Speakers

Rob Aragao
Field CISO
DataDog

Dynamic, results driven leader with extensive experience developing and executing strategic initiatives that drive growth and deliver measurable business impact. A trusted executive level advisor, with a strong ability to translate complex technology and cybersecurity risks into clear business priorities that support digital transformation.

Florian Örgens
Cyber Security Speaker & CISO
Vorwerk Gruppe

Florian Jörgens is an experienced cybersecurity leader with over 20 years of expertise in information technology and information security. He began his career at T-Systems International GmbH before gaining IT auditing experience at PwC and moving into senior information security roles at E.ON and LANXESS AG.

Surviving a CISO's Worst 72 Hours in the AI Era

Security teams have spent years modernising their security platforms, but better visibility hasn't changed how analysts actually respond when a real crisis hits. 

The session will open with a discussion on how the SOC is evolving beyond traditional, analyst-driven workflows toward AI-assisted detection, automated investigation, and faster response to meet the demands of the AI era. It will also explain how this approach reduces the toil that slows teams down in an incident and closes the gap between attackers and defenders.

Then you'll go inside a real-world ransomware crisis. Based on a tabletop exercise developed by CISO Florian Jörgens, you'll follow 72 hours inside a fictional attack by the "Green Devils" group: encrypted systems, exfiltrated customer data, a $2 million ransom demand, and a business grinding to a halt. Watch how the crisis escalates hour by hour, and what it actually takes to recover.

The session closes with live Q&A between Florian and Rob Aragao, Field CISO at Datadog, unpacking lessons on preparation, communication, and resilience you can apply before your own worst 72 hours begin.

Key Takeaways:

  • How AI is automating the investigation and decision layer - freeing analysts for judgment and response instead of manual triage.
  • What a ransomware crisis actually costs in time - recovery took 4 weeks in the simulated scenario, despite servers being restored in 9 days. 
  • The operational and communication demands of a live crisis (board, press, legal, employees).
  • Why SIEM modernisation solved visibility and scale but not analyst workflow - and what closes that remaining gap. 
  • Why unified observability and security data matter when minutes count.

    Good news: This is a virtual event that can be attended from the comfort of your office/home, eliminating the need to travel. By choosing to attend this virtual event, you are contributing to a more sustainable future while still benefiting from valuable industry insights.