Europe's defining gathering on digital governance
Digital governance has moved to the boardroom. So have we.
One room. One day. 350 of Europe's most senior leaders. The European Digital Governance Summit is where chairs, boards and executive leadership confront the ten digital risks they now personally own — guided by ten of Europe's foremost experts, one for each risk, and hosted end to end by Paul C. Dwyer.
The Mansion House, Dublin · Wednesday 25 November 2026 · One day
The concept
Ten risks. Ten experts. One host.
This is not an expo. The day is built around ten defining digital risks — and for each one, a dedicated leading expert takes the stage, chosen for authority, not affiliation. Ten experts, ten focused sessions, each delivering the boardroom view: what the risk really is, what regulators now expect, and what a defensible answer looks like. Threading it all together is the summit's overall host expert, Paul C. Dwyer. Selected partners are present around the room to engage during the breaks — but the stage belongs to education. Nothing is ever pitched from it.
One dedicated expert per risk — ten authoritative voices, each with one focused session and the floor to deliver it. No panels of pitches.
Paul C. Dwyer curates and hosts the day end to end — opening keynote, every conversation, closing address. One thread, from first word to last.
350 leaders, together for the whole day. No breakouts to choose between, no sessions missed. Everyone leaves with the same complete picture.
The Round Room · The Mansion House · Dublin
Why now
Accountability has been reassigned — upwards.
A new generation of European regulation places responsibility for digital risk squarely with leadership. The question in the boardroom is no longer "are we secure?" — it is "can I evidence that we are resilient?"
DORA
Operational resilience is now a regulatory obligation for financial entities — with the management body expected to direct, approve and oversee it.
NIS2
Cybersecurity duties now extend across essential and important sectors, with accountability attaching to management — not just to the IT function.
EU AI Act
As organisations adopt AI, boards are expected to govern its use with the same rigour they apply to any other material risk.
The agenda
Ten risks. One day. No noise.
The summit is built around The Top 10 Digital Risks Every European Board Must Own — the ten risks that now define board accountability across Europe. Each is addressed in a single, focused, expert-led session: practical, evidence-based and free of vendor pitches.
01Ransomware & Cyber Extortion
Ransomware is no longer a virus problem. It is an extortion business — organised, industrialised and profitable — whose product is your worst trading day. Modern operators rarely stop at encrypting systems: they steal data first, threaten publication, and price their demand against what they estimate an outage costs you per day.
They don't price the ransom against your data. They price it against your downtime.
The boardroom questionIf ransomware took our core systems down this morning, how many days could we trade — and who has independently verified that answer?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
02Third-Party & Concentration Risk
Every organisation has outsourced pieces of itself — cloud, payments, payroll, security, software. Each contract made sense on its own. Taken together, they have quietly relocated your operational risk into companies you do not control, cannot inspect at will, and often share with every competitor you have.
You can outsource the function. You cannot outsource the risk.
The boardroom questionWhich single provider, if it failed today, would take us down with it — and when did this board last see that map?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
03AI Adoption & Autonomous Decisions
AI is entering your organisation faster than your governance of it. Decisions once made by accountable people are increasingly made, shaped or accelerated by systems — often adopted team by team, without anyone approving the sum of it at the top.
You can delegate the decision to a machine. You cannot delegate the accountability.
The boardroom questionWhere is AI already making decisions in our name — and who approved that?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
04Operational Resilience & the Continuity Test
Every organisation has a continuity plan. Far fewer have evidence that it works. Resilience is not the existence of a document — it is the demonstrated ability to keep your most important services running through disruption, within tolerances the board has set.
Continuity you haven't tested is continuity you don't have.
The boardroom questionWhen did we last test our most important business service to the point of failure — and what did we change afterwards?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
05Identity, Access & the Human Perimeter
The perimeter is no longer the network. It is every person with credentials — and every voice, video call and email that can convincingly impersonate them. AI-enabled social engineering has made "verify who you're dealing with" a board-level control, not a training slide.
Attackers don't break in anymore. They log in.
The boardroom questionIf a convincing voice on the phone asked us to move money today, what — exactly — stands between that request and the transfer?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
06Data Protection, Privacy & Digital Sovereignty
Data is the one asset you can lose while still possessing it. Where your data lives, under whose laws, who can access it and who can compel access to it — these are now questions of sovereignty and strategy, not storage.
Data is the only asset you can lose and still hold.
The boardroom questionDo we know where our critical data resides, under which jurisdictions — and who could compel access to it tomorrow?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
07Regulatory Convergence: DORA, NIS2 & the AI Act
Europe's digital regulations were written separately, but they converge on a single expectation: that the management body directs, oversees and evidences the organisation's digital risk. Treating them as three compliance projects misses the point — together they define one governance discipline.
Regulators no longer ask what your IT department did. They ask what your board decided.
The boardroom questionCould we show a regulator, today, how this board directs and oversees digital risk — with evidence, not assurances?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
08Incident Response, Crisis Leadership & Disclosure
The incident tests your systems. The hours that follow test your board. European notification regimes start the clock almost immediately — which means who leads, who speaks, who notifies and in what order must be decided, and rehearsed, long before the worst day arrives.
A crisis reveals the decisions you didn't make in peacetime.
The boardroom questionIf the incident began right now — who leads, who speaks, who notifies — and have we ever rehearsed it together?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
09Cyber Insurance, Risk Transfer & Personal Liability
Insurance has a role in digital risk — but a narrower one than many boards assume. Policies pay some costs, under conditions, with exclusions. What they do not transfer is accountability: regulatory duties, disclosure obligations and, increasingly, personal exposure for those who govern.
Insurance transfers cost. It does not transfer accountability.
The boardroom questionDo we know what our policy actually excludes — and what exposure remains, for the organisation and for us, after it pays?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
10Geopolitics, the Threat Landscape & the Board Horizon
Your threat landscape is now shaped in capitals as much as in code. Conflict, sanctions, supply-chain realignment and state-aligned cyber activity reach directly into European organisations — which makes horizon scanning a governance duty, not a luxury.
Geopolitics no longer stops at the firewall.
The boardroom questionWhich geopolitical scenario would hurt us most — and does it appear anywhere on our risk register?
The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →
The complete briefing
Every risk. One document.
Download the Executive Guide — The Top 10 Digital Risks Every European Board Must Own — all ten briefings in a single board-ready document: the evidence, the legal mandates, and the ten questions every director should be asking.
Download the Executive Guide
Enter your details and your copy will be emailed to you.
The format
Built for people who chair meetings, not attend them.
- One day, one room, one agenda — no parallel tracks to choose between
- Ten focused sessions, each led by a dedicated subject-matter expert
- Board-level briefings, not technical deep-dives
- No sales pitches from the stage — partner conversations happen in the breaks, on your terms
- Structured networking with peers who hold the same responsibilities
Who it's for
The people the regulation now names.
- Chairs, non-executive directors and board members
- CEOs and executive leadership of regulated organisations
- Chief Risk Officers and Chief Information Security Officers
- Heads of compliance, audit and operational resilience
- Leaders preparing their organisations for DORA, NIS2 and the EU AI Act
Your host
Paul C. Dwyer
Founder & President, ICTTF International Cyber Threat Task Force
For more than 30 years, Paul has advised boards, governments and intelligence bodies on cyber risk and digital governance — including NATO and the UK National Crime Agency. He is the author of Cyber Risk Leadership and The Art of Cyber Risk Oversight, a TEDx speaker, and has been named among Ireland's Top 100 CEOs. Paul opens the summit, leads every conversation, and closes the day.
For VIP delegates: every VIP place includes the pathway to the Certified Digital Governance Professional (CDGP) credential, delivered through the EU Cyber Academy — so the day doesn't end when the room empties. Full details will be announced alongside the agenda.
Be in the room.
350 places. Ten risks. One day that sets the agenda for the year ahead. Register your interest — as a delegate or as a partner — and be first to receive the expert line-up, the full agenda and delegate details as they are announced.
Register your interest
Select in the form whether your interest is as a delegate or a sponsor — we'll follow up accordingly.
Hosted by the ICTTF International Cyber Threat Task Force · digitalgovernance.eu
HEAD OFFICE
-
ICTTF Ltd
ICTTF House
First Floor Unit 15
N17 Business Park
Tuam, Co Galway
H54 H1K2 -
info@icttf.org
support@icttf.org -
+353 (0)1 905 3263


