Conference Description
Key Takeaways
- Invitation-only forum for CISOs and senior security executives from major Canadian enterprises
- Focus on nation-state threats, threat intelligence, risk quantification and incident response
- Agenda shaped by an executive council of practising CISOs and CIOs
- Hands-on workshops and live attack simulations alongside strategic boardroom discussions
- Held at the Fairmont Chateau Laurier in Ottawa over three days
Introduction
The Watchtower CISO Forum Canada 2026 brings together Chief Information Security Officers and senior security leaders from large Canadian organisations for three days of intelligence briefings, peer-led discussions and tactical training. Designed for executives responsible for enterprise cybersecurity strategy, the forum addresses the operational and strategic challenges that define the current threat landscape, from nation-state adversaries and evolving attack patterns to board-level risk communication and incident response planning.
With geopolitical tensions continuing to shape cyber risk and regulatory expectations intensifying across critical sectors, Canadian security leaders face mounting pressure to demonstrate measurable resilience. The forum responds to this environment by combining real-world intelligence sharing with hands-on exercises, creating a setting where practitioners can benchmark approaches and refine defensive strategies alongside peers facing similar challenges.
About the Watchtower CISO Forum
The Watchtower CISO Forum operates as an invitation-only gathering, distinguishing it from larger industry conferences. Its agenda is developed by an executive council composed of practising CISOs and CIOs, ensuring that session topics reflect the priorities of working security leaders rather than vendor marketing objectives. Discussions operate under Chatham House Rules, allowing participants to share operational insights candidly without attribution.
The event takes place at the Fairmont Chateau Laurier in Ottawa, with travel, accommodation and meals provided for attendees. This structure removes logistical barriers and allows participants to concentrate on substantive engagement throughout the programme.
Threat Intelligence and Nation-State Cyber Risks
A central theme of the forum is the growing sophistication of nation-state cyber operations targeting Canadian enterprises and critical infrastructure. Sessions examine real-time attack patterns, attribution challenges and the countermeasures that security teams are deploying in response. For organisations in financial services, healthcare, energy and government, understanding the tactics employed by state-sponsored actors has become essential to defensive planning.
The programme connects threat intelligence with practical application, exploring how security operations centres can translate indicators of compromise into actionable detection rules and how executive teams can communicate threat severity to boards without resorting to technical jargon that obscures business impact.
Risk Quantification and Board Communication
Translating cybersecurity risk into financial and operational terms remains one of the most persistent challenges for security executives. The forum dedicates sessions to risk quantification methodologies that help CISOs articulate exposure in language that resonates with boards and audit committees. As regulatory frameworks increasingly require demonstrable risk oversight, the ability to present cyber risk alongside other enterprise risks has become a governance imperative.
Discussions also address how security leaders can secure investment for defensive programmes by framing requests in terms of risk reduction rather than technology acquisition, a shift that often determines whether proposals gain executive support.
Incident Response and Live Attack Simulations
Hands-on workshops and live attack simulations form a practical component of the programme. These exercises allow participants to test response procedures under realistic conditions, identifying gaps in playbooks and coordination before an actual incident exposes them. Simulations typically address scenarios such as ransomware intrusions, data exfiltration and supply chain compromises, reflecting the attack vectors that dominate current threat reporting.
Peer-led debriefs following each exercise encourage participants to share lessons learned and compare approaches, reinforcing the collaborative ethos that underpins the forum.
Technologies and Strategic Themes
The forum programme spans several technology domains central to enterprise security operations. Identity management receives significant attention as organisations grapple with credential-based attacks and the complexity of managing access across hybrid environments. Artificial intelligence in security is examined both as a defensive tool and as an enabler of more sophisticated adversary techniques. Managed detection and response services are discussed in the context of resource constraints facing internal security teams, particularly in sectors where talent acquisition remains difficult.
Sponsors and solution providers participating in the event include Commvault, Ping Identity, AirMDR, AppOmni, ThreatLocker, Scytale, Microsoft, Okta, Druva, Cyera, IBM, Trend Micro, SentinelOne, CrowdStrike, Dataminr, Fortinet, Zscaler, Varonis, Dux Security, Adaptive Security, Daylight Security and Rival Security.
Who Should Attend
The forum is structured for CISOs, CIOs, Vice Presidents and Directors of Security from large enterprises, financial institutions, critical infrastructure operators, healthcare organisations, government agencies and academic institutions. Attendees typically hold decision-making authority over cybersecurity strategy, budgets and operations, and benefit most from environments that facilitate candid peer exchange rather than introductory education.
