CIO & CISO France Roundtable

Venue: Paris, France

Address: TBC

Date: 16 April 2026

Event Overview

Agenda

08:00 - 09:00 - Registration

09:00 - 09:10 - WELCOME REMARKS

09:10 - 09:55 - OPENING PANEL DEBATE

From Compliance to Cyber Resilience: Gaining Real Visibility Across France’s Expanding Attack Surface

 

This roundtable will explore how French organisations are moving beyond regulatory compliance toward true cyber resilience. Participants will examine the growing complexity of the external attack surface, the challenge of prioritising vulnerabilities based on real-world risk, and the operational realities of implementing regulations such as NIS2 and DORA. The discussion will also address how resilience must extend beyond the firewall to include supply chains, digital risk exposure, and external threat intelligence. Through four focused discussion pillars, the session will surface peer insights, practical frameworks, and lessons learned that help security leaders gain meaningful visibility, improve risk prioritisation, and strengthen organisational resilience.

 

Panel Questions:

  1. What cyber risk scenarios keep you up at night in 2026?

  2. Where are your biggest blind spots across your external attack surface?

  3. How are you currently prioritising vulnerabilities and exposures?

  4. What metrics actually prove that your cyber risk is going down?

  5. How are you operationalising NIS2 and related regulations today?

10:00 - 10:30 - PRESENTATION

From Vulnerability Lists to Real Exposure: Making Cyber Risk Measurable

Security teams are overwhelmed by vulnerabilities, yet struggle to explain which ones truly matter to the business. This discussion focuses on shifting from raw vulnerability data to understanding actual exposure, combining internal weaknesses with external attack surface visibility. Participants will explore how to prioritise remediation based on exploitability, business impact, and threat context rather than volume. The session also addresses how security leaders can translate technical findings into risk language understood by boards and regulators. The goal is to move from reactive patching to defensible, risk-based decision-making.

Key discussions:

  • Why vulnerability volume does not equal real risk
  • Turning technical exposure into business-relevant risk metrics
  • Prioritisation strategies that reduce risk with limited resources

10:30 - 11:00 - PRESENTATION

Managing Cyber Exposure Across Third Parties and the Extended Enterprise

 

Organisations increasingly rely on suppliers, cloud providers, and partners, expanding their attack surface far beyond the traditional perimeter. This session examines how cyber exposure in third and fourth parties creates hidden risk that often bypasses internal controls. Attendees will discuss practical ways to gain visibility into external dependencies and assess supplier risk continuously rather than through annual questionnaires. The conversation will also touch on regulatory pressure around supply-chain security and operational resilience. Emphasis is placed on actionable insights, not compliance checklists.

Key discussions:

  • Why third-party cyber risk is an exposure problem, not a paperwork problem
  • Continuous vs point-in-time supplier risk assessment
  • Aligning third-party risk with operational resilience and regulation

11:00 - 11:30 - PRESENTATION

Operational Resilience in Practice: Linking Cyber Exposure, Continuity, and Regulation

 

Regulations such as DORA and NIS2 are forcing organisations to rethink how cyber risk impacts operational continuity. This discussion focuses on the practical link between cyber exposure, critical services, and real-world disruption. Participants will explore how security, IT, and risk teams can work together to identify scenarios where vulnerabilities translate into outages or regulatory breaches. The session moves beyond theory to discuss how resilience can be tested, measured, and improved. The emphasis is on operational readiness, not just policy alignment.

Key discussions:

  • Connecting cyber exposure to business service disruption
  • Bridging the gap between security teams and operational resilience owners
  • Preparing for regulatory scrutiny without overengineering controls

11:30 - 12:00 - NETWORKING BREAK

12:00 - 1:00 - LUNCH & CLOSING REMARKS

Event Attendees

Please enter your password to see the attendees.


Wrong password, please try again