ItaliaSec: Virtual Edition
2nd December 2026 // Online
2nd December 2026 // Online
Couldn’t attend ItaliaSec in Milan last May? This December, ItaliaSec: The Virtual Edition brings the best of our Spring conference straight to your screen.
In today’s fast-evolving digital landscape, cyber incidents cannot be entirely prevented. Success is no longer defined solely by the absence of breaches—it’s measured by cyber resilience: the ability to maintain business continuity, protect critical assets, and adapt under pressure.
We are unlocking our session vault to bring you exclusive recordings featuring top CISOs and cyber security leaders. Join us online to shift your mindset from prevention to sustained outcomes, equipping your organisation to withstand disruptions, recover faster, and thrive despite uncertainty. Secure your virtual pass today!
We are currently working on the virtual agenda and will be updating it soon.
In the meantime, take a look at the topics and themes discussed as part of the May 2026 agenda:
| 2nd December 2026 10:00 – 16:00 (CEST) | |
| 09:55 Login | |
| 10:00Chairman’s Opening Address | |
| 10:10 Quali saranno le principali minacce e opportunità per le organizzazioni italiane nel prossimo anno? In questo keynote esploreremo le tendenze emergenti della cyber security, dai ransomware e attacchi mirati all’impatto dell’AI e della digital transformation, fino alle strategie più efficaci per mitigare rischi e rafforzare la resilienza. Una panoramica indispensabile per CISO, manager e decision maker che vogliono anticipare i cambiamenti e preparare le proprie aziende a un contesto digitale in continua evoluzione. . . | |
| 10:40 Dalle dipendenze software di terze parti agli ecosistemi globali dei fornitori, i CISO devono ripensare il modo in cui valutano la fiducia e monitorano il rischio. Questa tavola rotonda riunisce leader della sicurezza per condividere approcci pratici su come costruire visibilità, governance, assurance e resilienza lungo l’intero ciclo di vita della supply chain. . • Come possiamo ottenere una visibilità davvero significativa sull’intera supply chain? Quali strumenti per la sua mappatura e monitoraggio continuo possono davvero fare la differenza? • Quali strategie funzionano meglio per valutare e verificare in modo continuativo la postura di sicurezza dei fornitori critici, non solo in fase di onboarding? • Con l’aumento delle pressioni regolatorie e geopolitiche, come possiamo bilanciare compliance, agilità di business e resilienza della supply chain? • Come possiamo prepararci all’eventualità in cui dobbiamo dismettere un fornitore critico rapidamente? . | |
| 11:20Break & Networking | |
| 12:00 Un approccio strategico per costruire fiducia digitale in un contesto sempre più guidato dall’IA L’aumento delle interazioni digitali sta facendo crescere in modo esponenziale i rischi di frodi e furti di identità. Come essere certi che gli utenti siano davvero chi dichiarano di essere? E come proteggere i percorsi digitali senza introdurre attriti che possano compromettere l’esperienza utente? Questa sessione esplorerà come: .
| |
| 12:30 . • Come superare il divario temporale critico tra attaccanti guidati dall’AI (che operano in pochi minuti) e i processi difensivi tradizionali basati sulla “velocità delle riunioni di spogliatoio” • Perché rincorrere il 100% delle patch è una battaglia persa in partenza, e come il team di Juventus si concentra invece sulle minacce che contano davvero sfruttando il “Vantaggio di Campo” . | |
| 13:00 In questo intervento assisteremo a una discussione approfondita sull’evoluzione del concetto di resilienza organizzativa. Esploreremo perché la resilienza è oggi un elemento critico nel contesto della cyber security, e come questa deve allontanarsi da una compliance puramente formale. Imparerai a prevedere e prepararti ai rischi emergenti più probabili che metteranno alla prova la tua organizzazione nei prossimi 12‑18 mesi, scoprendo strategie pratiche per costruire un futuro veramente resiliente. . | |
| 13:10Lunch | |
| 14:10 Le credenziali compromesse restano il vettore d’attacco dominante: il 22% delle breach parte dall’abuso di credenziali, l’88% degli attacchi web le sfrutta e il 54% delle vittime ransomware aveva credenziali già esposte. Account orfani, shadow admin, service account non gestiti e identità machine compongono una superficie d’attacco vasta e invisibile. Il contributo dimostra perché la Discovery continua è il primo passo imprescindibile di qualsiasi strategia di Identity Security. Partendo dalle ricerche dei Delinea Labs sulle minacce emergenti, inclusa l’ascesa della shadow AI e l’abuso di identità non-umane, presenteremo un framework pratico per costruire visibilità completa su tutte le identità — umane, machine e AI — e tradurla in riduzione concreta del rischio attraverso vaulting, least privilege e Zero Standing Privilege. . | |
| 14:40 Le minacce odierne evolvono più rapidamente di quanto possiamo formare i nostri team, e i CISO sanno che i programmi di sensibilizzazione tradizionali non sono più sufficienti per fermare attacchi sofisticati e in continua evoluzione. Partecipa a questo intervento per discutere strategie volte a: .
| |
| 15:10Break & Networking | |
| 15:40 L’intervento propone la condivisione dell’esperienza maturata nell’ambito dell’implementazione di un programma strutturato di cyber exposure management, finalizzato alla rilevazione, analisi e mitigazione continua delle vulnerabilità. La sessione illustrerà come, a partire da una maggiore visibilità sugli asset critici, sia possibile affinare i processi di prioritizzazione del rischio e ridurre progressivamente l’esposizione alle minacce, contribuendo a rafforzare la resilienza complessiva dei sistemi e a valorizzare la sicurezza informatica come elemento abilitante a livello strategico. . . | |
| 16:10 Closing Remarks & End of the Conference | |
#ItaliaSec features dynamic presentations, case studies and panel discussions hosted by major cyber security players from across the country. A-list speakers provide cyber security insights based on first-hand lessons learned, assess best practices for addressing workforce challenges, propose industry frameworks for addressing breaches and current threats, and analyse current cyber security trends and predictions for Italy’s core industries.
Last edition’s speaker line-up is listed below:
Ferrari Group
Andrea Succi is the CISO at Ferrari Group, service provider specialising in shipping, integrated logistics and high value-added services for luxury and precious goods, worldwide. He is also one of the founders of CISOs4AI, a community uniting CISOs across Italy.
L’Oreal
Giampiero Bonfiglio is the CISO for Italy and Greece at L’Oreal, with cross-functional responsibility spanning both IT and OT areas for these countries. He has been leading key initiatives that have strengthened the organisation’s security posture, catalysed innovation and fostered a strong, sustainable security culture.
PensieroSicuro
Alessandro is the founder of PensieroSicuro, a podcast that addresses every side of cyber security, privacy and technology in a fun, but deep way. Alessandro has a degree in Science and Technologies for Development, and is a certified CISO. He is the first “PensatoreSicuro”.
Infocamere
Claudio De Rossi is the CISO at InfoCamere, the digital innovation company of the Italian Chambers of Commerce. In this role, he steers the corporate security strategy, bringing recognized expertise in cyber security, security governance and risk management within complex regulatory frameworks.
Retail
Fabio Gianotti is a Security professional with more than 20 years on ICT and Information Security. He has xtensive experience in Cyber Security & Fraud and IT service Platforms, IT Security Governance, Disaster Recovery and Business Continuity, IT Security Engineering and Security R&D.
Lucart Group
Simone Santini has been working at Lucart for 25 years and serves as IT Infrastructure Manager & CISO. In this role, he oversees infrastructure, IT/OT security, data centers, networking, and NIS2 compliance, leading modernisation and business continuity initiatives to ensure the resilience and protection of the company’s systems.
IDM – Integra Document Management
Luca A. Giusti is CISO, Head of Infrastructure at IDM. His approach to security is anthropocentric and multidisciplinary: “security is a matter of people” is at the core if his approach to foster a 360 degree security culture integrating both technology and humans.
Gruppo Tea
Christian Bassi is the CISO at Grouppo Tea, a utility company, where he oversees cyber security and has been leading NIS2 compliance efforts.
Milano Serravalle – Milano Tangenziali
Marco Pedrotti is an electronics Engineer with a long career in information systems management/. He specialises in IT/OT security and NIS2 compliance, coordinating projects focused on infrastructure protection and risk management.
Dolce & Gabbana
Luca is a Senior Security Executive 20+ years’ international experience in critical sectors. Formerly Group Head of Security at UniCredit and Vodafone, he currently serves as Group CSO/CISO at Dolce & Gabbana. An expert in Cyber Defence and GRC, he specialises in leading digital transformation initiatives and strengthening operational resilience.
ENGIE Italia
Paolo Cannistraro is the CISO at ENGIE Italia. He specialises in information security, audit, risk management and compliance. He is also one of the founders of CISOs4AI.
CCR Commercial Refrigeration
Simone Rizzo is the CISO at CCR Commercial Refrigeration. After long experience designing and implementing infrastructures, he shifted his focus to the world of cyber security and has is now in charge of designing, planning and implementing CCR’s security strategy.
Credem Banca
Francesco Puccioni is the Head of Cyber Security Operations at Credem Banca. He brings 20+ years’ experience from previous roles at CSE- Consorzio Servizi Bancari, Telepass S.p.A. and CABEL. His areas of expertise include information security, privacy, security compliance, risk management, IT governance, project management, quality assurance, IT audit, business continuity and crisis management.
Fondazione Milano Cortina 2026
Vincenza Moroni is currently Head of Cyber Security & Compliance at the Milano Cortina 2026 Foundation, the organisation behind the 2026 Winter Olympic and Paralympic Games. In this unique role, she works to protect the Olympic ecosystem from cyber threats.
Philip Morris
Giovanni has 20+ years of cyber security experience, starting in leading consulting firms before joining Philip Morris International, where he has held roles spanning both IT and OT. He currently serves as Director Information Security for Operations with a global scope, driving secure business strategies, reducing cyber risk, and strengthening resilience.
Osservatorio per la Cyber Resilienza & AI delle Reti Energetiche
Gaetano is the Scientific Director of National Committee for Electrical Grid Cyber Security, Resilience and AI, in which he has been playing an active role since 2015.
Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.
Fastly is upgrading the internet experience to give people and organizations more control, faster content, and more dynamic applications. By combining the world’s fastest global edge cloud network with powerful software, Fastly helps customers develop, deliver, and secure modern distributed applications and compelling digital experiences. Fastly’s customers include many of the world’s most prominent companies, including Pinterest, The New York Times, and GitHub.
Akamai is the cyber security and cloud computing company that powers and protects business online. Our market-leading security solutions, superior threat intelligence, and global operations team provide defence in depth to safeguard enterprise data and applications everywhere. Akamai’s full-stack cloud computing solutions deliver performance and affordability on the world’s most distributed platform.
Delinea, a pioneer in identity protection through centralised authorisation, makes companies more secure by seamlessly governing their interactions across the modern enterprise. It applies context and intelligence across the identity lifecycle including cloud and traditional infrastructure, data and SaaS applications to eliminate identity-related threats. Delinea uniquely provides intelligent authorisation for all identities, enabling accurate user identification, appropriate access assignment, interaction monitoring and rapid response to irregularities.
At Ping, we deliver identity and access solutions that make it possible to trust every digital moment—moments with customers, employees, partners, and non-human identities. Whether you’re securing millions of users, fighting sophisticated fraud, simplifying third-party access, or embracing passwordless experiences and verifiable credentials, establishing trust shouldn’t slow you down. Our enterprise-grade identity platform is built for scale, speed, and flexibility.
SSH Communications Security (SSH) is a leading defensive cybersecurity company that secures communications and access for and between humans, systems, and networks. Our customers include a diverse range of enterprises, from multiple Fortune 500 companies to SMBs across various sectors, including Finance, Retail, Industrial, Critical Infrastructure, Healthcare, and Government. We help customers secure their business in hybrid cloud environments and distributed IT and OT infrastructures. SSH’s shares (SSH1V) are listed on Nasdaq Helsinki.
Claroty has redefined cyber-physical systems (CPS) protection with an unrivaled industry-centric platform built to secure mission-critical infrastructure. The Claroty Platform provides the deepest asset visibility and the broadest, built-for-CPS solution set in the market comprising exposure management, network protection, secure access, and threat detection – whether in the cloud with Claroty xDome or on-premise with Claroty Continuous Threat Detection (CTD).
ESET® provides cutting-edge cybersecurity, preventing attacks before they happen. By combining AI with human expertise, ESET stays ahead of global threats to secure businesses, infrastructure, and individuals. Whether for endpoint, cloud, or mobile protection, our AI-native solutions are effective and easy to use. ESET technology includes robust detection, encryption, and multifactor authentication with 24/7 defense and local support.
Perforce-Delphix automates secure, compliant data delivery to power DevOps, AI, and cloud transformation. By eliminating data bottlenecks, Perforce-Delphix helps enterprises speed up innovation, reduce risk, and cut costs — enabling faster releases, AI model training, and seamless compliance with privacy regulations.
Combining a clever mix of tailored awareness and hands-on training, Riot is the next-generation platform for preparing employees for cyberattacks. Founded in 2020, Riot has raised more than €3 million from prestigious investors, including Y Combinator (Stripe, Airbnb, Dropbox…), Frst Capital (Payfit, Doctrine) and FundersClub (Coinbase, Slack…). Today, Riot prepares more than 100,000 employees each month to deal with cyberattacks, including teams from Alan, Deezer, Intercom, Alcatel-Lucent and Le Monde.
Step on ItaliaSec’s virtual stage and present to CISOs, VPs & Heads of IT Security from the likes of Banca d’Italia, Calzedonia, Ferrari, ACEA, Sky Italia & Poste Italiane
Normal Price €299. Early Bird Offer Ends in 2nd October 2026
For End-users, Government
& Academia
For Cyber/IT Security Solution/Product Providers & Consultants