Programme

Registration - coffee - networking
Chairs Opening Address & House Keeping

Welcome to the Future of Cyber Security Manchester Conference.

Chairperson Purvi Kay opens the event with an introduction to the day’s themes — exploring the latest cyber insights, emerging threats, and the future landscape of digital security. In her address, Purvi will highlight the importance of collaboration, innovation, and resilience in an era of rapid technological change. She will also provide essential housekeeping information to ensure a smooth and engaging conference experience for all delegates. Join us as we set the stage for a day of expert discussion, knowledge sharing, and forward-looking perspectives on cybersecurity’s evolving future.

Speaker
Head of Cyber Security – Defence Prime Women in Cyber/Tech and Neurodiversity Advocate
Empowering Cyber Defence: Fighting Against The AI Bot Threat

Artificial Intelligence is revolutionizing the cybersecurity landscape, enabling organizations to detect threats faster, respond to incidents more effectively, and stay one step ahead of adversaries. Join Thales for an in-depth exploration of how AI solutions are shaping the future of cyber defence. Our experts will examine real-world examples, highlight the benefits and challenges of integrating AI into existing security ecosystems, and showcase the latest AI advancements from Thales that deliver enhanced threat detection and automated response. Learn how you can leverage AI to proactively secure your organization’s digital assets and adapt to the rapidly evolving threat landscape. This interactive session will provide valuable insights for cybersecurity leaders, IT professionals, and anyone interested in building AI-powered resilience.

Assume Breach, Prepare for Recovery

Join Darren Naidu of Object First as he explores why data resilience is mandatory for business survival. Leveraging insights from research on data protection and ransomware trends, he'll reveal why traditional Zero Trust models are inadequate for the future. Discover how an evolved Zero Trust approach can empower organisations to attain genuine data resilience in the face of emerging threats.

Keep Working Through The Unexpected

Cyber incidents rarely arrive on schedule, and recovery plans often focus on infrastructure while overlooking the people who still need to work. In this session, we’ll explore how a different approach to endpoint resilience can keep users productive through ransomware, Windows outages and other unexpected disruption, restoring secure access to critical applications without waiting for devices to be rebuilt or replaced.

This talk unpicks the technical offerings, and commercial uses, of AI, crypto, and quantum, as well as examining how they’ve been overhyped.

Trailblazing Rarilabs COO and founder of Blackwood, Consultant and Keynote Speaker on Artificial Intelligence, Cryptocurrency and Blockchain associated technologies.

Kitty Horlick is an expert on blockchain, AI, enhanced cryptography, and how these next-generation technologies are reshaping society. She is the COO of Rarilabs, the blockchain-based research centre.

The tools she pioneers tackle some of the biggest challenges facing life online; from ensuring AI and AI-generated content is easy to detect, to keeping your personal data out of the hands of social media giants. Rarilabs’ proudest accomplishment is Freedom Tool, a surveillance-free voting tool that was used by Russian dissidents to anonymously protest Putin, and which survived several attacks from the Kremlin.

Rarilabs is also a key contributor to the digital identity protocol Rarimo. Prior to Rarilabs, Kitty ran and founded Blackwood, a consultancy firm focused on onboarding traditional businesses into emergent technologies including AI and web3-associated technologies such as blockchain, and cryptocurrency. She is passionate about making complex technologies and the hidden impacts they have on businesses and society at large accessible. Kitty is a long-term adopter of blockchain with over eight years experience in the space. She is a tech insider: deeply embedded in the industry and with her finger closely on the pulse of the latest trends and challenges. In 2023, Kitty was the expert chosen to appear on a BBC Radio 4 programme examining crypto, blockchain and web3

Speaker
Trailblazing Rarilabs COO and founder of Blackwood, Consultant and Keynote Speaker on Artificial Intelligence, Cryptocurrency and Blockchain associated technologies.
AI Adoption Must be Secure-by-Design

As AI continues to fundamentally change the way organisations work, understanding the risks to data privacy and security is more important than ever. In this session, we will discuss the impact that AI is having on the threat landscape and how organisations can shine a light on their data and enable their users to productively, but securely, use AI.

How everyday identity indiscipline clears a path to sensitive resources

This session traces an attack path from end to end. It opens with recent UK cases where identity exposure, rather than anything sophisticated, provided the opening. It then follows the route an attacker takes from a single weak identity through to critical systems and data, and looks at how the same weaknesses map onto the frameworks UK organisations already answer to, whether it is Cyber Essentials, the NHS Data Security and Protection Toolkit, the UK NIS Regulations, and NIS2 for those trading into the EU. The rest is practical: three moves, in order. Map every identity and what it can reach. Measure the resulting risk so it can be tracked rather than argued about. Mitigate in the sequence that removes the most exposure fastest.

Coffee & Networking
Operating in the Autonomous Threat Era - Why the SOC must evolve

Most security operations were built for a world where attackers moved at human speed.

That world no longer exists. AI-powered threats can adapt and scale in seconds, creating new challenges for CIOs and IT leaders seeking to balance innovation, resilience, and risk. Join Gareth Lindahl-Wise, CISO at Ontinue, as he explores the rise of the Agentic SOC where AI-driven automation, human expertise, and continuous governance converge to deliver security at machine speed while maintaining trust and control.

In this session, you'll learn how to:

• Modernize your security operating model for the Autonomous Threat Era

• Accelerate detection, investigation, and response with AI and agentic capabilities

• Build a data foundation for machine-speed decision-making

• Establish governance, trust, and accountability for AI-driven operations

• Improve resilience while reducing operational complexity The future of cybersecurity is not AI or humans. It's AI and humans working together. Discover how to prepare your organization for what's next.

Fireside Chat with Dr. Elaine Kasket and Purvi Kay

What happens when technology begins to shape not just how we work, but how we think, behave, connect and even understand ourselves?

Leading cyberpsychologist Dr. Elaine Kasket joins Purvi Kay for a fascinating fireside conversation exploring the increasingly complex relationship between people, technology and AI. Drawing on Elaine’s work across cyberpsychology, digital wellbeing, AI, privacy and our digital lives, the discussion will look beyond the technology itself to examine its very human consequences. From our growing reliance on AI and the psychology behind online behaviour to digital identity, trust, privacy and what happens to the enormous trail of data we leave behind, Elaine and Purvi will explore some of the questions organisations — and society — are only beginning to confront.

Thought-provoking, surprising and guaranteed to get people talking, this is a fireside chat that asks a simple but increasingly important question: as technology becomes more human, how do we make sure humans remain in control?

Speaker
leading cyberpsychologist and Counselling Psychologist. She is an expert in how our digital choices shape our experience and relationships across the lifespan, at home and at work.
Verifying Identity in the Age of AI-Powered Impersonation

Cloned voices and deepfaked faces are being used to impersonate new hires, callers, and even IT staff, exploiting areas of identity security that are often overlooked: verification and recovery. Learn how the right identity verification solutions can stop AI-powered impersonation at the point of attack, without adding friction for legitimate users.

Lunch and networking
Chairs Afternoon Address
Speaker
Head of Cyber Security – Defence Prime Women in Cyber/Tech and Neurodiversity Advocate
Get to ‘Yes’ Faster Simple, Scalable and Secure Software Onboarding.

Enterprise software onboarding is a critical control point for reducing software supply chain risk, but traditional review processes are often too manual, slow, and dependent on vendor attestations.

This session explores how organizations can accelerate software approvals by using binary analysis, automation, and ITSM workflow integration to make faster, more consistent, and evidence-based onboarding decisions without compromising security. In this session, we’ll examine a practical approach to modernizing software onboarding with independent binary analysis and automated risk assessment.

Attendees will learn how to inspect commercial and third-party software before deployment, validate supplier claims such as SBOM accuracy, detect hidden risks including malware, vulnerable components, undocumented libraries, weak cryptography, and exposed secrets, and make more defensible approval decisions. We’ll also explore how these controls can be integrated into existing ITSM workflows to reduce friction, improve consistency, and scale software assurance across the organization. The goal is to help teams get to “yes” faster while maintaining strong, evidence-based security standards.

The New Attack Surface: Securing Identities in the Agentic AI Era

How many AI agents and machine identities have access to your systems right now? Most organisations can't answer that. Drawing on new global research of 3,200+ IT leaders, David Gordon examines the governance gaps agentic AI has exposed, and what identity-first security looks like in response.

Securing things that have not yet been invented

Everyone is stuck arguing about the same two tired AI narratives: “All hype, or jobs apocalypse”. Both are wrong, but while we debate them we are missing how to remain secure while the change is happening. In this session we will look at what is really happening, and how to formulate the cyber strategies needed. Looking at how we got here, gazing into the crystal ball to see what comes next, and learning how to get ahead of the conversation in your company

Speaker
Former Head of Future Technology at the Bank of England, Keynote Speaker on Artificial Intelligence, Leadership and wider Technology themes, Writer, Broadcaster.
Why King Philip needed a SIEM: a 16th-century lesson in drowning in data

King Philip II ran a continent-spanning empire on individual reports, reading every ‘log' himself with no way to correlate them until it was too late - a 16th-century case study in exactly why security teams need centralized visibility today. This talk traces that lesson through Snoop's own startup journey, implementing these lessons on log aggregation early, through maturing to a fully-fledged SIEM, and finally through the Vanquis transformation, showing how consolidating fragmented data into a single platform enabled the business to move securely at speed. You'll leave with a clear view of how centralized visibility actually benefits you, told through one very old case study…and one very current one!

The Future of Physical Security: Innovation That Actually Matters

Physical security is undergoing a fundamental transformation.

Legacy systems, decentralised, reactive, and increasingly disconnected from IT infrastructure, leave organisations perpetually on the back foot, responding to incidents rather than preventing them. Join Verkada's Andrew Price for a look at the trends reshaping the security industry, and what real innovation looks like in practice.

• The IT-ification of Physical Security: How physical security is increasingly falling under the IT umbrella and what a zero IT burden future looks like.

• Closing the Cyber-Physical Gap: How siloed physical security infrastructure creates cybersecurity blind spots, and how organisations can close the gap with connected, secured systems.

• AI Built In, Not Bolted On: Why fragmented, third-party AI adds cost and complexity — and what a truly native approach delivers.

• The Operational Upside: How leading organisations are moving beyond pure surveillance to unlock real business intelligence from their physical security data.

Risk Lives Where Visibility Ends: Turning Asset and Identity Data into Action

You cannot surface, prioritise, or reduce risk you cannot see. Every meaningful risk decision — from vulnerability remediation to threat detection — depends on a clear, current understanding of two things: what assets exist in your environment, and which identities can touch them. Without that foundation, risk scoring is guesswork, alerts lack context, and exposure hides in the gaps.

Join Craig Saunderson as he explores how unifying asset and identity visibility turns fragmented security signals into actionable risk intelligence – making exposure something teams can measure, rank and act on with confidence. Discover how clearer context strengthens cyber defences and helps security teams focus human intelligence where judgement matters most.

The Winning Playbook: Cyber Resilience and Game Integrity

Cyber resilience is no longer just a technical imperative—it's a competitive one. When the stakes are measured in fairness, trust, and competitive balance, security strategy must evolve beyond control. This talk explores the emerging threat landscape, the tactics that work in high-pressure environments, and how organisations build resilience when every play matters.

Speaker
Director of Cybersecurity & Risk Management for the National Football League NFL
Future CISO 100 Winner
The Right Test at the Right Time: A Practical Guide to Security Validation

Cyber security testing has never been more important, but with vulnerability scans, penetration tests, red team exercises and incident response simulations all promising to improve security, how do you know which approach is right for your organisation? This session cuts through the confusion and explains the purpose, value and limitations of the most common security testing activities. Attendees will learn when vulnerability scanning is enough, when a penetration test adds value, how red teaming measures real-world resilience, and why incident response testing is essential for validating preparedness when an attack succeeds. Whether you're a business leader, IT professional or security practitioner, this practical session will provide a clear framework for selecting the right test at the right time, ensuring your security investments deliver meaningful risk reduction rather than simply ticking a compliance box.

The 100-Day Wake-Up Call: Why Automation Is Now a Cyber Resilience Imperative

The countdown to 100-day TLS certificates has begun.

On 15 March 2027, maximum public TLS certificate lifetimes will fall to 100 days, before shrinking again to 47 days in 2029. This is not simply a certificate management deadline. It is a test of operational resilience. As renewal cycles accelerate, manual processes, fragmented ownership and limited visibility will increase the risk of outages, compliance failures and disruption.

At the same time, quantum computing is challenging the cryptographic foundations organisations rely on today. Although these changes may appear separate, both demand the same capabilities: complete visibility, automated lifecycle management and the ability to replace certificates, keys and algorithms quickly and safely. Drawing on more than a decade of leadership across technology and cybersecurity,

Will Craven will explain why automation is becoming the foundation of crypto-agility and why 100-day certificates should be treated as a catalyst for broader PKI modernisation. Attendees will leave with a clear understanding of how automation, PKI modernisation and post-quantum preparation fit together and the questions leaders should be asking now.

Coffee and networking
‘Fire-side chat’ with Paddy McGuiness

Cyber security meets comedy in a fireside chat that promises to be anything but predictable. Join cyber security leader Purvi Kaye and comedian and TV presenter Paddy McGuinness for a lively conversation exploring the human side of cyber security, resilience and life in an increasingly digital world.

Purvi will bring the cyber expertise, while Paddy brings his trademark humour, quick wit and a refreshingly different perspective. Expect candid conversation, unexpected questions and plenty of laughs as they tackle a serious subject without taking themselves too seriously.

No firewalls were harmed in the making of this fireside chat — although a few cyber clichés might not make it out alive.

Speaker
International Presenter & Comedian
Chairs Closing Remarks
Drinks Reception

Drinks reception