approved, we will send you a confirmation and payment details by e-mail.

Date
8 December 2026
Capacity
Confirmation
After expert review

Registration received for review

Thank you. Attendance is subject to approval - we will get back to you by e-mail with a confirmation and next steps.

Would you like to join the CISO Club WhatsApp group?

* Required fields

CISO Club history

Discussions that shaped CISO Club

Topics and experience that have been building the community of security leaders in Slovakia and the Czech Republic since 2019.

2026

4 meetings

10 September 2026 · Bratislava

CRA, communication during an incident, supplier responsibilities and AI tools

The thirtieth CISO Club meeting opens with the Cyber Resilience Act, communication during an incident, passing responsibilities to suppliers, the practical use of AI tools and asset management. The date and venue may still change.

  • CRA - opening the topic and walking through the basic requirements for organisations
  • How to make communication transparent during an incident?
  • Which responsibilities should be passed on to suppliers?
  • Using AI tools - use cases and the new threats they bring
  • Asset management (choosing a CMDB, populating it, asset ownership)
Meeting 30

16 June 2026 · Bratislava

Post-quantum encryption, AI agents and how security is perceived in the organisation

  • The current state of post-quantum encryption and quantum computers
  • AI agentic vs. AI automation vs. cyber security
  • What to do so that cyber security is perceived positively in the organisation?
  • Where do risks in the organisation come from? How to set a baseline?
Meeting 29 23 participants

21 April 2026 · Bratislava

Ransomware, the supply chain, insider and hybrid threats

  • What to do and how to defend against ransomware?
  • Attacking the supply chain is often easier than attacking the original target
  • The human factor and insider threats, a major source of attacks
  • Are you dealing with geopolitics and hybrid threats? You will be.
Meeting 28 20 participants

10 February 2026 · Bratislava

Exit procedures, DR tests, role-based training and monitoring AI

  • News from public administration
  • Exit procedure - and what about plan B (BCM)? Case: our key provider is leaving
  • Disaster recovery tests
  • Role-based training for non-security teams (HR, legal...) - how to do it?
  • LLM and open AI - how are we going to monitor AI?
Meeting 27 24 participants

2025

5 meetings

2 December 2025 · Bratislava

macOS in the enterprise, BCM and incident response, generative AI and network segmentation

  • Deploying macOS into enterprise architecture
  • Connecting BCM and incident response
  • Generative artificial intelligence - how to get a grip on it in the organisation?
  • How to run a good table top exercise - advice, recommendations, experience
  • Network segmentation and protection (from the outside world, under the Cyber Security Act, separating employees) - how to do it well and efficiently?
Meeting 26 19 participants

10 September 2025 · Bratislava

Secure development: SCA, SAST, DAST, IAST and vetting vendors

  • How to approach secure development?
  • External development must be a natural part of the central code repository and of secure development verification
  • What the acronyms SCA, SAST, DAST and IAST mean and how to work with them
  • Are there penetration testing applications that actually work?
  • How to verify a product delivered by a specific vendor?
Meeting 25 25 participants

17 June 2025 · Bratislava

Brownfield infrastructure, shadow IT, security of AI applications and ransomware

  • First steps to securing brownfield IT infrastructure
  • Shadow IT
  • Is AI in security already business as usual?
  • How to handle the security of AI applications, what to focus on?
  • How to deal with ransomware incidents?
Meeting 24 25 participants

29 April 2025 · Bratislava

ICT risk management, new decrees, IDM and asset ownership

  • ICT risk management - how to do it, which system to use, ideas and simplifications
  • New decrees of the national security authority to the Cyber Security Act
  • IDM - how to start rolling it out in the organisation
  • Business owner and IT owner - convincing the business owner, the never-ending job of pointing out the benefits
  • DAST
  • Artificial intelligence - simple steps; a human can be wrong, can a computer?
Meeting 23 24 participants

4 February 2025 · Bratislava

DAST, DORA and NIS2 in practice, NDR and motivating the security team

  • Experience with implementing DAST
  • Implementing DORA and NIS2 in practice
  • Network detection and response (cloud and on-prem)
  • How to motivate and retain members of the security team?
Meeting 22 20 participants

2024

4 meetings

3 December 2024 · Bratislava

LLM firewall, TLPT, choosing a cloud provider and break glass in PAM

  • AI - to protect or not to protect, and how? (LLM firewall)
  • TLPT - how to implement it?
  • How to choose between a local and a global cloud provider?
  • Hints and tips for raising productivity at the same cost
  • Ways to deploy break glass procedures alongside PAM
Meeting 21 23 participants

11 September 2024 · Bratislava

Cloud security, deploying PAM, digital supply chain risk and phishing

  • Cloud security
  • How to deploy PAM?
  • Digital supply chain risk
  • Phishing, our daily bread
Meeting 20 25 participants

29 May 2024 · Bratislava

NIS2 according to the national authority, the ISO update, thin clients and current threats

  • How the national security authority will approach NIS2
  • The new ISO update and its impact on companies
  • Experience with thin clients
  • Current cyber threats and protection
  • Which communities we use to share information
  • GRC, cloud, EA and more
Meeting 19 24 participants

24 January 2024 · Bratislava

AI security, long-term education, hybrid attacks and accepted risks

  • How to approach the security of artificial intelligence?
  • Training is no longer enough, we need long-term education
  • How to improve the company's readiness for hybrid attacks and how to spot an industrial spy?
  • What do you expect from this year? Where is information security heading - new types of attacks, new security toys
  • Risk management - what to do with accepted risks?
Meeting 18 19 participants

2023

3 meetings

13 September 2023 · Bratislava

Security budget, compliance, awareness, PAM and Zero Trust

  • How is a security budget created and worked with afterwards?
  • Compliance - what it covers in the company and how it connects to information security
  • Awareness (new trends, virtual learning, artificial intelligence)
  • PAM - how it is used
  • Open source risk assessment
  • Source code risk assessment
  • Zero Trust (VPN-less access)
Meeting 17 17 participants

30 May 2023 · Bratislava

Security KPIs, vulnerability and patch management, application control and SIEM

  • Security KPIs - the work of information security can be reported
  • Experience with vulnerability and patch management
  • How to set up application control?
  • Who owns the use case in SIEM?
Meeting 16 19 participants

2 February 2023 · Bratislava

Three lines of defence in the cloud, shadow IT, IoT and Active Directory in OT

  • How to manage cloud security through the three lines of defence
  • Which applications and tools should IT Ops manage and what should IT security do so that the three lines of defence are not broken?
  • Shadow IT in the organisation - can it be detected and sized, and how to work with it?
  • IoT in organisational security - a proven approach to managing and removing IoT
  • How to meet the Cyber Security Act requirements when third parties are not obliged to sign a contract
  • Security awareness - the recommended routes
  • Active Directory in OT
Meeting 15 20 participants

2022

4 meetings

10 November 2022 · High Tatras

Growing the security team, startups, application control and threat modelling

  • Developing the people who report to you in security
  • Leading people - the security team as a team of shared values, tied directly to the company's values
  • What is companies' attitude to startups?
  • Application control review
  • Threat model - how to build it and who is responsible for what?
Meeting 14 30 participants

7 September 2022 · Bratislava

Clean desk policy, zones for sensitive data, working from abroad and segregation of duties

  • How does a clean desk policy work in practice?
  • How to create and protect work zones for sharing sensitive data?
  • Working outside Slovakia (health and safety, taxes...)
  • Background checks for employees working abroad
  • Segregation of duties within the security team
Meeting 13 18 participants

26 May 2022 · Prague

Comparing clouds, SOC and threat intelligence, Pentera and changes in standards

  • Comparing AWS / Azure / Google cloud services from a security perspective
  • The process for using cloud compliance security
  • SOC and using threat intelligence in practice, incident management software - hands-on experience with deployment and operation
  • Experience with running Pentera and similar tools in companies
  • Changes in standards: NIS2, the new ISO 27002
  • A new view of ICT security in the light of events around us
Meeting 12 25 participants

9 March 2022 · Bratislava

IDM, DLP rules, macOS and cloud security

  • Setting up and using IDM
  • DLP - how to set the rules
  • macOS - minimum requirements
  • Security in the cloud
Meeting 11 15 participants

2021

4 meetings

1 December 2021 · Online

macOS in the company, incident management, DLP and password management

  • Bringing macOS into the company - how to meet security requirements built around a different system
  • Detecting, categorising and escalating incidents
  • Security incident handling and incident management in the cloud
  • How to free your colleagues' hands, or setting DLP right - what can actually be configured?
  • Password management in the company - password access manager versus a password wallet
Meeting 10 15 participants

9 September 2021 · Prague

Education and talent, cloud security, hybrid environments and DLP in a bank

  • Education in information security, how to develop it, KPIs and growing talent
  • Cloud security (initial review, contracts, logging, protection)
  • Security and connecting hybrid environments
  • DLP in a bank - how to set it up, manage controls and connect local DLP with the cloud
  • Disruptive development versus security (supporting the business, controlling fast changes and development in agile teams)
  • Dealing with legacy infrastructure in production
Meeting 9 18 participants

17 June 2021 · High Tatras

Zero Trust, backup strategy, supply chain attacks and the dark web

  • The Zero Trust concept and brand protection
  • How to approach a backup strategy?
  • Encrypting data in development environments
  • Current attacks in Slovakia and the region
  • Supply chain attacks
  • Dark web markets and what attackers are interested in today
Meeting 8 35 participants

17 February 2021 · Online

Bad habits of users and admins, combined attacks and a red team test

  • Users' bad habits and what to do about them - can a bad habit be stopped quickly?
  • Administrators' bad habits
  • Combined attacks - the nightmare: the cases we know and how to defend against them
  • Will a red team test help us? Experience from a real test
  • Backup strategy
  • Encrypting data in development environments
Meeting 7 6 participants

2020

4 meetings

10 December 2020 · Online

Security strategy, BCM during COVID-19, NBA, antivirus and malware analysis

  • Setting a security strategy in the company, BCM and COVID-19 - sharing experience for non-IT areas, DNS security
  • Future cybercrime - what to prepare for in the coming years?
  • Network behavioral analyzer - sharing deployment experience and capabilities
  • Antivirus is not obsolete - how to deploy it correctly and what it should do (antivirus, DLP, ATP, central information exchange and management)
  • Analysing malware from a sandbox, EDR metadata and hands-on experience with honeypots
Meeting 6 5 participants

15 October 2020 · Online

Comments on the Cyber Security Act, audits under it, home office and training during the pandemic

  • Commenting on the Cyber Security Act - going through the most serious comments
  • An audit under the Cyber Security Act - a nightmare, or a good thing?
  • Security when people work from home - how much can be outsourced?
  • Experience with risk management
  • Macs as a work tool
  • How to train people you cannot even see - rethinking training during the pandemic
Meeting 5 9 participants

13 May 2020 · Online

The situation during COVID-19 and what comes after it

The club's first online meeting. The main topic was how people in the CISO role responded to changes in company processes, purchases of new hardware and the move of employees to home office. The second part outlined what will matter once the COVID-19 measures end.

  • How CISOs responded to changes in company processes and to buying new hardware from a security perspective
  • The pros and cons of moving employees to home office
  • How to re-verify processes that are new and yet already running?
  • How to prepare for the future and what awaits us once the measures end?
Meeting 4 17 participants

11 February 2020 · Bratislava

Information security in industry

The third CISO Club meeting was devoted to information security in industry. Members and the chairman discussed how essential information security is and how far it is deployed in industry, how to handle incidents and how to protect the cloud.

  • Why information security is essential and how far it is deployed in industry
  • Incident handling for security incidents - remediation, reporting, internal and external collection of forensic evidence
  • The cloud and how to protect it
  • Security in the agile world and how it connects to the security world
Meeting 3 14 participants

2019

3 meetings

19 November 2019 · Bratislava

Fraud and SIEM technology

The autumn meeting was split into two blocks: fraud (online fraud detection, employee fraud) and SIEM - how to deploy the technology, which data to collect and how to report so that both business and IT accept it.

  • Online fraud detection system - implementation experience, where and why to deploy it
  • Fraud management and employee fraud - protection and employee background investigations
  • SIEM - how to deploy the technology, which data to collect, monitor and evaluate
  • Types of reporting and the importance of monitoring
  • The security dilemma - what to deploy first so that SIEM is accepted by both business and IT
Meeting 2 9 participants

18 June 2019 · Bratislava

A new information security architecture

The meeting looked at the new architecture of information systems security and its impact on how companies operate, including the newly adopted Cyber Security Act and its alignment with the ISO 27000 standard.

  • The Cyber Security Act and its decrees, and aligning them with ISO 27000
  • Moving security services to microservices and the emphasis on protecting them
  • Cloud and risk management - handling risks including BCM, physical security, IT, outsourcing and the GDPR
  • Raising security awareness - simple, catchy solutions and the bigger picture
Meeting 1 9 participants

10 April 2019 · Prague

The CISO role today, cloud and data, AI and ePrivacy

The club's inaugural meeting, held at the Qubit conference in Prague, looked at how the CISO role is perceived, cooperation with DPOs, cloud and data, artificial intelligence and ePrivacy.

  • CISO - how the role is perceived and cooperation with DPO colleagues, splitting responsibilities across the business
  • Cloud and data - how cloud is perceived, the dangers of using it, how to secure it
  • Sharing and storing data across several companies
  • Artificial intelligence and how to secure it, ePrivacy
Meeting 0 11 participants

Practical information

Frequently asked questions

If you cannot find the answer, write to us at [email protected]. We are happy to explain the conditions of attendance before you register.

For people in the CISO / CSO role or a similar position that fulfils CISO duties - for example Head of Cyber Security, Director of Security & Enterprise Risk or Security and Compliance Manager.

Choose a specific meeting and submit a registration. After approval and attending your first meeting you become a CISO Club member and are automatically invited to further meetings by e-mail.

No. There is an attendance fee that covers the venue, refreshments, organisation and facilities.

No. Attendance is subject to approval by Qubit Security after consulting the chairman, with regard to professional relevance.

Meetings follow the Chatham House Rule - you may use the information, but not attribute it to anyone. That keeps the discussion open and confidential.

Active membership depends on regular attendance. Not attending in-person meetings for a year leads to a review of membership and access to the club platform.

Qubit Conference®

Next expert event

Qubit Conference® Slovakia 2026

Six themes, one shared focus: how security leaders rebuild trust in an AI-driven world.

11. - 12. November 2026

Demänovská Dolina 226, 031 01 Liptovský Mikuláš

View conference