Agenda
Presentations already confirmed include:
►Mythos and Beyond: What the Next Generation of AI Means for Security, Sovereignty, and Business
Rob Flanders, Head of Threat and Incident Response, BAE Systems
- The changing AI landscape: the latest advances in AI models, the impact of US export controls, and how policy is shaping global AI development.
- Emerging security challenges: how increasingly capable AI models are changing the cyber threat landscape, including the path towards the much-discussed concept of Recursive Self-Improvement (RSI).
- Implications for the UK and Europe: what a US-centric AI ecosystem means for competitiveness, sovereignty, and the capabilities organisations will need to succeed.
►Fireside Chat: Capacity or Efficiency – What's the Real Issue in Cyber Defence?
Simon Brady, Event Chairman (Moderator)
Quentyn Taylor, Senior Director – Product, Information Security and Global Incident Response, Canon Europe (Middle East and Africa)
Leroy Stanford, Director of Cyber Security, Ocado Technology
- For years, cybersecurity has been framed as a capacity challenge: more threats, more alerts, more tools, and never enough people or budget. But what if the real constraint isn't capacity at all? What if organisations are failing to get the most from the people, platforms, and data they already have?
- Are security teams truly capacity constrained, or is operational inefficiency the bigger barrier to improving cyber resilience?
- Where is the greatest source of inefficiency today—people, processes, technology, or fragmented data?
- How should organisations measure efficiency in cyber defence, and what metrics best demonstrate a meaningful reduction in cyber risk?
- If you had one strategic investment over the next three years, would you prioritise increasing capacity or improving efficiency—and why?
►AI in the Middle : Basic security considerations in multi-model/agentic architectures
Ben Trethowan, CISO, Brit Insurance
- Identifying the need to perform effective supply chain security assessments upon AI providers, including consideration of product/service-level aspects.
- Discussing the importance of effective Non-Human Identity (NHI) management, across user/workload identities, as the role of identity encapsulation/impersonation increases.
- Highlighting the challenges of achieving pervasive security governance and observability across complex AI architectures.
- Appreciating the potential ‘novel’ security threats introduced through AI utilisation.
- Leveraging existing data security approaches to support the extension of data visibility/control into complex AI architectures.
►The New Security Baseline: People, Platforms and Priorities
Simon Brady, AKJ Associates (Moderator)
Katie Wood, Information Security Architect, Bibby Financial Services Limited
Soraya Viloria Montes de Oca, Group Information Security Officer, Harvey Nichols
- Which cybersecurity capabilities must organisations retain in-house, and which can be safely outsourced or automated without undermining resilience?
- What does a minimum viable security technology stack look like in 2026, and which tools, controls, and processes no longer justify the operational burden they create?
- What framework should CISOs use to decide which risks to mitigate, transfer, automate, or formally accept when security demand exceeds available capacity?
Education seminars
From the Front Lines: A Five-Time CISO's 5 Lessons — and How AI Rewrites the Rules
Niall Browne, CEO and Co-Founder, AIBound
Niall Browne — five-time Global CISO (Palo Alto Networks, Workday) turned AI security founder and CEO of AIBound — has spent his career in the trenches, protecting the world's most critical enterprise infrastructure and partnering with law enforcement on cyber threats. Now he distills the five hard-won lessons from thousands of real-world industry security incidents that separate resilient organizations from the breached — and confronts how AI rewrites the rules: attacks that are faster, smarter, stealthier, no longer bound by scale, and able to exploit zero-days across many targets at once. A rare view from someone who has both defended Fortune 500 infrastructure and built AI security from the ground up.
When the attacker is an AI Agent
Ian Dutton, EMEA Sales Engineering Lead, LMNTRIX
AI Agents have become the new cyber attackers. AI used to be a productivity tool which the human adversary operated, phishing became better, malware was easily created, reconnaissance was summarised and social engineering scripts were produced. Now the roles have reversed, AI which used to advise the human has now become the operator, carrying out real end to end intrusions at machine speed with minimal human input.
Attendees will learn:
- How AI-powered attacks are evolving.
- What real campaigns look like.
- Real-world examples of AI agents in action over the last 12 months.
- How to effectively detect, investigate and contain these threats.
Built, Deployed, Compliant: How to Map Your AI and Avoid Regulatory Fines
Bradley Bosher, Manager of Sales Engineering, Varonis
As AI adoption accelerates across every part of the business, compliance teams are facing increased pressure to understand where AI is being used, what data it can access, and how to meet evolving regulatory requirements. With the EU AI Act and other global AI regulations taking effect, organizations need a clear view of both sanctioned and shadow AI to reduce risk and demonstrate compliance. Join this session to learn how to discover, assess, and govern AI across your environment with confidence.
Attendees will learn:
- The latest EU AI Act requirements and key compliance deadlines organizations need to prepare for.
- How to uncover sanctioned, custom-built, and shadow AI applications across your organization.
- Practical ways to identify AI-related risks and generate the evidence needed for regulatory compliance.
- Why a strong, consistent data security strategy is the foundation for secure and compliant AI adoption.