Conference Description
Key Takeaways
- Hands-on workshop series covering identity and access management (IAM) and security information and event management (SIEM)
- Designed for IT managers, security analysts, SOC teams and IAM specialists
- Features practical labs, real-world use cases and direct engagement with product engineers
- Covers identity lifecycle automation, threat detection, incident response and compliance readiness
- Five UK locations in October 2026: London, Manchester, Birmingham, Bristol and Edinburgh
Introduction
The Shield NxG Workshop 2026 UK is a technical workshop series hosted by ManageEngine, bringing hands-on training in identity and access management and security information and event management to IT and security professionals across five British cities. As organisations contend with increasingly complex hybrid environments and evolving threat landscapes, the event addresses the operational realities of securing enterprise identities whilst maintaining effective threat detection and incident response capabilities.
The workshop format prioritises practical application over theoretical discussion, with participants working through product labs, troubleshooting scenarios and workflow automation exercises alongside the engineers responsible for building the tools.
About This Event
Shield NxG Workshop 2026 UK takes place across London, Manchester, Birmingham, Bristol and Edinburgh during October 2026. The in-person format enables direct collaboration between attendees and ManageEngine’s technical teams, with opportunities for one-to-one consultations and peer networking throughout each session.
Rather than passive presentations, the workshop structure centres on step-by-step labs where participants configure modules, build dashboards and alerts, create policies, and integrate security workflows. Attendees leave with personalised improvement plans, templates and scripts applicable to their own environments.
Identity and Access Management Focus Areas
The IAM track addresses the full identity lifecycle, from provisioning through to deprovisioning, with particular attention to the governance challenges that emerge as organisations scale. Sessions cover risk-aware access governance, dynamic role management and access review processes—capabilities that have become essential as regulatory scrutiny of identity controls intensifies.
Authentication and access control topics include unified login experiences, multi-factor authentication implementation, self-service password reset and conditional access policies. The latter has grown increasingly important as organisations seek to balance security with usability, applying context-aware controls that adapt to user behaviour, device posture and location without creating friction for legitimate access.
ManageEngine’s AD360 and Identity360 platforms serve as the technical foundation for these sessions, with labs designed around real operational scenarios rather than abstract demonstrations.
SIEM and Security Operations Content
The SIEM curriculum builds around ManageEngine’s Log360 platform, covering log management fundamentals through to advanced threat detection and incident response workflows. Participants work through attack simulation exercises, learning to identify indicators of compromise and construct appropriate response playbooks.
SOC modernisation receives significant attention, reflecting the operational pressures facing security teams expected to maintain visibility across expanding attack surfaces with constrained resources. The workshop addresses ITSM integrations that connect detection to remediation, dark web monitoring capabilities and the automation opportunities that can reduce analyst workload without sacrificing detection fidelity.
Bridging Identity and Incident Response
A distinguishing characteristic of the workshop is its treatment of IAM and SIEM as interconnected disciplines rather than separate domains. Compromised credentials remain a primary attack vector, making the relationship between identity controls and threat detection operationally critical. The programme explores how identity telemetry feeds into security monitoring and how access anomalies can serve as early indicators of account compromise.
This integrated approach reflects broader industry recognition that effective security operations require visibility across both identity systems and infrastructure logs, with correlation capabilities that can surface threats spanning multiple data sources.
Who Should Attend
The workshop targets mid-level to senior IT and security professionals with operational responsibility for identity infrastructure or security monitoring. Relevant roles include IT managers, security analysts, SOC analysts, IAM specialists, security engineers and compliance officers. The technical depth assumes familiarity with enterprise identity concepts and security operations fundamentals, making it most valuable for practitioners seeking to enhance existing capabilities rather than those new to the field.
Organisations across sectors with significant IT infrastructure—including enterprise, public sector and education—will find the content applicable to their operational challenges.

