CIO & CISO France Roundtable
Event Overview
Agenda
08:00 - 09:00 - Registration
09:00 - 09:10 - WELCOME REMARKS
09:10 - 09:55 - OPENING PANEL DEBATE
From Compliance to Cyber Resilience: Gaining Real Visibility Across France’s Expanding Attack Surface
This roundtable will explore how French organisations are moving beyond regulatory compliance toward true cyber resilience. Participants will examine the growing complexity of the external attack surface, the challenge of prioritising vulnerabilities based on real-world risk, and the operational realities of implementing regulations such as NIS2 and DORA. The discussion will also address how resilience must extend beyond the firewall to include supply chains, digital risk exposure, and external threat intelligence. Through four focused discussion pillars, the session will surface peer insights, practical frameworks, and lessons learned that help security leaders gain meaningful visibility, improve risk prioritisation, and strengthen organisational resilience.
Panel Questions:
-
What cyber risk scenarios keep you up at night in 2026?
-
Where are your biggest blind spots across your external attack surface?
-
How are you currently prioritising vulnerabilities and exposures?
-
What metrics actually prove that your cyber risk is going down?
-
How are you operationalising NIS2 and related regulations today?
10:00 - 10:30 - PRESENTATION
From Vulnerability Lists to Real Exposure: Making Cyber Risk Measurable
Security teams are overwhelmed by vulnerabilities, yet struggle to explain which ones truly matter to the business. This discussion focuses on shifting from raw vulnerability data to understanding actual exposure, combining internal weaknesses with external attack surface visibility. Participants will explore how to prioritise remediation based on exploitability, business impact, and threat context rather than volume. The session also addresses how security leaders can translate technical findings into risk language understood by boards and regulators. The goal is to move from reactive patching to defensible, risk-based decision-making.
Key discussions:
- Why vulnerability volume does not equal real risk
- Turning technical exposure into business-relevant risk metrics
- Prioritisation strategies that reduce risk with limited resources
10:30 - 11:00 - PRESENTATION
Managing Cyber Exposure Across Third Parties and the Extended Enterprise
Organisations increasingly rely on suppliers, cloud providers, and partners, expanding their attack surface far beyond the traditional perimeter. This session examines how cyber exposure in third and fourth parties creates hidden risk that often bypasses internal controls. Attendees will discuss practical ways to gain visibility into external dependencies and assess supplier risk continuously rather than through annual questionnaires. The conversation will also touch on regulatory pressure around supply-chain security and operational resilience. Emphasis is placed on actionable insights, not compliance checklists.
Key discussions:
- Why third-party cyber risk is an exposure problem, not a paperwork problem
- Continuous vs point-in-time supplier risk assessment
- Aligning third-party risk with operational resilience and regulation
11:00 - 11:30 - PRESENTATION
Operational Resilience in Practice: Linking Cyber Exposure, Continuity, and Regulation
Regulations such as DORA and NIS2 are forcing organisations to rethink how cyber risk impacts operational continuity. This discussion focuses on the practical link between cyber exposure, critical services, and real-world disruption. Participants will explore how security, IT, and risk teams can work together to identify scenarios where vulnerabilities translate into outages or regulatory breaches. The session moves beyond theory to discuss how resilience can be tested, measured, and improved. The emphasis is on operational readiness, not just policy alignment.
Key discussions:
- Connecting cyber exposure to business service disruption
- Bridging the gap between security teams and operational resilience owners
- Preparing for regulatory scrutiny without overengineering controls