personal<IT>y: "A lot of risks arise on the human side," CIO explains where companies make cybersecurity mistakes, why technology alone is not enough
2026-01-12 | 16 min Anasoft
In the interview, ANASOFT's CIO openly returns to moments when security decisions are not made under ideal conditions, but under time pressure, with a limited budget, and with people who have completely different priorities than IT, and explains why these situations are the most dangerous for companies.
In the series of interviews personaly, we continue with a look into the world of strategic IT management and cybersecurity. This time, we are not looking at technologies through the lens of solution architecture, but through the responsibility of the person who bears the final decisions—for infrastructure, security, and the stability of the company’s entire digital environment. Even at this level, however, the same thing still applies: IT is not made up of systems alone, but of people, their way of thinking, experience, and the ability to remain calm in situations where a lot is at stake.
The CIO of ANASOFT, Peter, operates at the intersection of several roles. In addition to managing the company’s internal security and infrastructure, he is involved in large customer projects, contributes to the design of architectures, and at the same time leads a team that must function in an environment of constantly evolving threats. In the interview, he speaks openly about why panic does not work in security, how responsibility-related pressure can be handled, what still excites him about cybersecurity, and why today the weakest link is often not technology, but people.
The CIO’s approach is close to the thinking of Alan Turing, the mathematician and visionary who laid the foundations of modern computing not primarily as a manager, but as a systematic thinker capable of connecting abstraction with practical impact. Turing understood that what is decisive is not only computing power, but the way we think about a problem. Similarly, Peter approaches security not as a set of tools, but as a process that requires discipline, foresight, and the ability to keep a system functional even at the moment when things start to become complicated.
When the CIO sleeps peacefully
How often do you wake up at night?
Usually not at all. I sleep well and wake up more because of how much beer I had in the evening than because of work. To be serious: I don’t get any dramatic notifications at night. Occasionally something appears, but so far it has never been anything truly serious. Neither from clients nor due to major outages.
For clients, we provide so-called L3 support within security, meaning we are the very last line. Many things they handle themselves, and only incidents that are truly fatal or urgent reach us. That’s why there isn’t as much of it as one might think.
Are there any threats that really keep you from sleeping?
Not anymore. Of course, we deal with important things, but I’ve learned to distance myself from them. It’s not like I wouldn’t sleep because of threats. Theoretically, I should be the first person to know about them, but precisely because of that I try to approach them systematically, not with panic. Panic doesn’t help in security—quite the opposite.
How do you learn about new threats?
It’s a mix of sources. I’m connected to several professional communities, I subscribe to newsletters, follow groups of security professionals, and I also draw a lot from foreign portals. SK-CERT, which deals with cybersecurity at the state level, also sends out quite a high-quality bulletin.
And then we also have internal sources—for example, a colleague who literally reads everything that comes out in the security world. He always comes up with some “tidbit.” But there’s a big difference between what we deal with internally for Anasoft and what we deal with for customers. These are often completely different requirements, different priorities, and also different sources of information.
How predictable is your workday?
It’s hard to say in one sentence. My day depends on which role I’m currently “in.” Basically, I have four. The first is the CIO role itself—security at Anasoft. The second is IT infrastructure management. The third is project management for customers, especially larger projects. And the fourth is managing the department as such.
Under normal circumstances, this wouldn’t be handled by one person, but we are a company of a certain size and we distribute roles in a way that makes sense. Each of them means a completely different approach and a completely different type of day. The least predictable is the customer-facing work—things change quickly there, new priorities arise, and you have to react.
Four roles in one workday
And what about the CIO role itself?
In most cases, it’s more predictable than customer projects. If something unexpected comes up, it’s usually an unpleasant thing that needs to be addressed immediately, but I try to maintain a technical, calm approach. Panic doesn’t help. Years of practice help a lot in being able to keep a cool head. And I’m constantly educating myself, listening to people who have more experience—that gives inner peace. Honestly, though, if a completely catastrophic scenario were to happen, it would probably shake anyone. We’re not machines.
Are we talking about a hacker attack?
Rather not. For customers, we have a person responsible for each service. If they are under attack, we help them resolve our part or provide forensic data for the investigation. But that’s not something that would keep me awake at night in the sense that I’d be sitting by the phone all night.
What would keep me awake is something fatal at Anasoft itself. And that, fortunately, hasn’t happened. Over the years there were maybe two truly major cases, but they were more outages than attacks. When 300 servers suddenly stop working, it’s clear that everyone is calling you at once and you have to deal with it immediately.
A major security incident that would put us on full alert? Thankfully, we haven’t experienced that. Smaller incidents—yes, regularly. Those are situations like: “We have a problem, we stopped it, now let’s remove it completely so it doesn’t spread further.” And those are actually the best outcomes: the company doesn’t even know about them. That’s how it should be. When someone outside the team finds out about an incident, it means it was serious.
And what do people most often ask you about your work? For example, at home—do they know what you actually do all day?
They ask, sometimes. But it’s not entirely easy to explain. My son is 14 and I sometimes talk about it with him too. I try to explain that I have four roles that I have to balance somehow. And that is probably the hardest part: finding time for each of them and not forgetting about the others when one suddenly needs priority.
At home, they basically think I sit at a computer and “type stuff.” They know I deal with security because I sometimes “annoy” them all with it, but I don’t think they have a more detailed idea of what exactly I do and what it all involves.
When you break it down into those three or four areas, is there one you enjoy less?
It’s not that I don’t enjoy it, but some things are already static for me—they don’t move me forward. For example, hardware. I used to enjoy it a lot. I’m originally an electrical engineer. When I was young, I used to build various things at home that I needed: amplifiers, even a radio. I always wanted to study electronics, not computers. Gradually, it all shifted toward IT. But today, I practically don’t deal with hardware in my work anymore, and as a result, that attraction has faded as well.
And do you think that past helps you in some way? That it gives you a predisposition for this job?
I don’t think so. In today’s security, hardware is more of a marginal thing. I basically don’t deal with it.
So what really keeps you going is security itself and the fact that it’s constantly changing?
Yes, exactly that. I like that it’s always new. What applied yesterday may not apply today. It’s hard to say exactly why a person enjoys this in particular, but it simply keeps my attention. It’s alive, it doesn’t stagnate.
What is the biggest challenge for you in everyday work?
Probably realizing that there is no one who can cover security “from A to Z.” It’s an extremely broad field. Even top experts are specialists in only one, two, at most three areas. And very often I encounter an incorrect approach: “If I don’t know it, it probably can’t happen.”
But reality is different. Things happen. Constantly. Attackers are looking for gaps everywhere. Ransomware in the cloud, attacks on technologies that didn’t even exist before—these are all completely normal things today.
And that’s what makes security fascinating and scary at the same time: you have to be constantly prepared. You have to have, as they say, “your eyes open.” And when something bad happens, you have to know how to react immediately.
That’s the everyday challenge—and at the same time the reason why I still enjoy this work.
From hardware to security
So you have to be a bit of a visionary? To anticipate?
The correct answer is yes. But honestly, I don’t consider myself a visionary. I rather try to be. In security, there are two basic approaches. The first is reactive: when something happens, you need to have backup plans, recovery procedures, everything necessary to get the company back on its feet. And the second is proactive: invest so that an incident doesn’t happen at all, so that risk is minimized. And the truth is, both are equally important. Without prevention, we would be constantly putting out fires. Without reaction, we wouldn’t know how to handle situations that will still happen from time to time anyway.
What do you enjoy more—reactive security or preventive security?
Honestly, both. One cannot exist without the other. And on both sides I meet people, even at clients. I’m a bit of a “security evangelist”—I constantly remind people of the basics, but also of new threats. In my opinion, the most important thing is when a person becomes aware of the risks at all. If they at least think about them, that’s half the success.
A lot of risks can be eliminated on the human side, and that is often the cheapest. But people don’t naturally function that way. They are under stress, dealing with other tasks, under pressure. That’s why they need technologies that protect them even when they make a mistake. And at the same time, it is extremely important to invest in awareness. That is essentially a form of education. Without it, it doesn’t work.
Industry is not IT: OT and a world that can’t be “patched“
Let’s move to projects: what are the most common topics you deal with?
A big topic is security in industry. And I have to say that I enjoy it extremely. In my opinion, it is only truly coming to Slovakia and Europe now—I hope not painfully. I don’t mean hacker attacks, but rather that companies will have to go through the implementation of security standards firsthand to understand what it means. Large companies already have some level. But small companies… there, security is often completely zero. And across all sectors: food industry, manufacturing, mechanical engineering, automotive. And that is a problem.
Why is security in industry still perceived so weakly?
Because for them the main thing is that the process works, that the production line doesn’t stop, the transport of oil, gas, whatever. Cybersecurity is not perceived as a critical part.
And the second thing: in industry, the position of a “security manager” often still doesn’t exist—a person who would have a real mandate to change something.
And what do you enjoy most in this area?
It’s a relatively new discipline and not everyone does it. I see a lot of space in it—market-wise and educational. It’s not a topic that companies would normally deal with or understand. Last year we did a project where we focused on it more intensively, and we already have our own know-how.
Lectures and conferences are fine, but you only understand it once you actually “get your hands on it.” Every type of industry is different. In IT, communication is unified—emails, web, common services. In industry, communication is often completely specific to each sector. And that is fascinating.
So protecting OT, meaning industrial control systems like production lines or power plants, is a completely different discipline?
Completely. Firewalls are evergreen, but industry is a more specific world. There are various protocols, often 20–30 years old, tied to specific devices. Every protocol needs its own approach. And one more very important thing: in IT they say “patch, patch, patch,” meaning update. In OT, “patch” is almost a forbidden word. There are technologies that no one has ever patched and no one even knows how they should do it. And those machines have to run nonstop. Stopping them for an update simply isn’t possible.
And now outside of industry—what are the most common threats you deal with?
Ransomware. Definitely. And protection against it is not one thing, but an entire set of layers. The first is phishing—still the most common way attackers get in. That’s why email filters, web gateways, and firewalls must be set up correctly.
Then endpoints come into play—computers, mobile phones. Today we call it EDR, Endpoint Detection & Response. It’s a more advanced type of protection that can monitor a computer’s behavior and recognize ransomware itself.
We are trying to achieve three things:
- for the attack not to get in at all,
- if it does get in, for us to detect it immediately,
- and if it is already in progress, to stop it within seconds, not only after an hour when someone realizes that “something is wrong.”
And then there is another layer: “What if it still gets through?” Because nothing is 100%. If ransomware hits a company and starts encrypting, there must be offline backups and a recovery plan—what gets restored first, what the priorities are. Otherwise complete panic will occur. We implement all of this for clients.
Backups, budget, and management decisions
So backups are the most critical part?
To a large extent, yes. Backups are a very sensitive area, mainly because ordinary employees don’t come into contact with them. They are managed by a narrow group of people, and the result depends on what know-how they have, what budget they have, and what support they have from management. And convincing management that it is necessary to invest in backups is one of the biggest problems—in both small and large companies.
Have you encountered an extreme example?
Yes. In one industrial company that manufactures components for global producers. They have very strict SLAs; downtime is counted in tens of minutes and every minute costs a lot of money.
We proposed a solution for approximately 20 thousand euros that would significantly increase system availability. And they refused it. So I told them: “Every year you lose 20 to 40 thousand euros due to downtime and you don’t want to invest 20 thousand that would eliminate that downtime?” I couldn’t understand it.
And it wasn’t a big company—there was no need to go through five levels of management. But simply… it didn’t pass.
When you act as project manager, do you communicate with the client directly?
Yes, practically from the beginning. I communicate with the client already in the pre-project phase. To a certain extent I also support presales activities, meaning solution presentations, or we do proof-of-concept or pilot deployments. When the customer can’t decide, I suggest: “Alright, we’ll deploy it at your place for a month, test it, evaluate the results, and then you’ll say whether you want it or not.”
And does it always have to be a trial or proof-of-concept?
No. It depends on the type of solution. Sometimes a trial is deployed “for real”—the customer wants to try it directly in a real environment.
It has also happened to us that we deploy a trial, the technology proves itself, and the customer keeps it. Then we put it under contract and add licenses. And if it doesn’t prove itself, we simply remove it.
Honestly, it has not yet happened to me that they didn’t keep it. We have the “proof-of-concept” process very well fine-tuned.
And what about managing the deployment itself?
That is full-scale project management: budget, timelines, people management, documentation, project meetings, handling crisis situations. Everything that comes with it.
That’s also why I enjoy projects—they are dynamic, they move me and the team forward, and every customer is different. We learn something new every time.
Is project management interesting for you?
I enjoy it especially when it’s a good project and a good client. That means a decent, fair person on the other side who also has a real mandate to manage the project. It’s very important that there is a “project owner” who takes it as their own and has the competence to move it forward.
When that happens—which fortunately is not rare at all—I enjoy the project a lot. Work flows, decisions are made quickly, and the whole process makes sense.
How is it different for you from day-to-day operations?
Because it is always something new. Operations are often routine—something fails, something gets fixed, you move on. Projects are dynamic. They are new challenges, new situations, new technologies.
They move me personally, because I constantly have to learn something, and they also move the whole team forward—technically and humanly. Every customer is a bit different; every company enriches you in some way. Sometimes positively, sometimes less so, but it always moves you somewhere.
So there’s also a piece of creativity in it?
Definitely. In solution designs you have to be creative, look for a way to combine technologies and processes so that it makes sense for a specific company.
With smaller customers, we often come up with “everything,” since there are no fixed architectures there. With larger ones, it can’t be done without their participation—they have their infrastructure, their level of security, their limits. There we create it together: the customer says what they want to achieve, what budget they have, what they need to integrate, what their operational requirements are, and we propose how to put it all together.
And you come up with the concept?
Often yes. I am one of the solution architects, always in cooperation with our people and often also with technology suppliers. And that’s what I enjoy: that “assembling.” Looking at how everything can be connected so that it works, makes sense, and is also feasible.
How creative do you and your colleagues have to be?
Quite a lot. But at the same time we know that the possibilities are not infinite—we always have some framework: available technologies, processes, budget. Within that, we have to find the most effective solution for a given project.
And of course, we don’t know everything either. The customer has their idea, we have ours. We correct each other and look for a compromise. Sometimes we say: “We’ve already done it like this elsewhere and it worked—let’s try it here too.” Other times the customer comes with a perspective that moves us forward.
And that’s the best part—that we enrich each other. There’s nothing like experience. Know-how is basically just a set of things you have actually lived through.
Project reality: people, trust, and “assembling” solutions
What is the most bizarre incident you have experienced?
That’s a good question… and at the same time I don’t remember many of them, because with smaller incidents you solve the problem and move on. But I’ll mention one of the more memorable ones.
It was an industrial company—an important and major customer for us. And yet they placed almost no importance on security. Which is common: people focus on their business, they have a lot going on, and what they haven’t experienced, they don’t address. Their logic was: “We have insurance, we have antivirus, so what…”
For a long time we couldn’t convince them that it makes sense to address security preventively. They had holes in their systems and they themselves knew they were working with exposed data where a leak would mean both a reputational and financial problem.
And of course, as it happens, it was on a Friday evening. A former colleague—a friend from that company—called me, and I was just out cycling after two beers somewhere near Horáreň. He told me: “Something is happening. Employees are turning off computers, changing passwords, changing access credentials… something is not right.”
These are the most typical reactions people have when they feel something is happening: they turn off the computer, change the password. Logs are important—if something is red somewhere, that’s the first clue.
We agreed that on Monday we would look at it together. And in the end it was a false alarm. No one attacked them, nothing leaked. But at least it scared them and they finally understood the “what if.” And they started taking security more seriously.
We started doing basic, sensible things for them. In small companies it often isn’t complicated at all—you just need to change the mindset and the way of working. And people naturally don’t want to do that.
What do you mean by a changed mindset?
The absolute basics. For example, not working with local administrator privileges. Having strong passwords, using a password manager, mandatory two-factor. These are cheap things. But they have to be introduced—and above all explained why they are important.
If a company doesn’t have this, I can sell them any “super technology,” but if someone works as a local admin, we’re done. That’s the path to trouble.
So primarily you have to change people’s behavior?
Yes. Awareness is the first step. Only then do processes come into play. And they have to come from the top—from the owner, manager, director. If leadership doesn’t push it through, it won’t work. When people understand why they are doing it and that it makes sense, it’s easier. If not, you can’t enforce it.
Do you still encounter companies that have computers without passwords?
Many small companies have it that way. And they often use local accounts. And whoever clicks on a phishing email—it’s the same everywhere.
Approaches differ. Somewhere we manage to convince them more, somewhere less. It depends on their habits, willingness to change things, and honestly also on what kind of year they had. When business is good and the company has budget, it’s easier to invest. When they are “running on fumes,” security ends up at the bottom of the priority list. And I understand that.
But if the customer perceives you as an expert, as a “security partner,” they listen to you differently. And that is the authority.
So it’s also about authority?
We could call it that. It’s not a word I would use about myself, but yes—some clients perceive it that way. When I talk to someone as a partner, not as a security salesperson, it’s much easier.
That’s why it’s important to find the right person on the client side. And then guide them, keep communication with them, explain the right settings and processes so that the whole thing makes sense and works.
You mentioned awareness in a company. What do you consider the absolute basic in personal cybersecurity?
Password manager. I honestly think that starting to use a password manager is one of the first things every “ordinary mortal” should do. And I’m also speaking from my own experience—it took me years to convince my own wife about it. So I completely understand that it’s a process. Without a password manager, a person simply cannot have strong, unique passwords everywhere. And without that, it can’t be done in today’s world.
And with children? How do you handle that?
With children I handle two things: screen time and awareness. I don’t try to strictly restrict content; rather, I talk with them about what they do there and why. I set boundaries so they don’t sit on the phone or computer all day.
I listen to a lot of psychology podcasts so I know what approach to choose. I don’t want to overly restrict them, but I also don’t want them to have no boundaries at all. So far I feel like it works quite well… although they might tell you something else.
How do you clear your head? Does sport help you?
Sport is very important for me—not only for “clearing my head,” but also for health.
In the past I also used sport as a form of thinking. I went for a run or a bike ride and at the same time I solved work things in my head. Some ideas need to mature. A person needs half an hour or an hour of silence for everything to come together in their head. At work it’s harder—there are priorities, meetings, and you can’t always sit down and just think. With sport, you can.
In recent years, however, I often listen to podcasts while doing sport. Then I don’t really switch my head off from security, but I “fill” it with other content. On the other hand, it’s not nonsense—I listen to things about politics, economics, security, technologies. And also English—more “human,” not technical. There too I feel there’s room for improvement.
Which sport is most important to you?
Rowing. I’ve been doing it for about 30 years and I still enjoy and find it fulfilling. I used to row competitively; now in “senior” categories. It’s a team sport—we have a group of people we meet with regularly.
Rowing also has many accompanying sports—running, cycling, sometimes the gym. And when it’s rowing on an ergometer, I often put on podcasts, because the ergometer itself doesn’t engage me mentally as much.
Besides sport, what clears your head the most?
Conversations with my wife. Often over wine. We have our own category of debates: “discussions about the biggest problems of humanity.”
For example, once we talked for a long time about how sea turtles are endangered—when they hatch, they have to run to the ocean, predators are waiting there, birds… Such “small big” problems. It’s a topic that doesn’t affect us personally, but you can talk about it endlessly without dealing with politics or work. And paradoxically, it also clears your head.
Does professional deformation show up in you in that you are paranoid even in private?
A bit, definitely. I have a colleague who I think is much more paranoid than I am, and maybe he would be offended by that. But I try to keep a reasonable measure. That’s for those around me to judge, not me.
But yes, in this position a certain degree of paranoia is absolutely necessary. “Just because I’m paranoid doesn’t mean they’re not after me” (laugh). But being prepared is never a bad thing.