Where Cybersecurity Leaders Connect and Decide What’s Next

Next IT Security conference, Stockholm — attendee networking

This is not a typical conference.

Next IT Security Benelux is an exclusive gathering of cybersecurity decision-makers from across the Benelux region, designed for honest conversations, practical insights, and meaningful networking — free from vendor-driven presentations and unnecessary distractions.

Every conversation is intentional. Every connection is relevant.
This is where cybersecurity leaders meet to exchange insights that actually matter.

Event Location

Event Snapshot

Event Date

TBC, 15 April 2027

Duration

One-day executive event

Time

8:00 AM – 6:00 PM

Location

TBC, Amsterdam

Audience

CISOs, Heads of Security, IT Leaders

Attendance

Limited to 150 delegates

Join 150 Cybersecurity Leaders

Private, invitation-based event for CISOs and senior decision-makers.

    • ✔ No vendors. No noise.
    • ✔ Real discussions, real insights
  • ✔ Closed-door executive environment

Event Aftermovie

Next IT Security — Benelux

Agenda

Day 01
TBC April 2027
TBC
08:00
Registration

Registration

08:1508:55
Roundtable Breakfast

Roundtable Breakfast

Time for initial networking and informal peer exchange before the Opening Keynote.

Chapter One

When Software Goes Rogue — Accountability and Trust in Agentic Ecosystems

09:0009:25
Opening Keynote

The First Digital Employee: When AI Starts Acting on Our Behalf

AI is moving beyond copilots and assistants. The next generation of enterprise AI will increasingly execute tasks, access systems, make decisions and interact with other software.

We explore what happens when software stops simply responding to humans and begins acting independently.

  • When does an AI agent become an operational actor?
  • How much autonomy should organizations allow?
  • Who is accountable for an autonomous decision?
  • How do you monitor AI operating at machine speed?
  • Can an AI agent become an insider threat?
09:2509:50
Expert Panel

The Agentic Enterprise: Who Is Really in Control?

AI agents are increasingly being introduced into business processes, software development, security operations and decision-making. But autonomy creates a new security challenge: how do you control something designed to act independently?

  • Human-in-the-loop vs human-on-the-loop
  • Defining acceptable agent autonomy
  • Agent permissions and authorization
  • Monitoring autonomous actions
  • Preventing unintended actions
  • Accountability for AI-driven decisions
09:5510:20
Innovator Keynote

Securing the AI Workforce

The enterprise workforce of the future will not consist only of people. Organizations will increasingly deploy digital workers alongside human employees.

This session explores how security teams can establish controls around autonomous AI agents without preventing innovation.

  • Agent identity
  • Agent permissions
  • Runtime monitoring
  • Guardrails
  • Policy enforcement
  • Agent-to-agent security
10:2510:30
Firestarter

Firestarter

10:3011:00
Coffee Break & 1:1 Meetings

Coffee Break & 1:1 Meetings

Chapter Two

The New Identity Perimeter — Who Do You Trust When Humans Aren’t the Only Users?

11:0011:25
Keynote

The Death of the Human-Centric Perimeter

For decades, identity security has been built around people. That assumption is breaking down. Machines, APIs, workloads, applications and AI agents now require access to critical systems and data.

This keynote explores what identity means when digital interactions increasingly occur without a human directly involved.

  • Non-human identity explosion
  • Machine and workload identities
  • AI agent identity
  • Privileged access for autonomous systems
  • Continuous authentication and authorization
  • Identity as the foundation of AI security
11:2511:50
Expert Panel

Trust Without Humans: Can We Secure the Non-Human Enterprise?

The identity perimeter is expanding rapidly. Every new workload, API, machine and AI agent introduces another relationship that must be trusted, monitored and governed.

  • Who gives an AI agent its identity?
  • Should machines receive the same privileges as employees?
  • How do we prevent identity sprawl?
  • Can zero trust work in an autonomous environment?
  • How do we revoke access from systems operating continuously?
  • What happens when one compromised identity can control thousands of machines?
11:5012:15
Innovator Keynote

Identity at Machine Speed

Traditional identity security was designed around humans logging into applications. The autonomous enterprise requires identity decisions to happen continuously and programmatically.

This session explores the architecture required to secure machine-to-machine and agent-to-system interactions.

  • Machine identity
  • Secrets and credentials
  • Privileged access
  • Policy-based authorization
  • Identity governance
  • Continuous verification
12:1512:20
Firestarter

Firestarter

12:2013:20
Lunch Break

Lunch Break

Chapter Three

The CRA Countdown — From Regulation to Operational Reality

13:2013:45
Keynote

The CRA Is No Longer Someone Else’s Problem

The Cyber Resilience Act changes the way organizations must think about product security, software vulnerabilities and digital supply chains. With the December 2027 deadline approaching, security leaders need to understand what the regulation means beyond legal interpretation.

  • Secure-by-design
  • Vulnerability management
  • Software supply chains
  • SBOMs
  • Product security
  • Supplier accountability
  • Incident reporting
  • Security throughout the product lifecycle
13:4514:10
Expert Panel

CRA: Compliance Exercise or Security Transformation?

The CRA has the potential to fundamentally change how European organizations develop, procure and manage digital products. But will organizations treat it as another compliance obligation — or use it to fundamentally improve security?

  • Who owns CRA responsibility inside the enterprise?
  • How should CISOs work with product and engineering teams?
  • What happens to legacy products?
  • How should organizations assess suppliers?
  • Can procurement become a security control?
  • What will enforcement change?
14:1514:40
Innovator Keynote

From Secure-by-Design to Secure-by-Default

Security cannot be added at the end of the product lifecycle. This session explores how organizations can translate regulatory expectations into practical security engineering and product development.

  • Security architecture
  • Vulnerability disclosure
  • Product lifecycle security
  • Software supply-chain visibility
  • Security testing and assurance
14:4515:15
Coffee Break

Coffee Break

Chapter Four

From Cyber Resilience to Systemic Resilience — Can You Survive the Failure of Something You Don’t Control?

15:1515:40
Keynote

The Failure We Cannot Prevent

Organizations spend enormous resources protecting their own infrastructure. But some of the most consequential failures originate somewhere else — a cloud provider goes down, a critical supplier is compromised, an identity platform becomes unavailable, a software dependency fails, a telecommunications network is disrupted.

This keynote asks a different question: what happens when the thing we depend on fails — not by accident, but by geopolitical design?

  • Concentration risk
  • Cloud dependency
  • Critical third-party providers
  • Digital supply-chain disruption
  • Identity and SaaS dependency
  • Weaponized interdependence
  • Subsea cable and infrastructure sabotage
  • Sanctions impacting SaaS availability
  • Business continuity beyond the enterprise perimeter
15:4016:05
Expert Panel

When the Ecosystem Fails: Can the Enterprise Keep Operating?

Modern organizations are ecosystems rather than isolated entities. The resilience of the enterprise increasingly depends on the resilience of its suppliers, technology platforms and infrastructure providers.

  • How much dependency is too much dependency?
  • Should organizations diversify critical technology providers?
  • How do you identify systemic concentration risk?
  • Can you build resilience without owning the infrastructure?
  • What should the board understand about ecosystem risk?
  • Where does third-party risk management end and systemic resilience begin?
16:1016:35
Innovator Keynote

Designing for Failure

The objective of resilience is not to prevent every failure. It is to ensure that critical business functions can continue when failure occurs.

This session explores practical approaches to designing organizations that can absorb disruption.

  • Dependency mapping
  • Digital continuity
  • Recovery architecture
  • Multi-provider strategies
  • Resilience testing
  • Preparing for cascading failures
16:3517:40
Round Table Discussions

Round Table Discussions

When AI Becomes Autonomous, Who Do We Trust?

  • How much autonomy should organizations give AI agents?
  • Who is accountable for an autonomous decision?
  • Should AI agents have their own identities?
  • Where should human oversight remain mandatory?
  • How do we secure agent-to-agent interactions?
  • How do we secure non-human identities?
  • How do we control machine and AI access?
  • Is zero trust still designed for the world we are entering?
  • How do we prevent identity and privilege sprawl?
  • Can we establish trust without human intervention?

The CRA Reality Check: Can We Survive What We Don’t Control?

  • Are organizations actually ready for December 2027?
  • Who owns CRA responsibility?
  • How will product security change?
  • Can procurement become a security control?
  • How should organizations manage suppliers that cannot meet new expectations?
  • What happens when a critical cloud provider fails?
  • How much technology concentration is acceptable?
  • Can third-party risk ever be fully understood?
  • How do we prepare for cascading digital failures?
  • What does systemic resilience look like at enterprise level?
17:45
Book Signing

Book Signing

18:00
Networking Dinner

Networking Dinner

Upcoming
Editions of Next IT Security

Exclusive access to industry leaders, actionable insights, and high-value executive networking.

Nordics Edition

Nordics Edition

Benelux Edition

Benelux Edition

Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.

DACH Edition

DACH Edition

Frankfurt earned the nickname “Mainhattan” for a skyline that rivals Manhattan’s. Dinner sits in the financial district with towers lit on every side, seating C-suite cyber minds alongside the day’s keynote speakers — no stage between you, just the conversation continuing.

East Central

East Central

Nordics Edition

Nordics Edition

Benelux Edition

Benelux Edition

Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials