IT Security Summit
Securing an AI-powered enterprise
Rethinking trust, compliance and innovation
The IDC IT Security Summit is the premier event for business, security and technology executives to discuss how trust, governance and resilience can be placed at the heart of digital transformation. We are entering a critical phase of digital and cybersecurity development. According to the latest study by IDC, IT security spending in Germany is expected to grow at double-digit rates through 2028, driven by increasing cyber threats, the adoption of AI, and cloud modernisation initiatives. The country’s cybersecurity agenda, which is aligned with the EU AI Act, the NIS2 Directive and DORA, underscores the national commitment to resilience, data protection and digital sovereignty. IDC also notes that software, cloud-native security and analytics solutions will be the fastest-growing segments of the German cybersecurity market as enterprises increasingly adopt integrated and intelligent protection models.
Agenda
The IDC IT Security Summit is the ultimate meeting place for business, security and technology leaders who want to put trust, governance and resilience at the heart of their digital transformation strategies. Join IDC analysts and industry experts to learn how to build trusted digital ecosystems that combine innovation with security. Gain insights into Germany’s most dynamic industries – including finance, energy, manufacturing and public services – and take away actionable concepts that will help you turn security into a strategic differentiator rather than just a reactive cost.
2026 Predictions
By 2028, 40% of organisations will use autonomous, agent-based platforms to quantify cyber risks, converting security metrics into financial risks to guide budgets, controls, and Mu0026A risk assessments.
Key Topics
Regulation, resilience and value creation
Compliance is no longer a burden on the back office, but a strategic factor. We will examine how companies can integrate legal requirements (data protection, cybersecurity laws, new AI/technology rules) into their core businesses and transform requirements into levers for resilience, stakeholder trust and business value. Key topics include cyber-by-design, auditability, supplier responsibility and continuity in the face of disruption.
AI, automation and responsible innovation
AI and intelligent agents are changing the way security is ensured, but with great power comes great risk. We will look at the pragmatic use of AI: governance models, safeguards against misuse, prioritising high-impact use cases, and aligning AI systems with trust, transparency and accountability.
Operation, analytics and reliability engineering
Detection, response, and recovery are now continuous cycles rather than discrete events. We will delve into advanced analytics, managed detection and response, orchestration, external threat visibility (supply chain, third parties), and resilience metrics to operationalise security effectiveness.
The human factor: leadership and culture
Technology alone does not guarantee security. Leadership, culture and skills development must be aligned. We will focus on transforming teams, embedding security responsibility across functions, and empowering leaders to speak the language of risk and trust with the board, CEOs and business units.
Incident and restoration of trust
Violations will always occur, but how a company responds to them is crucial. We cover crisis communication, forensic measures, dealing with regulatory authorities, insurance, restoring stakeholder trust and turning adversity into credibility.
Sector and domain security challenges
Different industries and environments have unique security requirements. We focus on securing critical infrastructure (energy, utilities), connected devices and IoT, healthcare, finance, and new environments such as smart cities and industrial systems.
2026 Predictions
By 2028, AI agents will triage 80% of SOC alerts in most SOCs worldwide.
Advisory Board
Tareq Ahmadi
John Sellmann
Mark Child
Associate Research Director Mark Child of IDC’s European Security Group leads the group’s Endpoint Security and Identity & Digital Trust (IDT) research for both Western Europe and Central & Eastern Europe. He monitors developments in security technologies and strategies as organizations address the challenges of evolving business models, IT infrastructure, and cyberthreats. Mark’s coverage includes in-depth security market studies, end-user research, white papers, and custom consulting.
Mark supports IDC’s global products, including Security Trackers, Security Spending Guides, and Security FutureScapes. He is a regular speaker at IDC events across Europe, including European Security Road Shows and the CISO Summit. Mark also presents at custom events and webinars for security vendors.
Prior to joining IDC in 2004, Mark worked at the Prague Business Journal and as a research analyst for market research firm NFO AISA. Mark Child earned a Bachelor of Science from the University of Brighton.
Tareq Ahmadi
Florian Jörgens
Florian Jörgens developed his professional interest in information technology in 2002.
While working as an IT specialist for systems integration at T-Systems International GmbH in application and system support, he earned a Bachelor of Science in Business Information Technology.
After further experience in IT auditing at PricewaterhouseCoopers and an MSc in IT Management, Florian Jörgens
subsequently worked at E.ON in Essen as Manager for Information Security for the entire German sales organization.
In March 2019, he assumed overall responsibility for the group’s information security as Chief Information Security Officer at LANXESS AG in Cologne.
Today, Florian Jörgens is Chief Information Security Officer
of the Vorwerk Group. He also works as a keynote speaker, lecturer, author, and research assistant at various universities. He also gives lectures on the topics of information security, awareness, and cybersecurity.
Florian Jörgens was awarded the Digital Leader Award in the “Cyber Security” category by CIO Magazine in September 2020.
He is the author of the book “The Human Firewall: How to Create a Culture of Cyber Security.”
Dorothée M. Mönch
In ihren über 30 Jahren Berufserfahrung in der IT, davon über 20 Jahre in leitenden Funktionen, hat sich Dorothée M. Mönch zunächst über Tätigkeiten im High Security Bereich bei Giesecke & Devrient zu einer breitaufgestellten Expertin im Cybersecurity Umfeld entwickelt, wobei sie sich u.a. in Stationen wie Munich Re, ITERGO, der Bundesbank, LBBW oder EnbW einbrachte. Schwerpunkt ihrer Arbeit war dabei immer auch das Umfeld mit seinen besonderen Anforderungen, etwa in der Regulatorik. Aktuell ist sie als Head of Secure Operations bei der Fidelity Fondsbank in Kronberg (Taunus) angestellt. Ihr besonderes Augenmerk gilt dabei jenen Herausforderungen, die hier in der zunehmenden Komplexität und den damit verbundenen Unsicherheiten begründet sind.
Maximilian Obenaus
Maximilian Obenaus ist Chief Information Officer (CIO) der Verkehrsbetriebe Karlsruhe (VBK), der Albtal-Verkehrs-Gesellschaft (AVG) und des Karlsruher Verkehrsverbundes (KVV). In dieser Funktion verantwortet er die IT-Strategie, IT-Governance, Cybersecurity, Infrastruktur, Anwendungen sowie die digitale Transformation im Umfeld des öffentlichen Personennahverkehrs.
Nach seinem Studium der Informatik am Karlsruher Institut für Technologie (KIT) sowie der Wirtschaftswissenschaften an der FernUniversität Hagen war er zunächst Leiter des Bereichs Digitale Fahrgastinformation beim Karlsruher Verkehrsverbund. Seit 2019 leitet er die Stabsstelle Informationstechnologie von VBK, AVG und KVV und treibt die Weiterentwicklung von Cyber-Resilienz, Informationssicherheit und digitaler Transformation in einer KRITIS-nahen Unternehmensumgebung voran.
Christian Dittrich
Jörg Rafflenbeul
Jan Seeger
John Sellmann
Oguz Sirin
Gevorg Stepanyan
Aydin Tekin
Als Senior Sales Engineer bei Ping Identity entwickelt Aydin Tekin gemeinsam mit Kunden in der EMEA-Region moderne Identity-Lösungen, die starke Sicherheit mit bester User Experience vereinen. Im engen Austausch mit Sales, Product und den Kundenteams übersetzt Aydin komplexe technische und geschäftliche Anforderungen in praxisnahe Architekturen auf der Ping-Plattform. So hilft Aydin Unternehmen dabei, Zero Trust und die digitale Transformation konkret umzusetzen. Aydins Herz schlägt dafür, das volle Potenzial von Identitätsmanagement als strategischen Business-Treiber nutzbar zu machen.
Aamir Haroon
Mit mehr als zehn Jahren Erfahrung in Technologie und Cybersicherheit ist Aamir Haroon Senior Enterprise Solution Engineer bei 1Password. Seine Laufbahn begann im Bereich Cybersicherheit bei Intel Security und umfasst technische Presales-Beratung, Solution Consulting und strategische Kundenbetreuung. Seine Schwerpunkte liegen in den Bereichen Cybersicherheit, Identity and Access Management, Privileged Access Management, Testautomatisierung und DevSecOps. Heute unterstützt er Unternehmen dabei, Zugriffe für Menschen, Maschinen und KI-Agenten abzusichern und auf die neuen Anforderungen moderner Identitätssicherheit zu reagieren.
Aamir arbeitet mit Unternehmen in der DACH-Region und begleitet Technologieevaluierungen, Transformationsvorhaben und strategische Sicherheitsinitiativen. Dabei bringt er technische Teams, Sicherheitsverantwortliche und Führungskräfte zusammen und übersetzt komplexe Technologieentscheidungen in klare geschäftliche Ergebnisse.
Jens Egger
Jens Egger is an experienced technical Senior Sales Engineer who has been working in the cybersecurity industry for many years. He possesses extensive technical expertise and in-depth knowledge in the areas of penetration testing, next-generation firewalls, information and data protection, networking, as well as threat protection and defense.
Piotr Zakrzewski
Piotr Zakrzewski ist Commercial Account Executive für die DACH-Region bei Wasabi Technologies. In seiner Funktion unterstützt er Unternehmen und Partner bei der Entwicklung skalierbarer, wirtschaftlicher und cyberresilienter Cloud-Storage-Strategien. Sein besonderer Fokus liegt auf der Absicherung geschäftskritischer Daten, modernen Backup- und Recovery-Konzepten sowie dem Schutz vor Ransomware und anderen Cyberbedrohungen. Dabei verbindet er seine Erfahrung im Technologievertrieb mit einem klaren Verständnis für die geschäftlichen, technischen und regulatorischen Anforderungen moderner Unternehmen.
Marcel Weber
Marcel Weber ist Senior Territory Manager bei Object First und verfügt über mehr als 15 Jahre Erfahrung in Consulting, PreSales und Sales. Seine Karriere führte ihn vom IT-Partner über Veeam zu Object First. Mit technischer Expertise, Vertriebserfahrung und einem klaren Blick auf die Herausforderungen moderner Datensicherung berät er Unternehmen in der DACH-Region rund um Cyber-Resilienz, Ransomware-Schutz und Immutable Storage.
Notis Iliopoulos
Notis Iliopoulos is EVP of Managed Risk & Controls Services at Obrela, with more than 28 years of experience in information security, risk management, and cybersecurity leadership across Greece, the Balkans, the Middle East and Central Europe. Throughout his career, he has held senior consulting, CISO, and business leadership roles, leading complex cybersecurity and risk management initiatives in critical sectors, including telecommunications and financial services.
Notis specializes in cyber risk management, governance, compliance, information security strategy, and resilience programs. He holds an MSc in Information Security from Royal Holloway, University of London, an MSc in Management of Business Innovation & Technology, and is certified CISA, CISM, and ISO 27001 Lead Auditor.
Aaron Schlotterer
Aaron Schlotterer ist Director of Strategic Accounts bei Tanium. Zuvor war er dort als Strategic Account Executive, Account Executive und in verschiedenen Business-Development- und Sales-Funktionen tätig. Sein beruflicher Schwerpunkt liegt auf strategischem Vertrieb, Enterprise-Kunden, Cybersecurity und dem Aufbau langfristiger Kundenbeziehungen.
Georgios Papazafiris
Georgios Papazafiris ist Solution Engineer bei CoreView und seit rund 30 Jahren in der IT-Branche tätig. Sein Schwerpunkt liegt auf Microsoft 365, Governance und Security. Er unterstützt Unternehmen dabei, Risiken in komplexen Microsoft-365-Umgebungen sichtbar zu machen, Fehlkonfigurationen zu erkennen und Governance- sowie Security-Konzepte praxisnah umzusetzen. Als technischer Berater und Speaker verbindet er technische Tiefe mit den Anforderungen von IT-Administratoren, Security-Verantwortlichen und Entscheidern.
Robert Christian
Marco Schmidt
Marco Schmidt ist Cybersecurity Strategist bei TrendAI™. Er übersetzt komplexe Cyberrisiken in Entscheidungen, die im Management tatsächlich getroffen werden können. Sein Schwerpunkt liegt auf Datenanalyse, Gap Assessments und KI-gestützter Automatisierung von Security-Prozessen. Marco arbeitet vom SOC bis zur Geschäftsleitung, mit Fokus auf die DACH-Region und Erfahrung aus Industrie, Beratung und Herstellerseite.
Patrick Englisch
Knowledge Hub
The NIS 2 Directive – where are we now?
The deadline for implementing the second EU Directive on the security of network and information systems (NIS 2) expired in October 2024, with only a handful of Member States having fulfilled this task.
Impact of NATO's spending target of 5% of GDP on European ICT expenditure
At the NATO summit in The Hague a few weeks ago, member states committed to spending 5% of their annual GDP on core defence requirements and defence and security-related expenditure by 2035.
IAM 2025: The Rise of the Machines
Identity and access management (IAM) and, consequently, identity security is one of the biggest and most consequential challenges facing all European companies today from an operational and risk management perspective.
Venue
Steigenberger Hotel Köln
Steigenberger Hotel Köln
Habsburgerring 9-13, 50674 Cologne, Germany
Terms & Conditions
Please read BEFORE registering:
The IT Security Summit is aimed at IT and specialist staff from IT user companies in Germany. For the purposes of these conditions of participation, IT user companies are defined as all companies that do not themselves provide consulting services and/or develop, manufacture or distribute information and communication technology (ICT) products or services. Employees of outsourced IT companies who work exclusively for the parent company and do not conduct business with third parties are also eligible to participate. Employees of IT service companies generally only have access to our events through sponsorship. IT provider companies within the meaning of these conditions of participation are hardware, software, service and telecommunications companies as well as consulting firms and ICT service providers. IDC expressly reserves the right to reject registrations from persons who do not belong to the above-mentioned target group, even if the invitation was issued by one of our partners, accidentally by IDC itself or through participation in an online survey. After registering via the online registration form and successful verification by IDC, you will receive a binding confirmation of registration by email.
partners
Not the right event for you?
Don't worry! We organise a variety of events designed to inspire original ideas, share the latest industry knowledge and connect professionals like you. Simply sign up for event invitations and we'll notify you when a new event matches your interests.
Sign up