TLC Connect CISO Summit - UK
13th & 14th October 2026
Tobacco Dock – London
13th & 14th October 2026
TLC Connect CISO Summit - UK
The TLC Connect CISO Summit UK brings together senior cybersecurity leaders responsible for protecting enterprise organisations in an environment defined by constant disruption, escalating threat activity, and growing operational pressure.
Across two focused days, CISOs, security executives, and cyber leaders will examine the realities shaping modern security leadership: AI-driven threats, resilience under pressure, supply chain exposure, regulatory scrutiny, identity risk, and the increasing expectation to translate cyber strategy into measurable business outcomes. This is not a summit built around theory or vendor-led hype. It is designed around practical leadership, operational resilience, and the decisions security teams are making right now to reduce risk while enabling the business to move forward.
The programme combines real-world case studies, peer-led roundtables, workshops, and candid executive discussions focused on what is actually working inside enterprise security environments. Attendees will leave with practical insight into cyber resilience, AI governance, exposure management, security operations, third-party risk, and communicating risk effectively at board level.
Key Themes for 2026
Built for Speed, Engineered for Resilience: Governing Cyber Risk in the Age of Automation
Operational Resilience Under Constant Pressure
Keeping critical services stable while managing cyber risk, supplier dependency, technical debt, and operational disruption in increasingly volatile environments.
Simplifying Complexity & Regaining Control
Reducing tooling sprawl, fragmented architectures, and operational inefficiencies to improve visibility, execution speed, and security confidence.
AI, Automation & Security at Scale
Moving beyond AI experimentation toward governed, production-ready adoption while balancing innovation, resilience, compliance, and operational risk.
Leadership, Accountability & Board Communication
Helping CISOs translate cyber risk, resilience investment, and technology trade-offs into outcomes boards, regulators, and stakeholders can clearly understand.
Elevate Your Technology Leadership
Summit Agenda Overview
Welcome to the TLC Connect CISO Summit UK 2026. This invitation-only gathering brings together senior cybersecurity leaders responsible for defending enterprise organisations in an environment defined by relentless threat activity, operational disruption, regulatory pressure, and rising board-level scrutiny.
Across two focused days, the summit examines the realities shaping today’s security function: ransomware resilience, third-party exposure, identity risk, AI governance, security operations fatigue, and the growing challenge of securing increasingly complex digital estates. This is not a summit centred around abstract frameworks or transformation rhetoric. It is focused on the operational decisions, trade-offs, and leadership challenges CISOs are navigating right now.
The programme combines real-world case studies, candid executive discussions, peer-led roundtables, and technical workshops designed to explore what is actually working inside enterprise security environments. Attendees will hear honest lessons from security leaders operating under pressure, including what has failed, what has delivered measurable resilience improvements, and what organisations have deliberately stopped doing to reduce complexity, improve visibility, and strengthen cyber readiness.
Designed to deliver practical insight rather than theory, the summit provides actionable takeaways across cyber resilience, exposure management, AI security, supply chain assurance, security operations, and communicating cyber risk in ways boards, regulators, and stakeholders can clearly understand.
Our Speakers
Tash van den Heever
Chief Information Security Officer
Investec PLC
Rob Brown
Senior Director, Technical Services
Absolute Security
Johann van Duyn
Chief Information Security Officer
DO & CO AG
Glen Wilson
SVP Strategy EMEA & APAC
Lansweeper
Paul Colnan
Chief Information Security Officer
NewDay

Matt Logan
Field CTO, EMEA
Securiti AI
Jay Vinda
Global CISO and Cyber Risk Engineering Lead
Mosaic Insurance

Haydn Brooks
CEO
Risk Ledger
Gabriela Anselmi-Assalemi
Chief Information Security Officer
University of Cambridge

Andrew Kane
Field CTO
Cyera
Giles Lindsay
Chief Information Officer
Agile Delta
Laure Lydon
VP of Security & Infrastructure
Flo Health Inc
Mantas Marcinkevicius
Chief Information Security Officer
Lloyd's List

John White
Field CISO EMEA
Torq
Gloria Croxall
Head of Cybersecurity
John Swire & Sons
Paul Mallon
Solutions Engineering Manager
Rubrik
Jonathan Mattey
Chief Information Security Officer
Forge Holidays

Christina Hoefer
VP, OT & xIoT Strategy
Forescout
Tiago Rosado
Chief Information Security Officer
Asite
Abhishek Kumar
Business Architect, CISO Advisory
Cisco
Lee Morton
Head of Cybersecurity
GBG
Richard Storry
Senior Manager
Druva
Matt White
Cyber Advisory and App Security Director
Royal Mail

Conner Brown
Regional Manager
Securiti AI
Irina Simbotin
Founder, NED, Strategic Advisor

Vivek Marwah
Director of AI/ML Security
GSK
Fahad Burney
Head of Operational Risk
Industrial and Commercial Bank of China
Mikhail Chernyshev
Senior Solutions Engineer
HUMAN Security
Asim Khwaja
Cyber Risk Leader
Government Entity (all views are personal)

Csaba Csordas
Alliance Director
Hyperproof
Professor Andrew Green
University College London
London Centre for Nanotechnology
Daniel Oxley
EMEA Technology Leader
Doppel
Alan Radford
Global Identity and Access Management Strategist
One Identity

Angus Dike
Sales Engineer
Huntress
Lance Moraitis-Jones
Senior Engineer
Recorded Future

Juan Torrez
Solution Engineer
NinjaOne

Dominik Bieszczad
Solutions Engineer, EMEA
runZero
Chris Phillips
Mid-Market Account Executive, EMEA
runZero
Chair's Welcome
Autonomous Cyber Resilience in the Era of AI
AI now sits on both sides of the resilience equation. Absolute Security's latest global research, surveying 1,000 CISOs across the US and UK, reveals that AI-assisted attackers now weaponise vulnerabilities faster than most enterprises can patch them: 41% of organisations have already experienced AI-accelerated exploitation in the past 12 months, and 58% agree their patching processes can't keep pace.
The financial exposure is stark. When endpoint devices go down, research found related costs reach $19 million per hour on average — and nearly half of UK enterprises (49%) reported total recovery costs exceeding $10 million from their most recent disruptive incident.
Yet the response hasn't caught up. Only 4% of organisations describe themselves as "broadly autonomous," even though 88% of CISOs agree autonomous recovery would measurably cut downtime costs. Trust — not budget or integration complexity — is the single biggest barrier holding leaders back.
In this opening keynote, Rob Brown, Senior Director, Technical Services at Absolute Security, unpacks the data behind their latest Enterprise Cyber Resilience research series, and makes the case for why UK enterprises need to close the trust gap before the speed of AI-driven attacks closes it for them.


The Strategic CISO: Expanding Influence, Elevating Accountability, Redefining Leadership
The CISO role is shifting rapidly. No longer just technical guardians, today’s security leaders are expected to act as strategic architects of organisational resilience, shaping risk posture, influencing investment decisions, and guiding board‑level strategy. This evolution comes as scrutiny intensifies.
Regulators, investors and executives increasingly expect CISOs to demonstrate informed judgment, transparent governance and strategic foresight. The UK’s Cyber Security and Resilience Bill, which expands sectoral obligations and codifies board‑level accountability, reinforces that personal liability now sits alongside strategic authority. And with Gartner predicting that by 2028 50% of CISOs will own disaster recovery as well as incident response, the remit is expanding into full‑spectrum resilience leadership.
This opening panel explores how CISOs are embracing this elevated strategic role while navigating the convergence of greater influence and heightened personal exposure.





Building a Robust Data Security Program
Bad news: your data classification program probably failed. Good news: it actually matters now. AI agents are running wild across your data, and classification is finally the thing that unlocks productivity instead of just killing projects. We'll dig into what's broken, why it matters, and five simple questions your team should ask.


Patch Everything, Break Nothing: Risk-Aware Vulnerability Management in the Era of AI-Powered Exploits
AI has fundamentally changed vulnerability discovery: vulnerabilities are published faster than ever, the disclosure-to-exploitation window is collapsing, and exploitation is the leading initial access vector. But rushing patches is risky: even routine vendor updates can trigger outages. Patch too slowly and attackers win; too fast and the outage is self-inflicted. The session shows AI reshaping both sides, from faster attacks to AI-driven vulnerability assessment and Patch Intelligence that keep humans in control. Vetcor shows how eight to ten technicians manage 15,000 endpoints across 900 clinics, with automated patching reclaiming 40+ hours monthly, powered by risk-aware remediation within unified endpoint management.


From Business Risk to Board Confidence: Security Strategy for the AI and Privacy Era
As organisations accelerate AI adoption, CISOs must enable innovation while protecting sensitive data, meeting evolving regulatory obligations and sustaining critical business services. The challenge is turning these demands into a coherent security strategy with clear priorities and measurable outcomes.
Drawing on CISO advisory engagements and strategy workshops across EMEA, this session presents a practical approach to connecting business objectives, AI and privacy risks, and regulatory expectations with accountable ownership, security architecture and investment decisions. It explores how network security approaches to securing AI, identity, Zero Trust and integrated security operations support that strategy, and how leaders can build evidence of control effectiveness and business value.
Attendees will leave with questions to pressure-test their strategy and a method for shaping a phased roadmap: 0-30 days, 30-90 days and 3-12 months - with clear owners, dependencies and success measures that support meaningful board conversations.


When AI Agents Become Your Customers: Opportunity, Risk and Control
As AI agents increasingly interact with businesses on behalf of customers, they present new opportunities to drive revenue, improve customer experiences and streamline digital transactions. But this creates a growing tension between embracing AI-driven innovation and protecting businesses from fraud and malicious automation.
Using everyday scenarios, from managing loyalty programmes to making purchases, this interactive workshop explores how legitimate AI agents and malicious actors can interact with the same digital services. How can security teams distinguish between them, manage the risks and enable trusted interactions without restricting the commercial opportunities AI agents bring?
Through a practical case study and open discussion, delegates will explore the visibility and controls needed to navigate this new landscape.


Break and Networking
From Compliance Theatre to Genuine Resilience: The UK Cyber Security and Resilience Bill Reality Check
Twelve months into DORA enforcement, and with the UK’s Cyber Security and Resilience Bill progressing through Parliament, the gap between regulatory intent and operational reality is becoming increasingly visible. Research published in early 2026 found that only 16% of organisations in scope for NIS2 are confident they are fully compliant, while 11% were entirely unaware they fell within its scope. The NCSC’s 2025 Annual Report recorded 204 nationally significant cyber attacks in the year to September 2025, nearly double the previous year’s figure, accelerating the UK government’s legislative response and raising expectations for demonstrable resilience.
For organisations operating across both UK and EU jurisdictions, the divergence between the EU’s prescriptive Article 21 security requirements and the UK’s more principles‑based approach has created a dual‑compliance burden that most have not adequately resourced. The result is a widening gap between what regulators are signalling and what enterprises can operationally sustain.
This panel moves beyond the mechanics of compliance to examine what genuine operational resilience looks like in practice, from validated incident response and continuous assurance to supply‑chain dependency mapping and board‑level accountability. We explore why the organisations treating regulation as a minimum baseline rather than a maximum ambition are already differentiating on trust, transparency, and long‑term resilience.






When Recovery Is the Target: Building Cyber Resilience for the Age of Agentic AI
Attackers no longer start with production. They start with recovery. Adversarial AI now goes after the backup tier first, corrupting or deleting restore points so that when the ransom note lands, there is nothing clean to go back to. At the same time, machine identities outnumber humans 82 to 1.
AI agents, copilots and MCP connections are being handed privileged access and acting at machine speed. Identity is the new perimeter, and the backup platform is now part of the attack surface.
In this 20-minute workshop, Richard Storry, International Channel SE Leader at Druva, shows how to anticipate that move and neutralise it before it lands. He will set out what a resilient recovery tier actually looks like. That means a true logical air-gap and immutability that a compromised admin cannot switch off. It means Safe Mode tenant lockdown the moment an attack is suspected. And it means zero-trust policy controls and least-privilege guardrails for the non-human identities now operating across your estate. Delegates will also get a simple five-level cyber readiness model to benchmark where they stand today.


Why AI in Cybersecurity Still Needs a Human in the Loop
AI promises to transform the SOC, but the real question for security leaders is whether they can trust, explain, and remain accountable for AI-driven decisions. The session explored automation bias, accountability gaps, and how a human-led, AI-accelerated SOC can work in practice through a Huntress customer story.


The Rapidly Changing Role of the CISO
AI isn’t just reshaping the threat landscape, it’s changing how security leaders and teams operate across the business. This interactive discussion will explore how leadership, decision-making, and operational priorities are evolving in the era of agentic AI, and what this means in practice for modern security organisations.
• How agentic AI is collapsing the gap between strategy and execution, and why articulating clear outcomes is now your most valuable skill
• Why the operational grip that made great CISOs is becoming their biggest constraint in an autonomous world
• How shifting focus from controls to outcomes builds the machine-speed defence that makes compliance and resilience a byproduct, not a goal.


Beyond Third Parties: Identifying Nth-Party Concentration Risks to Strengthen Operational Resilience
Direct third-party supplier oversight has matured considerably over the past decade, yet most organisations still have limited visibility beyond their first tier of suppliers. The dependencies that sit two or three layers deeper, shared infrastructure, common software vendors, concentrated niche services providers, are rarely surfaced through a bilateral risk assessment, and are often only discovered once a disruption has already impacted multiple organisations at once.
This roundtable brings together CISOs as well cyber security and TPRM practicioners to compare notes on a problem that sits largely outside individual control: how do you manage risk in a supply chain layer you can't directly assess or have contractual relationships with? The discussion will draw on real operational experience to explore where nth-party exposure has caused genuine difficulty, what's realistic to expect from current tools and processes, and how this challenge can be overcome in practice.


Be Bold! Active Asset Management is a Contact Sport
Join us for an interactive roundtable on bridging the gap between perceived and actual network visibility. We will examine the limitations of traditional asset management—like CMDBs and EDR agents—and quantify exposure risks across unagentable OT, IoT, and building management systems. With AI-assisted attacks accelerating the speed at which adversaries exploit hidden entry points, achieving total asset clarity has never been more urgent.
• Roundtable question: What do you use for asset management, and do you think it’s 100% accurate, reliable, and up to date?
• Roundtable question: What % of connected smart thermostats, cameras, HVAC systems, PLC’s, or other similar equipment are accounted for in your asset management solution?
• Roundtable question: Are you feeling more or less urgent to understand your assets and exposures in this new AI assisted attack era?
• Roundtable question: When was the last time you performed active discovery on your own network?


The Human Resilience Gap: Why Exhausted Security Teams Are Becoming an Enterprise Risk
The 2025 ISC2 Cybersecurity Workforce Study reported a global talent gap of 4.8 million professionals whic is a 19% increase year‑on‑year. But the headline masks a deeper structural failure. In 2024, 25% of organisations experienced cybersecurity layoffs, 37% absorbed budget cuts, and 90% reported critical skills shortages that materially elevate enterprise risk. The result is a profession operating under sustained strain, where burnout is no longer a wellbeing issue but a quantifiable operational vulnerability: elevated stress and cognitive fatigue are consistently linked to slower incident response, higher error rates, and reduced detection accuracy across SOC environments.
This session examines the organisational dynamics that make many security functions psychologically unsafe by design.
The discussion will highlight why psychological safety is now a core resilience metric, directly correlated with faster detection, higher retention, and stronger defensive performance.



Chair's Closing
MOVE TO NETWORKING DINNER AND DRINKS
Drinks
Dinner
Breakfast and Registration
Chair's opening
Preemptive Cybersecurity: Why Detect-and-Respond Is No Longer Sufficient
Preemptive Cybersecurity is the defining security shift of the next three years (Gartner) . A move away from reactive monitoring toward anticipatory, AI‑assisted threat neutralisation. The data underscores the urgency: time‑to‑exploit has collapsed from over 700 days in 2020 to just 44 days in 2025, AI‑generated phishing now outperforms human red teams, cloud intrusions have risen 35% year‑on‑year, and the adversarial use of autonomous coding agents (documented across 17 extortion campaigns in a single month in 2025) has fundamentally accelerated the kill chain.
Traditional detect‑and‑respond architectures assume attackers will be visible before they are effective. That assumption is no longer holding. Gartner forecasts that by 2028, security products lacking preemptive capabilities will lose market relevance, as boards shift from asking whether breaches can be contained to demanding evidence that threats can be anticipated and neutralised before exploitation.
This session examines what it takes to operationalise preemptive cybersecurity at scale. From architectural redesign and telemetry‑driven intelligence to the cultural and organisational changes required to move from perimeter‑defending to threat‑anticipating. We explore the investments, capabilities, and operating models that enable security teams to act ahead of the adversary, not behind them.





Securing the Future of AI Agents
AI agents aren't waiting for permission, they're already inside your critical systems, deciding what happens to your most sensitive data. Scaling that safely takes visibility, control, and resilience most programs lack today. The reason: data, identity, access, and AI security are managed as separate disciplines, leaving blind spots that keep risk from being seen in time. Join security experts to explore strategies for safely scaling AI agents.


Governing Agentic AI: When Your Most Dangerous Insider Is a Machine
The rapid deployment of AI agents has reshaped the enterprise threat surface in ways that most governance models were never designed to handle. A 2026 Dark Reading survey found that 48% of security professionals now rank agentic AI as the year’s top attack vector, ahead of ransomware and nation‑state campaigns. Gartner projects that 40% of enterprise applications will incorporate task‑specific AI agents by the end of 2026, up from fewer than 5% in 2025, creating an explosion of autonomous processes operating far beyond traditional oversight mechanisms.
The risk is not the agents themselves but the governance vacuum surrounding them: unmanaged non‑human identities, over‑permissioned service accounts, missing audit trails, and security awareness programmes built for human behaviour patterns that offer no coverage for autonomous decision‑making.
This panel examines the governance frameworks that are actually working in early‑adopter enterprises, from runtime privilege enforcement and agent identity lifecycle management to continuous validation of autonomous actions and board‑level oversight of AI deployment. We explore the specific controls, operating models, and assurance mechanisms required to close the widening gap between agent velocity and organisational security maturity, and what CISOs must prioritise as AI becomes a first‑class actor in the enterprise environment.






One Program, Many Entities: Standardising Global Compliance After Growth by Acquisition
Growth by acquisition brings new compliance programs, each at a different level of maturity. For global organisations facing varied regulatory pressure, that patchwork quickly becomes a governance risk. In this session, we examine how one global financial services organisation replaced isolated business-unit programs with a single, centralised compliance model, scaling common controls and policies across acquired entities and multiple frameworks. The discussion includes the hard lessons learned when a unified control set meets business units at very different stages of maturity.


The New Attack Surface CISOs Can’t Ignore: Securing the Connected Enterprise Beyond IT
Even organisations with limited traditional OT now depend on connected assets beyond standard IT, including building systems, cameras, sensors, access control, smart facilities, and third-party-managed equipment. This session explores why traditional asset inventories and vulnerability views are no longer enough, and how CISOs can use asset intelligence, device context and risk-based prioritisation to uncover hidden exposure, understand what matters most and strengthen resilience across the connected enterprise.


20 Min Break
Autonomy is Outrunning Accountability
One Identity's Technology Strategist Alan Radford will unpack one of the most urgent identity challenges facing enterprises today: as AI agents and autonomous systems take on more decision-making and action-taking power, the guardrails for who (or what) is accountable haven't kept pace, the bill is getting out of hand and Quantum is just around the corner.


Breaking the AI-Driven Social Engineering Attack Chain
Social engineering has evolved from opportunistic phishing into a relentless, AI-orchestrated lifecycle. Traditional defensive models like the Cyber Kill Chain and siloed solutions, such as legacy Digital Risk Protection (DRP), Security Awareness Training (SAT), and inbox-only email security, are no longer sufficient to stop modern adversaries. Today's attackers leverage automation and generative AI to manage complex campaigns that span executive impersonation, brand abuse, and deepfake-enhanced pretexting, often bypassing MFA and identity controls with ease.


Peer to peer discussions and 121 meetings
Third-Party Risk in a Fragmented World: Continuous Assurance for AI, Cloud and Critical Suppliers
Third‑party ecosystems have become the most volatile component of the modern enterprise attack surface. Forrester forecasts that 65% of breaches will originate in third‑party environments by 2027, driven by opaque supply chains, unmanaged SaaS adoption, and the rapid introduction of AI vendors with limited security maturity. ENISA’s 2026 Threat Landscape Report highlights a 37% year‑on‑year increase in supply‑chain‑driven incidents, while Gartner notes that 75% of organisations will require continuous security assurance from critical suppliers by 2028, replacing static questionnaires and annual audits.
At the same time, cloud concentration risk is accelerating: IDC reports that 42% of UK enterprises rely on fewer than three hyperscalers for mission‑critical workloads, creating systemic dependencies that amplify the blast radius of outages, misconfigurations, and upstream compromises. The rise of AI agents and data‑hungry models adds further complexity, with 451 Research finding that only 28% of organisations have visibility into how third‑party AI systems handle, store, or train on enterprise data.
This panel examines how CISOs can build continuous, intelligence‑driven assurance models that keep pace with a fragmented supplier landscape. We explore how leading organisations are integrating automated monitoring, contractual controls, shared intelligence networks, and AI‑assisted risk scoring to manage third‑party exposure at scale. The discussion will highlight why third‑party risk is no longer a procurement exercise but a core pillar of enterprise resilience, requiring tight alignment across security, legal, procurement, and data governance teams.





LUNCH
Quantum Computing: What CISOs Need to Know Now - Separating Hype from Strategic Risk
Quantum computing is accelerating fast, but what does that really mean for enterprise security? In this fireside chat, our speakers cut through the hype to give CISOs a clear, practical view of the risks, timelines, and strategic decisions that matter now. From the future of cryptography to the rise of “harvest now, decrypt later” threats, this session offers a rare opportunity to hear directly from one of the UK’s leading quantum thinkers on how to build long‑term resilience in a rapidly shifting landscape.
Prof Andrew Green, University College London, London Centre for Nanotechnology



From Burnout to Balance: Safeguarding the Mental Health of Security Teams
Cybersecurity professionals often operate under relentless pressure, long hours, high stakes, and constant threat monitoring. Participants will discuss how they can proactively address burnout, foster psychological safety, and embed wellbeing into the culture of security teams.
Moderation Questions:
• What early warning signs of burnout should leaders look for in their teams?
• How can cybersecurity leaders balance 24/7 operational demands with sustainable workloads?
• Which wellbeing initiatives have proven effective in high-stress security environments?
• How do you measure the ROI of wellbeing programs in terms of resilience and retention?
Resilience Through Diversity: Building Teams That Think Differently
Diversity of thought, background, and experience strengthens problem-solving and resilience. Participants will explore how to embed diversity, equity, and inclusion (DEI) into security hiring and leadership pipelines.
Moderation Questions:
• How does diversity directly impact the resilience of a security team?
• What barriers still exist to building diverse security teams, and how can they be dismantled?
• How can cybersecurity leaders ensure DEI initiatives are authentic rather than performative?
• What metrics or benchmarks can track progress in building diverse teams?
Upskilling for the Future: Preparing Teams for AI, Cloud, and Emerging Threats
As technology evolves, so must the skills of security professionals. This roundtable focuses on continuous learning, reskilling, and preparing teams for the next wave of threats, from AI-driven attacks to quantum risks.
Moderation Questions:
• Which emerging skills are most critical for security teams over the next 3–5 years?
• How can cybersecurity leaders create a culture of continuous learning without overwhelming staff?
• What role should certifications, labs, and simulations play in upskilling?
• How do you balance investment in training with immediate operational needs?
Chair's Closing & End of Summit
Our Partners
