Conference Description
Key Takeaways
- Austria’s leading cybersecurity meetup for IT security and risk management professionals takes place on 22 September 2026 in Graz
- Programme addresses AI-driven security threats, autonomous AI agent vulnerabilities, and defensive strategies against machine-speed attacks
- Sessions examine the gap between regulatory compliance and actual security posture, including NIS 2 implications
- Disinformation as a cyber risk and geopolitical dimensions of hybrid threats feature in dedicated panel discussions
- Target audience includes CISOs, CSOs, risk managers, compliance officers and CIOs from enterprise organisations
Introduction
The Cyber Crime Forum Graz brings together senior IT security professionals, risk managers and technology vendors to address the evolving threat landscape facing Austrian and European enterprises. Scheduled for 22 September 2026 at Steiermarkhof in Graz, the conference tackles pressing concerns around AI-enabled attacks, regulatory compliance gaps, and the increasingly blurred boundaries between cyber threats and geopolitical conflict. As organisations grapple with NIS 2 implementation deadlines and the rapid deployment of autonomous AI systems, the forum provides a platform for practitioners to share defensive strategies and operational insights.
About the Cyber Crime Forum Graz
Organised by LSZ, the Cyber Crime Forum operates as part of a broader Austrian conference series with events in Vienna, Salzburg, Rankweil, Linz and Graz. The format combines keynote presentations, expert talks, interactive roundtable sessions and structured networking opportunities. The event is free for qualifying attendees from the target audience, with separate paid tickets available for solution providers and consultants seeking visibility within the Austrian security community.
The 2026 edition features moderation by Jimmy Heschl, Group CISO at Red Bull, and Anna Habenegg, Senior Associate at PwC Cybersecurity & Privacy. This practitioner-led approach reflects the forum’s emphasis on peer-to-peer knowledge exchange rather than vendor-dominated presentations.
AI Security and the Challenge of Autonomous Agents
A significant portion of the programme addresses the security implications of AI systems that operate with elevated privileges. One session, presented by iC Consult, examines scenarios where a compromised AI agent with administrative rights could cause damage exceeding that of traditional botnets. The discussion explores why conventional security architectures struggle to contain autonomous systems and outlines countermeasures spanning identity management, access controls and monitoring frameworks.
Horizon3 AI contributes a session focused on shifting security priorities from vulnerability lists toward business risk and impact assessment. The approach advocates using AI-powered offensive testing to identify exposures that matter most to organisational operations, rather than chasing every technical weakness.
Compliance Versus Actual Security
Dr Fabian Bohrn from A1 addresses a tension familiar to many security leaders: the gap between demonstrating compliance and achieving genuine protection. His session argues that compliance audits answer whether an organisation meets regulatory requirements, while attackers ask an entirely different question about what is visible and exploitable from outside. The presentation includes a live passive reconnaissance demonstration, illustrating how external attack surfaces can diverge significantly from internal compliance assessments.
This theme connects directly to broader discussions around NIS 2 and European regulatory frameworks. As organisations invest heavily in certification and audit processes, the forum encourages reflection on whether these efforts translate into meaningful risk reduction.
Disinformation and Hybrid Threats
The afternoon programme includes a panel discussion examining disinformation as a cyber risk. Featuring Cordula Simon from ACIPSS (Austrian Center for Intelligence, Propaganda and Security Studies) alongside a representative from the Austrian Federal Chancellery, the session explores how information manipulation intersects with traditional cybersecurity concerns. A separate presentation by Thomas Zraunig, CISO at 21X AG, addresses personal, physical and travel security in the context of hybrid geopolitical conflicts.
Resilience and Crisis Leadership
The closing keynote takes an unconventional approach, drawing parallels between polar exploration and enterprise risk management. Peter Baumgartner examines leadership principles from Sir Ernest Shackleton’s expeditions, translating lessons about decision-making under extreme uncertainty into frameworks applicable to organisational crisis response. The session positions resilience not merely as a technical capability but as a competitive advantage rooted in leadership, adaptability and forward planning.
Interactive Roundtable Sessions
The forum incorporates smaller group discussions allowing deeper exploration of specific topics. Roundtable themes include negotiating with ransomware attackers, prioritising business risk over technical vulnerabilities, and digital sovereignty strategies. ESET hosts a session examining approaches to achieving greater independence, security and resilience in technology choices.
Who Should Attend
The Cyber Crime Forum Graz is designed for senior professionals responsible for security strategy, risk management and compliance within their organisations. The target audience includes CISOs, CSOs, IT security officers, risk and compliance managers, CIOs and other executives with direct involvement in security governance. The programme balances strategic perspectives with technical depth, making it relevant for both business-focused leaders and hands-on security practitioners seeking to understand emerging threats and defensive approaches.

