EDBT 2026 Demo / reviewers in the wild / expert
Jakub Vostoupal
dblp:299/5989
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-1669-9931ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Comparative analysis of OSINT tools, techniques, and legal aspectsabstractOpen Source Intelligence (OSINT) has emerged as a crucial practice in the digital era, driven by the rapid growth of information available on the internet and its expanding applications across multiple sectors. This study examines the role of OSINT as a vital tool in domains such as the indexed internet, social networks, the darknet, archives, and network devices. We present a comparative analysis over 140 tools, services, and databases usable for OSINT. The analysis reveals significant diversity in functionality, licensing, and accessibility, with no single solution capable of meeting all intelligence needs. The findings emphasize the necessity of combining multiple tools with manual methods to acquire accurate and reliable intelligence, while also highlighting persistent challenges, including limited integrations, licensing constraints, and the volatility of online sources. Beyond technical and methodological aspects, OSINT practice is shaped by complex legal and ethical considerations, as the public availability of data does not guarantee lawful use. This study provides a legal analysis of the General Data Protection Regulation (GDPR) and the Budapest Convention in relation to OSINT investigations. As compliance remains context-specific, the study underscores that the future of OSINT depends not only on technological advancement, but also on strong legal and ethical responsibility to mitigate risks of liability and reputational harm. Willi Lazarov, Vojtech Moravec, Pavel Loutocký, Jakub Vostoupal, Zdenek Martinasek |
Comput. Secur. | 4 |
| 2024 | Beyond the Bugs: Enhancing Bug Bounty Programs through Academic PartnershipsabstractThis paper explores the growing significance of vulnerability disclosure and bug bounty programs within the cybersecurity landscape, driven by regulatory changes in the European Union. The effectiveness of these programs relies heavily on the expertise of participants, presenting a challenge amid a shortage of skilled cybersecurity professionals, particularly in less sought-after sectors. To address this issue, the paper proposes a collaborative approach between academia and bug bounty issuers. Andrej Kristofík, Jakub Vostoupal, Kamil Malinka, Frantisek Kasl, Pavel Loutocký |
ARES | 2 |
| 2024 | Using Real-world Bug Bounty Programs in Secure Coding Course: Experience ReportabstractTo keep up with the growing number of cyber-attacks and associated threats, there is an ever-increasing demand for cybersecurity professionals and new methods and technologies. Training new cybersecurity professionals is a challenging task due to the broad scope of the area. One particular field where there is a shortage of experts is Ethical Hacking. Due to its complexity, it often faces educational constraints. Recognizing these challenges, we propose a solution: integrating a real-world bug bounty programme into the cybersecurity curriculum. This innovative approach aims to fill the practical cybersecurity education gap and brings additional positive benefits. Kamil Malinka, Anton Firc, Pavel Loutocký, Jakub Vostoupal, Andrej Kristofík, Frantisek Kasl |
ITiCSE (1) | 4 |
| 2024 | Stuxnet vs WannaCry and Albania: Cyber-attribution on trial
Jakub Vostoupal |
Comput. Law Secur. Rev. | 1 |
| 2024 | The legal aspects of cybersecurity vulnerability disclosure: To the NIS 2 and beyond
Jakub Vostoupal, Václav Stupka, Jakub Harasta, Frantisek Kasl, Pavel Loutocký, Kamil Malinka |
Comput. Law Secur. Rev. | 1 |
| 2023 | The Curation Mechanism for the Czech National Qualifications Framework in CybersecurityabstractThe cybersecurity field is a fast-paced, ever-changing, and complex environment. Society’s growing dependency on ICT combined with the rising number and seriousness of cyber threats emphasizes the need for a sufficient number of cybersecurity experts, who are, at the moment, still pretty scarce. Furthermore, the lack of common methodology, understanding of individual cybersecurity work roles, and the disparate perspectives of cybersecurity stakeholders from diverse backgrounds (academia, public entities, private sector) further hinder any long-term solutions. In our previous contributions, we presented the National Qualifications Framework in Cybersecurity, which could provide a solution for a sufficiently up-to-date, broad, and granular taxonomy of skills requirements for existing and future cybersecurity work roles that could mitigate this problem. The Platform, including the curation mechanism, was created for this Framework to be easy to navigate, administer, update and flexible. This enabled further utilization (and possibly even development) of the available inputs and synergies from existing qualification frameworks, such as the NICE Framework and the European Cybersecurity Skills Framework. In this article, we introduce and analyze the curation mechanism and the challenges of navigating cybersecurity qualification frameworks and producing a sufficient UI. Primarily we focus on the specific functions of the curation mechanism, e.g., the feedback collection and Framework updates, which could be adapted even for other framework content or languages and thereby implemented in parallel solutions. Therefore, we present the Platform, including the curation mechanism, as a dynamic common reference tool for cybersecurity workforce requirements. Frantisek Kasl, Pavel Loutocký, Jakub Vostoupal |
ARES | 3 |
| 2022 | The Platform for Czech National Qualifications Framework in CybersecurityabstractThe scarcity of cybersecurity experts negatively affects the overall state of cybersecurity among all relevant stakeholders in the private and public sectors. The efforts to close the cybersecurity skills gap are unfortunately limited by the lack of a sufficiently broad and granular taxonomy. In this article, we introduce our work on the Czech National Qualifications Framework in Cybersecurity as a possible remedy for the said problem. Firstly, we shortly describe other relevant projects and initiatives. Further, we focus on the development process of the Czech Framework, its components and their interactions, and subsequently we focus on the Platform and its functions. This interactive platform offers other stakeholders (and future users) an effective access to the framework and its further utilization. It also simplifies and allows for an effective administration and update of a framework on this level of granularity. Jakub Vostoupal, Frantisek Kasl, Pavel Loutocký, Tomás Pitner, Patrik Valo, Adam Valalský, Damián Paranic |
ARES | 1 |
| 2021 | The Matter of Cybersecurity Expert Workforce Scarcity in the Czech Republic and Its Alleviation Through the Proposed Qualifications FrameworkabstractThis paper is focused on challenges connected with the persisting imbalance between the supply and demand of the cybersecurity expert workforce. We analyse the current situation in the Czech Republic, finding that although the shortage of experts affects the private and public sectors both, the public sector is constrained by a massive financial undervaluation of cybersecurity experts and other legal and systematic deficiencies and obstacles and therefore has a much lower chance of attracting talents in this field. The inability of public institutions to find relevant workforce causes, among other things, problems with formulating public procurements, assessing offers and communicating their requirements to the supply-side of the labour market. One of the solutions to this crisis might be in the systematic support of education programmes. However, the cybersecurity field is so dynamic and fragmented that the alignment of the education programme with the market needs presents a significant challenge. There, a unified qualifications framework could serve as a basis for finding common ground. We focus on the benefits of creating such a framework, especially the benefits that a united taxonomy can bring to the cybersecurity labour market by bolstering cybersecurity higher education. Finally, we summarise the key features of the cyber-qualifications framework that is being developed under our current project and highlight its potential use for labour market optimisation and efficient development of new cybersecurity study programs and further education. Jakub Drmola, Frantisek Kasl, Pavel Loutocký, Miroslav Mares, Tomás Pitner, Jakub Vostoupal |
ARES | 6 |