21st & 22nd April 2027 in Hamburg
21st & 22nd April 2027 in Hamburg Contact: info@cybersecuritysumm.it or +49 40 999 993 868

Cybersecurity Summit Day 1

Cybersecurity Summit Day 1

The agenda of the Cybersecurity Summit on April 28th, 2026.

Cybersecurity Summit Day 2

Cybersecurity Summit Day 2

The agenda of the Cybersecurity Summit on April 22nd, 2027.



21st Apr 2027 Cybersecurity Summit Day 1

  1. CYBERSECURITY SUMMIT MAIN STAGE
  1. RESILIENCE SUMMIT MAIN STAGE
  1. ZUGSPITZE Masterclasses
  1. MATTERHORN Masterclasses
  1. 08:30
     

    08:30 Welcome

    Our doors open at 08:30 - so you can start networking at the first coffee and secure the best seat.

  1. 09:15
     

    A welcome from the Cybersecurity Summit team

    Welcome by the Cybersecurity Summit Team

  2. 10:30
     

    Coffee break

    Enjoy coffee and breakfast and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

  3. 11:00
    Panel discussion

    Human Risk 2.0: AI, voice cloning and the new dimension of personalised attacks

    People remain the biggest target – yet artificial intelligence is taking social engineering to a whole new level. Deceptively realistic voice clones, AI-generated deepfakes and hyper-personalised phishing campaigns are rendering traditional awareness training increasingly ineffective.

    The panel will discuss how organisations can protect themselves against AI-enabled attacks when identities can be manipulated and communication is no longer reliably authentic. The focus will be on new defensive approaches, ranging from identity verification and zero-trust communication to organisational safeguards that go beyond mere training.

    Presentation:

    Isabelle Ewald Isabelle Ewald BDO
  4. 11:45
    Presentation

    Brain–Computer Interfaces: Emerging Implications for Law Enforcement and Public Security

    Brain–Computer Interfaces are moving from lab to street, turning the human brain into a new data source and marking the shift from cyber-security to neuro-security. This keynote examines what BCIs mean for policing and justice — the opportunities, the threats of neural-data misuse, and the human-rights stakes around mental privacy and cognitive liberty — and makes the case for legal boundaries, oversight, and international cooperation before neuro-enabled crime arrives.

  1.  

    09:15 Opening

    Opening of the event with a warm welcome by the moderator.

  2. Panel discussion

    09:30 Digital Sovereignty & Cyber Warfare: Strategic Resilience in the Geopolitical Age

    Cyberattacks have long been part of geopolitical power shifts. Both states and businesses face the challenge of safeguarding their digital sovereignty – in a world where supply chains, cloud infrastructures and data flows are globally intertwined.

    The panel will examine how organisations can arm themselves against state-sponsored cyberattacks whilst simultaneously reducing technological dependencies. Discussions will focus on strategies relating to sovereign cloud, data sovereignty, critical infrastructure and the question of how much digital independence is realistic and economically viable.

  3.  

    10:15 Coffee break

    Enjoy coffee and breakfast and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

  4. Panel discussion

    10:30 NIS2, DORA, CRA: Lessons learnt from the first wave of implementation

    With NIS2, DORA and the Cyber Resilience Act, the EU has made cybersecurity a regulatory obligation at board level. But what does implementation look like in practice? Which requirements have actually made companies more resilient, and where have new operational or legal challenges arisen?

    The panel takes stock of the situation so far: from liability issues and reporting obligations to supply chain requirements and organisational changes in security and governance. The focus is on whether regulation has led to a measurable increase in security – or, above all, has simply increased the pressure to comply.

  5. Panel discussion

    11:45 API Security & Application Layer Security: The new battleground beyond the perimeter

    Attacks are increasingly shifting from the network layer to APIs, applications and SaaS platforms. Rather than bypassing firewalls, attackers now target business logic, identity models and flawed API implementations. Modern architectures featuring microservices, cloud-native environments and third-party integrations massively expand the attack surface.

    The panel will discuss how organisations can holistically secure API ecosystems – from runtime protection and API discovery to authentication and authorisation models in a zero-trust context. The focus will be on how application-layer security can be reimagined when traditional network boundaries no longer provide protection.

  1. Presentation

    In preparation

  2. Presentation

    In preparation

  3. Presentation

    11:00 Masterclass Formalize

    Well-known vulnerabilities, such as Log4Shell and PrintNightmare, impressively demonstrate what we can learn from previous attacks for tomorrow's cyber defense.

    Key topics:

    • Zero Days in Reality Check: What known exploits reveal about today's threats.
    • When vulnerabilities collide: Understanding combined attack scenarios.
    • Structured endpoint management: Inventory, analyze, patch.
    • Unified endpoint management: Simplify processes, reduce risks, secure standards.
    • Blueprint for sustainable resilience: Which measures are crucial now?
  4. Presentation

    In preparation

  5. Presentation

    12:00 Masterclass Akarion

  1. Presentation

    In preparation

  2. Presentation

    In preparation

  3. Presentation

    In preparation

  4. Presentation

    In preparation

  5. Presentation

    In preparation

  6. Presentation

    In preparation

  1. 12:15
     

    12:15 Lunch break

    Enjoy the food and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

  1. 14:00
  2. 15:15
    Panel discussion

    Defensive AI vs. Offensive AI: Who controls autonomous systems?

    Artificial intelligence is no longer merely a tool, but an active player in cyberspace. Whilst defensive AI detects anomalies in real time, automates incident response and enables security operations centres to operate with increasing autonomy, attackers are developing AI-powered exploits, generative malware and adaptive attack campaigns that dynamically adapt to defensive mechanisms.

    The panel will examine the new reality of an AI-driven arms race: just how resilient are autonomous SOCs really? Will AI agents themselves become a target? And how great is the risk posed by model manipulation, data poisoning or prompt injection? The discussion will focus on where automation makes sense, where human control remains indispensable, and whether we are heading towards a future in which machines fight each other whilst humans merely monitor.

  3. 16:00
     

    Coffee break

    Enjoy coffee and cake and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

  4. 16:15
    Panel discussion

    Supply Chain Security & Software Liability: Who is liable when trust becomes a vulnerability?

    Digital supply chains have long since become a strategic target. With NIS2, the Cyber Resilience Act and stricter transparency requirements, the focus is increasingly shifting from technical security to the issue of responsibility and liability. Today, companies must not only manage third-party risks, but also ensure that their entire software and OT landscape is resilient and ‘secure by design’.

    The panel will discuss how supply chain security, software liability and regulatory requirements can be implemented in practice – from SBOMs and open-source risks to the protection of critical infrastructure. The focus will be on how trust in networked ecosystems must be redefined when it can become the greatest vulnerability.

  5. 17:00
    Presentation

    Logging, yes – but how do you analyse the data? Why cybersecurity reporting in the public sector is a legal issue before it becomes a statistical one

    Authorities log data, monitor networks and analyse threat intelligence – NIS2 makes this mandatory. But are authorities also permitted to demonstrate that their security measures are actually effective? This is precisely where a gap exists that is rarely discussed in practice. Using Bavaria as an example, the presentation demonstrates just how precisely the BayDiG regulates monitoring by the State Office for Information Security – with a narrow purpose, strict retention periods and clear boundaries. Surprisingly, even the State Office itself comes up against these boundaries as soon as it seeks to quantify its own successes: how many attacks have been thwarted, and how effective are the measures in place?

    The presentation explores whether a new legal basis is required for this, or whether the more pragmatic approach is closer at hand than one might initially think. It is precisely this precision that becomes a challenge as soon as other authorities wish to use the same data to evaluate the effectiveness of their security measures: is the GDPR sufficient for this? Is a different legal basis required? And where does Article 89 of the GDPR, with its requirements on anonymisation and pseudonymisation, come into play? A look at Hesse and Baden-Württemberg shows that the Bavarian example is not unique. The presentation provides clear, practical guidance for anyone who wishes to view cybersecurity monitoring and data protection not as opposing concepts, but as a task to be tackled jointly.

  6. 17:30
     

    Speaker & Startup Awards Ceremony

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1. Panel discussion

    14:45 Measuring Resilience: What KPIs actually matter?

    How can resilience be measured and managed in practice at management level? The panel will examine which KPIs are truly relevant, outline practical approaches to assessment, and discuss how companies can improve their resilience using data-driven methods.

  2. Fireside Chat

    15:30 How is Kubernetes transforming modern DevSecOps and observability processes?

    Security policies, monitoring and runtime visibility need to be rethought in highly dynamic cloud-native environments.
  3.  

    16:00 Coffee break

    Enjoy coffee and cake and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

  4. Panel discussion

    16:15 Resilient Software Architecture: Who owns security by design?

    Modern software architectures play a decisive role in determining how resilient organisations are to cyber risks. At the same time, the lines of responsibility between development, security and business are becoming increasingly blurred.

    The panel will discuss how organisations integrate ‘security by design’ and resilience into their architectural decisions – from microservices and cloud-native solutions to platform strategies. The focus will be on who bears responsibility: does it lie with engineering, security or the business – and how can clear ownership and effective collaboration be established?

  5. Presentation

    17:00 Just Culture: Dealing fairly with actions that jeopardise safety

    Sanctions are the enemy of a good error culture, but in everyday life people still like to look for and punish the guilty. The presentation explains the principle of "Just Culture". IT and other types of industry can still learn a lot from healthcare and aviation in this respect. An error model and tools such as "Critical Incident Reporting Systems" will be presented, which can be used to develop a safety culture. The presentation provides a look over the shoulder at ECE, where employees are involved in terms of (IT) security culture, errors are reported in fuck-up sessions and a mascot supports the CISO.

  6.  

    17:30 Main Stage Speaker Awards Ceremony

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1. Presentation

    14:15 Masterclass Syss

  2. Presentation

    14:45 Masterclass Ontinue

  3. Presentation

    In preparation

  4. Presentation

    In preparation

  5.  

    15:45 Networking & Coffee break

    Enjoy some coffee and cake and make new contacts with other visitors and exhibitors of the Cybersecurity Summit.

  6. Presentation

    In preparation

  7. Presentation

    In preparation

  8.  

    17:30 Cybersecurity Summit Awards Ceremony 2027

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1. Presentation

    In preparation

  2. Presentation

    In preparation

  3. Presentation

    In preparation

  4.  

    15:30 Networking & Coffee break

    Enjoy some coffee and cake and make new contacts with other visitors and exhibitors of the Cybersecurity Summit.

  5. Presentation

    In preparation

  6. Presentation

    In preparation

  7. Presentation

    In preparation

  8. Presentation

    In preparation

  9.  

    17:45 Cybersecurity Summit Awards Ceremony 2027

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download.

  1. 18:00
     

    18:00 Aftershow Lounge

  1. 23:00
     

    23:00 End of today's event

21st April 2027 Cybersecurity Summit Day 1

08:30

Welcome

Our doors open at 08:30 - so you can start networking at the first coffee and secure the best seat.

09:15 CYBERSECURITY SUMMIT MAIN STAGE:

A welcome from the Cybersecurity Summit team

Welcome by the Cybersecurity Summit Team

09:15 RESILIENCE SUMMIT MAIN STAGE:

Opening

Opening of the event with a warm welcome by the moderator.

09:30 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

Digital Sovereignty & Cyber Warfare: Strategic Resilience in the Geopolitical Age

Cyberattacks have long been part of geopolitical power shifts. Both states and businesses face the challenge of safeguarding their digital sovereignty – in a world where supply chains, cloud infrastructures and data flows are globally intertwined.

The panel will examine how organisations can arm themselves against state-sponsored cyberattacks whilst simultaneously reducing technological dependencies. Discussions will focus on strategies relating to sovereign cloud, data sovereignty, critical infrastructure and the question of how much digital independence is realistic and economically viable.

10:00 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

10:00 MATTERHORN MASTERCLASSES:
Presentation

In preparation

10:15 RESILIENCE SUMMIT MAIN STAGE:

Coffee break

Enjoy coffee and breakfast and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

10:15 MATTERHORN MASTERCLASSES:
Presentation

In preparation

10:30 CYBERSECURITY SUMMIT MAIN STAGE:

Coffee break

Enjoy coffee and breakfast and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

10:30 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

NIS2, DORA, CRA: Lessons learnt from the first wave of implementation

With NIS2, DORA and the Cyber Resilience Act, the EU has made cybersecurity a regulatory obligation at board level. But what does implementation look like in practice? Which requirements have actually made companies more resilient, and where have new operational or legal challenges arisen?

The panel takes stock of the situation so far: from liability issues and reporting obligations to supply chain requirements and organisational changes in security and governance. The focus is on whether regulation has led to a measurable increase in security – or, above all, has simply increased the pressure to comply.

10:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

10:45 MATTERHORN MASTERCLASSES:
Presentation

In preparation

11:00 CYBERSECURITY SUMMIT MAIN STAGE:
Panel discussion

Human Risk 2.0: AI, voice cloning and the new dimension of personalised attacks

People remain the biggest target – yet artificial intelligence is taking social engineering to a whole new level. Deceptively realistic voice clones, AI-generated deepfakes and hyper-personalised phishing campaigns are rendering traditional awareness training increasingly ineffective.

The panel will discuss how organisations can protect themselves against AI-enabled attacks when identities can be manipulated and communication is no longer reliably authentic. The focus will be on new defensive approaches, ranging from identity verification and zero-trust communication to organisational safeguards that go beyond mere training.

Presentation:

Isabelle Ewald Isabelle Ewald BDO
11:00 ZUGSPITZE MASTERCLASSES:
Presentation

Masterclass Formalize

Well-known vulnerabilities, such as Log4Shell and PrintNightmare, impressively demonstrate what we can learn from previous attacks for tomorrow's cyber defense.

Key topics:

  • Zero Days in Reality Check: What known exploits reveal about today's threats.
  • When vulnerabilities collide: Understanding combined attack scenarios.
  • Structured endpoint management: Inventory, analyze, patch.
  • Unified endpoint management: Simplify processes, reduce risks, secure standards.
  • Blueprint for sustainable resilience: Which measures are crucial now?
11:00 MATTERHORN MASTERCLASSES:
Presentation

In preparation

11:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

11:30 MATTERHORN MASTERCLASSES:
Presentation

In preparation

11:45 CYBERSECURITY SUMMIT MAIN STAGE:
Presentation

Brain–Computer Interfaces: Emerging Implications for Law Enforcement and Public Security

Brain–Computer Interfaces are moving from lab to street, turning the human brain into a new data source and marking the shift from cyber-security to neuro-security. This keynote examines what BCIs mean for policing and justice — the opportunities, the threats of neural-data misuse, and the human-rights stakes around mental privacy and cognitive liberty — and makes the case for legal boundaries, oversight, and international cooperation before neuro-enabled crime arrives.

11:45 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

API Security & Application Layer Security: The new battleground beyond the perimeter

Attacks are increasingly shifting from the network layer to APIs, applications and SaaS platforms. Rather than bypassing firewalls, attackers now target business logic, identity models and flawed API implementations. Modern architectures featuring microservices, cloud-native environments and third-party integrations massively expand the attack surface.

The panel will discuss how organisations can holistically secure API ecosystems – from runtime protection and API discovery to authentication and authorisation models in a zero-trust context. The focus will be on how application-layer security can be reimagined when traditional network boundaries no longer provide protection.

12:00 ZUGSPITZE MASTERCLASSES:
Presentation

Masterclass Akarion

12:00 MATTERHORN MASTERCLASSES:
Presentation

In preparation

12:15

Lunch break

Enjoy the food and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

14:00 MATTERHORN MASTERCLASSES:
Presentation

In preparation

14:00 PITCHUP STAGE:

Startup Awards Part 1

On our PitchUp Stage, up-and-coming startups present their smartest solutions for the cybersecurity and resilience – concise, compelling, and packed with fresh ideas. You'll find the stage right next to our Startup Area on the event floor.

 

Stop by, discover tomorrow’s innovations, and have your say: You decide which three startups will win the Startup Award!

14:15 ZUGSPITZE MASTERCLASSES:
Presentation

Masterclass Syss

14:30 MATTERHORN MASTERCLASSES:
Presentation

In preparation

14:45 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

Measuring Resilience: What KPIs actually matter?

How can resilience be measured and managed in practice at management level? The panel will examine which KPIs are truly relevant, outline practical approaches to assessment, and discuss how companies can improve their resilience using data-driven methods.

14:45 ZUGSPITZE MASTERCLASSES:
Presentation

Masterclass Ontinue

15:00 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

15:00 MATTERHORN MASTERCLASSES:
Presentation

In preparation

15:15 CYBERSECURITY SUMMIT MAIN STAGE:
Panel discussion

Defensive AI vs. Offensive AI: Who controls autonomous systems?

Artificial intelligence is no longer merely a tool, but an active player in cyberspace. Whilst defensive AI detects anomalies in real time, automates incident response and enables security operations centres to operate with increasing autonomy, attackers are developing AI-powered exploits, generative malware and adaptive attack campaigns that dynamically adapt to defensive mechanisms.

The panel will examine the new reality of an AI-driven arms race: just how resilient are autonomous SOCs really? Will AI agents themselves become a target? And how great is the risk posed by model manipulation, data poisoning or prompt injection? The discussion will focus on where automation makes sense, where human control remains indispensable, and whether we are heading towards a future in which machines fight each other whilst humans merely monitor.

15:30 RESILIENCE SUMMIT MAIN STAGE:
Fireside Chat

How is Kubernetes transforming modern DevSecOps and observability processes?

Security policies, monitoring and runtime visibility need to be rethought in highly dynamic cloud-native environments.
15:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

15:30 MATTERHORN MASTERCLASSES:

Networking & Coffee break

Enjoy some coffee and cake and make new contacts with other visitors and exhibitors of the Cybersecurity Summit.

15:45 ZUGSPITZE MASTERCLASSES:

Networking & Coffee break

Enjoy some coffee and cake and make new contacts with other visitors and exhibitors of the Cybersecurity Summit.

15:45 MATTERHORN MASTERCLASSES:
Presentation

In preparation

16:00

Coffee break

Enjoy coffee and cake and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

16:00 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

16:15 CYBERSECURITY SUMMIT MAIN STAGE:
Panel discussion

Supply Chain Security & Software Liability: Who is liable when trust becomes a vulnerability?

Digital supply chains have long since become a strategic target. With NIS2, the Cyber Resilience Act and stricter transparency requirements, the focus is increasingly shifting from technical security to the issue of responsibility and liability. Today, companies must not only manage third-party risks, but also ensure that their entire software and OT landscape is resilient and ‘secure by design’.

The panel will discuss how supply chain security, software liability and regulatory requirements can be implemented in practice – from SBOMs and open-source risks to the protection of critical infrastructure. The focus will be on how trust in networked ecosystems must be redefined when it can become the greatest vulnerability.

16:15 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

Resilient Software Architecture: Who owns security by design?

Modern software architectures play a decisive role in determining how resilient organisations are to cyber risks. At the same time, the lines of responsibility between development, security and business are becoming increasingly blurred.

The panel will discuss how organisations integrate ‘security by design’ and resilience into their architectural decisions – from microservices and cloud-native solutions to platform strategies. The focus will be on who bears responsibility: does it lie with engineering, security or the business – and how can clear ownership and effective collaboration be established?

16:15 MATTERHORN MASTERCLASSES:
Presentation

In preparation

16:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

16:45 MATTERHORN MASTERCLASSES:
Presentation

In preparation

17:00 CYBERSECURITY SUMMIT MAIN STAGE:
Presentation

Logging, yes – but how do you analyse the data? Why cybersecurity reporting in the public sector is a legal issue before it becomes a statistical one

Authorities log data, monitor networks and analyse threat intelligence – NIS2 makes this mandatory. But are authorities also permitted to demonstrate that their security measures are actually effective? This is precisely where a gap exists that is rarely discussed in practice. Using Bavaria as an example, the presentation demonstrates just how precisely the BayDiG regulates monitoring by the State Office for Information Security – with a narrow purpose, strict retention periods and clear boundaries. Surprisingly, even the State Office itself comes up against these boundaries as soon as it seeks to quantify its own successes: how many attacks have been thwarted, and how effective are the measures in place?

The presentation explores whether a new legal basis is required for this, or whether the more pragmatic approach is closer at hand than one might initially think. It is precisely this precision that becomes a challenge as soon as other authorities wish to use the same data to evaluate the effectiveness of their security measures: is the GDPR sufficient for this? Is a different legal basis required? And where does Article 89 of the GDPR, with its requirements on anonymisation and pseudonymisation, come into play? A look at Hesse and Baden-Württemberg shows that the Bavarian example is not unique. The presentation provides clear, practical guidance for anyone who wishes to view cybersecurity monitoring and data protection not as opposing concepts, but as a task to be tackled jointly.

17:00 RESILIENCE SUMMIT MAIN STAGE:
Presentation

Just Culture: Dealing fairly with actions that jeopardise safety

Sanctions are the enemy of a good error culture, but in everyday life people still like to look for and punish the guilty. The presentation explains the principle of "Just Culture". IT and other types of industry can still learn a lot from healthcare and aviation in this respect. An error model and tools such as "Critical Incident Reporting Systems" will be presented, which can be used to develop a safety culture. The presentation provides a look over the shoulder at ECE, where employees are involved in terms of (IT) security culture, errors are reported in fuck-up sessions and a mascot supports the CISO.

17:15 MATTERHORN MASTERCLASSES:
Presentation

In preparation

17:30 CYBERSECURITY SUMMIT MAIN STAGE:

Speaker & Startup Awards Ceremony

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

17:30 RESILIENCE SUMMIT MAIN STAGE:

Main Stage Speaker Awards Ceremony

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

17:30 ZUGSPITZE MASTERCLASSES:

Cybersecurity Summit Awards Ceremony 2027

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

17:45 MATTERHORN MASTERCLASSES:

Cybersecurity Summit Awards Ceremony 2027

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download.

18:00

Aftershow Lounge

23:00

End of today's event

22nd Apr 2027 Cybersecurity Summit Day 2

  1. CYBERSECURITY SUMMIT MAIN STAGE
  1. RESILIENCE SUMMIT MAIN STAGE
  1. ZUGSPITZE Masterclasses
  1. MATTERHORN Masterclasses
  1. 09:00
     

    09:00 Welcome

    Our doors open at 9:00 a.m. - so you can start networking with your first coffee and secure the best seat.

  1. 10:00
     

    Opening

    Opening of the event and welcome by the moderator

  2. 10:15
    Fireside Chat

    International Fire Side Chat: Cybersecurity 2030: Is true security even realistic anymore?

    When AI attacks and defends autonomously, geopolitical conflicts escalate digitally and supply chains become politicised, an uncomfortable question arises: are we still striving for security – or merely for damage control?

    An international panel takes an honest look ahead and discusses what strategic decisions need to be made today to ensure that by 2030 we are not just compliant, but truly resilient.

  3. 10:45
    Panel discussion

    Is the SOC Dead? Autonomous Security Operations 2027

    The traditional Security Operations Centre is on the cusp of a fundamental transformation. AI-powered detection, automated response playbooks and agent-based systems are taking on an increasing number of operational tasks. The key question is no longer whether the SOC is operated internally or externally – but how autonomous it can be.
    This panel will discuss how ‘AI-first’ architectures, autonomous decision-making processes and new MDR models are transforming security operations. What role remains for humans in the ‘human-in-the-loop’ model? Where are the limits of automation? And when does efficiency become a new risk?
    The focus is on the strategic evolution of security operations away from reactive alarm management towards adaptive, semi-autonomous cyber defence.

  4. 11:30
    Presentation

    365 Days as a CISO: From the Initial Assessment to Managed Security

    How information security can be strategically developed over the course of a year: through clear governance, effective security operations, robust IT business continuity management (BCM) and enhanced incident response processes. Honest lessons learnt from real-world transformation experience show why effective information security requires, above all, clarity regarding responsibilities, risks and operational capability.

  5. 12:00
    Panel discussion

    Post-Quantum Security: From Threat to Migration Strategy

    The question is no longer whether quantum computers can break cryptographic methods – but how long existing systems will remain secure. As the first post-quantum algorithms are being standardised and implemented, businesses face a complex challenge: how can they migrate without operational risks?

    This panel discusses concrete roadmaps for the post-quantum transformation – from crypto inventories and risk assessment through hybrid cryptography models to long-term migration strategies. The focus is on practical implementation: Which systems need to be migrated first? How significant is the ‘harvest now, decrypt later’ risk really? And how can organisations ensure that the migration itself does not become a security vulnerability?

  1.  

    10:00 Opening

    Opening of the event and welcome by the moderator

  2. Presentation

    10:15 The Art of War for Talent – How to Attract, Develop and Retain the Best Security Staff

    TBA

  3.  

    10:45 Coffee break

    Enjoy coffee and breakfast and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

  4. Panel discussion

    11:00 Business Continuity & Crisis Management: Are we really prepared?

    How do companies test their BCM strategies under realistic conditions – and where are the biggest gaps between planning and implementation? 

  5. Presentation

    11:45 Interactive cyber crisis simulation by the Hamburg State Criminal Police Office (LKA)

    How does it feel to suddenly be responsible, as a member of a crisis response team, for the survival of a company hit by ransomware? What steps must be taken, and what pitfalls must be avoided, to weather such a crisis? Take part in the interactive crisis simulation and get a sense of the challenges posed by modern cyberattacks.

  6. Panel discussion

    12:15 AI Governance & Souveränität: How do we control what we don’t fully understand?

    How do companies establish effective governance structures for AI whilst balancing innovation, risk and regulation? This session demonstrates how organisations can build control, transparency and resilience when working with AI.

  1. Presentation

    In preparation

  2. Presentation

    In preparation

  3. Presentation

    In preparation

  4. Presentation

    In preparation

  1. Presentation

    In preparation

  2. Presentation

    In preparation

  3. Presentation

    In preparation

  4. Presentation

    In preparation

  1. 12:45

    12:45 Lunch break

    Enjoy lunch and make new contacts with visitors and exhibitors.

  1. 14:00
  2. 15:15
    Panel discussion

    AI Agents & Autonomous Systems Security: Who controls the digital actors?

    With the widespread integration of copilots, agent-based automation and self-executing workflows, new digital actors are emerging within organisations. These systems make decisions, access data and carry out actions – often with far-reaching permissions.

    The panel will discuss the new security landscape: how can AI agents that act autonomously be secured? What risks arise from prompt injection, tool abuse or manipulated training data? And how can organisations prevent autonomous systems from becoming invisible attack surfaces?

    The focus is on governance models for agent-based systems, identity and rights concepts for machine agents, and strategies to ensure that innovation is not achieved at the cost of losing control.

  3. 16:00
    Fireside Chat

    Machine Identity & Non-Human Identities: The Invisible Majority on the Network

    Whilst security strategies have focused on human identities for years, the number of non-human identities is growing exponentially. Workloads, containers, APIs, bots and autonomous systems are constantly communicating with one another – secured by certificates, tokens and secrets that are often created and expire unchecked.

    This panel explores the growing challenges surrounding workload and API identities, secret sprawl and ‘certificate chaos’. How do organisations keep track of millions of machine identities? What role do identity fabrics, automated certificate lifecycle management and zero-trust architectures play? And how do organisations prevent expired certificates or compromised secrets from becoming systemic vulnerabilities?

    The focus is on the question of how identity security can be reimagined now that machines have long since become the majority of actors on the network.

  4. 16:30
    Fireside Chat

    From Cybersecurity to Resilience: Who owns the risk?

    Cyber risks are no longer purely an IT issue, but affect the entire organisation at a strategic level. With increasing regulation and a growing threat landscape, the question arises as to how companies can clearly define responsibilities and effectively allocate them between the CISO, CRO and CIO.

    The panel will examine how governance models, decision-making structures and responsibilities need to be designed to manage cyber and resilience risks holistically. The focus will be on who ultimately bears responsibility – and how collaboration at C-level works in practice.

  5. 17:00
     

    Speaker & Startup Awards Ceremony

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1. Panel discussion

    14:45 Cybersecurity for Critical Infrastructure: Securing Energy & OT

    Critical infrastructure, particularly in energy and OT environments, is increasingly becoming the target of targeted cyberattacks. At the same time, regulatory requirements are rising and complexity is increasing due to the convergence of IT and OT.

    The panel will discuss how organisations can effectively secure their OT and ICS systems – from network segmentation and monitoring to secure IT/OT architectures. The focus will be on how security strategies need to evolve to both meet compliance requirements and ensure the stability of critical systems.

  2. Fireside Chat

    15:30 Cloud, On-Premise & Data Platforms: The Right Infrastructure Strategy for AI, Resilience and Digital Sovereignty

    ‘Cloud-first’ is no longer the only strategy. Whilst cloud platforms are driving innovation and AI, on-premises and hybrid models are gaining in importance due to digital sovereignty, compliance and critical infrastructure. The panel will discuss the role that cloud, hybrid and on-premises architectures will play in the future, and how organisations can strike a balance between scalability, security, control and efficiency.

  3. Fireside Chat

    Resilience in Practice: What Leading Companies Do Differently

    What specific approaches are leading companies in the DACH region successfully implementing? This session highlights best practices, success factors and what sets pioneers apart from the rest.

    Presentation:

    Florian Jörgens Florian Jörgens  
  4.  

    16:30 Main Stage Speaker Awards Ceremony

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1. Presentation

    In preparation

  2.  

    14:00 Cybersecurity Summit Awards Ceremony 2027

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1.  

    14:00 Cybersecurity Summit Awards Ceremony 2026

    The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
    App-Download

  1. 17:15
     

    17:15 End of Cybersecurity Summit 2027

22nd April 2027 Cybersecurity Summit Day 2

09:00

Welcome

Our doors open at 9:00 a.m. - so you can start networking with your first coffee and secure the best seat.

10:00 CYBERSECURITY SUMMIT MAIN STAGE:

Opening

Opening of the event and welcome by the moderator

10:00 RESILIENCE SUMMIT MAIN STAGE:

Opening

Opening of the event and welcome by the moderator

10:00 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

10:15 CYBERSECURITY SUMMIT MAIN STAGE:
Fireside Chat

International Fire Side Chat: Cybersecurity 2030: Is true security even realistic anymore?

When AI attacks and defends autonomously, geopolitical conflicts escalate digitally and supply chains become politicised, an uncomfortable question arises: are we still striving for security – or merely for damage control?

An international panel takes an honest look ahead and discusses what strategic decisions need to be made today to ensure that by 2030 we are not just compliant, but truly resilient.

10:15 RESILIENCE SUMMIT MAIN STAGE:
Presentation

The Art of War for Talent – How to Attract, Develop and Retain the Best Security Staff

TBA

10:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

10:30 MATTERHORN MASTERCLASSES:
Presentation

In preparation

10:45 CYBERSECURITY SUMMIT MAIN STAGE:
Panel discussion

Is the SOC Dead? Autonomous Security Operations 2027

The traditional Security Operations Centre is on the cusp of a fundamental transformation. AI-powered detection, automated response playbooks and agent-based systems are taking on an increasing number of operational tasks. The key question is no longer whether the SOC is operated internally or externally – but how autonomous it can be.
This panel will discuss how ‘AI-first’ architectures, autonomous decision-making processes and new MDR models are transforming security operations. What role remains for humans in the ‘human-in-the-loop’ model? Where are the limits of automation? And when does efficiency become a new risk?
The focus is on the strategic evolution of security operations away from reactive alarm management towards adaptive, semi-autonomous cyber defence.

10:45 RESILIENCE SUMMIT MAIN STAGE:

Coffee break

Enjoy coffee and breakfast and get to know the visitors and exhibitors at the Cybersecurity & Resilience Summit.

11:00 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

Business Continuity & Crisis Management: Are we really prepared?

How do companies test their BCM strategies under realistic conditions – and where are the biggest gaps between planning and implementation? 

11:00 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

11:00 MATTERHORN MASTERCLASSES:
Presentation

In preparation

11:15 MATTERHORN MASTERCLASSES:
Presentation

In preparation

11:30 CYBERSECURITY SUMMIT MAIN STAGE:
Presentation

365 Days as a CISO: From the Initial Assessment to Managed Security

How information security can be strategically developed over the course of a year: through clear governance, effective security operations, robust IT business continuity management (BCM) and enhanced incident response processes. Honest lessons learnt from real-world transformation experience show why effective information security requires, above all, clarity regarding responsibilities, risks and operational capability.

11:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

11:30 MATTERHORN MASTERCLASSES:
Presentation

In preparation

11:45 RESILIENCE SUMMIT MAIN STAGE:
Presentation

Interactive cyber crisis simulation by the Hamburg State Criminal Police Office (LKA)

How does it feel to suddenly be responsible, as a member of a crisis response team, for the survival of a company hit by ransomware? What steps must be taken, and what pitfalls must be avoided, to weather such a crisis? Take part in the interactive crisis simulation and get a sense of the challenges posed by modern cyberattacks.

12:00 CYBERSECURITY SUMMIT MAIN STAGE:
Panel discussion

Post-Quantum Security: From Threat to Migration Strategy

The question is no longer whether quantum computers can break cryptographic methods – but how long existing systems will remain secure. As the first post-quantum algorithms are being standardised and implemented, businesses face a complex challenge: how can they migrate without operational risks?

This panel discusses concrete roadmaps for the post-quantum transformation – from crypto inventories and risk assessment through hybrid cryptography models to long-term migration strategies. The focus is on practical implementation: Which systems need to be migrated first? How significant is the ‘harvest now, decrypt later’ risk really? And how can organisations ensure that the migration itself does not become a security vulnerability?

12:15 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

AI Governance & Souveränität: How do we control what we don’t fully understand?

How do companies establish effective governance structures for AI whilst balancing innovation, risk and regulation? This session demonstrates how organisations can build control, transparency and resilience when working with AI.

13:30 ZUGSPITZE MASTERCLASSES:
Presentation

In preparation

14:00 ZUGSPITZE MASTERCLASSES:

Cybersecurity Summit Awards Ceremony 2027

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

14:00 MATTERHORN MASTERCLASSES:

Cybersecurity Summit Awards Ceremony 2026

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

14:00 PITCHUP STAGE:

Startup Awards Part 2

On our PitchUp Stage, up-and-coming startups present their smartest solutions for the cybersecurity and resilience – concise, compelling, and packed with fresh ideas. You'll find the stage right next to our Startup Area on the event floor.

 

Stop by, discover tomorrow’s innovations, and have your say: You decide which three startups will win the Startup Award!

14:45 RESILIENCE SUMMIT MAIN STAGE:
Panel discussion

Cybersecurity for Critical Infrastructure: Securing Energy & OT

Critical infrastructure, particularly in energy and OT environments, is increasingly becoming the target of targeted cyberattacks. At the same time, regulatory requirements are rising and complexity is increasing due to the convergence of IT and OT.

The panel will discuss how organisations can effectively secure their OT and ICS systems – from network segmentation and monitoring to secure IT/OT architectures. The focus will be on how security strategies need to evolve to both meet compliance requirements and ensure the stability of critical systems.

15:15 CYBERSECURITY SUMMIT MAIN STAGE:
Panel discussion

AI Agents & Autonomous Systems Security: Who controls the digital actors?

With the widespread integration of copilots, agent-based automation and self-executing workflows, new digital actors are emerging within organisations. These systems make decisions, access data and carry out actions – often with far-reaching permissions.

The panel will discuss the new security landscape: how can AI agents that act autonomously be secured? What risks arise from prompt injection, tool abuse or manipulated training data? And how can organisations prevent autonomous systems from becoming invisible attack surfaces?

The focus is on governance models for agent-based systems, identity and rights concepts for machine agents, and strategies to ensure that innovation is not achieved at the cost of losing control.

15:30 RESILIENCE SUMMIT MAIN STAGE:
Fireside Chat

Cloud, On-Premise & Data Platforms: The Right Infrastructure Strategy for AI, Resilience and Digital Sovereignty

‘Cloud-first’ is no longer the only strategy. Whilst cloud platforms are driving innovation and AI, on-premises and hybrid models are gaining in importance due to digital sovereignty, compliance and critical infrastructure. The panel will discuss the role that cloud, hybrid and on-premises architectures will play in the future, and how organisations can strike a balance between scalability, security, control and efficiency.

16:00 CYBERSECURITY SUMMIT MAIN STAGE:
Fireside Chat

Machine Identity & Non-Human Identities: The Invisible Majority on the Network

Whilst security strategies have focused on human identities for years, the number of non-human identities is growing exponentially. Workloads, containers, APIs, bots and autonomous systems are constantly communicating with one another – secured by certificates, tokens and secrets that are often created and expire unchecked.

This panel explores the growing challenges surrounding workload and API identities, secret sprawl and ‘certificate chaos’. How do organisations keep track of millions of machine identities? What role do identity fabrics, automated certificate lifecycle management and zero-trust architectures play? And how do organisations prevent expired certificates or compromised secrets from becoming systemic vulnerabilities?

The focus is on the question of how identity security can be reimagined now that machines have long since become the majority of actors on the network.

16:00 RESILIENCE SUMMIT MAIN STAGE:
Fireside Chat

Resilience in Practice: What Leading Companies Do Differently

What specific approaches are leading companies in the DACH region successfully implementing? This session highlights best practices, success factors and what sets pioneers apart from the rest.

Presentation:

Florian Jörgens Florian Jörgens  
16:30 CYBERSECURITY SUMMIT MAIN STAGE:
Fireside Chat

From Cybersecurity to Resilience: Who owns the risk?

Cyber risks are no longer purely an IT issue, but affect the entire organisation at a strategic level. With increasing regulation and a growing threat landscape, the question arises as to how companies can clearly define responsibilities and effectively allocate them between the CISO, CRO and CIO.

The panel will examine how governance models, decision-making structures and responsibilities need to be designed to manage cyber and resilience risks holistically. The focus will be on who ultimately bears responsibility – and how collaboration at C-level works in practice.

16:30 RESILIENCE SUMMIT MAIN STAGE:

Main Stage Speaker Awards Ceremony

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

17:00 CYBERSECURITY SUMMIT MAIN STAGE:

Speaker & Startup Awards Ceremony

The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download

17:15

End of Cybersecurity Summit 2027