Conference Description
Key Takeaways
- Scotland’s principal cyber security conference bringing together senior InfoSec professionals, IT leaders, academics, and law enforcement
- Core themes include identity and access management, AI governance, post-quantum cryptography, and organisational security culture
- Addresses practical challenges around evolving threats, regulatory compliance, and securing AI adoption
- Format combines keynotes, workshops, parallel breakout sessions, and exhibition networking
- Relevant to CISOs, CTOs, security managers, and decision-makers across finance, public sector, and critical infrastructure
Introduction
Scot-Secure West is Scotland’s leading annual cyber security conference, organised by DIGIT and held in Glasgow. The event convenes senior information security professionals, IT leaders, academics, security researchers, and law enforcement representatives for a programme of keynotes, workshops, and exhibitions focused on improving cyber security awareness and operational resilience. With organisations facing increasingly sophisticated threat actors, regulatory pressures, and the rapid adoption of artificial intelligence, the conference addresses topics that have moved from technical concerns to boardroom priorities.
About This Event
The conference takes place at the Hilton Hotel in Glasgow, offering an in-person format designed to facilitate meaningful exchange between practitioners. The agenda balances plenary sessions with parallel breakout streams, allowing attendees to tailor their experience according to technical depth or strategic focus. An exhibition area provides opportunities to engage with security vendors and explore current solutions across identity management, threat detection, and infrastructure protection.
BeyondTrust serves as headline sponsor, with additional participation from organisations including Sword Group, Barracuda, ManageEngine, Yubico, Arctic Wolf, ThreatLocker, Cloudflare, Orange Cyberdefense, and Horizon3.ai, among others. This vendor presence reflects the breadth of technologies under discussion, from privileged access management to cloud security and AI-driven threat intelligence.
Identity, Access, and the Challenge of Machine Credentials
Identity and access management remains a central theme, with sessions examining both human and machine identity challenges. As organisations adopt zero-trust architectures, the traditional network perimeter has given way to identity as the primary control plane. This shift demands robust privileged access management and continuous verification, particularly as machine identities now outnumber human users in many enterprise environments. The proliferation of service accounts, API keys, and automated processes creates attack surfaces that conventional identity governance frameworks were not designed to address.
AI Governance and Emerging Regulatory Pressures
The rapid integration of artificial intelligence into business operations introduces governance challenges that extend beyond technical implementation. Security leaders must now consider how AI systems interact with sensitive data, how adversaries might exploit machine learning models, and how regulatory frameworks are evolving to address algorithmic accountability. The conference explores these intersections, recognising that AI governance sits at the confluence of data privacy, operational risk, and strategic decision-making.
Regulatory developments feature prominently across the programme. Organisations operating in financial services, healthcare, and critical infrastructure face overlapping compliance obligations, and the pace of legislative change shows little sign of slowing. Practical guidance on navigating these requirements while maintaining operational agility represents a recurring thread throughout the event.
Preparing for Post-Quantum Cryptography
Post-quantum cryptography has transitioned from theoretical concern to active planning priority. With standards bodies finalising quantum-resistant algorithms and nation-state actors potentially harvesting encrypted data for future decryption, organisations must begin assessing cryptographic dependencies across their estates. The conference addresses this emerging requirement, helping attendees understand timelines, implementation challenges, and the strategic implications of cryptographic migration.
Building Security Culture and Addressing Human Factors
Technical controls alone cannot address the full spectrum of cyber risk. Human factors remain a persistent vulnerability, whether through social engineering, credential misuse, or simple operational error. The conference examines approaches to embedding security culture within organisations, moving beyond compliance-driven awareness training toward genuine behavioural change. This includes vulnerability reporting programmes that encourage responsible disclosure and create feedback loops between security teams and the wider workforce.
Who Should Attend
Scot-Secure West is designed for CISOs, CTOs, security managers, IT directors, and professionals responsible for risk, compliance, and governance functions. The programme serves both public and private sector organisations, with particular relevance to those operating in finance, technology, government, and critical national infrastructure. Security researchers and academics will find value in the technical streams, while executive-level content addresses strategic and budgetary considerations facing senior leadership.
Conclusion
As cyber threats grow more sophisticated and regulatory expectations intensify, events that facilitate genuine knowledge exchange between practitioners become increasingly valuable. Scot-Secure West offers a forum where technical depth meets strategic perspective, providing attendees with practical insights applicable to their own organisational contexts.

