Conference Description
Key Takeaways
- Peer-led cybersecurity summit designed exclusively for CISOs, CIOs, and senior risk executives
- Focus areas include agentic AI governance, Zero Trust 2.0, ransomware defence, and cyber-fraud fusion
- Participation from FBI, US Secret Service, and DHS alongside enterprise security leaders
- Structured around moderated discussion pods and curated networking rather than vendor presentations
- Addresses board-level risk translation, regulatory compliance, and workforce development challenges
Introduction
The Northeast Annual Cybersecurity Summit (NEACS) brings together senior cybersecurity executives for a practitioner-driven forum addressing the strategic, operational, and regulatory challenges facing security leaders today. Now in its thirteenth year, the event serves CISOs, CIOs, CTOs, and heads of risk from large enterprises, financial institutions, critical infrastructure operators, government agencies, and academia. The summit’s relevance has intensified as organisations grapple with the rapid integration of artificial intelligence into both defensive capabilities and adversarial attack methodologies, alongside mounting regulatory scrutiny and the persistent threat of ransomware and fraud.
About This Event
Organised by the CxO Security Forum in partnership with regional and national information security associations, NEACS takes place at Quinnipiac University in North Haven, Connecticut. The event distinguishes itself through a strict policy limiting vendor participation to ten vetted, non-competitive solution providers, with no product pitches permitted during sessions. This structure prioritises candid peer exchange over commercial messaging, creating an environment where executives can discuss operational realities without filtering for sales audiences.
The format combines keynote presentations with moderated discussion pods and panel sessions, enabling participants to engage deeply with specific topics rather than passively consuming content. Government agency representatives from the FBI, US Secret Service, and Department of Homeland Security participate alongside private sector leaders, facilitating the kind of public-private dialogue that has become essential to effective threat intelligence sharing.
AI Governance and the Evolution of Identity Security
A significant portion of the summit agenda addresses the security implications of artificial intelligence, particularly agentic AI systems that operate with increasing autonomy. As organisations deploy AI agents capable of making decisions and taking actions without direct human oversight, traditional identity and access management frameworks require fundamental reconsideration. The concept of Zero Trust 2.0 emerges from this context, extending zero trust principles beyond human users to encompass machine identities, AI agents, and the complex trust relationships between automated systems.
These discussions carry particular weight given emerging regulatory frameworks such as the AI Clarity Act, which introduces new compliance obligations for organisations deploying AI systems. Security leaders must now evaluate not only whether AI tools improve their defensive posture but also whether their governance structures can demonstrate appropriate oversight to regulators and boards.
Cyber-Fraud Fusion and Economic Impact
The summit examines cybersecurity through an economic lens, treating breaches and fraud as business events with quantifiable financial and operational consequences. This framing supports more effective communication with boards and executive leadership, translating technical risk into language that drives appropriate investment and strategic prioritisation.
A notable theme involves the integration of fraud prevention and cybersecurity functions, often referred to as cyber-fraud fusion. Historically siloed within organisations, these disciplines increasingly overlap as adversaries combine technical intrusion techniques with social engineering and financial fraud schemes. Ransomware operations, for instance, now frequently incorporate data theft and extortion alongside encryption, blurring the line between cybercrime and financial fraud. Organisations that maintain separate fraud and security teams risk gaps in detection and response.
Adversary Tradecraft and Third-Party Risk
Sessions on adversary tradecraft address current ransomware tactics, fraud ecosystems, and attack methodologies targeting enterprise environments. Vulnerability management receives particular attention, including the challenges of prioritising CVE remediation when organisations face thousands of disclosed vulnerabilities annually. Third-party risk management features prominently, reflecting the reality that supply chain compromises and vendor breaches now represent primary attack vectors for sophisticated threat actors.
The inclusion of operational technology and edge device security acknowledges the expanding attack surface as organisations connect industrial control systems, IoT devices, and distributed infrastructure to enterprise networks.
Who Should Attend
NEACS restricts registration to qualified executives, explicitly excluding sales, marketing, and business development professionals. The target audience comprises decision-makers responsible for security strategy, risk management, compliance, and technology leadership within their organisations. Attendees from Liberty Mutual Insurance, GroupSense, IT-Harvest, and RadicalNotion.AI are among the featured speakers, representing perspectives from insurance, threat intelligence, and emerging technology sectors.
The summit serves executives seeking substantive peer dialogue on workforce development, talent pipeline challenges, cyber insurance and risk transfer strategies, and the practical realities of regulatory compliance across frameworks including BSA requirements.

