Trust in the Digital Space Is Not a Given: The Critical Infrastructure Protection & Resilience Europe (CIPRE) interview

With Michal Března of ESET.

Cyber-attacks are increasingly aimed at people rather than machines. Fraudsters use artificial intelligence to create persuasive content, personalise scams and coordinate activity across websites, telephone calls, messaging services and social media. A transaction or command may appear legitimate because the attacker has manipulated an authorised user into carrying it out.

For Michal Března, Market Lead for Central and Eastern Europe at ESET Corporate Solutions, this changes the way organisations must think about cyber resilience. Through ESET PRIVATE, its tailored offering for critical infrastructure and regulated industries, the company starts with the customer’s risk rather than a standard product. Protecting a bank, energy network or other critical service at its perimeter is no longer enough when the same person and device may connect to several essential services, both as a customer and as an employee.

The defensive response, he argues, must be as coordinated as the attack. Banks, telecommunications providers, technology companies, critical infrastructure operators and public authorities need to combine signals, build context and intervene earlier. Protection must also be simple enough to reach millions of users, because even the strongest technology has limited value if adoption remains low.

ESET is a Global Cybersecurity Partner of CIPRE 2026, which takes place in Brussels from 20 to 22 October.

Ben Lane spoke with Michal about the changing threat, the lessons ESET is taking from banking and distributed energy, and why trust should be treated as part of Europe’s critical infrastructure.

Ben Lane: Thank you for joining us. Can you explain your role and responsibilities at ESET?

Michal Března: I am Market Lead for Central and Eastern Europe for ESET Corporate Solutions. ESET is widely known for its consumer and business cybersecurity products, but Corporate Solutions responds to a different requirement, particularly among large organisations and critical infrastructure operators.

In these environments, a product alone will not necessarily solve the problem. Through ESET PRIVATE, we start with the customer’s particular risk, frame it properly and then design a solution around it. That may involve more than one technology and require the operating model to be adjusted as the threat changes. We combine ESET’s cybersecurity foundation with the ability to build a tailored response to a specific operational need.

Ben Lane: What strategies are attackers using today, and how has artificial intelligence changed the picture?

Michal Března: Two shifts stand out. The first is that it is often easier to hack a person than a machine. Organisations have invested heavily in protecting their systems, digital channels and identities. Attackers are therefore moving towards manipulating authorised users, who then enter a legitimate channel and make the payment or take the action themselves.

Artificial intelligence makes that manipulation more persuasive and easier to scale. It can generate convincing content, personalise a scheme for an individual and help coordinate a sequence of contacts over days or weeks. A fraudulent website may be reinforced by a telephone call, a message and social media content. Each element may look harmless in isolation, but together they form a carefully staged attack.

The second shift is the speed and scale of cybercrime. Financial losses in banking give us a measurable indicator, but they are only the visible part of a much wider problem. The same methods can affect small businesses, employees and users of essential digital services, including services where the consequences extend well beyond fraudulent payment.

Ben Lane: How do fraudsters think? Are attacks random, or are particular groups more exposed?

Michal Března: Fraud operates like a business. Attackers look for the best return at the lowest cost and adopt new technology very quickly. As simple phishing becomes less effective in a particular market, they move to more sophisticated and personalised schemes.

Small and medium-sized businesses are an obvious concern. Their security practices may be less mature than those of large enterprises, while their transactions can be much larger than those of individual consumers. That creates an attractive combination for criminals. The attack is rarely random in the true sense. Criminals study where trust can be exploited, where controls are fragmented and where the potential return justifies the effort.

Ben Lane: Is defence by individual companies and institutions sufficient, or do we need a more systemic approach?

Michal Března: Individual defence remains essential, but it is no longer sufficient. On the attacking side, one group can coordinate activity across several channels. On the defensive side, a telecommunications provider may block suspicious calls, an internet provider may filter domains, and a bank may protect its payment channel, but each organisation sees only part of the sequence.

That fragmentation removes the context needed to recognise the full scheme. A call and a web link might each appear acceptable when assessed separately. If the signals are correlated, however, the combined risk score may show that a scam is under way. Effective resilience therefore depends on cooperation between banks, payment processors, telecommunications companies, internet service providers, technology partners and, where appropriate, government bodies.

The aim is not to centralise every piece of data. It is to share the signals and intelligence needed to detect the pattern, while maintaining appropriate security, privacy and governance. The earlier the pattern is recognised, the more opportunities there are to interrupt it.

Ben Lane: What does that layered and cooperative model look like in practice?

Michal Března: We describe it through two connected layers. Layer 0 sits with the user and the device. It focuses on the luring phase, which may last for days, weeks or even months while an attacker uses calls, messages, fraudulent websites, social media and deepfakes to build trust and manipulate the victim.

Layer 1 operates within the service provider’s infrastructure. It addresses the termination phase, when a fraudulent transaction, compromised instruction or manipulated command is about to pass through. Information from each layer improves the other. Device-level evidence gives the operator context, while network-level intelligence strengthens the protection around the user.

The same logic applies beyond banking. In critical infrastructure, the final action may be a command affecting an energy asset rather than a payment. Waiting until that command reaches the operator’s perimeter is too late. Protection needs to move closer to where the attack starts.

Ben Lane: ESET PRIVATE also emphasises its EU ownership and base. Why does that matter to critical infrastructure operators?

Michal Března: For critical infrastructure, sovereignty is an operational question. Operators need to understand who controls a supplier, how customer data is handled, which legal jurisdictions apply and whether the service depends on infrastructure outside Europe. Those considerations become particularly important when the protected systems are connected to national energy, finance or other essential services.

ESET is an EU-owned and EU-based cybersecurity company with more than 35 years of experience and a global presence. That European foundation was central to the creation of ESET PRIVATE. It gives customers a clear basis for discussing integrity, data governance and long-term strategic dependence alongside the technical capability of the solution.

Ben Lane: ESET is preparing a large-scale rollout with a major Czech bank. What can critical infrastructure operators learn from that deployment?

Michal Března: The important lesson is that security at scale depends on adoption as much as technology. A sophisticated defence used by only a small proportion of customers will not create collective resilience. The service therefore has to be simple to activate, easy to understand and relevant to the problem the customer believes they have.

The banking model provides a baseline level of protection across the customer base, with additional tiers for customers who want deeper cover. Onboarding takes place through the bank’s existing digital environment and is designed to require only a few steps. Users can also see what has been blocked, which helps them understand the value of the protection and builds confidence over time.

There is a wider organisational lesson as well. The bank began the discussion by asking how it could protect its customers and whether ESET had the integrity, European base and approach to data required for that responsibility. That values-led starting point matters when a provider is being trusted with systems and information connected to essential services.

Ben Lane: You are also working on the protection of distributed photovoltaic installations. How does that differ from defending a conventional power station?

Michal Března: Distributed energy can resemble retail banking more than the traditional model of protecting one large, heavily defended asset. The exposure is spread across many household installations, inverters and community energy systems, which ultimately connect to the wider network. A large number of smaller endpoints may have uneven levels of security.

The defence must therefore operate across the chain, from the individual installation to the energy community and the grid operator. The device and network layers work together, but the solution also has to be deployable at scale. It cannot assume that every household or small operator has specialist cybersecurity knowledge. The customer needs to understand the outcome: protection against financial loss, disruption or loss of service, rather than a long list of technical features.

Ben Lane: Critical infrastructure sectors are increasingly interdependent. Where is the most underestimated risk between energy, telecommunications, transport and financial services?

Michal Března: The connecting point is the human being. The same person, often using the same device, may be a customer of a bank, an insurer, an energy company and a telecommunications provider. That person is also likely to be an employee with access to an organisation’s systems. Compromising the individual can therefore create exposure across several parts of the ecosystem.

Building protection around the user will not solve every critical infrastructure risk, but it creates a layer that can be deployed quickly and adapted as attackers change their methods. That is why cross-sector threat sharing is so important. Each sector holds a different part of the picture, and forums such as Information Sharing and Analysis Centres can help organisations understand the wider pattern without treating resilience as a collection of isolated sector problems.

Ben Lane: CIPRE 2026 will examine NIS2 and CER implementation, systemic risk and uneven resilience. Where do the most important gaps remain?

Michal Března: NIS2 provides an important structure for improving cybersecurity governance, policies and infrastructure. The gap is that regulation and organisational controls may not keep pace with the speed at which attackers exploit the human factor and newly discovered vulnerabilities.

Companies developing new digital services can receive large numbers of vulnerability findings and must decide what to address first. At the same time, attackers are using automation and artificial intelligence to reduce the period between identifying a weakness and exploiting it. Operators need faster vulnerability triage, protection that adapts continuously and a clearer understanding of how customers and employees connect otherwise well-protected systems to the outside world.

Policymakers should also look beyond direct financial damage. If people no longer trust online channels, they may reduce their use of banking, government, municipal and commercial digital services. That would affect productivity and economic growth. The loss of trust may ultimately be more damaging than the initial fraud.

Ben Lane: If there is one message you want operators and policymakers to take from this discussion, what is it?

Michal Března: Trust in the digital space is not a given. We have to protect it together. Technology is essential, but resilience depends on coordinated signals, rapid deployment and the active participation of users and operators.

We need defence ecosystems that can reach large populations, respond as the threat changes and remain economically sustainable. Banks, energy companies, telecommunications providers, technology businesses and government each have different capabilities and incentives. The task is to bring those together before trust is lost. In that sense, trust itself should be treated as part of our critical infrastructure.

See ESET at CIPRE 2026, Brussels October 20-22.

ESET’s experts will be speaking in two key sessions:

ESET will also be hosting a roundtable discussion:  

Oct 20, 10:30–12:30, lunch included, ahead of the official conference opening keynote at 13:30.

Topic: “From Rooftop to Grid: Securing the New Energy Infrastructure” – securing distributed energy infrastructure, from household PV/community systems to grid-connected assets, including an EVC case study on cybersecurity for large-scale BES