Agenda

Presentations already confirmed include:


►Fireside Chat: Cybersecurity at a Tipping Point — The Future of the Security Stack

Simon Brady, Event Chairman (Moderator)
Ulf Larsson, Security CTO, SEB

  • AI and the widening vendor gap: Are the largest security platforms pulling away, and can smaller vendors keep pace with the speed and investment AI demands?
  • Rethinking the security stack: Are banks and large organisations moving from best-of-breed point solutions towards fewer, broader platforms? Are we at a genuine tipping point?
  • How large organisations buy security technology today: What matters when evaluating new technology: innovation, integration, resilience, cost and vendor longevity?
  • What wins next: In an AI-driven world, where will specialist vendors still have an edge, and what will the security stack of the future look like?

►Panel Discussion: The Corporate Security Case for AI Sovereignty

Simon Brady, Event Chairman (Moderator)
Laurits Ketscher, Data Protection Officer, Danish Ministry of Finance

  • Your AI runs on someone else's infrastructure, under someone else's law — is that a security risk your board has signed off on?
  • Do you actually know which AI models are running inside your organisation — and do you control what data they see and send out?
  • NIS2, the AI Act, and GDPR each touch AI sovereignty differently — how do you build one coherent security programme when the regulations pull in different directions?
  • If your primary AI vendor became inaccessible tomorrow — through outage, sanctions, or a geopolitical event — how long before your operations fail, and do you have a continuity plan?

►Conformity Will Not Save You: AI Risk Beyond the EU AI Act

Geoffrey Taylor, Information Security Officer, Nordea Asset Management

Your assessment said Low Risk. Is it really?

  • The EU AI Act requires organisations to classify their AI systems and demonstrate conformity. Conformity is similar to compliance — it is binary, a yes or a no at a point in time. It cannot calibrate impact when the unexpected occurs.
  • On 24 April 2026, an AI agent deleted an entire company's production database in nine seconds. It was running the best model available, configured with explicit safety rules. When asked to explain itself, it produced a written confession: "I violated every principle I was given."
  • This session applies the Assume. Design. Test. framework to AI governance — shifting the question from "are we compliant?" to "how could we be impacted?" — and gives attendees a practical lens for assessing where their governance ends and their exposure begins.

►Why Quantum Cryptography Isn’t Really a Technology Problem

Rune Espensen, Head of Information Security Office, Nordea

  • Why quantum computing is a society-wide challenge and how its impact extends far beyond purely technical concerns
  • Learn why preparation must start now and what early actions reduce long-term risk as quantum capabilities advance
  • Discover why technology isn’t the main barrier and what organisational, cultural, and strategic shifts are required to navigate the quantum transition effectively

►Panel Discussion: Beyond Compliance — Building Cyber Resilience That Actually Works

Simon Brady, Event Chairman (Moderator)
Jan Jans, Legal Counsel, Finanstilsynet (Danish Financial Supervisory Authority)

  • How do we turn risk appetite statements into real decision levers instead of paperwork?
  • With NIS2 and similar rules, what does “appropriate and proportionate” really mean on the ground — and how can risk management steer the response?
  • Which cyber metrics really matter — and how do we prove our risk posture to the Board, to clients, and across the entire supply chain, right down to nth-party dependencies?
  • How does a resilience-first mindset transform culture — moving from blame and unrealistic prevention to readiness, adaptability, and fast recovery?

►Utilise your Threat Intelligence to Improve your Security Posture, Continuously!

Magnus Lundgren, Sales Director Nordics, Filigran

  •  How good is your cyber defense? How do you know?
  • Could you measure this and bring Threat Intel and Detection teams closer?
  • Centralize threat intelligence from OSINT, feeds, and internal detections into one correlated view of the threats that matter to you
  • Convert that intelligence into adversary emulation scenarios and test against the TTPs.
  • Validate detection and response controls continuously against real attack techniques
  • Put Threat Intel and Detection teams on the same workflow Nemeth
     

Education seminars


See it, Control it, Trust it: Mastering Context in a Cloud-First World


Lars Liljeroth, Solutions Engineer, Netskope

The perimeter is dead, but your data is more active than ever. As organizations sprint toward SaaS and AI-native workflows, the security "blind spot" isn’t just growing—it’s becoming the new infrastructure. True Zero Trust isn't about rigid boundaries; it’s about contextual intelligence. Drawing from Netskope's unique vantage point across billions of global cloud transactions, this session explores why traditional controls fail in the face of autonomous AI agents and complex SaaS ecosystems.

Attendees will learn:

  • The AI/SaaS Reality: Why "Shadow IT" has evolved into a web of autonomous agents and third-party integrations.
  • Context as Currency: How to transform static policies into real-time, data-aware security.
  • Risk Intelligence: Identifying the hidden risks within your cloud supply chain before they escalate.