Agenda

Presentations already confirmed include:


►The Deadline Moved. The Declaration Didn't.

Punit Bafna, Head of Cybersecurity & Compliance, Haleon

  • What actually changed under the AI Act amendments in July 2026, and which obligations were never deferred at all?
  • Why standard identity controls (recertification, joiner-mover-leaver, segregation of duties) fail structurally when the identity is an autonomous agent
  • Where the current control frameworks stop short, and what evidence a board realistically needs before declaring controls effective

►Mythos and Beyond: What the Next Generation of AI Means for Security, Sovereignty, and Business

Rob Flanders, Head of Threat and Incident Response, BAE Systems

  • The changing AI landscape: the latest advances in AI models, the impact of US export controls, and how policy is shaping global AI development.
  • Emerging security challenges: how increasingly capable AI models are changing the cyber threat landscape, including the path towards the much-discussed concept of Recursive Self-Improvement (RSI).
  • Implications for the UK and Europe: what a US-centric AI ecosystem means for competitiveness, sovereignty, and the capabilities organisations will need to succeed.

►Fireside Chat: Capacity or Efficiency – What's the Real Issue in Cyber Defence?

Simon Brady, Event Chairman (Moderator)
Quentyn Taylor, Senior Director – Product, Information Security and Global Incident Response, Canon Europe (Middle East and Africa)
Leroy Stanford, Director of Cyber Security, Ocado Technology

  • For years, cybersecurity has been framed as a capacity challenge: more threats, more alerts, more tools, and never enough people or budget. But what if the real constraint isn't capacity at all? What if organisations are failing to get the most from the people, platforms, and data they already have?
  • Are security teams truly capacity constrained, or is operational inefficiency the bigger barrier to improving cyber resilience?
  • Where is the greatest source of inefficiency today—people, processes, technology, or fragmented data?
  • How should organisations measure efficiency in cyber defence, and what metrics best demonstrate a meaningful reduction in cyber risk?
  • If you had one strategic investment over the next three years, would you prioritise increasing capacity or improving efficiency—and why?

►The New Security Baseline: People, Platforms and Priorities

Simon Brady, AKJ Associates (Moderator)
Katie Wood, Information Security Architect, Bibby Financial Services Limited
Soraya Viloria Montes de Oca, Group Information Security Officer, Harvey Nichols
Raam Ratnam, Managing Director, EMEA Corporate Ratings, London, S&P Global
Wisdom Aveh, Head of Information Security & Data Protection Officer, Kurt Geiger

  • Which cybersecurity capabilities must organisations retain in-house, and which can be safely outsourced or automated without undermining resilience?
  • What does a minimum viable security technology stack look like in 2026, and which tools, controls, and processes no longer justify the operational burden they create?
  • What framework should CISOs use to decide which risks to mitigate, transfer, automate, or formally accept when security demand exceeds available capacity?

►Empowering Cyber Defence: Fighting Against The AI Bot Threat

Tim Ayling, Vice President -  Cyber Solutions Specialists, Thales

  • Artificial Intelligence is revolutionizing the cybersecurity landscape, enabling organizations to detect threats faster, respond to incidents more effectively, and stay one step ahead of adversaries. 
  • Join Thales for an in-depth exploration of how AI solutions are shaping the future of cyber defence. 
  • Our experts will examine real-world examples, highlight the benefits and challenges of integrating AI into existing security ecosystems, and showcase the latest AI advancements from Thales that deliver enhanced threat detection and automated response. 
  • Learn how you can leverage AI to proactively secure your organization’s digital assets and adapt to the rapidly evolving threat landscape. 
  • This interactive session will provide valuable insights for cybersecurity leaders, IT professionals, and anyone interested in building AI-powered resilience.

►Meet Your Rogue Agents

Scott Shields, Enterprise Sales Engineer, Delinea

  • Every headline AI agent incident this year shares the same root cause: the database deleted in nine seconds, the outage from an agent left to "fix" its own problem, the AI that kept finding new ways to act after being shut down.  Nothing was hacked. Nothing broke. Every action was taken with credentials the agent was, technically, allowed to use. 
  • The uncomfortable truth for security leaders is not that agents might go rogue, its recognising they are rouge by design without appropriate controls.  
  • This reframes agentic AI as an identity and access problem, not a model-safety one. 
  • This session will cover some real world learnings from the field and offer some practical insights to help you securely prepare for the agentic era.

Education seminars


From the Front Lines: A Five-Time CISO's 5 Lessons — and How AI Rewrites the Rules


Niall Browne, CEO and Co-Founder, AIBound

Niall Browne — five-time Global CISO (Palo Alto Networks, Workday) turned AI security founder and CEO of AIBound — has spent his career in the trenches, protecting the world's most critical enterprise infrastructure and partnering with law enforcement on cyber threats. Now he distills the five hard-won lessons from thousands of real-world industry security incidents that separate resilient organizations from the breached — and confronts how AI rewrites the rules: attacks that are faster, smarter, stealthier, no longer bound by scale, and able to exploit zero-days across many targets at once. A rare view from someone who has both defended Fortune 500 infrastructure and built AI security from the ground up.


When the attacker is an AI Agent


Ian Dutton, EMEA Sales Engineering Lead, LMNTRIX

AI Agents have become the new cyber attackers. AI used to be a productivity tool which the human adversary operated, phishing became better, malware was easily created, reconnaissance was summarised and social engineering scripts were produced. Now the roles have reversed, AI which used to advise the human has now become the operator, carrying out real end to end intrusions at machine speed with minimal human input.

Attendees will learn:

  • How AI-powered attacks are evolving.
  • What real campaigns look like.
  • Real-world examples of AI agents in action over the last 12 months.
  • How to effectively detect, investigate and contain these threats.

Built, Deployed, Compliant: How to Map Your AI and Avoid Regulatory Fines


Bradley Bosher, Manager of Sales Engineering, Varonis

As AI adoption accelerates across every part of the business, compliance teams are facing increased pressure to understand where AI is being used, what data it can access, and how to meet evolving regulatory requirements. With the EU AI Act and other global AI regulations taking effect, organizations need a clear view of both sanctioned and shadow AI to reduce risk and demonstrate compliance. Join this session to learn how to discover, assess, and govern AI across your environment with confidence.

Attendees will learn: 

  • The latest EU AI Act requirements and key compliance deadlines organizations need to prepare for.
  • How to uncover sanctioned, custom-built, and shadow AI applications across your organization.
  • Practical ways to identify AI-related risks and generate the evidence needed for regulatory compliance.
  • Why a strong, consistent data security strategy is the foundation for secure and compliant AI adoption.

You Don’t Need More Security Tools. You Need More Control.


Rob Gupta, Founder and CEO, ConnectProtect

Security teams are under more pressure than ever: threats are increasing, budgets and resources are stretched, compliance expectations are growing, and organisations are managing an increasingly complex mix of tools, alerts and systems.

Adding more technology doesn’t necessarily create more control, it can create more complexity.

This session explores a smarter, more practical approach to security: getting greater value from the tools and investments you already have, reducing operational pressure, and creating a clearer, more manageable security model.

Attendees will learn:

  • Why security complexity keeps growing and how disconnected tools, limited resources and increasing accountability can make risk harder to manage.
  • How to get more from your existing security investments by bringing data together, correlating and prioritising threats, and combining automation, AI and human expertise.
  • How to move from reactive to proactive security, with 24x7x365 monitoring and hands-on support that helps take pressure away from internal technical teams.
  • How to make security value more visible to the business, including demonstrating ROI, supporting compliance and creating more predictable security costs.

Humans Are the Weakest Link? Think again


Etay Maor, VP Threat Intelligence and Founding Member of Cato CTRL, Cato Networks
 
Cybersecurity has long treated humans as the weakest link - people make mistakes, are easy to socially engineer, are slow to change behaviour, and pose insider-threat risk. In this session, Etay Maor (VP of Threat Intelligence at Cato Networks and founding member of Cato CTRL) argues those same four weaknesses now apply to AI and AI agents - making AI the new weakest link in the enterprise. Drawing on real attacks, live demonstrations, and intelligence gathered from dark web and criminal forums, he shows how attackers are weaponising AI systems and agents, exposing risks most security teams can't yet see.
 
Attendees will learn:
  • The "weakest link" framing is shifting: the same reasons humans were called insecure now describe the risks AI agents introduce into the enterprise
  • Live demonstrations of real attacks and exploitation techniques against AI agents - not just theory 
  • Intelligence straight from the dark web and criminal forums on how threat actors are actually talking about and using AI
  • "Shadow AI" is already inside most organisations - employees unknowingly leak confidential data into public AI tools, and security teams often have no visibility into it
  • A challenge to rethink current AI agent security approaches, with practical implications for how enterprises should govern and monitor agentic AI use

AI Agents are the Ultimate Insiders: Securing AI and the Humans Behind It


Mimecast

Over a billion AI agents will operate inside enterprises by 2029, acting for every employee: accessing data, executing tasks, and making decisions. The agent is no longer a tool used by an insider — it has become the insider. The same agent, deployed by two different people, isn't the same risk. This session reframes agentic AI as an insider problem, covering ways to manage this risk: attributing each agent to its human, and securing both as one.