21-23 April 2027, Amsterdam, The Netherlands
Third Party & Supply Chain Cyber Security Summit
Learn from your peers and ensure the most effective cyber risk management approach towards your suppliers.
In 216 days
-
How much of your data security is really under your control?
-
What is your risk management approach towards your suppliers?
-
How to secure your network and protect your sensitive data?
-
How to build an action-oriented third party risk program?
About the Summit
Learn the latest case studies on the end-to-end cyber security implementation practices when working with third parties to ensure a truly resilient and secure supply chain network at the Third Party & Supply Chain Cyber Security Summit.
Led by 35+ TOP Information Security professionals from leading companies, the discussion will allow you to see the issue from the perspective of different industries & angles and identify the complex solution to implement in your company.
Join us in Amsterdam and build your end-to-end strategy!
Five reasons to attend
-
Up to date industry insights
Take a chance to discuss the latest industry news and case studies with your peers face-to-face.
-
Quality networking with your industry peers
Develop long-lasting relationships and get support from the community.
-
The best experts from all over the world
Surround yourself with people who are eager to learn and grow professionally.
-
Health and safety are a priority
All appropriate measures are ensured according to the local government directives.
-
TOP destinations for you to explore
Enjoy travelling and enrich yourself with the new city vibes.
Key topics
-
Cyber Risk Quantification
-
Regulations & Compliance
-
IT Security Evaluation & Audit
-
Third Party Risk Management
-
Software Supply Chain Security
-
Supply Chain Attacks & Cyber Resilience
-
End-to-End Cyber Security Assurance
Who Attends Our Event
- Director
- Manager
- Analyst
- Chief
- Head
- Consultant
Our Past Speakers Include
-
George Necola
CISO
Alpiq
-
Katia Winkler
Deputy CISO
Vaillant Group
-
Michael Deckert
Director, Supplier Mgmt. for Cyber Security
Siemens
-
Andrea Szeiler
Global CISO
MVM Group
-
Greg Pollock
Director of Research and Insights
Upguard
-
Florian Scharf
Lead Cyber-TPRM
Zürcher Kantonalbank
-
Christoph Hagenbuch
Cyber Security - Team Lead 3rd Party Mgmt.
E.ON
-
Elli Tsiala
Senior Product Owner Supply Chain Security
ABN AMRO Bank
-
Raymond Stanton
NED / Board Member/
Consultant / CiSO / CRO / CSO -
Monika Atanasova
Head of Cyber TPRM
Raiffeisen Group Switzerland
-
Chris Desforges
Director Software Supply Chain Security
IBM
-
Vladimir Krupnov
Threat Intelligence Lead
Revolut Bank
-
Karthikeyan Ramdass
Cybersecurity Lead Member of Technical Staff
Salesforce
-
Michael Beaupre
Managing Director
RPC3
-
Shafia Zubair
Director, Supply Chain Cybersecurity
Johnson Controls
-
Chuks Ojeme
Independent CISO and Executive Advisor
ex-Brenntag
-
Yelena Pearson
Head TP CIS Oversight
UBS
-
Oriol Cañadas
Information Security Manager
Almirall
-
Milena Nikolic
Cybersecurity Contract Manager
Siemens Energy
-
Predrag Gaic
CISO
Viedoc Technologies AB
-
Tereza Jaskova
Managing Director & Senior Legal Counsel
Alpiq
-
Zuzana Rebrova
Head of Third Party Cyber Risk Management
Swiss Re
-
Elizabeth Dunsmoor
TPRM Principal
Shared Assessments
-
Jennifer Hancock
SVP of Professional Development & Education
Shared Assessments
-
Bharat Raigangar
Global Head AI Cyber Security & Risk
1CxOCSA PhoxHealth
-
Mirco Rohr
Director, Solutions Consulting Services
Mastercard Cybersecurity
-
Joel Brandon
VP EMEA
ProcessUnity
-
Gilbert Kumeta
Director R&D Security, EMEA Brands
Nemetschek SE
-
Jiri Cejka
Independent Cyber Risk & GRC Advisor
-
Ana-Maria Matejić
Senior Cyber Advisor
XLT
-
Al McLaughin
Senior Solutions Architect
BlueVoyant
-
Yuri Pluzhnik
CISO
EMCD
-
Milena Patiño-Villa
Head of Geopolitical Risk & Strategic Intelligence
BBVA
-
Daniel Svartman
Director of ProdSec
Fireblocks
-
Arina Razmyslovich
Research Lead
DNI
-
Harry Farrell-Beales
Senior Account Executive
UpGuard
-
Jan Lemnitzer
Assistant Professor
Copenhagen Business School
-
Stefan Weber
COO Digitale Plattform
DB Fernverkehr AG
-
Sana Yaakoubi
Digital Risk & Assurance Advisor
-
Jerry Hodge
AVP Product Management
Recorded Future
Summit Partners
-
Shared Assessments
Shared Assessments is a global membership organization dedicated to developing the best practices, education and tools to drive third party risk assurance. We are creators of the industry standard third party risk toolkit, used by over 15,000 organizations worldwide.
-
ProcessUnity
ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their evergrowing ecosystem of business partners. By combining the world’s largest third-party risk data exchange, the leading TPRM workflow platform, and powerful artificial intelligence, ProcessUnity extends third-party risk, procurement, and cybersecurity teams so they can cover their entire vendor portfolio. With ProcessUnity, organizations of all sizes reduce assessment work while improving quality, securing intellectual property and customer data so business operations continue to operate uninterrupted. See how at www.processunity.com
-
UpGuard
UpGuard gives security teams unified intelligence across their attack surface, workforce, vendor ecosystem, and trust relationships. Powered. by agentic AI, the company’s CRPM platform turns billions of signals into actionable insights, cuts through noise, and empowers teams to resolve risk faster, reduce manual work, and strengthen resilience.
Company website: https://www.upguard.com/
-
BlueVoyant
BlueVoyant delivers a comprehensive cloud-native security operations platform that provides real-time threat monitoring for networks, endpoints, and supply chains, extending to the clear, deep, and dark web. The platform integrates advanced AI technology with expert human insight to offer extensive protection and swift threat mitigation, ensuring enterprise cybersecurity. Trusted by more than 1,000 clients globally, and the 2024 Microsoft Worldwide Security Partner of the Year, BlueVoyant sets the standard for modern cyber defense solutions.
-
Mastercard Cybersecurity
Mastercard Cybersecurity is helping organizations secure their infrastructure, applications, third parties, and global supply chains by providing deep visibility into risk across internal systems and external relationships. Through unique threat intelligence, cyber risk insights, and multi-layered, cloud-based defense technologies, Mastercard helps organizations and consumers address risk in real-time, enhancing resilience against today’s most sophisticated cyberattacks.
-
PwC
Our clients face diverse challenges, strive to put new ideas into practice and seek expert advice. They turn to us for comprehensive support and practical solutions that deliver maximum value. Whether for a global player, a family business or a public institution, we leverage all of our assets: experience, industry knowledge, high standards of quality, commitment to innovation and the resources of our expert network in 136 countries.
Building a trusting and cooperative relationship with our clients is particularly important to us – the better we know and understand our clients’ needs, the more effectively we can support them.
PwC Germany. More than 15,000 dedicated people at 20 locations. €3.27 billion in turnover. The leading auditing and consulting firm in Germany.
-
ImmuniWeb SA
ImmuniWeb SA is a global cybersecurity company headquartered in Geneva, Switzerland with regional offices in London, Dubai and Washington, DC. Founded in 2019, ImmuniWeb currently serves over 1,000 customers from more than 50 countries. ImmuniWeb is ISO 27001 and ISO 9001 certified and CREST accredited company.
Founded by a team of cybersecurity veterans, the company has been profitable, cashflow positive and rapidly growing since its incorporation. The award-winning ImmuniWeb® AI Platform helps enterprise customers to discover, test and protect their web and mobile applications, APIs and micro services, cloud and network infrastructure, as well as to continually third-party systems processing corporate data to prevent supply chain attacks.
Providing one of the most comprehensive offering of products and services in the industry, ImmuniWeb® AI Platform offers over 25 use cases related to cybersecurity, compliance and privacy. ImmuniWeb’s proprietary AI technology is a recipient of numerous awards and industry recognition for practical usage of AI, including Gartner Cool Vendor, IDC Innovator and SC Awards Europe.
The first award was received back in 2019, outlining corporate vision and strategy to leverage AI far before it became a mainstream after the release of ChatGPT in late 2022. Our Machine Learning and AI technology intelligently automates and accelerates numerous tasks and processes thereby offering a significant cost reduction and faster delivery of service to our customers, eventually creating an unbeatable price/quality ratio.
The ImmuniWeb’s Community Edition helps SMEs, colleges, universities and small municipal governments to test their cybersecurity, privacy and compliance at no cost, currently running over 100,000 daily tests. ImmuniWeb also contributes to sustainable development of the cybersecurity industry via its strategic partnerships with such organizations as the UN ITU, CyberPeace Institute, national CERTs and law enforcement agencies.
-
Recorded Future
Recorded Future is the world's largest threat intelligence company, serving over 1,900 businesses and government organizations across 80 countries. The Recorded Future platform provides the most complete coverage across adversaries, infrastructure, and targets through the Intelligence Graph® containing 200+ billion nodes of specialized threat data. By combining precise, AI-driven analytics with breakthrough autonomous capabilities, Recorded Future enables organizations to automatically operationalize threat intelligence across entire security ecosystems. Recorded Future was acquired by Mastercard (NYSE: MA) in 2024. Headquartered in Boston with offices around the world, Recorded Future continues to lead the evolution from traditional threat intelligence to automated risk mitigation. Learn more at www.recordedfuture.com.
-
Agnostic Intelligence
Agnostic Intelligence is a Swiss-based provider for AI‑powered Cyber Third Party Risk Management. The platform leverages advanced analytics and autonomous AI Agents to conduct assessments, automate onboarding and monitoring, and to detect deviations and supply chain cyber risks. In a landscape of rising supply chain cyber attacks and increasing regulatory scrutiny, Agnostic Intelligence reduces legal, operational, and reputational exposure by fully automating and optimizing the end‑to‑end Cyber-TPRM lifecycle.
-
3rd Risk
Simplified and automated third-party risk management
3rdRisk, Diligent’s AI-native third-party and vendor risk management software is trusted by risk leaders and recognized by Gartner® as a Leader in Third‑Party Risk Management Tools to manage every component of your third-party relationships. Get real-time insights, better control and manage your third-party risks in full compliance with emerging regulations. Stay up to date on incidents with automated notifications and reduce supplier risks, today.
-
CyberVadis
CyberVadis provides enterprises with a cost-effective and scalable solution for third-party cybersecurity risk assessments. Our methodology maps to all major international compliance standards including NIST, ISO 27001, GDPR, and many other privacy and security laws. CyberVadis’ solution combines the speed of automation with the accuracy and effectiveness of a team of experts. We directly engage vendors from all over the world with assessments, validate results with an in-house team of security analysts, and issue companies a standardized cybersecurity rating that they can share with others, along with a detailed improvement plan for increasing their score and the ability to collaborate with clients on implementing better practices.
-
Synopsys
Synopsys builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands.
Our market-leading solutions help developers to secure code as fast as they write it; development and DevSecOps teams to automate testing within development pipelines without compromising velocity; and security teams to proactively manage risk and focus remediation efforts on what matters most.
With Synopsys, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle. -
Fortress
Fortress is the AI-powered cybersecurity company, defending critical infrastructure, government agencies, and their supply chains against cyber threats and mission risks. We know the security and stability of our energy and utilities infrastructure is absolutely critical to sustaining our economy. We know our nation’s defenders deserve the best tools in hand to safeguard our way of life. Understanding third-party risk, illuminating, and resolving vulnerabilities, and ensuring safe operation – these are the challenges we set out to solve. It’s Absolutely Critical.
-
Sonatype
Sonatype is a software supply chain management company. We empower developers and security professionals with intelligent tools to innovate more securely at scale. Our platform addresses every element of an organization’s entire software development life cycle, including third-party open-source code, first-party source code, & containerized code. Sonatype identifies critical security vulnerabilities and this helps organizations develop high-quality, secure software which meets their business needs and those of their end customers and partners. More than 2,000 organizations, including 70% of the Fortune 100, and 15 million software developers rely on our tools and guidance to help them deliver and maintain exceptional and secure software.
-
FortifyData
FortifyData has built a Next Gen Cybersecurity Risk Management platform that enables you to identify and manage your risk exposure across your entire attack surface – This includes external risks, internal risks, cloud configuration risks, and also third-party risks. All of these components are consolidated into one platform that enables you to – perform customizable risk modeling, integrate with other security technologies, produce a financial cyber risk quantification, and a security rating. With FortifyData you will always get the most current and accurate visibility of risk your organization is exposed to. See a demo at www.fortifydata.com.
-
Censys
Censys is the leading Internet Intelligence Platform for Threat Hunting and Exposure Management. We provide governments, enterprises, and researchers with the most comprehensive, accurate, and up-to-date map of the internet to defend attack surfaces and hunt for threats. Censys scans 45x more services than the nearest competitor across the world’s largest certificate database (>10B), reducing the likelihood of a breach by 50%. To learn more, visit censys.com
-
Endor Labs
Endor Labs is a software supply chain security (SSCS) platform for organizations that value developer experience. We help DevSecOps teams build credibility with developer-centric tools that make it safer and faster to use OSS code, easier to detect CI/CD risks, and simpler to comply with SSCS regulations. Existing Software Composition Analysis (SCA) and Application Security Posture Management (ASPM) tools bury teams in uncontextualized data and tens of thousands of false positive alerts. Endor Labs’s new approach cuts 80% of the noise while providing actionable fix information that actually makes developers faster.
The Endor Labs Supply Chain addresses three key pain points and outcomes:
- Open Source Code Security: Endor Labs helps engineers improve application performance and minimize attack surface by selecting and maintaining secure & high quality dependencies across the SDLC. Endor Labs replaces the existing breed of SCA solutions that lack context on code usage, thereby cutting ~80% of SCA noise so teams can focus on what matters. • CI/CD Pipeline Security: Endor Labs helps you discover pipelines and shadow engineering, ensure consistent security tool coverage, monitor the posture of repositories, and implement build integrity verification, all through a single hook and policy-as-code framework integrated into your pipeline.
- Compliance & SBOM: Endor Labs helps teams adhere to standards and regulations by detecting legal risk, generating and ingesting SBOMs/VEX, code signing, and align with NIST, SSDF, and CIS frameworks. We help organizations from startups to Fortune 500, including VMWare, Edelman Financial Engines, and Five9. For more information, visit EndorLabs.com.
-
Immersive Labs
Immersive Labs, the leader in people-centric cyber resilience, empowers your entire organization to effectively prevent, and respond to cyber threats. Our tailored approach continuously assesses, builds, and proves your cyber capabilities, relevant to individual roles, while keeping your team ahead of an ever-evolving threat landscape, including the impact of AI as both a threat and opportunity. We have a relentless focus on evidence, giving you unparalleled visibility into your organization's cyber resilience.
With a single enterprise platform for individuals, teams, and your entire workforce, Immersive Labs helps you take a unified approach to cyber resilience. Join the world's largest organizations and experience complete confidence to manage cyber threats.
-
KY3P SPG
S&P Global (NYSE: SPGI) provides essential intelligence. We enable governments, businesses and individuals with the right data, expertise and connected technology so that they can make decisions with conviction. From helping our customers assess new investments to guiding them through ESG and energy transition across supply chains, we unlock new opportunities, solve challenges and accelerate progress for the world. We are widely sought after by many of the world’s leading organizations to provide credit ratings, benchmarks, analytics and workflow solutions in the global capital, commodity and automotive markets. With every one of our offerings, we help the world’s leading organizations plan for tomorrow, today. For more information, visit www.spglobal.com.
-
SecurityScorecard
SecurityScorecard provides teams with a complete understanding of their attack surface and business ecosystem risk—including partners, contractors, third- and fourth-party vendors, and supply chain. As the industry leader in security ratings, SecurityScorecard is uniquely trusted to quantify risk, quickly respond to cyber-risks, and strengthen cyber defenses.
-
Supplier Shield
Supplier Shield provides advisory, managed service, and a clever platform to help you manage third-party risks in an ever-growing regulatory environment. We help organizations to comply with NIS2, DORA, GDPR, and other regulations (FINMA for Swiss). Most organizations may lack the time, resources, or expertise to keep up. That’s where Supplier Shield comes in, the end-to-end, simplified TPRM solution:
• The right process. Our advisors can ensure your business aligns with NIS2, DORA, GDPR, FINMA, and ESG, helping you create a clear, structured third-party risk framework.
• Resources. Get auditors, cybersecurity specialists, and compliance officers to assess your suppliers and help on the TPRM program. Our resources are available within Supplier Shield and through our partners’ network.
• Supplier mapping. Our cloud platform strives to keep things simple and user-friendly with an interface that tracks supplier risks, and monitor compliance and incidents continuously. Supplier Shield, a brand of Abilene Advisors S.A., a Swiss-based group
-
Bitsight
Bitsight is the global leader in cyber risk intelligence, helping teams make informed risk decisions with the industry’s most extensive external security data and analytics. With 3,300 customers and 65,000 organizations active on its platform, Bitsight delivers real-time visibility into cyber risk and threat exposure—enabling teams to quickly identify vulnerabilities, detect threats, prioritize actions, and mitigate risk across their extended attack surface.
Built on over a decade of market-leading innovation, an unparalleled cyber dataset, and intelligence-driven workflows, Bitsight uncovers security gaps across infrastructure, cloud environments, identities, and third- and fourth-party ecosystems. From security operations and GRC teams to the boardroom, Bitsight provides the unified intelligence backbone organizations need to proactively address exposures before they impact performance.
For more information, visit bitsight.com, read our blog, or connect with us on LinkedIn.
Event Partners
-
International TPRM Alliance
The International TPRM Alliance is your global gateway to excellence in third-party and supply-chain risk management. As the first community-driven organization based in the EMEA and JAPAC regions, we are dedicated to empowering TPRM professionals and organizations worldwide. Whether you are here to enhance your professional skills, stay updated on industry trends, or connect with fellow TPRM experts, our platform offers everything you need to succeed in the evolving world of risk management. The International TPRM Alliance, formerly the TPRM-with-Yedhu WhatsApp group, was founded in July 2020 with a mission to support TPRM professionals impacted by the COVID-19 pandemic. What began as a small group of five members has grown into a global network of over 150 TPRM experts dedicated to advancing the field of Third Party and Supply Chain Risk Management. We are the first TPRM Community Development organization based out of the EMEA and JAPAC regions, committed to fostering a collaborative environment where TPRM professionals can learn, grow, and lead. Our initiatives include hosting monthly virtual roundtables, organizing an annual TPRM summit, and providing a comprehensive resource database for our members.
-
CyAN
Cybersecurity Advisors Network (CyAN) is an international platform of advisors in cybersecurity, privacy, cyber law, cyber forensics, cyber mental health and trust & safety. The ambition is to strengthen the security and safety in the digital environment through a multi-disciplinary approach based on mutual trust and on complementarity of profiles and experiences of its global members.
Media Partners
Our past events
Nothing can replace the value of dozens of the brightest minds gathering in one room. Join us to make yours.
Lisbon All photos from 2025
Barcelona All photos from 2023
Amsterdam All photos from 2022
Lisbon All photos from 2020
Barcelona All photos from 2019
Feedback & Key Takeaways
How supply chain cyber risks have
evolved over the last three decades
The supply chain risks have evolved a lot since the early 90s. Listen to the experts on how to approach them today.
FAQ
How do I register for the Summit and how much does it cost?
The registration is available online here. On the registration page, you can also check early bird and standard registration rates. If you would like to pay via bank transfer, please contact us at [email protected] and we will advise you on further steps shortly.
What is included in the delegate pass?
The standard delegate pass includes all physical & online conference materials, coffee breaks with snacks, hot lunches, and cocktail reception. Please note that accommodation is not included in the registration fee and must be booked separately. Contact us at [email protected] for the conference hotel discounted rates for our group.
Is there any group discount available?
Yes, we are delighted to provide the groups of 3 and more participants with a discount. The more people you bring, the bigger is your discount!
If I plan to attend only one day of the Summit, is it possible to get a discount?
Absolutely! Contact us at [email protected] with your request and we will provide you with more details.
What is the refund policy?
In case you would like to cancel your participation for some unexpected eventualities, such requests must be submitted in written form and sent by post or email four weeks prior to the event in order to obtain a full credit note for any future event organised by GIA Global Group s.r.o. The fees charged are strictly nonrefundable.
In the event that GIA Global Group s.r.o. cancels the conference, delegate payments at the date of cancellation will be refunded in full. In the event that GIA Global Group s.r.o. postpones a conference, delegate payments will be credited towards the rescheduled date.
May I transfer my pass to someone else?
Yes, places within a company are transferable without any charge. In order to do so, please notify us in advance at [email protected]
How can I speak at the Summit?
You can express your interest to speak at the Summit by submitting the form here.
How can we sponsor the Summit?
You can check more details on the partnership opportunities here.
Is there an option to attend the Summit virtually?
Although the participation in-person gives you much more opportunities in terms of learning & networking, we do realise that not everyone can join us live. That is why we provide an option to attend the Summit virtually for a reduced registration rate. The virtual pass includes access to the event platform where you can watch main agenda presentations, check exhibition area, connect and chat with participants. For more details please contacts us at [email protected]
Summit location
Hotel Novotel Amsterdam City
Get directions