The most elite pan-European cybersecurity event, bringing together experts from across the continent.
This is not a typical conference.
Next IT Security East Central 2026 brings together a carefully selected group of cybersecurity leaders, executives, and decision-makers from across Central and Eastern Europe for focused discussions, practical knowledge sharing, and high-value networking.
Why Belgrade: A strategic meeting point between Central and Eastern Europe, offering excellent connectivity, a thriving technology ecosystem, and the ideal environment for regional collaboration and knowledge exchange.
Cybersecurity Advisor | ENISA Working Group Member
Sabrina Eisele Jensen
Information Security Officer | Too Good To Go
Esmeralda Kazia
CTO of OT/ICS & Automation | Albanian Power Corporation (KESH)
Eri Kejser
Global CISO | Semco Maritime
Dennis Rempe
Information Security Officer | Dutch Police
Nenad Bogunović
Chief Inspector, Cybercrime Service | Ministry of Internal Affairs, Serbia
Radosław Gnat
Senior Manager, Cyber Resilience |SK
Jovana Milić Jensen
Head of ESG Reporting & Data Management Ambu A/S
Luise Bang
Board Member | ABENA
Next IT Security — East Central
Agenda
Day 01
October 31, 2027
Belgrade · Sava Centar
08:00↓08:15
Registration & Welcome Coffee
Registration & Welcome Coffee
Venue: Sava Centar
08:15↓08:55
Power Breakfast
Power Breakfast
08:55↓09:00
Firestarter
Firestarter
09:00↓09:25
Opening Keynote
WORLD PREMIERE: State of CEE Cybersecurity 2026
Original research commissioned exclusively for this event. This session presents findings that nobody in this room has seen before, direct field interviews with CISOs across the CEE region, mapping NIS2 and local cyber law implementation gaps, AI deployment without security frameworks, budget constraints, awareness levels, and vendor dependency across critical infrastructure.
Attendees will gain an unfiltered view of where the region actually stands, not where it claims to stand. The data provides a foundation for every conversation that follows throughout the day, grounding the agenda in regional reality rather than theoretical frameworks.
Organizations that miss this session will lose the only independent, regionally specific benchmark available for 2026, the starting point against which every compliance, AI, and sovereignty decision should be measured.
Speakers
Luca Tagliaretti
Executive Director
European Cybersecurity Competence Center
09:25↓09:30
Diplomatic Opening Remarks
Diplomatic Opening Remarks
Chapter One
Compliance & Regulation Regulatory enforcement that can no longer be postponed
09:30↓09:50
Keynote
The Regulator's Perspective: What Auditors Actually Look For
NIS2, DORA, and CRA are no longer upcoming deadlines. They are being enforced. This keynote delivers the view from the other side of the audit table. What regulators actually look for, when penalties are applied, and what the enforcement reality looks like for CEE and Balkan organizations in 2027.
Attendees will gain direct insight into regulatory expectations, the criteria auditors use to assess compliance, and the specific gaps that are causing organizations in this region to fail. The session translates regulatory language into operational reality, giving leaders the clarity needed to act before the auditor arrives.
Without this perspective, organizations risk preparing for the wrong things, investing resources in compliance theatre while missing the controls that regulators actually prioritize. The cost of that misalignment is no longer just reputational. It is personal.
Speakers
Jelena Zelenovic Matone
CISO
European Investment Bank
09:50↓10:20
Expert Panel
How Do You Know If You Are Actually Compliant?
The law is clear. The implementation is not. CISOs across the region are asking the same questions: Are we doing this correctly? What happens when the regulator arrives? How do we verify our suppliers are compliant? Three CISOs who have been through it share what they found.
Attendees will gain honest, unscripted accounts of what compliance implementation actually looks like in practice, the gaps discovered, the decisions made under pressure, and the frameworks that held up when tested. This is peer learning at its most direct.
Organizations that rely solely on legal interpretation rather than practitioner experience risk discovering their compliance gaps at the worst possible moment, during an audit, after an incident, or when a supplier fails them.
Speakers
Gustavo Maniá
Information Security and Risk Manager
Heineken
Ulf Larsson
CTO
SEB Group Security
Ana-Maria Matejic
Cybersecurity Advisor & ENISA Working Group Member
Radosław Gnat
Senior Manager, Cyber Resilience
GSK
Jovana Milić Jensen
Head of ESG Reporting & Data Management Ambu A/S
Sabrina Eisele Jensen
Information Security Officer
Too Good To Go
10:20↓10:40
Innovator Keynote
Closing the Compliance Gap: Tools That Actually Work in a CEE Context
How to verify your own compliance posture and your supply chain's compliance practically, without enterprise-level budgets or dedicated compliance teams. This session moves beyond regulatory theory to demonstrate the tools and approaches that work specifically within the resource constraints facing CEE organizations.
Attendees will leave with a practical shortlist of approaches that can be implemented immediately, without waiting for budget cycles or additional headcount. The focus is on doing more with what organizations already have and knowing where investment will have the greatest compliance impact.
Without practical tools, compliance remains an aspiration. Organizations that cannot verify their own posture, let alone their suppliers' remain exposed regardless of how well they understand the regulation.
10:40↓11:10
Coffee Break & Pre-Scheduled 1:1 Meetings
Coffee Break & Pre-Scheduled 1:1 Meetings
Chapter Two
Chapter Two: AI & Emerging Threats Shadow AI, Accelerated Attacks, and the Governance Gap
11:10↓11:30
Keynote
The Attack Surface Nobody Is Mapping
What European threat intelligence shows about AI-accelerated attacks targeting CEE and Balkan organizations right now. How AI is being weaponized, automated reconnaissance, AI-generated phishing at scale, autonomous lateral movement. Threat actors are moving faster than most organizations can detect. Classified-level insight, declassified for this room.
Attendees will gain a current, intelligence-led picture of the threat landscape specific to this region, not the global averages that dominate most cybersecurity conferences, but the specific actors, techniques, and targets that are active in CEE and the Balkans today.
Organizations that are unaware of the regional threat picture are defending against last year's attacks. The gap between attacker speed and defender awareness is where breaches happen.
Speakers
Andrew Byrd
CISO
NATO Communications and Information Agency
11:30↓12:00
Expert Panel
Shadow AI: Deployed Fast, Secured Slowly
Employees are using AI tools the security team never approved. Developers are deploying AI agents with access to sensitive systems. Vendors are selling AI solutions that are not yet mature enough to trust. Three CISOs share how they discovered unauthorized AI inside their organizations, and what governance structure they built afterwards. Attendees will gain honest accounts of how Shadow AI was discovered, what the actual risk exposure looked like, and what governance structures proved effective without killing innovation. This is the conversation most organizations are not yet having internally — but need to. Organizations that assume their AI governance policies are being followed are operating on faith, not visibility. Shadow AI is not a future risk. For most organizations in this room, it is already present.
Speakers
Sandip Wadje
Managing Director and Global Head of Emerging Technology Risks
BNP Paribas
Arnaud Wiehe
Managing Director of IT
FedEx
Surinder Lall
Head of Cyber GRC (Governance, Risk, and Compliance)
DMG Media
Gilles Schwoerer
head of Western Balkans Cyber Capacity Centre (WB3C)
Esmeralda Kazia
Director of Monitoring & Incident Response Operations Center (SOC/C-SIRT), National Cybersecurity Authority, Albania
Eri Kejser
Global CISO
Semco Maritime
12:00↓12:20
Innovator Keynote
Governing What You Did Not Choose: Practical AI Security for the CEE Reality
Tools that give visibility into what AI is doing inside your environment when you did not deploy it yourself, and how to build governance without rebuilding your entire stack. This session focuses exclusively on AI security, addressing the practical challenge of governing Shadow AI within the resource and infrastructure constraints specific to CEE organizations.
Attendees will leave with a clear understanding of what visibility tools exist, how to prioritize governance actions, and how to build an AI security framework that is proportionate to their organization's size and risk profile, without requiring a complete technology overhaul.
Without visibility into unauthorized AI, organizations cannot govern it. And without governance, every AI tool running inside the environment is an unmanaged risk, invisible to security teams until it becomes an incident.
12:20↓13:20
Lunch Break
Lunch Break
Chapter Three
Vendor Dependency & Sovereignty Who Defends Your Infrastructure — and With Whose Tools?
13:20↓13:40
Keynote
Who Actually Defends Europe and With Whose Tools?
80% of European critical infrastructure is defended by non-EU technology. Your cloud is American. Your endpoint protection is non-EU. Your AI tools are American. This keynote does not pretend this is simple to fix; it maps the dependency honestly and asks what CEE and Balkan organizations can actually do about it, given real budget constraints and a non-EU member context.
Attendees will gain a clear, unsentimental picture of where European technology dependency actually stands and where the realistic options for reducing it exist. The session separates political aspiration from operational reality, giving leaders a framework for making vendor decisions that are strategically informed rather than ideologically driven.
Organizations that ignore vendor dependency are not avoiding the problem; they are deferring it. When the geopolitical environment shifts, the organizations without a dependency strategy will be the least prepared to respond.
Speakers
Flavio Aggio
CISO
WHO*
13:40↓14:10
Expert Panel
The Vendor Dependency Problem: Strategic Risk or Unavoidable Reality?
Three practitioners who have made real vendor decisions in real CEE organizations. What replacing a core vendor dependency actually looks like operationally. What the regulator expects regarding third-party risk. And what happens when a trusted supplier becomes your biggest vulnerability as it did in a supply chain attack in the region last year.
Attendees will gain direct practitioner insight into the decisions, tradeoffs, and consequences of vendor dependency management in the CEE context, not theoretical frameworks, but real decisions made with real constraints. The discussion will help leaders understand what is actually achievable and where the greatest risks lie.
Organizations that treat vendor dependency as someone else's problem, the regulator's, the vendor's, the government's will find themselves unprepared when a supplier becomes a threat vector. Third-party risk is now a board-level liability.
Former Bank of England Senior Cyber Security Consultant
Thomas B. Zuliani
Senior Director, Security Services
Gea Group
Moderator
Ray Stanton
Award-winning CISO/CRO/CSOs
14:10↓14:30
Innovator Keynote
European Alternatives: Where They Genuinely Exist and Where the Gaps Honestly Remain
A straightforward assessment of what European-headquartered security technology can deliver today and what it cannot. No overselling. Practical guidance for organizations that want to reduce strategic dependency without compromising operational capability.
Attendees will leave with a clear-eyed view of the European security technology landscape which categories have credible alternatives, which do not, and how to make procurement decisions that balance sovereignty goals with security performance and budget reality.
Without an honest assessment of what European alternatives can and cannot deliver, organizations risk making vendor decisions based on politics rather than capability or avoiding the question entirely and remaining fully dependent by default.
14:30↓15:00
Coffee Break & Pre-Scheduled 1:1 Meetings
Coffee Break & Pre-Scheduled 1:1 Meetings
Chapter Four
Cybercrime in a Borderless Threat Landscape
15:00↓15:20
Keynote
Law Enforcement Cyber Crisis Debrief
A real-world debrief from senior cybercrime units across Europe, shifting from theory to operational reality.
How major cyber incidents are handled across jurisdictions, what slows investigations down, and where international cooperation actually breaks or succeeds in practice.
Speakers
Brian Abellera
FBI’s attaché to Europol for cyber matters and embedded within the Joint Cybercrime Action Taskforce (J-CAT)
15:20↓15:45
Expert Panel
Cybercrime Landscape: Challenges and Cooperation
Four senior cybercrime law enforcement voices. Four perspectives. One shared reality. Short, unscripted reflections from experienced cybercrime investigators on what real cases look like beyond headlines — from attribution challenges to cross-border coordination and operational constraints.
Speakers
Patrick Ghion
Chief Cyber Strategy Officer
Geneva State Police
Dennis Rempe
Information Security Officer
Dutch Police
Jan Olsson
Police Superintendent
The Swedish Police Authority
Nenad Bogunović
Chief Inspector at the Service for Combating Cybercrime
Ministry of Internal Affairs of the Republic of Serbia
Luise Bang
Board Member
ABENA
15:45↓16:25
Closing Debate
European Cyber Sovereignty: Strategic Necessity or Expensive Illusion?
The room votes before the debate starts. The room votes again at the end. The shift in the vote is the result. This closing debate puts the day's central tension on trial between the vision of a sovereign European cyber defense and the operational reality facing organizations that cannot afford to rebuild their entire stack.
Before the debate begins, the event chair sets the context in two sentences: In this room we have organizations running predominantly non-EU technology, CISOs with budgets that cannot cover basic hygiene let alone sovereign infrastructure, and a Serbian context where EU alignment is an aspiration not a membership. With that reality in mind, two opposing voices take the stage.
The Idealist: Dependency on foreign technology in critical infrastructure is one political decision away from becoming a strategic crisis. The cost of building sovereignty is high. The cost of not building it is existential.
The Realist: For organizations in this room, full sovereignty is not achievable in any meaningful timeframe without crippling operational capability. Manage dependencies intelligently, invest in what you can control, and stop letting perfection be the enemy of functionality.
Format: 10 minutes each to make their case. With a 10 minutes open floor any delegate may challenge either speaker directly. Final 10 minutes: closing arguments, one minute each, then the room votes.
Speakers
Moderator
Markus (Macke) Küchler
Head of Global IT Security Epiroc and Major (res)
Swedish Armed Forces
Luca Tagliaretti
Executive Director
European Cybersecurity Competence Center
16:25↓18:00
Closing Remarks & Delegate Photo
Closing Remarks & Delegate Photo
18:00
Networking Dinner
Networking Dinner
By Invitation Only
No sessions in this filter.
Workshop Day | 29 SEPTEMBER
Workshop 1Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Date
29 Sep 2026
Workshop 2Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment.
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations operating outside the EU membership framework.
Selected as the official venue for Next IT Security Belgrade, Sava Center stands as the most prestigious conference and business venue in the region. Following a complete transformation and modernization, it has become the preferred destination for major international events, bringing together industry leaders, decision-makers, and experts from around the world.
Located in the heart of New Belgrade’s business district, Sava Center provides the ideal environment for high-level discussions, networking, and knowledge exchange. Its state-of-the-art facilities, advanced technology, and impressive conference capacities deliver an experience that meets the standards of Europe’s leading events.
As a symbol of business excellence and international collaboration, Sava Center offers a setting where innovation, strategy, and leadership come together — perfectly reflecting the values of the Next IT Security community.
Partners & Industry Leaders
Trusted by Cybersecurity Leaders
Our partners don’t just attend — they lead the conversation.
tockholm’s Grand Hôtel has hosted royalty since 1874 — now it hosts Next IT Security. Sessions close, doors open onto the water, and a private boat carries C-suite cyber minds into the Stockholm archipelago for conversations held under Chatham House rules — no notes, no headlines.
Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
Frankfurt earned the nickname “Mainhattan” for a skyline that rivals Manhattan’s. Dinner sits in the financial district with towers lit on every side, seating C-suite cyber minds alongside the day’s keynote speakers — no stage between you, just the conversation continuing.
Dinner closes the day forty stories up, in the St. Regis atop Kula Belgrade — the tallest tower on the Belgrade Waterfront, glass reflecting the Sava and Danube below. C-suite cyber minds take the panoramic restaurant at the top, city lights spreading out in every direction.
Join us for the exclusive Cybersecurity Event at Stockholm. This exclusive event offers a unique opportunity to network with C-suite Power Players, whilst enjoying fine dining and entertainment in a spectacular setting. Our C-Suites are our strength.
Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.