Conference Description
Key Takeaways
- Virtual summit focused on measuring and benchmarking cyber resilience using the Cyber Resilience Capability Maturity Model (CR-CMM)
- Addresses the gap between compliance requirements and practical resilience implementation
- Covers AI-driven threats, zero trust, NIS2 risk strategies and governance frameworks for IT service restoration
- Designed for CISOs, security architects, risk managers and compliance officers in regulated industries and critical infrastructure
- Features sessions from practitioners alongside organizations including ECSO, Cloud Security Alliance and NIST
About the Event
Cyber Resilience Awareness Day 2026 is a free virtual summit hosted by ISSA’s Cyber Resilience SIG. The 2026 theme, “Quantifying Cyber Resilience Readiness,” centers on helping organizations assess their current resilience posture, identify gaps and track improvement over time. The program includes expert-led sessions, panels, fireside chats and real-world case studies, with content spanning both technical and executive perspectives.
Maturity Models and Measurement
A central focus of the summit is the Cyber Resilience Capability Maturity Model (CR-CMM), presented as a benchmarking and communication tool for organizations seeking to quantify their resilience readiness. Sessions address how maturity models can establish a common language across teams, enabling clearer communication of progress to leadership and stakeholders. The event aims to provide practitioners with frameworks that translate resilience concepts into measurable outcomes rather than abstract principles.
Technical and Regulatory Topics
The agenda spans several interconnected areas relevant to modern security programs. Sessions cover threat-informed defense and zero trust architectures, AI-integrated threat modeling and the impact of AI on resilience strategies. Governance frameworks for IT service restoration and NIS2 risk strategies address regulatory requirements facing European organizations. Additional topics include human factors in resilience, economic considerations and European cybersecurity priorities as outlined by ECSO.
Sponsors and Contributing Organizations
The summit features involvement from Rubrik, ECSO (European Cyber Security Organisation), Cloud Security Alliance, NIST, Qualys and ProofPackets. These organizations contribute perspectives spanning cloud security, regulatory frameworks, vulnerability management and data protection.
Who Should Attend
The event targets security and risk professionals responsible for building and maintaining organizational resilience. This includes CISOs, security architects, risk managers, IT leaders, compliance officers and practitioners working in governance roles. The content is particularly relevant for those in mid-to-large enterprises, critical infrastructure sectors, technology providers and regulated industries who need to demonstrate resilience capabilities to regulators, boards or customers.

