Decoding the world of cybersecurity

·

Ukraine develops CISO role through first national forum

Ukraine has held its first national CISO Forum as authorities develop the cybersecurity leadership role introduced into legislation in 2025.

Ukraine develops CISO role through first national forum
Summary
  • Ukraine’s State Service of Special Communications and the e-Governance Academy held the first CISO Forum in Kyiv.
  • The CISO role entered Ukrainian legislation in 2025 as part of a wider move towards organisational cyber risk management.
  • Government, regional, private sector and international representatives discussed responsibilities, skills and implementation.

Ukraine has held its first national forum for chief information security officers as the country works to turn a cybersecurity leadership role introduced into legislation in 2025 into a functioning part of organisational governance.

The State Service of Special Communications and Information Protection of Ukraine and the e-Governance Academy convened CISO Forum 2026 in Kyiv, bringing together representatives from government, regional administrations, the private sector, international partners and the cybersecurity community.

The government said discussions focused on the role of the CISO and the practical work needed to develop it. Ukrainian legislation formally introduced the position of head of cyber protection in 2025.

Putting the role into law established responsibility at an organisational level, but effective implementation also depends on authority, professional skills and the relationship between security leadership and wider management.

Volodymyr Trofymenko, deputy head of the State Service, said CISOs and their teams are expected to assess risk, set priorities and prepare organisations for cyber incidents. He also emphasised the need for the role to carry sufficient competence and authority.

Governance is moving alongside technical defence

Ukraine’s approach places cybersecurity responsibility inside management structures rather than treating protection solely as a technical function. The government describes the CISO model as part of a broader move towards systematic cyber risk management and clearer accountability.

The organisational role is separate from Ukraine’s national cyber coordination structures. A CISO is responsible for cybersecurity within an organisation, while national bodies coordinate policy and response across government and the wider state.

Professional development is also part of the programme. Ukraine has established CISO Campus to develop management and cybersecurity competencies using practical cases and the experience of practitioners.

The forum adds a national professional network around that training and legal framework. Officials said continued exchange between practitioners, regulators and organisations implementing the requirements will help develop the role in practice.

No new certification scheme, statutory deadline or separate competency regime was announced through the forum. The development is instead part of the implementation of an existing legal change.

Ukraine now has a recognised CISO role in legislation, a training initiative intended to develop the people filling it and a national forum bringing together organisations responsible for putting that structure into practice.

×