Cyber Security in Financial Services Summit 2025

Now in its 8th year, the renowned, Cyber Security in Financial Services Summit continues to be the go-to event in the BFSI sector and enables attendees to form many new meaningful business relations.

27

November

  • The Minster Building London
  • Free
  • Why attend?
  • Agenda
  • Speakers
  • Plan Your Visit
  • Event Gallery
  • Sponsors
  • Media Centre
  • Contact Us

Why attend?

Highlights of the 2024 Cyber Security event

Agenda

  • 27 Nov 2025
Expand All

8 AM

Networking and registration

8:55 AM

Chair’s opening remarks

Speakers

Jon Bernstein
Freelance Writer, Moderator and Digital Media Consultant

9 AM

Regulatory expectations in a digitally-driven threat landscape – FCA’s perspective on cyber resilience

  • Key cyber resilience outputs from the FCA in 2025 and what they mean for the financial sector
  • The growing importance of collective action to strengthen sector-wide resilience
  • Emerging technologies reshaping the cyber landscape, including AI and quantum
  • The evolving role of boards in cyber oversight, accountability, and resilience governance

Speakers

Luke Vile
Cyber Technical Specialist, Technology, Resilience and Cyber, Specialist Supervision, FCA

9:20 AM

Keynote Presentation – Inside the Inbox: Real Attacks Hitting Financial Services in 2025

Attackers are bypassing legacy tools with business email compromise (BEC), account takeover (ATO), QR code phishing, and OAuth consent scams at increasing scale. We will share anonymized, recent cases from financial services environments, including how a global firm saw advanced attacks bypass a traditional secure email gateway and what actually stopped them. Co-presented by Abnormal AI and BlueFort, attendees leave with a practical playbook: the signals to look for, the controls that work, and how to achieve time-to-value without added friction.

Speakers

John Flatley
Solutions Engineer, Abnormal AI, Abnormal.ai
Josh Neame
Chief Technology Officer, BlueFort Security Ltd

9:45 AM

PANEL DISCUSSION: What’s keeping CISOs awake in 2025?

As financial institutions navigate an era defined by AI-driven change, evolving regulation, and increasingly complex threats, this panel explores the hopes, expectations, and fears of security leaders as they look ahead to 2026.

Key discussion points include:

  • The evolving role of GenAI in cybersecurity and its influence on threat detection
  • Identity, social engineering, and the rise of behavioural anomaly detection
  • Balancing risk, regulation, and reputation across financial services
  • Defining best practice for modern security operations

Moderator: Jon Bernstein, Freelance Writer, Moderator and Digital Media Consultant

Speakers

Jon Bernstein
Freelance Writer, Moderator and Digital Media Consultant
Adrian Warman
Former Head of Security Operations at Ministry of Justice UK, Senior Cyber Threat Intelligence Analyst, Bournemouth University
Jamie Brummell
Founder and CTO, Socura
Darren Swift
Security Sales Engineer FSI, Google Cloud
Nicole Fowler
CISO, Bank of Ireland

10:30 AM

DRAGONS DEN

A dynamic quick-fire session where selected innovators have one minute each to present a cutting-edge idea or solution shaping the future of cybersecurity in financial services.

This high-energy segment offers delegates a rapid insight into emerging technologies, new approaches, and creative thinking driving progress across the sector setting the stage for deeper conversations during the networking break that follows.

Speakers

Michael Brooks
Senior Enterprise Account Executive, Abnormal AI, Abnormal.ai
Chris Weston
Co-Founder and Chief Revenue Officer, Amberwolf
Ryan Sheldrake
Field CTO, Chainguard
Justin Kuruvilla
Chief Cyber Security Strategist at Risk Ledger
Dele Adu
Business Development Manager, NormCyber
Colin Makin
Spector ops
Neil Langridge
Product Marketing Manager, Cato Networks (Wavenet Partner)
Ryad Jawaheer
Senior Solutions Architect, eSentire
Rodney Jess
Account Director at Edgescan
Jamie Brummell
Founder and CTO, Socura
Stuart Durrant
Regional Manager, Tenable

10:40 AM

Networking coffee break

11:10 AM

Managing risk in a shared responsibility model

As financial institutions deepen their reliance on cloud infrastructure, managing cyber risk becomes a shared responsibility, but where does the provider’s role end and the institution’s begin? This discussion explores how to cut through the noise of data and alerts to focus on what truly matters for business resilience.

  • Too much data, not enough clarity and how that overload hides real financial and operational exposure.
  • Cutting noise down to the risks that actually matter to revenue, operations, and regulators.
  • Exposing the unknown estate shadow IT, shadow APIs, and forgotten cloud services driving unseen risk.
  • Turning thousands of technical “criticals” into one clear, defensible, business-level risk picture.
  • Measuring what truly improves resilience: reduced exposure, faster remediation, better prioritisation, clearer audit trails.

Moderator: Jon Bernstein, Freelance Writer, Moderator and Digital Media Consultant

Speakers

Jon Bernstein
Freelance Writer, Moderator and Digital Media Consultant
Joel Barnes
Senior Director EMEA - Tenable
Nicole Fowler
CISO, Bank of Ireland

11:40 AM

The Confidence Illusion: Rethinking How We Assess Technical Risk

The financial services market has driven major security improvements through frameworks such as CBEST and TIBER, with its behaviour helping raise standards across other sectors. But does confidence still outpace reality? This session explores the blind spots that remain, including fragile supply chains, hidden attack paths, and vendor risks, while challenging what resilience and true assurance mean in complex, real-world environments

Speakers

Julian Storr
Co-Founder, AmberWolf

12:05 PM

AI Security: Between Science Fiction and Reality

  • Understanding how to frame AI security – novel challenges, similarities, and differences with traditional cybersecurity
  • Practical insights for designing safer, more trustworthy AI systems

Speakers

Ioan Nascu
GenAI Security Assurance, VP, Citi

12:25 PM

Untangling the Supply Chain Problem in Financial Services

  • Explore how systemic supply chain risks are reshaping the financial services landscape, from corporate dependencies to software and logistical vulnerabilities.
  • Understand why traditional TPRM no longer protects interconnected financial ecosystems, and how collaboration is becoming the new resilience strategy.
  • Hear real-world insights from government and financial communities on tackling concentration risk and achieving shared visibility across suppliers.
  • Discover how network-based
  •  security models can strengthen regulatory compliance and operational resilience under frameworks like DORA.
  • Learn how to move beyond fragmented risk management and Defend-as-One against evolving third-party threats.

 

Speakers

Justin Kuruvilla
Chief Cyber Security Strategist at Risk Ledger

12:45 PM

PANEL DISCUSSION: Navigating the regulatory maze – global compliance for cybersecurity leaders

• Overview of key cybersecurity regulations
• Managing compliance across jurisdictions
• How to be prepared for evolving data privacy standards?

 

Speakers

Jon Bernstein
Freelance Writer, Moderator and Digital Media Consultant
Sonia Luthra
Managing Director, UK Data Protection Officer & Head of Data Protection, Société Générale
Josh Neame
Chief Technology Officer, BlueFort Security Ltd

1:15 PM

Lunch

2:10 PM

The Future of Digital Risk Protection in Financial Services

As financial services firms continue to digitise, their exposure now stretches far beyond the traditional perimeter. From the dark web to domain impersonation and unpatched vulnerabilities, risks can emerge anywhere your brand or data appear online.

This session explores how organisations can harness diverse intelligence sources – including the dark web – to uncover hidden risks and strengthen their digital resilience. Through real-world examples, we’ll show how Digital Risk Protection (DRP) turns threat data into clear, actionable insight that helps financial institutions stay ahead of attackers

Speakers

Paul Wilford
Solutions Consultant, NormCyber

2:30 PM

How to Sweep Vulnerabilities under the Rug – How to Properly manage vulnerabilities and effectively prioritize remediation

Edgescan delivers risk-prioritized vulnerability intelligence across applications, APIs, and infrastructure with manual validation baked in.

Let’s take a step back to some fundamentals.

  • A reality check and recap on the basics (Find, Prioritize, Fix).
  • How to deal with “Too Many Risk Scores”. Edgescan’s effort to simplify an approach to Risk.
  • Asset Context - how it plays into Risk and how AI and Metadata can help vulnerability prioritization.
  • How to quantify Risk and present options not just problems.

Speakers

Keith Geraghty
Director of Solutions Engineering, Edgescan

2:40 PM

Beyond the Perimeter: Proactive threat hunting for finance leaders

Financial organisations face relentless and increasingly sophisticated cyber threats. Reactive security measures aren’t enough to stop them. In this tech spotlight, Ryad Jawaheer from eSentire explains how finance IT leaders can stay ahead of attackers through managed detection and response (MDR), continuous threat management, and active threat hunting.

 

You’ll hear how eSentire’s team of experts detects and stops attacks in real time, helping financial institutions protect critical systems, meet regulatory demands, and strengthen resilience against disruption.

 

Speakers

Ryad Jawaheer
Senior Solutions Architect, eSentire

2:50 PM

Cybersecurity in Financial Services: What Does the 2026 Landscape Look Like?

This forward-looking session explores how cybersecurity in financial services will evolve over the next 12–18 months. Drawing on GlobalData’s latest research, it will examine: 

  • The adoption and security implications of emerging technologies – including cloud, AI, 5G, IoT, and quantum computing.
  • How evolving business models and ecosystems in banking and financial services are reshaping cyber risk.
  • The balance between innovation, risk, and operational resilience in an increasingly complex digital environment.

Speakers

David Bicknell
Principal Analyst, Thematic Research, GlobalData

3:10 PM

Secure by Default: Why the Future of Open Source Demands it

  • The real cost of “free” software and the security gaps it creates
  • How technical debt in open-source stacks becomes a growing risk for financial institutions
  • Why traditional “shift left” approaches are no longer enough
  • What a secure-by-default model looks like and what organisations should expect from their tools and teams

Speakers

Ryan Sheldrake
Field CTO, Chainguard

3:35 PM

The Extended Enterprise: managing cybersecurity risk beyond your walls

This presentation provides a strategic blueprint for guarding the digital gates organisations no longer directly control, a necessity given the increasing prevalence and systemic nature of third party cyber threats.

●      Systemic threat requires a new architecture.

●      Single vendor compromise impacts thousands.

●      DORA mandates shared vendor accountability.

●      Need Visibility, Collaboration, Automation.

●      Be the architect, not the gatekeeper.

Speakers

Federico Iaschi
Information Security Director, Starling Bank

3:55 PM

Networking coffee break

4:15 PM

Lessons on Identity – the new battleground for enterprise security

In recent years, some of the most damaging cyberattacks in Europe share a common thread – identity. As traditional defences strengthen, attackers have shifted tactics, moving away from malware and exploits toward abusing legitimate credentials, permissions, and trust relationships within enterprise environments.

This session considers how attackers use identities to navigate industry-standard defences. We’ll explore the anatomy of an identity-based attack – from initial access through to organisational-wide takeover – and highlight recurring patterns seen across European enterprises.

Today’s breaches aren’t the result of poor security but of unseen complexity. Hidden identity attack paths buried deep in Active Directory and Entra ID provide adversaries with millions of routes to critical systems.

We’ll conclude with a strategy to move from reactive defence to proactive identity risk management. By continuously mapping and removing identity attack paths, organisations can eliminate the bridges adversaries depend on.

Speakers

Mark Wilson
Solutions Engineer, SpecterOps
Adam Chester
Services Architect and Red Teamer, SpecterOps

4:35 PM

The cost of cyber complexity

Description: The session explores how organisations need to manage cyber risk and complexity. We’ll explore the current landscape, and how digital transformation, business pressures and compliance requirements are driving ever more complex networks. We’ll look at the cost and impact of that complexity, and then how organisations can consolidate their technology stack and simplify their security through unified platforms to solve those challenges, including exploring some real world customer stories.

Speakers

Neil Langridge
Product Marketing Manager, Cato Networks (Wavenet Partner)

4:50 PM

Interview: AI, Governance, and Cyber Security

  • Designing effective governance frameworks  from policy to implementation  for institutions at different stages of maturity
  • How security strategy, governance thinking and policy development is adapting to Ai functionality across major financial institutions
  • Practical lessons from early internal adoption, including colleague-facing change, operational readiness and evolving approaches to risk assessment
  • The key concerns shared by regulators and large institutions, such as safety, accountability, model transparency and systemic risk
  • The organisational impact of AI, from workforce considerations to skills, decision-making processes and oversight structures
  • The balance between innovation and regulatory expectations, and what responsible adoption looks like in real operational environments

Speakers

Dr Deeph Chana
Director, Institute for Security Science and Technology, Imperial College London
Dr Claire Greene
Senior Policy Technical Specialist, Bank of England
Jennifer Holmes
Colleague Journey Lead - Natwest Group

5:20 PM

Chair’s closing remarks followed by networking drinks

Speakers

Jon Bernstein
Freelance Writer, Moderator and Digital Media Consultant

Speakers

Select a speaker to learn more

Back
Sonia Luthra
Managing Director, UK Data Protection Officer & Head of Data Protection, Société Générale

Session Details:

PANEL DISCUSSION: Navigating the regulatory maze – global compliance for cybersecurity leaders

2025-11-27, 12:45 PM

View In Agenda
Next speaker
Back
Ryad Jawaheer
Senior Solutions Architect, eSentire

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

Session Details:

Beyond the Perimeter: Proactive threat hunting for finance leaders

2025-11-27, 2:40 PM

View In Agenda
Next speaker
Back
Ioan Nascu
GenAI Security Assurance, VP, Citi

Session Details:

AI Security: Between Science Fiction and Reality

2025-11-27, 12:05 PM

View In Agenda
Next speaker
Back
Adrian Warman
Former Head of Security Operations at Ministry of Justice UK, Senior Cyber Threat Intelligence Analyst, Bournemouth University

Session Details:

PANEL DISCUSSION: What’s keeping CISOs awake in 2025?

2025-11-27, 9:45 AM

View In Agenda
Next speaker
Back
Federico Iaschi
Information Security Director, Starling Bank

Federico Iaschi is a multilingual Information Security Director at Starling Bank, with over 20 years of experience in both the private and public sectors. He specialises in cyber security resilience and observability, focusing on building robust practices to proactively identify and mitigate risks across diverse systems. As a recognised speaker and author, Federico holds various certifications, including CISSP, CISM, and CCISO, highlighting his deep expertise in information security and risk management. His strategic insights are essential for navigating the evolving landscape of cybersecurity and resilience in the financial services sector.

Session Details:

The Extended Enterprise: managing cybersecurity risk beyond your walls

2025-11-27, 3:35 PM

View In Agenda
Next speaker
Back
Darren Swift
Security Sales Engineer FSI, Google Cloud

Darren Swift is a Senior Customer Engineer at Google Cloud Security, based in Manchester, United Kingdom. With a 17-year career as a highly technical pre-sales professional, he has a proven track record of establishing and growing the UKI presence for emerging technologies at companies including Google, Rubrik, Zerto, EMC, and Autodesk.

Session Details:

PANEL DISCUSSION: What’s keeping CISOs awake in 2025?

2025-11-27, 9:45 AM

View In Agenda
Next speaker
Back
Jamie Brummell
Founder and CTO, Socura

Jamie is a cyber security professional with more than two decades of experience in the sector. As CTO and Co-founder at Socura, he oversees the technology architecture of Socura’s Managed Detection and Response service. He works closely with security teams across industries to continuously enhance security operations and achieve outcomes at scale.

Session Details:

PANEL DISCUSSION: What’s keeping CISOs awake in 2025?

2025-11-27, 9:45 AM

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

View In Agenda
Next speaker
Back
Keith Geraghty
Director of Solutions Engineering, Edgescan

As Senior Solutions Director at Edgescan, Keith plays a key role throughout the entire customer journey—from leading the technical side of business development to ensuring measurable value is delivered long after implementation. With over a decade of experience in technical security roles, including penetration testing, Keith now focuses on helping clients solve complex security challenges and maximizing the impact of the Edgescan platform.

When he’s not identifying and helping to mitigate vulnerabilities in systems, you’ll find him on the mats, trading exploits for takedowns with his sparring partners.

Session Details:

How to Sweep Vulnerabilities under the Rug – How to Properly manage vulnerabilities and effectively prioritize remediation

2025-11-27, 2:30 PM

View In Agenda
Next speaker
Back
Luke Vile
Cyber Technical Specialist, Technology, Resilience and Cyber, Specialist Supervision, FCA

Session Details:

Regulatory expectations in a digitally-driven threat landscape – FCA’s perspective on cyber resilience

2025-11-27, 9:00 AM

View In Agenda
Next speaker
Back
Julian Storr
Co-Founder, AmberWolf

Julian Storr is a Director and co-founder at AmberWolf, a specialist security consultancy helping organisations understand and manage real-world technical risk. With over a decade of experience in offensive and assurance roles, Julian was one of the first to hold dual CREST CCSAS and CCSAM certifications, enabling him to lead and deliver more than 18 regulatory red-team engagements under frameworks such as CBEST, TIBER, and ICAST for major financial and telecoms firms. Today, Julian focuses on helping clients bridge the gap between testing, detection, and true resilience.

Session Details:

The Confidence Illusion: Rethinking How We Assess Technical Risk

2025-11-27, 11:40 AM

View In Agenda
Next speaker
Back
Paul Wilford
Solutions Consultant, NormCyber

Paul Wilford has 25 years of experience in the IT industry, 10 of which have been in cyber security; in a mixture of detection & response and security posture analysis roles. He is now a Solutions Consultant for NormCyber - an award-winning provider of security operations.

Session Details:

The Future of Digital Risk Protection in Financial Services

2025-11-27, 2:10 PM

View In Agenda
Next speaker
Back
David Bicknell
Principal Analyst, Thematic Research, GlobalData

David Bicknell has over 30 years’ experience in writing about and analysing the technology sector, both from the vendor and the user perspective, both in the UK and the US. His career in technology journalism and analysis has included detailed research into IT projects and he has co-authored a book, ‘Crash’, which explored why and how IT projects go wrong. He has also co-authored a novel on the life of computer pioneer Charles Babbage. Prior to joining Thematic Research, David spent six years editing a GlobalData title exploring the use of technology in the UK public sector. He is currently also studying part-time for an Undergraduate Certificate in the History of Art at the University of Oxford.

Session Details:

Cybersecurity in Financial Services: What Does the 2026 Landscape Look Like?

2025-11-27, 2:50 PM

View In Agenda
Next speaker
Back
Jon Bernstein
Freelance Writer, Moderator and Digital Media Consultant

Session Details:

Chair’s opening remarks

2025-11-27, 8:55 AM

Session Details:

PANEL DISCUSSION: What’s keeping CISOs awake in 2025?

2025-11-27, 9:45 AM

Session Details:

Managing risk in a shared responsibility model

2025-11-27, 11:10 AM

Session Details:

PANEL DISCUSSION: Navigating the regulatory maze – global compliance for cybersecurity leaders

2025-11-27, 12:45 PM

Session Details:

Chair’s closing remarks followed by networking drinks

2025-11-27, 5:20 PM

View In Agenda
Next speaker
Back
Rodney Jess
Account Director at Edgescan

As Account Director at Edgescan, Rodney partners with organizations to strengthen their security posture, reduce risk, and simplify vulnerability management. He focuses on building trusted, long-term relationships and helping clients achieve measurable improvements in their cybersecurity resilience.

A petrol head at heart, Rodney can often be found around anything with two or four wheels and speed. When not working or enjoying motorsport, he’s a keen cyclist who values the challenge and freedom of the open road.

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

View In Agenda
Next speaker
Back
Justin Kuruvilla
Chief Cyber Security Strategist at Risk Ledger

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

Session Details:

Untangling the Supply Chain Problem in Financial Services

2025-11-27, 12:25 PM

View In Agenda
Next speaker
Back
Adam Chester
Services Architect and Red Teamer, SpecterOps

Session Details:

Lessons on Identity – the new battleground for enterprise security

2025-11-27, 4:15 PM

View In Agenda
Next speaker
Back
Mark Wilson
Solutions Engineer, SpecterOps

Session Details:

Lessons on Identity – the new battleground for enterprise security

2025-11-27, 4:15 PM

View In Agenda
Next speaker
Back
Nicole Fowler
CISO, Bank of Ireland

Session Details:

PANEL DISCUSSION: What’s keeping CISOs awake in 2025?

2025-11-27, 9:45 AM

Session Details:

Managing risk in a shared responsibility model

2025-11-27, 11:10 AM

View In Agenda
Next speaker
Back
Chris Weston
Co-Founder and Chief Revenue Officer, Amberwolf

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

View In Agenda
Next speaker
Back
Ryan Sheldrake
Field CTO, Chainguard

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

Session Details:

Secure by Default: Why the Future of Open Source Demands it

2025-11-27, 3:10 PM

View In Agenda
Next speaker
Back
Dele Adu
Business Development Manager, NormCyber

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

View In Agenda
Next speaker
Back
Colin Makin
Spector ops

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

View In Agenda
Next speaker
Back
Neil Langridge
Product Marketing Manager, Cato Networks (Wavenet Partner)

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

Session Details:

The cost of cyber complexity

2025-11-27, 4:35 PM

View In Agenda
Next speaker
Back
Dr Deeph Chana
Director, Institute for Security Science and Technology, Imperial College London

Session Details:

Interview: AI, Governance, and Cyber Security

2025-11-27, 4:50 PM

View In Agenda
Next speaker
Back
Stuart Durrant
Regional Manager, Tenable

Session Details:

DRAGONS DEN

2025-11-27, 10:30 AM

View In Agenda
Next speaker
Back
Dr Claire Greene
Senior Policy Technical Specialist, Bank of England

Dr Claire Greene is a Senior Policy Technical Specialist at the Bank of England’s Prudential Regulation Authority, where she develops policy on ICT and cyber resilience. Previously, she worked in UK Government on the implementation of the Network and Information Systems Regulations, focusing on strengthening national cyber security. Claire brings extensive experience in financial services regulation and public policy. She is a CISSP-certified professional, a Chartered Accountant and a Fellow of the ICAEW.

Session Details:

Interview: AI, Governance, and Cyber Security

2025-11-27, 4:50 PM

View In Agenda
Next speaker
Back
Jennifer Holmes
Colleague Journey Lead - Natwest Group

Session Details:

Interview: AI, Governance, and Cyber Security

2025-11-27, 4:50 PM

View In Agenda
Next speaker

Plan Your Visit

Venue

The Minster Building, 21 Mincing Ln., London EC3R 7AG

Sponsors

Select a sponsor to learn more

Headline Sponsors

Gold Sponsors

Silver Sponsors

Bronze Sponsor

Tech Spotlight Sponsors

Panel Sponsor

Exhibitors

Co-Sponsor

Partners

Media Centre

Knowledge Partners

Become a media partner today

 

 

Highlights of the 2024 Cyber Security event

Enquiry

Contact Us

SPONSORSHIP OPPORTUNITIES

Nadine Edwards

+44 (0)204 540 7672

SPEAKING OPPORTUNITIES

Carlos Fernandes

Marketing Enquiry

Kellee Halliburton

SPONSORSHIP OPPORTUNITIES

 

Nadine Edwards:

Commercial Director Events


+44 0204 540 7672

SPEAKER OPPORTUNITIES

 

Emily Martyr

Head of Event Content