Agenda
| 08:00 - 08:50 |
Breakfast networking and registration |
| 08:50 - 09:00 |
Chairman's Welcome |
| 09:00 - 09:20 |
►Mythos and Beyond: What the Next Generation of AI Means for Security, Sovereignty, and Business Rob Flanders, Head of Threat and Incident Response, BAE Systems
|
| 09:20 - 09:40 |
►Trust, then autonomy: A new framework for evaluating Agentic AI in security Chris Vaughan, Security Engineer, Sublime Security
|
| 09:40 - 10:00 |
►The Six-Hop Debrief: What One Real Breach Teaches Us About Standing Privilege Lee Elliott, Director of Solutions Engineering, BeyondTrust
|
| 10:00 - 10:20 |
►Panel Discussion: Capacity or Efficiency – What's the Real Issue in Cyber Defence? Simon Brady, Event Chairman, Moderator
|
| 10:20 - 11:00 |
► Education Seminar 1 Delegates will be able to choose from a range of topics:
|
| 11:00 - 11:30 |
Networking Break |
| 11:30 - 11:50 |
►The Deadline Moved. The Declaration Didn't. Punit Bafna, Head of Cybersecurity & Compliance, Haleon
|
| 11:50 - 12:10 |
►Agentic AI, Business Psychology and the New Resilience Risk Richard Cassidy, International CISO, Rubrik
|
| 12:10 - 12:30 |
►Meet Your Rogue Agents Scott Shields, Enterprise Sales Engineer, Delinea
|
| 12:30 - 12:50 |
►Empowering Cyber Defence: Fighting Against The AI Bot Threat Tim Ayling, Vice President - Cyber Solutions Specialists, Thales
|
| 12:50 - 13:30 |
► Education Seminar 2 Delegates are invited to attend:
|
| 13:30 - 14:30 |
Lunch and Networking |
| 14:30 - 15:00 |
►Fireside Chat: Cybersecurity at a Tipping Point – The Future of the Security Stack Simon Brady, Event Chairman (Moderator)
|
| 15:00 - 15:20 |
►Evolving Security in a Changing Threat Landscape Rob FitzSimons, Sales Engineer, Huntress
|
| 15:20 - 15:40 |
►Anti-Heroes! Why AI Goes Rogue Michael Adjei, Director, Systems Engineering, Illumio
|
| 15:40 - 15:45 |
►Zero Trust Controls at the Endpoint John McNamee, Sales Manager, ThreatLocker
|
| 15:45 - 16:20 |
► Education Seminar 3 Delegates will be able to choose from a range of topics:
|
| 16:20 - 16:40 |
Networking Break |
| 16:40 - 17:10 |
►Panel Discussion: The New Security Baseline: People, Platforms and Priorities Simon Brady, AKJ Associates, Moderator
|
| 17:10 - 17:30 |
►Rise of Autonomous Attacks (Live Mythos-Style Hack) Manit Sahib, Ethical Hacker & Former Head of Penetration Testing & Red Teaming, Bank of England
|
| 17:30 - 17:35 |
Chairman's Closing Remarks |
| 17:35 - 18:30 |
Drinks Reception & Networking, Kindly Sponsored by Vega.io |
Education seminars
From the Front Lines: A Five-Time CISO's 5 Lessons — and How AI Rewrites the Rules
Niall Browne, CEO and Co-Founder, AIBound
Niall Browne — five-time Global CISO (Palo Alto Networks, Workday) turned AI security founder and CEO of AIBound — has spent his career in the trenches, protecting the world's most critical enterprise infrastructure and partnering with law enforcement on cyber threats. Now he distills the five hard-won lessons from thousands of real-world industry security incidents that separate resilient organizations from the breached — and confronts how AI rewrites the rules: attacks that are faster, smarter, stealthier, no longer bound by scale, and able to exploit zero-days across many targets at once. A rare view from someone who has both defended Fortune 500 infrastructure and built AI security from the ground up.
Attendees will learn:
- The top five ways hackers breach organisations today, from a former Palo Alto Networks and Workday CISO with 25 years in security.
- How AI lets attackers move faster and deeper into your systems, and why traditional defences miss AI
- Hard-won lessons from thousands of real-world incidents you can apply now to defend against AI-driven attacks.
When the attacker is an AI Agent
Ian Dutton, EMEA Sales Engineering Lead, LMNTRIX
AI Agents have become the new cyber attackers. AI used to be a productivity tool which the human adversary operated, phishing became better, malware was easily created, reconnaissance was summarised and social engineering scripts were produced. Now the roles have reversed, AI which used to advise the human has now become the operator, carrying out real end to end intrusions at machine speed with minimal human input.
Attendees will learn:
- How AI-powered attacks are evolving.
- What real campaigns look like.
- Real-world examples of AI agents in action over the last 12 months.
- How to effectively detect, investigate and contain these threats.
Built, Deployed, Compliant: How to Map Your AI and Avoid Regulatory Fines
Andrew Dreier, Manager of Sales Engineering, Varonis
As AI adoption accelerates across every part of the business, compliance teams are facing increased pressure to understand where AI is being used, what data it can access, and how to meet evolving regulatory requirements. With the EU AI Act and other global AI regulations taking effect, organizations need a clear view of both sanctioned and shadow AI to reduce risk and demonstrate compliance. Join this session to learn how to discover, assess, and govern AI across your environment with confidence.
Attendees will learn:
- The latest EU AI Act requirements and key compliance deadlines organizations need to prepare for.
- How to uncover sanctioned, custom-built, and shadow AI applications across your organization.
- Practical ways to identify AI-related risks and generate the evidence needed for regulatory compliance.
- Why a strong, consistent data security strategy is the foundation for secure and compliant AI adoption.
You Don’t Need More Security Tools. You Need More Control.
Rob Gupta, Founder and CEO, ConnectProtect
Security teams are under more pressure than ever: threats are increasing, budgets and resources are stretched, compliance expectations are growing, and organisations are managing an increasingly complex mix of tools, alerts and systems.
Adding more technology doesn’t necessarily create more control, it can create more complexity.
This session explores a smarter, more practical approach to security: getting greater value from the tools and investments you already have, reducing operational pressure, and creating a clearer, more manageable security model.
Attendees will learn:
- Why security complexity keeps growing and how disconnected tools, limited resources and increasing accountability can make risk harder to manage.
- How to get more from your existing security investments by bringing data together, correlating and prioritising threats, and combining automation, AI and human expertise.
- How to move from reactive to proactive security, with 24x7x365 monitoring and hands-on support that helps take pressure away from internal technical teams.
- How to make security value more visible to the business, including demonstrating ROI, supporting compliance and creating more predictable security costs.
Humans Are the Weakest Link? Think again
- The "weakest link" framing is shifting: the same reasons humans were called insecure now describe the risks AI agents introduce into the enterprise
- Live demonstrations of real attacks and exploitation techniques against AI agents - not just theory
- Intelligence straight from the dark web and criminal forums on how threat actors are actually talking about and using AI
- "Shadow AI" is already inside most organisations - employees unknowingly leak confidential data into public AI tools, and security teams often have no visibility into it
- A challenge to rethink current AI agent security approaches, with practical implications for how enterprises should govern and monitor agentic AI use
AI Agents are the Ultimate Insiders: Securing AI and the Humans Behind It
Alexander Decarne, Sr Product Marketing Manager, Threat Protection, Mimecast
Over a billion AI agents will operate inside enterprises by 2029, acting for every employee: accessing data, executing tasks, and making decisions. The agent is no longer a tool used by an insider — it has become the insider. The same agent, deployed by two different people, isn't the same risk. This session reframes agentic AI as an insider problem, covering ways to manage this risk: attributing each agent to its human, and securing both as one.
Attendees will learn:
- Why AI agents should be treated as an emerging insider risk.
- How the same AI agent can pose different risks depending on who deploys it.
- How to secure the human and their AI agent as a single identity.
Inside the Inbox: Anatomy of an Email Attack
Chris Vaughan, Security Engineer, Sublime Security
Ed Maunders, Security Solutions Engineer, Sublime Security
Join Sublime for a live walkthrough of a real life attack discovery, the reasoning behind the verdict, and detections deployed in response.
You'll see Sublime's AI agents, ASA (Autonomous Security Analyst) and ADÉ (Autonomous Detection Engineer) in real time, doing what they are designed and deployed to do: how ASA triages user reported email end-to-end, and how ADÉ generates and deploys a new, org-specific detection in response to a real threat.
Attendees will learn:
- See a live walkthrough of Sublime's operational experience
- How ASA triages user reported email end-to-end
- How ADÉ generates and deploys new, org-specific detections in response to new threats
- There is an open Q&A, bring your hardest example
Million Dollar Conversation: What happens when the criminal isn't breaking into the conversation, they're already in it?
John Mc Loughlin, Group CEO, J2 Software
In this 30-minute session, John Mc Loughlin, Group CEO of J2 Software, will take the audience inside two real-world attacks where criminals quietly inserted themselves into legitimate business conversations that cost the businesses millions.
This is a story of deception, impersonation and massive losses. John will show how thinking you are safe with security tools can hurt you. The story will unpack a crypto loss of $1.6 Million in one case and $4 million and personal losses for directors in the second. The criminals were talking to both parties, and nobody knew until after the money was gone.
Attendees will learn:
- John will reveal how the attacks unfolded, the missed opportunities that could have exposed the criminals earlier, and how even two legal firms conducting due diligence in the second case were themselves deceived.
- This is not a session about another security service. This is about trust, identity, human behaviour, visibility and what happens when criminals become an invisible participant in a legitimate business conversation.
- Who is really in your next million-dollar conversation?
Key findings from The Annual Cybersecurity Attitudes and Behaviours Report 2025/26
James Beary, Sales Director, CybSafe
Join us for a review of the key findings of the latest (sixth, to be exact) 'Oh, Behave!' report.
Attendees will learn:
- Global snapshot: We'll present a global snapshot of people's cybersecurity attitudes and behaviours.
- Mindsets & motivations: What do people really think about cybersecurity, and what keeps them up at night? We'll explore who they rely on for protection and where they place the responsibility.
- The AI challenge: AI use has exploded, but training hasn't. People are more confident, but also more vulnerable. In a world of shadow AI and deepfake scams, we'll discuss how to bridge the knowing-doing gap.
Own, Outsource, Automate, Eliminate: A Framework for a successful Passwordless Implementation
Marta Góral, Head of Partner Sales, UK&I, OneSpan
John Gilbert, Director, Red Lodge Consulting Ltd
Security leaders are increasingly being made aware that they can't own everything, without unlimited resources, they have to make hard capacity calls. Passwordless authentication is a perfect example; everyone agrees FIDO2 is now mandatory, but nobody has the internal capacity to run hardware logistics, credential lifecycle, and recovery workflows at enterprise scale. That's not a technology gap, it's an operational capacity gap and it's exactly the kind of thing the eCrime Summit's own framework says should be outsourced.
Attendees will learn:
- In this session we will examine what must we own, what can we safely outsource, what should be automated, and what should we stop doing in relation to deploying phishing resistant authentication in the enterprise.
- We'll highlight how OneSpan's FIDO + CMS platform delivers the security outcome (AAL3, phishing-resistant), Digipass as a Service delivers the capacity outcome (fully managed, so the CISO's team never has to build or staff for it) and how together, they let a CISO check the box marked “delivered” rather than “in progress”.
From Secure Email to Brand Recognition with BIMI
Faisal Misle, Senior Lead Engineer, Customer Success, Red Sift
A brand’s logo in the inbox is one of the first trust signals for a recipient. In this seminar, Red Sift breaks down Brand Indicators for Message Identification (BIMI), what it is, the authentication protocols behind it, and how AI shortens the path.
BIMI displays your verified logo on authenticated email, but it isn't something you just switch on. SPF, DKIM and DMARC need to be working together first, and a single weak link can hold the whole thing back.
Attendees will learn:
- The impact of BIMI and why it's a mark of trust
- How SPF, DKIM and DMARC interact as the foundation
- What happens when one of those protocols breaks
- The steps to adopting BIMI, simplified
Smaller Surfaces. Smaller Spend. Controlled Agents. Controlled Runtimes
Richard Meeus, Senior Director Security Technology and Strategy, EMEA, Akamai
This session will explore strategic ways to optimise your defences for rapid financial return, with the potential to achieve full payback in as little as six months. Discover how reducing your attack surface can strengthen security while lowering costs. You’ll also learn how modern Microsegmentation can enable more controlled agent and runtime deployment, isolating critical workloads to contain breaches faster and accelerate incident response.
Attendees will learn:
- Smaller surfaces, smaller spend. Discover how reducing your attack surface doesn’t require bigger budgets but actually lowers them. In this session, you’ll learn practical, proven ways to strengthen your security posture while actively cutting costs.
- Rapid financial return. Learn how optimizing your defenses can yield maximum economic efficiency, giving your organization the potential to see a full payback on your security investment in as little as six months.
- Controlled agent and runtime deployment. Explore how modern microsegmentation isolates critical workloads and applications to contain breaches faster and accelerate incident response times.
The Agentic Enterprise: Securing Humans, Data, and AI
Alistair Mills, Director, Sales Engineering, Proofpoint
The Agentic Enterprise: Securing Humans, Data, and AI explores how the rapid adoption of AI tools and autonomous agents is reshaping the enterprise security landscape. As humans and AI increasingly work side by side, agents are gaining access to sensitive data, systems and business processes with privileges approaching those of employees—but often without equivalent oversight. The session examines three emerging risk vectors: AI-generated threats that make attacks cheaper and easier to scale, over-privileged AI that can expose sensitive enterprise data, and runtime risk when autonomous agents act beyond intended boundaries. It then outlines a unified approach to securing the “agentic workspace,” bringing collaboration, data and AI security together rather than treating them as separate problems.
Attendees will learn:
- Control what AI can access and reuse. Apply least-privilege principles to AI by default and understand what sensitive data existing tools and agents can already reach.
- Treat email, collaboration and AI as one attack surface. AI is accelerating familiar threats and allowing attacks to move across channels, making connected detection and protection increasingly important.
- Treat every AI agent like an insider. Agents need clearly defined identities, permissions, behavioural boundaries and accountability—just as employees do.
- Start with visibility and audit ability. Organisations should know which AI tools and agents are operating, who approved them, what data they can access and whether their actions can be reconstructed through an audit trail.