Conference Description
Key Takeaways
- Private executive forum for CISOs, CIOs, and senior cybersecurity leaders focused on peer-driven dialogue
- Core topics include third-party cyber risk management, agentic AI, Zero Trust architecture, and operational technology security
- Addresses regulatory pressure, executive accountability, and evolving identity and access management challenges
- Discussion-based format with moderated panels and practitioner-led sessions under Chatham House Rule
- Designed for large enterprises and regulated industries navigating complex compliance requirements
Introduction
The NYC CXO Security Forum brings together senior cybersecurity, risk, and compliance executives for a private, in-person briefing focused on the strategic and operational challenges defining enterprise security leadership. As organisations contend with expanding attack surfaces, autonomous AI systems, and intensifying regulatory scrutiny, the forum provides a structured environment for practitioners to exchange insights on third-party risk, Zero Trust implementation, and the shifting responsibilities of security executives. The event is designed exclusively for decision-makers at the CISO, CIO, and Chief Risk Officer level, explicitly excluding sales and marketing professionals to preserve the integrity of peer discussions.
About This Event
The forum operates under Chatham House Rule, enabling candid conversation without attribution. Rather than conventional vendor presentations, the programme features moderated discussions, TED-style talks, and interactive sessions where attendees share real-world experiences and lessons learned. This practitioner-first approach distinguishes the event from typical industry conferences, prioritising actionable dialogue over product demonstrations. Participants gain the opportunity to benchmark their security programmes against peers from similarly complex environments while building relationships within a trusted executive community.
Third-Party Cyber Risk and Assurance Model Evolution
Third-party cyber risk management has become a board-level concern as organisations increasingly depend on interconnected cloud and SaaS ecosystems. The forum examines how traditional assurance frameworks such as SOC 2 and HITRUST are adapting to address continuous risk visibility rather than point-in-time assessments. Discussions explore the limitations of current vendor risk evaluation methods and the operational challenges of maintaining oversight across extended supply chains. For security leaders in regulated industries, understanding how assurance models are evolving is essential for demonstrating due diligence to regulators and stakeholders.
Agentic AI, Zero Trust, and Identity Management
The convergence of agentic AI and Zero Trust architecture represents one of the more complex challenges facing enterprise security teams. Autonomous AI systems introduce new categories of risk that traditional identity and access management frameworks were not designed to address. The forum explores how Zero Trust principles must evolve when machine identities and AI agents operate with increasing autonomy across organisational boundaries. Sessions examine the practical implications of AI-driven security tools alongside the governance requirements necessary to manage AI as both a defensive capability and a potential threat vector. Identity management, long a foundational element of enterprise security, requires fundamental reconsideration as non-human entities proliferate within corporate environments.
Operational Technology Security and Insider Threats
Operational technology environments present distinct security challenges that differ substantially from conventional IT infrastructure. The forum addresses the operational resilience requirements of organisations managing critical systems where security failures carry physical consequences. Insider threat detection remains a persistent concern, particularly as hybrid work arrangements and contractor relationships complicate traditional monitoring approaches. Practitioners discuss detection methodologies and the organisational dynamics that influence insider risk programmes.
Executive Accountability and Regulatory Pressure
Regulatory expectations for cybersecurity leadership have intensified considerably, with personal accountability for CISOs and other executives becoming an increasingly prominent feature of enforcement actions. The forum provides a setting for executives to discuss how their roles are changing in response to regulatory developments and board-level expectations. Risk ownership is no longer confined to security teams, and the event examines how responsibility is distributed across executive leadership. For attendees navigating complex compliance obligations, peer insight into how other organisations structure accountability can inform governance decisions.
Who Should Attend
The NYC CXO Security Forum is designed for CISOs, CIOs, Chief Risk Officers, and senior executives responsible for cybersecurity strategy, risk management, and compliance within large enterprises. Attendees typically represent organisations in regulated industries with complex security requirements and significant third-party dependencies. The forum is particularly relevant for leaders seeking to refine their approach to AI governance, Zero Trust implementation, and executive risk communication. Those looking for vendor-neutral peer dialogue on strategic security challenges will find the format well suited to their needs.

