Outline Programme

EARLY BIRD DEADLINE - register by 20th September 2026 to save with Early Bird Delegate Fees

PLENARY SESSIONS:

From Definition to Delivery: Governance, Methodology, and Practical Implementation of NIS2 and CER
This session explores how the translation of policy into practice has developed under NIS2 and CER. There still appears to be a lack of understanding around who is responsible for identifying critical infrastructures in a transnational setting, who is responsible for its security and resilience and which actors are required to report incidents, particularly under the evolving NIS-2 and the CER Directive regimes. We will examine governance models, definitions, and practical methodologies for risk assessment, compliance, and reporting.

Panel Discussion – Systemic Risk and Uneven Resilience: Confronting Europe’s Next Critical Infrastructure Shock
In this panel discussion, we will examine Europe’s current preparedness for systemic infrastructure disruption, exploring the persistent resilience gaps across Member States and critical entities, and its fragmented capabilities against the evolving hybrid threat landscape. In this engaging discussion, we will assess how current NIS2 and CER implementation is addressing these challenges, where governments and operators are succeeding and falling short, and what must change to influence future frameworks such as NIS3 and CER2, ensuring more consistent, cross-border, and operationally effective resilience across Europe.

TRACK TOPICS:

Emerging & Evolving Threats against CI
Critical infrastructure faces increasingly complex and evolving threats. Cyberattacks are growing more sophisticated, terrorism remains a concern, and climate change is making natural disasters more unpredictable. New dangers such as drone attacks, misuse of artificial intelligence, evolving hybrid threats and state sponsored attacks further complicate the landscape. A key challenge is how to effectively identify, monitor, and understand these diverse and emerging threats.

Infrastructure Interdependencies and Cascading effects
Modern critical infrastructure is deeply interconnected, making it increasingly vulnerable to cascading failures. Disruptions in one sector—such as energy, transport, or communications—can rapidly propagate across systems, amplifying impacts and complicating response efforts. Understanding these interdependencies is essential for effective protection and resilience. This session explores how to identify systemic risks, model cascading effects, and strengthen cross-sector coordination to mitigate disruptions, enhance situational awareness, and ensure continuity of essential services in an increasingly complex threat landscape.

Infrastructure Resilience Under Fire: Ukraine Case Study
Lessons learned from Ukraine – the most advanced real-world laboratory for modern critical infrastructure resilience under sustained attack – where the country is witnessing constant coordinated attacks. Listen to Ukraine’s experts tasked with keeping the lights on and goods moving. It’s the only large-scale, prolonged test of critical infrastructure under continuous cyberattacks, physical strikes (from missiles and drones) and hybrid warfare.

Skills Gaps, Fragmentation Capabilities & Public–Private and Cross-Sector Coordination
Critical infrastructure resilience is increasingly constrained by workforce shortages and fragmented capabilities across sectors and borders. This session explores how skills gaps in cybersecurity, OT, and crisis management limit preparedness, and siloed operations hinder effective response. It will examine the urgent need for cross-sector coordination, improved information sharing, and aligned capability development. Attendees will gain practical insights into building a more integrated, skilled, and collaborative resilience ecosystem.

Technologies to Detect and Protect
The latest technologies for detecting and predicting threats to critical national infrastructure span ground, land, underwater, space-based, and cyber domains, supported by advanced sensors and access control systems. Artificial intelligence increasingly enhances these capabilities by improving speed, accuracy, and cross-domain analysis of threat signals. New, developing systems and solutions enable earlier detection, better prediction, and stronger situational awareness across interconnected infrastructure systems.

Risk Mitigation, Resilience, Business Continuity Strategies
Developing effective resilience strategies across the critical infrastructure community requires disciplined information sharing, strong preparedness, and robust risk mitigation and management. This session explores how organisations can identify, assess, and prioritise risks in a structured way, while reducing vulnerabilities and strengthening overall system resilience. It also examines how to embed continuity planning for potential disruptions or disasters, ensuring coordinated responses and support long-term operational stability across interconnected infrastructure systems.

Drones and UAS
Drones present a growing threat to critical infrastructure due to their accessibility, manoeuvrability, and payload capabilities, enabling surveillance, disruption, or delivery of explosives. However, they can also support infrastructure protection through monitoring and response applications. This session examines the evolving drone threat landscape, available countermeasures, and the dual-use role of drones in both challenging and enhancing critical infrastructure security and resilience.

AI and Cyber in CI
AI plays a dual role in critical infrastructure cybersecurity, acting as both a defensive tool and a potential threat. It strengthens protection by improving threat detection, automating responses, and predicting attacks through advanced data analysis and anomaly detection. However, malicious actors can also exploit AI to develop more sophisticated attacks. We investigate how effective defence requires harnessing AI’s benefits while managing its risks through strong security controls and continuous adaptation.

MINI SYMPOSIUMS:

Power & Energy Sector Symposium
Europe’s power and energy sector—spanning oil, gas, and rapidly expanding renewables—remains fundamental to all critical infrastructure. In today’s security climate, it faces escalating cyber and hybrid threats targeting IT, OT, and SCADA systems, alongside intensifying climate-driven disruptions. Ensuring resilience means anticipating attacks, reducing the impact of outages, and safeguarding interconnected grids. Strengthening Europe’s energy networks is now a strategic priority to maintain stability, security, and continuity across essential services and economies.

Cybersecurity and Cyber Resilience Sector Symposium
Cybersecurity for critical infrastructure has shifted from prevention alone to a broader focus on resilience. While strong defenses, threat detection, and response remain essential, today’s threat landscape demands the ability to withstand, adapt to, and rapidly recover from cyber incidents. This session explores the nature of increasingly sophisticated and disruptive cyber threats to proactive strategies for ensuring business continuity, disaster recovery, and operational integrity, enabling vital services to remain secure, reliable, and functional.

Transport & Logistics Sector Symposium
The transport and logistics sector is a cornerstone of critical infrastructure, enabling the movement of people, goods, and essential services. Increasing interconnectivity, digitalisation, and reliance on complex supply chains expose it to cyber, physical and hybrid threats. This session examines strategies to enhance resilience, protect key assets, and ensure continuity, focusing on risk management, cross-border coordination, and safeguarding operations against evolving threats in a dynamic global environment.

Maritime and Subsea Infrastructure Sector Symposium
Maritime and subsea infrastructure now face an intensified threat landscape, from hybrid and cyber attacks on ports, vessels, and undersea cables to rising geopolitical tensions and sabotage risks. As digitalisation expands vulnerabilities, protecting this sector requires integrated resilience strategies, including integrating physical security, cybersecurity, and operational continuity, alongside stronger international collaboration to protect global trade and connectivity.