Where Cybersecurity Leaders Connect and Decide What’s Next
This is not a typical conference.
Next IT Security Benelux is an exclusive gathering of cybersecurity decision-makers from across the Benelux region, designed for honest conversations, practical insights, and meaningful networking — free from vendor-driven presentations and unnecessary distractions.
Every conversation is intentional. Every connection is relevant.
This is where cybersecurity leaders meet to exchange insights that actually matter.
Event Location
Event Snapshot
Event Date
TBC, 15 April 2027
Duration
One-day executive event
Time
8:00 AM – 6:00 PM
Location
TBC, Amsterdam
Audience
CISOs, Heads of Security, IT Leaders
Attendance
Limited to 150 delegates
Join 150 Cybersecurity Leaders
Private, invitation-based event for CISOs and senior decision-makers.
- ✔ No vendors. No noise.
- ✔ Real discussions, real insights
- ✔ Closed-door executive environment
Event Aftermovie
Agenda
Roundtable Breakfast
Time for initial networking and informal peer exchange before the Opening Keynote.
When Software Goes Rogue — Accountability and Trust in Agentic Ecosystems
The First Digital Employee: When AI Starts Acting on Our Behalf
AI is moving beyond copilots and assistants. The next generation of enterprise AI will increasingly execute tasks, access systems, make decisions and interact with other software.
We explore what happens when software stops simply responding to humans and begins acting independently.
- When does an AI agent become an operational actor?
- How much autonomy should organizations allow?
- Who is accountable for an autonomous decision?
- How do you monitor AI operating at machine speed?
- Can an AI agent become an insider threat?
The Agentic Enterprise: Who Is Really in Control?
AI agents are increasingly being introduced into business processes, software development, security operations and decision-making. But autonomy creates a new security challenge: how do you control something designed to act independently?
- Human-in-the-loop vs human-on-the-loop
- Defining acceptable agent autonomy
- Agent permissions and authorization
- Monitoring autonomous actions
- Preventing unintended actions
- Accountability for AI-driven decisions
Securing the AI Workforce
The enterprise workforce of the future will not consist only of people. Organizations will increasingly deploy digital workers alongside human employees.
This session explores how security teams can establish controls around autonomous AI agents without preventing innovation.
- Agent identity
- Agent permissions
- Runtime monitoring
- Guardrails
- Policy enforcement
- Agent-to-agent security
Firestarter
Coffee Break & 1:1 Meetings
The New Identity Perimeter — Who Do You Trust When Humans Aren’t the Only Users?
The Death of the Human-Centric Perimeter
For decades, identity security has been built around people. That assumption is breaking down. Machines, APIs, workloads, applications and AI agents now require access to critical systems and data.
This keynote explores what identity means when digital interactions increasingly occur without a human directly involved.
- Non-human identity explosion
- Machine and workload identities
- AI agent identity
- Privileged access for autonomous systems
- Continuous authentication and authorization
- Identity as the foundation of AI security
Trust Without Humans: Can We Secure the Non-Human Enterprise?
The identity perimeter is expanding rapidly. Every new workload, API, machine and AI agent introduces another relationship that must be trusted, monitored and governed.
- Who gives an AI agent its identity?
- Should machines receive the same privileges as employees?
- How do we prevent identity sprawl?
- Can zero trust work in an autonomous environment?
- How do we revoke access from systems operating continuously?
- What happens when one compromised identity can control thousands of machines?
Identity at Machine Speed
Traditional identity security was designed around humans logging into applications. The autonomous enterprise requires identity decisions to happen continuously and programmatically.
This session explores the architecture required to secure machine-to-machine and agent-to-system interactions.
- Machine identity
- Secrets and credentials
- Privileged access
- Policy-based authorization
- Identity governance
- Continuous verification
Firestarter
Lunch Break
The CRA Countdown — From Regulation to Operational Reality
The CRA Is No Longer Someone Else’s Problem
The Cyber Resilience Act changes the way organizations must think about product security, software vulnerabilities and digital supply chains. With the December 2027 deadline approaching, security leaders need to understand what the regulation means beyond legal interpretation.
- Secure-by-design
- Vulnerability management
- Software supply chains
- SBOMs
- Product security
- Supplier accountability
- Incident reporting
- Security throughout the product lifecycle
CRA: Compliance Exercise or Security Transformation?
The CRA has the potential to fundamentally change how European organizations develop, procure and manage digital products. But will organizations treat it as another compliance obligation — or use it to fundamentally improve security?
- Who owns CRA responsibility inside the enterprise?
- How should CISOs work with product and engineering teams?
- What happens to legacy products?
- How should organizations assess suppliers?
- Can procurement become a security control?
- What will enforcement change?
From Secure-by-Design to Secure-by-Default
Security cannot be added at the end of the product lifecycle. This session explores how organizations can translate regulatory expectations into practical security engineering and product development.
- Security architecture
- Vulnerability disclosure
- Product lifecycle security
- Software supply-chain visibility
- Security testing and assurance
Coffee Break
From Cyber Resilience to Systemic Resilience — Can You Survive the Failure of Something You Don’t Control?
The Failure We Cannot Prevent
Organizations spend enormous resources protecting their own infrastructure. But some of the most consequential failures originate somewhere else — a cloud provider goes down, a critical supplier is compromised, an identity platform becomes unavailable, a software dependency fails, a telecommunications network is disrupted.
This keynote asks a different question: what happens when the thing we depend on fails — not by accident, but by geopolitical design?
- Concentration risk
- Cloud dependency
- Critical third-party providers
- Digital supply-chain disruption
- Identity and SaaS dependency
- Weaponized interdependence
- Subsea cable and infrastructure sabotage
- Sanctions impacting SaaS availability
- Business continuity beyond the enterprise perimeter
When the Ecosystem Fails: Can the Enterprise Keep Operating?
Modern organizations are ecosystems rather than isolated entities. The resilience of the enterprise increasingly depends on the resilience of its suppliers, technology platforms and infrastructure providers.
- How much dependency is too much dependency?
- Should organizations diversify critical technology providers?
- How do you identify systemic concentration risk?
- Can you build resilience without owning the infrastructure?
- What should the board understand about ecosystem risk?
- Where does third-party risk management end and systemic resilience begin?
Designing for Failure
The objective of resilience is not to prevent every failure. It is to ensure that critical business functions can continue when failure occurs.
This session explores practical approaches to designing organizations that can absorb disruption.
- Dependency mapping
- Digital continuity
- Recovery architecture
- Multi-provider strategies
- Resilience testing
- Preparing for cascading failures
Round Table Discussions
When AI Becomes Autonomous, Who Do We Trust?
- How much autonomy should organizations give AI agents?
- Who is accountable for an autonomous decision?
- Should AI agents have their own identities?
- Where should human oversight remain mandatory?
- How do we secure agent-to-agent interactions?
- How do we secure non-human identities?
- How do we control machine and AI access?
- Is zero trust still designed for the world we are entering?
- How do we prevent identity and privilege sprawl?
- Can we establish trust without human intervention?
The CRA Reality Check: Can We Survive What We Don’t Control?
- Are organizations actually ready for December 2027?
- Who owns CRA responsibility?
- How will product security change?
- Can procurement become a security control?
- How should organizations manage suppliers that cannot meet new expectations?
- What happens when a critical cloud provider fails?
- How much technology concentration is acceptable?
- Can third-party risk ever be fully understood?
- How do we prepare for cascading digital failures?
- What does systemic resilience look like at enterprise level?
Book Signing
Networking Dinner
No sessions in this filter.
Upcoming
Editions of Next IT Security
Exclusive access to industry leaders, actionable insights, and high-value executive networking.
Nordics Edition
- Stockholm, Sweden
- Grand Hotel
- 22 October 2026
- 08:00 AM – 06:00 PM
Nordics Edition
Benelux Edition
- Amsterdam, Netherlands
- Felix Meritis
- 12 November 2026
- 8:00 AM – 6:00 PM
Benelux Edition
DACH Edition
- Frankfurt, Germany
- Logenhaus zur Einigkeit
- 26 November 2026
- 8:00 AM – 6:00 PM
DACH Edition
East Central
- Belgrade, Serbia
- Sava Centar
- 31 October 2027
- 08:00 AM – 06:00 PM
East Central
Nordics Edition
- Stockholm, Sweden
- TBC
- 11 March 2027
- 8:00 AM – 6:00 PM
Nordics Edition
Limited seats available
Benelux Edition
- Amsterdam, Netherlands
- TBC
- 15 April 2027
- 8:00 AM – 6:00 PM
Benelux Edition
Limited seats available