Conference Description
Key Takeaways
- Tenth edition of the Balkan region’s principal cybersecurity conference, held in Belgrade
- Technical focus on threat detection, memory forensics, security automation and AI applications in cybersecurity
- Designed for CISOs, security architects, SOC analysts and IT leaders from enterprise and public sector organisations
- Hands-on training sessions covering tools such as YARA, Wazuh, Microsoft Sentinel and eBPF-based detection
- Addresses operational challenges including incident response maturity, compliance requirements and security-business alignment
Introduction
The eSecurity Conference returns to Belgrade in 2026 for its tenth edition, continuing its role as the Balkan region’s foremost gathering for cybersecurity professionals. Hosted at the Karbon Event Center, the conference brings together security leaders, technical practitioners and industry experts to examine the defensive strategies and technologies required to counter increasingly sophisticated cyber threats. With ransomware attacks growing more targeted, regulatory frameworks tightening across Europe, and artificial intelligence reshaping both offensive and defensive capabilities, the timing reflects the sector’s current inflection point.
About This Event
Now in its tenth year, the eSecurity Conference has established itself as a significant platform for cybersecurity knowledge exchange in Southeast Europe. The programme combines keynote presentations, technical workshops, panel discussions and hands-on training sessions, with content structured to serve both executive decision-makers and technical specialists. The conference emphasises practical demonstrations and real-world case studies rather than purely theoretical discussion, reflecting the operational realities that security teams face daily.
The event draws participation from major technology vendors including Trend Micro, Cisco, Kaspersky, Check Point and Broadcom, alongside regional specialists and professional bodies such as ISACA and ISC2. This mix of international and local expertise provides attendees with perspectives that span global threat intelligence and region-specific operational challenges.
Threat Detection and Incident Response
A substantial portion of the programme addresses the technical foundations of threat detection and incident response. Sessions cover Linux rootkit detection techniques, anomaly identification methodologies and memory forensics workflows using tools such as Volatility and LiME. These topics reflect the growing complexity of attacks targeting enterprise infrastructure, where adversaries increasingly operate in memory to evade traditional file-based detection.
The conference also examines modern detection frameworks including YARA rule development, ClamAV integration and host-based monitoring through Auditd, OSSEC and Wazuh. For organisations building or maturing their security operations centres, these sessions offer practical guidance on implementing detection capabilities that balance coverage with operational overhead.
Security Automation and Cloud Infrastructure
As security teams contend with expanding attack surfaces and persistent staffing constraints, automation has become essential rather than aspirational. The programme addresses this through sessions on Microsoft Sentinel implementation and GitHub Actions for security workflow automation. These platforms represent the broader industry shift toward security orchestration, where repetitive tasks are codified and human analysts focus on investigation and decision-making.
Cloud and infrastructure security receives dedicated attention, with discussions covering the enforcement mechanisms provided by SELinux and AppArmor, file integrity monitoring approaches, and the emerging role of eBPF in kernel-level observability. The inclusion of Keylime, a remote attestation solution, signals growing interest in hardware-rooted trust for distributed environments.
Artificial Intelligence in Cybersecurity
The dual nature of artificial intelligence in cybersecurity—as both defensive tool and attack enabler—features prominently in the conference agenda. Sessions explore how machine learning enhances threat detection and behavioural analysis while acknowledging the risks posed by AI-powered social engineering, automated vulnerability discovery and adversarial techniques designed to evade detection systems. This balanced treatment reflects the nuanced reality that security practitioners must navigate as AI capabilities proliferate.
Who Should Attend
The eSecurity Conference is structured for mid-to-senior level professionals responsible for organisational security posture. Chief information security officers and security architects will find strategic content addressing security leadership, risk management and the alignment of security programmes with business objectives. SOC analysts, incident responders and digital forensics specialists benefit from the technical depth of hands-on workshops and tool-focused sessions.
The audience typically includes representatives from finance, government, telecommunications, retail and IT services—sectors where data protection requirements and threat exposure are particularly acute. For professionals operating within critical infrastructure or public sector organisations, the conference offers relevant perspectives on compliance frameworks and regulatory developments affecting the region.
Building Security Community in the Balkans
Beyond its educational programme, the conference serves as a focal point for professional community development in a region where cybersecurity expertise continues to mature rapidly. Dedicated networking sessions and evening events facilitate the peer connections that often prove as valuable as formal content. For security professionals working in smaller teams or organisations without extensive internal expertise, these relationships provide ongoing channels for knowledge sharing and mutual support throughout the year.

