Deep Dive Podcast

European Digital Governance Summit

Watch Full Recording of Webinar

Write your awesome label here.

Europe's defining gathering on digital governance

Digital governance has moved to the boardroom. So have we.

One room. One day. 350 of Europe's most senior leaders. The European Digital Governance Summit is where chairs, boards and executive leadership confront the ten digital risks they now personally own — guided by ten of Europe's foremost experts, one for each risk, and hosted end to end by Paul C. Dwyer.

The Mansion House, Dublin · Wednesday 25 November 2026 · One day

1Day
10Risks
350Leaders
0Sales Pitches

The concept

Ten risks. Ten experts. One host.

This is not an expo. The day is built around ten defining digital risks — and for each one, a dedicated leading expert takes the stage, chosen for authority, not affiliation. Ten experts, ten focused sessions, each delivering the boardroom view: what the risk really is, what regulators now expect, and what a defensible answer looks like. Threading it all together is the summit's overall host expert, Paul C. Dwyer. Selected partners are present around the room to engage during the breaks — but the stage belongs to education. Nothing is ever pitched from it.

10 Experts

One dedicated expert per risk — ten authoritative voices, each with one focused session and the floor to deliver it. No panels of pitches.

1 Host Expert

Paul C. Dwyer curates and hosts the day end to end — opening keynote, every conversation, closing address. One thread, from first word to last.

1 Room

350 leaders, together for the whole day. No breakouts to choose between, no sessions missed. Everyone leaves with the same complete picture.

Inside the Round Room at the Mansion House, Dublin — venue of the European Digital Governance Summit

The Round Room · The Mansion House · Dublin

Why now

Accountability has been reassigned — upwards.

A new generation of European regulation places responsibility for digital risk squarely with leadership. The question in the boardroom is no longer "are we secure?" — it is "can I evidence that we are resilient?"

DORA

Operational resilience is now a regulatory obligation for financial entities — with the management body expected to direct, approve and oversee it.

NIS2

Cybersecurity duties now extend across essential and important sectors, with accountability attaching to management — not just to the IT function.

EU AI Act

As organisations adopt AI, boards are expected to govern its use with the same rigour they apply to any other material risk.

The agenda

Ten risks. One day. No noise.

The summit is built around The Top 10 Digital Risks Every European Board Must Own — the ten risks that now define board accountability across Europe. Each is addressed in a single, focused, expert-led session: practical, evidence-based and free of vendor pitches.

01Ransomware & Cyber Extortion

Ransomware is no longer a virus problem. It is an extortion business — organised, industrialised and profitable — whose product is your worst trading day. Modern operators rarely stop at encrypting systems: they steal data first, threaten publication, and price their demand against what they estimate an outage costs you per day.

They don't price the ransom against your data. They price it against your downtime.

The boardroom questionIf ransomware took our core systems down this morning, how many days could we trade — and who has independently verified that answer?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

02Third-Party & Concentration Risk

Every organisation has outsourced pieces of itself — cloud, payments, payroll, security, software. Each contract made sense on its own. Taken together, they have quietly relocated your operational risk into companies you do not control, cannot inspect at will, and often share with every competitor you have.

You can outsource the function. You cannot outsource the risk.

The boardroom questionWhich single provider, if it failed today, would take us down with it — and when did this board last see that map?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

03AI Adoption & Autonomous Decisions

AI is entering your organisation faster than your governance of it. Decisions once made by accountable people are increasingly made, shaped or accelerated by systems — often adopted team by team, without anyone approving the sum of it at the top.

You can delegate the decision to a machine. You cannot delegate the accountability.

The boardroom questionWhere is AI already making decisions in our name — and who approved that?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

04Operational Resilience & the Continuity Test

Every organisation has a continuity plan. Far fewer have evidence that it works. Resilience is not the existence of a document — it is the demonstrated ability to keep your most important services running through disruption, within tolerances the board has set.

Continuity you haven't tested is continuity you don't have.

The boardroom questionWhen did we last test our most important business service to the point of failure — and what did we change afterwards?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

05Identity, Access & the Human Perimeter

The perimeter is no longer the network. It is every person with credentials — and every voice, video call and email that can convincingly impersonate them. AI-enabled social engineering has made "verify who you're dealing with" a board-level control, not a training slide.

Attackers don't break in anymore. They log in.

The boardroom questionIf a convincing voice on the phone asked us to move money today, what — exactly — stands between that request and the transfer?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

06Data Protection, Privacy & Digital Sovereignty

Data is the one asset you can lose while still possessing it. Where your data lives, under whose laws, who can access it and who can compel access to it — these are now questions of sovereignty and strategy, not storage.

Data is the only asset you can lose and still hold.

The boardroom questionDo we know where our critical data resides, under which jurisdictions — and who could compel access to it tomorrow?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

07Regulatory Convergence: DORA, NIS2 & the AI Act

Europe's digital regulations were written separately, but they converge on a single expectation: that the management body directs, oversees and evidences the organisation's digital risk. Treating them as three compliance projects misses the point — together they define one governance discipline.

Regulators no longer ask what your IT department did. They ask what your board decided.

The boardroom questionCould we show a regulator, today, how this board directs and oversees digital risk — with evidence, not assurances?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

08Incident Response, Crisis Leadership & Disclosure

The incident tests your systems. The hours that follow test your board. European notification regimes start the clock almost immediately — which means who leads, who speaks, who notifies and in what order must be decided, and rehearsed, long before the worst day arrives.

A crisis reveals the decisions you didn't make in peacetime.

The boardroom questionIf the incident began right now — who leads, who speaks, who notifies — and have we ever rehearsed it together?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

09Cyber Insurance, Risk Transfer & Personal Liability

Insurance has a role in digital risk — but a narrower one than many boards assume. Policies pay some costs, under conditions, with exclusions. What they do not transfer is accountability: regulatory duties, disclosure obligations and, increasingly, personal exposure for those who govern.

Insurance transfers cost. It does not transfer accountability.

The boardroom questionDo we know what our policy actually excludes — and what exposure remains, for the organisation and for us, after it pays?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

10Geopolitics, the Threat Landscape & the Board Horizon

Your threat landscape is now shaped in capitals as much as in code. Conflict, sanctions, supply-chain realignment and state-aligned cyber activity reach directly into European organisations — which makes horizon scanning a governance duty, not a luxury.

Geopolitics no longer stops at the firewall.

The boardroom questionWhich geopolitical scenario would hurt us most — and does it appear anywhere on our risk register?

The full briefing on this risk — evidence, legal mandate and board insight — is included in the Executive Guide. Register & download your free copy →

The Executive Guide — The Top 10 Digital Risks Every European Board Must Own

The complete briefing

Every risk. One document.

Download the Executive Guide — The Top 10 Digital Risks Every European Board Must Own — all ten briefings in a single board-ready document: the evidence, the legal mandates, and the ten questions every director should be asking.

Download the Executive Guide

Enter your details and your copy will be emailed to you.

The running order

Three blocks. One narrative arc.

The day is structured in three themed blocks — the threat you face, the dependencies you've created, and the response you owe — each building on the last.

View the full agenda
09:00 – 10:00 Registration, Coffee & Networking
10:00 – 10:15 Opening Address: Digital Governance Has Moved to the Boardroom
Block 1 — The Threat You Face
10:15 – 10:35 Ransomware & Cyber Extortion
10:35 – 10:55 Geopolitics, the Threat Landscape & the Board Horizon
10:55 – 11:15 Identity, Access & the Human Perimeter
11:15 – 11:40 Panel 1: From Obligation to Evidence — What Regulators Now Expect
11:40 – 11:55 Coffee Break
Block 2 — The Dependencies You've Created
11:55 – 12:15 Third-Party & Concentration Risk
12:15 – 12:35 AI Adoption & Autonomous Decisions
12:35 – 12:55 Data Protection, Privacy & Digital Sovereignty
12:55 – 13:40 Lunch
Block 3 — The Response You Owe
13:40 – 14:00 Operational Resilience & the Continuity Test
14:00 – 14:20 Incident Response, Crisis Leadership & Disclosure
14:20 – 14:40 Cyber Insurance, Risk Transfer & Personal Liability
14:40 – 14:55 Coffee Break
14:55 – 15:15 Regulatory Convergence — DORA, NIS2 & the AI Act (Capstone)
15:15 – 15:40 Panel 2: Ask the Faculty — The Ten Questions Your Board Should Be Asking
15:40 – 16:00 Closing Address & CDGP Announcement

Agenda correct as of publication and subject to change. Session order, timings and speakers may be adjusted as the programme is finalised — the definitive agenda will be issued to registered delegates ahead of the summit.

The format

Built for people who chair meetings, not attend them.

  • One day, one room, one agenda — no parallel tracks to choose between
  • Ten focused sessions, each led by a dedicated subject-matter expert
  • Board-level briefings, not technical deep-dives
  • No sales pitches from the stage — partner conversations happen in the breaks, on your terms
  • Structured networking with peers who hold the same responsibilities

Who it's for

The people the regulation now names.

  • Chairs, non-executive directors and board members
  • CEOs and executive leadership of regulated organisations
  • Chief Risk Officers and Chief Information Security Officers
  • Heads of compliance, audit and operational resilience
  • Leaders preparing their organisations for DORA, NIS2 and the EU AI Act
A full audience of senior leaders at a previous ICTTF event
The Room
Keynote speaker on stage at a previous ICTTF event
The Stage
Leaders networking between sessions at a previous ICTTF event
The Network

Who's in the room

Leaders from Ireland's biggest institutions, already confirmed.

A cross-section of the boards, banks and organisations already sending leaders to EDGS.

Logos of organisations confirmed to attend the European Digital Governance Summit

Plus delegates already confirmed from

AccentureAEGEAN AirlinesAssetMetrixBroadcomCommissioners of Irish LightsConveraDanske BankDell TechnologiesDiacomEnvironmental Protection Agency (Ireland)FINEOSHealth Service Executive (HSE)Kerry County CouncilKyndrylMater Misericordiae University HospitalMercedes-BenzNasdaqNational Rehabilitation HospitalNordeaPayac Services CLGPhonovationProgressive Credit UnionQuipu GmbHSemperisSIPTUStryveThe Bar of Ireland / Law LibraryThe Coombe HospitalTymans Group

The seat you'll be sat beside

ChairNon-Executive DirectorChief Executive OfficerChief Risk OfficerChief Information Security OfficerChief Compliance OfficerChief Technology OfficerChief AI OfficerHead of AI GovernanceHead of Digital ResilienceHead of Internal AuditHead of Operational ResilienceData Protection OfficerGeneral CounselBoard Secretary
Paul C. Dwyer, host of the European Digital Governance Summit

Your host

Paul C. Dwyer

Founder & President, ICTTF International Cyber Threat Task Force

For more than 30 years, Paul has advised boards, governments and intelligence bodies on cyber risk and digital governance — including NATO and the UK National Crime Agency. He is the author of Cyber Risk Leadership and The Art of Cyber Risk Oversight, a TEDx speaker, and has been named among Ireland's Top 100 CEOs. Paul opens the summit, leads every conversation, and closes the day.

CDGP — Certified Digital Governance Professional seal, EU Cyber Academy

For VIP delegates: every VIP place includes the pathway to the Certified Digital Governance Professional (CDGP) credential, delivered through the EU Cyber Academy — so the day doesn't end when the room empties. Full details will be announced alongside the agenda.

Industry Partners

Standing alongside EDGS

For partners

Ten risks. Ten partners. Nowhere to hide in a crowd.

EDGS was built to be different from every governance event you've been asked to sponsor. There is no expo hall, no shared logo wall, and no stage time sold to the highest bidder. Instead, ten organisations — one per risk on the agenda — stand alongside our expert faculty as the credible, trusted voice on the risk they know best, in front of 350 of Europe's most senior digital governance leaders.

10Partner Slots
1Per Risk
20Minutes on Stage
0Logo Walls
One Risk, Exclusively Yours

No shared themes, no competitors in your space. Your organisation is the name associated with one defined risk, across every piece of EDGS branding and material — for the life of the event, not just the day.

20 Minutes on Stage

Each partner delivers a focused session on their chosen risk — what it is, why it matters for leaders, and how it can be addressed. Thought leadership, not a pitch: the same standard the stage holds every other speaker to.

A Room Built to Talk

Beyond the stage, partners have a branded presence on the delegate floor and a dedicated stand at the room's perimeter — built for the real conversations that happen in the breaks, not just visibility from a distance.

Why partner now

The people in this room are the people the regulation now names.

DORA, NIS2 and the EU AI Act have moved digital risk ownership to the boardroom — which means the budget, the mandate and the urgency now sit with exactly the audience EDGS brings into one room: chairs, CEOs, CROs, CISOs and the leaders preparing their organisations for these obligations. Reaching them here means reaching the people who will decide, not the people who will escalate.

What's included

Built for real access, not passive visibility.

  • Exclusive ownership of one named risk domain across all EDGS branding and materials
  • A 20-minute speaking slot on your chosen risk — education, not a product pitch
  • Complimentary delegate passes for client and prospect hosting
  • A branded table on the delegate floor and a dedicated stand at the room's perimeter
  • Recognition across the ICTTF community — 50,000+ members strong
  • Introduction to delegates for follow-up after the event, in line with GDPR

Full partnership details, including investment and terms, are set out in our partner prospectus. Register your interest below and we'll send it straight over.

Ten slots. Going now. Each risk domain is available to one partner only, and slots are being confirmed on a first-come basis. Once a domain is taken, it isn't available again until next year.

Not a neat fit for one of the ten named risks, or looking for a different kind of presence at the summit? We're open to discussing a bespoke partnership — tell us your goals and we'll talk it through.

Early bird rates available — see link above

Be in the room.

350 places. Ten risks. One day that sets the agenda for the year ahead. Register your interest — as a delegate or as a partner — and be first to receive the expert line-up, the full agenda and delegate details as they are announced.

Register your interest

Select in the form whether your interest is as a delegate or a sponsor — we'll follow up accordingly.

Hosted by the ICTTF International Cyber Threat Task Force  ·  digitalgovernance.eu