The Cybersecurity Act, which implements the European NIS2 Directive, came into force a year ago. Now, however, we are entering the period in which compliance will begin to be scrutinised, with substantial fines awaiting those who fail to meet the requirements. Are Czech companies and institutions ready? Tomáš Kubát, the head of HPE in the Czech Republic, dismissed the question at the very outset: “The law is one thing, but all of us are responsible for the stability and security of our companies. If we are sensible, we take care of that regardless of whether the law requires us to. Its requirements should not come as a surprise to anyone,” he stressed, as most of the nearly seven hundred people in the audience nodded in agreement.

The law is in force, but for some it is a step too far
Research conducted by ESET, however, presents a rather different picture. “Every two years, we carry out a survey asking companies how they are doing. The last time we asked about their preparedness for the Cybersecurity Act, 33 per cent of respondents said they were not ready and did not have the necessary resources, whether financial or human,” said Jan Urbík, the company’s Country Manager. This is one of the reasons why ESET plans to launch a “cybersecurity calculator” on its website in October. The questionnaire will allow organisations to assess their situation and identify the areas in which they are most exposed.
Given the rapid development of artificial intelligence, it is clear that the number of risks will only continue to grow. When the speakers were asked where AI might be in two or three years’ time, nobody was prepared to offer a precise prediction. There was, however, no shortage of individual insights or major challenges.

“When we talk about what matters most to users deploying AI, the discussion is about what it can do, how much it costs and how many tokens it requires. Security, however, is simply ignored. Nobody is paying attention to it,” said Martin Ignjatović of Fortinet boldly. The TechForum programme appeared to support his view. Across the conference, discussions focused on the tools organisations can use to monitor the activities and decisions of AI systems, as well as to understand how employees are working with AI, so that corporate and institutional data remains secure
New tools, familiar problems
Several real-life examples showed that data is not always secure today. “At one of our public-sector customers, an employee using an AI tool decided to see whether it would send them the salaries of every employee. And the Excel spreadsheet arrived,” said Zuzana Švecová, Managing Director of Cisco Czech Republic. Her example highlighted a problem raised by several speakers: the large-scale deployment of AI agents and enterprise AI systems often exposes a lack of control over access permissions, with data available to people who should never have been able to access it.
The rapid evolution of how people work with AI was another major topic. We have moved almost overnight from simple prompting into the age of agentic AI. This prompted a question from the audience: is artificial intelligence already beginning to slip beyond our control? “We can see agents communicating with one another, creating their own rules, and the situation is becoming increasingly complex. That is why comprehensive security management must also become a priority for all of us. We need to address it now rather than wait,” said Fridrich Matejík of IBM. Jaroslav Dvořák of Aricoma immediately picked up the thread: “Socrates once criticised the invention of writing, arguing that if we began writing things down, we would stop using our brains. Today, we are having a similar debate. There is no point in rejecting AI, but we should use it in a controlled way,” Dvořák observed. Governance was therefore discussed at every level, from Europe and the Czech Republic to individual companies, institutions and users.
Those at the forefront are not waiting
Society must now strike a balance between defending itself against an ever-growing number of cyberattacks, protecting data and ensuring it is handled properly, and making the most of the opportunities offered by artificial intelligence.

“First, we were trying to understand what artificial intelligence actually was. Then we experimented with it. Now the question is how to derive real value from it,” said Martin Maštalír of Dell. Michal Stachník, the head of Microsoft in the Czech Republic, followed by comparing AI adoption rates in different countries. “At Microsoft, we conduct international comparisons, and we are not doing badly at all. The Czech Republic ranks 26th, alongside countries such as Germany and the United States. But the breakneck pace of development leads some organisations to think they should wait, for fear of backing the wrong horse. And that is precisely what sets them apart from those at the forefront. The leaders are not waiting.”
TechForum therefore demonstrated that, in the age of AI, the question is no longer simply what the technology is capable of. Above all, it is about how quickly we can put it to work without losing control of our data, security and accountability.
