CySec 2026
Full schedule
Two days of keynotes, panels and hands-on workshops.
- 07:45 – 08:30
Registration of Participants; Arrival of Speakers & Guests
Badge collection and arrivals at The Rizqun International Hotel. (Level 8: CBCTF teams register, set up and the competition begins.)
- 08:30 – 08:45
Arrival of Invited Guests
Government officials, corporate officials and diplomats.
- 08:45 – 09:00
Arrival of Members of the Legislative Council
- 09:00 – 09:05
Arrival of the Guest of Honour
Yang Berhormat Dato Seri Setia Awang Mohd Riza bin Dato Paduka Haji Mohd Yunos, Minister of Transport and Infocommunications, as the Minister-in-charge of Cybersecurity.
- 09:05 – 09:10
Recital of Surah Al-Fatihah
- 09:10 – 09:15
Safety Briefing
- 09:15 – 09:20
Opening Remarks
By Yang Mulia Shamsul Bahri bin Haji Kamis, Interim Commissioner, Cyber Security Brunei (CSB).
- 09:20 – 09:30
Keynote Address by the Guest of Honour
- 09:30 – 09:35
Official Launch of CySec 2026
Official launch of the Brunei Cyber Security Conference 2026 by the Guest of Honour.
- 09:35 – 09:55
Exchange of MOUs & Awards Presentation
Announcement of The Opening of Universiti Brunei Darussalam (UBD) Cybersecurity and Digital Forensics Laboratory, Powered by Information Technology Protective Security Services Sdn Bhd (ITPSS) & Cyber Security Brunei (CSB) | Top Women in Security ASEAN Region 2026 Finalist (Brunei) Award Presentation | Exchanging of Memoranda of Understanding (MoUs) | Official Handover of Key from Information Technology Protective Security Services Sdn Bhd (ITPSS) to Brunei Cybersecurity Association (BCSA)
- 09:55 – 10:15
Featured Speech
By Mr. Frédéric Margotton, Cyber Attaché — ASEAN Region, High Commission of Canada in Singapore.
- 10:15 – 10:30
Exhibition Tour & Group Photo
The Guest of Honour tours the exhibition booths, followed by the group photo session in Songket Hall.
- 10:30 – 10:40
Fortinet OT Security Platform for Critical Infrastructure
Discover the key trends and security challenges shaping the Operational Technology (OT) landscape in Critical Infrastructure (CI). This session outlines actionable best practices for safeguarding Critical Infrastructure and demonstrates how the Fortinet AI-Powered OT Security Platform—powered by OT-centric Threat Intelligence—delivers a unified, single-platform approach to safely securing IT/OT convergence.
- 10:30 – 10:40
Attack Sophistication at Zero Cost
It was previously thought that nation states and sophisticated actors are the ones mostly kept targeting CIIs, today this has changed due to AI. We will have to start asking "who has the intent" now instead of "who can"
- 10:40 – 10:50
Beyond the Patch: Securing Brunei's CII - Vulnerability Management vs Exposure Management
In cybersecurity, "green" scanning reports often foster a dangerous illusion of safety. For years, organizations have relied heavily on traditional Vulnerability Management (VM)—meticulously scanning for software bugs (CVEs) and applying patches. However, as Brunei Darussalam accelerates its digital economy under Wawasan Brunei 2035, our attack surfaces have outgrown traditional scan-and-patch cycles. Attackers are increasingly bypassing code-level defenses by exploiting untracked shadow IT, cloud misconfigurations, and over-privileged identities. In this high-impact, visual briefing at CySec 2026, we unpack the critical operational shift from tactical Vulnerability Management to strategic Exposure Management (EM). Using clear real-world metaphors this session will reveal the stark disconnect between perceived security and actual control resilience. We will dive into real-world threat simulation data showing why highly feared, headline-making threats are frequently blocked, while quiet, untested delivery methods achieve a startling 87% bypass rate against active corporate defenses. Crucially, this session translates global frameworks like Gartner’s Continuous Threat Exposure Management (CTEM) into actionable steps for Brunei's local landscape. We will discuss direct alignment with Brunei’s Cybersecurity Order 2023, the newly enforced Cyber Security Code of Practice for Critical Information Infrastructure (CII), and AITI's Personal Data Protection Order (PDPO) 2025. Attendees will walk away with a practical, 30-day proactive roadmap—covering automated asset discovery, privilege minimization, and virtual patching—to systematically shrink their organizational blast radius and protect the Sultanate's digital sovereign space. Key Takeaways for Attendees: • The Paradigm Shift: Understand why Vulnerability Management remains essential for code-level system hardening, but why Exposure Management is required to map, prioritize, and validate real-world attack paths. • The Control Validation Gap: Analyze the data-driven reality of how quiet threat delivery mechanisms slip past traditional defensive controls despite "compliant" patching records. • National Compliance Blueprint: Learn how to seamlessly operationalize compliance with CSB's Code of Practice and the PDPO 2025 using a continuous exposure-based approach. • Bruneian 30-Day Action Plan: Obtain four immediate, highly practical security wins (Find, Restrict, Context, Shield) tailored for local IT and security operations teams. Target Audience: This session is highly recommended for CII Owners, Chief Information Security Officers (CISOs), Risk & Compliance Managers, and IT Security Directors within Brunei's banking, energy, telecommunications, transport, and public services sectors.
- 10:40 – 10:50
Five Years, Five Breaches: Rethinking ASEAN's Cyber Defense
Recent cyber incidents across Southeast Asia have disrupted telecommunications, healthcare, government services, transportation, and financial systems, exposing vulnerabilities that organizations can no longer afford to ignore. This session examines five major cyber incidents across ASEAN and explores the common attack vectors behind them, including supply chain compromises, exposed internet-facing assets, credential misuse, and emerging AI-assisted threats. Participants will gain practical insights into how organizations can strengthen visibility, improve resilience, and defend against evolving cyber risks in an increasingly complex threat landscape. GMO Cybersecurity by Ierae and Innov8 Labs will also share how AI-powered Security Operations Centre (SOC) capabilities and External Attack Surface Management (EASM) can help organizations enhance cybersecurity effectiveness, improve threat detection, and build resilience without significantly increasing resources.
- 10:50 – 11:00
Autonomous AI Defense for Critical Infrastructure — How SentinelOne Stops Threats Before They Escalate
Invited guest presentation — not sponsor-bookable.
- 10:50 – 11:00
Operational Resilience Through Collective Intelligence
As operational environments become more connected and complex, resilience is no longer only about preventing or responding to cyber incidents. It is also about how organisations learn, adapt and make better decisions from the experiences of others. This short session explores how collective intelligence can strengthen operational resilience by turning shared incidents, vulnerabilities, observations and lessons learned into practical insights for critical infrastructure operators. Rather than asking only, “How do we protect our own environment?”, the session introduces a broader question: “What can we learn collectively today that helps us make better operational decisions tomorrow?” The session will share practical observations on how trusted industry collaboration can help organisations challenge assumptions, identify common risks earlier and strengthen resilience across the wider OT community.
- 11:00 – 11:30
Critical Infrastructure Cybersecurity — Panel Discussion
Panel discussion: Critical Infrastructure Cybersecurity.
- 11:00 – 12:00
Operational Technology (OT), ICS & SCADA Security — Panel Discussion
Panel discussion: Operational Technology (OT), ICS & SCADA Security.
- 12:00 – 13:30
Lunch and Networking
Lunch served; exhibition floor open.
- 13:30 – 13:40
When AI Gets an Identity: Securing the Next Digital Workforce
AI is evolving from assistants that support employees into agents that can access data, interact with systems, and execute business processes. This creates a new identity challenge: who owns the agent, what can it access, and how are its actions governed? This session explores how Identity and Access Management and Zero Trust must evolve to secure AI agents as part of the future digital workforce.
- 13:30 – 13:40
Securing AI That Acts: Governing Agentic AI in the Age of Autonomy
- 13:30 – 13:40
National Cybersecurity Strategy & Public–Private Partnerships — Presentation #1
National Cybersecurity Strategy & Public–Private Partnerships.
- 13:40 – 13:50
BruneiID: From Digital Identity to Digital Trust
As digital services become more interconnected, establishing trust in who is interacting with them becomes a critical part of cybersecurity. This presentation shares Brunei’s experience in developing BruneiID as a national digital identity capability and explores how trusted identity can support more secure, consistent and privacy-conscious digital interactions across the wider ecosystem. The session looks at digital identity not simply as a login mechanism, but as an important foundation for building digital trust.
- 13:40 – 13:50
Building Talent for the Cybersecurity Workforce
Building Talent for the Cybersecurity Workforce gives an overview of what working in cybersecurity is really like (after the morning coffee, of course) and how aspiring professionals can prepare for the workforce. The session shares practical ways to build real skills through hands-on labs, personal projects, CTFs and community involvement.
- 13:50 – 14:00
The Quantum Countdown: Establishing Trust in an Age of Cryptographic Disruption
The quantum countdown has begun. As quantum computing advances, the "Harvest Now, Decrypt Later" threat is already active, with adversaries intercepting sensitive data now to decrypt tomorrow. To safeguard critical assets, organizations must build quantum resilience today. Thales empowers organizations to navigate this cryptographic disruption with confidence. Our quantum-resistant solutions and agile encryption platforms enable a seamless transition to Post-Quantum Cryptography (PQC). Discover how Thales establishes trust in an uncertain future, delivering the visibility, agility, and robust defense needed to secure your critical assets today.
- 13:50 – 14:00
The Pipeline Nobody Funded
cyber673 has never had a funding line, a strategy document, or a five-year plan. It has had a room at Brunei Innovation Lab, a rotating supply of pizza from four very patient local firms, and a Wednesday night that kept coming round whether we were ready or not. This talk follows the twenty months since the first session, told through the things we had to build every time the community outgrew what it had. A Microsoft Form became an events platform, because fourteen sessions in we still could not say who kept turning up. Monthly talks became HACK101, a hands-on run through networks, web and mobile that somehow draws over thirty people every time. A careers panel became a job-seeker pipeline, because people kept asking us where to go next and we had run out of ways to say "good question." None of it was clever. All of it is repeatable. That is the whole pitch.
- 14:00 – 14:10
Cyber Workforce Development, Skills & Leadership — Presentation #4 (Invited guest)
Invited guest presentation — not sponsor-bookable.
- 14:00 – 14:10
Strengthening Brunei Darussalam’s Cybersecurity Ecosystem through National and Public-Private Cooperation
The presentation introduces ITU’s cybersecurity work and the Global Cybersecurity Index, with a focused overview of Brunei Darussalam’s strengths and potential areas for continued development across the five GCI pillars. It also explores how government and the private sector can collaborate throughout the lifecycle of a National Cybersecurity Strategy, drawing on international guidance and country examples.
- 14:00 – 15:00
Ladies in Cyber Networking Session
Connect with women building Brunei's cybersecurity community.
- 14:10 – 14:50
Cyber Workforce Development, Skills & Leadership — Panel Discussion
Panel discussion: Cyber Workforce Development, Skills & Leadership.
- 14:10 – 14:50
National Cybersecurity Strategy & Public–Private Partnerships — Panel Discussion
Panel discussion: National Cybersecurity Strategy & Public–Private Partnerships.
- 15:30 – 16:00
Break (Refreshment)
Afternoon refreshments on the exhibition floor. (Level 8: CBCTF competition ends.)
- 16:00 – 17:00
Prize Presentation: CBCTF
Prize presentation for the Capture-the-Flag competition (Brunei CBCTF, run on Level 8).
- 17:00 – 17:00
End of Day 1
Have a ticket? Open your attendee portal to star sessions and download your personal agenda — including any closed-door sessions you're invited to.