Ukraine’s State Service of Special Communications and Information Protection (SSSCIP) and the e-Governance Academy (eGA) held the country’s first Chief Information Security Officer (CISO) Forum in Kyiv on 2 October, bringing together cybersecurity leaders from the public and private sectors.
The event was supported by the EU-funded Continued EU Support to Cybersecurity project, known as EU4CyberUA, the European External Action Service (EEAS) announced on Tuesday.
The CISO role — a senior official responsible for managing an organisation’s cyber risks — was introduced into Ukrainian legislation in 2025.
Participants included representatives of central government institutions, regional military administrations, the private sector, international partners and experts.
“CISOs and their teams must adopt a systematic approach to cybersecurity: assessing risks, setting priorities, and ensuring organisational readiness for cyber incidents,” Volodymyr Trofymenko, Deputy Chairman of SSSCIP, told the forum.
He said the forum should bring participants together annually for exchanges between those who set rules and those who implement them.
Training and regional cooperation
The European Union is supporting Ukraine in developing professional expertise and cybersecurity governance alongside technical capabilities, Asier Santillán of the EU Delegation to Ukraine said.
The statement also highlighted CISO Campus, a training initiative designed to build management and professional skills for the role using training and practical cases.
Demand for CISO training is high and expanding it to more specialists would require additional expertise, people and resources, Ieva Ilves, CEO of CISO Campus, the EEAS stated, adding that support from international partners was particularly important while Ukraine is at war.
Sessions at the forum covered incident response, the work of CERT-UA — Ukraine’s national computer emergency response team — regional cyber resilience and protecting state information resources.
A second day, held as “CSIRT Day”, focused on regional cybersecurity, including the development of regional centres and their co-operation with CERT-UA.
EU4CyberUA is set to run from 2026 to 2029 with a budget of €10 million and is implemented by FIAP and eGA in co-operation with SSSCIP.

