Security Fest 2026

Michal Rampasek

Michal is a PhD candidate and lecturer at the Faculty of Law of Comenius University in Bratislava, the Institute of Information Technology Law and Intellectual Property Law. He is a Slovak attorney and lawyer of Slovak Government CSIRT unit.
His practice and academic research focuses on ICT law, cybersecurity law, and criminal law. His recent research address issues such as legal aspects of OSINT, CTI and information sharing, as well as legal protection of good-faith security researchers and coordinated vulnerability disclosure (CVD),


Session

05-29
11:30
40min
Building Trusted CTI for the Public Sector at CSIRT Slovakia
Adrian Ondov, Michal Rampasek

Operating a Cyber Threat Intelligence (CTI) capability for the public sector means working at the intersection of security, regulation, and trust. This presentation by CSIRT.SK shows how its Afrodita platform, built on MISP and integrated with several internal systems Aura and Atena, delivers actionable CTI while meeting the specific requirements of NIS2 directive and Slovak cybersecurity legislation.

CSIRT.SK runs a centralized architecture of MISP instances connected across GOVNET, the governmental network, and beyond. This design enables secure CTI exchange among public institutions and partners, including selected international instances such as NATO MISP and FIRST MISP. Afrodita acts as the main interface for constituents, while Aura provides internal automation and correlation of incident data, and Atena links threat indicators to the Governmental Security Operation Center (SOC). In return, data collected during SOC operations and incident response, are used for building situational awareness as one of the core services defined by FIRST CSIRT Services.

The presentation explains how this multi-layered architecture ensures data enrichment, contextualization, and traceable sharing of IoCs, enabling faster detection and coordinated response within a controlled trust domain. It also highlights practical challenges unique to the public sector constituency and the benefits for other CSIRT Services.

Attendees will learn how CTI sharing under Afrodita helps public entities demonstrate NIS2 compliance, by integrating intelligence into vulnerability assessment, security monitoring, incident reporting, and evidence of “state of the art” cybersecurity controls.

Main Stage