CySec 2026

Full schedule

Two days of keynotes, panels and hands-on workshops.

RegistrationCeremonyOperational Technology (OT), ICS & SCADA SecurityCritical Infrastructure CybersecurityNetworkingCyber Workforce Development, Skills & LeadershipNational Cybersecurity Strategy & Public–Private PartnershipNational Cybersecurity Strategy & Public–Private PartnershipsCommunityBreakKeynoteClosingCyber Threat Intelligence & Threat HuntingCloud Security, Zero Trust & Secure ArchitectureAI for Cyber Defense & Responsible AI SecurityData Protection, Privacy & Regulatory ComplianceIncident Response, Crisis Management & Cyber ResilienceRansomware Defense & Business Continuity PlanningWorkshop Room A
  • 07:4508:30

    Registration of Participants; Arrival of Speakers & Guests

    Badge collection and arrivals at The Rizqun International Hotel. (Level 8: CBCTF teams register, set up and the competition begins.)

    Registration
  • 08:3008:45

    Arrival of Invited Guests

    Government officials, corporate officials and diplomats.

    Ceremony Plenary Hall
  • 08:4509:00

    Arrival of Members of the Legislative Council

    Ceremony Plenary Hall
  • 09:0009:05

    Arrival of the Guest of Honour

    Yang Berhormat Dato Seri Setia Awang Mohd Riza bin Dato Paduka Haji Mohd Yunos, Minister of Transport and Infocommunications, as the Minister-in-charge of Cybersecurity.

    Ceremony Plenary Hall
  • 09:0509:10

    Recital of Surah Al-Fatihah

    Ceremony Plenary Hall
  • 09:1009:15

    Safety Briefing

    Ceremony Sutra HallTo be announced
  • 09:1509:20

    Opening Remarks

    By Yang Mulia Shamsul Bahri bin Haji Kamis, Interim Commissioner, Cyber Security Brunei (CSB).

    Ceremony Plenary Hall
  • 09:2009:30

    Keynote Address by the Guest of Honour

    Ceremony Plenary Hall
  • 09:3009:35

    Official Launch of CySec 2026

    Official launch of the Brunei Cyber Security Conference 2026 by the Guest of Honour.

    Ceremony Plenary Hall
  • 09:3509:55

    Exchange of MOUs & Awards Presentation

    Announcement of The Opening of Universiti Brunei Darussalam (UBD) Cybersecurity and Digital Forensics Laboratory, Powered by Information Technology Protective Security Services Sdn Bhd (ITPSS) & Cyber Security Brunei (CSB) | Top Women in Security ASEAN Region 2026 Finalist (Brunei) Award Presentation | Exchanging of Memoranda of Understanding (MoUs) | Official Handover of Key from Information Technology Protective Security Services Sdn Bhd (ITPSS) to Brunei Cybersecurity Association (BCSA)

    Ceremony Plenary Hall
  • 09:5510:15

    Featured Speech

    By Mr. Frédéric Margotton, Cyber Attaché — ASEAN Region, High Commission of Canada in Singapore.

    Ceremony Plenary Hall
  • 10:1510:30

    Exhibition Tour & Group Photo

    The Guest of Honour tours the exhibition booths, followed by the group photo session in Songket Hall.

    Ceremony Songket Hall
  • 10:3010:40

    Fortinet OT Security Platform for Critical Infrastructure

    Discover the key trends and security challenges shaping the Operational Technology (OT) landscape in Critical Infrastructure (CI). This session outlines actionable best practices for safeguarding Critical Infrastructure and demonstrates how the Fortinet AI-Powered OT Security Platform—powered by OT-centric Threat Intelligence—delivers a unified, single-platform approach to safely securing IT/OT convergence.

    Operational Technology (OT), ICS & SCADA Security Conference Hall AEntoro Wijaya Budiman · Solution Architect, Operational Technology
  • 10:3010:40

    Attack Sophistication at Zero Cost

    It was previously thought that nation states and  sophisticated actors are the ones mostly kept targeting CIIs, today this has changed due to AI. We will have to start asking "who has the intent" now instead of "who can"

    Critical Infrastructure Cybersecurity Plenary HallDave Gurbani · Group CEO
  • 10:4010:50

    Beyond the Patch: Securing Brunei's CII - Vulnerability Management vs Exposure Management

    In cybersecurity, "green" scanning reports often foster a dangerous illusion of safety. For years, organizations have relied heavily on traditional Vulnerability Management (VM)—meticulously scanning for software bugs (CVEs) and applying patches. However, as Brunei Darussalam accelerates its digital economy under Wawasan Brunei 2035, our attack surfaces have outgrown traditional scan-and-patch cycles. Attackers are increasingly bypassing code-level defenses by exploiting untracked shadow IT, cloud misconfigurations, and over-privileged identities. In this high-impact, visual briefing at CySec 2026, we unpack the critical operational shift from tactical Vulnerability Management to strategic Exposure Management (EM). Using clear real-world metaphors this session will reveal the stark disconnect between perceived security and actual control resilience. We will dive into real-world threat simulation data showing why highly feared, headline-making threats are frequently blocked, while quiet, untested delivery methods achieve a startling 87% bypass rate against active corporate defenses. Crucially, this session translates global frameworks like Gartner’s Continuous Threat Exposure Management (CTEM) into actionable steps for Brunei's local landscape. We will discuss direct alignment with Brunei’s Cybersecurity Order 2023, the newly enforced Cyber Security Code of Practice for Critical Information Infrastructure (CII), and AITI's Personal Data Protection Order (PDPO) 2025. Attendees will walk away with a practical, 30-day proactive roadmap—covering automated asset discovery, privilege minimization, and virtual patching—to systematically shrink their organizational blast radius and protect the Sultanate's digital sovereign space. Key Takeaways for Attendees: • The Paradigm Shift: Understand why Vulnerability Management remains essential for code-level system hardening, but why Exposure Management is required to map, prioritize, and validate real-world attack paths. • The Control Validation Gap: Analyze the data-driven reality of how quiet threat delivery mechanisms slip past traditional defensive controls despite "compliant" patching records. • National Compliance Blueprint: Learn how to seamlessly operationalize compliance with CSB's Code of Practice and the PDPO 2025 using a continuous exposure-based approach. • Bruneian 30-Day Action Plan: Obtain four immediate, highly practical security wins (Find, Restrict, Context, Shield) tailored for local IT and security operations teams. Target Audience: This session is highly recommended for CII Owners, Chief Information Security Officers (CISOs), Risk & Compliance Managers, and IT Security Directors within Brunei's banking, energy, telecommunications, transport, and public services sectors.

    Critical Infrastructure Cybersecurity Plenary HallAriffin Sabli · Head of Security Research Team
  • 10:4010:50

    Five Years, Five Breaches: Rethinking ASEAN's Cyber Defense

    Recent cyber incidents across Southeast Asia have disrupted telecommunications, healthcare, government services, transportation, and financial systems, exposing vulnerabilities that organizations can no longer afford to ignore. This session examines five major cyber incidents across ASEAN and explores the common attack vectors behind them, including supply chain compromises, exposed internet-facing assets, credential misuse, and emerging AI-assisted threats. Participants will gain practical insights into how organizations can strengthen visibility, improve resilience, and defend against evolving cyber risks in an increasingly complex threat landscape. GMO Cybersecurity by Ierae and Innov8 Labs will also share how AI-powered Security Operations Centre (SOC) capabilities and External Attack Surface Management (EASM) can help organizations enhance cybersecurity effectiveness, improve threat detection, and build resilience without significantly increasing resources.

    Operational Technology (OT), ICS & SCADA Security Conference Hall AKosuke Ito · PhD | Executive Officer & General Manager, Global Strategy Headquarters
  • 10:5011:00

    Autonomous AI Defense for Critical Infrastructure — How SentinelOne Stops Threats Before They Escalate

    Invited guest presentation — not sponsor-bookable.

    Critical Infrastructure Cybersecurity Plenary HallJason Siew · Senior Consultant
  • 10:5011:00

    Operational Resilience Through Collective Intelligence

    As operational environments become more connected and complex, resilience is no longer only about preventing or responding to cyber incidents. It is also about how organisations learn, adapt and make better decisions from the experiences of others. This short session explores how collective intelligence can strengthen operational resilience by turning shared incidents, vulnerabilities, observations and lessons learned into practical insights for critical infrastructure operators. Rather than asking only, “How do we protect our own environment?”, the session introduces a broader question: “What can we learn collectively today that helps us make better operational decisions tomorrow?” The session will share practical observations on how trusted industry collaboration can help organisations challenge assumptions, identify common risks earlier and strengthen resilience across the wider OT community.

    Operational Technology (OT), ICS & SCADA Security Conference Hall AAJ Eserjose · Regional Director
  • 11:0011:30

    Critical Infrastructure Cybersecurity — Panel Discussion

    Panel discussion: Critical Infrastructure Cybersecurity.

    Critical Infrastructure Cybersecurity Plenary HallTo be announced
  • 11:0012:00

    Operational Technology (OT), ICS & SCADA Security — Panel Discussion

    Panel discussion: Operational Technology (OT), ICS & SCADA Security.

    Operational Technology (OT), ICS & SCADA Security Conference Hall ATo be announced
  • 12:0013:30

    Lunch and Networking

    Lunch served; exhibition floor open.

    Networking Exhibition Floor
  • 13:3013:40

    When AI Gets an Identity: Securing the Next Digital Workforce

    AI is evolving from assistants that support employees into agents that can access data, interact with systems, and execute business processes. This creates a new identity challenge: who owns the agent, what can it access, and how are its actions governed? This session explores how Identity and Access Management and Zero Trust must evolve to secure AI agents as part of the future digital workforce.

    Cyber Workforce Development, Skills & Leadership Conference Hall ASiti Nadzirah Zaini
  • 13:3013:40

    Securing AI That Acts: Governing Agentic AI in the Age of Autonomy

    National Cybersecurity Strategy & Public–Private Partnership Plenary HallMohamad Azad Zaki Haji Mohd Tahir · Chief Information Security Officer
  • 13:3013:40

    National Cybersecurity Strategy & Public–Private Partnerships — Presentation #1

    National Cybersecurity Strategy & Public–Private Partnerships.

    National Cybersecurity Strategy & Public–Private Partnerships Plenary HallTo be announced
  • 13:4013:50

    BruneiID: From Digital Identity to Digital Trust

    As digital services become more interconnected, establishing trust in who is interacting with them becomes a critical part of cybersecurity. This presentation shares Brunei’s experience in developing BruneiID as a national digital identity capability and explores how trusted identity can support more secure, consistent and privacy-conscious digital interactions across the wider ecosystem. The session looks at digital identity not simply as a login mechanism, but as an important foundation for building digital trust.

    National Cybersecurity Strategy & Public–Private Partnership Plenary HallAmallul Latif · Head of Programme Management Office
  • 13:4013:50

    Building Talent for the Cybersecurity Workforce

    Building Talent for the Cybersecurity Workforce gives an overview of what working in cybersecurity is really like (after the morning coffee, of course) and how aspiring professionals can prepare for the workforce. The session shares practical ways to build real skills through hands-on labs, personal projects, CTFs and community involvement.

    Cyber Workforce Development, Skills & Leadership Conference Hall ARabbani Amirrudin · Cybersecurity Officer
  • 13:5014:00

    The Quantum Countdown: Establishing Trust in an Age of Cryptographic Disruption

    The quantum countdown has begun. As quantum computing advances, the "Harvest Now, Decrypt Later" threat is already active, with adversaries intercepting sensitive data now to decrypt tomorrow. To safeguard critical assets, organizations must build quantum resilience today. Thales empowers organizations to navigate this cryptographic disruption with confidence. Our quantum-resistant solutions and agile encryption platforms enable a seamless transition to Post-Quantum Cryptography (PQC). Discover how Thales establishes trust in an uncertain future, delivering the visibility, agility, and robust defense needed to secure your critical assets today.

    National Cybersecurity Strategy & Public–Private Partnership Plenary HallMelvin Koh · Thales Technical manager ASEAN
  • 13:5014:00

    The Pipeline Nobody Funded

    cyber673 has never had a funding line, a strategy document, or a five-year plan. It has had a room at Brunei Innovation Lab, a rotating supply of pizza from four very patient local firms, and a Wednesday night that kept coming round whether we were ready or not. This talk follows the twenty months since the first session, told through the things we had to build every time the community outgrew what it had. A Microsoft Form became an events platform, because fourteen sessions in we still could not say who kept turning up. Monthly talks became HACK101, a hands-on run through networks, web and mobile that somehow draws over thirty people every time. A careers panel became a job-seeker pipeline, because people kept asking us where to go next and we had run out of ways to say "good question." None of it was clever. All of it is repeatable. That is the whole pitch.

    Cyber Workforce Development, Skills & Leadership Conference Hall AIzdihar Sulaiman · Principal Security Consultant
  • 14:0014:10

    Cyber Workforce Development, Skills & Leadership — Presentation #4 (Invited guest)

    Invited guest presentation — not sponsor-bookable.

    Cyber Workforce Development, Skills & Leadership Conference Hall ARic Chen · Director
  • 14:0014:10

    Strengthening Brunei Darussalam’s Cybersecurity Ecosystem through National and Public-Private Cooperation

    The presentation introduces ITU’s cybersecurity work and the Global Cybersecurity Index, with a focused overview of Brunei Darussalam’s strengths and potential areas for continued development across the five GCI pillars. It also explores how government and the private sector can collaborate throughout the lifecycle of a National Cybersecurity Strategy, drawing on international guidance and country examples.

    National Cybersecurity Strategy & Public–Private Partnership Plenary HallCalvin Chan · Programme Officer
  • 14:0015:00

    Ladies in Cyber Networking Session

    Connect with women building Brunei's cybersecurity community.

    Community Room C
  • 14:1014:50

    Cyber Workforce Development, Skills & Leadership — Panel Discussion

    Panel discussion: Cyber Workforce Development, Skills & Leadership.

    Cyber Workforce Development, Skills & Leadership Conference Hall ATo be announced
  • 14:1014:50

    National Cybersecurity Strategy & Public–Private Partnerships — Panel Discussion

    Panel discussion: National Cybersecurity Strategy & Public–Private Partnerships.

    National Cybersecurity Strategy & Public–Private Partnership Plenary HallTo be announced
  • 15:3016:00

    Break (Refreshment)

    Afternoon refreshments on the exhibition floor. (Level 8: CBCTF competition ends.)

    Break Exhibition Floor
  • 16:0017:00

    Prize Presentation: CBCTF

    Prize presentation for the Capture-the-Flag competition (Brunei CBCTF, run on Level 8).

    Keynote Plenary Hall
  • 17:0017:00

    End of Day 1

    Closing Main Hall

Have a ticket? Open your attendee portal to star sessions and download your personal agenda — including any closed-door sessions you're invited to.