|
8:30
|
Networking and Registration
|
|
9:30
|
IDC¦CSO Cybersecurity Summit Opening Remarks
|
|
Hannah Dowie
Event Manager IDC UK
|
|
9:40
|
IDC Keynote: Security and Trust in the New AI World
|
|
The advancement of AI continues to impact corporate strategy as models and use-cases gain maturity and develop from beta-phase testing to full launch in active functions and applications. However, AI models and applications can increase cyber risk, exposing organizations to new security and privacy vulnerabilities that cyber attackers will seek to exploit. Additional to cyber threat, poorly implemented security and privacy governance in AI use cases will incur regulatory fines and potential loss of license to operate. The implementation guidelines of NIS2, DORA, and the EU AI Act will all encourage businesses to establish robust AI governance practises, as well as address cyber risk and cyber resilience programs to ensure and maintain compliance. AI is also being used by cyber criminals to enhance their capabilities, which raises new challenges for security teams. Finally, security vendors continue to develop their own in-house AI models to layer on new and innovative features into security toolsets to augment security systems, such as automation in security operations, applied AI models in threat detection and IR, and more.
Duncan Brown
Group Vice President, European Enterprise Research, IDC
|
|
10:05
|
Intelligent Cyber Resilience
|
|
As regional legislation and regulation increases the demand for cyber resilience in the more heavily regulated industries and organisations, we will need to develop and implement strategies that help us visualise, withstand and survive in the face of a rapidly evolving threat landscape. As the demand for stronger cyber resilience extends the scope beyond heavily regulated industries and organisations to the wider supply chain, we will ALL need to take action to improve our cyber resilience. In this session we will discuss the impact of time and how the future application of intelligence, AI and automation will be key to maintaining effective cyber resilience. We will shine a light on the challenges some organisations are facing in applying these key elements to their cyber resilience strategies and how we think advances technology and focusing on processes as well as people can deliver better outcomes.
Rob Lay
Leader, Systems Engineering, Cyber Security, Cisco
Stephen Faulkner
Chief Technologist for Security Office of the CTO, CDW
|
|
10:25
|
Opening Panel Discussion: AI-Driven Cybercrime: Building Resilience Against Adaptive Threats
|
|
The rise of AI in cybercrime is amplifying existing cyber threats and creating new challenges, which forces organisations to reevaluate their defensive strategies.
Cybercriminals are leveraging AI to automate attacks, craft more convincing phishing schemes, and evade traditional security measures.
While the full impact of AI in cybercrime is still emerging, its potential to develop adaptive and highly targeted threats underscores the need for proactive preparation.
This panel will discuss how you can coordinate a well-funded and forward-looking approach that integrates people, processes, and technology to navigate these evolving challenges.
Wendy Ng
Business Information Security Officer, Marks & Spencer
Glen Hymers
Head of Data Privacy & Compliance, The Cabinet Office
|
|
10:55
|
Networking Break
|
|
11:30
13:00
|
Track 2: Building Strength in Cybersecurity: Fostering Skills and Resilience (Parallel Sessions)
|
|
11:30 - 11:45
Beyond the Reach of Cyber
With each new advancement, comes the advancement of new threats & for every new technology, there is an adversary looking to exploit it. We explore how CISO’s can help to cultivate a different way of thinking and encourage the business to strengthen its first line of defence.
Mari Sterman
Security Officer, T-Systems
11:45 - 12:00
Building Strength in Cybersecurity – Data Privacy, Resilience, and Risks of AI
We all aspire to build a rock solid cybersecurity system. One that can cope with ever evolving cyber risks, meet increasingly stringent regulations and adapt to the world of AI. Now, cybersecurity vendors are a critical part of your 'supply chain', and the pressure is on to ensure it is resilient. Let's explore the issues and practical considerations as you evaluate just how strong you really are.
Clive Finlay
Chief Technology Officer, APJ & EMEA, Symantec
12:00 - 12:30
Re-Skilling the Workforce for a Cybersecure Future
With cyber threats coming in all shapes and sizes, equipping employees with cybersecurity skills is no longer optional—it’s essential. Companies need to implement strategies for re-skilling the workforce to address growing security challenges, from foundational cybersecurity training to advanced skill development. Fostering a culture of security awareness, closing the skills gap, and empowering employees to play an active role in protecting digital assets is key.
During this panel we will discuss insights on successful re-skilling initiatives, the latest training tools, and how investing in employee cyber readiness can safeguard your organisation’s future.
Gary Osborn
Head of Information Security, Amnesty International
Clare Quick
IT Operations Director, National Trust
Mike Brass, Dr
Head of Enterprise Security Architecture, National Highways
12:30 - 13:00
Breaking the Burnout Cycle: Managing Stress and Fatigue in Cybersecurity
It is well documented that burnout in cybersecurity is at an all-time high, with the need to address the intense pressures of 24/7 threat vigilance and high-stakes environments. Options to reduce workloads include through automation, fostering supportive workplace cultures, and building resilience among professionals. This panel will address actionable insights to mitigate stress, enhance mental health, and create sustainable, effective security teams capable of navigating today’s evolving cyber challenges.
Justyna Larkowaska
CISO, Ardonagh Advisory
Mike Backinsell
Deputy CISO, Manpower Group
|
|
11:30
13:00
|
Track 1: Understanding and Countering Modern Threats (Parallel Sessions)
|
|
11:30 - 11:45
Zero Trust: A Modern Security Strategy for a Changing World
In today’s rapidly evolving cybersecurity landscape, traditional perimeter-based security is no longer sufficient. This session explores Zero Trust, a modern security framework based on the principle that no entity. inside or outside the network should be inherently trusted.
Join Richard Moir as he examines the evolution of Zero Trust, why it’s more critical than ever, and how organizations can successfully implement it using HPE Aruba Networking’s cutting-edge solutions. Learn how advanced networking and security technologies can reinforce Zero Trust principles, enhance visibility, and mitigate risk.
With increasing regulatory requirements such as NIS2 mandating stronger cybersecurity measures, adopting a Zero Trust approach is no longer optional: it's essential.
Whether you're just beginning your Zero Trust journey or looking to refine your existing strategy, this session will provide valuable insights, key regulatory considerations, and actionable steps to strengthen your security posture.
Richard Moir
Solutions Architect, HPE Aruba
11:45 - 12:00
The attacker’s POV: How to build the right continuous threat exposure management (CTEM) program to reduce risk
Today’s cybersecurity leaders are under constant pressure to demonstrate their ability to manage risks effectively. With threats constantly evolving, companies need dynamic strategies to mitigate risks, especially in the cloud. This session will explore how CISOs can use Cyber Threat Exposure Management (CTEM) to stay ahead of threats and maintain strong security by analyzing attack methods and threat actor behavior.
The only way security practitioners can effectively manage the ever-changing threat landscape and maximize defensive strategies is by leveraging automation, orchestration, and continuous, evidence-based validation of the tools and technologies deployed in their enterprise environment. Effective threat management must be an ongoing, continuous, and integrated service, not just a one-time analysis or isolated mitigation effort.
In this session, attendees will learn about:
• Generating an effective organizational threat profile
• Identifying the threat actors, campaigns and adversarial TTPs that pose the greatest risk to your organization
• Understanding the business and security risks of threat exposure
• Gathering meaningful metrics to develop the business case for enhanced cybersecurity
• Developing a threat management solution that clearly helps manage and optimize your organization's attack and defense surface
Matt Baird
Lead Solutions Architect, CyberProof, a UST Company
12:00 - 12:30
Securing Innovation – Embedding Security from the Start
In the race to innovate with AI, IoT, and cloud computing, businesses face a dual challenge: driving transformative growth while safeguarding against cybersecurity threats like data breaches and ransomware. Embedding security from the earliest stages of any project is critical to protect systems, data, and user trust. However, this proactive approach is often hindered by costs, resource limitations, and organizational barriers.
Join this panel to explore strategies for integrating robust cybersecurity measures from the ground up, ensuring innovation and security work hand-in-hand to drive success in an increasingly connected world.
Tom O'Driscoll
Head of Security Operations & Intelligence, National Highways
Hazel McPherson
Former CISO, Global Financial Services Organisation
12:30 - 13:00
Securing the API Revolution: Strategies for Modern Threats
According to IDC, APIs are pivotal to cloud-native applications, but their growth has heightened security risks like AiTM, DDoS, and data exposure attacks. Alarmingly, only 9% of organizations have comprehensive API security plans, according to IDC.
This panel will discuss best practices for data governance, AI-driven security, and standardized frameworks to protect API ecosystems.
Wendy Ng
Business Information Security Officer, Marks & Spencer
|
|
13:00
|
Networking Lunch Break
|
|
14:00
14:40
|
IDC Connect Roundtables (Parallel Sessions)
|
|
Peer-to-peer discussions around topics, with the aim being to come up with three key takeaways from the group discussion. Delegates will choose which roundtable they want to attend based on the topic put forward.
14:00 - 14:40
The Future State of Intelligent Cyber Resilience
Cyber resilience, crucial in safeguarding digital assets, ensures an organisation can maintain core functions during and after cyber attacks. Join our discussion on how applying intelligence, AI, and automation will shape the future of cyber resilience.
Rob Lay
Leader, Systems Engineering, Cyber Security, Cisco
Stephen Faulkner
Chief Technologist for Security Office of the CTO, CDW
14:00 - 14:40
Cyber Defence & The Advancements That Make It Possible
Please join T-Systems as we explore the variables of cyber security vs cyber defence and the technological advancements in AI Security, Automation and threat intelligence that make it achievable.
Mari Sterman
Security Officer, T-Systems
14:00 - 14:40
Ctrl+Alt+Defend: Resetting Cyber Resilience Strategies
In a world where breaches are a matter of when, not if, resilience is the new frontline. This roundtable explores how IT and security leaders can rethink endpoint recovery and cyber resilience—starting with the ability to reset, rehydrate, and resecure devices at scale. We’ll dive into real-world strategies for maintaining visibility, control, and security even when endpoints go dark. Join us to explore how Absolute Security’s firmware-embedded platform is helping organisations move from reactive defence to built-in resilience—so every reboot is a comeback.
Mike Spence
Head of International Presales Engineering, Absolute Security
14:00 - 14:40
The Future of Identity Security: Balancing User Experience & Zero Trust
Jason Goode
VP of Sales Western & Southern Europe, Ping Identity & iC Consult
14:00 - 14:40
The Unseen Threat: Closing the Access-Trust Gap
Natalie Williams
Head of Enterprise, 1Password
14:00 - 14:40
From Cyber Security to Cyber Resilience
Ian Wood
Senior Director Technology Northern EMEA, Commvault
14:00 - 14:40
From Defence to Dominance: Predicting, Preventing, and Proving Cyber Resilience
For years, cybersecurity teams have chased threats across the perimeter, the endpoint, and the network - yet breaches remain inevitable. Boards are demanding evidence of resilience, regulators expect proof of control, and traditional security operations are struggling to keep up as attackers leverage AI and automation. Is proactive security and resilience a realistic aim? Can we predict, prevent and prove cyber resilience?
Join Rubrik for a discussion on how leading organisations are shifting from endless threat chasing to risk-based outcomes across on-premise, cloud and SaaS.
14:00 - 14:40
From Protection to Potential: Leveraging DLP to Unlock Copilot’s Power
Clive Finlay
Chief Technology Officer, APJ & EMEA, Symantec
14:00 - 14:40
Building a Positive Cybersecurity Culture
Romain Fouchereau
Research Manager, IDC
Ralf Helkenberg
Senior Research Manager, Research Manager - Privacy & Data Security, IDC UK
|
|
14:45
15:15
|
Track 1: Understanding and Countering Modern Threats (Parallel Sessions)
|
|
14:45 - 15:15
Securing the Expanding Attack Surface – Continuous Vulnerability Management in Action
As organisations embrace new technologies and scale their operations, their attack surface grows exponentially. Proactively managing this ever-expanding landscape is crucial to defend against evolving cyber risks. Therefore, Continuous Vulnerability Exposure (CVE) Management is critical.
This panel will discuss strategies and tools that enable organisations to monitor and protect all access points, ensuring a proactive, resilient defence against breaches.
Manish Chandela
CISO, Sportradar
Justyna Larkowaska
CISO, Ardonagh Advisory
|
|
14:45
15:15
|
Track 2: Building Strength in Cybersecurity: Fostering Skills and Resilience (Parallel Sessions)
|
|
14:45 - 15:15
From Vulnerability to Strength: Building a Culture of Cybersecurity Accountability
Human error remains the leading cause of cybersecurity incidents, from phishing attacks to insider threats. While organizations invest in advanced technologies, fostering a strong cybersecurity culture is crucial to bridging the gap. Integrating security awareness into everyday operations, therefore empowering employees to take ownership of cybersecurity, and addressing the challenges of creating a collaborative, blame-free reporting culture.
Join this panel to discover how to turn people from the weakest link into the strongest defence.
Ruth Humpherson
IT Security Manager, ramarketing
Greg Emmerson
Group IT Director Infrastructure & Security, Applegreen
Hazel McPherson
Former CISO, Global Financial Services Organisation
|
|
15:15
|
Afternoon Networking Break
|
|
15:45
|
Who Owns the Machines? Governing AI and Non-Human Identities in the Age of Autonomy
|
|
AI agents, bots, and machine identities are multiplying across cloud and enterprise environments — often with elevated access, no clear owner, and limited governance. As we enter the age of autonomous operations, these non-human identities represent one of the most overlooked risks in modern cybersecurity.
In this session, we explore how organisations can regain control through better discovery, ownership mapping, and governance practices — laying the foundation for secure automation at scale. He will also offer a glimpse into how SailPoint is evolving the identity model with its upcoming Identity Graph, designed to unify and contextualise identity relationships across the business.
Mo Joueid
Advisory Solutions Consultant, Sailpoint
|
|
15:55
|
IDC Research Insight: Cybersecurity and Beyond:
Resilience, Compliance and AI
|
|
Romain Fouchereau
Research Manager, IDC
Ralf Helkenberg
Senior Research Manager, Research Manager - Privacy & Data Security, IDC UK
|
|
16:10
|
Closing Panel: The Ethical Implications of AI in Security
|
|
As AI becomes a foundation of modern security systems, its ethical implications demand critical examination. The main challenges of balancing innovation with responsibility are privacy, accountability, bias, surveillance, and the potential for misuse. IDC research is focused on how AI-powered surveillance impacts civil liberties, the risks of data misuse, and the role of fairness in combating biases. All of which can lead to discrimination or unequal security outcomes.
This panel will discuss how to navigate these ethical complexities and ensure that AI in security serves as a tool for protection without compromising fundamental rights.
Zahra Zohoor
BISO, Nationwide
Jess Matthews
Governance Compliance Officer, Acacium Group
Theo Botha
CISO, Dr Martens
|
|
16:40
|
Closing Remarks & Key Takeaways
|
|
16:50
|
Event Close
|