11-13 March 2024 | Brussels Marriott Hotel Grand Place

Conference Agenda 2024

Monday 11 March

Day 1

08:00-09:00 Registration

Foyer

09:00-17:00 Special Focus Day

The EU Cyber Acts Conference Starts with Two Special-Focus Full-Day Events

Produced with the support of ISO/IEC JTC 1/SC 27/WG 3, focused on future cryptographic compliance requirements. Complete Agenda

New for 2024. Focused on the global development of cybersecurity certification frameworks for AI systems. Complete Agenda

Tuesday 12 March

Day 2

08:00-09:00 Registration

Foyer

09:00-10:10 Plenary Keynote Session (P10)

Ballroom AB

09:00 Introduction and Welcome (P10a) Wouter Slegers, CEO, TrustCB, Netherlands

09:10 Industry Keynote (P10b) Wolfgang Steinbauer, Senior VP, Head of Crypto and Security, Austria

09:40 An Update on ENISA Certification Activities (P10c) Philippe Blot, Head of Sector Certification, European Union Agency for Cybersecurity (ENISA), Greece

10:10-10:50 Networking Break in Exhibits

Foyer

10:50-12:20 Track Sessions

Ballroom A

Cloud Frameworks (C11)
EUCS
Moderator: Dr. Igor Furgel, Head of Certification Body Deutsche Telekom Security GmbH, Germany

10:50 Panel Discussion: EU Cloud Service Certification (C11a) Leader: William Ochs, CSO / CCO & Global ISSM – Cisco SD-WAN / Cisco EMEA Cloud Certification Lead, Cisco, United States; Anders Jonson, Member ENISA AHWG EUCS, Founder & Senior Advisor, SecureAppbox, Sweden; Volkmar Lotz, Senior Manager and Chief Research Strategist, SAP, Germany [60MIN]


11:50 Certification of Cloud Services or IT Products: Results of Two Pilot Certification in EUCS Scheme and EUCC Scheme (C11c) Theresa Krüger, Certifier, Deutsche Telekom Security GmbH, Germany

Ballroom B

Public Policy (B11)
(Inter)national Policies
Moderator: Miguel Bañon, Independent Consultant, Convenor ISO/IEC JTC 1/SC 27/WG 3, Spain

10:50 The Regionalization of Cybersecurity Policies: The End to International Cybersecurity Standards? (B11a) Eloïse Ryon, Senior Manager, Europe Digital Policy, Schneider Electric, Belgium


11:20 The Intersection of US and EU Cybersecurity Requirements (B11b) Eric Crusius, Partner, Holland & Knight, United States


11:50 NIAP Addresses U.S. Executive Orders, Memorandums, and Policies: SBOM, Cloud, and Zero Trust (B11c) Jade Stewart, Portfolio Manager, NIAP, United States

12:30-13:30 Lunch in Exhibits

Foyer

13:30-15:00 Track Sessions

Ballroom A

Cloud Frameworks (C12)
Cloud and Software
Moderator: Dr. Igor Furgel, Head of Certification Body Deutsche Telekom Security GmbH, Germany

13:20 Common Criteria in the Cloud – Certification for IT Products No Longer in Your Server Room (C12a) Tyrone Stodart, Senior Principal Security Analyst, Oracle Corporation UK Ltd, United Kingdom


13:50 Improving Software Transparency on the Path to Supply Chain Risk Management (C12b) Jeff Schutt, Principal Security Engineer, Cisco, United States


14:20 TBA

Ballroom B

Standards and Certification (S12)
EUCC Implementation
Moderator: Petra Manche, Common Criteria Manager, Cisco, United Kingdom

13:20 Implementation of the EUCC Scheme in Germany: First Observations and the Way Forward (S12a) Klementina Geyer, Common Criteria Certification Expert, Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany; Fritz Bollmann, Head of Software Certification, Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany


13:50 TBA


14:20 Insights from Automated Large-Scale Analysis of Common Criteria Certificates (S12c) Adam Janovský, PhD Candidate, Masaryk University, Czechia

15:00-15:30 Networking Break in Exhibits

Foyer

15:30-17:30 Track Sessions

Ballroom A

IoT Challenges (I13)
IoT Tested in Practice
Moderator: Bret Jordan, Chief Security Strategist, Afero, United States

15:20 Delivering Trust at the Edge of the Edge (I13a) Stephane Di Vito, Senior Director and Lead Security Architect for Trusted Edge Solutions, Analog Devices, France; Debra Delise, VP of Security Business Unit, Analog Devices, United States


15:50 Scaling Security Testing for IoT Firmware (I13b) Hugues Thiebeauld, CEO, eShard, France


16:20 Charting the Course: Navigating Maritime Cybersecurity (I13c) Anna Prudnikova, Team Manager—Products Certifications, Secura, Netherlands


16:50 The Big Picture – Matching Regulations and Compliance Using Composition (I13d) Georg Stuetz, Head of IoT & Automotive Certification, NXP Semiconductors, Austria

Ballroom B

Standards and Certification (S13)
EUCC and CSA Discussions
Moderator: Reserved TBA

15:20 Panel Discussion: EU Cybersecurity Certification (EUCC) (S13a) Leader: Petra Manche, Common Criteria Manager, Cisco, United Kingdom [60MIN]


16:20 Panel Discussion: CSA Speed and Consistency (S13c) Leader: Gabor Hornyak, Head of Site & Process Certification, NXP Semiconductors, Hungary [60MIN]

17:20 Adjourn

18:30 Dine Around Brussels

Enjoy an informal group dinner at one of Brussel’s top restaurants with your EU Cyber Security Act colleagues on Tuesday, 12 March. This is an add-on to the conference registration. For an additional fee you can reserve your seat for a prix-fixe dinner at a group table. Reserve early—seating is limited. On site, you’ll meet your group at 18:30 at the conference registration desk and depart from there. 

Wednesday 13 March

Day 3

08:00-09:00 Coffee

Foyer

09:00-10:30 TRACK SESSIONS

Ballroom A

IoT Challenges (I20)
Industrial IoT
Moderator: Bret Jordan, Chief Security Strategist, Afero, United States

09:00 Cyber Security as an Opportunity for SMEs: How We Met the IEC 62443-4-1 Standard (I20a) Siegfried Müller, VP Advanced Technologies, Red Lion Europe GmbH (former MB connect line GmbH), Germany


09:30 Impact of the CRA on the SME Equipment Manufacturers in Europe: Experience and Lessons Learned (I20b) Salvador Trujillo, CEO, ORBIK Cybersecurity, Spain


10:00 EU Cyberresilience Act – A Boon in Die Tide (I20c) Meghana Pote, Senior Expert IEC 62443 Auditor & Trainer, Tüv Süd as Certification Body in Germany, Germany

Ballroom B

Standards and Certification (S20)
RED
Moderator: Miguel Bañon, Independent Consultant, Convenor ISO/IEC JTC 1/SC 27/WG 3, Spain 

09:00 RED Cybersecurity Requirements and Regulatory Landscape (S20a) Angelo D Amato, Lead Principal, UL Solutions, Netherlands


09:30 Panel Discussion on CRA & RED: Allies or Antagonists? (S20b) Leader: Tony Boswell, Senior Principal Consultant, CyTAL, United Kingdom [60MIN]

10:30-11:00 NETWORKING BREAK IN EXHIBITS

Foyer

11:00-12:30 Track Sessions

Ballroom A

IoT Challenges (I21)
Industrial IoT
Moderator: Reserved TBA

11:00 Creating New Requirements for Security Certification (I21a) Dan O’Loughlin, VP Engineering, Qualcomm, Germany


11:30 IoT Security – How SESIP Is Supporting Industries to Prepare for Incoming EU Legislation (I21b) Olivier Van Nieuwenhuyze, Vice Chair of the Board and Chair of the Security Task Force, GlobalPlatform, Belgium


12:00 Transforming Into a Secure-by-Design Company—Roadmap for Achieving CRA Compliance (I21c) Antti Tolvanen, Sales Director, Etteplan, Finland

Ballroom B

Public Policy (B21)
CRA Policy
Moderator: Arnaud Martin, Agoria, Belgium

11:00 The EU Assurance Paradigm: CRA Conformity Assessment Procedures and Presumption of Conformity with CSA (B21a) Jose Emilio Rico MartÍnez, Business Development and Strategy, DEKRA Testing and Certification S.A.U., Spain


11:30 Panel Discussion: EU Cyber Resilience Act (B21b) Leader: Alban Feraud, Board Member, Eurosmart, and Regulatory Affairs, Market & Business Development, IDEMIA, France; Roberto Cascella, Head Of Sector – Technology, Supply Chain & Strategic Autonomy, European Cyber Security Organisation (ECSO), Belgium [60MIN]

12:30-13:30 Lunch in Exhibits

Foyer

13:30-15:00 Track Sessions

Ballroom A

Public Policy (B22)
Policy Implications
Moderator: Matthias Intemann, Head of Certification, Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany

13:30 Fuzzing for Assurance and Certification – Lessons from Smart Meters (B22a) Tony Boswell, Senior Principal Consultant, CyTAL UK Ltd, United Kingdom


14:00 Separation of Duties: Evaluation vs Consulting (B22b) Marc Le Guin, Head of Evaluation Body IT Security, TÜV Informationstechnik GmbH, Germany


14:30 The Paradigm Shift in Patching Regulation – Upcoming EU Rules for Cybersecurity Patching (B22c) Lisa Rooij, PhD Researcher Regulation and Governance of Patching Security in Organizations , Tilburg University (TILT), Netherlands


15:00 European Cross-Border Cybersecurity Operations Collaboration through the Lens of the CACAO Standard (B22d) Vasileios Mavroeidis, Professor for Cybersecurity, University of Oslo, Norway; Bret Jordan, Chief Security Strategist, Afero, United States

Ballroom B

Standards and Certification (S22)
CRA Legal Aspects
Moderator: Arnaud Martin, Agoria, Belgium

13:30 The Interplay Between EU Regulations and Cybersecurity Certification (S22a) Leader: Renate Verheijen, Legal Adviser on Cybersecurity, European Union Agency for Cybersecurity (ENISA), Greece [60MIN]


14:30 When Product Cybersecurity Becomes Law: Implementing the CRA at a Global Cross-Domain Product Manufacturer (S22c) Marko Wolf, Chief Expert Product Cybersecurity Governance, Robert Bosch GmbH, Germany


15:00 Can the Cyber Resilience Act Function as CE Legislation? Insights from the Home Appliance Perspective. (S22d) Alexander Eisenberg, Head of Office EU Technical Market Access, BSH Home Appliances S.A., Belgium

15:30-16:00 Networking Break

Foyer. Exhibits close at 16:00.

16:00-17:00 Closing Presentation

Ballroom

16:00 European Cybersecurity Legislation—Industry View—How Can We Make Laws Work Together? (P23a) John Boggie, President, Eurosmart, United Kingdom; Pierre-Jean Verrando, Director General, Eurosmart, Belgium [60MIN]

17:00 Adjourn