CSO Cybersecurity Awards & Conference UK

Latest 2026 Programme

New sessions and speakers updated regularly. Check back for the latest

Thursday, November 26

09:00 – 09:10
Chair’s Opening Remarks
Speaker
Georgina Owens Contributing Editor CIO
09:10 – 09:40
Opening Panel Discussion: Ask the Regulators – The Questions You’ve Always Wanted to Ask, but Never Had the Chance

Forget presentations and prepared statements. This is your opportunity to put your toughest questions directly to the UK’s leading cyber and data regulators. With no slides, no speeches and no pre-approved agenda, this candid “Ask Me Anything” session gives CIOs and CISOs unprecedented access to the organisations shaping the UK’s cyber, data protection and operational resilience landscape.

Questions to explore:

– What are regulators seeing that organisations are still getting wrong?
– What does “good” cyber governance really look like in 2026?
– How will AI change regulatory expectations over the next three years?
– Which emerging risks are keeping regulators awake at night?
– How can organisations build stronger relationships with regulators before an incident occurs?
– If you could give every FTSE 100 board one piece of advice, what would it be?
– What do organisations consistently overestimate – or underestimate – about regulatory scrutiny?

Bringing together representatives from regulatory bodies for an “Ask Me Anything” session. No presentations- only audience questions.

Speaker
Georgina Owens Contributing Editor CIO
09:40 – 10:00
Headliner Partner Presentation – Riot
10:00 – 10:20
Keynote Presentation: When the Attack Comes – The Inside Response to a Major Cyber Incident

When a sophisticated, multi-stage cyber attack strikes, every decision matters. In this candid session, one CISO reflects on the organisation’s experience following a cyber incident. From leading through uncertainty to balancing business continuity with recovery, discover the lessons that reshaped an approach to cyber resilience and what every executive team should be preparing for before -not after- an attack.

– The first 24 hours: What really happens when a major cyber incident unfolds?
– Leading under pressure: How do you make critical decisions with incomplete information?
– Keeping the business running while responding to an evolving threat
– Working with the board, regulators, customers and the media during a crisis
– What surprised us most – and the lessons we wish we’d known beforehand
– How the incident has changed our approach to cyber resilience, technology investment and organisational preparedness

If we could start again, what would we do differently?

10:20 – 10:25
Introductions for Morning Breakout Sessions
10:25 – 10:55
Networking Break
10:55 – 11:40
Morning Breakout Session 1: Inside the Security Operations of Industry Leaders – How the Experts Secure Themselves

The world’s leading cybersecurity providers face the same evolving threats as every other organisation – but with the added pressure of setting the standard for the industry. In this fast-paced executive session, senior security leaders share how they’re transforming their own security operations, responding to emerging threats and deciding where to invest next. Expect honest insights into what’s working, what isn’t, and the technologies and strategies shaping the future of cyber defence.

Hear first-hand:

– How we’ve implemented new security technologies across our own organisations
– The biggest cyber challenges we’re facing – and how they’re evolving
– How AI is reshaping our security operations, governance and decision-making
– Emerging threats we’re preparing for over the next 12–24 months
– Technologies and capabilities we’re prioritising – and those we’re moving away from
– How we’re balancing innovation, resilience and operational complexity
– Lessons learned from transformation programmes and major security initiatives
– One prediction every CIO and CISO should be planning for today

Speaker
Georgina Owens Contributing Editor CIO
Speaker
Stephen McDermid CSO EMEA Okta
Speaker
Matthew O’Neill Field CTO Salesforce
Morning Breakout Session 2
Morning Breakout Session 3
11:45 – 12:05
Keynote Presentation: Inside a Large Enterprise Security Budget – Where Should You Really Invest?

Every CISO faces the same challenge: how do you maximise security outcomes with finite resources? In this rare behind-the-scenes keynote, a FTSE 100 security leader shares how they approach one of the biggest decisions in cybersecurity -where to invest, where to cut, and how to demonstrate value to the board. Gain an honest insight into the trade-offs, tough conversations and investment decisions that shape a modern enterprise security strategy, as one security leader walks through how they allocate a large security budget.

– The biggest investment priorities for today’s enterprise security function
– Where we’re increasing spend – and where we’re confidently reducing it
– Lessons learned from security investments that didn’t deliver the expected value
– Rationalising vendors without increasing organisational risk
– Balancing innovation, resilience, compliance and business priorities
– How to build a compelling business case for security investment
– The metrics and KPIs that matter most to boards and executive committees
– Looking ahead: where should security leaders be investing over the next three years?
– If I had to cut 20% of my security budget tomorrow, what would I stop funding – and what would I protect at all costs?

Speaker
Phillip Davies International CISO Equifax
12:05 – 12:20
Featured Presentation – Pluralsight
Speaker
John Elliott Pluralsight Author Fellow Pluralsight
12:20 – 12:35
Featured Presentation – Salesforce
Speaker
Matthew O’Neill Field CTO Salesforce
12:35 – 13:55
Networking Lunch Break
13:55 – 14:25
Panel Discussion: The Vendor Graveyard- The Security Investments We’d Never Make Again

Every security leader has made an investment that promised transformational results but failed to deliver. In this refreshingly candid panel, CISOs share the technologies, programmes and procurement decisions they wish they’d approached differently. Without naming vendors, they’ll unpack the real reasons projects fall short – and reveal the lessons that have shaped how they evaluate, implement and measure security investments today.

– What made the solution look like the right decision at the time?
– At what point did you realise it wasn’t delivering the expected value?
– Were the warning signs there from the beginning -and did you miss them?
– Was the failure down to the technology, implementation, culture or unrealistic expectations?
– How do you distinguish between a poor product and poor change management?
– What questions should every CISO ask before making a major security investment?
– How do you know when to persevere – and when to cut your losses?
– What procurement, governance and stakeholder lessons have fundamentally changed the way you buy technology today?
– If you had to remove one security tool from your stack tomorrow, which would it be – and would anyone notice?

Speaker
Georgina Owens Contributing Editor CIO
Speaker
Jonathan Holloway MD – MWI Practice Technology (Merlin) Cencora
14:25 – 14:35
The CISO Pulse Check: The Results Are In

What are your peers really thinking? Before the conference, delegates were invited to anonymously share their views on the biggest issues facing today’s security leaders – from AI governance and board engagement to budgets, ransomware and burnout. In this rapid-fire session, we’ll reveal the results live, challenge expectations and uncover the trends, surprises and uncomfortable truths shaping the future of cyber leadership.

Speaker
Georgina Owens Contributing Editor CIO
14:35 – 14:55
Introductions for Afternoon Breakout Sessions
15:05 – 15:50
Executive Strategy Lab: The £20 Million Challenge – Build a Cyber Strategy That Can Survive the Next Three Years

If you had £20 million to transform your organisation’s cyber resilience, where would you invest – and what would you leave behind? In this interactive strategy challenge, you’ll join fellow CIOs and CISOs to tackle the competing priorities every security leader faces today. With finite budgets, evolving threats and increasing board expectations, can your team build a strategy that delivers resilience, innovation and measurable business value?

The Challenge:

Working in table teams, you’ll take on the role of the executive security leadership team for a fictional FTSE 100 organisation. Each table will receive a unique business scenario, complete with its own opportunities, constraints and risks. Each scenario includes:

– A detailed business profile and strategic priorities
– A fixed £20 million cyber investment budget
– The latest threat intelligence and risk landscape
– Organisational skills and resource constraints
– Regulatory and compliance obligations
– Business growth plans, digital transformation initiatives and board expectations

Your mission:

– Decide where to invest- and where not to
– Prioritise the initiatives that will have the greatest business impact
– Balance innovation, resilience, compliance and operational risk
– Prepare a three-year cyber strategy that you can defend to the board

Feedback & Debate:

Each table will have two minutes to present the highlights of its strategy before the room compares approaches. This session will explore why different teams made different investment decisions, challenge assumptions and identify the common priorities emerging across the room.

Questions we’ll explore:

– Where should today’s CISOs be investing most heavily?
– What would you deliberately stop funding?
– How do you justify difficult investment decisions to the board?
– How do you balance cyber resilience with AI, cloud and digital transformation?
– What does a successful three-year security strategy look like in 2026?

Speaker
Manoj Bhatt Founder Cyberhash
Speaker
Meera Tamboli Digital Forensics and Incident Response Analyst
Afternoon Breakout Session 2
Afternoon Breakout Session 3
15:50 – 16:20
Panel Discussion: The Great AI Lockdown- Should We Tighten Security Controls or Set AI Free?

As organisations race to deploy AI, CIOs want to empower the workforce while CISOs are under pressure to protect sensitive data, intellectual property and critical systems. Does AI demand tighter controls, or is excessive governance the biggest threat to innovation? Senior leaders go head-to-head in a live debate, with the audience voting before and after to decide which argument prevails.

The audience will vote on:

– This House believes AI requires more restrictive security controls
– This House believes AI makes traditional security policies obsolete
– This House believes productivity should trump protection in the age of AI
– This House believes Zero Trust Is no longer fit for the AI era
– This House believes every employee should have unrestricted access to enterprise AI tools

Speaker
Georgina Owens Contributing Editor CIO
Speaker
Ali Nouman Global Head of Cyber Security Pret A Manger
Speaker
Shaun Barry IT Director Pret A Manger
Speaker
Peter Yeung CIO and Global Data Protection Officer Optimizely
Speaker
Leroy Stanford Director of Cyber Security Ocado Technology
16:35 – 17:15
Lightening Talks & Panel Discussion: What Kept Me Awake This Year – Five CISOs. Five Minutes. Five Unfiltered Perspectives

Forget polished presentations and hindsight. In this fast-paced session, five leading CISOs each have just five minutes to share the one issue that caused them the greatest concern in 2026 – whether it was AI, board pressure, resilience, talent, regulation or something no one saw coming. Following the lightning talks, all five speakers return to the stage for an interactive Q&A, giving delegates the opportunity to dig deeper into the challenges, decisions and lessons that defined the year.

Expect honest insights on topics such as:

– The one challenge that had the biggest impact on my organisation this year
– The decision I found most difficult to make
– The emerging risk I underestimated – and won’t again
– What changed my security strategy in 2026
– The biggest lesson I’ve taken into 2027
– One prediction every CIO and CISO should be preparing for now

This isn’t a collection of case studies – it’s a rapid-fire insight into the issues that genuinely occupied the minds of security leaders over the past year. By bringing together five different perspectives, delegates will gain a unique snapshot of the risks, decisions and leadership challenges shaping the UK’s cyber agenda, while discovering whether the concerns keeping one CISO awake are shared across the entire industry.

Speaker
Georgina Owens Contributing Editor CIO
Speaker
Neil Bennett CISO Post Office
Speaker
Sam Das CISO Metro Bank
Speaker
Ian Buffey CISO AtkinsRealis
Speaker
Simon Chan Head of Cyber Security Operations Berenberg
17:15 – 17:30
Chair’s Closing Remarks