IT Security Summit
Securing an AI-Powered Business
Navigating the new frontier of trust, compliance and innovation
Navigating the new frontier of trust, compliance and innovation
Sweden is entering a pivotal phase in its cybersecurity and digital innovation journey. According to IDC, European security spending is forecast to grow at a compound annual rate of around 9.4% through 2029, with software, analytics, and cloud-native security driving investment. In Sweden, organizations are responding to a rising volume of sophisticated cyber threats, the rollout of EU regulatory frameworks such as the NIS2 Directive, the Cyber Resilience Act, and the EU AI Act, as well as a stronger national focus on critical infrastructure protection and digital sovereignty. The Swedish Civil Contingencies Agency(MSB) and the National Cybersecurity Centre (NCSC-SE) are coordinating new initiatives that enhance cyber readiness, public–private collaboration, and secure technology adoption across key sectors.
At the same time, AI is reshaping Sweden’s cybersecurity landscape. IDC research shows that nearly 40% of European organizations are already investing in AI or automation, and over 70% expect AI-driven disruption within the next 18 months, trends visible across Sweden’s manufacturing, energy, and public-sector ecosystems. For Swedish security leaders, AI represents both a strategic opportunity and an evolving source of risk: it strengthens threat detection, incident response, and operational decision-making, but also enables new attack vectors such as AI-driven phishing, automated exploitation, and misinformation. As a result, Swedish organizations are increasingly prioritizing AI-enabled analytics, identity and access management (IAM), and managed detection and response (MDR) to improve resilience while ensuring ethical AI use, transparency, and governance.
Agenda
The IDC IT Security Sweden 2026 is the definitive event for business, security, and technology leaders to explore how to embed trust, governance, and resilience at the core of digital transformation.
Join IDC analysts and industry experts to explore how to build trusted digital ecosystems that combine innovation with assurance. Gain insights into Sweden’s most dynamic sectors (including manufacturing, energy, finance, and public administration) and walk away with actionable frameworks to make security a strategic differentiator, not just a reactive cost.
2026 Prediction
By 2028, 40% of enterprises will use autonomous agent–powered cyber-risk quantification platforms to turn security metrics into financial exposure, guiding budgets, controls, and M&A risk assessments.
Main Themes
Regulation, Resilience and Value Creation
Regulatory compliance is no longer a back-office burden, it’s a strategic enabler. We will explore how organizations can embed regulatory mandates (data privacy, cybersecurity laws, emerging AI/tech rules) into core operations, turning requirements into levers for resilience, stakeholder trust, and business value. Keytopics include cyber-by-design, auditability, vendor accountability, and continuity in the face of disruption.
AI, Automation and Responsible Innovation
AI and intelligent agents are transforming how security is delivered, but with great power comes risk. We will explore pragmatically deploying AI: governance models, guardrails for misuse, prioritization of high-impact use cases, and aligning AI systems with trust, transparency, and accountability.
Operations, Analytics and Resilience Engineering
Detection, response, and recovery are now continuous cycles rather than discrete events. We’ll delve into advanced analytics, managed detection & response, orchestration, external threat visibility (supply chain, third parties), and resilience metrics to operationalize security effectiveness.
The Human Factor: Leadership and Culture
Technology alone doesn’t guarantee security. Leadership, culture, and skill development must align. We will focus on transforming teams, embedding security ownership across functions, and equipping leaders to speak the language of risk and trust to the board, CEOs, and business lines.
Incident and Trust Recovery
Breaches will happen, but what matters is how an organization responds. We will cover crisis communication, forensic response, regulatory handling, insurance, stakeholder trust restoration, and turning adversity into credibility.
Sector and Domain Security Challenges
Different industries and environments pose unique security demands. We will focus on securing critical infrastructure (energy, utilities), connected devices and IoT, healthcare, finance, and emerging environments like smart cities or industrial systems.
2026 Prediction
By 2028, AI agents will be triaging 80% of SOC alerts in the majority of SOCs worldwide.
Speakers
Duncan Brown
Duncan Brown is associate vice president, European Security Practice, at IDC EMEA and leads the firm’s security research program in Europe. He specializes in providing strategic advice to his clients, informing and validating their corporate, product, and marketing plans. Brown is an expert in analyzing the security market globally, and his list of security-related clients includes enterprises, central banks, government organizations, and security product suppliers and services providers. Brown’s expertise spans the gamut of security topics including incident response, threat intelligence, and global privacy issues. He established and leads IDC’s coverage of the global impact of the GDPR, the RPEC (ePrivacy Directive update) and NIS Directive on technology companies and their customers. His analysis and opinions are widely sought by industry leaders and investors, while his comments on industry trends and developments frequently appear in the leading business and trade publications.
Event Sessions
One Day Event 3:25 pm
Final Remarks & Key Takeaways
One Day Event 2:15 pm
Fireside chat: AI and Security: Tool, Threat, Trust
One Day Event 9:05 am
Securing an AI-Powered Business – Navigating the New Frontier of Trust, Compliance & Innovation
Europe is at a strategic inflection point. According to IDC’s latest research, security spending in Europe is forecast to reach nearly $60 billion by 2028, growing at a compound annual growth rate of around 9.4% from 2025 to 2029. Organizations are responding to intensifying cyber threats, expanding regulatory frameworks such as the EU AI Act, NIS2, GDPR, and DORA, and a surge in stakeholder demand for digital trust and sovereignty. IDC also reports that software and cloud-native security solutions are expected to account for a majority of global security spend by 2028, as enterprises accelerate their adoption of integrated, analytics-driven protection.
At the same time, AI is reshaping the security landscape in Europe. IDC research shows that 38% of European organizations are already investing in AI or Agentic AI, and 43% are actively testing or running proofs of concept, while nearly 70% expect AI-driven disruption within the next 18 months. For European security leaders, this represents both a strategic opportunity and a growing area of risk. AI is enhancing threat detection, automation, and decision-making, yet it is also being exploited by adversaries to scale attacks and manipulate data. As a result, European organizations are prioritizing investments in AI-powered security analytics, identity and access management (IAM), and managed detection and response (MDR) to stay ahead of threats while maintaining transparency, compliance, and ethical governance.
Joel Stradling
As research director for IDC’s European Security practice, Joel Stradling leads the content and analyst team for tracking the European security segment. His main focus area is the integration of network plus security and evolution of network architectures towards software-defined secure access.
Stradling has 20 years of experience as an analyst of international managed enterprise network and IT services. He is a regular speaker at major industry conferences talking about emerging technologies in B2B enterprise network and IT and wholesale carrier-to-carrier services. Joel is a well-known and highly regarded expert in the industry, offering insight and advice to C-level executives on technology competitive landscapes and emerging technologies, such as SD-WAN, 5G, SDN/NFV, and cyber-security.
Gian Carlo De La Paz
gdelapaz@idc.com
Event Sessions
One Day Event 3:25 pm
Final Remarks & Key Takeaways
One Day Event 9:00 am
Welcome by IDC
Jake Moore
Jake Moore, Crime Enthusiast and Cybersecurity Advisor, brings a unique edge to the digital security realm. As well as conducting research and analysis into the latest cybersecurity and AI threats, he also regularly comments on a range of cybersecurity and AI stories in the press for outlets such as BBC, Sky News and CNN. Jake previously worked in the police force for 14 years in the Digital Forensics and Cyber Crime Unit. He investigated 100s of crimes and spent much of his time in Crown Court producing digital evidence for an abundance of different offences ranging from fraud to murder. Leveraging this experience, he now guides businesses and employees in bolstering their cybersecurity by blending real-world crime-fighting insights, using artificial intelligence and social engineering techniques with advanced digital security strategies to combat evolving cyber threats.
Event Sessions
One Day Event 2:35 pm
The Deepfake Interview: Breaking In From the Inside
Jake lifts the lid on the darker side of artificial intelligence, taking you deep into the criminal underworld powered by today’s most advanced technology. In the name of research, he used AI driven face-swapping tools to pass a live video job online interview under a completely false identity. Not once, but repeatedly. Through these real-world experiments, Jake reveals how powerful AI tools are already being weaponised by criminals to infiltrate organisations from the inside, bypassing traditional security and exploiting human trust.
But it doesn’t stop there. With the same tools now widely available, Jake demonstrates how AI can clone voices, generate convincing documents and create fake identities in seconds, giving cybercriminals everything they need to scale deception like never before. Nothing is real anymore. The question is, would you spot it?
Sofia Edvardsen
With a deep interest in law, technology and business strategy, Sofia Edvardsen engages passionately in understanding and explaining the world’s emerging legal regulatory landscape for technologies. How can businesses prepare today for the regulations of the future? What should be done short term to position the industry for the long term considering what rules that then will apply?
With extensive experience as an attorney, she has worked closely with a wide range of organisations. That enables her to provide practical and realistic solutions to emerging legal challenges, also aiming to help make the right decisions based on an understanding of what is possible today and what the future might bring. She is the founding partner of Sharp Cookie Advisors (https://www.sharpcookie.se/en), a technology and digitization law firm based in Stockholm, Sweden. In her role there she represents sellers and buyers of cloud computing (IaaS, PaaS, and SaaS models), software licensing and other technology transactions.
She also holds the role as Data Protection Officer for several global companies as well as start-ups. In addition, she provides services to Data Protection Programs for health care providers and companies in media, marketing, retail and tech. Sofia also leads the Swedish chapter of the International Association of Privacy Professionals (IAPP). In that role, she facilitates the development of privacy-enhancing practices for the Swedish industry and the public sector.
Sofia Edvardsen graduated from School of Business, Economics and Law at the University of Gothenburg and has a degree from Chalmers University of Technology. She is a certified privacy professional and holds a CIPP/E certification. She has served as in-house legal counsel of a global telecom company, in-house legal counsel at a technology investment fund and as a lawyer in the Stockholm and London offices of Baker McKenzie law firm.
Event Sessions
One Day Event 3:00 pm
Regulation & Resilience: NIS2, DORA, EU AI Act & Beyond
Jaye Tillson
Jaye Tillson is the CTO Security and a Distinguished Technologist at HPE, recognized as a leading voice in cybersecurity with a focus on Zero Trust, AI, and SASE strategy. He is renowned for translating complex security architectures into business outcomes that resonate with C-level executives.
With more than 25 years of experience driving global technology transformations, Jaye has guided countless organizations through their Zero Trust journeys, helping them accelerate digital transformation, strengthen resilience, and thrive in today’s dynamic landscape. He brings executive credibility and a rare ability to bridge conversations across IT, OT, and business leadership.
Within HPE, Jaye drives go-to-market success by coaching sales teams to position Zero Trust as a catalyst for cloud adoption, hybrid work, and regulatory compliance. By reframing security as a competitive advantage rather than a cost center, he serves as a force multiplier in winning strategic opportunities. Recognized as a trusted advisor both internally and externally, Jaye partners closely with marketing and PLM teams while also serving as the voice of the customer. He brings field insights back into HPE to shape product strategy, refine sales motions, and fuel innovation.
A recognized thought leader, Jaye speaks regularly at leading industry events including Gartner, VMWorld, Evanta, IDC, and .Next. He has served on advisory boards for VMware, Nutanix, CIOnet, and Proofpoint, and is co-founder of the Zero Trust Forum and co-host of the No Trust podcast, where he engages audiences on Zero Trust, SASE, SSE, AI, and the evolving role of the CISO.
Jaye is also an active contributor to the Cloud Security Alliance Zero Trust Working Group, a board member of the CSA UK Chapter, and an advisor to Infosec.live. Beyond work, he pursues his passions for motor racing, fine cuisine, and global travel.
More at: jayetillson.tech
Event Sessions
One Day Event 9:30 am
Zero Trust or Bust: Why Half Measures Create Full Risk
Most organisations haven’t failed at Zero Trust because they chose the wrong technology. They’ve struggled because they’re trying to bolt Zero Trust onto architectures that were never designed for it.
At the same time, AI is changing the pace of cybersecurity. Vulnerabilities are discovered faster, exploits are developed faster, and attackers are moving faster than ever before. Complexity has become one of the biggest risks facing security teams.
In this session, Jaye Tillson explains why Zero Trust is an operating model rather than a product, why consistency is the foundation of modern security, and how organisations can simplify their architecture by bringing identity, networking and security together.
You’ll leave with practical ideas for reducing complexity, improving resilience and building a Zero Trust strategy that’s designed for the realities of today’s hybrid and AI-driven world.
Paul Estep
Christof Jacques
Christof Jacques is a Solutions Architect at Horizon3.ai, where he specializes in helping organizations move from reactive security to proactive resilience. With over 25 years of experience in the cybersecurity sector, Christof has served as a technical lead and security evangelist for several global industry leaders. He leverages a deep background in malware analysis, incident response, and threat intelligence to help modern enterprises identify and close exploitable gaps before they can be leveraged by attackers. He holds a Master’s Degree in Computer Science from KU Leuven.
Event Sessions
One Day Event 11:00 am
In the Cyber Trenches: War Stories from 326,000 pentests
To defeat the adversary, we must move beyond tracking their tools—we must understand their mind.
The traditional approach to cybersecurity has focused relentlessly on the technical what (malware signatures, TTPs) and the macro why (geopolitical tension, economic drivers). However, the next decisive frontier in intelligence and defence requires a pivot to the who: the personality dynamics that fuel cyber threat actor groups and using autonomous tools to follow in their footsteps.
Andrei Dumitru
Andrei leads the Identity for AI practice at IT Smart Systems, where he helps enterprises turn agentic AI from prototype into production. Drawing on two decades of digital identity and open banking implementations for top-tier EMEA financial institutions, Andrei designs the runtime security that makes AI agents trustworthy: every action authorized – agent behaviour scored in real time – and a human in the loop for the decisions that matter. He is the architect of IT Smart Systems’ end-to-end accelerator for securing digital assistants on enterprise agent platforms with the Ping Identity Platform, and a frequent voice on why security, not the model, is what unlocks the agentic channel.
Event Sessions
One Day Event 9:50 am
From Conversational AI to Trusted Agents: Securing the Agentic Channel
AI assistants are moving beyond answering questions and recommendations to acting: accessing data, invoking APIs, orchestrating workflows, and transacting on behalf of people. This creates significant opportunities for better customer experiences, but also new risks around impersonation, excessive permissions, and accountability.
In this session, Andrei will explore how organisations can build trust into conversational and agentic experiences by giving AI agents their own identities, binding them to an accountable human or organisation, applying delegated and least-privilege access, authorising actions at runtime, and keeping people in control of high-impact decisions. The session will show why identity is becoming the control plane for secure AI adoption and the next generation of customer experiences.
Filip Wennerhult
Event Sessions
One Day Event 2:15 pm
Fireside chat: AI and Security: Tool, Threat, Trust
Axel Sundelöf
Event Sessions
One Day Event 11:20 am
When budget pressure meets ransomware: The cost of waiting to modernize backup
As organizations balance economic pressures, AI initiatives, and cybersecurity priorities, backup modernization is often pushed down the investment list. Yet the financial and operational impact of a successful ransomware attack can far exceed the cost of building resilient recovery infrastructure. Join Veeam and Object First as they explore IDC research on the growing risks of deferred backup investment and share practical recommendations for strengthening cyber resilience.
Johan Sanneskar
Event Sessions
One Day Event 11:20 am
When budget pressure meets ransomware: The cost of waiting to modernize backup
As organizations balance economic pressures, AI initiatives, and cybersecurity priorities, backup modernization is often pushed down the investment list. Yet the financial and operational impact of a successful ransomware attack can far exceed the cost of building resilient recovery infrastructure. Join Veeam and Object First as they explore IDC research on the growing risks of deferred backup investment and share practical recommendations for strengthening cyber resilience.
Ian Wood
During his 25+ years in the software industry, Ian has worked in a variety of roles in data management and security practices, previously at Veritas and Symantec. Ian and his team are engaged with customers to design cyber resilience solutions to solve complex problems for organizations across multiple business sectors.
Event Sessions
One Day Event 11:35 am
The Day After: Why Recovery Has Become the Most Important Security Strategy
Every cybersecurity strategy is built around a single moment: the day after an attack.
When systems are encrypted, identities are compromised, and business services are offline, prevention is no longer the priority. Recovery is.
This session reveals why organisations are shifting investment and leadership focus towards Cyber Resilience and Resilience Operations (ResOps).
Knowledge Hub
The NIS 2 directive – where are we now?
The deadline for the transposition of the EU’s second Network and Information Systems Security directive (NIS 2) came and went in October 2024 with only a handful of member states having completed the task.
European ICT spending implications of NATO’s 5% GDP spending target
At the 2025 NATO Summit in The Hague a few weeks ago, member states pledged to allocate 5% of their annual GDP to core defense requirements and defense- and security-related expenditures by 2035.
IAM 2025: The Rise of the Machines
Identity and access management (IAM), and by extension, identity security, is one of the most pervasive and impactful challenges facing all European organizations today, from an operational and risk management perspective.
Not the right event for you?
Don’t worry! We organize a variety of events designed to inspire original ideas, share the latest industry insights, and connect professionals like you. Simply sign up for event invitations, and we’ll notify you whenever a new event matches your interests.
Sign up