Infosecurity Europe 2026: What GCC Security Leaders Need to Know Before June's Flagship Cybersecurity Event
Infosecurity Europe 2026 runs June 2 to 4 at ExCeL London. With sessions covering AI agent security, ransomware tradecraft, cloud fundamentals, and hybrid infrastructure threats, this year's programme carries direct relevance for GCC enterprise security leaders. Early registration closes May 5.

Infosecurity Europe 2026 London ExCeL preview for GCC cybersecurity professionals
Infosecurity Europe 2026 takes place June 2 to 4 at ExCeL London. Now in its twenty-fifth year, it is the largest cybersecurity conference in Europe and one of the most substantive gatherings in the global security calendar, drawing 13,000 professionals including CISOs, security architects, policymakers, and enterprise security leaders across industries. For GCC and MENA security professionals, the 2026 programme is worth examining specifically because its thematic focus aligns closely with the challenges regional organisations are navigating heading into the second half of the year.
The threat actors, technology trajectories, and regulatory directions shaping European enterprise security are not confined to European borders. Ransomware groups targeting Gulf healthcare and financial institutions operate the same infrastructure used against European targets. AI security risks emerging in European cloud and agentic AI deployments are arriving in GCC environments on the same timeline. European regulatory frameworks including NIS2 and DORA are actively referenced by GCC regulators developing their own requirements, and GCC enterprises with European operations or data flows face direct obligations under those frameworks already.
Infosecurity Europe is also one of the primary venues where the global cybersecurity vendor community demonstrates new capabilities and direction. For security leaders responsible for technology evaluation and procurement, 300 exhibitors across the main floor, Discovery Zone, Cyber Startups Zone, and Cyber Innovation Zone represent a concentrated benchmarking opportunity that is difficult to replicate outside of a major international event.
Sessions Relevant to the GCC and MENA Security Agenda
Becca Lynch, NVIDIA AI Red Team: AI Agents: Attacks, Defences, and What You Need to Know
Drawing on real internal red-team exercises at NVIDIA, this session examines precisely how AI agents fail under adversarial conditions and what effective AI security testing looks like before attackers find the same failures themselves. For GCC security teams in the UAE and Saudi Arabia, where AI agent deployment across government, financial services, and enterprise operations is accelerating rapidly, the security testing and validation frameworks for these systems remain largely undeveloped. This session addresses the gap between the pace of AI adoption and the maturity of the security practices surrounding it.
Cynthia Kaiser, Former FBI Cyber Division Deputy Assistant Director, Halcyon: What the Dark Web is Showing Us About Evolving Ransomware Tradecraft
Kaiser brings decades of frontline experience tracking advanced ransomware operations to a session that draws on dark web intelligence to map where ransomware groups are taking their capabilities next. For GCC security operations and incident response teams, understanding how these groups are evolving their targeting criteria, negotiation tactics, and technical tradecraft ahead of the next wave of attacks is directly actionable intelligence. Ransomware remains among the most consequential threats facing GCC healthcare, financial services, and critical infrastructure sectors.
Shlomo Kramer, Founder of Check Point, Imperva, and Cato Networks: On the AI Era: Risk, Reality and What Comes Next
Kramer has been at the founding moment of three distinct waves of enterprise security technology, from the firewall era through web application and data security to cloud-delivered SASE architecture. His session applies that longitudinal perspective to the current AI inflection point, addressing where genuine architectural transformation is occurring versus where marketing cycles are outrunning substance. For GCC CISOs making long-term technology investment decisions in a market saturated with AI-native claims, this kind of strategic calibration from a practitioner with that depth of experience is a rare and practically useful input.
Ron Leizrowice: The Infosec Big Fat Cloud Security Annual Update
This annual session focuses this year on adapting proven cloud security fundamentals for AI-integrated environments, addressing the specific challenge that cloud security posture management, workload protection, and access governance frameworks were not designed with AI workloads, AI-generated code, and AI-assisted development in mind. For GCC enterprises running cloud-first programmes under Vision 2030 and UAE Smart Government initiatives, this is the area where security frameworks and deployment reality are most visibly diverging.
Dr. Dmytro Kuleba, Former Ukrainian Foreign Minister: Ukraine's Hybrid War and the New Cyber Frontline
Dr. Kuleba led Ukraine's diplomatic effort during a period of sustained, coordinated, state-backed attack on national digital and physical infrastructure simultaneously. His session addresses the operational realities of defending energy systems, communications networks, financial infrastructure, and industrial facilities under that pressure. The relevance to GCC critical infrastructure operators is grounded in a comparable risk profile. GCC nations operate oil, gas, water desalination, and power generation infrastructure whose strategic value makes it a permanent feature of sophisticated adversarial targeting calculations. The documented history of attacks on Gulf energy infrastructure, including the Shamoon campaigns against Saudi Aramco and attacks on Gulf petrochemical facilities, establishes that this is not a theoretical concern. The lessons from defending high-consequence national infrastructure at operational scale, including continuity under pressure, resilience architecture, and cross-sector coordination, are directly transferable to the frameworks GCC enterprises and national cybersecurity authorities are building.
Event Details
Dates: June 2 to 4, 2026 Venue: ExCeL London, One Western Gateway, Royal Victoria Dock, London E16 1XL Daily hours: 9:30am to 5:30pm on June 2 and 3, 9:30am to 4:00pm on June 4 Registration: infosecurityeurope.com
GCC and MENA security professionals attending should plan session attendance in advance given the scale of the programme and the likelihood of high-demand sessions reaching capacity.
Salma Mubarak
Cloud Security & AI Security ContributorSalma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.
At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.