The most elite pan-European cybersecurity event, bringing together experts from across the continent.

Next IT Security conference, Stockholm — attendee networking

This is not a typical conference.

Next IT Security East Central 2026 brings together a carefully selected group of cybersecurity leaders, executives, and decision-makers from across Central and Eastern Europe for focused discussions, practical knowledge sharing, and high-value networking.

Why Belgrade:
A strategic meeting point between Central and Eastern Europe, offering excellent connectivity, a thriving technology ecosystem, and the ideal environment for regional collaboration and knowledge exchange.

Event Location

Event Snapshot

Event Date

31 October 2027

Duration

One-day executive event

Time

8:00 AM – 6:00 PM

Location

Sava Center, Belgrade

Audience

CISO-level and senior cybersecurity professionals

Attendance

Limited to 150 delegates

Join 150 Cybersecurity Leaders

Private, invitation-based event for CISOs and senior decision-makers.

    • ✔ No vendors. No noise.
    • ✔ Real discussions, real insights
  • ✔ Closed-door executive environment

The Biggest Cybersecurity Event in the Balkans 2026

C-LEVEL LEADERS

Featuring Global Security Experts & C-Level Visionaries

Council of the European Union

Luca Tagliaretti

Executive Director at European Cybersecurity Competence Center

Flavio Aggio

Flavio Aggio

CISO | WHO*

Brian Abellera

Brian Abellera

FBI Attaché to Europol | J-CAT

Andrew Byrd

Andrew Byrd

CISO | NATO Communications & Information Agency

Jelena Zelenovic Matone

Jelena Zelenovic Matone

CISO | European Investment Bank

Chika Amadi

Chika Amadi

Former Bank of England Senior Cyber Security Consultant

Ulf Larsson

Ulf Larsson

CTO | SEB Group Security

Dr. Leila Taghizadeh

Dr. Leila Taghizadeh

Global Head of Cyber Risk | Allianz

Sandip Wadje

Sandip Wadje

MD & Global Head of Emerging Technology Risks | BNP Paribas

Patrick Ghion

Patrick Ghion

Chief Cyber Strategy Officer | Geneva State Police

Jan Olsson

Jan Olsson

Police Superintendent | Swedish Police Authority

Gustavo Maniá

Gustavo Maniá

Information Security and Risk Manager | Heineken

Thomas B. Zuliani

Thomas B. Zuliani

Senior Director, Security Services | GEA Group

Helmut Spoecker

Helmut Spoecker

VP, Chief Security Officer ECS | SAP

Markus Küchler

Markus (Macke) Küchler

Head of Global IT Security | Epiroc

Magnus Carling

Magnus Carling

CISO | Stena AB

Arnaud Wiehe

Arnaud Wiehe

Managing Director of IT | FedEx

Surinder Lall

Surinder Lall

Head of Cyber GRC | DMG Media

Ray Stanton

Ray Stanton

Award-winning CISO / CRO / CSO | WEF / BT / Airbus

Ana-Maria Matejic

Ana-Maria Matejic

Cybersecurity Advisor | ENISA Working Group Member

Sabrina Eisele Jensen

Sabrina Eisele Jensen

Information Security Officer | Too Good To Go

Esmeralda Kazia

Esmeralda Kazia

CTO of OT/ICS & Automation | Albanian Power Corporation (KESH)

Eri Kejser

Eri Kejser

Global CISO | Semco Maritime

Dennis Rempe

Dennis Rempe

Information Security Officer | Dutch Police

Nenad Bogunović

Nenad Bogunović

Chief Inspector, Cybercrime Service | Ministry of Internal Affairs, Serbia

Radosław Gnat

Radosław Gnat

Senior Manager, Cyber Resilience |SK

Jovana Milić Jensen

Jovana Milić Jensen

Head of ESG Reporting & Data Management Ambu A/S

Luise Bang

Luise Bang

Board Member | ABENA

Next IT Security — East Central

Agenda

Day 01
October 31, 2027
Belgrade · Sava Centar
08:0008:15
Registration & Welcome Coffee

Registration & Welcome Coffee

Venue: Sava Centar

08:1508:55
Power Breakfast

Power Breakfast

08:5509:00
Firestarter

Firestarter

09:0009:25
Opening Keynote

WORLD PREMIERE: State of CEE Cybersecurity 2026

Original research commissioned exclusively for this event. This session presents findings that nobody in this room has seen before, direct field interviews with CISOs across the CEE region, mapping NIS2 and local cyber law implementation gaps, AI deployment without security frameworks, budget constraints, awareness levels, and vendor dependency across critical infrastructure.

Attendees will gain an unfiltered view of where the region actually stands, not where it claims to stand. The data provides a foundation for every conversation that follows throughout the day, grounding the agenda in regional reality rather than theoretical frameworks.

Organizations that miss this session will lose the only independent, regionally specific benchmark available for 2026, the starting point against which every compliance, AI, and sovereignty decision should be measured.

Speakers
Luca Tagliaretti
Luca Tagliaretti
Executive Director
European Cybersecurity Competence Center
09:2509:30
Diplomatic Opening Remarks

Diplomatic Opening Remarks

Chapter One

Compliance & Regulation Regulatory enforcement that can no longer be postponed

09:3009:50
Keynote

The Regulator's Perspective: What Auditors Actually Look For

NIS2, DORA, and CRA are no longer upcoming deadlines. They are being enforced. This keynote delivers the view from the other side of the audit table. What regulators actually look for, when penalties are applied, and what the enforcement reality looks like for CEE and Balkan organizations in 2027.

Attendees will gain direct insight into regulatory expectations, the criteria auditors use to assess compliance, and the specific gaps that are causing organizations in this region to fail. The session translates regulatory language into operational reality, giving leaders the clarity needed to act before the auditor arrives.

Without this perspective, organizations risk preparing for the wrong things, investing resources in compliance theatre while missing the controls that regulators actually prioritize. The cost of that misalignment is no longer just reputational. It is personal.

Speakers
Jelena Zelenovic Matone
Jelena Zelenovic Matone
CISO
European Investment Bank
09:5010:20
Expert Panel

How Do You Know If You Are Actually Compliant?

The law is clear. The implementation is not. CISOs across the region are asking the same questions: Are we doing this correctly? What happens when the regulator arrives? How do we verify our suppliers are compliant? Three CISOs who have been through it share what they found.

Attendees will gain honest, unscripted accounts of what compliance implementation actually looks like in practice, the gaps discovered, the decisions made under pressure, and the frameworks that held up when tested. This is peer learning at its most direct.

Organizations that rely solely on legal interpretation rather than practitioner experience risk discovering their compliance gaps at the worst possible moment, during an audit, after an incident, or when a supplier fails them.

Speakers
Gustavo Maniá
Gustavo Maniá
Information Security and Risk Manager
Heineken
Ulf Larsson
Ulf Larsson
CTO
SEB Group Security
Ana-Maria Matejic
Ana-Maria Matejic
Cybersecurity Advisor & ENISA Working Group Member
Radosław Gnat
Radosław Gnat
Senior Manager, Cyber Resilience
GSK
Jovana Milić Jensen
Jovana Milić Jensen
Head of ESG Reporting & Data Management Ambu A/S
Sabrina Eisele Jensen
Sabrina Eisele Jensen
Information Security Officer
Too Good To Go
10:2010:40
Innovator Keynote

Closing the Compliance Gap: Tools That Actually Work in a CEE Context

How to verify your own compliance posture and your supply chain's compliance practically, without enterprise-level budgets or dedicated compliance teams. This session moves beyond regulatory theory to demonstrate the tools and approaches that work specifically within the resource constraints facing CEE organizations.

Attendees will leave with a practical shortlist of approaches that can be implemented immediately, without waiting for budget cycles or additional headcount. The focus is on doing more with what organizations already have and knowing where investment will have the greatest compliance impact.

Without practical tools, compliance remains an aspiration. Organizations that cannot verify their own posture, let alone their suppliers' remain exposed regardless of how well they understand the regulation.

10:4011:10
Coffee Break & Pre-Scheduled 1:1 Meetings

Coffee Break & Pre-Scheduled 1:1 Meetings

Chapter Two

Chapter Two: AI & Emerging Threats Shadow AI, Accelerated Attacks, and the Governance Gap

11:1011:30
Keynote

The Attack Surface Nobody Is Mapping

What European threat intelligence shows about AI-accelerated attacks targeting CEE and Balkan organizations right now. How AI is being weaponized, automated reconnaissance, AI-generated phishing at scale, autonomous lateral movement. Threat actors are moving faster than most organizations can detect. Classified-level insight, declassified for this room.

Attendees will gain a current, intelligence-led picture of the threat landscape specific to this region, not the global averages that dominate most cybersecurity conferences, but the specific actors, techniques, and targets that are active in CEE and the Balkans today.

Organizations that are unaware of the regional threat picture are defending against last year's attacks. The gap between attacker speed and defender awareness is where breaches happen.

Speakers
Andrew Byrd
Andrew Byrd
CISO
NATO Communications and Information Agency
11:3012:00
Expert Panel

Shadow AI: Deployed Fast, Secured Slowly

Employees are using AI tools the security team never approved. Developers are deploying AI agents with access to sensitive systems. Vendors are selling AI solutions that are not yet mature enough to trust. Three CISOs share how they discovered unauthorized AI inside their organizations, and what governance structure they built afterwards. Attendees will gain honest accounts of how Shadow AI was discovered, what the actual risk exposure looked like, and what governance structures proved effective without killing innovation. This is the conversation most organizations are not yet having internally — but need to. Organizations that assume their AI governance policies are being followed are operating on faith, not visibility. Shadow AI is not a future risk. For most organizations in this room, it is already present.

Speakers
Sandip Wadje
Sandip Wadje
Managing Director and Global Head of Emerging Technology Risks
BNP Paribas
Arnaud Wiehe
Arnaud Wiehe
Managing Director of IT
FedEx
Surinder Lall
Surinder Lall
Head of Cyber GRC (Governance, Risk, and Compliance)
DMG Media
Gilles Schwoerer
Gilles Schwoerer
head of Western Balkans Cyber Capacity Centre (WB3C)
Esmeralda Kazia
Esmeralda Kazia
Director of Monitoring & Incident Response Operations Center (SOC/C-SIRT), National Cybersecurity Authority, Albania
Eri Kejser
Eri Kejser
Global CISO
Semco Maritime
12:0012:20
Innovator Keynote

Governing What You Did Not Choose: Practical AI Security for the CEE Reality

Tools that give visibility into what AI is doing inside your environment when you did not deploy it yourself, and how to build governance without rebuilding your entire stack. This session focuses exclusively on AI security, addressing the practical challenge of governing Shadow AI within the resource and infrastructure constraints specific to CEE organizations.

Attendees will leave with a clear understanding of what visibility tools exist, how to prioritize governance actions, and how to build an AI security framework that is proportionate to their organization's size and risk profile, without requiring a complete technology overhaul.

Without visibility into unauthorized AI, organizations cannot govern it. And without governance, every AI tool running inside the environment is an unmanaged risk, invisible to security teams until it becomes an incident.

12:2013:20
Lunch Break

Lunch Break

Chapter Three

Vendor Dependency & Sovereignty Who Defends Your Infrastructure — and With Whose Tools?

13:2013:40
Keynote

Who Actually Defends Europe and With Whose Tools?

80% of European critical infrastructure is defended by non-EU technology. Your cloud is American. Your endpoint protection is non-EU. Your AI tools are American. This keynote does not pretend this is simple to fix; it maps the dependency honestly and asks what CEE and Balkan organizations can actually do about it, given real budget constraints and a non-EU member context.

Attendees will gain a clear, unsentimental picture of where European technology dependency actually stands and where the realistic options for reducing it exist. The session separates political aspiration from operational reality, giving leaders a framework for making vendor decisions that are strategically informed rather than ideologically driven.

Organizations that ignore vendor dependency are not avoiding the problem; they are deferring it. When the geopolitical environment shifts, the organizations without a dependency strategy will be the least prepared to respond.

Speakers
Flavio Aggio
Flavio Aggio
CISO
WHO*
13:4014:10
Expert Panel

The Vendor Dependency Problem: Strategic Risk or Unavoidable Reality?

Three practitioners who have made real vendor decisions in real CEE organizations. What replacing a core vendor dependency actually looks like operationally. What the regulator expects regarding third-party risk. And what happens when a trusted supplier becomes your biggest vulnerability as it did in a supply chain attack in the region last year.

Attendees will gain direct practitioner insight into the decisions, tradeoffs, and consequences of vendor dependency management in the CEE context, not theoretical frameworks, but real decisions made with real constraints. The discussion will help leaders understand what is actually achievable and where the greatest risks lie.

Organizations that treat vendor dependency as someone else's problem, the regulator's, the vendor's, the government's will find themselves unprepared when a supplier becomes a threat vector. Third-party risk is now a board-level liability.

Speakers
Helmut Spoecker
Helmut Spoecker
Vice President, Chief Security Officer ECS Partner Management
SAP
Chika Amadi
Chika Amadi
Former Bank of England Senior Cyber Security Consultant
Thomas B. Zuliani
Thomas B. Zuliani
Senior Director, Security Services
Gea Group
Ray Stanton
Moderator
Ray Stanton
Award-winning CISO/CRO/CSOs
14:1014:30
Innovator Keynote

European Alternatives: Where They Genuinely Exist and Where the Gaps Honestly Remain

A straightforward assessment of what European-headquartered security technology can deliver today and what it cannot. No overselling. Practical guidance for organizations that want to reduce strategic dependency without compromising operational capability.

Attendees will leave with a clear-eyed view of the European security technology landscape which categories have credible alternatives, which do not, and how to make procurement decisions that balance sovereignty goals with security performance and budget reality.

Without an honest assessment of what European alternatives can and cannot deliver, organizations risk making vendor decisions based on politics rather than capability or avoiding the question entirely and remaining fully dependent by default.

14:3015:00
Coffee Break & Pre-Scheduled 1:1 Meetings

Coffee Break & Pre-Scheduled 1:1 Meetings

Chapter Four

Cybercrime in a Borderless Threat Landscape

15:0015:20
Keynote

Law Enforcement Cyber Crisis Debrief

A real-world debrief from senior cybercrime units across Europe, shifting from theory to operational reality.

How major cyber incidents are handled across jurisdictions, what slows investigations down, and where international cooperation actually breaks or succeeds in practice.

Speakers
Brian Abellera
Brian Abellera
FBI’s attaché to Europol for cyber matters and embedded within the Joint Cybercrime Action Taskforce (J-CAT)
15:2015:45
Expert Panel

Cybercrime Landscape: Challenges and Cooperation

Four senior cybercrime law enforcement voices. Four perspectives. One shared reality. Short, unscripted reflections from experienced cybercrime investigators on what real cases look like beyond headlines — from attribution challenges to cross-border coordination and operational constraints.

Speakers
Patrick Ghion
Patrick Ghion
Chief Cyber Strategy Officer
Geneva State Police
Dennis Rempe
Dennis Rempe
Information Security Officer
Dutch Police
Jan Olsson
Jan Olsson
Police Superintendent
The Swedish Police Authority
Nenad Bogunović
Nenad Bogunović
Chief Inspector at the Service for Combating Cybercrime
Ministry of Internal Affairs of the Republic of Serbia
Luise Bang
Luise Bang
Board Member
ABENA
15:4516:25
Closing Debate

European Cyber Sovereignty: Strategic Necessity or Expensive Illusion?

The room votes before the debate starts. The room votes again at the end. The shift in the vote is the result. This closing debate puts the day's central tension on trial between the vision of a sovereign European cyber defense and the operational reality facing organizations that cannot afford to rebuild their entire stack.

Before the debate begins, the event chair sets the context in two sentences: In this room we have organizations running predominantly non-EU technology, CISOs with budgets that cannot cover basic hygiene let alone sovereign infrastructure, and a Serbian context where EU alignment is an aspiration not a membership. With that reality in mind, two opposing voices take the stage.

The Idealist: Dependency on foreign technology in critical infrastructure is one political decision away from becoming a strategic crisis. The cost of building sovereignty is high. The cost of not building it is existential.

The Realist: For organizations in this room, full sovereignty is not achievable in any meaningful timeframe without crippling operational capability. Manage dependencies intelligently, invest in what you can control, and stop letting perfection be the enemy of functionality.

Format: 10 minutes each to make their case. With a 10 minutes open floor any delegate may challenge either speaker directly. Final 10 minutes: closing arguments, one minute each, then the room votes.

Speakers
Markus (Macke) Küchler
Moderator
Markus (Macke) Küchler
Head of Global IT Security Epiroc and Major (res)
Swedish Armed Forces
Luca Tagliaretti
Luca Tagliaretti
Executive Director
European Cybersecurity Competence Center
16:2518:00
Closing Remarks & Delegate Photo

Closing Remarks & Delegate Photo

18:00
Networking Dinner

Networking Dinner

By Invitation Only

Workshop 1 Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Date
29 Sep 2026
Workshop 2 Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment.
Time
11:15 – 13:15
Format
Masterclass + case analysis
Duration
2 hours
Date
29 Sep 2026
Workshop 3 Chapter 3 · Vendor Dependency & Sovereignty
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations operating outside the EU membership framework.
Time
13:15 – 15:15
Format
Masterclass + structured audit
Duration
2 hours
Date
29 Sep 2026
Workshop 4 Chapter 4 · Cybercrime & Borderless Threats
Cross-Border Cybercrime: What Private Sector Security Leaders Need to Know
A practitioner-led masterclass bridging private sector incident response and the realities of cross-jurisdictional law enforcement across borders.
Time
15:30 – 17:30
Format
Masterclass + Q&A
Duration
2 hours
Date
29 Sep 2026

Selected as the official venue for Next IT Security Belgrade, Sava Center stands as the most prestigious conference and business venue in the region. Following a complete transformation and modernization, it has become the preferred destination for major international events, bringing together industry leaders, decision-makers, and experts from around the world.

 

Located in the heart of New Belgrade’s business district, Sava Center provides the ideal environment for high-level discussions, networking, and knowledge exchange. Its state-of-the-art facilities, advanced technology, and impressive conference capacities deliver an experience that meets the standards of Europe’s leading events.

 

As a symbol of business excellence and international collaboration, Sava Center offers a setting where innovation, strategy, and leadership come together — perfectly reflecting the values of the Next IT Security community. 

Trusted by Cybersecurity Leaders

Our partners don’t just attend — they lead the conversation.

Limited partner slots available

Upcoming
Editions of Next IT Security

Exclusive access to industry leaders, actionable insights, and high-value executive networking.

Nordics Edition

Nordics Edition

Benelux Edition

Benelux Edition

Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.

DACH Edition

DACH Edition

Frankfurt earned the nickname “Mainhattan” for a skyline that rivals Manhattan’s. Dinner sits in the financial district with towers lit on every side, seating C-suite cyber minds alongside the day’s keynote speakers — no stage between you, just the conversation continuing.

East Central

East Central

Nordics Edition

Nordics Edition

Benelux Edition

Benelux Edition

Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials