The Richmond Cyber Security Forum will bring together CISOs and senior cyber security executives from mid-sized and large UK organisations on 24 September 2026 at the Four Seasons Hotel London at Park Lane. The programme will focus on organisational resilience, third-party risk and the practical use of artificial intelligence as businesses face a more complex threat environment.
The complimentary event is designed to give senior cyber leaders access to peers facing similar operational and strategic challenges. Delegates will be able to discuss those issues through workshops, discussion groups and professional development sessions, while networking with other cyber security executives in a five-star setting.
The programme will examine current challenges facing CISOs and approaches organisations can use to address them. Topics include secure technology design, incident management, workplace culture, executive communication and the changing expectations placed on cyber security leaders.
Dr Victoria Baines, Professor of Information Technology and Professor Emerita at Gresham College, will open the programme in conversation with Purvi Kay, Head of Cyber and Information Security at a UK defence prime. Their discussion will examine how organisations can prioritise security investment, reduce exposure and build longer-term resilience.
Secure design
Barbara Aung, Chief Information Security Officer at Virgin Media O2, will lead a workshop on embedding security throughout the technology lifecycle.
The session will examine how companies can move security from a design-stage requirement to a default part of software, service and technology deployment. It will cover the alignment of security controls with business objectives and collaboration between security teams and other functions.
Aung has worked in information technology security for more than 25 years. Her experience includes incident response, security operations, architecture and information security management.
Stuart Frost, Head of Enterprise Security and Risk Management at the UK Government, will address third-party and supply chain cyber risk.
His session will examine accountability across vendor ecosystems and the effect of behaviours within procurement, operations and security teams. It will also consider how companies can target assurance work across different suppliers while maintaining continuous business delivery.
The programme identifies diffused responsibility and limited visibility as recurring problems when organisations manage interconnected digital and operational supply chains.

Crisis response
Lynda Petherick, Chief Operating Officer and Chief Information Officer at New Look, and soon to be Chief Executive Officer, and Joe Kelly, Head of Information Security at New Look, will discuss the use of Gold and Silver Teams during major incidents.
Their workshop will cover decision-making when information remains incomplete and time is limited. It will also examine team responsibilities, competing organisational priorities, response runbooks and third-party preparedness.
Petherick chairs New Look's Gold Team, which would direct the company's response during a significant business crisis. Kelly is responsible for the retailer's cyber security maturity and resilience programmes.
Charles White, Chief Executive Officer at The Cyber Scheme, will use an incident response case study to examine how attackers identify and select targets.
His workshop will cover threat actor motivations, factors that increase organisational exposure and reasons security projects may fail to deliver their intended outcomes.
Human factors
Janette Bonar Law, Information Security Operations Manager at Channel 4, will focus on behavioural and cultural change.
The workshop will examine why employees bypass security policies and how workplace incentives, stress and organisational structures influence cyber-related decisions. It will also cover storytelling as a way to communicate risk and the alignment of people, policy and operational processes.
Simon Hepburn, Visiting Professor at Aston University, will address the professionalisation of cyber security.
His session will consider the UK's certification landscape, professional standards and the role of CISOs in shaping policy. It will also examine how professional pathways, ethics and governance can strengthen confidence among company boards.
Tamlynn Deacon, Founder of Empower Authentic Coaching, will lead a professional development session on executive communication. The workshop will address communication styles, boardroom relationships and the presentation of technical risks in business terms.
Annabel Berry, Founder and Director of Leading Cyber, will examine pressure, boundaries and resilience among security leaders and their teams. The session will cover psychological safety and working practices intended to support sustained performance.

Applied AI
Grant Ongers, Security-Advisor, Ambassador and Architect, will lead a discussion on the practical deployment of AI within security functions.
Participants will consider how organisations measure risk reduction, incident response times and control effectiveness. The discussion will also cover criteria for moving AI projects from pilots to enterprise deployments and governance triggers for resetting or ending programmes.
"The easiest path to production should also be the safest one. Identity is where that promise lives - or dies," said Grant Ongers, Security-Advisor, Ambassador and Architect.
The programme will close with a panel moderated by Ant Davis, Host of The Awareness Angle. Panellists include Deborah Saffer, Director Information Security at Liberty Specialty Markets, Lee Howard, Chief Information Security Officer at Evri, and Joe Kelly, Head of Information Security at New Look. The discussion will revisit cyber resilience, third-party and supply chain risk, AI adoption and changes in the CISO role.