Agenda
| 08:00 - 08:50 |
Registration & Breakfast Networking |
| 08:50 - 09:00 |
Chair's Welcome |
| 09:00 - 09:20 |
►Conformity Will Not Save You: AI Risk Beyond the EU AI Act Geoffrey Taylor, Information Security Officer, Nordea Asset Management Your assessment said Low Risk. Is it really?
|
| 09:20 - 09:40 |
►Agentic AI and the New Resilience Challenge Richard Cassidy, Field CISO, Rubrik
|
| 09:40 - 10:00 |
►Presentation to be Confirmed JupiterOne |
| 10:00 - 10:20 |
►Actions Speak Louder Than Tokens: Treating Frontier AI Agents as Insider Threats Matt Adams, Generative AI & Emerging Technology Security, Citi
|
| 10:20 - 11:00 |
► Education Seminars 1 Delegates will be able to choose from the following topics:
|
| 11:00 - 11:30 |
Networking Break |
| 11:30 - 11:50 |
►Securing Cloud Platforms at Scale Laura Good, Cloud Security Architect, Lloyds Banking Group
|
| 11:50 - 12:10 |
►The Evidence Game: Proving cyber resilience without slowing the business Alan Simpson, UK and Ireland Field CISO, Rapid7
|
| 12:10 - 12:30 |
► This Was Never a Drill: The Case for Autonomous IT Dan Jones, Senior Security Advisor, Tanium
|
| 12:30 - 12:35 |
►Presentation to be Confirmed ThreatLocker |
| 12:35 - 13:15 |
► Education Seminar 3 Delegates will be able to choose from a range of topics:
|
| 13:15 - 14:20 |
Lunch and Networking |
| 14:20 - 14:40 |
►Quantum Is Coming. Financial Services Can’t Afford to Wait Will Collinson, Technical Director - Cryptography, HSBC
|
| 14:40 - 15:00 |
►Trust, Then Autonomy: Evaluating Agentic AI in Financial Services Institutions Chris Vaughan, Solution Engineer, Sublime Security
|
| 15:00 - 15:20 |
►The New Non-Human Insider: Governing the Agents Drata
|
| 15:20 - 16:00 |
► Education Seminar 3 Delegates will be able to choose from a range of topics:
|
| 16:00 - 16:20 |
Networking Break |
| 16:20 - 16:50 |
►Panel Discussion: Customer Data & AI: Control, Exposure, and Proof Simon Brady, Event Chairman
|
| 16:50 - 17:10 |
►Rise of Autonomous Attacks (Live Mythos-Style Hack) Manit Sahib, Ethical Hacker & Former Head of Penetration Testing & Red Teaming, Bank of England
|
| 17:10 - 17:15 |
Chairs Closing Remarks |
| 17:15 - 18:30 |
Drinks Reception & Networking |
Education seminars
The Identity Gap: Closing what AI opened in financial services
Mario Platt, Vice President, CISO, LastPass
This thought-provoking session will challenge assumptions around existing security strategies, revealing how the rapid rise of AI tools, agents, and non-human identities is outpacing traditional controls like MFA and IAM. Through compelling data, real-world case studies, and practical guidance, attendees will gain fresh insight into managing credential sprawl, securing AI-driven environments, and meeting evolving regulatory expectations, equipping them to move beyond the illusion of security and build truly resilient, identity-first protection.
Attendees will learn:
- How to manage credential sprawl
- Secure AI-driven environments
- Meet evolving regulatory expectations
- How to move beyond the illusions of security and build truly resilient, identity-first protection
Securing the Invisible - AD NHI Discovery and Protection
Kev Smith, EMEA Principal Engineer, Silverfort
Service accounts are one of the most overlooked areas in identity security. They operate continuously in the background, connecting applications and running automated processes across your environment - often with elevated privileges and no human owner actively managing them. This is even more prevalent with frontier models like Mythos leveraging such identities.
That's exactly the problem Silverfort was built to solve. Full discovery, behavioural baselining, and real-time enforcement - across your entire environment.
Attendees will learn:
- Discovery and runtime access protection for service accounts is a critical capability for any IAM team operating at scale.
- Know what you have - discover and prioritise your highest risk service accounts before they become a problem.
- Get to control fast - no agents, no schema changes, no lengthy deployment; protection that fits around your environment, not the other way round.
Third party compromise - attacks through the suppliers, code and pipelines you already trust
Oliver Livesy, Red team specialist, WorkNest
Organisations increasingly face threat actors who bypass perimeter defences entirely by targeting the third-party suppliers, software libraries, and CI/CD pipelines that already hold trusted access to their environments. This presentation explores how attackers exploit these relationships to achieve high-impact compromises, examining why financial entities are prime targets, the methods adversaries use, and the defensive considerations organisations should be aware of, including how red team engagements can be leveraged as a practical tool for identifying and stress-testing supply chain exposure before a real attacker does.
Attendees will learn:
- How attackers exploit these relationships to achieve high-impact compromises
- Why financial entities are prime targets and the methods adversaries use
- The defensive considerations organisations should be aware of, including how red team engagements can be leveraged as a practical tool
Disrupting Social Engineering in Financial Services: Protect Your Customers, People, Brand, and Revenue
Daniel Oxley, Senior Engineer, Doppel
Financial institutions are facing a new era of fraud driven by AI-powered social engineering attacks that exploit trust across both external channels and human workflows.
From impersonated executives and phishing campaigns to deepfake voice calls targeting helpdesks and contact centers, attackers are operating faster across more channels and with greater sophistication than ever before. During this session, Dan will break down how these attacks actually operate and what it takes to stop them.
Attendees will learn:
- How to move beyond fragmented tools and traditional training programs to a unified approach that exposes and eliminates real-world threats
- Through real examples and a live walkthrough of Doppel’s platform, you will see how financial institutions can protect customers, strengthen workforce readiness, and reduce fraud and regulatory risk.
AI is Breaking Data Security… And Fixing It: The New Reality of AI-Driven Risk and How to Stay Ahead
Stephen Green, Regional Vice President of EMEA, ConcentricAI
AI is rapidly becoming one of the biggest drivers of productivity and innovation in the enterprise — and one of the fastest-growing sources of data security risk. As copilots, assistants, and public AI tools become integrated into daily work, sensitive data is flowing into systems that most security teams can’t fully see, understand, or control.
The problem is that traditional data security controls were never built for this. In fact, many organizations were already struggling to operationalize data security before AI accelerated the challenge. The good news? AI isn’t just creating the problem — it’s also enabling a smarter, more effective way to solve it.
Attendees will learn:
- Why AI has become one of the fastest-growing and least visible sources of enterprise risk
- How GenAI is creating new exposure points for sensitive data
- Why legacy data security tools have failed to keep up — and why AI is making those gaps harder to ignore
- How context-aware, AI-driven data security can deliver more accurate visibility, stronger controls, and real-time enforcement
- What organizations can do to enable AI innovation without expanding their risk surface
- Attendees will leave with a clearer understanding of how AI is reshaping data security — and how they can use that same technology to gain control, minimize exposure, and support safer AI adoption across the business.
Beyond the Checkbox: When Third-Party Risk Becomes Client Disruption
Haydn Brooks, CEO, Risk Ledger
Mark Walmsley, CISO, Freshfields
Third-party cyber risk remains one of the biggest challenges facing security and legal teams. Recent industry research found that 75% of legal organisations say their biggest concern following a supplier incident is the impact on client service - from disrupted access to systems and data through to delays in delivering client work, while 80% say supplier audit rights are still difficult to enforce in practice.
Join Risk Ledger's CEO, Haydn Brooks and Mark Walmsley, CISO, Freshfields as they explore the gap between contractual best practise and operational reality - from how to respond effectively to vendor breaches, to navigating negotiations with large technology suppliers.
This panel discussion will examine how organisations can balance commercial priorities with cyber risk and focus on the controls that meaningfully improve resilience.
Attendees will learn:
- How to respond effectively to vendor breaches.
- How to navigate negotiations with large technology suppliers.
- How organisations can balance commercial priorities with cyber risk and focus on the controls that meaningfully improve resilience.
The First Time You Test Crisis Decision Making Shouldn’t Be During a Crisis
Peter Lane, Consultancy Director, CyroCyber
Most organisations have an incident response plan. Far fewer know how their leadership teams will actually perform when critical decisions need to be made under pressure.
As financial services firms face increasing regulatory scrutiny and more disruptive cyber incidents, resilience can no longer be proven through documentation alone. The real test is how quickly and effectively an organisation can coordinate, communicate and make decisions when systems, operations and reputation are on the line.
This session explores how cyber exercising, from executive crisis simulations and Gold/Silver/Bronze command structures through to live play attack scenarios, helps organisations expose gaps before attackers or regulators do.
Attendees will learn:
- We’ll examine how leading financial services organisations are using exercising to expose hidden gaps in crisis decision making and escalation paths, and...
- Test how effectively executive, operational and technical teams coordinate under pressure, and...
- Improve speed and clarity of communication during high stakes incidents, and...
- Strengthen confidence in real world operational resilience, and...
- Align exercising programmes with expectations under the UK Cyber Security & Resilience Bill and CAF 4.0
- A practical discussion for CISOs and senior cyber leaders looking to build confidence in how their organisation will respond in the face of a cyber attack.