
UK & Ireland CISO Community
Executive Summit
18 October 2023 | The Landmark London
18 October 2023
The Landmark London
Collaborate with your peers
Get together with UK & Ireland's top CISOs to tackle shared business challenges and critical priorities facing your role today. Participate in this one-day, local program with peer-driven topics and interactive discussions with your true C-level peers.
Join your peers to discuss the most critical issues impacting CISOs today:
Securing AI, Automation and New Technology
Building Operating Models that Foster Agility and Security by Design
Strengthening Cyber Risk's Role as a Driver for Enterprise Decision Making
UK & Ireland CISO Governing Body
The Governing Body Co-Chairs shape the summit agenda, ensuring that all content is driven By CISOs, For CISOs®.
Governing Body Co-Chairs

Jared Carstensen
CRH
CISO

Paula Kershaw
Barclays
MD CCO, Cyber & Resilience

Sarah Lawson
University College London
CISO

Ewa Pilat
DWS Group
Group CISO

Helen Rabe
BBC
CISO

Yolande Young
BUPA
CISO
What to Expect
Agenda
08:15 - 09:00 Registration & Breakfast
09:00 - 09:45 Keynote
What's Next for the CISO Role — Evolution or Revolution?

Naina Bhattacharya
Group CISO
Danone
Complex, high-pressure and stressful. Three words that many CISOs use to describe their role in improving their organisation's security posture. As the pace of change ever quickens, it's vital to question what the role of the modern CISO should look like, and if the role can be sustained under these current demands. Can you remain productive at this level of pressure for the next 5, 10, or even 20 years? Should the CISO be on the management board, moving to the ‘proper C-suite’? What skills are you missing for the next step? In this keynote address, Naina Bhattacharya Group CISO at Danone will explore these essential questions.
Join this keynote where Naina will discuss:
- CISO as a technologist — where should the CISO focus be spent on, technology or management?
- CISO as a business enabler — how is the role evolving into a key business contributor and leader within the business?
- CISO as a storyteller — how can the CISO use storytelling skills to be seen as a thought leader and innovator?
09:45 - 10:00 Break
10:00 - 10:45 Breakout Session
Checking in on Your Operating Model — A CISO Deep Dive

Manish Chandela
Group CISO
Sportradar

Tammy Archer
CISO
Inchcape

Douglas Weekes
CISO and Director of Data Governance
Sainsbury's
As enterprises rapidly accelerate their digital initiatives, CISOs are tasked with striking a delicate balance between implementing the right structures and strategies to safeguard your organisation's assets and delivering services and applications faster than ever before. Join this interactive session for a conversation among peers, where you’ll share insights on the rationale behind your operating models and explore how you can leverage your unique perspective and expertise to drive innovation and secure your organisation's future.
Join this session to discover:
- Sharing how you are evolving your operating model to deliver better speed, agility and security while optimising cost savings
- Assessing how your business unit may evolve in line with new technological innovations
- Positioning your team as security advocates and demonstrating business value
10:00 - 10:45 Breakout Session
Navigating Compliance, Resilience, and Cybersecurity — Strategies for Convergence
Hosted by Proofpoint

Adenike Cosgrove
VP, Marketing EMEA
Proofpoint

Benedict Olaoya
CISO
SGN
Compliance vs. security. Compliance and security. The dichotomy between compliance and security persists, yet their convergence remains a strategic imperative and has never been more paramount. Amid the time invested in regulatory engagement, the perception that compliance drives security strategies gains prominence. Compliance forms a baseline but as the threat landscape continues to evolve at an ever-increasing pace, we must convince the board to continue to invest beyond the baseline.
In this session, Benedict Olaoya, (CISO, SGN) and Adenike Cosgrove (VP EMEA Marketing, Proofpoint) will delve into the symbiotic relationship—the dance—between cyber resilience, regulatory compliance, and continued investment once compliance goals are met.
Join this session to:
- Explore the intricate relationship between compliance and cyber resilience — fortifying your organisation's defences against emerging threats
- Examine how compliance obligations can enhance proactive security change
- Discuss methodologies and approaches to negotiating with the board to secure security investments
10:00 - 10:45 Executive Boardroom
How is Third-Party Risk Evolving?
Hosted by RiskRecon, a Mastercard Company

Jason Huggett
Regional Director
RiskRecon - A MasterCard Company

Stuart Seymour
Director of Security (Group CISO and CSO)
Virgin Media O2

Simon Langley
CISO
ASDA
Third-Party Risk remains a key priority for CISOs globally, as dependence on third-party services continues to escalate. In today's age of perpetual digital transformation, organisations are heavily reliant on third-party services. However, given the escalating frequency of breaches among third parties, it is crucial to evaluate how this risk is evolving and for CISOs to stay ahead of the threat curve.
Join this session to discuss:
- Assessing how the Third-Party Risk landscape is developing
- Discussing methods for CISOs to better collaborate on how vetting suppliers
- Debating who should be on the hook for a breach, where should the responsibility fall
10:00 - 10:45 Executive Boardroom
The CISO as a Savvy Board Communicator

Ash Hunt
Global CISO
Apex Group

Charl Brits
Group CISO
Laing O'Rourke

Toks Oladuti
Global CISO
Dentons
Translating the organisation's cybersecurity posture to the board can be a catalyst in improving organisational resilience and building strong rapport. How do you communicate security initiatives clearly when the stakes are high?
Join this session to discuss:
- Leveraging your expertise to build trust
- Demystifying cybersecurity spending
- Translating cybersecurity into actionable language
10:45 - 11:45 Networking Break
10:55 - 11:40 Peer-to-Peer Meetings
Peer-to-Peer Meetings
Connect with like-minded peers in a one-on-one setting through Evanta’s Peer-to-Peer Meetings. You will be matched with peers in your community based on your shared interests and priorities.
11:45 - 12:30 Breakout Session
Securing Your Organisation — A CISO's Perspective on NIST

Derek Cheng
CISO
Deliveroo
The Cybersecurity Framework developed by the National Institute of Standards and Technology (NIST) is an essential tool for managing cyber risks. It offers a comprehensive approach that helps organisations identify, assess, and handle cybersecurity threats more effectively. Despite its widespread use, the framework is often overlooked and deserves further exploration, particularly from the perspective of a seasoned CISO like Derek Cheng, who has been implementing it for many years. In this session, Derek Cheng, the CISO at Deliveroo, will share his insights into the framework's strengths and weaknesses.
Join Derek, where he’ll unpack the NIST Cybersecurity Framework:
- Lessons learned from NIST adoption — what you need to be cognisant of when implementing NIST
- Considering why NIST may be the best framework for you
- Addressing NIST’s shortcomings — managing complexity and budget constraints
11:45 - 12:30 Breakout Session
Challenging the Rules of Security — There Has to be a Better Way to Protect the Enterprise!
Hosted by Google Chrome

Oliver Madden
Chrome Browser Enterprise Lead
Google Chrome Enterprise

Reza Salari
Head of Business Information Security (BISO)
Pacific Life Re

Dan Burns
Head of Information Security
Next
The threats are constantly growing and so are the costs. Protecting endpoints is one of the many challenges faced by CISOs. Faced with continuously evolving attacks, CISOs must now escape from this quagmire and make game-changing improvements in cybersecurity and administration to prevent cyberattacks and ransomware. Every endpoint could provide an attacker access to the corporate network, but IT organisations today can capitalise on several layers of control to ensure stronger security and operations, whilst ensuring productivity is not compromised. Join this session to discuss:
- Rethinking your capabilities for strengthening endpoint security and simplifying endpoint management
- Looking at defence in-depth, securing devices as well as connections, and creating innovative multi-layered defences at different levels
- Striking the balance between effectively protecting the enterprise without compromising the overall productivity of users
11:45 - 12:30 Executive Boardroom
A CISO's Guide to Shifting Your AppSec Focus — Advancing Your Developer's Experience With AppSec
Hosted by Checkmarx

Fabiano Lima
Head of Global Sales
Checkmarx

Ian Snelling
Senior Security Leader
Skipton Building Society
Effective application security (AppSec) requires developers to play a critical role. However, they often face the challenge of balancing productivity with security and resisting top-down solutions. Not understanding this can create friction, and lead to a negative impact on developer experience, engagement and overall output. To establish a long-term successful AppSec framework, it is crucial to engage with developers early and frequently.
Join this Executive Boardroom and leave with actionable insights on:
- Best practices on improving collaboration between DevOps, Security and Technology teams — accelerating secure applications and transformations
- Case studies on improving developer experience and engagement to maximise the value of AppSec
- Recasting AppSec teams as security facilitators and maintaining oversight of the developer teams’ security efforts
11:45 - 12:30 Executive Boardroom
Securing and Driving the Business – The Power of Security Operations

Eduardo Mastranza
VP, TM EMEA SRM Executive Partners
Gartner

Soraya Viloria-Montes de Oca
Group Information Security Officer
Harvey Nichols

Paul Key
CISO & VP Information Security
Smith & Nephew
Sure, your SOC’s strength is the make-or-break factor when it comes to threat detection, but that’s simply the beginning. With the right security operations culture, you can increase efficiencies and, through that, drive the business forward.
Join your C-level peers for:
- An interactive conversation on winning security operations strategies
- A chance to measure your security operations program against those of your peers
- A proactive approach to keeping your business ahead and risk free
Apply to Participate
Apply to participate in the UK & Ireland CISO Community Executive Summit.
Gartner facilitates exclusive, C-level communities by personally qualifying and understanding the priorities, challenges and interests of each member.
Our selective approach maintains the high quality of the network and ensures top-level discussions with peers from the world’s leading organizations.
Each application will be reviewed, and once your participation is confirmed, you will have access to year-round community programs.
Location
Venue & Accommodation
The Landmark LondonParking & Transportation
Closest Railway & Underground Station:
London Marylebone Railway & Underground Station Approximately 0.1 miles.
Baker street closest underground station.
Travelling by car:
Please note the hotel does not have an onsite car park but there is close NCP car parks available in the area.
A block of rooms has been reserved at the The Landmark London at a reduced conference rate. Reservations should be made online or by calling 020 7631 8000. Please mention Evanta to ensure the appropriate room rate.
Deadline to book using the discounted room rate of £409 GBP (plus tax) is 25 September 2023.
Community Programme Manager
For inquiries related to this community, please reach out to your dedicated contact.
Luis Arango Abello
Senior Community Programme Manager
+44 (0)1784 267 880
luis.arangoabello@gartner.com