-
CYBERSECURITY SUMMIT MAIN STAGE
-
RESILIENCE SUMMIT MAIN STAGE
-
ZUGSPITZE Masterclasses
-
MATTERHORN Masterclasses
-
08:30
-
09:15
-
10:30
-
11:00Panel discussion
Human Risk 2.0: AI, voice cloning and the new dimension of personalised attacks
People remain the biggest target – yet artificial intelligence is taking social engineering to a whole new level. Deceptively realistic voice clones, AI-generated deepfakes and hyper-personalised phishing campaigns are rendering traditional awareness training increasingly ineffective.
The panel will discuss how organisations can protect themselves against AI-enabled attacks when identities can be manipulated and communication is no longer reliably authentic. The focus will be on new defensive approaches, ranging from identity verification and zero-trust communication to organisational safeguards that go beyond mere training.
Presentation:
Isabelle Ewald
BDO
-
11:45Presentation
Brain–Computer Interfaces: Emerging Implications for Law Enforcement and Public Security
Brain–Computer Interfaces are moving from lab to street, turning the human brain into a new data source and marking the shift from cyber-security to neuro-security. This keynote examines what BCIs mean for policing and justice — the opportunities, the threats of neural-data misuse, and the human-rights stakes around mental privacy and cognitive liberty — and makes the case for legal boundaries, oversight, and international cooperation before neuro-enabled crime arrives.
-
Panel discussion
09:30 Digital Sovereignty & Cyber Warfare: Strategic Resilience in the Geopolitical Age
Cyberattacks have long been part of geopolitical power shifts. Both states and businesses face the challenge of safeguarding their digital sovereignty – in a world where supply chains, cloud infrastructures and data flows are globally intertwined.
The panel will examine how organisations can arm themselves against state-sponsored cyberattacks whilst simultaneously reducing technological dependencies. Discussions will focus on strategies relating to sovereign cloud, data sovereignty, critical infrastructure and the question of how much digital independence is realistic and economically viable.
Presentation:
Lisa Fröhlich
Women4Cyber Germany / Link11
-
Panel discussion
10:30 NIS2, DORA, CRA: Lessons learnt from the first wave of implementation
With NIS2, DORA and the Cyber Resilience Act, the EU has made cybersecurity a regulatory obligation at board level. But what does implementation look like in practice? Which requirements have actually made companies more resilient, and where have new operational or legal challenges arisen?
The panel takes stock of the situation so far: from liability issues and reporting obligations to supply chain requirements and organisational changes in security and governance. The focus is on whether regulation has led to a measurable increase in security – or, above all, has simply increased the pressure to comply.
-
Panel discussion
11:45 API Security & Application Layer Security: The new battleground beyond the perimeter
Attacks are increasingly shifting from the network layer to APIs, applications and SaaS platforms. Rather than bypassing firewalls, attackers now target business logic, identity models and flawed API implementations. Modern architectures featuring microservices, cloud-native environments and third-party integrations massively expand the attack surface.
The panel will discuss how organisations can holistically secure API ecosystems – from runtime protection and API discovery to authentication and authorisation models in a zero-trust context. The focus will be on how application-layer security can be reimagined when traditional network boundaries no longer provide protection.
-
Presentation
11:00 Masterclass Formalize
Well-known vulnerabilities, such as Log4Shell and PrintNightmare, impressively demonstrate what we can learn from previous attacks for tomorrow's cyber defense.
Key topics:
- Zero Days in Reality Check: What known exploits reveal about today's threats.
- When vulnerabilities collide: Understanding combined attack scenarios.
- Structured endpoint management: Inventory, analyze, patch.
- Unified endpoint management: Simplify processes, reduce risks, secure standards.
- Blueprint for sustainable resilience: Which measures are crucial now?
-
12:15
-
14:00
-
15:15Panel discussion
Defensive AI vs. Offensive AI: Who controls autonomous systems?
Artificial intelligence is no longer merely a tool, but an active player in cyberspace. Whilst defensive AI detects anomalies in real time, automates incident response and enables security operations centres to operate with increasing autonomy, attackers are developing AI-powered exploits, generative malware and adaptive attack campaigns that dynamically adapt to defensive mechanisms.
The panel will examine the new reality of an AI-driven arms race: just how resilient are autonomous SOCs really? Will AI agents themselves become a target? And how great is the risk posed by model manipulation, data poisoning or prompt injection? The discussion will focus on where automation makes sense, where human control remains indispensable, and whether we are heading towards a future in which machines fight each other whilst humans merely monitor.
Presentation:
Nico Freitag
Cybersecurity ist Chefsache
-
16:00
-
16:15Panel discussion
Supply Chain Security & Software Liability: Who is liable when trust becomes a vulnerability?
Digital supply chains have long since become a strategic target. With NIS2, the Cyber Resilience Act and stricter transparency requirements, the focus is increasingly shifting from technical security to the issue of responsibility and liability. Today, companies must not only manage third-party risks, but also ensure that their entire software and OT landscape is resilient and ‘secure by design’.
The panel will discuss how supply chain security, software liability and regulatory requirements can be implemented in practice – from SBOMs and open-source risks to the protection of critical infrastructure. The focus will be on how trust in networked ecosystems must be redefined when it can become the greatest vulnerability.
Presentation:
Thomas Heine
SDG media
-
17:00Presentation
Logging, yes – but how do you analyse the data? Why cybersecurity reporting in the public sector is a legal issue before it becomes a statistical one
Authorities log data, monitor networks and analyse threat intelligence – NIS2 makes this mandatory. But are authorities also permitted to demonstrate that their security measures are actually effective? This is precisely where a gap exists that is rarely discussed in practice. Using Bavaria as an example, the presentation demonstrates just how precisely the BayDiG regulates monitoring by the State Office for Information Security – with a narrow purpose, strict retention periods and clear boundaries. Surprisingly, even the State Office itself comes up against these boundaries as soon as it seeks to quantify its own successes: how many attacks have been thwarted, and how effective are the measures in place?
The presentation explores whether a new legal basis is required for this, or whether the more pragmatic approach is closer at hand than one might initially think. It is precisely this precision that becomes a challenge as soon as other authorities wish to use the same data to evaluate the effectiveness of their security measures: is the GDPR sufficient for this? Is a different legal basis required? And where does Article 89 of the GDPR, with its requirements on anonymisation and pseudonymisation, come into play? A look at Hesse and Baden-Württemberg shows that the Bavarian example is not unique. The presentation provides clear, practical guidance for anyone who wishes to view cybersecurity monitoring and data protection not as opposing concepts, but as a task to be tackled jointly.
-
17:30
Speaker & Startup Awards Ceremony
The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download
-
Panel discussion
14:45 Measuring Resilience: What KPIs actually matter?
How can resilience be measured and managed in practice at management level? The panel will examine which KPIs are truly relevant, outline practical approaches to assessment, and discuss how companies can improve their resilience using data-driven methods.
Presentation:
Nadia Patricia Stefan
Cybersecurity & Executive Coach
-
Panel discussion
16:15 Resilient Software Architecture: Who owns security by design?
Modern software architectures play a decisive role in determining how resilient organisations are to cyber risks. At the same time, the lines of responsibility between development, security and business are becoming increasingly blurred.
The panel will discuss how organisations integrate ‘security by design’ and resilience into their architectural decisions – from microservices and cloud-native solutions to platform strategies. The focus will be on who bears responsibility: does it lie with engineering, security or the business – and how can clear ownership and effective collaboration be established?
-
Presentation
17:00 Just Culture: Dealing fairly with actions that jeopardise safety
Sanctions are the enemy of a good error culture, but in everyday life people still like to look for and punish the guilty. The presentation explains the principle of "Just Culture". IT and other types of industry can still learn a lot from healthcare and aviation in this respect. An error model and tools such as "Critical Incident Reporting Systems" will be presented, which can be used to develop a safety culture. The presentation provides a look over the shoulder at ECE, where employees are involved in terms of (IT) security culture, errors are reported in fuck-up sessions and a mascot supports the CISO.
-
17:30 Main Stage Speaker Awards Ceremony
The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download
-
17:30 Cybersecurity Summit Awards Ceremony 2027
The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download
-
17:45 Cybersecurity Summit Awards Ceremony 2027
The best speakers on our stages are to be honored. You decide which speakers you found particularly inspiring, charismatic and innovative. At the end of the day, we will honor the best speaker of the day on each stage. Voting takes place via our app. Access is via your ticket code.
App-Download.