Agenda / Day

Monday, 21 September, 2026 / 05:00 PM - 07:30 PM GMT

Harbour 1

Registration and Information

Registration and Information hours for the day.

Tuesday, 22 September, 2026 / 07:30 AM - 06:00 PM GMT

Foyer

Gartner Showcase

Discover cutting-edge tools, diagnostics and actionable resources at the Gartner Showcase. Visit our demo space for a personalized walkthrough of our business and technology insights platform and learn how Gartner's leading tools like Third-Party Cybersecurity Insights Platform, Cybersecurity Controls Assessment, and Cybersecurity Business Value Benchmark can help you make faster, smarter decisions on your mission-critical priorities.

Tuesday, 22 September, 2026 / 07:30 AM - 06:45 PM GMT

Harbour 1

Registration and Information

Registration and Information hours for the day.

Tuesday, 22 September, 2026 / 09:30 AM - 10:15 AM GMT

Auditorium

Gartner Opening Keynote: Seize the Moment

It feels like everything is happening, everywhere, all at once. But amidst the chaos, there are opportunities, “moments” that we can seize, to ensure Cybersecurity’s success. What if we could use our organizations’ rush to AI as an opportunity to modernize both human and machine identity? What if we could turn the inevitability of cyber-attacks into a learning cycle that continuously makes us smarter, stronger, faster and more resilient? What if we could monetize our innovation with a cycle of continuous learning to fund even more innovation?  Join this keynote and learn how to seize these moments!

Tuesday, 22 September, 2026 / 10:15 AM - 11:00 AM GMT

Exhibit Showcase

Refreshment Break

Join us on the Exhibit Showcase, Level 0 for coffee, tea, and some light snacks in a brief break between sessions. Please click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367590_15367590.pdf) to see our refreshment break menu.

Tuesday, 22 September, 2026 / 10:15 AM - 06:45 PM GMT

Exhibit Showcase

Exhibit Showcase Open Hours

Visit the Exhibit Showcase to evaluate industry offerings that can move your business forward. Engage with your peers, Gartner analysts, and exhibitors. Attend a theater session to see technology in action.

Tuesday, 22 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 1, Exhibit Showcase

Kroll: Six Cyber Risk Domains Every Board and CISO Should Prioritize

Responding to 1,000+ cyber incidents annually gives Kroll a frontline view of how attacks succeed. Drawing on patterns from real-world compromises, Kroll identified six intelligence-informed risk domains. This session explains why they matter to Boards and CISOs and offers practical guidance for prioritizing investment and building resilience based on adversary behaviour and business impact not compliance checklists alone.

Tuesday, 22 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 2, Exhibit Showcase

Vanta: Trust at Scale — Building More Resilient Security and Risk Operations

As security programs scale, fragmented controls, regulatory demands & third-party risk make trust harder to maintain. In this practitioner-led session, Vin Arora, VP of Information Security at Crown Agents Bank, will share how they are evolving compliance, audit readiness, risk management & vendor oversight in a regulated wholesale bank. He will discuss lessons from moving beyond point-in-time audits toward more scalable, visible risk operations.

Tuesday, 22 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 3, Exhibit Showcase

NinjaOne: Time is the Vulnerability You Are Not Measuring

Getting visibility into which endpoints need patching and striking the balance between the security risk of not installing updates and the operational risk of endpoint failure when you do has always been a challenge for IT and Security teams. In this session, you'll learn how you can confidently shrink the vulnerability window of unpatched endpoints whilst lowering the risk of disruption.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Auditorium

Future of AI in Cybersecurity: AI Predictions and Roadmap Guidance for 2026-2029

Everyone knows what the future holds for AI and Cybersecurity, except it changes every week. Planning for long term success seem impossible yet cybersecurity teams must do it. This session delves into key AI predictions and current challenges, providing CISOs with actionable insights to build effective and resilient three-year roadmaps. Learn how to optimize AI initiatives for cybersecurity and adapt security programs to align with future business uses.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Capital Suite 15

Outlook for Cyber-Physical Systems Security: Adapt to New World Realities

Cyber-physical systems (otherwise referred to as OT) have become ubiquitous in today’s society. More and more "smart" assets are deployed to connect the digital to the physical world. This session will provide security leaders with insights on topics such as the security implications of this trend, the role of regulators and whether any best practices are emerging.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Maritime Suite 10

Outlook for Data Security: Going from Reactive to Resilient

Many organizations find it challenging to move beyond reactive data security measures despite increasing threats and regulatory pressures. This session outlines a strategic approach to maturing toward a posture of resilience through data-centric security, leveraging AI-driven adaptive controls and strengthening incident response and business continuity.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Maritime Suite 9

Outlook for Identity and Access Management: Elevate IAM With Identity-First Security

Identity has become the de-facto organization perimeter and the primary control plane for cybersecurity amid the shift to cloud and the rapid adoption of AI technologies. Modern IAM strategies enhance cybersecurity and reduce the business friction associated with legacy cybersecurity controls. Cybersecurity leaders must transform IAM from a tactical or checkbox exercise into a key pillar of cybersecurity strategy.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Capital Suite 10

What Public Sector Leaders Are Getting Wrong About AI (And What They Must Do Now)

Public sector AI investments often fail to deliver ROI due to a narrow focus on buying tools and ill-defined goals, exposing them to backlash from political leaders. Technology leaders must shift to an ecosystem-focused AI strategy — that advances D&A and aligns contracts, talent and governance — to drive real mission impact.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Maritime Suite 25

3 Steps to Building a Solid Postquantum Plan

The move to postquantum cryptography will be a companywide effort that will affect every part of data security, cloud management, I&O, IAM and most other systems. But, with a problem so large, where should you begin? In this session, we will go over the three initial steps that will form a solid foundation for ongoing efforts in the transition, promoting a scalable, smooth process over the next two years.

Tuesday, 22 September, 2026 / 11:00 AM - 11:30 AM GMT

Maritime Suite 26

Outlook for SOC: The Ultimate Cybersecurity Remix

The era of the siloed SOC is over. To handle modern threats, security leaders must integrate Incident Response, Threat Hunting, and Exposure Management into a single, synchronized ecosystem. This session will outline the strategic roadmap to the "Ultimate Cybersecurity Remix," where diverse security areas work together to extract maximum value from existing investments.

Tuesday, 22 September, 2026 / 11:00 AM - 11:20 AM GMT

Theater 1, Exhibit Showcase

Magic Quadrant for Security Information and Event Management

The SIEM market is evolving at an unprecedented rate. This presentation discusses the latest SIEM Magic Quadrant, and what forces and trends are disruptive to the SIEM market. This presentation is for cybersecurity leaders looking to reevaluate their SIEM strategy and understand what key capabilities are required from modern SIEM.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Maritime Suite 10

SentinelOne: Innovation Without Risk — The AI Governance Starting Point

AI adoption is accelerating. So is the risk. This session explores the critical visibility gaps most organizations are missing today - agent identity, runtime behavior, and data lineage and offers a clear starting point for governing AI in a way that makes every action attributable, auditable, and recoverable. Security is not the friction slowing AI down. It is the foundation that makes innovation sustainable.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Capital Suite 12

Cloudflare: Markerstudy's Secure Path to Enterprise AI

Markerstudy modernised its network security to scale enterprise AI safely. In this case study, we share the real-world friction of legacy architectures and how stripping away complexity reduced latency. You will learn how to design a secure network foundation, evaluate security-versus-agility trade-offs, and implement practical controls to accelerate AI adoption across your enterprise without introducing technical debt.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Maritime Suite 25

Safe: Life After Mythos - How Hundreds of AI Agents Manage Millions of Vulnerabilities Daily

Mythos proved AI can find vulnerabilities faster than any human team can fix them. Now defense must catch up. This session introduces Agentic Vulnerability Management: hundreds of specialized AI agents that reason over enterprise context, correlate internal and third-party exposures, prioritize by exploitability and business impact, and autonomously execute remediation. Includes a live demo of AI agents managing enterprise findings end-to-end.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Maritime Suite 24

Google Chrome Enterprise: Securing the Modern Browser in the AI Era

As AI shifts the security perimeter to the browser, legacy network controls struggle against evolving threats. Drawing from Google's 2026 Cybersecurity Forecast, this session explores emerging risks and how to strengthen security with Chrome Enterprise Premium. Learn practical approaches to govern browser security, apply Zero Trust, improve visibility, and secure AI adoption while managing operational complexity.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Capital Suite 10

Darktrace: Guardrails Break — Defense in Depth for Non-Deterministic AI

Organizations are deploying AI agents into production faster than security operations can adapt. Non-deterministic AI introduces a new attack surface across prompts, agents, data pipelines, toolchains, and runtime behaviour. This session presents a defense-in-depth model for securing AI built around the realities of runtime behaviour, using NIST's Secure / Defend / Thwart framing.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Maritime Suite 27

Cyera: Secure AI Future, Now

AI runs on data. As companies move from generative AI to copilots, agents and agentic workflows, risk expands across data, access, and action. Scaling AI securely shouldn't pit protection against progress, yet only 14% of security leaders succeed at both. Yuri reveals the shift enterprises are making: from fragmented AI controls to a unified, data-centric approach that discovers AI assets, governs identities, and enforces guardrails in real time.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Maritime Suite 26

Netskope: AI Authority Drift — Closing the Governance Gap

Agentic AI doesn't wait for policy. It expands its own permissions, chains actions, and makes decisions at machine speed, often faster than governance can react. Netskope's CDIO Mike Anderson breaks down how authority drift opens the governance gap and what a real AI control plane looks like at enterprise scale. Leave with a clear view of which risks to contain first and the governance model built to scale with them.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Maritime Suite 9

Zscaler: The SecOps Revolution — How AI and Agentic Technology Are Changing Security Forever

AI is reshaping security. As attackers move faster and hide better, teams embracing agentic tech respond at machine speed, replacing manual logs with smart response. This SecOps shift is as significant as DevOps was for engineering. Join Zscaler CISO Sam Curry for a practitioner's view of how AI is changing the threat landscape, practical examples of agentic operations in action, and a roadmap for the modern SOC.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Auditorium

Palo Alto Networks: Anatomy of an Agentic Breach — You Make the Calls

08:40 - a developer ships an AI agent on an unscanned model. 16:00 - your SOC closes the alert as expected behaviour. In between, it was hijacked and your data walked out. We replay the day hour by hour. Six signals were there. Most organisations miss all six. During the session you will make the calls in real time, see how the room compares, then watch where the chain breaks. Leave with a 90-day plan and an honest benchmark against your peers.

Tuesday, 22 September, 2026 / 12:00 PM - 12:30 PM GMT

Capital Suite 15

Proofpoint: The Agentic Enterprise — Securing Humans, Data, and AI at Scale

AI agents now access, generate, and move data with human-level privileges but limited oversight. Attackers exploit this gap, targeting people, data, and AI workflows together. Learn three critical priorities: controlling what AI systems can access and reuse, detecting threats across email, collaboration, and AI workflows, and treating agents as insiders with enforceable policy and accountability.

Tuesday, 22 September, 2026 / 12:30 PM - 02:15 PM GMT

Harbour 5, Anchor & Exhibit Showcase

Grab Lunch at Harbour 5, Anchor or the Grab 'n' Go Cafe in Exhibit Showcase

Join us at Harbour 5 & Anchor, Level 1 to network with your peers and make new connections over a seated lunch. Alternatively, head to the Exhibit Showcase for a Grab & Go lunch! Engage with your peers, Gartner Analysts, and exhibitors while enjoying delicious food and beverages. Click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367551_15367551.pdf) to view the seated lunch menu. Click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367575_15367575.pdf) to view the Grab & Go Café menu. For specific dietary needs, please visit the dietary table located in Anchor for further details and assistance.

Tuesday, 22 September, 2026 / 12:45 PM - 01:15 PM GMT

Maritime Suite 26

Cybersecurity's Basic Questions Preparing Every AI Initiative for AI Laws

Using AI for the sake of using AI is ill advised, we know this now. However, after a decade of privacy and data protection laws, the coming decade will see similar AI law requirements. Although there are many details necessary to observe, taking a step back and approaching every intended AI usage consistently the same, will not only prevent guaranteed failure but also set you up for potential success. Attendees will walk away with five universal requirements, before diving into details.

Tuesday, 22 September, 2026 / 12:45 PM - 01:15 PM GMT

Maritime Suite 25

Pentesting the Organizations Future

Security leaders rely on penetration testing to identify and address security vulnerabilities before malicious actors can exploit them. By adopting a futurist perspective, organizations can strengthen their security posture and reduce the risk of breaches both in the near term and over the long term.

Tuesday, 22 September, 2026 / 12:45 PM - 01:15 PM GMT

Maritime Suite 24

Drive Down Costs and Improve Security: Your Guide to Successful Vendor Consolidation Projects

As security gets more complex and budgets get tighter, more CISOs are considering security vendor consolidation projects as a way to improve security outcomes and budget bottom lines. This session will explore top practices for achieving a successful security vendor consolidation project. We will also discuss the future of the security solutions market, with an emphasis on how to evaluate emerging security platforms.

Tuesday, 22 September, 2026 / 12:55 PM - 01:15 PM GMT

Theater 1, Exhibit Showcase

ProcessUnity: HyperTPRM and Rethinking Third-Party Risk

Third-party risk management is at a breaking point. Vendor ecosystems outpace risk teams, signals are fragmented, and traditional methods can't keep up. HyperTPRM offers a modern approach: data-first intelligence, workflow, community-powered exchange, and AI acceleration with human confirmation. Learn how organizations are evolving TPRM to prioritize vendors dynamically, reduce friction, and shift to continuous, risk-based monitoring.

Tuesday, 22 September, 2026 / 12:55 PM - 01:15 PM GMT

Theater 2, Exhibit Showcase

Dragos: AI Is Already in OT - Is It Disrupting, Attacking, or Defending Your Physical Process?

AI is entering operational technology environments, creating visibility gaps and operational risk in systems that must not fail. At the same time, AI is accelerating attacks on critical infrastructure. OT-native AI, built on OT-specific intelligence and context, changes what defense can do. This session examines all three dimensions: where AI creates risk, where it amplifies threats, and what it makes possible for defenders.

Tuesday, 22 September, 2026 / 12:55 PM - 01:15 PM GMT

Theater 3, Exhibit Showcase

DataBee®, A Comcast Company: 8 Concrete Actions for Agentic AI Governance

Frontier AI is reshaping the attack surface faster than most GRC programs can adapt. A pilot promised to cut reporting time in half and looked successful, until someone asked a question no one could answer. The cause wasn't the AI model, it was ungoverned data and ownership. This session moves past the hype cycle to give CISOs and GRC leaders eight concrete actions, from asset inventories to unified data, so agentic AI doesn't outrun governance.

Tuesday, 22 September, 2026 / 01:20 PM - 01:40 PM GMT

Theater 1, Exhibit Showcase

Tines: Your employees are using AI. Do you know what they're building?

Shadow AI isn't a future risk, it's happening right now. Employees across your organization are pasting sensitive data into AI tools, generating code with security flaws, and deploying workflows with zero oversight. In this session, we'll show how Tines gives every team a secure place to build with AI confidently, while security retains the visibility and control to govern it.

Tuesday, 22 September, 2026 / 01:20 PM - 01:40 PM GMT

Theater 2, Exhibit Showcase

XBOW: Keeping Agents on Track

Frontier AI models are becoming more capable, autonomous, and persistent. But giving agents the freedom to reason and act also creates a fundamental challenge: how do you keep them from going somewhere or doing something they shouldn’t? Operating autonomous offensive security agents in production forced us to confront this problem early and build a defense-in-depth safety architecture around it.

Tuesday, 22 September, 2026 / 01:20 PM - 01:40 PM GMT

Theater 3, Exhibit Showcase

BeyondTrust: Seeing Every Identity. Securing Every Path — IVIP in Practice

Most organizations invest heavily in IAM tools but still struggle to map true access. Move beyond marketing to explore the operational reality of identity visibility. This session examines the internal friction and technical obstacles of mapping complex access paths. Attendees will leave with a concrete framework to assess their posture, move past merely provisioned access, and secure the access that actually exists in their environment.

Tuesday, 22 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 26

Cloud Security as a Sovereignty Enabler

With the rise of geopolitical tensions in the world, organizations are increasingly questioning where their data resides, how they can protect it and under which jurisdiction it falls. This session explores the evolving concept of cloud sovereignty and its key pillars and how cloud security can be an enabler.

Tuesday, 22 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 27

Ransomware Reloaded: How AI Is Reshaping the Threat and the Defense

As AI rapidly advances, it is transforming the ransomware landscape, empowering both attackers and defenders. This session explores how threat actors use AI to accelerate the success of their cyberattacks, while security leaders turn to AI tools for faster detection and response. This session offers a look at the evolving AI-powered threat environment and provides actionable insights on adapting defenses, updating playbooks and preparing for the next generation of intelligent cyber extortion.

Tuesday, 22 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 25

Fast-Track Your Data Classification Efforts in 3 Steps

As GenAI becomes increasingly widespread, data classification remains a critical process to secure data that powers models. However, its success if often hindered by perceptions that classifying all organizational data is impractical, and that data owners are either unable or unwilling take on the task. Come to this session to learn how CISOs can address these perceived barriers and accelerate their classification initiatives by leveraging user education, automation and risk-based approaches?

Tuesday, 22 September, 2026 / 01:45 PM - 02:05 PM GMT

Theater 1, Exhibit Showcase

GitHub: What Four Times More Alerts Teach Us About Agentic AppSec

Alert volume is already surging as AI changes how software gets written. More findings alone will not make organizations safer; they can bury teams and erode developer trust. This session uses the agentic SDLC as a front-line case study for moving from static severity queues to a living view of exploitable risk, where AI helps cut noise, expose attack paths and prove progress.

Tuesday, 22 September, 2026 / 01:45 PM - 02:05 PM GMT

Theater 2, Exhibit Showcase

Saviynt: Ride the AI Wave Confidently with Identity Security

Identity security now secures human, machine, and agent identities. Reshaped by AI, key 2026 forces include platformization 2.0, Model Context Protocol (MCP) for interoperability, modern machine IAM, visibility/intelligence, and AI governance. Join this session to explore the top 2026 identity trends leaders must master to drive secure, identity-led business in the age of AI.

Tuesday, 22 September, 2026 / 01:45 PM - 02:05 PM GMT

Theater 3, Exhibit Showcase

Thales: How Vodafone Secures Its Digital Future by Reducing API Risk

Vodafone’s APIs power complex digital services globally. This session reveals why API security shifted to a strategic priority, explores top challenges like visibility and runtime protection, and shares real-world risk management successes. Learn how AI adoption reshapes API security needs and gain expert advice for leading enterprise API-security programs amid evolving threats.​

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Auditorium

Leadership Vision for 2026: Cybersecurity and Risk Management

Cybersecurity leaders are key enablers of digital business and are accountable for helping the enterprise balance associated risks and benefits. This “Leadership Vision for 2026” helps SRM leaders plan for 2026 and develop presentations for leadership, peers and teams.

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 25

Outlook for Cybersecurity Threat Landscape: Prioritizing Threats With Gartner's ThreatScape

The cybersecurity threat landscape is a moving target. Organizations cannot address all threats due to resource limitations and need proven ways to prioritize their investments. Gartner's updated ThreatScape for 2026-2027 enables organizations to optimize their prediction and prevention, enhance detections, and prepare for new and emerging threats.

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Capital Suite 15

Outlook for Application Security: Elevating Maturity Amid AI Disruption

Application security maturity remains low despite its critical role in data breaches. As organization race to harness AI in development and applications, they face a rapidly evolving risk landscape, while trying to mature their application security programs. This session provides an overview of the most important elements of an application security strategy.

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 10

Harnessing Reference Architectures to Drive Security Innovation and Modernization

Defining reference architectures for security capabilities helps accelerate and deploy often complex layered defenses repeatedly as needed. This session presents a case study using a capability model which helps define requirements fulfilled by security capabilities in Gartner’s reference architecture briefs and resource center.  These resources present leading approaches to security which help clients to identify, innovate and modernize their organization’s future-state security approach.

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 9

The Revolution Will Not Be Televised: Adapting Agentic AI Into Your Application Security Practice

AI is everywhere and in seemingly in everything. What impact is it having in application security? Can I finally forget about AppSec and just let AI do all the work? Short answer: No, but there are a number of ways Agentic AI is showing up in AppSec that you can leverage today. In this session we'll go over some of the current uses of AI in AppSec, what is on the horizon, and how IT leaders can evaluate and leverage this today.

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 26

From Strangled to Strategic: 5 Steps for CISOs to Master Cyber Regulations

Today, CISOs are increasingly challenged by the growing complexity and volume of cyber regulations, which can overwhelm resources and hinder strategic progress. This presentation will examine the regulatory landscape, highlight common pain points and provide practical approaches for managing compliance without sacrificing security objectives. Learn how to prioritize regulatory requirements, streamline compliance efforts and develop strategies to remain agile and effective in a highly regulated environment.

Tuesday, 22 September, 2026 / 02:15 PM - 02:45 PM GMT

Capital Suite 10

Executive Story: The Journey of Outcome-Driven Metrics in a Telco

Telia Company, a major player in the telecommunications sector, recognized how Gartner’s framework: Outcome-Driven Metrics (ODM) could be a valuable change to the traditional security metrics, as well as being a valuable supplement to existing KPI’s and security controls assessments. The presentation will offer valuable insights into Telia’s complex and fascinating Outcome Driven Metrics (ODM) journey, beginning from a point of limited visibility and progressing to the achievements realized today. Highlighting key learnings along the way and additional perspectives on ODM for the future.

Tuesday, 22 September, 2026 / 02:15 PM - 02:35 PM GMT

Theater 1, Exhibit Showcase

Magic Quadrant for SASE Platforms

This session describes Gartner’s Magic Quadrant and Critical Capabilities for Single-Vendor SASE. Take a look at Gartner’s Magic Quadrant covering SASE platforms. SASE platforms deliver converged network and security capabilities to connect and secure distributed users, devices, and locations to resources in the cloud, edge, and on-premises.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Auditorium

Horizon3: Go Hack Yourself. With AI.

Attackers move at machine speed. Most defenders test annually and drown in scanner noise. So “Are we secure?” is a guess—until the bad guys answer it. See what 250,000+ production-safe autonomous pentests across 6,000+ environments uncover: domain compromise without CVEs, EDR bypass via stolen credentials, and what’s actually exploitable. Learn to Hack-Fix-Verify continuously—with AI for proof and scale, not magic.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Maritime Suite 24

IBM: The Next Era of Cybersecurity - From Automation to Autonomous Security

AI is reshaping cyber risk faster than traditional security can adapt. As attackers operate at machine speed, companies need a new operating model. Discover how Autonomous Security combines trusted AI with human expertise to enable resilient, AI-powered enterprises. Key takeaways:  ·  The evolution from Automation to Autonomous Security.  ·  Practical actions organizations can take today to prepare for the next generation of cyber threats.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Capital Suite 15

Rubrik: The Mirror Law– Frameworks for Resilient Decision-Making

Enterprise AI assumes teams will be faster and smarter, but real-world data shows professionals often become less effective as AI expands information surfaces beyond human cognition. This session explores the friction of AI-assisted decision-making. Attendees will learn to identify cognitive overload, apply the Mirror Law framework, and implement practical strategies to keep their organizations resilient under pressure.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Maritime Suite 27

Mimecast: Securing the AI Attack Surface — From Shadow Tools to the Human Layer

AI has expanded the enterprise attack surface faster than any technology in a generation, and most security programs still address it one risk at a time. From shadow AI and embedded copilots to MCP servers and autonomous agents, the existing stack was not built for this new reality. The human behind every AI system adds critical context that changes everything. This session gives CISOs a unified framework for managing AI risks and where to start.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Capital Suite 10

Commvault: From Data Risk to Clean Recovery — A Playbook for Operational Resilience

Cyber threats, AI and expanding data risk are increasing operational risk faster than most security programs can adapt. For CISOs, resilience requires more than detection and response. It demands visibility into critical data, stronger governance and a clear path to trusted, clean recovery. Join us to explore a practical playbook to reduce data risk, improve decision-making and strengthen recovery confidence.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Maritime Suite 9

Crowdstrike: Hello, Are There Any Humans Out There? How Adversaries Use AI Against You

AI is accelerating the adversary, but speed is only part of the story. CrowdStrike’s 2026 Threat Hunting Report reveals how attackers exploit trust across identity, cloud, AI and supply chains. SNARKY SPIDER moved from account takeover to data theft in under 5 minutes. AI agent-triggered detection leads occur at 2.5x the rate of human triggered leads. Learn how to hunt and stop adversaries before trusted technology becomes their advantage.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Maritime Suite 10

ServiceNow: Autonomous Defense - Redefining Security When Threat Actors Never Sleep.​

Your defenses operate at human speed. Your attackers operate at machine speed. That gap isn't widening - it's collapsing, and the security teams caught in the middle are losing. The answer is not better detection alone. It is security architected as an action platform. Human-speed workflows create dangerous lag between finding and fixing vulnerabilities, and that gap is where breaches happen. Five AI-powered capabilities close it.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Maritime Suite 26

Cisco: Security at Agentic Scale - Protecting Networks When Apps and Attackers Use AI

As enterprises deploy AI agents and attackers leverage AI to increase the speed and scale of attacks, security must evolve. This session explores the unified vision of Cisco and Splunk for Agentic Security and the Agentic SOC. Discover how to govern identity, protect apps, and drive detection at machine speed through identity-first access, distributed security, and AI-powered operations.

Tuesday, 22 September, 2026 / 03:15 PM - 03:45 PM GMT

Capital Suite 12

SecurityScorecard: Modernising TPRM — Building a Continuous, AI-Accelerated Program

Annual assessments can’t keep pace with threat actors. With supply chain incidents driving 48% of breaches, and pressure from DORA and the UK Cyber Resilience Bill, security leaders must move beyond static reviews. Learn how forward-thinking teams use real-time intelligence and AI automation to eliminate the blind spots of annual snapshots, drastically reduce manual effort, and shift to an always-on risk function to stay ahead of threats.

Tuesday, 22 September, 2026 / 03:45 PM - 04:15 PM GMT

Exhibit Showcase

Refreshment Break

Join us on the Exhibit Showcase, Level 0 for coffee, tea, and some light snacks in a brief break between sessions. Please click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367661_15367661.pdf) to see our refreshment break menu.

Tuesday, 22 September, 2026 / 03:50 PM - 04:10 PM GMT

Theater 1, Exhibit Showcase

Chainguard: Surviving the Vulnpocalypse – Supply Chain Security in a Post Mythos World

Software security has fundamentally changed. AI is accelerating vulnerability discovery, collapsing the window between disclosure and exploitation, and putting sophisticated attack capability in the hands of a far wider set of adversaries. The assumptions behind most current patching cycles, risk registers and third-party assurance processes were built for a slower world. This session is for security and risk leaders who need to answer three questions: how much has our real exposure changed, what do we do about it, and what do we tell the board? We'll size the shift honestly (without the hype) and then focus on remediation: how to harden code and systems against AI-accelerated attack. That includes using LLMs defensively as part of your control set, alongside the traditional disciplines that still do the heavy lifting: supply chain provenance, patch velocity, and reducing what you have to defend in the first place. Attendees will leave with a practical view of which controls to prioritise now, which investments can wait, and how to frame the risk in terms the board will act on.

Tuesday, 22 September, 2026 / 03:50 PM - 04:10 PM GMT

Theater 2, Exhibit Showcase

Diligent: Can AI kill the 40-hour vendor assessment?

As third-party risk management (TPRM) shifts to continuous monitoring, security teams face critical bottlenecks with manual assessments. This session shares real insights from our CISO roundtable in Washington, D.C., detailing where current AI tools fall short and the friction of changing your TPRM program. Attendees will leave with 3-5 practical lessons to move beyond point-in-time assessments and manage emerging supply chain risks.

Tuesday, 22 September, 2026 / 03:50 PM - 04:10 PM GMT

Theater 3, Exhibit Showcase

Vectra AI: Attackers Know Your Gaps. Does Your SOC?

Attackers do not move within the neat boundaries of your security stack. They exploit the gaps between endpoint, identity, cloud, SaaS, and network tools to hide, move laterally, and progress attacks. Drawing on Vectra AI’s Mind Your Attack Gaps research, Lucie Cardiet shows how SOC teams can find missing signal, connect network behavior with identity context, and close the gaps attackers count on.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Maritime Suite 27

Top Trends in Cybersecurity for 2026

Cybersecurity leaders face unprecedented external forces — from geopolitical tensions to rapid AI growth — testing the limits of existing programs. This session details Gartner’s top eight trends for 2026, providing the strategic pivot needed to manage risk and build resilience across three core themes: transforming governance, securing new frontiers and empowering AI adoption.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Capital Suite 15

The State of the Application Security Testing Market

This session gives an overview of current trends, technologies, and approaches to AppSec testing, including new AI-augmented tools like application code security assistants, AI false positive suppression, and vibe coding.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Maritime Suite 25

Outlook for AI and Cybersecurity: Guiding CISOs Through Change and Opportunity

AI's promises shaped high expectations in the past. Moreover, every step forward in AI, such as LLMs, created a new wave of "AI washing" and new hopes for concrete improvements. This session puts recent and upcoming changes in perspective and guides CISOs on integrating AI into their cybersecurity roadmap.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Capital Suite 10

Top Findings from the 2026 Gartner Technology Adoption Roadmap

Learn about the key findings from the 2026 Gartner Technology Adoption Roadmap Survey of cybersecurity leaders. Gain knowledge to make informed technology investment decisions, with peer perspectives and a balanced framework for shaping your future cybersecurity technology implementation strategies. Discover which technologies are on CISOs’ radar, their adoption stages, best practices to adopt, pitfalls to avoid, and insights into the main risks and benefits associated with various technologies.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Maritime Suite 26

How to Build a Zero-Trust Architecture

Zero trust still continues to be relevant as attacks ramp up and bad actors continue to explore creativity to evade measures and compromise vulnerabilities in architecture and applications. This session will guide security architects on building and deploying a zero-trust architecture to mitigate cybersecurity risks through practical architectural insights.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Maritime Suite 9

Modernizing Data Security: AI-Driven DLP for the Enterprise

Learn how AI and automation enable real-time data loss prevention across SaaS, endpoints and AI workflows. Discover practical architectures that use machine learning and behavioral analytics to reduce false positives, adapt policies, and close data exfiltration gaps, without impacting productivity.

Tuesday, 22 September, 2026 / 04:15 PM - 04:45 PM GMT

Maritime Suite 10

SLA SOS: How to Rescue Your Security Team With Smarter Managed Security Metrics

Metrics for detection and response services rarely ensure good service quality. Generic and rigid time-based SLAs can be costly if they are not aligned with internal processes. Unclear metrics may lead to unmet service expectations. This session will explore how to best design cybersecurity metrics to measure the effectiveness of managed services and improve your security operations team’s efficiency.

Tuesday, 22 September, 2026 / 04:15 PM - 04:35 PM GMT

Theater 1, Exhibit Showcase

Emerging Market Quadrants for AI Application Security

Traditional cybersecurity tools simply cannot address the security risks associated with AI-enabled applications and AI agents. AI application security tools are emerging that combine security testing and runtime defense to protect AI applications and agents. Join us for an overview of the market landscape and capabilities of AI Application Security tools.

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Maritime Suite 27

Six Big Ideas to Shake Up Cybersecurity

Cybersecurity governance has atrophied and needs a reset. Big ideas like a standard of due care, stakeholder defensibility, a threat readiness index, protection-level agreements and outcome-based governance offer to shake it up. We need new ways to engage executives, determine what good looks like and drive priorities and investments. Join this session to know more.

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Maritime Suite 10

Securing AI Application Development Goes Beyond Traditional DevSecOps

Traditional DevSecOps practices enable better secure software outcomes. But when the software starts thinking, learning or generating on its own, new risks appear. AI systems can be tricked, biased or leak information in ways normal code cannot. To protect them, software engineering teams must extend DevSecOps practices with AI security practices, including model and data security and continuous monitoring.

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Maritime Suite 9

Ensuring Cyber Resilience in the Age of Vendor and Platform Consolidation

Gartner surveys show the average enterprise uses 42 security tools. This complexity undermines security, prompting most CISOs to reduce the number of security vendors. Converging onto platforms is necessary, and the same will happen with AI security. However, this can create fragility by increasing dependence on a single provider. This session will offer guidance for evaluating the resiliency of security platforms during selection and contracting.

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Maritime Suite 26

Staffing the SOC in 2030

This session will explore the impact of the adoption of Agentic AI technologies on SOC staffing levels, skillsets and guide participants into areas they will need to make human capital investments in to maintain the relevance of the SOC into 2030.

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Capital Suite 10

How to Negotiate Security and Risk Into Technology Vendor Contracts

CISOs are increasingly responsible for negotiating security services and subscriptions for their function or are called on by procurement and business leaders to opine over security specific clauses in business-critical agreements. This session will outline Gartner's position on the top risk and security clauses that must be addressed to ensure business resiliency and regulatory compliance for your organization and some negotiation tactics to improve the likelihood of success.

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Maritime Suite 25

What Is Your Plan B for AI Failure?

AI adoption has been accelerating for years but almost always bypassing certain basic elements of cybersecurity due diligence, hygiene, risk and impact assessments or alternatives and exit plans. Cybersecurity leaders must be prepared for major disruption. What will you do when GenAI collapses, AI-embedded apps fail, or your vendors make choices contrary to your policies? Join this session to find out!

Tuesday, 22 September, 2026 / 05:15 PM - 05:45 PM GMT

Capital Suite 15

Outlook for Privacy: From Emergence to Enforcement

While the principles protecting individual privacy remain steadfast, organizations operating in multiple regions are confronted with divergent regulatory approaches, ranging from emergence and enforcements to evolution. Join this session to learn of the latest trends, (regulatory) developments, and actions for succeeding in such a diverse environment.

Tuesday, 22 September, 2026 / 05:15 PM - 05:35 PM GMT

Theater 1, Exhibit Showcase

Being a Human CISO in a Future AI-Driven World

To successfully navigate this landscape as a "human CISO," leaders must shift from securing static digital workflows to proactively protecting context-aware physical environments. Crucially, as systems become increasingly automated and intelligent, security leaders must actively champion preserving critical thinking against the complacency of AI autopilot. Join this session to learn more.

Tuesday, 22 September, 2026 / 05:55 PM - 06:15 PM GMT

Theater 1, Exhibit Showcase

ArmorCode: Hard Lessons in Automating AI-Scale Remediation

AI scales vulnerability discovery faster than teams can fix them. Traditional scores fail to prioritize effectively. Learn how to overcome alert fatigue by correlating cross-stack signals to isolate true attack paths. We share 3 practical strategies to automate remediation workflows, move beyond basic exploitability, and align your AppSec program with real-world exposure management without disrupting developers.

Tuesday, 22 September, 2026 / 05:55 PM - 06:15 PM GMT

Theater 2, Exhibit Showcase

SafeBreach: AI Scales Attackers, What Scales Defenders? CTEM for Every Security Team

AI didn't create the exposure problem; it exposed it. As offensive capabilities accelerate, the challenge is no longer identifying risk but turning insight into action. This session explores why mobilization is becoming the defining capability of modern CTEM, and how purpose-built AI agents empower organizations of any size to operate with the speed and discipline once reserved for elite security teams.

Tuesday, 22 September, 2026 / 05:55 PM - 06:15 PM GMT

Theater 3, Exhibit Showcase

One Identity: From Audit Finding to Risk Signal: Modernizing Identity Governance

Compliance audits demand proof, not paperwork. AI governance is testing the limits of our existing regulatory frameworks. Learn how leading organizations transform access certification and entitlement analytics from annual compliance exercises into live risk signals, turning identity governance into a board-level risk conversation, not just an audit checkbox.

Wednesday, 23 September, 2026 / 08:00 AM - 05:45 PM GMT

Foyer

Gartner Showcase

Discover cutting-edge tools, diagnostics and actionable resources at the Gartner Showcase. Visit our demo space for a personalized walkthrough of our business and technology insights platform and learn how Gartner's leading tools like Third-Party Cybersecurity Insights Platform, Cybersecurity Controls Assessment, and Cybersecurity Business Value Benchmark can help you make faster, smarter decisions on your mission-critical priorities.

Wednesday, 23 September, 2026 / 08:00 AM - 06:30 PM GMT

Harbour 1

Registration and Information

Registration and Information hours for the day.

Wednesday, 23 September, 2026 / 09:00 AM - 09:45 AM GMT

Auditorium

Guest Keynote: The New Leadership Edge: Unlocking Human Intelligence in the Age of AI

Renowned executive coach, economist, and author Caroline Webb delivers a keynote on Leadership Intelligence, drawing from her new book to reveal science-backed strategies for exceptional leadership. As AI becomes ever more capable, the leaders who distinguish themselves will be those who understand how to make the most of the human intelligence on their team - and as she demonstrates, it's easier to achieve that if you have an understanding of how the human brain works. Caroline will share actionable insights on how this understanding can help us make wise choices under pressure, inspire great performance in our teams, and build resilience to the inevitable ups and downs along the way.

Wednesday, 23 September, 2026 / 09:45 AM - 10:30 AM GMT

Exhibit Showcase

Refreshment Break

Join us on the Exhibit Showcase, Level 0 for coffee, tea, and some light snacks in a brief break between sessions. Please click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367702_15367702.pdf) to see our refreshment break menu.

Wednesday, 23 September, 2026 / 09:45 AM - 06:30 PM GMT

Exhibit Showcase

Exhibit Showcase Open Hours

Visit the Exhibit Showcase to evaluate industry offerings that can move your business forward. Engage with your peers, Gartner analysts, and exhibitors. Attend a theater session to see technology in action.

Wednesday, 23 September, 2026 / 10:00 AM - 10:20 AM GMT

Theater 1, Exhibit Showcase

Google Chrome Enterprise: Advancing Enterprise Browsing in the AI Era

As AI shifts the security perimeter to the browser, legacy network controls often create friction. This session explores how organizations scale DLP and Zero Trust with Chrome Enterprise Premium. We will share practical lessons on reducing IT complexity, governing AI tools securely, and navigating the trade-offs of modernizing endpoint controls.

Wednesday, 23 September, 2026 / 10:00 AM - 10:20 AM GMT

Theater 2, Exhibit Showcase

SailPoint: How to Control the Chaos: Practical Guidance to  Non-Human Identities

AI agents and Non-Human Identities (NHIs) are now the top cyber attack vector, bypassing traditional security. Is your enterprise safe? Join this session to expose the hidden risks of credential-harvesting AI agents and learn a practical, 4-phase approach to discover, remediate, and govern NHIs. Discover how to map operational chains, enforce least privilege, and control the chaos before a single unsecured NHI triggers a devastating breach.

Wednesday, 23 September, 2026 / 10:00 AM - 10:20 AM GMT

Theater 3, Exhibit Showcase

Delinea: A Zero Trust Approach for Securing Agentic AI– Discovery to Control

As autonomous AI agents scale, traditional identity security struggles to keep pace. This session details the friction of discovering and governing agentic AI. Attendees will learn how to implement zero-trust best practices, apply continuous analysis, and execute real-time monitoring to safely control AI agents. We will provide actionable steps and real-world examples to mitigate risk without stalling innovation.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Capital Suite 10

Outlook for Human Factors in Cybersecurity: Adapt to Optimize

The human factor continues to be one of the biggest contributors to data breaches and in the age of AI, this is only amplified. CISOs must take into account omnipresent and emerging human-centric factors to ensure they have an effective cybersecurity program. Join this session to hear about the how the human element is shaping and being shaped to optimize your cybersecurity program.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 26

Outlook for Cyber Resilience

In today’s digitally connected world the reality that many businesses face is the constant potential for a cyber attack leading to catastrophic business impacts . As cyber threats evolve with fresh sophistication, the question is not if your organization will be targeted, but when. Join this session to explore the main considerations and challenges for cyber resilience in the future, and discover what strategies you will need to put in place to ensure your cyber resilience strategy is fit for the threats ahead.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Capital Suite 15

Outlook for Infrastructure Security: Navigating the Complexities of a Modern Enterprise

The infrastructure security landscape is undergoing unprecedented threats, necessitating innovative solutions and a proactive approach. Discover insights into how infrastructure security integrates workspace security, network security and cloud security to combine innovation and action in addressing the ever-changing threats to infrastructure.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 9

Outlook for Third-Party Cyber Risk Management: Challenge the Status Quo to Evolve Your Program

As frequency and impact of disruption caused by third-party cyber incidents grow, regulators, Boards and other enterprise stakeholders require cybersecurity to step in and manage these risks. This session will discuss the evolution of the practice from due-diligent focus to on-going monitoring, implications on resilience and AI risks as well as how its helping drive efficiency.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 25

How to Secure AI That Enterprises Build and Employees Use

AI applications add new attack surfaces and steps in the application development life cycle, requiring dedicated and new security practices. This session will cover Gartner's recommendation to secure AI and generative AI applications. Gartner's AI TRiSM includes required measures to prevent AI failures.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 27

Cybersecurity Planning Guide: Navigate AI Disruption and Geopolitical Volatility

Global conflict, AI-based disruption and political upheaval continue to impact the risk landscape for organizations. In this environment, cybersecurity programs become paramount. This session will provide insights into the current global cybersecurity landscape.

Wednesday, 23 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 10

Outlook for Exposure Management: Accelerating CTEM Adoption

Threat exposure management requires visibility into modern attack surfaces and the security team’s coordination and cooperation with other business functions, such as networking, cloud, identity and app teams. This session will provide insights into what is on the horizon for 2026 with regards to threat exposure management, its evolution, including the impact of new business practices and threats on your security exposure.

Wednesday, 23 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 1, Exhibit Showcase

Thought Leadership Theater: The Future Is Autonomous Business

What comes after digital business? Autonomous business! Autonomous business is how we monetize on AI at scale. But it comes with its own set of risks as well. In this emerging technology vision, we explore both opportunities and risks. Welcome to the biggest story of the Security and Risk Summit.

Wednesday, 23 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 2, Exhibit Showcase

The Future of Digital Identity

The future world that businesses will operate in cannot thrive without identity. This session discusses the plausible future where organizations work across the globe, space and spatial and synthetic worlds — all being influenced by automation and AI. It explores how stakeholders will need a stronger and more innovative system of digital identity. Join this session to learn more.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Auditorium

Thales: Extending Zero Trust to Data — 3 Practical Steps to Digital Sovereignty

Technology disruptions such as AI or quantum, accelerate requirements for sovereignty. Organizations need greater visibility and control over sensitive data. In this session, Thales shares three practical steps to extend Zero Trust to the data layer using DSPM. Learn how to discover sensitive data, prioritize risk, and strengthen digital sovereignty across hybrid environments while addressing common operational and compliance challenges.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 25

Island: How Booking.com Scaled Secure Work to 17,000 Users

As organisations rely more on BPO partners and other extended-workforce models, securing access to critical systems is a strategic imperative. In this fireside chat, Booking.com shares how migrating 17,000 customer care users to Island strengthened visibility and control for a workforce on unmanaged devices - reducing third-party risk without disrupting operations, while improving user experience and gaining richer insights.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 24

Wiz: Scaling Secure Development Beyond Model-Led Scanning with AI SAST

AppSec is breaking. AI speeds up development, but frontier models add hidden costs: they are too expensive for continuous scans, and custom harnesses add overhead. We’ll explore why point-in-time scanning fails and how to move to a sustainable, agentic system. Learn how to balance deterministic analysis with AI reasoning to achieve continuous coverage and scale application security while reducing operational friction.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 26

ThreatLocker: Defending Against Hidden Risks of AI Tools in The Workplace

AI tools have the power to transform organizational productivity while exponentially increasing risk. Join this session to uncover how workplace AI tools can expose sensitive data, bypass controls, and introduce new attack surfaces. We’ll also explore what you can do to mitigate these risks effectively without impeding innovation

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 27

Sophos: Containment Is the New Prevention — A CISO's Playbook for Agentic AI

Agentic AI demands new security approaches. Prevention isn’t enough—containment is essential. Learn how CISOs can manage risk, balance autonomy, and apply effective containment strategies to protect sensitive data and enable secure AI innovation.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Capital Suite 10

Check Point: Your AI Guardrails Are Failing — Here’s What Actually Works

AI guardrails built for chat interfaces are failing modern agents that read documents, call APIs, and act autonomously. Attackers exploit this with prompt injection and agent‑level abuse that static filters can’t see. Drawing on real deployments, we show why first‑gen controls miss these threats and what works instead: behavioural, context‑aware security that protects full AI sessions.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 9

Vectra AI: The Agentic SOC Won’t Fix Garbage-In, Garbage-Out

AI agents can summarize, search, correlate, and recommend at speed. But in the SOC, bad signal means faster bad decisions. Martin Roesch explains why the Agentic SOC needs trusted signal grounded in network, identity, and cloud context. Learn how CISOs can assess readiness, avoid garbage-in, garbage-out AI, and build or add agentic capabilities with confidence.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 10

ManageEngine: Less Complexity. More control. A Real World IT Security Transformation Story

Every CISO inherits the same challenge:Years of security and IT tools, each solving one problem while adding another login, another dashboard, another gap nobody's watching.The result isn't stronger security;it's tool sprawl.Buckinghamshire Healthcare NHS Trust turned that sprawl into a unified operating model: One platform, one audit trail, and compliance deadlines met without adding headcount.See how complexity became simplicity, in practice.

Wednesday, 23 September, 2026 / 11:30 AM - 12:00 PM GMT

Capital Suite 15

KnowBe4: Your Risk Score Means Nothing If No One Believes It

One of the biggest failure modes in human risk programmes isn't the data - it's trust. When employees and security teams can't explain why someone's high risk, the score becomes a liability. Black-box scoring breeds defensiveness, not behaviour change. This session shows how to build a risk score people believe, with tests every score must pass, signs your score is being manipulated, and a blueprint for turning verdicts into conversations.

Wednesday, 23 September, 2026 / 12:00 PM - 01:30 PM GMT

Harbour 5, Anchor & Exhibit Showcase

Grab Lunch at Harbour 5, Anchor or the Grab 'n' Go Cafe in Exhibit Showcase

Join us at Harbour 5 & Anchor, Level 1 to network with your peers and make new connections over a seated lunch. Alternatively, head to the Exhibit Showcase for a Grab & Go lunch! Engage with your peers, Gartner Analysts, and exhibitors while enjoying delicious food and beverages. Click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367549_15367549.pdf) to view the seated lunch menu. Click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367577_15367577.pdf) to view the Grab & Go Café menu. For specific dietary needs, please visit the dietary table located in Anchor for further details and assistance.

Wednesday, 23 September, 2026 / 12:15 PM - 12:45 PM GMT

Maritime Suite 26

Top Cybersecurity Projects for 2026

CISOs should implement or improve upon these top eight security projects in 2026. The selected projects leverage current technologies, address the changing needs of cybersecurity and prepare organizations for the continued adoption of AI technologies. Join this session to learn more.

Wednesday, 23 September, 2026 / 12:15 PM - 12:45 PM GMT

Maritime Suite 25

How to Secure Software Development in the Age of AI

This session explores the evolving risk landscape as AI tools become integral to software development. It highlights key security challenges like inconsistent protocols, vulnerabilities in AI-generated code and supply chain threats. Discover the necessity of robust cybersecurity governance, the limits of automation and the critical role of human expertise in risk analysis. Learn how to align AI-driven practices with enterprise security standards and why human-in-the-loop processes are essential.

Wednesday, 23 September, 2026 / 12:15 PM - 12:45 PM GMT

Maritime Suite 9

Navigating NIS2, DORA and the EU AI Act

This discussion examines how organizations can respond to new European regulations, including NIS2, DORA, and the EU AI Act, which set stricter requirements for cybersecurity, digital operational resilience, and AI governance. It outlines key steps for compliance, such as updating risk management processes, enhancing transparency, and strengthening oversight of digital and AI systems. By proactively addressing these regulations, organizations can ensure legal compliance and build trust in their digital and AI operations.

Wednesday, 23 September, 2026 / 12:15 PM - 12:35 PM GMT

Theater 1, Exhibit Showcase

IBM: Preparing for Quantum-Safe Resilience: Protecting Against Emerging Quantum Threats

Quantum computing is driving the need to modernize cryptography across global IT environments. New regulations, standards, and cyber threats require organizations to identify cryptographic risks, prioritize exposures, and prepare for post-quantum cryptography (PQC). Discover practical strategies and technologies to automate discovery, planning, and migration, enabling a smooth transition to quantum-safe while strengthening business resilience.

Wednesday, 23 September, 2026 / 12:15 PM - 12:35 PM GMT

Theater 2, Exhibit Showcase

HackerOne: The Validation Crisis — Why AI Makes Finding Vulnerabilities Easy & Fixing Them Harder

Every major AI model release spikes vulnerability report volume. But organizations aren't drowning in vulnerabilities — they're drowning in unvalidated findings. With exploitation windows now under 24 hours and remediation measured in months, the gap is widening. This session gives security leaders a framework to measure what actually matters: time to validate, exposure backlog, and time to remediate.

Wednesday, 23 September, 2026 / 12:15 PM - 12:35 PM GMT

Theater 3, Exhibit Showcase

Upwind: Invisible Attack Paths, AI Agents, Endpoints, and Cloud Risk

The integration of AI tools into daily workflows introduces new security challenges and risks. Learn how AI agents impact cloud risk, Why traditional controls may not be sufficient , Strategies for AI visibility and governance,  Identifying blind spots and understanding AI activity in your environment

Wednesday, 23 September, 2026 / 12:40 PM - 01:00 PM GMT

Theater 1, Exhibit Showcase

Safe: What You Don’t Know About Your Third Parties

Spreadsheet assessments are dead weight. As vendor ecosystems explode, scaling TPRM through manual reviews guarantees analyst burnout and procurement gridlock. Join Jacqueline Lebo from SAFE and Austin Lebo from Elsevier, for a rapid, 20-minute masterclass on replacing static questionnaires with automated telemetry, defensible cyber risk quantification, and actionable tiering—slashing assessment cycles without expanding headcount.

Wednesday, 23 September, 2026 / 12:40 PM - 01:00 PM GMT

Theater 2, Exhibit Showcase

Zscaler: Digital Sovereignty & Frontier AI — A Zero Trust Blueprint for Security Leaders

As Europe’s tech sovereignty agenda clashes with the unpredictable risks of Frontier AI, security leaders face a complex governance dilemma. How can you maintain control globally? Join this session to explore how to secure your strategy and architecture outside EU borders. We deliver concrete insights on leveraging Zero Trust to satisfy strict regulatory expectations, mitigate advanced AI threats, and preserve operational flexibility.

Wednesday, 23 September, 2026 / 12:40 PM - 01:00 PM GMT

Theater 3, Exhibit Showcase

Salt Security: Demystifying Agentic AI - Driving Innovation Without Compromising Governance

An efficient agent that flawlessly resolves my customer needs—where do I sign?" The allure of Agentic AI is undeniable, but the reality of deploying and operating it securely is complex. Join this session as we explore the critical steps you must take to safely harness the power of Agentic AI. Bridging the gap between business enthusiasm and enterprise security, ensuring your AI initiatives drive innovation without breaking your risk frameworks.

Wednesday, 23 September, 2026 / 01:05 PM - 01:25 PM GMT

Theater 1, Exhibit Showcase

Datadog: Securing AI Agents With Runtime Observability

AI agents expose enterprise data to new risks that legacy DLP tools miss. Without guardrails, prompt-triggered exfiltration goes unnoticed. This session explores runtime observability as a practical defense. Attendees will learn to use traces, logs, and events to gain visibility into agent behavior, detect data misuse in real time, and respond to threats before damage occurs.

Wednesday, 23 September, 2026 / 01:05 PM - 01:25 PM GMT

Theater 2, Exhibit Showcase

Netskope: Architecting AI Guardrails — Eliminating the Latency Tax

69% of employees frequently bypass security guidance to get the job done. Bolting on AI appliances or relying on backhall creates a latency tax users will route around and is a placement problem, not a policy problem. This session explores the architecture required to secure AI without slowing down work. Attendees will learn how to design a single enforcement plane, evaluated at the point of request, reducing user friction and safely enabling AI.

Wednesday, 23 September, 2026 / 01:05 PM - 01:25 PM GMT

Theater 3, Exhibit Showcase

Semgrep: How to Manage the Rising Risk of AI Coding Agents

AI coding agents are moving from pilot to production, making decisions and taking actions with real financial and legal consequences, often with little oversight. This session unpacks that risk: non-technical teams now directing powerful agents, daily malware attacks outpacing even the most sophisticated security teams, and code volumes growing faster than human review can scale. Join us to learn how to contain agent risk without AI-scale spend.

Wednesday, 23 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 26

Stopping the Quantum Threat: PQC in Three Waves

The clock is ticking on our current cryptographic infrastructure. With the advent of large-scale, fault-tolerant quantum computers looming, the algorithms we rely on today will be rendered obsolete, leaving our digital communications vulnerable. This session will discuss the three areas of cryptography - signatures, key exchange and certificates - you will need to upgrade before Q-day hits.

Wednesday, 23 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 10

Foundational Requirements for Addressing Data Security Debt to Secure AI

The rise of AI has revealed data security debt concerns that require attention. This session helps cybersecurity leaders to prioritize key areas of data security debt to address to secure AI.

Wednesday, 23 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 27

Negotiate Cybersecurity Protection Levels With Your Executives

Why don't executives fund cybersecurity according to their risk appetite? They have no idea how to do so. PLAs are concrete assertions of risk appetite. Negotiating PLAs determines your executives’ desired level of protection within their willingness to pay for it. They sharply guide investment, create stakeholder defensibility and are hard to ignore.

Wednesday, 23 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 25

Turbulence Report 2026: 7 Forces That Will Threaten Your Organization's Future

The security landscape is ever changing, evolving and complex. To add to the complexity, security threats could come from all areas of what Gartner refers to as Tapestry — technology, politics, economics, social, trust, regulatory and environmental (TPESTRE). This session discusses the seven forces that will threaten your organization's future.

Wednesday, 23 September, 2026 / 01:30 PM - 02:00 PM GMT

Capital Suite 15

Technical Insights: Workflow Augmentation and AI Strategies for SecOps

As security threats evolve and the market shifts away from traditional stand-alone SOAR tools, organizations must rethink their approach to SecOps automation. This technical session provides practical guidance for security architects and leaders on blending centralized and decentralized automation strategies to augment SecOps workflows. Attendees will learn how to leverage AI-driven solutions, apply use-case-based frameworks, and effectively measure workflow success. The presentation will empower attendees to adapt their security operations to changing technologies and threats, ensuring operational efficiency and maximum value in a consolidating market.

Wednesday, 23 September, 2026 / 01:30 PM - 02:00 PM GMT

Capital Suite 10

Executive Story: The Limits of the Mandate

Government cyber security has a structural problem: the centre is accountable for national resilience but doesn't own the risk, hold the budgets, or run the systems. Standards flow down; behaviour rarely changes. Drawing on frontline experience reshaping the UK's approach, this session makes the case for a polycentric model — where accountability stays local, capability is built where the work happens, and the centre shifts from mandating compliance to enabling delivery. It examines what the centre can genuinely influence versus control, why activity rarely equals outcome, and how to intervene without breaking what already works.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Auditorium

OneTrust: When Risks Can Think: Managing Risk and Compliance in the AI Era

Artificial intelligence is reshaping how organizations compete—accelerating productivity, sharpening decisions, and enabling new business models. That momentum introduces technology and regulatory risks most GRC programs weren’t designed to manage. In this session, you’ll gain a practical framework for governing AI, see how leading organizations adopt AI responsibly, and learn how to integrate AI controls into existing GRC processes.​

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Maritime Suite 25

Pentera: Seeing Through the AI Security Testing Hype — What Actually Works

AI is flooding offensive security testing with promises and hype but relying solely on probabilistic models introduces instability and unintended risk. This session cuts through the hype and shows why AI alone cannot validate security safely at Enterprise-scale. Learn how a hybrid approach, combining deterministic algorithms with probabilistic AI- delivers safe, consistent, and automated exposure validation to identify what is truly exploitable.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Maritime Suite 24

Axonius: Operationalizing Asset Intelligence for Secure AI

As organizations adopt AI, security teams face the dual challenge of integrating new tools and defending against AI-powered threats. This session explores the technical friction of fragmented asset inventories - the chief obstacle to AI success. Move beyond the hype to see how clean, context-rich asset intelligence provides a trusted foundation. Security leaders will leave with practical steps to defend against machine-speed threats.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Maritime Suite 26

apexanalytix: Quantum is Coming for Your 3rd-Parties — 3 Actions You Need to Take Now

Every piece of data that you and your third parties protect through encryption today will be compromised by quantum advances before 2030. Leading organisations are already adopting a quantum model for third-party risk. See how others are embedding risk controls, running proactive scenarios, and safely deploying Agentic AI to detect complex supply chain threats. The window to get ahead of this is closing. This session tells you where to start.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Maritime Suite 27

Tanium: This Was Never a Drill — Machine-Speed Threats, Human-Speed Bureaucracy

AI-accelerated attackers move faster than any human team — organisations must redesign how estates operate. Drawing on breach data and UK Government warnings, the talk walks from reactive to autonomous, self-healing operations. Autonomy is a force multiplier: machines act within guardrails, every action is auditable, humans stay in control. Three questions: what can the machine do, can every action be explained, can you undo mistakes at scale?

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Capital Suite 10

Snyk: Your Risk Register Was Priced for a Human Attacker

AppSec was built on a bargain: outnumbered 100 to 1, security engineers triaged what could be fixed by developers and accepted the rest. That bet assumed a human attacker, working at human speed. This evidence-led session examines what AI-assisted development and automated exploitation do to the accepted-risk backlog — and why it is now attack surface, not debt.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Maritime Suite 9

Airia: AI Sprawl is Exploding. Get ahead of Governance and Security Challenges Before It’s Too Late

The rapid explosion of AI and autonomous agents introduces risks that traditional security measures weren't built to address, placing new demands on organizations to govern the AI sprawl across the enterprise. Learn how leading organizations are gaining visibility over their AI ecosystems through practical strategies for discovering AI assets, implementing governance frameworks, orchestrating agent workflows, and maintaining accountability in AI-driven decisions. Walk away with actionable approaches to establish governance without stifling innovation.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Maritime Suite 10

Bitsight: Life After Mythos — How to Build Resilience as Exploit Windows Collapse

Frontier AI is reshaping cybersecurity by dramatically increasing the volume and velocity of vulnerabilities while collapsing the time between discovery and exploitation. As attackers move at machine speed, security teams need a new operating model for supply chain exposure management. Learn key practical strategies to automate exposure management, prioritise risk using threat and business context, and strengthen organisational resilience.

Wednesday, 23 September, 2026 / 02:30 PM - 03:00 PM GMT

Capital Suite 15

Silverfort: Runtime and Inline — Securing Identity in the Age of AI-Powered Attacks

Frontier AI has ended the old assumption that defenders have time to react after an attack begins. AI models compress attack chains into minutes, chaining misconfigurations at machine speed, without hesitation or fatigue. Detection turns forensic. Patching and access reviews can't keep pace. What stops an attack: access itself, the one checkpoint every identity must pass through. See why identity is becoming the next security control point.

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Maritime Suite 27

"Use AI Like a Threat Actor" and Other Strategies for AI in Cyber Defense

Join us for this session as we discuss how you can use AI in the way APTs are using it, for shortening the times for living-off-the-land hacking from weeks and months to hours and days. We will provide the full stratagem for this, as well as several others, including ways to wire cyber business intelligence into your SOC using AI.

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Maritime Suite 9

The CISOs Guide to Your First Year in Role

Your first year as a CISO determine your success in creating a security-conscious organization. This session provides guidance and support to new cybersecurity leaders to help maximize their success during this pivotal transition phase.

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Maritime Suite 10

Exceed the Status Quo: Why 'Resilience' Is No Longer Enough for Optimal Cybersecurity Outcomes

Cyber resilience is a mindset, an outcome and a capability. As the world continues to move at pace, maintaining the status quo is now just ‘table stakes.’ To thrive in this environment and deliver optimal business value from your cybersecurity program, while supporting broader organizational resilience, you must adopt adaptive resilience through an antifragile mindset and approach. Join this session to explore the spectrum of cyber resilience and go beyond being simply resilient.

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Maritime Suite 25

Extending Existing Controls to Discover and Control Third-Party AI Usage

AI Usage Control is a rapidly evolving space that includes AI-specific discovery and guardrails often lacking from traditional controls. In this session, we cover what AI UC is and how they can be used to improve discovery and place AI-specific guardrails around usage for the organization.

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Maritime Suite 26

Threat Intelligence Is the Swiss Army Knife of Cybersecurity

A session that will highlight and disclose different areas of cybersecurity where organizations can benefit from threat intelligence, starting with the traditional approaches of TI and then mentioning different areas that will be "unlocked" thanks to a mature threat intelligence program. (Areas like SIEM, SOC, threat hunting, penetration test, risk and so forth.)

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Capital Suite 10

We Cant Patch Our Way Out of Threat Exposure Debt

Patch management is a topic of interest to Gartner clients. However, approaches for prioritizing remediation have been lagging for some time. This session offers insights and approaches that assist in updating and adapting vulnerability prioritization, and in building support and collaboration from information security partners.

Wednesday, 23 September, 2026 / 03:30 PM - 04:00 PM GMT

Capital Suite 15

How to Manage Culture Change to Maximize IAM Success

Effectively managing cultural change is crucial for the successful implementation and user adoption of identity and access management projects. IAM leaders frequently encounter challenges related to cultural shifts. This session will delve into forces that shape organizational culture and how to encourage a culture of continuous improvement and learning to ensure successful IAM implementations.

Wednesday, 23 September, 2026 / 03:30 PM - 03:50 PM GMT

Theater 1, Exhibit Showcase

Magic Quadrant for Email Security

Join this session to see how the email security vendor space has evolved over the past year. We discuss vendor position movements, feature evolution and key points for vendor selection.

Wednesday, 23 September, 2026 / 03:30 PM - 03:50 PM GMT

Theater 2, Exhibit Showcase

Gartner's Most Maverick Predictions: The Human Body as the Next Computing Platform

Humans are technological beings. It is inevitable that we bring new technology closer and closer to our bodies — even inside our bodies. However, this has profound ethical, risk and security consequences. What do you think? Is this a plausible future or not, and what would be desirable and undesirable? Join this session to learn more.

Wednesday, 23 September, 2026 / 04:00 PM - 04:45 PM GMT

Exhibit Showcase

Refreshment Break

Join us on the Exhibit Showcase, Level 0 for coffee, tea, and some light snacks in a brief break between sessions. Please click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367703_15367703.pdf) to see our refreshment break menu.

Wednesday, 23 September, 2026 / 04:15 PM - 04:35 PM GMT

Theater 1, Exhibit Showcase

Simeio: Stop Chasing Evidence: Delivering Continuous, Automated IAM Controls at Scale

IAM compliance is still driven by manual checks and audit sprints, leaving organizations exposed to duplicated controls, stale evidence, and people‑dependent readiness. This session focuses on reducing compliance risk by shifting IAM to continuous, automated controls and evidence pipelines. Learn how to reuse controls across frameworks and report an always‑on, defensible IAM risk and compliance posture without increasing operational overhead.

Wednesday, 23 September, 2026 / 04:15 PM - 04:35 PM GMT

Theater 2, Exhibit Showcase

Mimecast: AI Agents are the Ultimate Insiders — Securing AI and the Humans Behind It

Over a billion AI agents will operate inside enterprises by 2029, acting for every employee: accessing data, executing tasks, and making decisions. The agent is no longer a tool used by an insider — it has become the insider. The same agent, deployed by two different people, isn't the same risk. This session reframes agentic AI as an insider problem, covering ways to manage this risk: attributing each agent to its human, and securing both as one.

Wednesday, 23 September, 2026 / 04:15 PM - 04:35 PM GMT

Theater 3, Exhibit Showcase

Keyfactor: Scaling Trust Infrastructure– Continuous Operations at Machine Speed

Trust infrastructure is no longer static. AI, shrinking certificate lifecycles, machine identities, and post-quantum cryptography require a shift from one-time deployment to continuous operations. This session explores how to make that transition. Attendees will learn how to build visibility into their machine identity and cryptographic estate, establish scalable governance, and develop a crypto-agility roadmap for constant technological change.

Wednesday, 23 September, 2026 / 04:45 PM - 05:30 PM GMT

Auditorium

Gartner Keynote: The Future of Cyber 2030 Skills, AI, Tech

In just three years the impact of AI on Cybersecurity has been immense. Join our session as we explore the future of cybersecurity skills, technology and the next set of impacts that AI will thrust upon our industry. Learn what is likely to transpire and what the impacts on our teams, our budgets and our overall cybersecurity program will be by 2030.

Wednesday, 23 September, 2026 / 05:40 PM - 06:00 PM GMT

Theater 2, Exhibit Showcase

Crowdstrike: Using Claude to Prioritise Identity Risk

Security teams face identity findings and risk signals spread across multiple systems. See how Claude can turn Falcon platform data and incident findings into prioritised, executive-ready identity insights. Learn how AI-assisted workflows can accelerate risk analysis, identify high-priority remediation actions, support analysts and streamline reporting across human and non-human identities.

Wednesday, 23 September, 2026 / 05:40 PM - 06:00 PM GMT

Theater 3, Exhibit Showcase

HCLSoftware: Govern Risk at AI Speed — Securing the Code You Build & Buy

Frontier AI accelerates software creation and vulnerability discovery at machine speed, creating a massive verification gap. Defending this requires new control models. Join this session to explore pragmatic strategies for securing the code you build AND buy. Discover how contextual risk intelligence, automated mitigation, and AI-assisted decisioning empower teams to act faster and prove measurable risk reduction to the C-Suite.

Wednesday, 23 September, 2026 / 05:40 PM - 06:00 PM GMT

Theater 1, Exhibit Showcase

F5: Securing GenAI – A 30-60-90 Day Framework

Most AI security guidance focuses on protecting a single application. Real-world AI deployments aren’t simple. Organizations quickly go from securing one AI app to managing dozens, and before long, autonomous agents that reason, use tools, and take action on their own. And with organizations still struggling with web application and API security, both genAI and agentic AI add significant complexity. This session introduces a practical 30-60-90 day framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. You'll leave with a blueprint for building a repeatable AI security program that scales with your organization's AI ambitions.

Wednesday, 23 September, 2026 / 06:05 PM - 06:25 PM GMT

Theater 3, Exhibit Showcase

Tailscale: The Network Is the Control Plane — AI Governance at the Network Layer

Enterprises long faced a tradeoff: connect everything to move fast, or lock it down to stay safe. AI shattered that compromise, multiplying what needs to talk across clouds and clusters. Kabir Sikand argues connectivity and security are one problem, best solved on an identity-aware network. Treat every workload, service, and AI agent as a first-class identity, and governance stops being a policy you hope holds. The infrastructure enforces it.

Wednesday, 23 September, 2026 / 06:05 PM - 06:25 PM GMT

Theater 2, Exhibit Showcase

Persona: Securing the Workforce Identity Lifecycle in the Age of Deepfakes

GenAI has made it easier than ever for threat groups to exploit trusted processes like hiring pipelines and employee help desks. This session explores how multilayered identity verification—document checks, liveness detection, and signals analysis—helps organizations spot fake candidates and employees before they gain access. Learn where threat vectors emerge, how to apply higher assurance, and how to rebuild trust from recruiting to employment.

Thursday, 24 September, 2026 / 08:00 AM - 03:30 PM GMT

Foyer

Gartner Showcase

Discover cutting-edge tools, diagnostics and actionable resources at the Gartner Showcase. Visit our demo space for a personalized walkthrough of our business and technology insights platform and learn how Gartner's leading tools like Third-Party Cybersecurity Insights Platform, Cybersecurity Controls Assessment, and Cybersecurity Business Value Benchmark can help you make faster, smarter decisions on your mission-critical priorities.

Thursday, 24 September, 2026 / 08:00 AM - 03:30 PM GMT

Harbour 1

Registration and Information

Registration and Information hours for the day.

Thursday, 24 September, 2026 / 09:00 AM - 09:45 AM GMT

Auditorium

Guest Keynote: The Uncertainty Principle: How to Lead in The Never Normal

In a world where disruption has become the default setting, uncertainty isn’t the exception — it’s the new operating system. The role of CIOs, technology peers and service providers has never been more critical, nor more complex. In this keynote, Peter Hinssen explores how applications and software engineering leaders can thrive in the Never Normal — an era defined by relentless change and exponential opportunity. Drawing on his latest book, The Uncertainty Principle, he shows how CIOs, technology peers and service providers can turn volatility into a source of innovation, build organizations that adapt at the speed of technology, and shape a future where AI augments leadership, foresight, and creativity. The question isn’t how to survive the storm — but how to lead when the storm becomes the climate.

Thursday, 24 September, 2026 / 09:45 AM - 10:30 AM GMT

Exhibit Showcase

Refreshment Break

Join us on the Exhibit Showcase, Level 0 for coffee, tea, and some light snacks in a brief break between sessions. Please click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367712_15367712.pdf) to see our refreshment break menu.

Thursday, 24 September, 2026 / 09:45 AM - 02:15 PM GMT

Exhibit Showcase

Exhibit Showcase Open Hours

Visit the Exhibit Showcase to evaluate industry offerings that can move your business forward. Engage with your peers, Gartner analysts, and exhibitors. Attend a theater session to see technology in action.

Thursday, 24 September, 2026 / 10:00 AM - 10:20 AM GMT

Theater 1, Exhibit Showcase

Keysight Technologies: A Practical Framework for Software Supply Chain Visibility

Most organizations cannot name every component in their software supply chain, yet own accountability for its risk. This session equips digital product producers and asset owners with a concrete framework to gain true software supply chain visibility. Move beyond the hype to learn how to operationalize SBOM exchange, management, and monitoring, empowering your team to proactively detect and mitigate critical vulnerabilities.

Thursday, 24 September, 2026 / 10:00 AM - 10:20 AM GMT

Theater 2, Exhibit Showcase

depthfirst: It's npm, Do you Know What Your AI has Downloaded?

What is AI downloading? Autonomous coding agents are introducing thousands of new software dependencies every day, leaving traditional SCA perpetually behind. Discover why leading organizations are moving from reactive detection to a Dependency Firewall that prevents risky software from ever entering the development lifecycle.

Thursday, 24 September, 2026 / 10:00 AM - 10:20 AM GMT

Theater 3, Exhibit Showcase

Vega Security: Agentic Cyber Defense in the Post-SIEM Era

Every SOC will be agentic. The only question is when yours starts. Vega's Chief Product Officer will show how a detection carries an investigation to a verdict before an analyst touches it: it knows the priority, holds the context, and finishes the work, because your best defenders taught it how. Leave with the playbook to take back to your team.

Thursday, 24 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 9

Apply Data Security Controls to Support Privacy and AI Governance Initiatives

AI governance and privacy are driven by law and regulations, but common principles help savvy cybersecurity leaders apply effective data controls at the data layer. While this does not guarantee compliance, the controls create efficiencies to rightsize the investments for compliance. This session highlights the controls organizations must implement to gain and demonstrate control over their data processing activities — a key step to meeting customer and regulatory demands.

Thursday, 24 September, 2026 / 10:30 AM - 11:00 AM GMT

Capital Suite 10

Fight AI Disinformation: A CISO Playbook

Attackers use disinformation through malicious online narratives against organizations, combining deepfakes with social engineering to target employees. As there is no clear ownership of the issue, CISOs must collaborate with their CMOs and CIOs to defend against such attacks.

Thursday, 24 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 27

Top Cybersecurity Predictions for 2026

Change is the only constant in cybersecurity. This session examines the future of cybersecurity, identifying and explaining Gartner's top cybersecurity predictions for the coming year.

Thursday, 24 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 26

Beyond Mythos: Addressing AI-Driven Vulnerability Discovery Challenges

Advents such as Anthropic Claude Mythos, Project Glasswing, OpenAI Daybreak urge organizations to plan and adapt both the way that they identify vulnerabilities and the way they patch. This session will assess the breadth of the challenges organizations are facing, what technological and process solutions exist and how are peers reacting to the proliferation of vulnerabilities fueled by frontier and other AI models.

Thursday, 24 September, 2026 / 10:30 AM - 11:00 AM GMT

Maritime Suite 10

Forget the Hype: 5 Key Things You Should Be Doing to Secure Your Endpoints

In a world full of hype and distractions, organizations need to focus on fundamentals and foundational security techniques before moving on to the latest and greatest hype. In this session, attendees will learn the five key things that every organization should be doing to secure their endpoints and reduce the attack surface.

Thursday, 24 September, 2026 / 10:30 AM - 11:00 AM GMT

Capital Suite 15

Executive Story: Cybersecurity Leadership, Liability, and Control in the Agentic AI Era

Autonomous agents are already making decisions inside the enterprise that no human reviewed. They are moving at a speed no human can audit. Traditional security assumed a person in the loop and a clear line of accountability. Both are gone. The time barrier is collapsing! This panel confronts the question every board is now asking its security leaders: when an agent acts, who answers for it? This panel cuts through the hype to the 3 problems that actually decide whether agentic AI is an asset or a liability : 1- Leadership under machine-speed uncertainty 2- Liability. personal and organizational liability under NIS2 , CRA and the EU AI Act. 3- Control. What’s the new definition of control when you can no longer inspect every decision.

Thursday, 24 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 2, Exhibit Showcase

Magic Quadrant for Exposure Assessment Platforms

The modern threat landscape is highly dynamic, with attack surfaces constantly growing and evolving — often leaving organizations struggling to keep pace with automation and patching efforts. Cybersecurity leaders can harness exposure assessment platforms (EAPs) to maintain an up-to-date inventory of their attack surfaces, prioritize risks more effectively, and centralize operational workflows through integrated risk scoring and visual dashboards that drive greater efficiency.

Thursday, 24 September, 2026 / 10:30 AM - 10:50 AM GMT

Theater 1, Exhibit Showcase

Magic Quadrant for Endpoint Protection

Join this session to understand how the endpoint security vendor space has evolved over the past year, covering vendor position movements, feature evolution and key points for vendor selection.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 25

Yubico: Rebuilding Identity Trust In The AI And Quantum Era

Generative and agentic AI are supercharging the scale of cyberattacks, from deepfakes to advanced phishing. The way we protect users has to evolve because the tools we use to validate remote users and systems are actively under attack, agentic AI is transforming work, and post-quantum computing is no longer theoretical. Learn how to evolve your cybersecurity & identity strategy that balances rapid scale with verified trust.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 24

Varonis: The Workforce Revolution

AI is evolving from a tool that answers questions into an autonomous workforce that can access data, use applications, and take action. This shift creates a new class of security risk shaped by excessive permissions, untrusted inputs, expanding autonomy, and actions that drift from the user’s original intent. This session examines why traditional access controls are not enough for agentic AI and introduces a practical framework for establishing trust. Attendees will learn how governance, least agency, continuous monitoring, runtime guardrails, and intent-based controls can help organizations manage agent behaviour and safely scale AI adoption.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 26

Illumio: Inside Virgin Money’s Microsegmentation Journey with Illumio

As ransomware, AI-driven threats and DORA raise the stakes for financial services, CISOs need more than strategy—they need proven ways to contain risk across legacy systems and emerging AI workloads. Join Raghu Nandakumara of Illumio and Neil Robinson, CISO of Virgin Money, for a candid fireside discussion on the decisions, challenges and lessons behind a real-world containment journey.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 27

Veeam: Modernizing the Three Lines of Defense Model to Safely Scale Agentic AI

As autonomous AI agents operate at machine speed, organizations face new risks of uncontrolled data access and cascading actions. Move beyond theory to see how leading enterprises are partnering with Veeam to modernize their Three Lines of Defense. This session shares concrete client case studies on unifying data security and resilience, applying legacy controls to Agentic AI, and provide actionable steps to proactively catch exposure.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Capital Suite 10

Akamai: From Reactive to Resilient — Navigating the AI-Enabled Attack Surface

As AI democratizes cyber-threats, security leaders must move beyond perimeter defense toward proactive, systemic resilience. This session explores the intersection of AI governance and cybersecurity, offering actionable strategies to redefine security operating models. Join us to discuss how CISO-level executives can mitigate risk in the AI era.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 9

Immersive: From Playbooks to Proof — Answering the Hardest Questions in Cybersecurity

Bridging the gap between security operations and the boardroom has never been harder. With AI reshaping the threat landscape, executives need more than passive playbooks—they need hard proof of their cyber readiness for regulators. Join BT's Lee Stephens and Immersive's Dan Potter for a fireside chat on translating exercising and safely adopting AI into business value, and proof of resiliency without slowing down digital transformation.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Capital Suite 15

Claroty: Building Operational Resilience with AI in an Era of Evolving Cyber Regulations

Cybersecurity compliance (NIS2, CRA) and AI threats challenge critical infrastructure and cyber-physical systems (CPS). Discover how leading operators use AI-powered solutions and frameworks to achieve asset visibility, mitigate risks proactively, and ensure operational uptime. Learn to select the right frameworks, leverage AI for smarter decisions, and deploy practical strategies to reduce audit burdens while strengthening resilience.

Thursday, 24 September, 2026 / 11:30 AM - 12:00 PM GMT

Maritime Suite 10

BeyondTrust: The Ghost in the Machine (Securing Non-Human Identities)

Non-human identities are the ghost in the machine. Service accounts, bots, and AI agents now outnumber human users — yet most privileged access strategies weren't built to govern them. This session covers the operational reality: where policy breaks down, the friction teams hit when they try to fix it, and how AI accelerates exposure. Attendees leave with a framework to secure non-human access, mitigating risk before the ghost becomes the threat.

Thursday, 24 September, 2026 / 12:00 PM - 01:30 PM GMT

Harbour 5, Anchor & Exhibit Showcase

Grab Lunch at Harbour 5, Anchor or the Grab 'n' Go Cafe in Exhibit Showcase

Join us at Harbour 5 & Anchor, Level 1 to network with your peers and make new connections over a seated lunch. Alternatively, head to the Exhibit Showcase for a Grab & Go lunch! Engage with your peers, Gartner Analysts, and exhibitors while enjoying delicious food and beverages. Click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367546_15367546.pdf) to view the seated lunch menu. Click [here](https://css-cf-pbl.emt.aws.gartner.com/events/sec27i/assets/15367578_15367578.pdf) to view the Grab & Go Café menu. For specific dietary needs, please visit the dietary table located in Anchor for further details and assistance.

Thursday, 24 September, 2026 / 12:15 PM - 12:35 PM GMT

Theater 1, Exhibit Showcase

Doppel: Social Engineering Attack Chain — A New Standard for Unified Defense

This session reframes social engineering as a coordinated, AI‑driven attack chain that spans email, chat, SMS, voice, and video. Attendees will learn how attackers design cross‑channel campaigns, what Human Risk Management looks like in practice, and how to build a unified, human‑centric defense model that aligns security controls, processes, and business stakeholders.

Thursday, 24 September, 2026 / 12:15 PM - 12:35 PM GMT

Theater 2, Exhibit Showcase

Pathlock: From Audit Findings to Audit-Ready — Wieland's Access Review Story

Unused access piles up in every application. Most companies only notice when auditors do. Christoph Morath, Senior Manager Technology & Transformation, joins Pathlock live to unpack how they took access reviews from deadline-driven fire drills to automated, evidence-backed recertification: what triggered the project, how they got busy managers to actually review and what changed after go-live. Practical lessons for audit-ready access controls.

Thursday, 24 September, 2026 / 12:15 PM - 12:35 PM GMT

Theater 3, Exhibit Showcase

Synack: Build or Buy AI Pentesting? 5 Tests for Production Readiness

Security teams can prototype an AI pentesting agent in days. But moving it into production is different. This session covers five tests for deciding whether to build or buy, covering orchestration, exploit verification, safety, model drift and human oversight. Attendees will leave with a practical scorecard for evaluating whether AI pentesting solutions can deliver trusted, repeatable results at scale.

Thursday, 24 September, 2026 / 12:40 PM - 01:00 PM GMT

Theater 1, Exhibit Showcase

One Identity: Navigating Cyber Identity Risk and Securing Your Digital Perimeter

This session takes a risk perspective on how rapid business and tech change affects cyber security readiness. We examine key impacts, vulnerabilities and threats, and explain why secure Digital Identity is central to mitigating cyber risk. We suggest pragmatic strategies for securing Digital Identity, helping you escape the break-fix, detect/respond cycle and building the cornerstone for Zero Trust and Digital Transformation programs.

Thursday, 24 September, 2026 / 12:40 PM - 01:00 PM GMT

Theater 2, Exhibit Showcase

Menlo: The Operational Blind Spots of Agentic AI

Standard security checklists miss the real exposure of the agentic enterprise: high-autonomy agents operating at machine speed in the cloud or on user desktops. This session examines the operational reality and compliance gaps these agents create. Attendees will learn how to identify runtime AI agent risks, establish agent accountability, and address these vulnerabilities at the board level.

Thursday, 24 September, 2026 / 12:40 PM - 01:00 PM GMT

Theater 3, Exhibit Showcase

Noma Security: When Context Becomes Control: Governing and Securing Agentic AI

Agentic AI's real risk isn't a single attack, it's the architecture. Prompt injection and context poisoning are emergent properties of systems that treat all inputs (user, retrieval, memory, tools) as equally trustworthy. With no concept of trust, malicious instructions can hijack intent. Learn where trust breaks in agentic systems and how to redesign boundaries with a control-centric blueprint for fast, autonomous, secure-by-design AI.

Thursday, 24 September, 2026 / 01:05 PM - 01:25 PM GMT

Theater 1, Exhibit Showcase

Securiti: Securing the Future of AI Agents

AI agents aren't waiting for permission, they're already inside your critical systems, deciding what happens to your most sensitive data. Scaling that safely takes visibility, control, and resilience most programs lack today. The reason: data, identity, access, and AI security are managed as separate disciplines, leaving blind spots that keep risk from being seen in time. Join security experts to explore strategies for safely scaling AI agents.

Thursday, 24 September, 2026 / 01:05 PM - 01:25 PM GMT

Theater 2, Exhibit Showcase

Infoblox: The Missing Link in Exposure Management

DNS misconfigurations, phishing, and domain abuse represent some of the most exploited — yet least managed — attack vectors in enterprise environments. Despite guidance from standards such as NIST SP 800-81, existing CTEM and EASM solutions were not designed with DNS in mind. This session makes the case for DNS-specific CTEM, demonstrating how organisations can surface and remediate DNS exposures to measurably reduce risk.

Thursday, 24 September, 2026 / 01:05 PM - 01:25 PM GMT

Theater 3, Exhibit Showcase

HID Global: 3 Steps to Converging Physical and Digital Identity

Managing physical and digital access in silos creates governance gaps, revocation failures, and severe operational friction. AI-driven social engineering makes this division a critical security risk. We share new research from the FIDO Alliance and 3 practical strategies to unify physical and digital identity, automate lifecycle management, and deploy phishing-resistant authentication without disrupting user experience or business speed.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Auditorium

Hoxhunt: You Can’t Ban Your Way Out of Shadow AI

Shadow AI is accelerating as employees adopt unsanctioned tools to move faster than approved solutions allow. This is not just a governance or technology problem, but a security culture issue. When secure paths create friction, people route around them. This session explores what drives that behavior, when risk is hidden vs surfaced, and how leaders can make secure AI use the easiest path, with practical strategies to shift behavior at scale.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 25

Anomali: Decisions, Not Alerts — Building the Governed Decisioning Layer for the AI-Era SOC

SOC teams don't have an alert problem — they have a decision problem. At 174 alerts per analyst daily, only 22% warrant investigation, and AI agents fail fast on raw, unnormalized telemetry. This session introduces the Governed Decisioning Layer: a unified dataset where every event carries what's needed to act, gated by approval thresholds and audit trails — the foundation that makes autonomous SOC response safe, not just fast.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 24

Sublime Security: Adapting at Adversary Speed — Lessons from 20 Years on the Email Security Front Line

Email is still the front door attackers walk through, and most defences were built for a threat landscape that no longer exists. Join security leader Steve Townsley for an unfiltered fireside chat on what it actually takes to modernise email defence when attacks evolve faster than vendors can respond. Expect insights on analyst workload, how to identify hidden threat and what separates defences that adapt and explain from tools that just report.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 26

1Password: Your Employees' AI Tools Will Break Identity Security. Don't Stop Them. Secure Them.

AI agents now access your most sensitive systems, secrets, and data - but most organizations can't see them, govern them, or audit what they're doing. That's not a future risk. It's today's gap. This session gives you a practical framework to discover shadow AI and exposed credentials, secure them with Just-In-Time and Just Enough Access, and audit every action with full attribution across humans and machines.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 27

Abnormal AI: Betrayed Trust — How Behavioural AI Catches the Attacks Signatures Miss

Modern breaches carry no malware and no malicious links. Instead, they impersonate people you trust: a supplier, an executive, or a colleague, and pass every technical check because nothing about them is technically wrong. Email security's built to catch known threats, not betrayed trust. Join this candid, real-world look at how behavioural AI catches impersonation, plus practical steps to strengthen your security posture and protect your people.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 9

Push Security: Phishing in 2026 — Behind the Scenes of the Latest Tools and Techniques

Modern phishing looks and feels way different to what we’re used to. Often, it’s as simple as clicking “accept” on a consent screen, or entering a seemingly harmless code into a legitimate page — no password required. These attacks are a problem for both technical controls and humans, routinely bypassing MFA (including “phishing resistant” passkeys). Join us for live demos of these attacks, and learn what security teams can do about them.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Capital Suite 10

Coreview: Governing the AI Agents Inside Your Microsoft 365 Tenant

AI agents are appearing across your Microsoft 365 tenant faster than any team can inventory them. Employees, third parties, and attackers all create them, with standing OAuth and Graph access, below your SIEM and EDR. Skip the panic and the paralysis: get an honest scorecard of what is settled, uncertain, and overblown, a map to find the riskiest agents first, and a least privilege governance loop. You leave with the frameworks and a Monday plan.

Thursday, 24 September, 2026 / 01:30 PM - 02:00 PM GMT

Maritime Suite 10

Dataminr: Governing Autonomous SecOps - A Risk Appetite Framework for AI Agents

AI agents can now remediate faster than a human escalation chain can respond. This session gives a practical framework for governing that speed: how to turn a risk appetite statement into a dollar-and-confidence threshold an agent can act on, when it should escalate instead, who must co-own that number (CISO, CFO, COO, legal), and how to review it continuously as decision windows shrink to minutes.

Thursday, 24 September, 2026 / 02:15 PM - 02:45 PM GMT

Capital Suite 10

How to Prepare for the Next Flawed Vendor Update

The 2024 CrowdStrike outage exposed a critical vulnerability: flawed vendor updates can disrupt your enterprise. Traditional IT disaster recovery is not equipped for this supply chain risk. Attend this session and learn the three essential steps security and IT teams must take to build endpoint resilience: granular ITDR planning, risk-based update management to limit the blast radius and converting undocumented knowledge into formal, repeatable recovery runbooks.

Thursday, 24 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 25

How to Secure Enterprise AI Agents

AI agents are emerging as organizations invest in homegrown generative AI applications for enterprise automation. Cybersecurity leaders should adapt secure development and runtime security practices to address new attack surfaces and risks from enterprise AI agents.

Thursday, 24 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 9

How to Measure Cloud Security Success Successfully

Cloud security is a programmatic effort, rather than a purely technical one. This session will cover how to design, implement and use ODMs to communicate the effectiveness and value of your cloud security efforts, as well as how to measure their success.

Thursday, 24 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 26

Three Ways CISOs Must Optimize Infrastructure Security

Expanding security stacks, overlapping capabilities and increasing pressure from vendors to adopt broad portfolios of security products have intensified the need for ongoing infrastructure security optimization. This session will present four strategies CISOs can use to simplify complex decisions, avoid wasted spending on ill-suited investments and enhance overall security.

Thursday, 24 September, 2026 / 02:15 PM - 02:45 PM GMT

Maritime Suite 10

Take Your Cybersecurity Mesh Architecture and Build Your Defense in Depth Platform of the Future!

How do you take your CSMA strategy and turn it into reality? This session will discuss the latest innovations in CSMA from architecture to vendor solutions.

Thursday, 24 September, 2026 / 03:00 PM - 03:30 PM GMT

Capital Suite 10

SSE Shopping: How Not to Blow Your Budget or Your Security

Selecting a security service edge solution requires balancing a wide range of feature sets with financial and business imperatives. This talk would address the key selection criteria and methodology for cybersecurity management leaders to better design their SSE and SASE procurement processes as evoked in my paper Buyers’ Guide to Security Service Edge which had the following outline: Step 1: Assess the Strategic Relevance of SSE for Your Organization — “When Do We Need SSE?” Step 2: Build a Selection Criteria Scorecard to Facilitate Vendor Shortlisting — “What SSE Do We Buy?” Step 3: Plan for SSE Specifics in Your Negotiation Process — “How Do We Negotiate?”

Thursday, 24 September, 2026 / 03:00 PM - 03:30 PM GMT

Maritime Suite 25

CISO Cyber Regret: How to Survive a Boardroom Reckoning

Cyber regret looms on the horizon. CISOs enjoy an unprecedented period of cybersecurity investment and innovation, but years of low budget scrutiny leads to looming regret over unrealized value and missed opportunities. This session introduces a framework to help CISOs prioritize, address and reduce cyber regret to an optimal level that balances investment risk-taking with value.

Thursday, 24 September, 2026 / 03:00 PM - 03:30 PM GMT

Maritime Suite 9

From Labels to Meaning: AI-Powered Data Classification for Strategic Value

Traditional data classification relies on static labels and manual tagging that no longer meet today’s complex data demands. AI-driven models enable organizations to understand the true value and context of their data. This session reveals how moving beyond compliance-focused classification unlocks deeper business insights and optimizes governance. Learn how semantic understanding and automation reduce errors and elevate data protection.

Thursday, 24 September, 2026 / 03:00 PM - 03:30 PM GMT

Maritime Suite 10

Tips, Tricks and Conflicts to consider for Cyber-Physical System (CPS) Security

The adoption of AI, cloud technologies, increased IT/OT alignment, vulnerabilities with aging assets, unsecured remote access mechanisms and the rise of IIoT in CPS environments have collectively widened the attack surface, making these environments more susceptible to threats. The session provides cybersecurity leaders with best practices for improving the overall security posture of their environment.

Thursday, 24 September, 2026 / 03:00 PM - 03:30 PM GMT

Maritime Suite 26

AI Drives New Cybersecurity Architecture

Optimizing cybersecurity technology and architecture effectiveness is an imperative, but there are now multiple, intersecting architecture trends to choose from. This session will help you to identify and navigate these trends as AI emerges as the underlying architecture.

Thursday, 24 September, 2026 / 03:00 PM - 03:30 PM GMT

Capital Suite 15

Putting the AI in Email Security: How AI Is Reshaping the Inbox

Email security vendors and attackers are in an arms race to gain the upper hand with AI in email. Find out how both sides are evolving, which features provide real business value, and what questions you need to ask to develop a more effective email security program.