ESET – The Critical Infrastructure Protection & Resilience Europe (CIPRE) interview

We met David Brezna Vice President of Operations and Scale-Up at ESET Corporate Solutions.

We are delighted to welcome ESET to CIPRE 2025 as Platinum Sponsor and as speakers on two sessions: https://www.cipre-expo.com/session/emerging-threats-against-ci/ and https://www.cipre-expo.com/session/cybersecurity-and-cyber-resilience-in-ci/

Ben Lane:

Thank you for joining us today David. Briefly describe your role at ESET.

David Brezna:

Thank you. So briefly, my position is VP of Operations and Scale-Up within the corporate solution division. This is a new division that focuses on serving and developing solutions beyond standard product for large organizations or government institutions. And specifically, from a territory perspective, I am responsible for Europe. So, I have lots of interactions with customers or organizations in European countries.

Ben Lane:

Thank you. The first topic we would like to explore is around the Joint Cyber Defense Collaborative (JCDC). ESET has joined this collaborative to share threat intelligence with public sector partners. What are the key benefits and the challenges of these collaborations, and how would you ensure that threat intelligence is actionable and timely?

David Brezna:

Public-private partnerships when it comes to threat intelligence are now vital; we hear and see that from customers and public organizations. One of the reasons is that companies such as ESET have gained certain intelligence, which is difficult for a single state or single organization to gain. There is more cooperation between governments or law enforcement bodies, and now critical infrastructure companies are becoming involved when it comes to threat intelligence or interpreting and understanding certain situations or types of attack. There is a need for consultative discussion on specific areas.

In many cases there is an exchange of information between different parties because we need to connect the dots. Sometimes we only see part of the chain, and other organizations see the rest, so without connecting the dots and correlating them we are much less efficient and much less successful in preventing attacks.

Ben Lane:

We are going to look at digital sovereignty and regulation and compliance. Given the increasing importance of digital sovereignty in Europe such as GDPR and NIS2, how would you ensure that a critical infrastructure operator remains resilient and complying with the regulations?

David Brezna:

From our perspective, what we see for critical infrastructure operators is a twofold problem. There’s infrastructure already in place and that could be composed of multiple technologies or vendors and suppliers. This cannot be changed easily because of the constant changes in geopolitical situations. So, there is a need to look back and make sure we protect, maintain, and secure the existing relationships or technologies.

And looking forward, we believe infrastructure providers should start thinking about not expanding or extending risk but being careful how they choose and pick the technologies and services moving forward. We view that as a critical path. Many critical infrastructure tenders are still evaluated based on price, and I think we should start thinking beyond price and cost. We need to start thinking strategically about protecting our ecosystems and letting European players grow and compete in terms of not only cost, but also the features and efficiency of large non-European players.

Ben Lane:

ESET emphasizes the idea of prevention-first security. What would a prevention-first strategy look like for critical infrastructure sector? And what are the metrics you would use to measure any success of that?

David Brezna:

I think one of the starting points we would look at is threat intelligence: we hear this sentence often, “tell me something I don’t know and tell me ahead of the time when it happens.” So, this is about changing the view from reactive to predictive insights and threat intelligence.

The first part is to understand if what we are seeing is happening somewhere else in the world that could potentially relate to us. In this way we can take measures or take precautions to prevent the problem. The second part is once we have this type of information, how quickly can we put that into operation. There is not one source of truth, and the problem is the time it takes to produce a response. Sometimes the response can be in weeks and that is too long. I always compare it to Bloomberg-like data when it comes to trading. When you have a week old data in your SOC systems, it does not help to protect you, as we need to work in minutes. And the third step is incident readiness. Not necessarily response, but incident response readiness.

Ben Lane:

Can you tell us a bit more about your involvement in the healthcare sector, and what areas are you concerned about in that sector and how are you prioritizing resources to mitigate those concerns?

David Brezna:

ESET has been quite active historically in the healthcare sector and we have quite a few installations at health service providers to secure and manage their operations. The interesting part about health is there is quite a bit happening on specific threat intelligence, but it is now moving down to the operational level. Hospitals are advanced or getting more advanced in terms of protecting IT. What we see is a problem with Operational Technology (OT) security; everything in a hospital’s corridors. That is a difficult part, and this area is not as protected as it should be. And as there is danger to life if you interfere incorrectly with hospital OT security. You need to take extra care. So just putting sensors into an OT environment in health care is not as easy as it would be for other industries. So that is one area where we must balance potential risk and the closeness of the environment with the need to sense deviations in the network.

The second part is issues with the supply chain, for example, air conditioning and ventilation providers. So, there is a second and third level of supply chain that can affect the operation of a health service provider. Many of these providers are often not large companies, so sometimes they cannot equip themselves with the level of cybersecurity skill set or tooling that you would expect at the hospital level.

Ben Lane:

We are going to look at a general case study. So, resilience means not just preventing attacks but also being able to respond and recover quickly. Can you walk us through a typical response plan that you would implement for a CI provider to ensure that the operations continue during a major attack?

David Brezna:

This might be a wider question, so I will try to highlight things that might be of interest here. I think one of the first things is to understand what the bare minimum is to operate or to reestablish continuity. And often this goes down to an exceedingly small set of parts or components of infrastructure, and it is good that an organization understands that not everything has to be up and operational. But there is a minimum standard that composes of process, people, and technologies. So that is one part, and it is often not understood. So, when organizations get under stress and attack, they try to reestablish everything to the normal state of operations, which is unrealistic, and it takes a lot more time.

The second part is the human aspect. This involves awareness, but it is about decision-making factors, such as when and how do we shut down and who needs to be called. It is not different from any other situation in IT industries. So, this is, I would say, closer to a business continuity plan than incident responses. You would find out about the problems when it comes to key decisions that must be taken within minutes, and when people do not know who should decide. They are not brave enough to decide. They do not want to take responsibility. And the third part is even more interesting. When you need to restart operations, who decides and what are the criteria to restart? Let me give you an example:

Recently we had a compromise, let us say it was a water provider. The question was, who turns on the green light and confirms the water is safe to drink? Even if the readiness plan contains the steps and decisions to shut down, there are questions about when we go back up, who can approve that decision and on what criteria can they approve that decision. So that is from a high-level perspective. Of course, when it comes down to technology, there are many other aspects and details that could be interesting.

But from our perspective, what is really an issue is when we enter the “island operation” mode. So, can we operate when we unplug the cables? So, for example, imagine a power utility goes down. They need to disconnect from the network, and they go into “island operation” mode, but they still need to operate and distribute electricity. They still have technicians plugging in with the computers that might be infected or contain malicious files. So how do we protect against that scenario?

Ben Lane:

Thank you, David, for your time today and we look forward to hearing more from your team in Brindisi in October.

David Brezna:
Thank you, Ben. It has been a pleasure to share our perspective. We are proud to support CIPRE 2025 and contribute to strengthening the resilience of critical infrastructure across Europe.