Where Cybersecurity Leaders Connect and Decide What’s Next
This is not a typical conference.
Next IT Security Stockholm brings together a carefully selected group of cybersecurity leaders to share real experiences, challenge ideas and build meaningful connections — without noise, without sales pitches, and without wasted time.
Every conversation is intentional. Every connection is relevant. This is where cybersecurity leaders meet to exchange insights that actually matter.
Event Location
Event Snapshot
Event Date
22 October 2026
Duration
One-day executive event
Time
08:00 AM – 06:00 PM
Location
The Grand Hôtel in Stockholm, Sweden
Audience
CISOs, Heads of Security, IT Leaders
Attendance
Limited to 150 delegates
Join 150 Cybersecurity Leaders
Private, invitation-based event for CISOs and senior decision-makers.
Discover how ThreatLocker applies Zero Trust at the endpoint, eliminating implicit trust by continuously verifying every application, executable, and action before authorisation
Learn how a deny-by-default, malware-proofing approach reduces ransomware risk, stopping unauthorised software and scripts even when other security layers are bypassed
Understand how least-privilege enforcement limits attacker capability, ensuring applications and users can perform only explicitly approved actions on enterprise devices
Explore how granular, policy-based endpoint control safeguards against modern threats, reducing enterprise exposure to ransomware and other advanced attacks
Speakers
Raphael Marranghello
Enterprise Account Executive
ThreatLocker
Chapter One
National Resilience, Regulatory & Geopolitical Complexity
09:00↓09:25
Opening Keynote
Building Cyber Resilience Across a Global Law-Enforcement Ecosystem
In today’s interconnected world, cybersecurity extends far beyond organizational boundaries. For INTERPOL, enabling secure collaboration across 196 member countries means protecting a global law-enforcement ecosystem that operates 24/7, processes billions of records, and supports millions of database queries each day.
This session explores how cybersecurity is approached in an environment defined by international cooperation, varying levels of security maturity, and highly sensitive data exchange. It highlights the challenges of securing globally connected systems where trust between agencies is critical to operational success.
The talk will present a strategic view of INTERPOL’s cybersecurity approach, built on three key pillars: governance and risk management, security operations, and the human layer. Particular focus will be placed on how cyber resilience is strengthened across different audiences, from internal personnel to National Central Bureaus (NCBs) and the wider public.
Attendees will gain insights into how security culture, governance, and collaboration contribute to resilience in complex, distributed environments, and how these lessons can be applied to enterprise organizations operating across borders and ecosystems.
Speakers
Osama TAHA
Business Information Security Officer (BISO)
INTERPOL
09:25↓10:00
Expert Panel
Boardroom to Battlefield: Leading in a Politically Charged Cyber Landscape
High-stakes incidents can impact markets, public trust, and critical services. Panelists discuss turning compliance obligations into strategic advantage, coordinating across sectors, and managing operational risks under geopolitical pressure.
Transforming regulations into actionable strategies Shows how organizations can convert compliance requirements into practical operations that protect enterprise and societal interests.
Building trust and collaboration between public and private sectors Highlights partnerships that enable effective threat intelligence sharing and coordinated response.
Managing operational continuity under high-stakes events Demonstrates crisis planning and real-time decision-making to maintain operations despite political or societal pressures.
Speakers
Moderator
Per Gustavsson
Executive Leader
Stratsys
Linda Avad
CISO
Alecta
Monika Kullberg
Cybersecurity Culture Manager & Psychologist
Sandvik Group
Johanna Parikka Altenstedt
Acting Head of Cybercenter and the Digital Security Unit
RISE
Henrik Tholsby
CISO
Danderyds sjukhus
10:00↓10:20
Innovator Keynote
Business Continuity at Global Scale: Keeping Critical Applications Running Under Pressure
As organizations expand across borders and face increasingly complex regulations, security architectures must do more than protect systems—they must enable growth, ensure compliance, and remain resilient under geopolitical pressures. This session explores how to build frameworks that integrate security, compliance, and operational efficiency without compromising innovation.
Achieving Visibility and Accountability Across Operations In multinational environments, organizations need centralized monitoring and control to maintain oversight of diverse systems. Effective architectures provide clear accountability, enabling teams to detect, respond, and report on security events in real time.
Embedding Compliance into Everyday Operations Regulatory requirements can slow innovation if treated as an afterthought. By operationalizing compliance frameworks, organizations can integrate legal and policy obligations into daily workflows, ensuring adherence without disrupting productivity.
Maintaining Resilience Amid Geopolitical Complexity Political and regulatory uncertainty can impact security effectiveness. Security architectures designed for resilience anticipate disruptions, adapt to changing conditions, and safeguard critical assets even in unstable environments.
Speakers
Sami Laurila
Rubrik
10:20↓10:50
Break
Coffee Break & 1-1 meetings
10:50↓10:55
Firestarter
Firestarter
Chapter Two
Securing What Cannot Fail: OT, Critical Infrastructure & Supply Chains
10:55↓11:20
Keynote Discussion
Protecting What Cannot Fail: Insights from Critical Infrastructure
Critical infrastructure—from energy grids to healthcare systems—forms the backbone of modern society, and disruptions can have immediate, far-reaching consequences. This session delves into strategies for maintaining operational resilience, achieving comprehensive visibility, and ensuring supply chain integrity in environments where failure is not an option.
Implementing Structured OT Monitoring and Alerting Developing robust operational technology monitoring frameworks allows organizations to detect anomalies early, preventing small issues from escalating into major incidents that could disrupt critical services.
Strengthening Third-Party and Supply Chain Security Protecting interconnected systems requires a proactive approach to supplier risk management. By assessing and securing third-party dependencies, organizations reduce vulnerabilities that could compromise the broader operational ecosystem.
Coordinating Crisis Response Across Interconnected Systems Effective resilience depends on planning, simulating, and executing coordinated responses across multiple critical systems. Structured crisis management ensures rapid recovery and minimizes impact during incidents affecting essential services.
Speakers
Dan Cristian Ungureanu
Cyber Exercises Director
CR14 (Estonian Ministry of Defence), NATO Cooperative Cyber Defence Centre of Excellence (Former CCDCOE)
11:20↓11:55
Expert Panel
The Playbook for Securing Critical Systems
In an era where mission-critical infrastructure underpins society and the economy, defending these systems against cyber threats has never been more urgent. This panel brings together industry experts to share practical strategies for protecting operational environments, managing supply chain risks, and ensuring continuity in high-stakes situations.
Operational Technology (OT) and supply chain visibility are essential for understanding and mitigating risks across complex systems. Panelists will discuss frameworks and tools that provide comprehensive monitoring and situational awareness, enabling organizations to act before small issues escalate into major disruptions.
Managing supplier risks and coordinating operations across third-party networks is crucial to reducing vulnerabilities. Experts will explore techniques for assessing vendor security, strengthening collaboration, and maintaining continuity even when partners face threats or disruptions.
Drawing on real-world critical infrastructure incidents, panelists will share lessons learned from previous breaches and failures. These insights provide actionable guidance for building resilient systems, improving incident response, and avoiding common pitfalls in high-risk operational environments.
Speakers
Moderator
Ilkka Turunen
Field CTO
Sonatype
Johan Thulin
Cybersäkerhetsstrateg
Sveriges Kommuner och Regioner
Dan Cristian Ungureanu
Lead of Cyber Exercises
NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE)
Reljo Saarepera
Programme Director
ISO 27001 Lead Auditor, Estonian Public Procurement Center
Victor Pettersson
CISO
Sokigo
Luise Bang
Board Director | Energy, Defence & Industrial Technology
Former Executive at Airbus, Bombardier & Vodafone, Abena
11:55↓12:20
Innovator Keynote
Technology-Enabled Resilience for High-Stakes Environments
In sectors where failure is not an option—such as energy, transportation, and industrial operations—resilience must be built into every system and process. This session explores how technology-driven platforms and frameworks can safeguard critical infrastructure while maintaining operational performance, ensuring organizations can anticipate, respond to, and recover from disruptions effectively.
Leveraging real-time monitoring and predictive risk modeling Advanced tools provide continuous visibility into systems and operations, enabling organizations to detect emerging threats and anticipate their potential impact on critical processes before they escalate.
Strengthening OT threat identification and mitigation Specialized frameworks allow organizations to assess vulnerabilities in Operational Technology, implement preventive controls, and reduce the risk of disruptions in industrial and operational environments.
Implementing supply chain assurance frameworks Structured approaches enhance oversight of complex supplier networks, ensuring transparency, operational continuity, and the ability to respond quickly to disruptions across interconnected ecosystems.
12:20↓13:20
Break
Lunch Break
Chapter Three
AI Risk & Governance
13:20↓13:45
Best practise Keynote
Learn about the Topic
Cybercrime has evolved into a sophisticated global ecosystem where specialization, commercialization, and digital services have lowered the barrier to committing serious crimes. This talk explores how emerging technologies — particularly artificial intelligence — are accelerating this shift, enabling more scalable, automated, and convincing attacks.
From the rise of Crime-as-a-Service models such as ransomware and extortion kits, to new and alarming developments like Violence-as-a-Service, the boundaries between digital and physical threats are increasingly blurred. At the same time, attackers are becoming more strategic, targeting critical infrastructure and exploiting supply chains to maximize impact.
In this rapidly changing and borderless threat landscape, prevention is no longer optional — it is essential. The session highlights the need for stronger international cooperation where public and private actors work together to build resilience against modern cyber threats.
Speakers
Björn Eriksson
Section Head
National Cybercrime Center, Noa, Polismyndigheten
13:45↓14:20
Expert Panel
Defensive AI: Harnessing Intelligence to Stay Ahead of Cyber Threats
As cyber threats grow faster and more sophisticated, organizations are turning to AI not just as a tool, but as a strategic defender. This panel explores how artificial intelligence can enhance security, improve operational efficiency, and maintain ethical and regulatory compliance, all while keeping human judgment at the center of decision-making.
AI can dramatically improve threat detection and response, acting as a force multiplier to identify and mitigate attacks faster than human-only processes. This accelerates response times and reduces the window of exposure to cyber incidents.
Automation must be carefully balanced with human oversight and operational priorities. By combining AI efficiency with expert judgment, organizations can avoid unintended outcomes and ensure security actions align with business and safety objectives.
As AI adoption expands, regulatory and ethical considerations become increasingly critical. Preparing for evolving legal frameworks and societal expectations helps organizations deploy AI responsibly while minimizing risk and maintaining trust.
Speakers
Moderator
Ash Hunt
VP of Strategy
Cyera
Gabriele Dauriz
Security Product Manager
TRATON Financial Services
Vikram Jeet
IT Risk & Compliance Manager
Alleima
Ioanna Hurubeanu
CISO
Quinyx
Sandip Wadje
Managing Director- Global Head of Emerging Technology Operational Risks & Intelligence
BNP Paribas
14:20↓14:45
Innovator Keynote
Building Trustworthy AI Across Complex Environments
As AI becomes deeply integrated into enterprise operations, securing these systems while preserving efficiency is critical. This session explores strategies to build trustworthy AI that organizations can rely on, even in complex and highly regulated environments.
Ensuring transparency, accountability, and auditability is essential for maintaining confidence in AI-driven decisions. By making AI operations understandable and verifiable, organizations can foster trust among stakeholders and users alike.
Implementing robust governance across enterprise AI provides a structured approach to policies, controls, and continuous monitoring. This framework ensures AI systems operate consistently, safely, and in alignment with organizational objectives.
Mitigating operational and reputational risks protects organizations from AI failures, unintended consequences, or bias. Proactive risk management safeguards both the enterprise and its stakeholders, preserving credibility and long-term value.
Speakers
Magnus Järnhandske
Chief of Cyber Security Operations
Asurgent
14:45↓15:15
Break
Coffee Break
Chapter Four
Talent & Skills Shortage
15:15↓15:40
Innovator Keynote
Workforce Sustainability: Securing People as a Critical Asset
Talent shortages in cybersecurity, AI, OT, and compliance are limiting organizational resilience. This session explores workforce strategies to upskill employees, prevent burnout, and maintain operational effectiveness.
Succession planning, cross-training, and workforce development Ensures continuity of expertise and critical skills.
Retention strategies and preventing burnout Maintains high-performing teams without overloading staff.
Building a culture that attracts and sustains top talent Enhances employer value and employee motivation
15:40↓16:00
Innovator Fireside Chat
Bridging the Cyber Skills gap: From awareness to action
With increasing operational complexity, organizations can no longer rely solely on technical defenses. Workforce sustainability, cross-training, and knowledge transfer are critical to maintaining resilience. This session examines how modern frameworks and programs empower teams to operate effectively while mitigating risks associated with talent shortages.
16:00↓16:50
Round Table Discussions
The Topics
Building cross-functional skillsets to fill critical gaps
Succession planning and knowledge transfer strategies
Each topic will be discussed at dedicated roundtables, allowing participants to exchange experiences and explore practical strategies for improving resilience across operational environments.
Speakers
Rikard
PBAB REDOVISNING OCH REVISION AB
Payam Razifar
Information Security Specialist
Bravida
Smeden Svahn
CISO
Adda
Vikram Jeet
IT Risk & Compliance Manager
Alleima
Ph.D. Girish Agarwal
Chief Digital & Information Officer
Vaisala
Thomas Lindén
CTO
TSS
Ioanna Hurubeanu
CISO
Quinyx
Ricardo Bergvall
Chief Information Security Officer
Travel Clearings
16:50↓17:00
Transfer
Short walk to Networking Dinner Cruise
17:00↓17:25
Fireside Panel
Securing AI in Action
Red Team Perspective: Identifying AI Vulnerabilities How offensive teams simulate real-world attacks on AI systems to uncover weaknesses, adversarial risks, and bias. The discussion highlights methods for probing operational and enterprise AI while staying aligned with ethical and regulatory boundaries.
Blue Team Perspective: Defending AI Operations How defensive teams implement monitoring, incident response, and protective controls to ensure AI systems remain reliable and secure. The focus is on maintaining operational continuity, preventing misuse, and preserving stakeholder trust in automated decisions.
Purple Team Perspective: Integrating Offensive and Defensive Insights How collaboration between red and blue teams strengthens AI governance, risk management, and resilience. The panel explores frameworks for continuous learning, cross-team feedback loops, and adaptive controls that enhance the security posture of AI at scale.
Speakers
Moderator
Luise Bang
Board Director | Energy, Defence & Industrial Technology
Former Executive at Airbus, Bombardier & Vodafone, Abena
Sandip Wadje
Managing Director- Global Head of Emerging Technology Operational Risks & Intelligence
Selected as the official venue for Next IT Security Stockholm, Grand Hôtel offers a setting that supports privacy, discretion and high-level interaction.
The Grand Hôtel in Stockholm has been home to celebrities, high-profile events and everyday bon-vivants since 1874. Situated in the best waterfront location imaginable, the hotel overlooks the Royal Palace and Gamla Stan, Stockholm’s old town.
The Grand is also home to the classic Swedish Veranda restaurant, renowned for its traditional smörgåsbord, Mathias Dahlgren’s awarded restaurants and the spectacular Cadier Bar.
Dinner closes the day forty stories up, in the St. Regis atop Kula Belgrade — the tallest tower on the Belgrade Waterfront, glass reflecting the Sava and Danube below. C-suite cyber minds take the panoramic restaurant at the top, city lights spreading out in every direction.
Stockholm’s Grand Hôtel has hosted royalty since 1874 — now it hosts Next IT Security. Sessions close, doors open onto the water, and a private boat carries C-suite cyber minds into the Stockholm archipelago for conversations held under Chatham House rules — no notes, no headlines.
Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
Frankfurt earned the nickname “Mainhattan” for a skyline that rivals Manhattan’s. Dinner sits in the financial district with towers lit on every side, seating C-suite cyber minds alongside the day’s keynote speakers — no stage between you, just the conversation continuing.
Join us for the exclusive Cybersecurity Event at Stockholm. This exclusive event offers a unique opportunity to network with C-suite Power Players, whilst enjoying fine dining and entertainment in a spectacular setting. Our C-Suites are our strength.
Amsterdam works best from the water and from above, so that’s how we’re doing it. A private canal cruise leads into dinner on one of the city’s best rooftops — a tightly curated table of C-suite cyber minds, kept deliberately small so every conversation counts.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.