Cyber Security Executive

11.3.2027 | hybrid: HYPE Areena, Espoo

Program

Thursday 11.3.

08:30

We open the doors – Welcome!

09:00

Opening remarks by our moderator

Jesse Kamras
Jesse Kamras Journalist, News Reporter
09:10
KEYNOTE

What Breaks First? The Assumptions Technology Leaders Must Revisit for 2027

  • The assumptions today’s cyber strategies are still built on — and which of them no longer hold
  • How AI agents, identity and digital concentration are changing the enterprise threat model
  • What happens when critical suppliers, cloud infrastructure or trusted digital services become unavailable
  • Where efficiency has quietly created fragility across the digital ecosystem
  • The decisions executives must make on redundancy, sovereignty, control and acceptable failure
09:45

The 30 Minutes Before a Cyber Crisis Becomes a Business Crisis

  • What a realistic executive red team exercise reveals before the full impact is known
  • How an attacker moves from identity compromise to operational disruption
  • The decisions that cannot wait for perfect information
  • Where authority, escalation and communication typically break down
  • What simulation findings should change at board and executive level
10:05

Networking Break

10:40
KEYNOTE

When AI Starts Acting: Securing the Agentic Enterprise

  • What changes when AI can act, approve, purchase, modify and execute across business systems
  • Governing agents, service accounts and other non-human identities at enterprise scale
  • How autonomous workflows challenge access control, segregation of duties and accountability
  • Protecting sensitive data across models, prompts, retrieval systems and integrations
  • The decisions CIOs and CISOs need to make before agent adoption outruns control
11:10

Beyond Zero Trust: Proving That Your Controls Actually Work

  • Why architecture principles and security frameworks are not evidence of protection
  • Continuously validating whether access, segmentation and detection controls perform as intended
  • Human, machine and AI-driven interactions inside the same assurance model
  • Finding the gap between controls that exist on paper and controls that stop real attack paths
  • What evidence executives should demand before accepting residual cyber risk
11:30

Lunch Break & Networking

12:30

What Actually Reduces Cyber Risk? Where the Next Euro Should Go

  • Why adding security tools can increase complexity without materially reducing risk
  • Which capabilities genuinely change exposure, detection and recovery outcomes
  • Exposure management, detection engineering, threat intelligence and response quality
  • Separating measurable risk reduction from security activity
  • How leaders should decide where the next increment of cyber investment creates the greatest return
12:50

The Attack Surface Nobody Owns: OT, IoT, SaaS and Forgotten Digital Dependencies

  • How IT, OT, IoT, SaaS and business-owned technology create one interconnected attack surface
  • Where accountability disappears between security, operations, procurement and business units
  • Why unknown assets and unmanaged integrations become crisis accelerators
  • How procurement and technology decisions create cyber exposure years before an incident
  • The executive questions that expose dependencies nobody realized they owned
13:10

The Death of “Seeing Is Believing”

  • Deepfakes, voice cloning and synthetic identities as cyber weapons
  • Why executives and privileged users are becoming high-value social engineering targets
  • How AI makes personalised manipulation cheap and scalable
  • When verification processes matter more than employee awareness
  • Designing critical decisions for a world where digital identity can be convincingly faked
13:30

Networking Break

14:00

When Cybersecurity Becomes a Product Requirement: The Business Impact of CRA

  • What changes when cyber resilience becomes part of product responsibility rather than only enterprise security
  • How vulnerability management, software components and supply-chain visibility move into the product lifecycle
  • Where security responsibility sits between product, engineering, procurement, legal and cyber leadership
  • How cyber requirements begin to influence supplier selection, product design and market access
  • What executives should have resolved before the Cyber Resilience Act reaches full application in 2027

 

 

14:20

The Cyber Leader’s Mandate for 2027: Decision Rights, Capital and Business Resilience

  • Why cyber leaders need decision rights, not responsibility without authority
  • How CISOs should influence capital allocation, transformation and strategic technology choices
  • Building cyber capability across the enterprise instead of expanding only the security organization
  • Turning cyber reporting into decisions about risk, resilience, investment and growth
  • What executive cyber leadership must become as AI, regulation and digital dependency reshape the business
14:45

Leading Through the Next Wave of Disruption

15:20

Closing Summary by Our Moderators

Jesse Kamras
Jesse Kamras Journalist, News Reporter