Europe's defining gathering on digital governance

Digital governance has moved to the boardroom. So have we.

One room. One day. 350 of Europe's most senior leaders. The European Digital Governance Summit is where chairs, boards and executive leadership confront the ten digital risks they now personally own — guided by ten of Europe's foremost experts, one for each risk, and hosted end to end by Paul C. Dwyer.

The Mansion House, Dublin · Wednesday 25 November 2026 · One day

1Day
10Risks
350Leaders
0Sales Pitches

The concept

Ten risks. Ten experts. One host.

This is not an expo. The day is built around ten defining digital risks — and for each one, a dedicated leading expert takes the stage, chosen for authority, not affiliation. Ten experts, ten focused sessions, each delivering the boardroom view: what the risk really is, what regulators now expect, and what a defensible answer looks like. Threading it all together is the summit's overall host expert, Paul C. Dwyer. Selected partners are present around the room to engage during the breaks — but the stage belongs to education. Nothing is ever pitched from it.

10 Experts

One dedicated expert per risk — ten authoritative voices, each with one focused session and the floor to deliver it. No panels of pitches.

1 Host Expert

Paul C. Dwyer curates and hosts the day end to end — opening keynote, every conversation, closing address. One thread, from first word to last.

1 Room

350 leaders, together for the whole day. No breakouts to choose between, no sessions missed. Everyone leaves with the same complete picture.

Inside the Round Room at the Mansion House, Dublin — venue of the European Digital Governance Summit

The Round Room · The Mansion House · Dublin

Why now

Accountability has been reassigned — upwards.

A new generation of European regulation places responsibility for digital risk squarely with leadership. The question in the boardroom is no longer "are we secure?" — it is "can I evidence that we are resilient?"

DORA

Operational resilience is now a regulatory obligation for financial entities — with the management body expected to direct, approve and oversee it.

NIS2

Cybersecurity duties now extend across essential and important sectors, with accountability attaching to management — not just to the IT function.

EU AI Act

As organisations adopt AI, boards are expected to govern its use with the same rigour they apply to any other material risk.

The agenda

Ten risks. One day. No noise.

The summit is built around The Top 10 Digital Risks Every European Board Must Own — the ten risks that now define board accountability across Europe. Each is addressed in a single, focused, expert-led session: practical, evidence-based and free of vendor pitches.

01Ransomware & Cyber Extortion

Ransomware is no longer a virus problem. It is an extortion business — organised, industrialised and profitable — whose product is your worst trading day. Modern operators rarely stop at encrypting systems: they steal data first, threaten publication, and price their demand against what they estimate an outage costs you per day.

They don't price the ransom against your data. They price it against your downtime.

The boardroom questionIf ransomware took our core systems down this morning, how many days could we trade — and who has independently verified that answer?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

02Third-Party & Concentration Risk

Every organisation has outsourced pieces of itself — cloud, payments, payroll, security, software. Each contract made sense on its own. Taken together, they have quietly relocated your operational risk into companies you do not control, cannot inspect at will, and often share with every competitor you have.

You can outsource the function. You cannot outsource the risk.

The boardroom questionWhich single provider, if it failed today, would take us down with it — and when did this board last see that map?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

03AI Adoption & Autonomous Decisions

AI is entering your organisation faster than your governance of it. Decisions once made by accountable people are increasingly made, shaped or accelerated by systems — often adopted team by team, without anyone approving the sum of it at the top.

You can delegate the decision to a machine. You cannot delegate the accountability.

The boardroom questionWhere is AI already making decisions in our name — and who approved that?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

04Operational Resilience & the Continuity Test

Every organisation has a continuity plan. Far fewer have evidence that it works. Resilience is not the existence of a document — it is the demonstrated ability to keep your most important services running through disruption, within tolerances the board has set.

Continuity you haven't tested is continuity you don't have.

The boardroom questionWhen did we last test our most important business service to the point of failure — and what did we change afterwards?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

05Identity, Access & the Human Perimeter

The perimeter is no longer the network. It is every person with credentials — and every voice, video call and email that can convincingly impersonate them. AI-enabled social engineering has made "verify who you're dealing with" a board-level control, not a training slide.

Attackers don't break in anymore. They log in.

The boardroom questionIf a convincing voice on the phone asked us to move money today, what — exactly — stands between that request and the transfer?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

06Data Protection, Privacy & Digital Sovereignty

Data is the one asset you can lose while still possessing it. Where your data lives, under whose laws, who can access it and who can compel access to it — these are now questions of sovereignty and strategy, not storage.

Data is the only asset you can lose and still hold.

The boardroom questionDo we know where our critical data resides, under which jurisdictions — and who could compel access to it tomorrow?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

07Regulatory Convergence: DORA, NIS2 & the AI Act

Europe's digital regulations were written separately, but they converge on a single expectation: that the management body directs, oversees and evidences the organisation's digital risk. Treating them as three compliance projects misses the point — together they define one governance discipline.

Regulators no longer ask what your IT department did. They ask what your board decided.

The boardroom questionCould we show a regulator, today, how this board directs and oversees digital risk — with evidence, not assurances?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

08Incident Response, Crisis Leadership & Disclosure

The incident tests your systems. The hours that follow test your board. European notification regimes start the clock almost immediately — which means who leads, who speaks, who notifies and in what order must be decided, and rehearsed, long before the worst day arrives.

A crisis reveals the decisions you didn't make in peacetime.

The boardroom questionIf the incident began right now — who leads, who speaks, who notifies — and have we ever rehearsed it together?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

09Cyber Insurance, Risk Transfer & Personal Liability

Insurance has a role in digital risk — but a narrower one than many boards assume. Policies pay some costs, under conditions, with exclusions. What they do not transfer is accountability: regulatory duties, disclosure obligations and, increasingly, personal exposure for those who govern.

Insurance transfers cost. It does not transfer accountability.

The boardroom questionDo we know what our policy actually excludes — and what exposure remains, for the organisation and for us, after it pays?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

10Geopolitics, the Threat Landscape & the Board Horizon

Your threat landscape is now shaped in capitals as much as in code. Conflict, sanctions, supply-chain realignment and state-aligned cyber activity reach directly into European organisations — which makes horizon scanning a governance duty, not a luxury.

Geopolitics no longer stops at the firewall.

The boardroom questionWhich geopolitical scenario would hurt us most — and does it appear anywhere on our risk register?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

The complete briefing

Every risk. One document.

Download the Executive Guide — The Top 10 Digital Risks Every European Board Must Own — all ten briefings in a single board-ready document: the evidence, the legal mandates, and the ten questions every director should be asking.

Download the Executive Guide

Enter your details and your copy will be emailed to you.

The format

Built for people who chair meetings, not attend them.

  • One day, one room, one agenda — no parallel tracks to choose between
  • Ten focused sessions, each led by a dedicated subject-matter expert
  • Board-level briefings, not technical deep-dives
  • No sales pitches from the stage — partner conversations happen in the breaks, on your terms
  • Structured networking with peers who hold the same responsibilities

Who it's for

The people the regulation now names.

  • Chairs, non-executive directors and board members
  • CEOs and executive leadership of regulated organisations
  • Chief Risk Officers and Chief Information Security Officers
  • Heads of compliance, audit and operational resilience
  • Leaders preparing their organisations for DORA, NIS2 and the EU AI Act
A full audience of senior leaders at a previous ICTTF event
The Room
Keynote speaker on stage at a previous ICTTF event
The Stage
Leaders networking between sessions at a previous ICTTF event
The Network
Paul C. Dwyer, host of the European Digital Governance Summit

Your host

Paul C. Dwyer

Founder & President, ICTTF International Cyber Threat Task Force

For more than 30 years, Paul has advised boards, governments and intelligence bodies on cyber risk and digital governance — including NATO and the UK National Crime Agency. He is the author of Cyber Risk Leadership and The Art of Cyber Risk Oversight, a TEDx speaker, and has been named among Ireland's Top 100 CEOs. Paul opens the summit, leads every conversation, and closes the day.

CDGP — Certified Digital Governance Professional seal, EU Cyber Academy

For VIP delegates: every VIP place includes the pathway to the Certified Digital Governance Professional (CDGP) credential, delivered through the EU Cyber Academy — so the day doesn't end when the room empties. Full details will be announced alongside the agenda.

Be in the room.

350 places. Ten risks. One day that sets the agenda for the year ahead. Register your interest — as a delegate or as a partner — and be first to receive the expert line-up, the full agenda and delegate details as they are announced.

Register your interest

Select in the form whether your interest is as a delegate or a sponsor — we'll follow up accordingly.

Hosted by the ICTTF International Cyber Threat Task Force  ·  digitalgovernance.eu