Internet Security Days @ it-sa 2026
2026 will be a reality check for companies. NIS2 and the Cyber Resilience Act are moving into practical implementation, whilst new European requirements are reshaping responsibilities and investment decisions. At the same time, AI, geopolitical dependencies and attacks on key digital infrastructures are exacerbating the security situation.
At the Internet Security Days @ it-sa 2026 we will therefore bring together those who are shaping, implementing and taking responsibility for these changes:
decision-makers from companies,
leading cybersecurity experts and
high-ranking representatives from politics and EU institutions.
For the first time, the eco Association’s established cybersecurity conference will take place right at the heart of it-sa, Europe’s leading trade fair for IT security.
In doing so, we are bringing two worlds together in a single day: the breadth and dynamism of the trade fair with the depth of a curated executive conference.
What does the new regulation actually mean for your organisation?
Where do you need to invest now?
Which technologies and architectures will be crucial for resilience?
And what really works in practice?
Six thematically interlinked sessions will address precisely these questions. From regulation, liability and market access, through resilient networks, the cloud and data centres, to secure AI, email security and defending against DNS abuse.
No endless debates about principles, but practical experience, real-world incidents and insights from people who are responsible for cybersecurity on a daily basis.. So that, at the end of the day, you are not only better informed but also able to make clearer decisions.
For strategy. For investment. For governance. And for when the worst happens.
CONTENTS & AGENDA
- 9:00
- Admission & registration
- 9:15
- Welcome & opening keynote
- 9:45
-
EU Cybersecurity Regulation at a Turning Point: From Compliance to Market Access
Speakers will be announced shortly.
The discussion will be held in English.
More about this session
Show less
What will change for companies when European cybersecurity regulation moves from legislation to implementation, supervision and market access?With NIS2, the Cyber Resilience Act and the planned reform of the EU Cybersecurity Act, a new phase is beginning for Europe’s digital economy: political requirements are being translated into concrete obligations, audits and liability risks. Requirements relating to risk management, reporting processes, certification, security by design and supply chain security are thus becoming strategic factors for investment, competitiveness and market access. It is crucial to create regulatory certainty without stifling innovation and growth.
High-level representatives from the European Commission, ENISA, the German Federal Office for Information Security (BSI), Deutsche Telekom and SAP will assess the transition from legislation to enforcement. The focus will be on regulatory overlaps, outstanding supervisory issues and the specific action required of companies. The session will demonstrate how cybersecurity is evolving from a compliance task into a prerequisite for trust, resilience and sustainable market success.
- 10:45
- Break
- 11:15
-
Future-Proofing Europe’s Networks: Digital Networks Act, Investment and Infrastructure Resilience
Speakers will be announced shortly.
The discussion will be held in English.
More about this session
Show less
What networks and investment models does Europe need to ensure that digital resilience is not merely mandated, but can actually be built and financed?Europe’s ambitions in AI, the cloud and digital sovereignty stand or fall with high-performance, secure and scalable networks. Perspectives from the European Parliament, the fibre optic sector, mobile communications, Internet Exchanges and cloud technology will examine whether the Digital Networks Act can create better investment conditions, reduce regulatory fragmentation and strengthen Europe’s digital competitiveness.
The focus will be on how fibre optic, mobile communications, interconnection and cloud infrastructures need to evolve in order to reliably support AI-based services. At the same time, the discussion will address how responsibility for investment, resilience and competitiveness should be distributed within the European digital ecosystem in future – and what decisions need to be taken today to set the right course.
- 12:15
-
Sovereign Infrastructures: Physical Cyber Resilience for AI, Quantum-Secure Systems and Critical Digital Services
Speakers will be announced shortly.
More about this session
Show less
How can digital sovereignty – beyond ownership and location – be ensured through controllable operating models, resilient connectivity, secure energy supply, robust recovery concepts and effective operational control?Digital sovereignty is also determined by physical infrastructure. AI applications, highly critical payment services and the migration to quantum-secure systems fundamentally increase the requirements for computing power, connectivity, availability and resilience. This brings the protection of critical workloads, the reduction of dependencies and the creation of robust redundancies into sharper focus.
Representatives from politics and Internet infrastructure will discuss how data centre hubs, regional sites, edge infrastructures and redundant fibre optic networks can be interconnected to form a resilient overall system. Topics will include physical single points of failure, concentration risks and energy and network availability – with the aim of keeping critical digital services available and controllable even under technological and geopolitical pressure.
- 13:15
- Lunch break
- 14:00
-
Artificial Intelligence and Cyber Resilience: Securely Automating Critical Internet Infrastructures
Speakers will be announced shortly.
More about this session
Show less
What decisions should AI be allowed to make independently in critical security processes – and who bears responsibility when it gets them wrong?Artificial intelligence is becoming a decisive factor for the cyber resilience of digital infrastructures: it enables earlier detection of threats, the analysis of complex attack patterns and faster responses to security incidents. At the same time, new attack surfaces, dependencies and systemic risks are emerging. The key challenge is therefore no longer whether AI should be used, but how it can be used securely, controllably and in compliance with regulatory requirements.
Experts from research, Internet infrastructure, operational cybersecurity and regulation will demonstrate how the potential of AI can be harnessed without compromising control and resilience. The focus will be on governance, risk management, secure automation and the requirements of the EU AI Act, NIS2 and the Cyber Resilience Act. The session will highlight the decisions that need to be taken now to ensure that AI enhances security rather than becoming a new business risk.
- 15:00
-
Secure Email as Standard: Translating BSI Requirements into Concrete CISO Action
Speakers will be announced shortly.
More about this session
Show less
How can companies implement the BSI requirements for email security effectively and measurably, with clearly defined responsibilities?Email remains the backbone of digital business communication – and, at the same time, one of the main entry points for phishing, identity theft and business email compromise. Building on the BSI’s “Year of Email Security”, this session will demonstrate how the Technical Guidelines on email authentication and secure transport can be implemented effectively. SPF, DKIM, DMARC, DNSSEC, DANE, TLS and MTA-STS will be translated into a concrete operational action plan.
The focus will be on fragmented domain portfolios, unknown third-party senders, legacy systems, deliverability risks and unclear responsibilities. Practical examples will demonstrate how governance can be established, progress made measurable and secure email communication permanently embedded in the security architecture. Organisations’ own domains strengthen control over sender identities and their ability to act independently in the digital sphere. The session will conclude with a concrete 90-day action plan for implementation.
- 16:00
- Break
- 16:30
-
From Detection to Disruption: Strengthening Cyber Resilience against DNS Abuse
Speakers will be announced shortly.
The discussion will be held in English.
More about this session
Show less
How can collaboration within the DNS and Internet infrastructure ecosystem be improved so that security intelligence can be translated more quickly into effective and legally compliant measures?Phishing, malware, botnets and other cyberattacks exploit a complex interplay of domains, DNS services, hosting platforms and compromised systems. Detection alone is therefore not enough: what is needed is robust data, actionable intelligence, clear responsibilities and rapid collaboration between security teams, CERTs, registrars, registries, hosting providers and the international DNS community. A current situation report from the eco initiative topDNS shows how patterns of abuse, attack duration and countermeasures are evolving.
The discussion will trace the entire response chain, from the first security signal to the coordinated disruption of criminal infrastructure. The focus will be on verifying reports, legally compliant and effective interventions and cross-border escalation procedures. The session will demonstrate how DNS intelligence and collaboration at the infrastructure level can be systematically integrated into incident response, risk management and cyber resilience.
- 17:30
- Networking
SPRECHER & HOSTS
CTO
Hornetsecurity Group
Corporate Communications
Link11 GmbH
Co-founder, Global Services
noris network AG
Senior Director, Global Services
Mapp Digital Services
Head of Testing Labs / Management Board
Founding Director of the Institute for AI Safety and Security
German Aerospace Center (DLR)
Vice President of Domains, Tucows
Managing Director Frankfurt
Global Switch
Strategy Director
cyberintelligence.institute
Vice President, Stakeholder Engagement & Managing Director, Europe
ICANN Org
Board member for IT Security
eco – Association of the Internet Industry
Founder
Pursche Tactical Consulting & Communications
Managing Director, Rickert Rechtsanwaltsgesellschaft mbH
Global Group General Counsel, Leaseweb
LOCATION
NürnbergMesse GmbH
Messezentrum 1
90471 Nuremberg
Germany
REGISTRATION
As part of the eco network, you can get tickets for €500 instead of €1,500 by using the code "itsa26eco500".
The Congress Ticket includes both attendance at the Internet Security Days @ it-sa 2026 and entry to it-sa. This turns a single day at the conference into an opportunity to experience the most important cybersecurity topics, providers and industry players all in one place..
Places are limited. Be there when the Internet Security Days take place at it-sa for the first time.
Subscribe here to the dotmagazine monthly newsletter with links to articles from dotmagazine and eco news and events.
HOSTS