CSO Council is a community of cybersecurity and information security managers, which has been created jointly by the ISSA Polska association and Evention since 2016. Only CSO Council members can become members of people performing CSO or CISO functions in large organizations – both in business and public administration. The community consists of over 300 registered directors and security heads from over 140 companies in Poland, and its activities are based on cyclical, closed industry meetings.
What is CSO Council and what is its mission
CSO Council was created on the initiative of ISSA Polska and Evention as a response to the lack of a platform enabling security directors to regularly, directly exchange experiences outside the conference format. The mission of the community is to integrate the environment and build a platform for knowledge exchange, mentoring and networking among cybersecurity heads operating in large companies and institutions in Poland.
The activities of the CSO Council are carried out primarily through cyclical meetings held in Warsaw or its surroundings – 8 to 10 such events are organized annually. The content of the program is supervised by the CSO Council, composed of security directors from large organizations, and the topic of each meeting is consulted directly with the participants.
In addition to current knowledge exchange, CSO Council also pursues long-term goals:
- raising industry standards by promoting good practices
- developing a common position of the community towards new regulations regarding cybersecurity and information security.
After a decade of operation, the community brings together over 300 registered managers who took part in a total of over 70 meetings, representing over 140 of the largest companies operating in Poland.
Who can become a member of the CSO Council
Membership in the CSO Council is reserved forleaders responsible for cybersecurity in large organizations – both in the enterprise and public administration sectors. A person who meets most of the following criteria may apply for admission:
- holds a managerial position in his organization,
- is responsible for cybersecurity, and this area takes up a significant part of her working time,
- determines and plans the security strategy independently,
- has a budget for cybersecurity solutions and services,
- manages the cybersecurity team,
- there is no higher-authorized person in the organization who is directly responsible for this area,
- represents an entity of significant size or market importance.
Membership and participation in meetings are freeexcept for the annual September away meeting. The status of an active member – which determines access to the full range of benefits – requires attendance at at least two meetings a year.
The admission criteria distinguish the CSO Council from open industry events: it is a closed community of practitioners in decision-making positions, not a public conference for everyone interested in cybersecurity.
CSO Council – who gives direction to the community
The substantive program of the CSO Council is managed by a council composed of security and cybersecurity directors from large organizations operating in Poland. Its members include, among others, representatives of:
- Orange Poland,
- Citi Handlowy,
- BNP Paribas Bank Polska,
- Allegro,
- Polkomtel,
- NASK,
- National Clearing House,
- Danske Bank.
The role of the Council is not limited to an advisory function. Its members select the topics of subsequent meetings, taking into account the current regulatory and technological challenges faced by organizations in Poland. The CSO Council’s annual program – including topics such as risks related to the implementation of AI agents or cybersecurity budgeting in talks with the management board – is created in direct consultation between the Council and meeting participants.
This management model distinguishes the CSO Council from classic program boards of industry conferences, in which participants have only an advisory vote: here it is the practitioners sitting on the Council who decide on the direction of the community, not an external organizer.
What are the benefits of membership in the CSO Council
Active CSO Council members gain access to benefits that go beyond participation in regular meetings. The greatest value is direct access to knowledge and contacts that are difficult to access outside a closed industry environment.
In the area of knowledge and professional development, membership gives access to the Knowledge Zone with unique reports, interviews and articles prepared especially for the community, and participation in meetings can be counted as CPE educational points required to maintain industry certificates such as CISSP or CISM.
Networking is additionally strengthened by a private communication channel connecting only CSO Council members and invitations to events not available to the general public – executive lunches and closed meetings with experts and industry personalities.
In addition, there are formal benefits: automatic membership in ISSA Polska, a VIP package as part of the Advanced Threat Summit conference, discounts on other Evention products and a real influence on the topics of subsequent meetings – each active member can submit issues that are discussed by the CSO Council.
What topics are covered by CSO Council meetings
The topics of CSO Council meetings are chosen jointly by the Council and the participants each year, thanks to which the program reflects the real challenges facing security departments at a given time. Three areas dominate in 2026.
- The first one concerns risks related to artificial intelligence: implementation of AI and AI agents in the organization are analyzed as a new type of internal threat, and a separate meeting is devoted to the automation of offensive and defensive activities using AI on the side of Red teams and Blue Team. At the same time, new challenges of identity and permissions management are discussed, which are further complicated by AI.
- The second area focuses on the organization’soperational readiness: testing digital resilience, conducting tabletop exercises, and acting in a crisis situation, including collecting evidence, communication and negotiations during the incident.
- The third area concerns managerial side of the CISO’s work – building and negotiating the cybersecurity budget with the management, obtaining funds for this purpose, as well as communicating with regulators, requiring the CISO to maintain a balance between formal compliance and the operational effectiveness of the team.
Meetings are held cyclically, 8-10 times a year, in Warsaw or its immediate vicinity, which allows you to follow the changing priorities of the industry on an ongoing basis, without the one-year delay typical of annual conferences.
CSO Council compared to other initiatives of Evention and ISSA Polska
Evention and ISSA Polska are behind several initiatives addressed to the cybersecurity community in Poland, but they differ in format and purpose. Advanced Threat Summit and KSC Forum are annual conferences with a specific date and agenda and ticketed registration, open to a wider range of participants, including technology providers.
CSO Council works differently – it is a permanent, closed community with no registration fees, based on admission criteria and a series of meetings spread throughout the year.
However, both formulas are related: active members of the CSO Council will receive a VIP package for the Advanced Threat Summit, and the community itself is among the patron organizations of the KSC Forum, which further expands the network of contacts available to its members.
It is also worth distinguishing CSO Council from the concept of CISO. CISO is a position and scope of responsibilities in an organization, while CSO Council is a community of people performing such functions – a platform for exchanging experiences, not a definition of a professional role.
FAQ – frequently asked questions about the CSO Council
What is the difference between CSO Council and CISO?
CISO is a position responsible for information security in an organization, and CSO Council is a community of people performing CSO and CISO functions in large companies and institutions in Poland.
How much does CSO Council membership cost?
Membership and participation in meetings are free, except for the annual September away meeting.
Who can join the CSO Council?
People holding managerial positions responsible for cybersecurity in large organizations, with a budget and a team in this area, without a superior directly responsible for cybersecurity.
How often do CSO Council meetings take place?
Meetings are held periodically, 8-10 times a year, in Warsaw or its immediate vicinity.