Agenda
Presentations already confirmed include:
►Defending Tomorrow: The Future of SOC and Cybersecurity
Adam Abdat, SOC Lead, easyJet
- Enhancing Tier-1 SOC workflows by improving signal quality, reducing alert fatigue, and supporting faster, more accurate triage.
- Bringing together security, cloud, and IT insights to improve collaboration and cross-team decision-making.
- Strengthening incident response by improving visibility, reducing tool sprawl, and streamlining operational processes.
- Tackling emerging threat patterns — including human, machine, and AI-driven behaviours — through improved detection and analysis.
►Third-Party Risk? Managed!
Andrea Szeiler, Group CISO, MVM Ltd
- Understanding Your Third-Party Ecosystem: Mapping vendors, services, and business dependencies to identify what truly matters.
- From Compliance to Control: Turning regulatory requirements into a practical approach for assessing and managing third-party risks.
- Trust, Verify, Collaborate; Strengthening resilience through effective partnerships, clear responsibilities, and shared preparedness
►From Telco to Quantum Telco: Reskilling for the Quantum Era
Julio Gonzalez-Saenz, Quantum Engagement Lead, Vodafone
- Quantum and the Telco's Role
- Quantum Telco Pillars
- Current Initiatives & Skills Transition
- Reskilling Framework
- Engagement& Culture
►Invisible Leaks: The Hidden Risks of Chatting with AI
Manit Sahib, Ethical Hacker & Former Head of Penetration Testing & Red Teaming, Bank of England
- AI Privacy Risks: How tools like ChatGPT, Claude, and Co-Pilot can end up knowing more about you than your best friend (and never forget a thing). The hidden dangers of casually sharing information with AI
- When Small Details Add Up: Why a few “harmless” details can combine to paint a full picture & How scattered information can reveal sensitive data without you realising
- The Myth of Security: Why AI models aren’t as secure as we might think & How attackers can trick them into spilling information
- Simple, Practical Steps: For employees: how to keep personal and company data safe & For organisations: reducing AI-related risks before they grow
►Compliance as a Consequence: Driving Security, Enabling Assurance
Simon Turner, Head of Security Governance and Compliance, BT Group
- Reframing compliance as the natural result of strengthening governance, managing risk, and designing effective controls, rather than treating it as a standalone or periodic activity.
- Unifying GRC efforts by embedding clear ownership, aligned controls, and security practices into daily operations while meeting overlapping regulatory and certification requirements.
- Strengthening resilience and reducing waste by moving from chasing audit evidence to building systems where compliance is the outcome of doing security the right way.
►Securing the Autonomous Frontier: Guardrails, Governance, and Agentic AI
Nathan Wyatt, Information Security Engineer, The Telegraph Group
- Securing Autonomous Agents
- Hardening the MCP Integration Layer
- Bringing Shadow AI to Light
- Defending the CNI Boundary
- Actionable Security Playbook
►Run Like a Business: What 196,000 Leaked Ransomware Chats Teach CNI Defenders
Chris Butchart, Senior Solutions Engineer, BeyondTrust
- Inside the leaked internal chats of a major ransomware operation: roughly 196,000 messages revealing a group run like a business, with salaries, management structure and office hours.
- Why the front door is remote access, not malware: what the group's own communications show about buying, brute-forcing and reusing VPN and remote access credentials instead of burning zero days.
- The weakest link in converged IT/OT environments: unmanaged third-party and vendor privileged access, and why the traditional VPN and jump host model cannot answer "who did what, where, and with which credential".
- What good looks like: closing the remote access gap with identity-first controls, including just-in-time access, credential injection and full session recording."
►Building a Modern OT Security Program: From Asset Visibility to Uptime
Julian Smith, Principal Solutions Engineer, Claroty
- How to overcome IT/OT integration challenges, bridge organisational silos, and prioritise the visibility blind spots that matter most across complex CNI environments.
- Why behavior-based monitoring outperforms vulnerability-driven risk scoring when protecting legacy devices and safeguarding system uptime.
- Best practices for prioritising high-impact risks aligned with regulatory frameworks like NIS2 and NCSC CAF, maximising operational resilience without overloading team capacity.
►Protecting Critical National Infrastructure in a Changing Threat Landscape
Robert FitzSimons, Sales Engineering Manager, Huntress
- Critical national infrastructure is increasingly targeted by attackers who do not need to break in, they simply log in using stolen credentials, compromised identities, or trusted tools.
- This session explores how organisations can move beyond alert fatigue and respond to the threats that matter most. We will discuss the modern attack chain, the importance of detecting initial access and lateral movement early, and how human-led threat hunting and security posture management can help protect essential services and strengthen resilience before an incident becomes a national-impact event.