Become a partner

(Very vivid) experience of incidents

Milan Pikula - Director , SK-CERT National Security Authority ·

Milan Pikula from SKCERT shed light on the behind-the-scenes of handling cyber incidents through concrete examples. From targeted phishing campaigns attributed to the GRU, through the case of border cameras, to the leak of login credentials to a state system. The recurring message was clear: suspicions should be reported, and procedures followed so that incidents can be thoroughly investigated.

From phishing to cameras: how the mosaic comes together

When SKCERT received an extensive report, the first step was to compare it with existing tickets and knowledge. Roughly half of the cases had already been attributed to the same group; others were linked thanks to new connections. A typical vector was targeted phishing emails that appeared trustworthy and sought to gain access to the victim’s infrastructure. Pikula urged people to report even "banal" suspicious messages, because they may be part of a coordinated campaign.

The issue of border cameras drew media attention, and SKCERT issued targeted warnings to organizations at risk. In parallel, it asked partners for non-public information to verify details and the broader context. Contacts of the NBU’s special envoy in Washington also helped, opening doors to the right people. The story shows that an effective response relies on connecting data, collaboration, and rapid information sharing.

Read more

Milan Pikula

SK-CERT
He was fortunate to not only witness the transformation of society from paper-based to information-based, but also to be directly involved in it. He has been active in cyber security, software development, Unix/Linux, and networks for 30 years. He currently leads SK-CERT, the national cyber security incident response unit. His most popular topic…

Recommendation speakers

Páčil sa ti článok? Zdieľaj ho a povedz o ňom aj ostatným