The Cybersecurity Council held its first quarterly meeting of 2026, bringing together security leaders from multiple critical industries. The discussion focused on strategic takeaways from the Munich Cyber Security Conference (MCSC 2026), practical AI/agentic AI applications in security operations, NIS2 readiness as organisations move toward supervisory reality, and an enterprise perspective on the European cybersecurity ecosystem.
Key themes and insights
- Resilience is evolving from “recover fast” to “stay operational under structural pressure.”
Participants observed a shift in executive and board conversations away from classic recovery metrics (RTO/RPO/MTTR) toward broader questions: How do we maintain operations under availability attacks, supplier concentration, geopolitical disruption, and ecosystem dependencies? Practical implications discussed included periodic architecture reviews (e.g., network entry points, segmentation, redundancy patterns), more realistic exercises, and tighter alignment between cyber resilience and business continuity. - Digital sovereignty is increasingly treated as a procurement and risk variable.
Rather than aiming for isolation, sovereignty was discussed as reducing strategic dependencies and increasing optionality across cloud and security layers. At the same time, many organisations face constraints—global scale requirements, procurement/tender rules, and maturity gaps of alternatives—that can limit rapid shifts. - Security tooling: consolidate where it makes sense, keep selective edge capabilities.
The group discussed the tension between cost pressure (tool reduction and consolidation) and resilience considerations that sometimes benefit from deliberate redundancy. A common pattern is consolidating “mainstream” capabilities via platforms (supported by a structured “tool matrix” view of purpose and overlap), while keeping a limited set of specialised solutions where differentiation or emerging threats justify it. - AI in cybersecurity: practical workload reduction, with governance guardrails.
Members shared approaches moving beyond experimentation—especially in security operations. The most mature use cases focus on automating repetitive analyst tasks (triage, enrichment, correlation), accelerating “intel-to-detection”, and generating executive-ready incident narratives and situation reports. Many organisations are targeting higher levels of automation but still keep humans in the loop due to trust and hallucination risks. “Shadow AI” is emerging as an additional challenge: enterprises want visibility into unsanctioned AI usage and into AI features enabled by vendors through updates. - NIS2: The shift from implementation projects to supervisory reality has begun.
Key operational challenges discussed included managing scope and registrations across many legal entities and countries, meeting tight incident reporting timelines (24/72 hours) across heterogeneous national portals, aligning board/management training with evolving guidance, and coordinating overlapping regimes and audit cycles. A consistent takeaway: board engagement is most effective when framed in business impact (operational disruption, service continuity, regulatory friction), not only in legal liability terms. - Enterprise perspective on the European cybersecurity ecosystem.
In an anonymised questionnaire and group discussion, members highlighted that vendor origin is increasingly considered in procurement decisions (especially for critical capabilities) and that dependency on a small number of global providers is a growing resilience concern. However, “European” alone is not a sufficient differentiator: adoption depends on functional parity, integration into existing platforms, supportability, and evidence of maturity and stability. Frequently cited barriers for European start-ups/scale-ups include scalability, integration complexity, limited global support capability, procurement risk aversion, and brand trust. Practical advice to founders: win on product excellence, make integration frictionless (APIs and ecosystem partnerships), stay agile, and offer enterprise-ready delivery and support models.
Next steps and upcoming meetings
The Council will continue peer exchange on practical AI/SOC use cases, consolidate the ecosystem questionnaire input into a shareable enterprise perspective, and facilitate a best-practice exchange on NIS2 board training and audit preparation. Upcoming sessions include a remote research update (April), an onsite quarterly meeting (May, Berlin), additional research updates (summer/autumn), and an onsite Council format in September.