

17 September 2026 | Glasgow
Scot-Secure West
Scotland’s largest annual cyber security summit will host a sister event in Glasgow, Scot-Secure West, for the 4th year running. The event brings together senior InfoSec personnel, IT leaders, academics, security researchers and law enforcement, providing a unique forum for knowledge exchange, discussion and high-level networking.
The programme is focused on improving awareness and best practices through shared learning: highlighting emerging threats, new research and changing adversarial tactics, and examining practical ways to improve resilience, detection and response.
This event is geared towards InfoSec & IT personnel and C-suite leaders. Previous events have gone to a waiting list weeks in advance so we recommend registering early to avoid disappointment.
​
2026 Headline Sponsor

About DIGIT
DIGIT has rapidly grown into the largest business technology community in Scotland. We host an extensive series of events focused on emerging technology and practical innovation. We also run Scotland's leading IT & Digital News Platform www.digit.fyi with over 50,000 page views per month.
​
The events provide a unique platform for knowledge exchange, drawing stakeholders together to explore challenges, best practice, and business impact. Our conferences attract a senior delegate following and have become renowned as an important forum for high-level networking and engagement.
​​

2026 Speakers


Journalist & Broadcaster, BBC Scotland

Founder, DIGIT
Conference Agenda

Breakfast Briefing
​
08:20 Prioritising Security Outcomes, Not Technology
​​​
-
How security leaders assess and prioritise risk across the organisation
-
Balancing people, process and technology to strengthen operational resilience
-
Turning security investment into action through the right people, processes and technology​
​
Jack McCurley, Intelligence Advisory Consultant, Recorded Future
​
08:50 End of Breakfast Briefing
​
SESSION 1
This session examines how effective organisational security depends on understanding the intersection between people, process and technology. We will explore designing systems that align with human behaviour, recognising the cultural signals hidden in everyday workarounds, and closing identity blind spots across humans, machines and AI.
​
09:15 Welcome and Introduction
​​
Mark Stephen, Journalist & Broadcaster, BBC Scotland
​​
09:25 Secure by Design: Putting People First
​​​
-
Understanding human behaviour is a necessary precursor to effectively embedding security across your organisation
-
How to design resilient systems that work with human behaviour, not against it
-
The most common blockers to driving security across the development lifecycle, and how to avoid them
-
Why meaningful metrics matter, and how to define them to incentivise behaviour and drive continuous improvement
​
Kathryn Pimblett, Senior Cyber Security Manager, A.P. Moller Maersk
​
09:50 Following the Elephant Lines: Understanding Security Culture Through How People Actually Work
​​​
-
Security workarounds are signals that official processes may not fit how people work.
-
Most shortcuts are driven by friction, urgency, or poor process design rather than bad intent.
-
Elephant lines help leaders spot where risk is becoming normalised or control is being lost.
-
Not every workaround should be accepted, but everyone should prompt the question: why?
-
Stronger security culture comes from designing secure routes that are simple, practical, and aligned to business deliver
​
Stephanie Perry, Group CISO, Babcock International
​
10:15 The Elephant in the Room: Closing the Identity Blind Spots Across Humans, Machines & AI
​​​
-
Why privileged access, not identity alone, is the real source of cyber risk
-
The growing challenge of managing human, machine and AI identities as AI adoption accelerates
-
How disconnected IAM, PAM, cloud and AI security teams create security gaps and operational silos
-
Practical strategies to unify identity security, improve visibility and reduce enterprise ris
​
Lee Elliot, Director: Solutions Engineering, BeyondTrust
​
10:35 Q&A​
11:00 Refreshments & Networking
SESSION 2
Session 2 will explore a series of key topics in a longer presentation format. The session will be run in a breakout format across four parallel streams, providing delegates the opportunity to attend two options.
11:35 First Breakout Option (A-D)
​
A. Vulnerability Reporting & The Increasing Role of AI-Assisted Research
​
-
How the MSRC intakes, validates, and acts on vulnerability submissions
-
The lifecycle of a report - submission, through triage and validation, to engineering fix
-
How the rise of AI-assisted security research is reshaping that process across the industry
-
Where AI adds value and introduces risk - and ensuring human judgement remains at the centre of decisions
-
Practical lessons that apply to any organisation receiving or acting on security findings
Adam Stevenson, Security Researcher: MRSC, Microsoft ​
​
B. Unintended Insights: What We Give Away Online
​​​
-
Fragments of our professional and personal data are scattered across multiple platforms and across time by ourselves and others.
-
They are almost impossible to erase once shared
-
Linking these fragments can produce a mosaic that affords significant and unintended insights to others—both human and AI.
-
This creates risks of reputational harm and security breaches to organisations and individuals
-
Awareness is crucial in training staff to consider what they post and where
Wendy Moncur, Professor: Cyber Security, University of Strathclyde
​
C. From Principles to Practice: Embedding Responsible AI Governance Across the BBC
​
-
How the BBC has translated its AI Principles into practical governance and risk assessment processes
-
Building visibility of AI risk from individual projects through to strategic oversight
-
Why building a Responsible AI culture is crucial to manage AI risk effectively
-
Lessons learned from embedding Responsible AI in a complex organisation
​
Julie Macleod, Senior Data Manager: Responsible AI, BBC
​
D. Thieves Don’t Break In… They Log In: Secure Your M365 in Minutes, Not Months
​​​
-
See why modern attacks bypass traditional protection - and what that means for your M365 environment
-
Discover how to stay ahead with a joined-up approach to detection, protection and recovery
-
Learn how to quickly strengthen your security without months of heavy lift or complexit
Rob Butterworth, Senior Solutions Architect, Barracuda Networks
​​​
12:10 Transition
12:15 Second Breakout Option (E-H)
​
Breakout options include:
​
E. The Identity Security Blueprint: Human + Non-Human - Securing the Complete Identity Ecosystem
​​​
-
Why identity is the new security perimeter — and why non-human identities (service accounts, APIs, workloads, and machine identities) now outnumber and out-risk human ones
-
A practical blueprint for unified visibility, governance, and lifecycle control across the complete identity ecosystem
-
How automation and adaptive access policies reduce identity risk while strengthening operational trust
-
Building towards a resilient, zero-trust identity architecture that scales with the modern enterpris
​
Ray Manash, Head of Business Development (IAM), ManageEngine
​
F. Keeping Your Data Safe in the AI Age
​​
-
Many AppSec programs stall despite having tools, dashboards, and scans in place
-
As AI continues to fundamentally change the way organisations work, understanding the risks to data privacy and security are more important than ever
-
The impact that AI is having on the threat landscape
-
How organisations can shine a light on their data
-
How to enable their users to productively use AI securely
​​
Dan Kendall, CTO for Public Sector & National Security UKI, Fortinet​​
​
G. The New Reality: Cyber Defence in an Unstable World
​​
-
Cyber threats from hostile nations that are bringing UK businesses to a standstill
-
Preparing your business for this new reality, where attack techniques are increasingly automated and there is a rising tide of new vulnerabilities
-
What's coming next: how escalating geopolitical tensions will continue to reshape the threat landscape for UK businesses
​
Cian Heasley, Principal Consultant, Acumen Cyber
​
H. Secure Your AI Future: Scaling AI Adoption with Confidence
​​​​
-
Understand the New AI Risk Landscape - Explore how copilots, AI agents and autonomous workflows are reshaping enterprise security.
-
Adopt a Data-Centric Security Strategy - Move beyond fragmented controls to a unified approach focused on protecting sensitive data.
-
Strengthen AI Governance - Gain visibility into AI assets, identities, permissions and the data AI systems can access.
-
Enable AI Innovation Securely - Implement real-time guardrails that support responsible AI adoption without compromising business agility
Yuri Duchovy, Head of Technical Solutions & Global Field CTO
​
12:45 Lunch & Networking
​
​
SESSION 3
This afternoon session looks at some of the key challenges currently facing practitioners, from keeping up with the threat landscape, to navigating regulation, and keeping your career ahead of change. We will then turn to the emerging quantum shift, looking at the state of post-quantum cryptography, evolving global standards, and the practical steps organisations must take now to prepare for PQC adoption.
​
13:35 Breakout Selection (I-K)
​
I. Security Gearbox: How Not to Overheat the Engine and Still Reach Your Destination Fast
​​​
-
Dissecting the work of a CISO and a security team in a fast-changing threat landscape
-
A pragmatic view of a field that is always evolving and somehow always the same
-
Covering offensive security, defence in dept, (scary) compliance & boardroom war stories
-
What “good” looks like based on 20 years of experience
-
Demystifying security leadership to help technical professionals speak up and influence
-
A candid “group therapy” session for security leaders
Zibby Kwecka, CISO, Arnold Clark
​
J. Will the Cyber Security and Resilience Bill Improve Cyber Defences?
​​​
-
Overview and background - likely timing
-
The main proposed changes to existing NIS Regs 2018
-
Expanded scope
-
Regulators
-
Government flexibility
-
Will this make a difference - a personal view on whether law can keep up with technology
Laura Irvine, Managing Partner & Head of Regulatory Law, David Chalmers Stewart LLP
K. How to ‘Hack’ Yourself for Career Success in a World of AI & Geopolitical Challenges
​​​
-
My career, struggles and what techniques I use to stay relevant
-
Exploring the AI landscape and geopolitical situation - challenges and opportunities
-
What the dynamic landscape means for individuals and the challenges for a resilient cyber society
-
Horizon skills you need to provide a sustained approach to developing and maintaining your career path in an evolving world
​
James Kwaan, Cyber Operations Manager & President, ISC2 Scotland
​
14:00 Transition to Main Hall
​
​14:05 Post-Quantum Cryptography: Securing a Quantum Future
​​
-
Context of the quantum landscape will be outlined, with reference to UK Quantum Strategy and Hubs
-
The topic of post-quantum cryptography (PQC) will be introduced
-
An update will be given on recent developments in global PQC standardisation
-
Actionable advice on transitioning to PQC and preparing for quantum-related threats & opportunities
Dr Ciara Rafferty, Sr Lecturer, Queen’s University Belfast & Assistant Director, IQN Hub
​
14:30 Preparing for Post-Quantum Cryptography: What CISOs Need to Do Now
​​
-
Defining the quantum threat
-
Outlining business continuity threat and horizontal nature of the quantum threat
-
Outlining the current state of uptake/migration to quantum safe resilience across markets and regions
-
Overview of headlining challenges and obstacles to adoption
-
Providing practical PQC roadmap and recommendations
​​
Aisling Dawson, Senior Analyst, ABI Research
​
14:55 Combined Q&A
​
Zibby Kwecka, CISO, Arnold Clark
Laura Irvine, Managing Partner & Head of Regulatory Law, David Chalmers Stewart LLP
James Kwaan, President, ISC2 Scotland
Dr Ciara Rafferty, Sr Lecturer, Queen’s University Belfast & Assistant Director, IQN Hub
Aisling Dawson, Senior Analyst, ABI Research
15:20 Closing Remarks
15:25 End of Programme
​
Networking Drinks Reception
​
15:30 Networking & Drinks Reception
16:30 Close of Conference​
*The conference agenda is provisional and subject to change.












































.png)