Purple Ocean - inspiring change and creating value

The ISACA Risk Event will take place for the 5th time on Wednesday, November 6, 2024; our first lustrum. We will therefore provide an even more substantive and interesting program than in previous years.

The conference takes place in collaboration with IIA, NOREA and PvIB.

We proudly thank our sponsors for making Risk Event 2024 possible.

Risk Event 2024

Purple Ocean - inspiring change and creating value

The central theme this year is Purple Ocean – inspiring change and creating value.

This day we will highlight four tracks

  • Governance
  • Risk
  • Regulatory
  • Resilience

Each track contains various seminars from top speakers, where the participant can choose the program that best fits their wishes and interests. You will find all names of speakers on the program page. 

Workshop: This year we also add a separate workshop stream to the program. There are only limited places available for the workshops.

During the day (breaks, lunch and dinner) there is plenty of time to talk with speakers and participants.

The ISACA Risk Event mainly focuses on (IT) Risk Managers and Risk Consultants, Security/Privacy and Cyber specialists, IT Auditors, CIOs, (Senior) Management, Thought leaders in organizations, Business information managers, Application managers, Project and service managers and consultants in the IT industry.

Aftermovie

Experience the atmosphere and insights of Risk Event 2024. Curious what’s next? Join us this year and connect with the leaders in IT risk and security.

Programme Risk Event 2024

Explore four parallel tracks, and a workshop track. Each with its own focus on today's most pressing risks. Choose a Podium to view sessions from that track only. Curious to learn more? Click on a session title to see details about the speaker and topic.

Regulatory

Podium I

Resilience

Podium II

Governance

Podium III

Risk

Podium voor de Kunst

Workshop

Foyer III
08.30 - 09.15
Arrival, Registration, Coffee
Dwayne Valkenburg
President ISACA NL Chapter
IT Auditor en IT Risk & Compliance Manager
09.15 - 09.30
Podium I
Opening Talk by ISACA Netherlands Chapter President
Dwayne Valkenburg
President ISACA NL Chapter
IT Auditor en IT Risk & Compliance Manager

My name is Dwayne Valkenburg, I work as an IT Auditor and IT Risk & Compliance Manager. Since 2006, I have been active in the Managed IT Services & IT Outsourcing sector as an IT Engineer, switching to the IT Auditing profession at a BIG4 firm in 2013 and as of 2017, I founded Cyberus, an IT Assurance, Advisory & Consultancy firm.

I am also active on a voluntary basis since November 2014 with the professional associations the NOREA, ISACA and the IIA as, Chairman and Vice-Chairman of the Young Profs committees. In recent years, I have been responsible within the ISACA Board, with all events, webinars and conferences of ISACA Netherlands, as well as the Privacy and Young Profs working groups.

As of June 2022, I could call myself chairman of ISACA Netherlands and together with an enthusiastic and, above all, fun group of fellow volunteers, we may together offer a platform where we jointly take the profession of IT Auditing, IT Governance, IT Compliance, IT Security & IT Risk Management to a higher level.

If you have any questions, or are interested in working together, please feel free to contact me.

Hans de Vries
European Union Agency for Cybersecurity (ENISA)
Download
09.30 - 10.15
Podium I
NIS2 – Building up resilience in the EU’s critical sectors
In this talk we will give the EU perspective on the EU’s critical sectors, the different activities at EU level to increase resilience, the ENISA work supporting the implementation of the NIS2, including a sneak peak into the NIS2 security measures and incident reporting frameworks. At the end of the talk there will be a discussion with the audience about some open questions: How to make sure the NIS2 get implemented efficiently and effectively on the ground in the critical sectors. How to make the cybersecurity incident reporting process practical and workable for companies? How we can collaborate on resilience, forming a partnership between national authorities, national CSIRTs, and industry? What can national authorities and national CSIRTs do to support the sectors with increasing resilience?
Hans de Vries
European Union Agency for Cybersecurity (ENISA)

Hans de Vries is the Chief Cybersecurity and Operations Officer (COO) at the EU Agency for Cybersecurity (ENISA) since April 2024. Hans provides guidance and direction on the Agency’s operations activities and strategically advises the Executive Director.

Hans specifically represents ENISA in the NIS Cooperation Group, the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe) and the CSIRTs Network, which is composed of CSIRTs appointed by EU Member States and CERT- EU. His primary focus is the NIS2 implementation in the EU Member States and thereby helping to strengthen the current state of cybersecurity in Europe.

Prior to this role, Hans was the director of the Dutch National Cyber Security Centre (NCSC-NL) for almost a decade. In this position, Hans was a member of the ENISA Management Board and Executive Board. He was also one of the main organisational forces behind The Hague’s ‘ONE Conference’, which is among Europe’s prime cybersecurity events.

Hans’ prior working experience includes a top management position at the General Intelligence Services (AIVD) and the Ministry of the Interior and Kingdom Relations (BZK), where he served as head of the ‘ICT Management Division’ and head of ‘Operational Management Coordination’. He has also extended working experience in the ICT security domain at an inter-ministerial and international level gained while in the Ministry.

Hans has a law degree from Leiden University in the Netherlands and began his professional career in the private sector, before working for the Dutch central government in 2002.

10.15 - 10.40
10.15 - 10.40
Coffee Break
Dimitri van Zantvliet
Dutch Railways (Nederlandse Spoorwegen)
10.40 - 11.25
Podium I
The Cybersecurity revolution of Dutch Railways
Dutch Railways has ten security/safety domains embedded in their DNA where cybersecurity is just the youngest kid on the block. How did cyber evolve in the railway domain and what drives the CISO’s strategic roadmap? Learn from one of the Netherlands largest organizations how they build on their digital resilience and how they foresee AI to radically change the landscape.
Dimitri van Zantvliet
Dutch Railways (Nederlandse Spoorwegen)

Dimitri is the Cybersecurity Director and CISO of Dutch Railways (Nederlandse Spoorwegen). He is Co-Chair to the Dutch and European Rail ISACS and European Railway CISO Forum and chair of the board of the Dutch CISO Foundation.

He’s also Non-Executive Director of NGRT,  advisory board member of Cybersec Netherlands, supervisory board member of the Dutch Anti Online Child Abuse foundation OFFLimits, GISEC Cyberstars Jury member and a regular cyber-columnist/author/speaker/lecturer.

Dimitri holds an international master’s degree and cyber certificates such as CISSP, CRISC, CISA, CISM, CDPSE, CIPP/E, CIPM, FIP, ISO27001 and ISO42001

10.40 - 11.25
Podium II
Organizational Resilience in the Boardroom: Strategieën voor succes
In de dynamische bedrijfsomgeving van vandaag is organisatorische veerkracht essentieel. Deze presentatie belicht strategieën voor leiders om veerkracht te bevorderen, met inzichten in best practices voor robuuste aanpak. We bespreken de huidige risico’s voor de board, nieuwe wetgeving die bestuursleden aansprakelijk stelt voor veerkracht, incident response en voorbereidingen om crises te voorkomen. Alles om bestuursleden de kennis te geven om hun organisaties door onzekere tijden te leiden en duurzaam succes te waarborgen.
Mimoent Haddouti
PwC

Mimoent is a Partner in PwC Cyber, Forensics and Privacy practice with a strong background in cyber security and hands-on experience in the financial sector. With more than twenty years of experience in IT and related areas such as (IT) risk management, agile, compliance and business continuity, third party management, including proper metrics and reporting to prove the value of measures and actions.

Renske de Haan
PwC

Renske is een ervaren expert op het gebied van Crisis & Resileince bij PwC NL met een achtergrond die zich uitstrekt over diverse sectoren. Haar expertise omvat het ontwikkelen van programma’s voor Bedrijfscontinuïteit en Crisismanagement, en ze is vaardig in strategische crisismanagementtrainingen en simulaties voor boards en ExCo.

Yves Vanderbeken
Antwerp Management School (AMS)
Download
10.40 - 11.25
Podium III
How should government agencies govern personalized, self-directed citizen services based on a business platform model?
Business platform models are rising worldwide in industry (e.g., Bol.com) and governments (e.g., UWV/STAP). However, it is a different way of organizing services and requires a different governance approach to create value. In industry, value is translated into revenue and profit, but in government, it is about ‘public value.’ For example, how to help people out of unemployment, or to provide maximum support to citizens when they are ill, etc. Using examples and research data, we will show how a platform governance approach can facilitate this innovation, with the government acting as the platform owner.
Yves Vanderbeken
Antwerp Management School (AMS)

For over 20 years, I have been active in governments internationally, focusing on bringing innovation with new technology. I am adding an academic dimension by researching how a business platform model changes a government organization’s operating model, dynamics, and governance.

10.40 - 11.25
Podium vd Kunst
Prepared for social disruption | Prepare for War
Social developments such as climate change, pandemics, geopolitical conflicts (for example the war in Ukraine) and IT concentrations (for example the use of CrowdStrike) increase our awareness of unexpected risks that can affect everyone. Resilience is therefore crucial to withstand social disruption, where organizations must be both self-reliant and support each other. This is especially true in wars. How does your organization prepare?
Peter Kornelisse
EY

Peter is sinds 2018 als partner werkzaam bij EY betreffende Cyber assurance. Daarvoor heeft Peter 24 jaar gewerkt bij KPMG (Security & Technology), en 4 jaar bij Booking.com (Risk & Compliance). Ook is peter al meer dan 20 jaren betrokken bij de opleiding IT-auditing van TIAS, waaronder als hoofddocent voor de specialisatie Auditing Cybersecurity.

Gemma Jansen
Strategisch BPM/CISO
Download
10.40 - 12.20
Foyer III
NIS 2: doe er gewoon je voordeel mee!
In deze interactieve workshop gaan we in op de feiten (en fabels) rondom de NIS 2 en natuurlijk ook de relatie met Integraal Risicomanagement. Dat basale begrip is nodig om met behulp van een paar simpele formats de vertaalslag te maken naar het (veel interessantere) “Hoe”, zoals: Hoe identificeer je wat dit concreet betekent voor jouw organisatie? Hoe vertaal je dat in je organisatie? Wat is jouw rol? En, hoe helpt het 3 Lines model hierbij?
Gemma Jansen
Strategisch BPM/CISO

Vandaag het maximale rendement halen en parallel toewerken naar de strategische doelen van morgen, dat is wat Gemma Jansen kenmerkt in haar werk als CISO. Gemma heeft daarbij een duidelijke visie op samenwerking, in combinatie met veel ervaring met end-to-end proces- & projectmanagement. Zowel de interne- als externe klant is daarbij haar uitgangspunt. Door alle betrokkenen op ieders verantwoordelijkheidsniveau mee te nemen in het proces, realiseert zij het doel: Een omgeving waar de verbeteringen en/of veranderingen zijn geborgd en worden gedragen door de mensen die het doen.

11.25 - 11.35
11.25 - 11.35
Hall Change
Patrick Spelt
Ministerie van Infrastructuur en Waterstaat
Download
11.35 - 12.20
Podium I
The new Cybersecurity Act: ready for the future or bound by rules?
This presentation explains how the supervision of this new law is structured. A number of important new developments are discussed from the perspective of the supervisor. It explains what you can expect when your supervisor visits you. Will you receive immediate fines if you do not comply with the law? What is expected of the company’s board? What if you are confronted with two or more supervisors? What about the foreign activities of my company and the local national supervision? What can I start doing now? What does the supervisor consider important? In short; after this session you will know much more about the new Cybersecurity Act and the supervision that comes with it.
Patrick Spelt
Ministerie van Infrastructuur en Waterstaat

Patrick currently works as Head of Cybersecurity Supervision at the Ministry of Infrastructure and Water Management, Environment and Transport Inspectorate. In this role he is involved in the supervision of cybersecurity measures within essential service providers in various vital infrastructure sectors, including Maritime, Rail, Aviation, Drinking Water. He has expertise in supervision, regulatory compliance and risk management within the domain of cybersecurity, ensuring the resilience and security of critical infrastructure. Prior to his current position, Patrick held key positions in the private sector, most recently as IT Lead Identity & Access Management at Rabobank. He also served as Domain Continuity and Risk Officer and GDPR coordinator.

Marcel de Boer
Hoppenbrouwers
11.35 - 12.20
Podium II
HR Resilience HACK: de strijd van Hoppenbrouwers tegen een cyber aanval
Marcel neemt u van uur tot uur mee in de strijd tegen de cyberaanval bij Hoppenbrouwers in juli 2021. Uervaart wat er gedurende een dergelijke crises gebeurt en wat erbij komt kijken om een dergelijke crisis te overwinnen.
Marcel de Boer
Hoppenbrouwers

Marcel werkt 27 jaar voor Hoppenbrouwers Techniek en heeft in die periode als eindverantwoordelijke voor Finance en IT meegebouwd aan de groei van een lokale installatiebedrijf met 60 medewerkers naar een landelijk opererende technisch dienstverlener met bijna 2000 medewerkers. Sinds 2024

11.35 - 12.20
Podium III
Governance en MKB: van regelgeving naar resultaat
In deze sessie deelt Guido hoe je governance kunt inrichten voor het MKB. Het is soms lastig een balans te vinden tussen voldoen aan regelgeving en dagelijkse bedrijfsvoering in de praktijk. Het moet namelijk wel werkzaam blijven. Toch is goed bestuur en beleid wel heel belangrijk, zeker in het MKB. Met minder formele structuren en snel moeten inspelen op veranderingen kan dit wel een uitdaging zijn. Door te zeggen wat je doet en te doen wat je zegt, stoom je jouw MKB-organisatie klaar voor de toekomst. Want een goed bestuurd bedrijf is goud waard!
Guido Wintjens
Ivengi.com

In 2002 heeft Guido Ivengi.com opgericht. Inmiddels behoort Ivengi tot de grootste internet/softwarebureaus en hebben we veel succesvolle oplossingen gerealiseerd. Ivengi.com is daarnaast koploper op het gebeid van subsidiesystemen en levert haar oplossing EasyFunders aan gemeentes met meer dan 100.000 inwoners en provincies. De ambitie van Ivengi.com is verder groeien in het subsidielandschap. Na 23 jaar heeft hij ruime ervaring met het besturen van een MKB-bedrijf. 

11.35 - 12.20
Podium vd Kunst
Elmar Lecher
Port of Rotterdam
Download
11.35 - 12.20
Podium vd Kunst
Why perimeter security is coming to an end
Perimeter security is a cornerstone in our modern security world and its engrained in compliancy framework all over the place. But the perimeter security has changed form being helpful to become a problem in itself. I will explain why the traditional approach has become a problem, what are possible alternatives like e.g.zero trust and where compliancy frameworks might be impacted.
Elmar Lecher
Port of Rotterdam

Information Security Specialist from Germany working in the Netherlands for nearly 10 years.
Rooted in the hacker scene now working for the Port of Rotterdam and help make the Port a more secure + compliant place.

12.20 - 13.30
12.20 - 13.30
Lunch Break
13.30 - 14.15
Podium I
13.30 - 14.15
Podium I
DORA in Control (study report)
During the session a brief overview of DORA will be given. Explaining the difference between Cyber Security and Cyber Resilience. A DORA control framework will be presented and why it is important to translate the multiple DORA documents into a concise and understandable model, easy to use for gap assessments and tracking DORA implementation (dashboard). At last, we will focus on the importance of applying an engineering perspective in your DORA/Digital Resilience journeys to have a sustainable impact on your organization.
Sandeep Gangaram Panday
Schuberg Philis

Sandeep is Trust Officer at Schuberg Philis. Chair of the NOREA DevOps working group. Chair of the NOREA DORA Taskforce.
Author of DevOps in Control NOREA report. Co-author of Ransomware in Control NOREA report. Guest lecturer on DevOps & Ransomware at several universities.

Jeremy Oschmann
Schuberg Philis

Jeremy is IT auditor at Schuberg Philis. Expert on digital resilience and privacy legislation. Co-creator of the DORA in Control Framework

13.30 - 14.15
Podium II
Strong Supply Chain Resilience through Collaboration
Companies become more interconnected in many ways nowadays. You can be depend on suppliers, services or information exchange to name a few. Whatever the dependency you need to know how resilient your supplier is and prepare/compensate if needed. Understanding why and what is the starting point. Next is how to include the right supplier as assessing/monitoring all supplier is not possible/efficient. The last steps is actually assessing and improving supplier based on identified GAPS in a risk based manner. = = = = sections and who’s presenting = = = = Supply chain resilience Goal (why/what) Fleur Inclusion (how) Fleur Security Assessment (how) Robbert Improvement (how) Robbert
Fleur Koster
ASML

Fleur Koster studied accountancy and joined ASML as auditor. Later on she moved towards SS&P and got more involved in the area of supplier risk management. Today she is head of S&P Risk, ESG & Contract Management. In her role she leads different risk dimensions applicable to suppliers and the supply chain.

Robbert Kramer
ASML

Robbert Kramer studied business information technology and started working for EY as an IT Auditor. He performed IT audits and was also involved in Legal Hack activities. After EY he started working for Van Lanschot in ‘s-Hertogenbosch. Joined the Internal Audit department and afterwards moved to Security Management. In 2016 Robbert became Security Risk Manager for ASML performing Supplier Security. Main pillars for supplier security are protecting ASML Information and Cyber Security.

Robbert Kramer is also lecturer at the TIAS for the IT audit program. As senior lecturer he is responsible for the module that deals with Trust and Control of technologies.

Jan Stolker
Erasmus School of Economics
Download
13.30 - 14.15
Podium III
From the dark triad of corporate narcism to a balanced board
Jan Stolker will discuss the content and message of his new book, ‘Het Spel in de Boardroom’, an introduction to Behavioral Governance. While we think executives and non executive directors are rational operators, emotions and psychological factors drive them into biases and suboptimal decision-making. From a vision of the dark triad of CEO narcissism, Stolker arrives at an enlightened triad of empathetic and strategic leadership. In his concept of behavioral governance, risk management is about balancing control and trust and ratio and emotions. How can non-executive directors, remotely, as part-timers, effectively take responsibility here?
Jan Stolker
Erasmus School of Economics

Jan is director Leadership & Governance at Erasmus University and serves as a boardroom advisor. In 2023, he published ‘Het Spel in de Boardroom’, the first book on Behavioral Governance. In 2009, he founded the Erasmus Governance Institute, the postgraduate education center for non-executive directors. Since 2002, he has executed corporate restructurings in Western Europe and held non-executive board functions in different sectors of the economy. Earlier, he held leadership positions at ABN AMRO in corporate banking, risk management, and private equity.

Arash Rahmani
Treasurer ISACA NL Chapter
Download
13.30 - 14.15
Podium vd Kunst
Driving Transformation and Value: The Strategic Importance of Information Risk Management
In this session, we’ll explore the impact and strategic importance of information risk management from a board-level perspective. Information risk is not solely an IT problem, it is a business challenge. In our evolving digital world, effective information risk management enhances business transformation and value. NIS2 and DORA are accelerating the shift from viewing it as an IT problem to recognizing it as a business problem. As an Information Security Officer, CISO, Information Risk Manager or other risk role, it is crucial to understand the board’s perspective to effectively manage risk and enhance the risk culture. Join me to understand The Strategic Importance of Information Risk Management from a board perspective.
Arash Rahmani
Treasurer ISACA NL Chapter

Arash has over 15 years of experience in leading IT and information security teams. He is passionate about digital resilience, AI and innovation. He believes that technology has the power to enrich lives and contribute to a safer, more prosperous society.

Besides his role as a board member of ISACA Netherlands. He is also a Trusted Advisor at Sogeti (part of Capgemini), where he provides management teams with strategic guidance on improving digital resilience and manages teams in roles such as a CISO. He is a speaker in the field of digital resilience, innovation and AI, active within the Dutch association of board members (NCD) and an apprentice in the supervisory board of HTM.

Within ISACA Netherlands, he is committed to ensuring liquidity and financial stability, enabling us to continue investing in our community and helping our members to develop their knowledge and skills.

Ali Alam
Senior Manager KPMG Netherlands
Download
13.30 - 15.10
Foyer III
DORA: The final sprint, D-Day is here soon, are you ready to comply?
Ali will give an update on the latest developments on DORA and the challenges faced by financial institutions as well as the recommendations on how fare well during this final sprint towards compliance. The workshop will be concluded with a practical exercise on how to approach certain DORA requirements.
Ali Alam
Senior Manager KPMG Netherlands

Ali Alam, Senior Manager at KPMG Netherlands,. Wide range of experience on performing assessments, implementations pertaining the DNB Information Security Good Practice 2019/2020, EBA Guidelines on Security and Outsourcing.
Currently building expertise and capabilities on the Digital Operational Resilience Act (DORA) within KPMG.
Lives in The Hague.

14.15 - 14.25
14.15 - 14.25
Hall Change
14.25 - 15.10
Podium I
Where Ethics and Risks Meet:The AI ​​Act in Compliance Practice
A risk-based regulation of AI, that is what the AI ​​Act promises us. However, this new European regulation is far from straightforward. It mixes familiar concepts of product safety and quality management with ethical issues, and therefore poses a major challenge for risk management practice. This presentation discusses the framework and the most important considerations of the Act, and provides you with tools for the dilemmas that the law raises.
Arnoud Engelfriet
ICTRecht

Arnoud is a computer scientist and IT lawyer, working as Chief Knowledge Officer at ICTRecht in Amsterdam. He specializes in AI, data and software and has published many books, such as “ICT & Recht”, “AI & Algorithms” and “The Annotated AI Act”. Arnoud is also a lecturer at the Vrije Universiteit Amsterdam

Jeroen van Kesteren
De Nederlandsche Bank
Download
14.25 - 15.10
Podium II
Cyber Resilience, wacht niet tot je er klaar voor bent!
In zijn presentatie zal Jeroen niet alleen ingaan op wat DNB allemaal doet rond de cyber weerbaarheid van de eigen DNB organisatie op een open en transparantie manier, maar ook aandacht geven aan de rol van DNB als beleidmaker en Toezichthouder. Wat moet je doen om incidenten te voorkomen, maar ook, wat doe je als het wel misgaat. Hoe betrek je de board, en wat betekend wet- en regelgeving zoals GDPR/AVG, NIS2 en DORA voor jou keuzes? Hoe moet je rekening houden met externe factoren zoals de arbeidsmarkt, Quantum en AI?
Jeroen van Kesteren
De Nederlandsche Bank

Jeroen van Kesteren is CISO van DNB. In deze rol is hij verantwoordelijk voor het Information Security Office, Security Operations Center, Team Digital Forensics en Identity and Access Management. “Ik geloof niet in Security by obscurity, maar in security door transparantie” is een veel gebruikt citaat van hem. Dit is voor hem een belangrijke drijfveer om de kennis en ervaringen binnen DNB te delen met andere organisatie. Door elkaar te informeren worden we met z’n alle sterker.

Voordat hij CISO werd, heeft Jeroen diverse rollen gehad; Toezichthouder en Head of Mission bij grote financiële instellingen, Gast docent op de VU en TIAS, programma manager bij Capgemini, IT auditor bij van Lanschot zijn hier een aantal van.  

14.25 - 15.10
Podium III
Internal auditing als katalysator van waarde en verandering
Hoe kun je als auditfunctie de organisatie helpen haar waarde te vergroten en de daarvoor benodigde veranderingen stimuleren? Governance en control zijn in beweging: de wereld is ‘VUCA’, wetgeving en de vraag om veranderingen nemen toe. Dat stelt nieuwe eisen aan auditing, zeker als zij waarde wil toevoegen aan de organisatie, zoals centraal staat in de nieuwe IIA-standaarden en Vision 2035. De presentatie biedt handvatten om aan die eisen te voldoen, langs twee lijnen: de goede dingen doen de dingen goed doen Afstemming en samenwerking staat centraal, tussen de diverse (in- en externe) auditors, met management en 2e lijn. Maar hoe?
Peter Hartog

Peter Hartog is Directeur Vaktechniek van IIA Nederland, en was lid van de International Internal Audit Standards Board gedurende het opstellen van de nieuwe standaarden. Hij doceert ook aan de Internal Auditing & Advisory opleiding van de EUR. In het verleden werkte hij onder andere bij de SVB, ACS en KPMG.

14.25 - 15.10
Podium vd Kunst
Jair Cardoso de Santanna
Northwave Cyber Security & University of Twente
Download
14.25 - 15.10
Podium vd Kunst
The Double-Edged Sword
Imagine receiving a phishing email so impeccably crafted by an AI language model that it bypasses advanced filters and deceives even cybersecurity experts. While AI tools like GPT-4 enhance our defenses, they also equip attackers with sophisticated means to exploit vulnerabilities. This presentation delves into risks such as adversarial attacks, data poisoning, and model inversion. We explore ethical concerns like bias and privacy breaches, operational challenges from over-reliance on AI, and the weaponization of these models by malicious actors. Attendees will gain insights on balancing AI’s transformative benefits with the imperative of security and ethical responsibility.
Jair Cardoso de Santanna
Northwave Cyber Security & University of Twente

Jair is an enthusiastic and passionate principal researcher (@Northwave Cyber Security) and an assistant professor (@University of Twente). He is a practical, data-driven and extremely curious person. He loves to spread the knowledge with the scientific community and with cybersecurity practitioners. He prepares his presentations thinking about you (the audience). Therefore, he promises to give an engaging, enthusiastic, and to-the-point presentation. 

15.10 - 15.50
15.10 - 15.50
Coffee Break
15.50 - 16.35
Podium I
15.50 - 16.35
Podium I
The future cannot wait !
Ramsés Gallego Iglesias

Ramsés, with an MBA and Law education, has over 25 years of experience in security, with expertise in Risk Management and Governance. Recently the CTO at OpenText Cybersecurity, he previously served as Strategist & Evangelist at Symantec’s Office of the CTO and held roles at Dell Security, CA Technologies, SurfControl, and Entelgy. Active in ISACA, he served on the CISM and CGEIT Certification Committees, chaired the ISRM Conference, and contributed to the first ISACA World Congress. He is certified in CISM, CGEIT, CISSP, SCPM, CCSK, ITIL, and COBIT, and is a Six Sigma Black Belt. Ramsés is an award-winning international speaker and was recently inducted into the ISACA Hall of Fame. He teaches at IE Business School and is the Executive Vice President of the Quantum World Association.

16.35 - 16.45
Podium I
Elmar Zwart
getalenteerde jonge muzikant
16.35 - 16.45
Podium I
Musical Intermission
Elmar Zwart
getalenteerde jonge muzikant
Pav Gill
Confide
16.45 - 17.30
Podium I
Wirecard’s Whistleblower – The Journey from Scandal to Safety
Pav Gill, the whistleblower behind the colossal EUR 24 billion scandal, Wirecard, will share his insights on what happened at Wirecard and how that eventually led him to founding his existing startup, Confide.
Pav Gill
Confide

Pav, renowned for exposing the €24 billion Wirecard fraud, is a former Magic Circle lawyer and fintech general counsel. He founded Confide in late 2023, a pioneering whistleblowing & corporate investigations platform. Pav’s work has redefined governance technology and corporate ethics, earning him global recognition and prestigious awards.

Firas Abali
Board Member ISACA NL Chapter
17.30 - 17.45
Podium I
Closing Talk by ISACA Risk Event Committee Chairman
Firas Abali
Board Member ISACA NL Chapter
17.45 - 20.00
17.45 - 20.00
Dinner & Drinks
<h1 class='my-heading'>Just some HTML</h1><?php echo 'The year is ' . date('Y'); ?>
document.addEventListener("DOMContentLoaded", function () {
  const container = document.querySelector(".risk-loop-container");
  if (!container) return;

  const kaarten = Array.from(container.querySelectorAll(".risk-card"));
  const rijen = {};

  // Sorteer alle kaarten eerst op starttijd
  kaarten.sort((a, b) => {
    const tijdA = a.getAttribute("risk-starttijd") || "";
    const tijdB = b.getAttribute("risk-starttijd") || "";
    return tijdA.localeCompare(tijdB);
  });

  // Verdeel kaarten per tijdslot
  kaarten.forEach((kaart) => {
    const tijd = (kaart.getAttribute("risk-starttijd") || "").trim();

    if (!rijen[tijd]) {
      const rij = document.createElement("div");
      rij.classList.add("risk-row");
      rij.setAttribute("data-starttijd", tijd);
      container.appendChild(rij);
      rijen[tijd] = rij;
    }

    rijen[tijd].appendChild(kaart);
  });

  // Sorteer binnen elke rij op data-podium
  Object.values(rijen).forEach((rij) => {
    const cards = Array.from(rij.querySelectorAll(".risk-card"));

    cards.sort((a, b) => {
      const pA = parseInt(a.getAttribute("data-podium")) || 999;
      const pB = parseInt(b.getAttribute("data-podium")) || 999;
      return pA - pB;
    });

    cards.forEach((kaart) => rij.appendChild(kaart));
  });
});
function sorteerEnGroepeerKaarten() {
  const container = document.querySelector(".risk-loop-container");
  if (!container) return;

  // Verwijder oude rijen (voor het opnieuw opbouwen)
  container.querySelectorAll(".risk-row").forEach((el) => el.remove());

  // Zoek alle kaarten
  const kaarten = Array.from(container.querySelectorAll(".risk-card"));
  const rijen = {};

  // Sorteer kaarten op starttijd
  kaarten.sort((a, b) => {
    const tijdA = a.getAttribute("risk-starttijd") || "";
    const tijdB = b.getAttribute("risk-starttijd") || "";
    return tijdA.localeCompare(tijdB);
  });

  // Groepeer kaarten per tijdslot
  kaarten.forEach((kaart) => {
    const tijd = (kaart.getAttribute("risk-starttijd") || "").trim();

    if (!rijen[tijd]) {
      const rij = document.createElement("div");
      rij.classList.add("risk-row");
      rij.setAttribute("data-starttijd", tijd);

      // 🔧 Dit is waar de grid toegepast moet worden:
      rij.style.display = "grid";
      rij.style.gridTemplateColumns = "repeat(auto-fit, minmax(220px, 1fr))";
      rij.style.gap = "1rem";

      container.appendChild(rij);
      rijen[tijd] = rij;
    }

    rijen[tijd].appendChild(kaart);
  });

  // Sorteer binnen elke rij op podium-nummer
  Object.values(rijen).forEach((rij) => {
    const cards = Array.from(rij.querySelectorAll(".risk-card"));

    cards.sort((a, b) => {
      const pA = parseInt(a.getAttribute("data-podium")) || 999;
      const pB = parseInt(b.getAttribute("data-podium")) || 999;
      return pA - pB;
    });

    cards.forEach((kaart) => rij.appendChild(kaart));
  });
}

// Initieel en bij AJAX reload
document.addEventListener("DOMContentLoaded", sorteerEnGroepeerKaarten);
document.addEventListener("bricks/ajax/nodes_added", sorteerEnGroepeerKaarten);
function sorteerEnGroepeerKaarten() {
  const container = document.querySelector(".risk-loop-container");
  if (!container) return;

  // Verwijder oude gegroepeerde rijen
  container.querySelectorAll(".risk-row").forEach((el) => el.remove());

  // Verzamel en sorteer alle kaarten op starttijd
  const kaarten = Array.from(container.querySelectorAll(".risk-card"));
  const rijen = {};

  kaarten.sort((a, b) => {
    const tijdA = a.getAttribute("risk-starttijd") || "";
    const tijdB = b.getAttribute("risk-starttijd") || "";
    return tijdA.localeCompare(tijdB);
  });

  // Groepeer kaarten per tijdslot
  kaarten.forEach((kaart) => {
    const tijd = (kaart.getAttribute("risk-starttijd") || "").trim();

    if (!rijen[tijd]) {
      const rij = document.createElement("div");
      rij.classList.add("risk-row");
      rij.setAttribute("data-starttijd", tijd);
      rij.style.display = "grid";
      rij.style.gridTemplateColumns = "repeat(auto-fit, minmax(220px, 1fr))";
      rij.style.gap = "1rem";

      container.appendChild(rij);
      rijen[tijd] = rij;
    }

    rijen[tijd].appendChild(kaart);
  });

  // Sorteer binnen elk tijdslot op podium
  Object.values(rijen).forEach((rij) => {
    const cards = Array.from(rij.querySelectorAll(".risk-card"));
    cards.sort((a, b) => {
      const pA = parseInt(a.getAttribute("data-podium")) || 999;
      const pB = parseInt(b.getAttribute("data-podium")) || 999;
      return pA - pB;
    });
    cards.forEach((kaart) => rij.appendChild(kaart));
  });
}

function initKaarten() {
  sorteerEnGroepeerKaarten();

  const container = document.querySelector(".risk-loop-container");

  // Herinitialiseer Bricks Extras Lightbox
  if (typeof doExtrasLightbox === "function" && container) {
    doExtrasLightbox(container, true);
    console.info("✅ Bricks Extras Lightbox opnieuw geïnitialiseerd");
  } else {
    console.warn("⚠️ Bricks Extras Lightbox functie niet beschikbaar of container niet gevonden");
  }
}

// Init bij paginalaad
document.addEventListener("DOMContentLoaded", initKaarten);

// Init na AJAX/facet filtering
document.addEventListener("bricks/ajax/nodes_added", initKaarten);

Location

This year’s Risk Event took place at Spant!, a modern and inspiring venue in the heart of the Netherlands. Located in Bussum, just 25 minutes from Amsterdam and easily accessible by car and public transport.

Spant!
Dr. A. Kuyperlaan 3
1402 SBBussum

We do our best with using as less posible cookies and tracking. By continuing to use this site, you acknowledge and accept our use of functional cookies. However, some external services require your permission to place cookies.

Accept All Accept Required Only