EspañaSec Summit 2027
The EspañaSec Summit is a focused gathering in Madrid, ESP, dedicated to advancing cybersecurity. This event serves as a platform for professionals to discuss emerging threats, share best practices, and explore innovative solutions in the field of digital security. It emphasizes the collaborative effort required to build resilient cyber defenses against a constantly evolving threat landscape.
Committees & topics
Topics
IT Security in an Era of Converged Digital Infrastructure · Cyber Security and State Behavior in Cyberspace · Geopolitical Risks to the Global Security Environment · Regulatory Challenges in Digital and Cyber Governance · Business Continuity and Operational Resilience · Artificial Intelligence in Cyber Security · Supply Chain Security in Critical Goods and Software · Third-Party and Vendor Risk Management
Why it matters
In an increasingly interconnected world, cybersecurity is not merely a technical challenge but a critical component of national security and economic stability. Events like EspañaSec Summit are vital for fostering international cooperation and knowledge exchange, which are essential for developing robust defenses against cyber threats that transcend national borders. The discussions and collaborations at this summit directly contribute to strengthening the collective ability to protect critical infrastructure, sensitive data, and digital economies.
The summit's location in Madrid, ESP, highlights the growing importance of cybersecurity within Europe and its role in shaping regional and global digital policies. By bringing together experts and decision-makers, the event helps to bridge gaps between policy, technology, and implementation, ensuring that cybersecurity strategies are both effective and adaptable. This focus on practical application and strategic foresight is crucial for addressing the complex challenges posed by state-sponsored attacks, cybercrime, and other malicious activities.
How to prepare
Delegates preparing for the EspañaSec Summit should focus on understanding the current geopolitical landscape of cybersecurity, particularly as it pertains to ESP and the broader European context. Reviewing recent cyber incidents and policy responses will provide valuable background for engaging in discussions. Participants should also consider the various stakeholders involved in cybersecurity, from government agencies to private sector entities, as outlined in the "what-is-stakeholder-mapping" and "hidden-stakeholders" lessons.
Effective participation will require an understanding of both technical and policy aspects of cybersecurity. Familiarity with concepts such as "adaptive-cyber-defense" and "cyber-espionage" from the glossary will be beneficial. Delegates should also prepare to engage in discussions on "engagement-strategies" to foster cross-sector collaboration, as the summit aims to create a unified front against cyber threats. Considering the "dynamic-analysis" of threat vectors will also be crucial for contributing meaningfully to the dialogue.
Country perspectives
Where the most-relevant 1 countries stand on the core issues in play. Click through for the full country profile.
Topics & background
The background behind each topic and the actors that shape it.
IT Security in an Era of Converged Digital Infrastructure
Key players
SpainHost state; operates INCIBE and the ENS public-sector security framework.
United StatesSets de facto global baselines through NIST, CISA, and Executive Order 14028.
GermanyBSI provides one of Europe's most influential national IT security standards regimes.
United KingdomNCSC's Cyber Essentials and active defense programs shape Anglosphere practice.
IsraelMajor exporter of enterprise IT security technology and threat intelligence.
Cyber Security and State Behavior in Cyberspace
Key players
United StatesLeading offensive and defensive cyber power; advances coalition-based attribution.
RussiaAccused source of major destructive operations; promotes a state-sovereignty model of cyberspace.
ChinaPursues cyber-enabled industrial espionage and advocates the principle of cyber sovereignty.
North KoreaUses cyber operations, including cryptocurrency theft, to evade sanctions.
SpainEU bridge actor; INCIBE-CERT coordinates national incident response.
EstoniaHost of NATO CCDCOE and a normative leader on cyber defense doctrine.
Geopolitical Risks to the Global Security Environment
Key players
United StatesAnchor of the Western alliance system and architect of major sanctions regimes.
ChinaPrincipal systemic competitor to the US; reshapes trade, technology, and Indo-Pacific security.
RussiaRevisionist actor in Europe; driver of energy and food-security disruption.
IranRegional power whose proxy network shapes Middle East risk.
SpainEU/NATO member exposed to Mediterranean, Sahel, and Atlantic security risks.
GermanyLargest EU economy navigating decoupling from Russian energy and Chinese supply chains.
Regulatory Challenges in Digital and Cyber Governance
Key players
BelgiumSeat of EU institutions driving GDPR, NIS2, DORA, CRA, and the AI Act.
SpainAEPD and INCIBE shape national implementation of EU digital rules.
United StatesSectoral and SEC-driven approach; sets the transatlantic data-transfer agenda.
United KingdomPost-Brexit divergence on data protection and AI regulation.
ChinaCybersecurity Law, DSL, and PIPL exemplify the data-sovereignty model.
Business Continuity and Operational Resilience
Key players
SpainHost state; recent climate and grid events have stress-tested national resilience.
United KingdomPioneer of regulator-led operational resilience requirements for financial services.
United StatesFFIEC, CISA, and sector-specific continuity guidance shape global practice.
JapanLong experience with natural-disaster-driven continuity planning.
SwitzerlandHome of FINMA and a hub for resilience standards in finance and pharma.
Artificial Intelligence in Cyber Security
Key players
United StatesHome to leading model developers and to NIST's AI safety and risk frameworks.
ChinaMajor AI power with distinct regulatory model and generative-AI labeling rules.
United KingdomConvener of the AI Safety Summit process and host of the AI Safety Institute.
FranceHost of the 2025 AI Action Summit; advances European AI sovereignty agenda.
SpainEstablished AESIA, one of Europe's first national AI supervisory agencies.
IsraelSignificant ecosystem of AI-driven cybersecurity vendors.
Supply Chain Security in Critical Goods and Software
Key players
United StatesLeads SBOM mandates, export controls, and Secure by Design initiative.
ChinaDominant in rare earths and many manufacturing inputs; target of export controls.
TaiwanIndispensable node in advanced semiconductor manufacturing via TSMC.
NetherlandsHome to ASML, the sole producer of EUV lithography systems.
GermanyIndustrial heart of EU supply chain due-diligence and CRA implementation.
SpainHost of major Atlantic ports and growing semiconductor and renewables manufacturing base.
Third-Party and Vendor Risk Management
Key players
United StatesHosts the largest cloud and SaaS providers and sets much of the third-party risk guidance.
BelgiumEU policy hub driving DORA and NIS2 oversight of critical third parties.
United KingdomPRA/FCA regimes for critical third parties influence global financial supervision.
IrelandEuropean headquarters jurisdiction for many hyperscalers; key data-protection regulator.
SpainBanco de España and CNMV implement DORA across a major EU financial market.
Resources
News, lessons, and country profiles to prep for EspañaSec Summit 2027.
Lessons
Bite-sized lessons to build the basics
Courses
Guided courses that go deeper on the topic
The states in play, with the data that shapes their stance
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Related conferences
By committee
- IT Security in an Era of Converged Digital Infrastructure
- Cyber Security and State Behavior in Cyberspace
- Geopolitical Risks to the Global Security Environment
- Regulatory Challenges in Digital and Cyber Governance
- Business Continuity and Operational Resilience
- Artificial Intelligence in Cyber Security
- Supply Chain Security in Critical Goods and Software
- Third-Party and Vendor Risk Management