Where Cybersecurity Leaders Connect and Decide What’s Next

Next IT Security conference, Stockholm — attendee networking

This is not a typical conference.

Next IT Security Stockholm brings together a carefully selected group of cybersecurity leaders to share real experiences, challenge ideas and build meaningful connections — without noise, without sales pitches, and without wasted time.

Every conversation is intentional. Every connection is relevant.
This is where cybersecurity leaders meet to exchange insights that actually matter.

Event Location

Event Snapshot

Event Date

11 March 2027

Duration

One-day executive event

Time

08:00 AM – 18:00 PM

Location

Berns, Stockholm, Sweden

Audience

CISOs, Heads of Security, IT Leaders

Attendance

Limited to 150 delegates

Join 150 Cybersecurity Leaders

Private, invitation-based event for CISOs and senior decision-makers.

    • ✔ No vendors. No noise.
    • ✔ Real discussions, real insights
  • ✔ Closed-door executive environment

March Event Aftermovie

Next IT Security — Nordics

Agenda

Day 01
March 2027
Berns, Stockholm
08:00
Registration

Registration

08:15
Power Breakfast

Roundtable Breakfast

An opportunity to connect with fellow CISOs, security leaders and industry experts before the conference officially begins.

08:55
Firestarter

Firestarter

Chapter One

AI-Driven Attacks & the Collapse of Human-Speed Security

09:0009:25
Opening Keynote

AI-Driven Attacks: When Attack Speed Exceeds Human Capacity

Automation and AI have compressed attacker timelines to a fraction of what human-led detect-decide-respond processes were built for. When that cycle can’t keep pace with the threat, something in the operating model has to give.

This session looks at what security leaders are actually changing — escalation paths, staffing models, and how much trust gets placed in automation — now that speed itself has become the primary constraint.

  • Operating when attacks move faster than human decision cycles
  • Redefining detection, response and escalation
  • Balancing automation with human judgement
  • Preparing security teams for increasingly autonomous attacks
09:2510:00
Expert Panel 1

From Human-in-the-Loop to Machine-Speed Defence: Who Makes the Decision?

AI is accelerating both sides of the fight, which forces an uncomfortable question: where does a machine get to act on its own, and where does a human still have to sign off? This panel digs into how organisations are actually redrawing those lines — decision rights, accountability, and what “trustworthy automation” looks like in practice.

  • What should security teams automate — and what should remain human-controlled?
  • Redefining decision rights in AI-enabled security operations
  • How much autonomy should AI-driven security systems have?
  • Building trust in automated detection and response
  • Preparing security teams for increasingly autonomous threats
10:0010:20
Innovator Keynote

Building Machine-Speed Security Operations

If attackers are using automation to move faster, defenders need the same edge. This session covers what AI-assisted detection, investigation and automated containment look like in practice — and how much of that can run without a human in the loop before it starts creating new risk of its own.

  • AI-assisted detection and investigation
  • Automated response and containment
  • Reducing time-to-detect and time-to-respond
  • Human oversight of autonomous security operations
10:2010:50
Break

Coffee Break & 1:1 Meetings

Chapter Two

CRA: From Reporting to Product Security by Design

10:5010:55
Chapter Introduction

Chapter Introduction

10:5511:20
Keynote

CRA Six Months Later: What We Have Learned from Putting Product Security into Practice

Six months into CRA implementation, the gap between the regulation on paper and what it actually demands from engineering, security and compliance teams has become clear.

This keynote shares what’s worked, what hasn’t, and what still needs to change before the next compliance milestone.

  • Lessons from early CRA reporting requirements
  • Where product-security processes are proving most difficult
  • Aligning security, engineering, product and compliance teams
  • Building security into the product lifecycle
  • Preparing for the next stage of CRA implementation
11:2011:50
Expert Panel 2

Beyond Compliance: Can CRA Become a Competitive Advantage?

For Nordic tech and industrial firms, CRA compliance is starting to shape how products get designed, sold and trusted — not just how they get certified. This panel debates whether that shift is a cost centre in disguise or a genuine differentiator, and what it takes to make that case internally.

  • What has CRA implementation exposed inside organisations?
  • Who should own product cybersecurity?
  • Integrating security into product development and engineering
  • Managing vulnerability disclosure and software supply chains
  • Can secure-by-design become a competitive differentiator?
11:5512:15
Innovator Keynote

Embedding Security Across the Product Lifecycle

Product security doesn’t stop at ship date — it has to follow the product through deployment, patching and eventual end-of-life. This session walks through practical approaches to secure-by-design development, supply chain visibility and coordinated disclosure that hold up across that whole lifecycle.

  • Secure-by-design development
  • Software supply chain visibility
  • Vulnerability management and coordinated disclosure
  • Continuous product security assurance
12:2013:20
Break

Networking Lunch

Chapter Three

Identity as the New Control Plane

13:2013:40
Best Practice Keynote

Identity Beyond the Human: Securing Machine and AI Agents

Employees and customers are no longer the majority of identities in most enterprises — applications, workloads and increasingly autonomous AI agents are. As those non-human identities pick up access to critical systems, the old assumptions behind identity governance stop holding.

This keynote covers what visibility and control actually look like once machines outnumber people in the directory.

  • The rise of non-human identities
  • Securing AI agents and autonomous systems
  • Privileged access for machines and workloads
  • Identity governance across hybrid and cloud environments
  • Establishing accountability for autonomous actions
13:4514:15
Expert Panel 3

Rebuilding Identity Security for an Enterprise Full of Machines

Traditional IAM was built around people, and it’s showing its age now that non-human identities can outnumber the human workforce several times over. Security leaders discuss what’s actually changing in how machine and AI agent access gets provisioned, scoped and revoked.

  • Managing machine and workload identities at scale
  • Governing AI agents and autonomous access
  • Privileged access and least privilege in an automated environment
  • Visibility and accountability for non-human identities
  • Balancing security with the speed of digital transformation
14:2014:40
Innovator Keynote

Securing the Non-Human Enterprise

Service accounts, workloads and AI agents have quietly become their own access layer — one most IAM systems were never designed to govern. This session covers the practical mechanics of finding them, managing their privileges and keeping tabs on what they’re doing.

  • Machine identity lifecycle management
  • Securing AI agent access
  • Privilege management
  • Continuous identity monitoring
14:4515:15
Break

Coffee Break

Chapter Four

Rebuilding Trust in a Fragmented World

15:1515:35
Keynote

Reassessing Trust in an Interconnected Technology Stack

Nordic organisations run on a dense web of global cloud providers, software vendors and infrastructure partners — and geopolitical tension is putting new pressure on how much of that can still be assumed to hold.

This keynote looks at how CISOs are re-mapping their real dependencies, not just their contractual ones.

  • Understanding strategic technology dependencies
  • Cloud and SaaS concentration risk
  • Geopolitical risk and cybersecurity
  • Data and technology sovereignty
  • Knowing what your organisation truly depends on
15:4016:10
Expert Panel 4

Beyond the Vendor Risk Questionnaire: Managing Trust Across the Digital Ecosystem

The annual vendor questionnaire was never built for a world of concentrated cloud dependency and shifting geopolitics. This panel asks a harder question than “is this supplier secure”: can we keep depending on them at all, and what changes when the answer becomes no?

  • Moving beyond traditional third-party risk assessments
  • Managing concentration and systemic supplier risk
  • Cloud, SaaS and critical technology dependencies
  • Software supply chain security
  • Geopolitical considerations in technology sourcing
  • What should happen when trust in a critical supplier changes?
16:1516:35
Innovator Keynote

Building Visibility Across the Modern Digital Supply Chain

You can’t manage a dependency you can’t see. This session looks at how organisations are mapping suppliers, software and infrastructure deep enough to catch concentration risk before it becomes a headline.

  • Third-party and supply chain visibility
  • Continuous risk monitoring
  • Identifying critical dependencies
  • Managing concentration risk
  • Building resilience across the digital ecosystem
16:3516:50
Transition

Transition to Roundtable Discussions

16:5017:40
Executive Roundtable Discussions

Executive Roundtable Discussions

Four parallel, CISO-led discussions — each mapped to one of the day’s chapters. Participants join the tables where the questions matter most to their organisation.

01 · Operating at Machine Speed — Focus: AI-Driven Attacks & Human Capacity

As AI accelerates the speed and scale of cyber attacks, security organisations must rethink how decisions are made and how much autonomy can safely be given to machines.

  • Where should AI be allowed to act autonomously?
  • Which security decisions still require human judgement?
  • How are organisations redesigning SOC operating models?
  • How do we measure readiness for machine-speed attacks?

02 · CRA in the Real World — Focus: CRA & Product Security

The CRA is moving cybersecurity deeper into product development and organisational processes. CISOs and product security leaders discuss the practical challenges of turning regulatory requirements into sustainable product-security practices.

  • What has been hardest about implementing CRA requirements?
  • Who owns product cybersecurity?
  • How are engineering and security teams collaborating?
  • Can product security become a competitive advantage?

03 · The Non-Human Identity Explosion — Focus: Identity & AI Agents

The number of machine identities, workloads and AI agents is rapidly expanding. Security leaders discuss how organisations can maintain control when non-human identities increasingly interact with critical systems.

  • How are organisations discovering non-human identities?
  • How should AI agents be governed?
  • How do you prevent privilege from spreading across autonomous systems?
  • Who is accountable for an AI agent’s actions?

04 · What Can We Still Trust? — Focus: Third-Party, Supply Chain & Geopolitical Risk

Nordic organisations are increasingly dependent on global technology ecosystems while facing a more complex geopolitical environment. This discussion explores how CISOs are reassessing technology and supplier trust.

  • Which dependencies create the greatest strategic risk?
  • How should organisations assess concentration risk?
  • What happens when a trusted supplier becomes a geopolitical concern?
  • How much visibility do CISOs really have across their digital supply chains?
17:4017:50
Transition

Transition to Networking Reception

18:00
Networking

Networking Dinner

What makes Berns venues stand out is our distinctive blend of historical settings and contemporary spaces, creating a unique atmosphere. Our venues is equipped to host a wide range of events and meetings, ensuring there’s something suitable for every occasion. Boasting Stockholm’s most extraordinary event venues, we approach event planning with a generous dose of courage and a keen ability to listen, resulting in outstanding experiences for each guest.

Upcoming
Editions of Next IT Security

Exclusive access to industry leaders, actionable insights, and high-value executive networking.

Nordics Edition

Nordics Edition

Benelux Edition

Benelux Edition

Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.

DACH Edition

DACH Edition

Frankfurt earned the nickname “Mainhattan” for a skyline that rivals Manhattan’s. Dinner sits in the financial district with towers lit on every side, seating C-suite cyber minds alongside the day’s keynote speakers — no stage between you, just the conversation continuing.

East Central

East Central

Nordics Edition

Nordics Edition

Benelux Edition

Benelux Edition

Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
✓ Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials