KEY TOPICS TO EXPLORE
A Look Through ESET Research: The Shock of Artificial Intelligence’s Impact and How to Adapt to It
We are living in a time when artificial intelligence is intersecting with almost everything humanity has built in modern history, including cybersecurity. In this lecture, we will take a closer look at how blind trust in artificial intelligence and a strong focus on rapid deployment of new solutions can create a new attack surface that cybercriminals can effectively exploit. We will also present real-world data that helps temper the often exaggerated debate about the impact of AI on modern cyber threats. These findings show that generative AI is currently used mostly for fraud, scams, phishing, and disinformation campaigns, and significantly less for the development of novel attack techniques or breakthrough malicious software, as many have predicted. Based on concrete examples from ESET’s research and development, as well as valuable practical experience, we will demonstrate why only an approach to artificial intelligence grounded in experimentation, rigorous testing, and human expertise can move us away from worst-case scenarios and ensure that technology delivers more benefits than risks.
A New Generation of Cybersecurity and Digital Risk Management Requirements
The field of cybersecurity is facing one of the biggest changes in recent years. While organizations have traditionally based their compliance and risk management primarily on established standards such as ISO/IEC 27001, new regulatory requirements and technological developments are significantly expanding the scope of organizations’ responsibilities and the expectations placed upon them.
The rise of artificial intelligence, the increasing interconnectedness of digital products, and growing dependence on supply chains are raising new questions regarding risk management, manufacturer liability, ensuring security throughout the entire product lifecycle, and demonstrating compliance. The ISO/IEC 42001 standard introduces the first systematic framework for managing artificial intelligence systems, while the Cyber Resilience Act (CRA) sets new requirements for manufacturers and suppliers of digital products in the European market.
These changes affect not only technical solutions but are also increasingly impacting the areas of management, oversight, employee competencies, and accountability. Organizations will need to establish appropriate processes, ensure independent verification of security requirements, develop new competencies, and ensure that management and technical functions are capable of effectively managing the increasingly complex requirements in the areas of cybersecurity, artificial intelligence, and digital resilience.
AI Adoption and Security: How Delinea Shields Customers from Emerging AI Threats
„AI has compressed attack timelines from weeks to minutes, automating up to 90% of tactical attack work. Meanwhile, Non-Human Identities — service accounts, API keys, AI agents — are proliferating uncontrolled, with organizations averaging 52 NHIs per human employee, most with no visibility or governance in place.
Static trust models compound the risk: temporary access averaging 30 days is rarely revoked, while AI agents operate 24/7 at machine speed, making traditional access policies obsolete.
The broader challenge is one of scale: yesterday's identity management handled tens of thousands of human accounts; tomorrow's world of autonomous agents will demand governance over millions of machine identities and trillions of access decisions — a complexity most organizations are entirely unprepared for. Join my session to discover how Delinea helps organizations visualize and take control of AI-driven cybersecurity risks
Autonomous AI for Offensive Cybersecurity: The Next Generation of AI-Driven Exploit Development
Artificial Intelligence is transforming offensive cybersecurity from an assistant into an autonomous developer of offensive capabilities. Multi-agent AI systems can autonomously generate, test, validate, and continuously improve cybersecurity tools and exploits with minimal human intervention, dramatically accelerating adaptation to new vulnerabilities. By combining multiple specialised AI models that collaboratively review and refine each other's work, these platforms achieve greater reliability and autonomy than a single model alone. This vision is being implemented by INFRA and Haxor within the European Union-funded VANTAGE project, which is developing a multi-agent AI platform for the autonomous generation and evolution of offensive cybersecurity capabilities.
Autonomous Security Patch Management
Unpatched vulnerabilities remain one of the most common causes of successful cyberattacks. As organizations manage an ever-growing number of systems, applications, and security alerts, timely patch deployment has become an increasingly complex operational challenge. Modern vulnerability management approaches therefore go beyond manual processes, leveraging automation and autonomous decision-making to identify, prioritize, and deploy security patches. This enables organizations to reduce their exposure to critical vulnerabilities, improve compliance, and relieve the workload of IT teams. In this session, we will demonstrate how autonomous security patch management can establish a more efficient vulnerability management process, explore the technologies available today, and show how organizations can significantly reduce the time between vulnerability detection and remediation, ultimately strengthening their overall cyber resilience.
Battle of the Machines: Why Automated Response Is the Only Defense Against Modern Cyber Threats
In an era where attackers leverage artificial intelligence, automated scripts, and highly sophisticated attack propagation techniques, traditional Security Operations Centers (SOCs) that rely primarily on manual response are increasingly struggling to keep pace.
Today, the time between an initial breach and the resulting damage is no longer measured in hours but in seconds—or even milliseconds—making human-only response insufficient. This session will explore why automated and intelligent incident response is becoming a critical pillar of modern cyber defense.
We will demonstrate how organizations can leverage advanced analytics, automation, and artificial intelligence to detect attacks faster, reduce response times, and better protect their digital environments against increasingly automated cyber threats.
Beyond Cybersecurity: Who Owns the Decision?
Cybersecurity has traditionally focused on protecting systems, identities, and data from compromise. Yet as AI, automation, cloud platforms, and globally interconnected infrastructures become foundational to how organizations operate, a new question is emerging:
Who owns the decision?
Drawing inspiration from the themes and discussions emerging from Black Hat and DEF CON 2026, this presentation explores how the security conversation is evolving from defending systems to defending decision-making. As attack costs fall, trust becomes programmable, and agency is increasingly delegated to machines, digital resilience and digital sovereignty are becoming inseparable.
Through examples ranging from agentic security and identity trust chains to undersea cables, semiconductor supply chains, energy dependencies, and access to AI compute, the session examines how hidden dependencies shape our ability to operate, adapt, and ultimately choose our own course of action.
Rather than focusing on vulnerabilities alone, the presentation challenges the audience to think about resilience, sovereignty, and agency in a world where critical capabilities increasingly depend on ecosystems we do not fully control.
Attendees will leave with a new perspective on security, and perhaps a deeper question:
Can we still exercise agency when our infrastructure, intelligence, energy, manufacturing, and decision-making increasingly depend on others?
Chasing the Holy Grail: Secure Supply Chains and the Path to Near-Zero CVEs
During the presentation, Artur will demonstrate how to create a secure application build and automate the deployment process. He will demonstrate methods for verifying the origin of individual components and show which image sources should be used when building applications. He will also introduce the concept of near-zero CVE images.
CLOSING KEYNOTE: Beyond the Horizon: Aviation, Entrepreneurship, Safety and the Future of AI
Edwin Brenninkmeyer will draw parallels between the worlds of aviation and entrepreneurship, exploring what business leaders can learn from the mindset and practices of pilots. Drawing on his own experience, he will highlight the importance of thorough preparation, effective execution, and post-flight debriefing, and show how these principles can also be applied to running a business. He will place particular emphasis on company culture, ethical business practices, and understanding the purpose of business, demonstrating how the right culture can become a powerful competitive advantage. Edwin will complement his entrepreneurial insights with stories from his aviation career, including flying air displays and piloting a wide range of aircraft – from vintage biplanes to former military fast jets.
Cloudy with a Chance of Clear Decisions
How Microsoft Fabric connects data, simplifies analytics, and helps companies get to the right insights faster.
Cyber Recovery by Design: PowerStore, DataDomain and AirGap
How can you build a comprehensive and effective cyber recovery strategy? This presentation demonstrates how PowerStore primary storage, a Data Domain backup appliance, and an Air Gap solution work together to create an end-to-end approach for protecting primary workloads, securely storing immutable backup copies, and enabling an isolated clean recovery scenario in the event of a cyberattack. The focus is on the practical integration of the storage, security, and recovery layers, with an emphasis on reducing complexity and accelerating the return to a secure and fully operational state.
Cybersecurity MADE IN EUROPE: How the Axence nVision Unified Platform Enhances IT Visibility, Security, and Operational Efficiency
European regulations and increasingly demanding cybersecurity requirements require organisations to gain better visibility into their IT environments, manage assets effectively, and respond to security incidents more quickly. How can these challenges be addressed with a unified solution?
The presentation will introduce Axence nVision, a European platform for comprehensive IT environment management and protection. It combines IT asset management, network monitoring, remote administration, user support, and security event monitoring.
Through practical examples, we will demonstrate how organisations can improve visibility, strengthen security, simplify IT management, and more easily meet regulatory and business requirements.
Cybersecurity of a Digitalized Power Grid: Monitoring and Control of the Process Environment in a Distribution Substation
The electrical power grid has become a key building block in the functioning of modern society. The integration of smart grid devices has changed the dynamics of power system operations. The digitalization of OT systems in today’s volatile world introduces an increased risk of cyber incidents. Practice shows that architecture and the deployment of high-quality equipment alone are not sufficient. To ensure high standards of reliability and availability in power grid management, we need tools capable of detecting anomalies in OT system operation. For this purpose, Omicron has developed the StationGuard/GridOps solution, which enables monitoring of correct system behavior and detection of cyber threats across the entire critical infrastructure ecosystem. Unlike traditional IDS solutions, Omicron’s StationGuard is based on an in-depth understanding of the dynamics of power OT ecosystems. This enables rapid implementation, a short learning curve, and a minimal number of false positives. Centralized management and vulnerability detection are carried out via the GridOps application. A pilot project in a real power grid environment will be presented.
December 2026: Two Deadlines, One Common Story
December 2026 will be a pivotal month for digital business, with two deadlines arising from entirely different legislative frameworks that nevertheless converge on the same issues in practice. Under eIDAS 2.0, Member States must provide at least one European Digital Identity Wallet by 24 December. Under ZInfV-1, essential and important entities, as well as their suppliers, must implement risk-management measures by 19 December, including multi-factor authentication and the preferential use of qualified trust services.
The presentation will explore how this regulatory interplay should be addressed in practice, while also considering the relevant requirements of the GDPR and ZVOP-2.
Elastic is not just a SIEM. And that’s exactly why it’s such a powerful SIEM.
In 2025, SI-CERT handled 6,196 incidents, 35% more than the year before. Attacks do not distinguish between identities, endpoints, applications, and networks.
Elastic Security is not powerful simply because it offers excellent capabilities for detecting security incidents. Its real strength lies in connecting security with logs, metrics, APM traces, and other data that organizations already collect.
Through a practical example, we will demonstrate how the same data can be used to detect incidents and anomalies with the help of machine learning, while also providing broader context and enabling faster investigations with an AI assistant.
The goal is not to create yet another dashboard, but to give analysts the shortest possible path from an alert to a verifiable answer—precisely when time is most critical.
Every Log Entry Has Two Costs
We all know the first cost: data ingestion, processing, and storage. We pay it monthly or annually for every log record, and we can quantify it in euros. The second cost is rarely calculated—the opportunity cost of a log record that is missing when an incident occurs. The first cost is usually significant but predictable. The second is often high and uncertain, which is precisely why, in practice, decisions tend to focus only on the first.
In this presentation, you will learn methods that enable informed decision-making: how to measure the cost of each data source and assess its value for both detection and investigation, how to classify sources according to these two costs, and how to prioritise optimisation efforts so that savings do not create blind spots in your visibility.
Everyone claims AI for security, but what about security for AI? A sober view on reducing the risk on a hyped new attack surface.
As organizations rapidly move AI initiatives from experimentation to real-world deployment, new risks emerge across security, governance, and operational resilience. AI doesn't just introduce new threats, it exposes how much of our security thinking was built for a world that no longer exists. We'll touch on AI in sec tools, but we'll go more deeply into sec tools for AI and explore the evolving threat landscape surrounding production AI systems from data poisoning, prompt injection, and model abuse to supply-chain vulnerabilities and governance challenges.
Forget Penetration Testing: Agentic CTEM Works 24/7
An annual penetration test was once the standard. Today, that is no longer enough—attackers do not wait for your next patching cycle. In this session, we will demonstrate how agentic CTEM (Continuous Threat Exposure Management) replaces traditional penetration testing with autonomous, continuous vulnerability discovery and validation.
You will learn how autonomous agents can work on behalf of your team—around the clock, independently, and without human error—and how to implement this approach within your organization.
Four Years After the High-Profile Cyberattack on the Administration of the Republic of Slovenia for Civil Protection and Disaster Relief
In August 2022, the Administration of the Republic of Slovenia for Civil Protection and Disaster Relief was the target of a cyberattack that received widespread media attention. Four years later, it is time to reveal what really happened, how the incident was portrayed in the media, what lessons were learned in its aftermath, and how the organization recovered from the attack.
The incident marked the beginning of a series of cyberattacks targeting numerous public institutions and private organizations, making it particularly valuable to compare these events and identify recurring patterns. Since then, the NIS2 Directive has introduced a range of new requirements and measures intended to strengthen cybersecurity and reduce the likelihood of such incidents.
However, security measures documented on paper—even when supported by comprehensive and well-designed policies—are not enough on their own. The key question remains: how can organizations genuinely improve their cybersecurity posture and ensure that security measures are effective in practice?
From ChatGPT to ISO/IEC 42001: How to Build a Secure AI Environment.
Generative artificial intelligence is no longer limited to ChatGPT. Today, it is embedded in Microsoft 365, ERP and CRM systems, development environments, SIEM and XDR platforms, firewalls, and numerous business applications. As a result, most organisations are already using AI—often without clear visibility, policies, or governance.
In this presentation, we will show how AI is changing the attack surface, what new risks are introduced by AI agents, RAG systems, MCP servers, and modern AI assistants, and why traditional security approaches are no longer sufficient.
We will present a practical framework for the secure adoption of artificial intelligence—from creating an inventory of AI solutions and assessing risks to designing AI security architectures, implementing security controls, and establishing AI governance. We will also bring together the requirements of the AI Act, ISO/IEC 42001, ISO/IEC 23894, NIS2, GDPR, the CRA, and other relevant frameworks into a unified governance model.
The presentation is intended for CISOs, security architects, IT managers, and everyone seeking to understand how to build an environment in which artificial intelligence does not represent a new risk, but a trusted business advantage.
From Compliance on Paper to Resilience in Practice: The CISO Between Regulation, Leadership, and Employees
Regulatory requirements, audits, policies, and evidence documentation are an essential part of modern information security governance. However, audit compliance is not the same as cyber resilience. Organizations can fall into a state of “compliance theater,” where processes are formally documented, responsibilities are assigned, and evidence is readily available, while actual security practices remain weakly embedded in employees’ day-to-day work.
This presentation will share the latest findings from the KREPKI research project, conducted across more than 50 Slovenian organizations and involving over 1,500 employees. It will focus on questions that are directly relevant to CISOs: when leadership genuinely supports security and when that support is primarily symbolic; what happens when a CISO carries significant responsibility but lacks the authority to drive change; and why employees often follow security rules more out of oversight and control than out of an understanding of the underlying risks.
The session will also explore practical implications for translating regulatory requirements into processes that strengthen trust, encourage responsible employee behavior, and enhance the organization’s actual cyber resilience.
From Digital Risk to Executive Intelligence: Rethinking Digital Risk Governance in the AI Era
Organizations today face an unprecedented fragmentation of digital risk: cybersecurity threats, AI-related risks, and regulatory requirements such as NIS2, DORA, GDPR, and the AI Act are often managed in silos, resulting in inconsistent reporting, duplicated controls, and limited visibility for executive decision-making.
As a result, CISOs and security leaders are increasingly challenged to translate highly technical and fragmented risk data into meaningful information for Boards and senior leadership, often relying on static dashboards and reactive reporting cycles that fail to reflect real-time risk exposure.
This session introduces an Integrated Digital Risk Governance approach designed to bridge the gap between technical risk data and strategic decision-making. The focus is on how organizations can transform dispersed signals into actionable executive intelligence, enabling Boards to prioritize, act, and allocate resources more effectively.
Through practical insights and patterns observed in digital transformation and compliance programs, the session will outline how to move from fragmented reporting structures to adaptive, intelligence-driven governance models that continuously evolve with the changing digital risk landscape.
The goal is to enable CISOs and security leaders to elevate digital risk from operational reporting to strategic decision support for the executive layer.
From the Unknown to the Controlled: Managing OT Risks in Practice with Nozomi Networks
You cannot effectively protect what you cannot see in industrial environments. Through practical examples, this session will demonstrate how Nozomi Networks enables comprehensive visibility across OT environments, providing detailed insight into devices, communications, and processes within critical infrastructure. The speakers will show how organizations can detect anomalies in real time, identify cyber threats and operational deviations, and proactively manage risks that could impact production systems. Attendees will learn the benefits of continuous OT monitoring, from reducing the attack surface and accelerating incident response to strengthening the overall cyber resilience of their organizations. This presentation will illustrate the journey from limited visibility to a well-monitored, transparent, and secure OT environment.
From Visibility to Protection: A Modern Approach to Data Security with Fortinet Solutions
Today, data is one of an organisation’s most valuable assets, while also being one of the most common targets of cyberattacks. In an era of hybrid work, cloud migration, and the growing use of generative artificial intelligence, protecting sensitive information is becoming increasingly challenging.
In the first part of the presentation, Ivan Krajačić (Fortinet) and Miha Petrač (ADD) will introduce the Fortinet Security Platform and its key security solutions for protecting users, networks, applications, and data. Particular emphasis will be placed on solutions that help organisations meet the requirements of the Slovenian Information Security Act (ZInfV-1) and strengthen their overall cyber resilience.
The second part will focus on Data Loss Prevention (DLP). The speakers will explain how modern DLP solutions enable organisations to discover, classify, and protect sensitive data throughout its entire lifecycle—while it is being transferred, used, and stored. Through practical examples, they will demonstrate how organisations can prevent both accidental and deliberate data leakage, reduce the risks posed by insider threats, and securely adopt generative AI solutions.
GDPR and the "Brussels effect." the most significant cases handled by the Italian data protection authority
Article 3 of the GDPR establishes that the Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing takes place in the Union or not. It also provides that the Regulation also applies, under certain conditions, to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union.
These provisions amplify the so-called "Brussels effect," the attractive force often exerted by EU legislation on other jurisdictions, as they establish specific responsibilities in the event of non-compliance with European personal data protection regulations.
This presentation will illustrate some cases handled by the Italian Authority (the “Garante”) in recent years, highlighting the outcomes these interventions have had in the various cases.
Finally, some considerations will be made on the effectiveness of the aforementioned provisions and the EDPB's action in this regard.
Hacked Without a Click: The Human Exploits Your Firewall Can't Patch
Ninety percent of successful cyberattacks begin not with malicious code, but with a compliant human.
A click. A scan.
A moment of misplaced trust.
The technology to prevent network-level intrusion has never been more sophisticated.
Yet social engineering continues to succeed against technically literate, security-aware professionals who know better. The reason isn't ignorance.
It's human cognition.
Returning to Infosek, Tony Haresign goes deeper into the human attack surface by mapping the cognitive exploits that underpin every social engineering attack and examining precisely why they work against the most security-aware people in the room.
KEY TAKEAWAYS
● Understand the cognitive architecture that makes every person in your organisation exploitable, regardless of their technical competence or security training.
● Learn to identify and name the six cognitive exploits used simultaneously in every social engineering attack.
● Walk away with the innovative C.U.T. method. A practical three step pattern interrupt you can deploy personally and brief to your entire team in under five minutes.
How Artificial Intelligence Is Once Again Transforming the Way Security Operations Centers Operate
Artificial intelligence has long been an integral part of information security. Until now, it has primarily been used in the detection phase of security processes. In many cases, malicious activities could not be detected effectively without it. However, the response phase has so far remained largely untouched by artificial intelligence. Recently, we have been witnessing a new wave of AI adoption in responding to potential malicious activities, giving Security Operations Centres renewed momentum.
How? Join us and find out.
How Organizations Implement Operational Cyber Risk Management in Compliance with NIS2
As organizations across Europe adapt to evolving regulatory requirements such as NIS2 and DORA, cybersecurity leaders are under increasing pressure to translate technical cyber risks into measurable business impact.
Security teams can no longer rely solely on vulnerability counts, maturity scores, or static security assessments. Boards and executive management expect organizations to be able to quantify risk exposure, prioritize investments, and demonstrate how cybersecurity programs reduce operational and financial risk.
In this session, cybersecurity experts from Mastercard will present how organizations can move from a reactive approach to security operations toward intelligent cyber risk management by:
- quantifying cyber risk exposure in financial terms,
- prioritizing risk remediation measures based on their business impact,
- aligning cybersecurity investments with operational resilience objectives,
- strengthening governance and executive decision-making in the context of NIS2 requirements,
- identifying the controls and security improvements that most effectively reduce risk.
Attendees will learn how cyber risk quantification, continuous exposure assessment, and operational resilience strategies can help organizations make more informed security decisions while supporting compliance with increasingly evolving regulatory requirements.
The session is primarily intended for CISOs, risk management leaders, cybersecurity managers and professionals, governance and compliance teams, and professionals responsible for operational resilience.
Humans vs. AI: Automating Security Culture in Practice
With the rise of artificial intelligence, phishing attacks have become highly personalised, convincing, and frequent, meaning that traditional annual training is no longer enough. So, who is winning the battle between offensive AI and human carelessness?
Through practical examples, we will demonstrate how to move from occasional security warnings to a fully automated security culture. You will learn how automated attack simulations and tailored real-time training can transform your employees from the weakest link into the company’s most reliable cyber defence.
Humans vs. AI: Automating Security Culture in Practice
With the rise of artificial intelligence, phishing attacks have become highly personalised, convincing, and frequent, meaning that traditional annual training is no longer enough. So, who is winning the battle between offensive AI and human carelessness?
Through practical examples, we will demonstrate how to move from occasional security warnings to a fully automated security culture. You will learn how automated attack simulations and tailored real-time training can transform your employees from the weakest link into the company’s most reliable cyber defence.
IBM Sovereign Core: Independence Without Compromise in the Age of Artificial Intelligence
Identity – The Foundation of the First and Last Line of Defense
Identity Management (IDM) has become a cornerstone of modern information security, as principles such as least privilege, Zero Trust, and comprehensive auditability cannot be effectively implemented without it. Since identity theft remains the most common attack vector in cyberattacks—and one of the most difficult to detect—IDM has become an essential tool for protecting organizations against misuse, insider threats, and increasingly sophisticated cyberattacks.
The implementation of IDM is also driven by regulatory requirements, including the Slovenian Personal Data Protection Act (ZVOP-2), the Information Security Act (ZInfV-1), and the Digital Operational Resilience Act (DORA), all of which require strict access control, transparency of changes, and demonstrable compliance with security processes. A well-designed IDM solution enables organizations to automate identity-related processes, reduce operational risks, strengthen cyber resilience, and improve transparency in managing the digital identities of employees, partners, and systems.
In this session, we will present Petrol's approach to implementing an IDM solution, covering the key objectives they set, the challenges they encountered, and how they aligned technical requirements with organizational change. We will also share practical implementation examples, highlight best practices, and conclude with a live demonstration.
Identity Under Attack: Detecting and Stopping Credential-Based Threats in Real Time
The theft and misuse of user identities are now among the most common ways attackers bypass traditional security controls. Instead of using malware, attackers increasingly rely on valid accounts, compromised credentials, and legitimate administrative tools to move through an environment undetected.
The presentation will cover the most common identity-based attack techniques, including credential theft, Kerberoasting, Pass-the-Hash, Pass-the-Ticket, lateral movement, and the misuse of privileged accounts. Through practical examples, it will explain how combining network, endpoint, and identity telemetry enables the timely detection of suspicious behaviour and helps stop attacks before they result in a serious system compromise.
IMS – Incident Management System as a Foundation of Modern Security Process Management: From NIS2 Challenges to Optimized Incident Response
We will begin with a brief overview of the current cybersecurity threat landscape, regulatory requirements, and the impact of NIS2, which places additional pressure on security teams and increases the need for automation and more efficient incident management.
This will be followed by a concise presentation of the INTERCEPT project and the key products being developed through this collaborative partnership.
The final part of the presentation will focus on the complete development process of the IMS (Incident Management System) — from identifying user needs and designing the system architecture to implementing its core functionalities. Particular attention will be given to the operational challenges the system addresses, how it simplifies the work of security teams, reduces manual processes, and improves traceability and responsiveness in incident handling. We will also demonstrate where IMS delivers the greatest practical benefits, especially in terms of data centralization and workflow optimization.
INTRODUCTORY SPEECH
INTRODUCTORY SPEECH
Kyborg: An Agentic Framework for SOC Security Analysts
This session will introduce Kyborg, an innovative agentic framework developed by KYBM that transforms large language models into a controlled and reliable tool for Security Operations Centers (SOCs). Designed to support security analysts, Kyborg streamlines incident investigation and response by ingesting incidents from various SIEM platforms and can be dynamically extended through the Model Context Protocol (MCP) to integrate virtually any external tool or data source. Its built-in Retrieval-Augmented Generation (RAG) capability enriches incidents with relevant organizational knowledge from internal documentation while also identifying similar historical incidents and reusing proven response strategies to significantly reduce investigation time. Kyborg analyzes enriched incidents using either public or private large language models, helping analysts understand events more quickly and recommending appropriate response actions. Sensitive operations remain under human control through a human-in-the-loop approval process, ensuring the safe execution of security actions. In addition, analysts can capture recurring workflows as reusable skills, which the framework automatically discovers and applies when handling similar incidents in the future.
Managing the AI Revolution with Zero Trust: From Shadow AI to Secure Deployment
Every organisation is racing to adopt AI—but most are deploying it faster than they can secure it. Cloudflare Solutions Engineer Alexey Konstantinov breaks down the real security challenges of the AI era: shadow AI, protecting the sensitive data AI models touch, securing AI apps and APIs against abuse, and defending against automated AI-driven threats. Through practical examples and a live look at securing AI with Zero Trust—from data loss prevention to AI Gateway—you'll leave with an actionable blueprint for enabling AI without making the wrong kind of headlines.
MORNING EXERCISE
Morning exercise on Friday, 4 September 2026, from 7:30 to 8:00 AM.
We will meet at 7:20 AM in front of Hotel Perla and walk together to the location where the exercise session will take place.
Network Access Control (NAC) as the Foundation of a Zero Trust Architecture
The presentation will focus on the role of Network Access Control (NAC) solutions in modern Zero Trust architectures and compare Aruba ClearPass and Fortinet FortiNAC. It will highlight their key features, strengths, differences, and practical insights gained from real-world implementations at our customers' organizations.
Palo Alto Networks Prisma Access Browser – The Browser as the New Perimeter
In today's digital world, users rely on web browsers as their primary tool for work and everyday tasks. Through the browser, they access business applications such as Salesforce, Microsoft 365, and many others, while also downloading files that may pose potential security risks to the organization. Access to corporate systems is possible from anywhere and on various devices, including BYOD (Bring Your Own Device) environments.
Palo Alto Networks Prisma Access Browser provides advanced security capabilities directly within the web browser, helping organizations prevent web-based attacks, protect against data leakage, and enable secure, controlled access to platforms through both graphical (RDP) and command-line (SSH) interfaces. At the same time, it protects users even when they are operating outside the company's trusted network environment.
Passkeys for Legacy Web Apps: Phishing-Resistant Logins Without Code Change
Many organizations still rely on self-hosted web applications that are critical to daily operations but difficult or risky to modernize. At the same time, they are under pressure to roll out phishing‑resistant authentication, strengthen access controls, and speed up security improvements. In this best-practices session, Michael Wendrowski explains how to add FIDO2 passkey-enabled multi-factor authentication (MFA) in front of existing web applications without changing application source code or rebuilding the login flow, even when the vendor offers no MFA option.
With practical, real-world examples, you will see how to enforce centrally managed MFA, reduce brute-force and credential-stuffing risk, verify user sessions with device fingerprinting, and apply step-up MFA through micro-authorizations for sensitive areas or actions. You will leave with practical guidance on rolling out passkeys with minimal friction and delivering fast, measurable security gains across existing environments.
Perhaps we’re not afraid of what we should be
We often think of artificial intelligence as a technology we need to protect ourselves from—data theft, deepfakes, prompt injection, manipulation and privacy breaches. But what happens when AI does not need to gain access to our data because we willingly give it away ourselves?
AI is becoming increasingly present in our everyday lives. We share personal problems, fears, relationships and information with it that we might sometimes hesitate to disclose even to people we trust. Why do we trust it so much? And what can AI infer about us even when we have never told it directly?
This presentation explores the intersection of trust, psychology, privacy and cybersecurity, and asks how our greatest vulnerability may emerge precisely where we feel safest.
What if AI never needs to break down the biggest doors into our lives—because we open them ourselves?
PHISHSTRIKE – Are Your Employees Ready for AI Phishing?
Generative AI has taken phishing to an entirely new level. Today, attackers can use AI to create highly personalized emails within seconds, imitate the writing style of company executives, generate convincing fake documents, and carry out targeted attacks that are becoming increasingly difficult to detect.
That is why traditional annual employee training is no longer enough.
In this session, we will present the PHISHSTRIKE platform, which enables organizations to continuously measure and improve employees’ security awareness. The platform combines knowledge assessment, advanced phishing simulations, and automated training tailored to each user’s actual level of knowledge.
We will demonstrate how regular testing of employee preparedness can help organizations reduce the risk of successful phishing attacks, improve compliance with NIS2 and ZInfV-1 requirements, and gain measurable indicators of security culture development.
If people were once considered the weakest link, today the greatest threat lies in the combination of people and artificial intelligence. That is precisely why employee awareness and training must become smarter as well.
Protect your Private Cloud with VMware vDefend
VMware vDefend helps protect private cloud environments with integrated, workload-level security designed to reduce attack surfaces, block lateral threats, and support a zero-trust approach across private cloud.
Ransomware Incident Case Study. When the Perimeter Becomes the Door
One unpatched, end-of-life firewall was all it took for a double-extortion crew to compromise an entire maritime network, encrypting files and erasing backups. This session walks through the real incident response, from a breach hidden inside legitimate admin tools to detection by behaviour rather than signatures. Expect practical, sector-relevant lessons on perimeter management, backup resilience, threat intelligence, and why sharing through the Infosek community shortens everyone's response.
Reasons and Limits of Employee Monitoring for Information Security
- Event analysis
- Incident detection
- Network traffic and location monitoring
- Monitoring of access rights and devices
Security at the Core: How Cisco Hypershield Is Transforming Cyber Defense
Modern data centres and cloud environments require a new approach to security—one that operates at lightning speed without placing additional strain on the system. This presentation explores the revolution in kernel-level security enabled by eBPF technology, as well as the role of Isovalent and its Tetragon tool in providing deep visibility into system activity and detecting threats in real time. The main focus will be on Cisco Hypershield, an AI-powered security architecture that brings these eBPF technologies together, enabling autonomous microsegmentation, automatic vulnerability patching without application downtime, and effective prevention of lateral attack movement across modern infrastructure.
Security Fault Lines
Modern organisations invest heavily in securing individual components: hardened endpoints, zero trust networks, patched servers, compliance frameworks, and more. Yet most failures don't begin inside a single system. They emerge at boundaries - where responsibility is unclear, suppliers integrate, IT meets OT, cloud responsibility is shared, and assumptions go untested.
These are the fault lines.
Drawing on systems engineering principles, this talk looks at vulnerabilities not as defects within components, but weaknesses in the interactions between them. Interfaces are politically awkward, technically complex, and frequently unowned. As systems become more interconnected - across organisations, infrastructures, and cyber-physical domains - stress builds at these invisible seems.
Attendees will leave with a practical mental model for identifying hidden fault lines in their own environments, and a clearer understanding of how to secure more than individual components.
Shadow IT was yesterday's challenge. Welcome to the era of Shadow AI.
Generative artificial intelligence has entered everyday business operations faster than security policies can keep up. Employees are using AI tools in their daily work, while traditional security mechanisms such as DLP, proxies, and CASB often fail to detect where data is flowing and what happens to it. The result is a loss of audit trails, unclear accountability, and increased organizational risk. In this session, we will demonstrate why Shadow AI presents a different challenge than Shadow IT, identify where the biggest security gaps emerge, and present a concrete example of a controlled architecture where AI usage runs within an organization’s own infrastructure or data center—ensuring full control over data, users, and compliance.
SRC.SECURE: From SOC to AI Agents – The Next Generation of Cyber Defense
Cyber threats are becoming increasingly sophisticated, as attackers today actively leverage artificial intelligence to rapidly adapt attacks and use global infrastructure to evade detection. As a result, defense must also become faster, more proactive, and technologically advanced.
We address these challenges within the SRC.SECURE services, which combine continuous monitoring and response through our Security Operations Center (SOC), supported by technologies such as XDR, NDR, SIEM, Cyber Threat Intelligence (CTI), honeypots, and other advanced threat detection mechanisms. This is complemented by our in-house developed AI solutions, including agents for penetration testing, language models for security log analysis, and locally deployed models for secure code analysis, where data remains within the client’s environment. For organizations facing a lack of time and resources to establish their own security operations center, we provide SIEM as a managed service, enabling continuous monitoring of security events, faster threat detection, and supporting compliance with the requirements of ZInfV-1 regarding the collection and retention of log data.
Stop trying to Protect Your Exposed Infrastructure. Just Stop Exposing It.
For decades, the cybersecurity industry has been building increasingly sophisticated firewalls, WAFs, EDR platforms, identity services and, more recently, AI-powered threat detection systems. Yet organizations continue to fall victim to the same types of attacks.
Most cyberattacks begin with one simple fact—the attacker can reach the target. Nearly every modern security solution is built on the same assumption: that infrastructure must be publicly reachable. Their job is then to detect the attack and stop it before it's too late.
But what if we challenged that assumption?
This session introduces the concept of Zero Exposure Architecture, where services are not publicly reachable by default but become reachable only after trust has been established. Through real-world attack examples and practical demonstrations, we'll explore how this approach dramatically reduces attack surface, limits exploitability (even 0-day) and offers a fundamentally different way of securing modern infrastructure.
Stopping Fraud Before It Starts: Identity Intelligence Meets Agentic AI
As AI agents, deepfakes, and automated attacks outpace traditional IAM, organisations face a widening identity trust gap. Drawing on Ping Identity’s State of Trust research, this session examines how to move from static authentication to continuous, verified trust - helping security leaders assess their current posture and apply practical, risk-adaptive IAM patterns over the next 12–24 months.
The AI Stack Under Scrutiny: Security Gaps That Article 32 of the GDPR Does Not Forgive
Artificial intelligence systems introduce attack surfaces into production environments that traditional information security has not previously encountered: prompt injection, personal data leakage from vector databases, uncontrolled logging of LLM calls, and shadow AI among employees. Each of these vulnerabilities can constitute both a security incident and a breach of Article 32 of the GDPR, which requires measures tailored to the actual level of risk.
The presentation examines a typical AI stack layer by layer—from data input into the model, through RAG architecture and vector databases, to outputs and logging. For each layer, it demonstrates where personal data can actually leak, which technical and organisational measures are required under the GDPR, and when an incident involving an AI system triggers the notification obligation under Article 33.
The session is intended for everyone who builds, manages, or evaluates AI systems—and wants to know what a supervisory authority will examine first and where it will look.
The Attacker's Path: From the Supply Chain to Critical Systems
Attackers exploit vulnerabilities in the supply chain to gain access to an organization's most critical systems through trusted partners, third-party service providers, or software. Uroš Zorčič will present the technical and organizational measures that organizations can implement to address these threats and explain why supply chain risk management has become one of the key pillars of cybersecurity. He will also discuss how organizations can effectively respond to the new regulatory requirements introduced by the Slovenian Information Security Act (ZInfV-1).
The Breathtaking Reality of Medical Device Security: why compliance won't save the patient
Medical devices are advancing rapidly: not just in clinical capabilities, but in software complexity. Yet, despite security being absolutely crucial, it is often only tolerated rather than actively promoted during product development. For many, cybersecurity is just a checkbox. For us, it is much more. When lives are at stake, "just enough" cybersecurity is not acceptable.
In this presentation, we will look at what happens when these systems are compromised through a live, CTF-style demo of a custom-built respiratory device designed to meet standard compliance requirements. Instead of just pointing out flaws, this live experiment shows how we can practically bridge the gap between paperwork and real-world resilience.
The Cloud Is a Lease Agreement. Have You Read the Fine Print?
Moving to the cloud is more than purchasing a service—it means entering into a relationship of dependency, where the terms are largely defined by the provider. This session explores how organizations can adopt cloud services while remaining prepared and retaining control over what matters most. What happens to your identities and access management when you decide to change providers? How complex is it to migrate an entire IAM platform to a different environment? When is a hybrid approach—where your identity infrastructure remains under your control—a better choice than a full cloud migration? And what does a well-designed migration strategy look like if you want to avoid long-term vendor lock-in?
The Future Is Here: The Borderless SOC
The future of the Security Operations Center (SOC) is no longer a distant vision. With the rapid advancement of AI-powered technologies, the way security teams operate is evolving at an unprecedented pace. Artificial intelligence is already transforming how organizations detect, investigate, and respond to cyber threats, while reshaping the way security operations are managed. This session will explore how AI is redefining the role of Security Operations Centers and blurring the boundaries between managed security service providers (MSSPs) and in-house security teams. Special attention will be given to what these changes mean for organizations, their cyber resilience, the evolving cybersecurity services market, and the future role of SOC analysts.
The Intelligent Enterprise Shield: Commvault's AI-Powered Rapid Recovery
A successful cyberattack is not just about data loss—it triggers a lengthy process of digital forensics, identifying clean recovery points, and mitigating the risk of reinfection. For security engineers, traditional backup solutions are no longer sufficient. In this session, we will explore how Commvault leverages advanced artificial intelligence (AI) to proactively detect anomalies and cyber threats. We will take a closer look at automated cyber recovery in isolated Clean Room environments and demonstrate how organizations can minimize Recovery Time Objective (RTO) while ensuring 100% clean data recovery. Discover the architecture, automation, and technical best practices that enable true cyber resilience.
The Intuitive Firewall: From Conversation to Implementation with AI
If managing a firewall sometimes feels like a one-sided conversation—or if the firewall never seems to hear us when we get frustrated—we now have the opportunity to add a touch of humanity to it. Who knows, it might even compliment us on writing a well-crafted security policy.
This session will demonstrate how LLMs (Large Language Models) can be securely integrated with Check Point firewalls through MCP (Model Context Protocol) servers, enabling AI-assisted firewall management. The presentation will focus on the practical benefits of this architecture, including centralized and controlled access to data and security functions, more effective access management, and improved traceability of interactions with AI services. It will also address the key security considerations for deploying these solutions in production environments.
The Use of Artificial Intelligence in Logistics Processes
Artificial intelligence is rapidly making its way into logistics, yet many companies face challenges in its implementation that go far beyond technology itself. The presentation will introduce the results of a study conducted among Slovenian companies operating in transport, warehousing, and manufacturing, revealing the actual state of AI adoption—from pilot projects to full-scale production use.
The findings show that more than half of the companies are already using or testing AI. However, they often lack clearly defined performance indicators and appropriate risk management, while standards such as ISO 42001 remain largely unused.
We will explore the factors that genuinely drive successful AI adoption, explain why the greatest barriers are not financial but rather a lack of expertise and high-quality data, and examine what this means for the responsible and strategic integration of AI into logistics processes.
The presentation offers practical insights for managers who are already introducing AI within their organisations or are planning to do so.
Too slow for the age of agents? How to turn network chaos into cyber resilience
Security models are changing fundamentally, and artificial intelligence is no longer just used to analyze individual events, but is actively co-managing IT environments. For engineers, this means a necessary shift from manual “firefighting” to proactive environment management. Modern NetSecOps teams are overwhelmed with alerts from hundreds of devices—rather than providing visibility, more data too often only creates confusing noise.
This lecture offers a practical perspective on how the combined power of Cisco and Splunk technologies can successfully address this challenge.
In the lecture, you will learn how, by combining network telemetry, advanced analytics, and rapid incident investigation, we can tame network chaos and quickly identify the root cause of service issues and resolve security incidents. The integration does not reduce the role of humans; rather, with the help of intelligent systems, it enables engineers to respond faster and more efficiently.
What Does a Device Do When No One Is Watching? From Communication Analysis to Secrets Hidden in the Firmware
What does a network device really do when no one is watching? Using an affordable network or IoT device as an example, we will demonstrate a practical security analysis process – from identifying the first suspicious connections to remote servers to extracting and analysing the device’s firmware.
We will monitor network traffic, identify external services, unpack the firmware, and examine the file system, configuration, and key software components. We will look for embedded keys, credentials, hidden diagnostic functions, insecure protocols, and other mechanisms that could allow the manufacturer or an attacker to gain access to the device.
The presentation will be based on a real-world device analysis and practical demonstrations. In addition to presenting specific findings, it will introduce a repeatable approach that can be used to verify what is actually hidden inside the devices we trust with access to our networks every day.
When are personal data truly anonymous and safe to use without concern?
Personal data are anonymous if they do not relate to an identified or identifiable natural person. Whether an individual can be considered identifiable, however, depends on the perspective of the various parties involved.
The presentation will take a closer look at the new guidelines of the European Data Protection Board, which clarify the concept of anonymous data in light of the judgment of the Court of Justice of the European Union in Case C-413/23 P (EDPS v SRB), as well as other relevant CJEU case law.
The guidelines are particularly relevant in the context of the use and development of AI solutions, where appropriate data anonymisation is often essential for ensuring compliance with personal data protection rules. In this context, the European Data Protection Board also highlights the importance of effective cooperation and information exchange between supervisory authorities across the EU.
When Artificial Intelligence Meets GDPR: Who Is Accountable When Data Slips Out of Control?
Artificial intelligence is rapidly becoming part of everyday business processes, yet employees often use publicly available AI tools without clear internal policies or oversight. They may enter personal, business, and other confidential information into prompts without understanding where that data is transferred, how long it is retained, or how it may be used.
This session explores the key GDPR-related risks associated with AI adoption, including the growing phenomenon of Shadow AI, and examines the responsibilities of employees, management, Data Protection Officers (DPOs), Chief Information Security Officers (CISOs), and AI solution providers.
Particular attention will be given to the legal basis for processing, transparency obligations, Data Protection Impact Assessments (DPIAs), and the internal policies and governance frameworks that enable organizations to use AI safely and responsibly.
The central question of the session is: Who is ultimately accountable when personal data slips out of control due to careless or unsupervised use of artificial intelligence?
Who Is Responsible for Our Cloud Services: The CISO or Microsoft, Google, Amazon/...?
How can organizations ensure the security of their cloud infrastructure, and who should be held responsible for it? Where is the boundary between the responsibilities of the organization and those of the cloud service provider? What are the common security pitfalls of cloud environments, and what are the specific considerations when conducting security assessments?
This presentation will address these questions and examine cloud security management from multiple perspectives. Special attention will be given to Microsoft 365 environments, which are frequently targeted by attackers, as well as the importance of adapting default configurations to the organization's actual environment and regularly verifying their effectiveness.
The session will provide practical insights into the challenges organizations face when securing their cloud services and infrastructure, along with recommendations and best practices for managing cloud security effectively.
Workspace Is the New Perimeter—From EDR to WDR: continuity under cyber and geopolitical pressure
Your AI is Probably Out of Control (And You Know It)
AI governance isn’t just an engineering headache anymore; it’s a mess that affects the whole company. Usage and costs are hard to keep in check, employees are using AI tools you are only vaguely aware of, and vendors are sneaking AI into the software you use every day. Writing safety rules on paper is easy, but those rules won't stop a data leak or a model that makes things up. If you want to keep your company safe, you have to move past "policy" and start using tools that actually watch what the AI is doing.
Relying on industry standards and best practices (e.g. ISO 42001, EU AI Act, agent governance tools), this session gives you a straightforward plan to secure the way you use AI. First, we’ll look at how to find where AI is hiding in your business and how to check those tools for risks. Next, we’ll talk about how to keep track of how your own AI is being built so you have proof of what happened if something goes wrong. Finally, we discuss how to set up "guardrails" that can step in and block an AI the second it tries to break a rule, without slowing everything down to a crawl.
Your Biggest Security Vulnerability Isn't a Hacker. It's Too Many Security Tools.
Every new or emerging security risk often leads to the deployment of yet another security solution. The result? More consoles, more alerts, and less time for effective incident response. In this session, we will present an integrated approach that combines network, cloud, email, identity, IT, and OT security with 24/7 Security Operations Center (SOC) services in a single intelligent platform. The platform automatically detects and responds to threats in real time, helping organizations reduce complexity while strengthening their overall cyber resilience. The session will also address the security challenges introduced by the growing use of generative AI and demonstrate how organizations can effectively protect themselves against these emerging risks.
CIO FORUM
24/7 Mobile Device Backup: Protecting Data, Identity, and Business Continuity
Android & iPhone – Architecture, Security, and Compliance for CIOs and IT Leaders
Today, a mobile phone is the gateway to the entire digital workplace: email, multi-factor authentication (MFA), contacts, messaging platforms, business applications, and cloud services. When a device is lost, stolen, damaged, compromised, or leaves the organization with an employee, businesses can instantly lose access to critical systems. Yet mobile backup is still too often viewed as an end-user convenience rather than a fundamental component of business continuity, data governance, and cyber resilience. This shift in perspective is the foundation of this session.
The presentation provides a structured and practical framework for building a reliable 24/7 backup strategy for mixed Android and iPhone environments. It begins by debunking the myth of the "one-click backup." A complete mobile backup consists of four distinct layers—operating system, contacts, media, and application data—each requiring different technologies and management approaches. The session also explains the fundamental architectural differences between Android and iOS, particularly regarding background application behavior, which directly determines which backup methods can be considered reliable.
The core of the presentation focuses on enterprise-grade mobile management, an area that is often overlooked in small and medium-sized organizations. It covers centralized fleet management through MDM/UEM platforms such as Microsoft Intune, Jamf, Samsung Knox, and others; compares device ownership models (BYOD, COPE, and COBO); and explains best practices for separating corporate and personal data. Special attention is given to messaging applications—including WhatsApp, Viber, Telegram, and Signal—whose default backup mechanisms differ significantly and are often not protected with end-to-end encryption.
The security section highlights the risks most frequently underestimated by decision-makers: encrypted backups, the evolution of the traditional 3-2-1 backup principle into the 3-2-1-1-0 strategy (including immutable backups and verified recovery to defend against ransomware), data residency, GDPR compliance, and one of the most critical scenarios—losing the multi-factor authentication credentials of a Microsoft 365 or Entra ID administrator, potentially locking an organization out of its entire cloud environment. The session also addresses remote and selective device wipe capabilities for lost devices or departing employees.
The presentation concludes with a practical decision-making framework for executives, comparing the cost of implementing a mobile backup strategy with the financial impact of security incidents, downtime, and GDPR penalties. It introduces key performance indicators (KPIs), a phased implementation roadmap, and a real-world example of a mixed fleet of 50 mobile devices (iPhones, Samsung devices, and other Android smartphones), including estimated costs and a recommended combination of management and backup solutions.
Key Takeaways
● Understand the four-layer mobile backup framework and why Android and iPhone require different backup strategies.
● Learn how to select the right MDM/UEM platform for organizations with 20–100 employees.
Identify security risks associated with messaging applications and multi-factor authentication (MFA) tools.
● Gain practical guidance for GDPR compliance, ransomware resilience, and preventing loss of access to Microsoft 365/Entra ID environments.
● Leave with a practical decision-making framework, including KPIs, implementation steps, and cost estimates that can be immediately applied within your organization.
Who Should Attend
This session is designed for CIOs, IT managers, information security leaders, and system administrators responsible for managing mixed fleets of Android and iPhone devices. The content is tailored to be accessible to business decision-makers while providing sufficient technical depth for IT professionals, and no prior knowledge is required.
Artificial Intelligence and Digital Sovereignty – The Bank of Slovenia’s Experience
Artificial intelligence is becoming an increasingly important part of modern business, as its use extends far beyond process automation. With the rapid development of AI solutions, questions of data governance, security, trust, and digital sovereignty remain at the forefront and are crucial for the responsible adoption and use of these technologies.
How can organizations harness the potential of new technologies while maintaining control over their data, processes, and critical digital infrastructure? Drawing on the experience of the Bank of Slovenia, the presentation will explore practical aspects of AI implementation, the challenges of ensuring compliance with European and Slovenian legislation, and key considerations for building a trustworthy and responsible digital future.
CIO in Times of Crisis: Which Decisions Save the Business During a Cyber Incident
Digitalization Is Built on Technology. Success Is Built on People. How Can Change Management Create the Conditions for a Successful Digital Transformation?
Digitalization is merely a tool that enables true business transformation – changing processes, ways of working, and decision-making. The success of such a transformation depends not only on technology, but on the people who co-create the changes, embrace them, and put them into practice in their everyday work.
The presentation will highlight the most common pitfalls of digital projects and the key success factors that enable organizations to achieve lasting change. Drawing on practical experience, we will demonstrate how digitalization can become a catalyst for comprehensive business transformation – not only of tools and systems, but also of organizational culture, processes, and ways of working.
Digitalizing the Future of Mobility: BMW Neue Klasse – The Beginning of a New Era!
Neue Klasse represents the most significant technological transformation in BMW’s history. The presentation will explore how the new generation of vehicles brings together advanced software architecture, artificial intelligence, high-performance computing systems, and digital user interfaces within a unified mobility ecosystem.
Special emphasis will be placed on the concept of the “software-defined vehicle,” the new BMW Panoramic iDrive system, central computing platforms (“superbrains”), connectivity, and advanced driver assistance systems. The presentation will also highlight the role of digitalization in development, production, energy management, and sustainability, demonstrating how Neue Klasse is laying the foundations for the future of digital mobility.
INTRODUCTION TO PANEL DISCUSSION 2:
INTRODUCTION TO PANEL DISCUSSION 3:
INTRODUCTION TO PANEL DISCUSSION 4:
LUNCH BREAK
PANEL DISCUSSION 1: The Future of Work: How to Securely Connect Time, Space, and People
Technology is transforming the way we work, collaborate, and use workplace environments. How can CIOs help create a secure, flexible, and efficient workplace that supports both employees and the organization's business objectives?
Key topics:
How will hybrid work, mobility, and changing employee expectations reshape organizations?
What is the CIO's role in designing a modern employee experience?
How can IT, HR, security, and smart building systems be effectively integrated?
The Evolution of Security: From Keys and Access Cards to Mobile Credentials
How can data, artificial intelligence, and automation improve productivity and decision-making?
How can organizations build a secure, flexible, and cost-effective workplace for the future?
PANEL DISCUSSION 2: CIO Under Pressure: How to Lead IT in Times of Constant Change
Today's CIO must simultaneously ensure business stability, control costs, introduce new technologies, and meet the ever-growing expectations of executive management. How can CIOs set the right priorities and successfully lead IT departments through rapid technological and business change?
Key topics:
How is the role and responsibility of the modern CIO evolving?
How can organizations balance operational stability, innovation, and limited budgets?
How should CIOs prioritize competing demands from executive management and business units?
How can CIOs lead their teams, develop critical skills, and attract and retain top IT talent?
How can organizations prepare for technological, regulatory, and geopolitical change?
PANEL DISCUSSION 3: Cybersecurity as a Strategic Priority for Modern Organizations
Cybersecurity is no longer just an IT responsibility—it has become a matter of business risk, organizational resilience, and executive accountability. How can CIOs ensure a strong security posture while enabling innovation, growth, and business agility?
Key topics:
How can cybersecurity risks be effectively communicated to executive management and the board?
Where is the right balance between acceptable risk, security investment, and business needs?
How can organizations prepare for cyberattacks, respond effectively, and ensure business continuity?
How should organizations manage cybersecurity risks across suppliers, partners, and third-party providers?
How can organizations build a strong security culture and clearly define the responsibilities of the CIO, CISO, and executive management?
PANEL DISCUSSION 4: From AI Pilots to Business Value: Building an AI Strategy That Delivers
Many organizations are already experimenting with artificial intelligence, but far fewer have a clear strategy for its long-term adoption. How can organizations identify the right use cases, establish governance, and integrate AI into business processes in a secure, scalable, and value-driven way?
Key topics:
How can organizations develop an AI strategy aligned with their business objectives?
How can they identify AI use cases that deliver measurable business value?
How can organizations move from isolated AI experiments to enterprise-wide adoption?
How should data, governance, security, privacy, and accountability be managed?
What skills, organizational changes, and strategic partnerships are needed to successfully scale AI?
The Evolution of Security: From Keys to Cards to Mobile Phones
Access control has evolved over time from mechanical keys to smart cards and mobile credentials. This session explores what has truly changed along the way—not only the user experience, but also the methods of identification, credential management, and security. Special attention will be given to common misconceptions surrounding card technologies, secure storage of user identities, and the transition to modern solutions such as MIFARE DESFire, Seos, and mobile phones as carriers of digital identity.
The Singularity Will Not Arrive. You Will Deploy It.
In this presentation, I will challenge the idea that the Singularity will arrive as one dramatic moment when artificial intelligence becomes more capable than humans and begins operating beyond our control.
I believe that inside companies, it may happen much more gradually: one AI agent, one permission, and one automated decision at a time.
I will explore why the real challenge is not unlimited intelligence, but unbounded autonomy. My view is that AI agents should be allowed to become more capable over time, while operating within clear and adaptable boundaries around access, authority, human oversight, and accountability.
I will place AI agent governance within the broader AI governance landscape and share a practical framework for how CIOs can decide where autonomy should expand, where human control must remain, and what companies should prepare for over the coming months.












































































