Skip to content
Cloud Security Alliance CSA EMEA Conference
30 Sep - 01 Oct 2026 - Zurich

Cloud Security Alliance
EMEA Conference

Sovereign Cloud and Artificial Intelligence - two days of training, insights, and actionable strategies for navigating sovereignty regulatory requirements across the globe.

About the Event

Sovereign Cloud &
Artificial Intelligence

Regulations defining Sovereignty requirements regarding the use of Cloud and AI technologies by data controllers, data processors and their entire supply chain are emerging in many legislations globally. These regulations impose strict requirements regarding legal, contractual, service design and architecture, operational, and compliance-related aspects.

The European Commission has published the Cloud Sovereignty Framework (CSF) which lists 8 core sovereignty domains:

  • Strategic sovereignty
  • Legal and jurisdictional sovereignty
  • Data and AI sovereignty
  • Operational sovereignty
  • Supply chain sovereignty
  • Technology sovereignty
  • Security and compliance sovereignty
  • Environmental sovereignty

The Event will provide training, background information and actionable insights into sovereignty regulatory requirements across the globe and how to address them from a legal, contractual, design & architecture, risk & compliance point of view, rounded up with practical examples of real world implementation cases.

Event Details

Venue

Amazon Conference Centre
Mythenquai 10
Zurich, Switzerland

Dates

30 September - 01 October 2026

Who Should Attend

CISOs, DPOs, and senior professionals in cyber risk, data protection, supply chain security, compliance, and cloud/AI governance.

Programme

Two days of deep insight

Event details
30

Day 1 — Training & Workshop

Wednesday, 30 September 2026

09:00 – 09:30

Registration & Welcome Coffee

09:30 – 12:30

Morning Session

12:30 – 13:30

Lunch Break

13:30 – 17:30

Afternoon Session

17:30

End of Training Session

18:00

Welcome Reception Speakers & Attendees with Apéro Riche

01

Day 2 — Conference

Thursday, 1 October 2026

08:30 – 09:00

Registration & Welcome Coffee

09:00 – 09:10

Welcome and Event Introduction by the Conference Hosts

Rolf A. Becker, Lars Ruddigkeit: Co-Presidents CSA Swiss Chapter

Jim Reavis: CEO Cloud Security Alliance

Linda Strick: MD Cloud Security Alliance EMEA

09:10 – 09:40

Agentic AI and Sovereign Cloud: Global and Regional Principles and Concerns — Fire Side Chat

As autonomous AI agents move into production, they collide with a countervailing force: the drive for sovereign control over data, access, and jurisdiction. Agentic systems cross boundaries by design; sovereignty draws them. This session will contrast regulatory requirements emerging, political concerns and opinion, research of the CSA, and implementation concerns. Emerging global principles for sovereignty and trustworthy agentic AI are contrasted with the regional realities shaping Europe, Switzerland, Middle East and Asian emerging regulations — examining accountability, identity, data residency, and cross-border control, and where these principles are still being tested against the hard trade-offs sovereignty demands.

Jim Reavis: CEO Cloud Security Alliance

Lukas Mäder: Editor Technology and Geopolitics, Neue Zürcher Zeitung

09:40 – 10:10

Sovereign Cloud: Global Overview of Regulations and Requirements

As cloud computing becomes mission-critical infrastructure, reliance on foreign-headquartered service providers presents significant strategic, operational, and legal risks. Digital sovereignty has transitioned from a political concept into an urgent operational priority, requiring organizations to maintain independence, business resilience, and regulatory compliance without compromising critical operations. This presentation examines the global landscape of cloud sovereignty regulations and requirements, drawing directly from the Cloud Security Alliance Sovereignty Working Group's controls framework. It introduces Authorized Jurisdictions and Locations (AJL) as a foundational, multi-layered specification to define where data, workloads, and access paths are legally and operationally permitted to reside or transit. Additionally, the session surveys conflicting global regulatory frameworks — ranging from the US CLOUD Act and EU GDPR/EUCS to strict local mandates in France (SecNumCloud), China, Saudi Arabia, and Australia. Attendees will gain actionable insights on evaluating commercial sovereignty models (independent, delegated, and superficial), enhancing traditional security controls (such as the CSA Cloud Controls Matrix), and structuring enforceable contractual commitments to ensure long-term digital autonomy and exit capability.

Jean-François Terminaux: CSA Sovereign Cloud Working Group

Linda Strick: MD Cloud Security Alliance EMEA

10:10 – 11:00

Sovereign Cloud: Regulatory Perspectives Europe, Middle East, Asia and USA — Expert Panel

Abstract in preparation

Bharat Raigangar: Global Head – AI Cyber Security & Risk / 1CxOCSA

Daria Catalui: Cluster CISO & Global Human Firewall, Group Information Security | Digital Resilience / Allianz

Apostolos Malatras: Head of Unit Cybersecurity Certification and Head of Unit Market, Technology and Product Security / ENISA

Lars Ruddigkeit: Co-President CSA Swiss Chapter, Amazon

Rolf von Rössing: Prof. h.c. Universität für Weiterbildung Krems, Partner at FORFA Consulting, Vice Chairman Resilience Association

Further Speakers: to be confirmed

11:00 – 11:30

Coffee Break & Networking

11:30 – 12:00

CSA AI Foundation, CSA AICM, Audits and more

Cybersecurity has entered the intelligence era, with adversaries operating at machine speed and human-paced governance falling behind. The strategic question is no longer whether to adopt AI, but how to defend and govern when AI is on both sides. This session presents CSA's practical guidance for that shift — how to reorganize security operations for machine speed, where human judgment still matters, and why AI belongs under AI-native frameworks like the AI Controls Matrix rather than retrofitted legacy frameworks.

Jim Reavis: CEO Cloud Security Alliance

Daniele Catteddu: CTO Cloud Security Alliance

12:00 – 12:30

Sovereign Agents: Setting Guardrails by Default

The next wave of artificial intelligence is not to simply assist humans; it will increasingly act autonomously on their behalf. As organizations deploy autonomous AI agents to execute business processes, interact with customers, and make operational decisions, the question of sovereignty becomes critical. Who governs these agents? Who controls their data, decisions, and actions? This presentation introduces the concept of Sovereign Agents: autonomous AI systems designed to operate with independence, yet fully aligned to guardrails including policies, values, and governance frameworks of the organizations that deploy them. Sovereign Agents represent a new foundation for digital trust, enabling enterprises and governments to benefit from AI autonomy while maintaining transparency, accountability, security, and control.

Sudhir Ethiraj: Global Head of Cybersecurity Office (CSO) & CEO Business Unit Cybersecurity Services / TÜV SÜD

12:30 – 13:30

Lunch Break & Networking

13:30 – 14:00

Agentic AI: Innovation at Machine Speed, Governance at Human Speed — and Cyber Risk all along

This session provides a practical perspective on how organizations can navigate AI and digital sovereignty transformations through the lens of cyber security, risk governance and accountability. While frameworks and standards such as the CSA AI Foundation, CSA AICM, NIST AI RMF and ISO 42000 provide valuable guidance, many organizations still lack transparency regarding who is using AI — including shadow AI — and who is accountable for managing its associated risks. Drawing on real-world examples and lessons learned from CISO interviews, the session presents actionable approaches for establishing effective AI governance and enabling a secure, responsible and successful AI business transformation. Participants will learn how to create clarity around ownership and accountability, identify and address risks arising from AI usage, and align people, processes and technologies with organizational, regulatory and resilience requirements.

Swantje Westpfahl: Director Cybersecurity Strategy & Market Engagement / Argos Security

14:00 – 14:30

Achieving Digital Sovereignty in Practice: Case Study

Digital sovereignty is of strategic importance for many jurisdictions globally, including the EU member states, Switzerland, UAE, Saudi Arabia, China, Singapore, USA and many more. The gradual and increasingly intensive use of international digital ecosystems in recent years has been primarily with a view to cost advantages; at the same time, a strategic dependency was created, which is now the focus. The presentation uses a practical case study to show how partial or overall sovereignty can be achieved step by step. Both organizational and technical aspects are addressed. At the same time, a strategy is presented that leads to successful implementation in iterative form.

Rolf von Rössing: Prof. h.c. Universität für Weiterbildung Krems, Partner at FORFA Consulting, Vice Chairman Resilience Association

Sana Yaakoubi: Digital Risk and AI Governance Leader

14:30 – 15:00

Implementation of Sovereign Cloud: Company Perspective Middle East

As critical infrastructure sectors migrate to the cloud, "Digital Sovereignty" has evolved from a technical requirement to a strategic imperative. This presentation examines the implementation of a Sovereign Cloud through the lens of a unified GRC framework. Rather than treating cybersecurity and social engineering as isolated technical challenges, this session demonstrates how to integrate them into the broader Governance, Risk, and Compliance ecosystem. By treating behavioral vulnerabilities as formal risk vectors and technical defenses as compliance controls, organizations can build a resilient security posture. The discussion will cover the alignment of sovereign data mandates with technical safeguards and the implementation of "Human-Centric GRC" to mitigate the risks of social engineering. Attendees will leave with a framework for deploying a cloud environment where technical sovereignty is reinforced by rigorous governance and a high-vigilance organizational culture.

Sara Alnoaimi: Head of Cybersecurity at Drilling & Workover Operations / aramco

15:00 – 15:30

Implementation of AI under Sovereignty Restrictions: Succeeding in a Regulated Market — Case Study from Singapore

This session takes the practitioner's view: how one global Tier-1 bank's Singapore-based wealth management business actually got an agentic AI deployment approved and live, under real data-sovereignty constraints. We walk through the architecture and security principles that earned sign-off: In-region hosting. Model-agnostic infrastructure. Segregated tenancy. Rigorous access and data-leakage controls. We show the legal and compliance work behind them, including one of the most extensive AI-specific contract addendum we've encountered. We map each regulatory expectation to the concrete answer we built for it. We share what a multi-year investment in local presence and direct regulator dialogue looks like in practice. AI comes with risks. Succeeding in Singapore meant weighing the business opportunity alongside those risks, not driving risk to zero. Standing still carries a risk too: employees turn to ungoverned "shadow AI" when there is no governed alternative.

Dr. Sina Wulfmeyer: Chief Data Officer & Board Member / Unique AI

Michael Dreher: CISO / Unique AI

15:30 – 16:00

Coffee Break & Networking

16:00 – 16:30

Implementation of Sovereign Cloud: Contractual Aspects of Sovereign Cloud and AI, Legal Framework for the Supply Chain, Leveraging Zero Trust and Reigning in on AI — Expert Panel

Abstract in preparation

David Rosenthal: Partner at VISCHER, Delegate of the Board at LawDigital Ltd.

Rolf A. Becker: Co-President CSA Swiss Chapter

Tereza Jášková: Managing Director & Senior Legal Counsel / Alpiq

16:30 – 17:00

AI Implementation Under Sovereignty Constraints — What Your Rollout Really Needs

AI is accelerating digital innovation — but without the right foundations, it can amplify risk just as quickly. And for organisations bound by data sovereignty requirements, the room to manoeuvre is narrower still: where data may be processed, under whose jurisdiction, and on whose infrastructure are no longer questions to be settled after the fact. In this keynote, Christine explains why security is no longer a control function but a strategic enabler of scalable, trustworthy innovation. Drawing on real-world cases — from prompt injection and shadow AI to large-scale fraud — she exposes the gaps organisations tend to discover too late: over-privileged access, weak data governance, and AI deployments that quietly breach sovereignty boundaries. She then introduces a practical framework for aligning security, data sovereignty and AI strategy — so that regulated organisations can move faster with confidence, build trust, and turn constraint into competitive advantage. Because in the age of AI, security doesn't slow innovation down — it decides whether it succeeds.

Christine Fahlberg: Former CISO | Co-Founder / Your Next Level GmbH

Swiss CISO Award 2025

17:00 – 17:30

Implementation of Sovereign Cloud: Company Perspective Europe

Digital sovereignty is no longer just a regulatory requirement — it has become a strategic business imperative. Yet many organizations struggle to translate sovereignty principles into practical implementation across technology, governance, and organizational structures. This session provides a practical enterprise perspective on implementing digital sovereignty. It explores how regulatory requirements, sovereign cloud capabilities, and organizational transformation must be aligned to create secure, compliant, and resilient digital environments. Drawing on real-world experience, the presentation highlights common challenges, key success factors, and lessons learned from supporting organizations on their digital sovereignty journey. Attendees will gain actionable insights into bridging the gap between strategy and execution while building the capabilities required for sustainable digital sovereignty.

Katia Winkler: Group Information Security Manager, Deputy CISO / Vaillant Group

17:30 – 18:00

Digital Forensics: Cross Border Cloud Investigations and Automated Cyber Incident Response Management (aCIRM)

Digital Forensic tools and techniques have evolved in the age of automated cloud computing infrastructure to ensure compliance with mandatory privacy and security compliance reporting while confronting the challenges presented by AI enabled threat actors. This session will cover the operational implementation of automated and remote digital forensic solutions to meet EU DORA, CRA, NIS2 and New York State Department of Financial Services Cybersecurity regulation part 500 as well as corporation regulated by the US SEC who have implemented ISO 27001 series or CSA CCM consistent control frameworks such as CSA CCM Domain: Security Incident Management, E-Discovery, & Cloud Forensics (SEF), specifically SEF-03 (Digital Evidence) and SEF-04 (Incident Response).

Klaus-Peter Finke-Härkönen: Secretary CSA Finland Chapter, Principal Finke Harkonen oy, Business Development Advisor / Binalyze

18:00 – 18:10

Wrap-up by the Conference Hosts

Rolf A. Becker, Lars Ruddigkeit: Co-Presidents CSA Swiss Chapter

Jim Reavis: CEO Cloud Security Alliance

Linda Strick: MD Cloud Security Alliance EMEA

Audience

Who Should Attend

Senior Leadership

CISOs, DPOs, and senior professionals responsible for cyber risk governance and control.

Risk & Compliance

Heads of third party risk management, supply chain compliance, GRC, audit, and operational risk.

Technical Leaders

Heads of cloud, AI and cyber security, security architecture, IT risk, and business continuity.

Speakers

Distinguished speakers

S

Sara Alnoaimi

Head of Cybersecurity at Drilling & Workover Operations at aramco

R

Rolf A. Becker

Co-President at Cloud Security Alliance Swiss Chapter

D

Daria Catalui

Cluster CISO & Global Human Firewall Group Information Security | Digital Resilience at Allianz

D

Daniele Catteddu

CTO at Cloud Security Alliance

M

Michael Dreher

CISO at Unique AI

S

Sudhir Ethiraj

Global Head of Cybersecurity Office (CSO) & CEO Business Unit Cybersecurity Services at TÜV SÜD

C

Christine Fahlberg

Former CISO | Co-Founder at Your Next Level GmbH, Swiss CISO Award 2025

K

Klaus-Peter Finke-Härkönen

Secretary of CSA Finland Chapter, Principal of Finke Harkonen oy, Business Development Advisor at Binalyze

T

Tereza Jásková

Managing Director & Senior Legal Counsel at Alpiq

A

Apostolos Malatras

Head of Unit Cybersecurity Certification and Head of Unit Market, Technology and Product Security at ENISA

L

Lukas Mäder

Editor Technology and Geopolitics at Neue Zürcher Zeitung

B

Bharat Raigangar

Global Head – AI Cyber Security & Risk at 1CxOCSA

J

Jim Reavis

CEO at Cloud Security Alliance

D

David Rosenthal

Partner at VISCHER, Delegate of the Board at LawDigital Ltd.

R

Rolf von Rössing

Prof. h.c. Universität für Weiterbildung Krems, Partner at FORFA Consulting, Vice Chairman Resilience Association

L

Lars Ruddigkeit

Co-President at Cloud Security Alliance Swiss Chapter

L

Linda Strick

Managing Director at Cloud Security Alliance EMEA

J

Jean-François Terminaux

CSA Sovereign Cloud Working Group

S

Swantje Westpfahl

Director Cybersecurity Strategy & Market Engagement at Argos Security

K

Katia Winkler

Group Information Security Manager, Deputy CISO at Vaillant Group

S

Sina Wulfmeyer

Chief Data Officer & Board Member at Unique AI

S

Sana Yaakoubi

Digital Risk and AI Governance Leader

About

The Event Organiser

The Cloud Security Alliance (CSA) is the world’s leading not-for-profit organisation committed to awareness, implementation, and credentialing of AI, Cloud, Zero Trust.

Organised by

Event Partners

SCCS Summit

The SCCS Third Party & Supply Chain Cyber Security Summit brings together senior Information Security & Cyber TPRM leaders to address one of today's most urgent challenges: how to secure the extended enterprise in an era of escalating cyber threats and growing regulatory pressure.

Dr. Peter van Eijk

Dr. Peter van Eijk is one of the world's most experienced cloud trainers: Technology for decision makers. Developing and delivering training and coaching programs for Cloud, AI and Security.

Amazon Web Services

Hosting the event and training workshop in their Zurich conference facilities.

Reserve your seat

Join us in Zurich

Register now to secure your place at the premier cloud sovereignty event in EMEA.

Register Now