How resilient is your organisation really? Do you know where your greatest third-party vulnerabilities sit? If a serious cyber incident happened tomorrow, could your business make good decisions quickly and under pressure? And when it comes to AI, are you delivering enough value to justify the risks?
These are increasingly important questions for cyber security leaders that will be at the heart of the Richmond Cyber Security Forum, taking place on 24 September 2026 at the Four Seasons Hotel London at Park Lane.
The forum brings together CISOs and senior cyber security executives from mid-sized and large UK organisations to explore the strategic challenges shaping the role, from organisational resilience and supply chain risk to incident preparedness, executive communication and AI.
The day opens with a conversation between Dr Victoria Baines, Professor of Information Technology and Professor Emerita at Gresham College, and Purvi Kay, Head of Cyber and Information Security at a UK defence prime. Together, they will examine how organisations can prioritise security investment, reduce risk exposure and build long-term resilience in an increasingly complex threat landscape.
Embedding resilience into technology and supply chains
As organisations expand their digital ecosystems and rely on increasingly complex supplier networks, how can security leaders reduce risk without slowing innovation?
The forum will explore how resilience can be built into technology delivery and third-party relationships from the outset, including security-by-design principles, aligning security controls with business objectives and improving collaboration across functions.
There will also be a focus on the challenge of maintaining accountability, assurance and visibility across interconnected vendor environments.
These discussions will be led by Barbara Aung, Chief Information Security Officer at Virgin Media O2, and Stuart Frost, Head of Enterprise Security and Risk Management at the UK Government.
Cyber crisis: from prepared response to business continuity
Prevention remains critical, but no organisation can eliminate cyber risk entirely. So how effectively is your organisation prepared to respond when an incident occurs?
The forum's crisis response sessions will focus on decision-making, governance and operational readiness under pressure. Topics will include incident leadership structures, making decisions with incomplete information, balancing competing business priorities, and the value of planning and rehearsing response processes.
The discussions will also examine how threat actors select targets, where organisations are most vulnerable, and why some security initiatives fail to deliver their intended outcomes.
Contributing to these discussions will be New Look's Lynda Petherick, COO & CIO and soon-to-be CEO, Joe Kelly, Head of Information Security (CISO), and Charles White, CEO at The Cyber Scheme.
The modern cyber leader: influencing beyond the security function
What does effective cyber leadership look like when the human and organisational dimensions of security are just as important as the technical ones?
Today's cyber leaders are expected to do far more than manage technology and security controls: they need to influence board-level decisions, shape organisational culture, develop their people and sustain high-performing teams in demanding environments.
A dedicated programme stream will explore behavioural change, security culture, professional standards, governance and ethics, alongside practical approaches to communicating cyber risk in business terms. It will also look at leadership resilience, psychological safety and how security leaders can support sustained performance within their teams.
Sessions will be delivered by Janette Bonar Law, Information Security Operations Manager at Channel 4; Simon Hepburn, Visiting Professor at Aston University; Tamlynn Deacon, Founder of Empower Authentic Coaching; and Annabel Berry, Founder and Director of Leading Cyber.
AI's balancing act: managing risk while delivering value
How can organisations deliver AI’s potential while understanding and managing the risks? The forum discussions will examine the practical questions around implementation: can AI genuinely reduce risk, improve incident response and deliver measurable operational value? What governance and performance measures are needed? And how should security leaders decide whether an AI initiative is ready to scale, or whether it is time to conclude?
The discussion will be led by Grant Ongers, Security Advisor, Ambassador and Architect, before the topic returns in the closing panel with Deborah Saffer, Director Information Security at Liberty Specialty Markets; Lee Howard, Chief Information Security Officer at Evri; and Joe Kelly, Head of Information Security (CISO) at New Look, moderated by Ant Davis, Host of The Awareness Angle.
Through this programme of workshops, peer discussion groups and professional development sessions, delegates will share experiences, explore emerging risks and gain practical insights, while also connecting with technology and service providers bringing different perspectives and expertise to the day.
The Richmond Cyber Security Forum is a complimentary event for senior cyber security leaders.
Request an invitation to join the conversation on 24 September 2026 or for more information.
Brought to you by:

Written by
Tanya Cheney
Conference Manager
Richmond Events
Tanya Cheney is Conference Manager at Richmond Events, where she researches and develops conference programmes and speakers for senior technology and business leaders. Her background includes PR, events, speaker management and corporate communications at PC Magazine & PC Direct, Inmarsat and NTL Business. She now works closely with senior industry leaders and practitioners to shape programmes around the challenges organisations are navigating today, ensuring the forums lead with meaningful peer-to-peer discussion.