Speaker

Dr. S. Isele

Dr. S. Isele

HelveticMinds - SwissShore LLC, President and Agilist

HelveticMinds - SwissShore LLC, President & Agilist

St. Petersburg, Florida, United States

Actions

Dr. Siegfried Isele is a Managing Director, senior transformation executive, and board-level
advisor with more than 25 years of international leadership experience across insurance,
financial services, government, logistics, retail, and technology.

He specializes in large-scale modernization and transformation programs, including legacy
system replacement, data migration, AI-enabled automation, and regulated platform
transformation. Dr. Isele has led initiatives involving hundreds of specialists across multiple
continents, operating in highly regulated environments where reliability, compliance, and
governance are mission-critical.

In addition to his executive delivery leadership, he serves as a Senior Security Auditor (ISO/IEC
27001 & OT Security) and trusted advisor on cybersecurity, operational risk, and regulatory
compliance. His board and advisory contributions focus on technology strategy,
transformation governance, risk oversight, and executive decision-making.

Dr. Isele is known for his pragmatic application of agile principles, bridging structured
governance with real-world execution. He holds advanced degrees in economics, law, and
business engineering and has completed executive education at Harvard University, MIT,
Columbia Business School, UC Berkeley, and IIM Bangalore.

He is authorized to work in all Europe (incl. D A CH), the United States, and the United Arab Emirates, as well as he operates internationally.

Dr. Siegfried Isele ist Managing Director, Senior Transformation Executive und Board-Advisor mit mehr als 25 Jahren internationaler Führungserfahrung in den Branchen Versicherung, Finanzdienstleistungen, öffentlicher Sektor, Logistik, Handel und Technologie.

Er ist spezialisiert auf groß angelegte Modernisierungs- und Transformationsprogramme, darunter Legacy-Systemablösungen, Datenmigrationen, KI-gestützte Automatisierung sowie die Transformation regulierter Plattformen. In seiner Laufbahn hat Dr. Isele komplexe Initiativen mit mehreren hundert Spezialistinnen und Spezialisten über verschiedene Kontinente hinweg geleitet – häufig in stark regulierten Umfeldern, in denen Zuverlässigkeit, Compliance und Governance geschäftskritisch sind.

Neben seiner operativen Führungsrolle ist er als Senior Security Auditor (ISO/IEC 27001 & OT Security) tätig und berät Organisationen in den Bereichen Cybersicherheit, operatives Risiko und regulatorische Compliance. Auf Board- und Advisory-Ebene liegt sein Schwerpunkt auf Technologiestrategie, Transformations-Governance, Risikosteuerung und fundierter Entscheidungsfindung auf Management-Ebene.

Dr. Isele ist bekannt für seinen pragmatischen Einsatz agiler Prinzipien, mit dem er strukturierte Governance-Modelle wirkungsvoll mit realer Umsetzung verbindet. Er verfügt über fortgeschrittene akademische Abschlüsse in Volkswirtschaftslehre, Rechtswissenschaften und Wirtschaftsingenieurwesen und hat Executive-Education-Programme an der Harvard University, dem MIT, der Columbia Business School, der UC Berkeley sowie dem IIM Bangalore absolviert.

Er ist in ganz Europa (inklusive Deutschland, Österreich und der Schweiz), in den Vereinigten Staaten sowie in den Vereinigten Arabischen Emiraten arbeitsberechtigt und international tätig.

Area of Expertise

  • Business & Management
  • Finance & Banking
  • Information & Communications Technology
  • Law & Regulation
  • Transports & Logistics

Topics

  • Core Transformation & Leadership
  • Large-Scale Digital Transformation
  • Legacy System Modernization
  • Enterprise Transformation Governance
  • Technology Strategy at Board Level
  • Executing Transformation in Regulated Environments
  • Technology & Architecture
  • Agile Delivery & Execution
  • Data Migration & Platform Modernization
  • Pragmatic Agile in Large Enterprises
  • Agile Governance for Complex Programs
  • Bridging Agile and Compliance
  • Managing Distributed & Global Teams
  • From Strategy to Execution
  • Security Risk & Compliance
  • Cybersecurity Governance and Risk Management
  • ISO/IEC 27001 in Practice
  • Operational & Technology Risk Management
  • Security by Design (Built-In Not Bolted-On)
  • Compliance in Digital Transformation
  • Executive & Board Perspectives
  • Technology Risk for Boards
  • Transformation Failure Patterns
  • Executive Decision-Making in Complex Programs
  • Governance Models for Digital Change
  • International & Cross-Cultural
  • Leading Global Transformation Programs
  • Managing Multinational Delivery Teams
  • US–Europe Transformation Perspectives
  • e2 visa
  • StartUp
  • Business Startup Law
  • Startups
  • Technology Startups
  • Startup Innovation & Creativity
  • Startup Legal
  • startup consultant
  • Early Stage Startups
  • Startup Technologies
  • starting a career in tech
  • Foreigner Life
  • Information Technology
  • Agile Transformation
  • Information Security
  • Networking
  • Cybersecurity Workforce Development and Training
  • Modern Work
  • network security
  • Teamwork
  • Future of Work
  • workplace culture
  • modern workplace
  • Digital Workplace
  • Mental Health at Work
  • Remote work
  • Remote Working
  • Administrative Leadership
  • Business Administration
  • AI
  • AI Governance & Responsible AI
  • Enterprise AI Transformation
  • AI Strategy & Organizational Readiness
  • AI in Regulated Environments
  • AI Risk Management
  • AI Governance for Boards
  • AI Without Illusions
  • Governance Before Autonomy
  • Legacy Modernization for the AI Era
  • Enterprise AI Architecture
  • AI Program Governance
  • Operationalizing AI in Enterprises
  • Bridging AI and Enterprise Reality
  • AI Strategy Beyond Hype
  • Helvetic Cybersecurity Maturity Model (HCMM)
  • Cybersecurity Maturity Assessments
  • Governance-Led Cybersecurity Transformation
  • Cybersecurity Operating Models
  • Organizational Cybersecurity Maturity
  • Governance-Centric AI Adoption
  • AI Control Frameworks
  • Enterprise AI Governance Models
  • Controlled Enterprise Transformation
  • Organizational Readiness for AI & Security
  • Governance Before Technology
  • Structured AI Adoption
  • Security Built Into Transformation

Sessions

Trust Before Autonomy: What AI Can Learn from Agile en

For more than two decades, Agile transformed how organizations build software, manage uncertainty, respond to change, and deliver value in complex environments.

Today, Artificial Intelligence is creating a similar wave of disruption. Organizations are investing heavily in AI platforms, copilots, autonomous agents, and large-scale automation initiatives. Yet despite impressive technological advances, many AI programs struggle to move beyond experimentation and deliver sustainable business value.

The reason is surprisingly familiar.

Many of the challenges organizations face with AI today are the same challenges Agile practitioners have encountered for years: ownership, accountability, transparency, governance, trust, feedback loops, and organizational alignment.

This session explores the bridge between Agile software development and successful AI adoption. Rather than focusing on models, algorithms, or vendor solutions, it examines the organizational lessons learned from twenty-five years of Agile transformation and how those lessons can help organizations implement AI more effectively.

Drawing on real-world experience in software delivery, enterprise transformation, governance, cybersecurity, and AI initiatives, Dr. Siegfried Isele presents a practical framework for applying Agile thinking to the next generation of intelligent systems.

Participants will explore why technology alone never solves organizational problems, why trust must be established before autonomy can scale, and how governance can enable innovation rather than restrict it.

The session also examines the growing importance of human oversight, accountability, decision ownership, and continuous learning in increasingly autonomous environments.

The central message is simple:

The Agile movement taught us that control does not eliminate innovation.

It enables sustainable innovation.

The same lesson applies to Artificial Intelligence.

Before organizations can successfully scale autonomy, they must first establish governance, visibility, accountability, and trust.

Control First. Then Autonomy.

Helvetic Cybersecurity Maturity Model – Measuring and Improving Organizational Cyber Resilience en

Cybersecurity is no longer only a technical issue – it has become a strategic business risk. Yet many organizations struggle to understand their actual cybersecurity maturity and how to systematically improve it.

While frameworks such as ISO 27001, NIST, or CIS provide important guidance, they often do not clearly answer the practical question many executives ask: Where do we stand today, and what should we improve first?

This session introduces the Helvetic Cybersecurity Maturity Model (HCMM), a structured framework designed to assess, visualize, and improve an organization's cybersecurity maturity in a practical and understandable way.

Inspired by principles of Swiss precision and structured engineering, HCMM helps organizations evaluate their security posture across key domains such as governance, identity management, infrastructure protection, monitoring, incident response, human factors, and data protection.

Participants will learn how maturity-based assessments can help translate complex cybersecurity challenges into clear management decisions, prioritize investments, and create realistic improvement roadmaps toward stronger cyber resilience.

The session provides strategic insights, practical perspectives, and a structured way to think about cybersecurity as a continuous improvement process rather than a collection of isolated security tools.

HCMM ¦ Beyond Compliance: Why Most Cybersecurity Programs Still Fail in the Real World en

Organizations today are overwhelmed by cybersecurity frameworks, audits, scorecards, compliance requirements, and vendor promises — yet many still struggle to answer fundamental operational questions:
- Where are we actually vulnerable?
- Which weaknesses matter most?
- What should we improve first?
- How do we measure real progress?
- And how resilient are we beyond compliance checklists?

Frameworks such as ISO 27001, NIST CSF, CIS Controls, Zero Trust architectures, and various maturity assessments provide valuable guidance. However, in real-world environments, many organizations still face a dangerous gap between documented compliance and actual operational cyber resilience.

This session introduces the Helvetic Cybersecurity Maturity Model (HCMM), a practical and structured approach designed to help organizations assess, visualize, prioritize, and improve cybersecurity maturity in a measurable and operationally meaningful way.

Rather than introducing “yet another framework,” this talk focuses on the real-world challenges many organizations face today:
- security programs driven by compliance instead of resilience
- fragmented tooling without strategic visibility
- unclear prioritization of investments
- leadership blind spots
- and the growing disconnect between technical controls and business risk

The session explores how maturity-based approaches can help organizations:
- identify operational weaknesses
- improve governance visibility
- prioritize security initiatives
- align cybersecurity with business objectives
- and build realistic improvement roadmaps instead of checkbox-driven activities

Attendees will gain practical insights into:
- where traditional cybersecurity maturity initiatives often fail
- why compliance alone is not enough
- how organizations can evaluate cyber resilience more realistically
- and how structured maturity models can support better operational and strategic decision-making

The presentation includes practical examples, governance considerations, operational perspectives, and lessons learned from complex transformation and cybersecurity environments.

Participants will leave with:
- a clearer understanding of the gap between compliance and resilience
- practical ideas for evaluating cybersecurity maturity
- approaches for prioritizing security improvements
- and actionable concepts for building measurable cyber resilience programs

Control First, Then Autonomy: Why Most Enterprise AI Agents Fail on Day Two en

Everyone is talking about autonomous AI agents.

But once organizations move beyond prototypes, they quickly discover that the challenge is not intelligence—it is governance, observability, security, ownership, and operational control.

This session explores how cloud-native platforms and Kubernetes can provide the foundation for responsible AI adoption.

Topics include:
Agent architectures in enterprise environments
Observability for AI workloads
Security and governance considerations
Local and sovereign AI deployments
Platform engineering patterns for AI operations
Lessons learned from real-world implementations

Attendees will learn why successful AI adoption depends less on model selection and more on the operational foundations that enable control, transparency, and scalability.

The session provides practical guidance for platform engineers, architects, DevOps teams, and technology leaders building AI-enabled systems in production environments.

Control First: Building Auditable AI Systems in Regulated Enterprise Environments en

Most organizations are rushing to deploy AI systems before they fully understand how to secure, govern, monitor, and control them at scale.

This session explores how regulated enterprise environments can build AI systems that are not only powerful, but also auditable, resilient, and operationally trustworthy.

Drawing from real-world modernization and transformation programs, Dr. Siegfried Isele demonstrates why AI security is often less about “protecting the model” and more about controlling the surrounding operational ecosystem: identity, governance, data ownership, monitoring, deployment pipelines, access boundaries, and accountability.

The talk focuses on practical architectural patterns, governance mechanisms, operational controls, and failure scenarios observed in complex enterprise environments.

Attendees will see how organizations can move from uncontrolled experimentation toward structured, secure, and scalable AI adoption without sacrificing agility or innovation.

Why AI, DevOps & Platform Engineering Fail Without Governance en de

Organizations are investing heavily in DevOps, Platform Engineering, AI, and automation. Yet many still struggle with slow delivery, recurring incidents, security concerns, compliance challenges, and unpredictable operations.

The problem is rarely technology.

It's the absence of operational governance.

Automation doesn't eliminate organizational problems—it amplifies them. AI coding assistants, GitOps, Infrastructure as Code, CI/CD pipelines, and autonomous operations can only deliver their full value when ownership, accountability, and governance are already in place.

Drawing on more than 25 years of leading international software delivery and transformation programs across Europe, North America, the Middle East, and Asia, this session shares practical lessons learned from organizations that successfully scaled DevOps—and from those that didn't.

Rather than focusing on another tool or framework, we'll explore how leadership, governance, engineering culture, and organizational design determine whether DevOps becomes a competitive advantage or simply another expensive initiative.

Attendees will leave with practical ideas they can immediately apply to build engineering organizations that deliver faster, remain secure, and are ready for AI-driven software development.

Audience
- DevOps Engineers
- Platform Engineers
- Engineering Managers
- DevOps Leaders
- Solution Architects
- CTOs & CIOs
- Transformation Leaders

Key Takeaways
- Why automation magnifies organizational weaknesses
- The hidden difference between governance and bureaucracy
- How AI fundamentally changes DevOps operating models
- Organizational patterns that enable high-performing engineering teams
- A practical roadmap for implementing "Control First. Then Autonomy."

Recommended Duration
- 45–60 minutes (also suitable as a 30-minute conference session)

Session Type
- Conference Talk / Keynote

Technical Level
- Intermediate to Advanced

Tracks
- DevOps • Platform Engineering • DevSecOps • AIOps • Engineering Leadership • Digital Transformation • AI Governance

Warum AI, DevOps & Platform Engineering ohne Governance scheitern en de

Unternehmen investieren massiv in DevOps, Platform Engineering, Künstliche Intelligenz und Automatisierung. Trotzdem kämpfen viele weiterhin mit langsamen Releases, wiederkehrenden Incidents, Sicherheitsproblemen, Compliance-Anforderungen und einer nur schwer beherrschbaren IT-Landschaft.

Das eigentliche Problem ist selten die Technologie.

Es ist fehlende Governance.

Automatisierung beseitigt organisatorische Schwächen nicht – sie verstärkt sie. AI Coding Assistants, GitOps, Infrastructure as Code, CI/CD-Pipelines oder autonome Betriebsmodelle entfalten ihren Nutzen erst dann, wenn Verantwortlichkeiten, Entscheidungsstrukturen und Governance klar definiert sind.

Basierend auf mehr als 25 Jahren Erfahrung in internationalen Software- und Transformationsprojekten in Europa, Nordamerika, dem Mittleren Osten und Asien zeigt diese Session, warum erfolgreiche DevOps-Organisationen zuerst Kontrolle schaffen und erst danach den Grad der Automatisierung erhöhen.

Statt über das nächste Framework oder Tool zu sprechen, beleuchtet dieser Vortrag die entscheidenden Faktoren erfolgreicher Transformationen: Führung, Governance, Engineering-Kultur und Organisationsdesign.

Die Teilnehmer erhalten konkrete Impulse und praxiserprobte Ansätze, um DevOps nachhaltig zu skalieren, AI sinnvoll zu integrieren und gleichzeitig Geschwindigkeit, Qualität und Sicherheit zu erhöhen.

Zielgruppe
- DevOps Engineers
- Platform Engineers
- DevSecOps Engineers
- Engineering Manager
- Solution Architects
- CTOs & CIOs
- IT- und Transformationsverantwortliche

Die Teilnehmer lernen
- Warum Automatisierung bestehende organisatorische Probleme verstärkt
- Weshalb Governance Innovation ermöglicht statt verhindert
- Wie AI die Anforderungen an DevOps grundlegend verändert
- Welche organisatorischen Muster erfolgreiche Engineering-Teams auszeichnen
- Wie das Prinzip "Control First. Then Autonomy." in der Praxis umgesetzt werden kann

Empfohlene Dauer
- 45–60 Minuten (auch als 30-Minuten-Konferenzvortrag geeignet)

Format
- Konferenzvortrag / Keynote

Technisches Niveau
- Fortgeschritten

Geeignet für Tracks
- DevOps • Platform Engineering • DevSecOps • AIOps • Engineering Leadership • Digitale Transformation • AI Governance

Why Offensive AI Still Struggles Against Real Enterprise Environments en de

Autonomous AI agents are rapidly changing the offensive security landscape. Every week brings new demonstrations of AI-driven reconnaissance, vulnerability discovery, exploitation, and autonomous penetration testing.

But there is one question that receives surprisingly little attention:

What happens when these agents leave the lab and enter a real enterprise?

Enterprise environments are rarely clean or predictable. They consist of decades of legacy systems, hybrid cloud architectures, fragmented identity management, technical debt, governance requirements, conflicting security controls, and thousands of interconnected business applications.

This session explores where today's offensive AI agents excel—and where they still struggle.

Rather than focusing on demonstrations or hype, we will examine the operational reality of complex organizations and discuss why context, identity, governance, and organizational complexity remain some of the biggest obstacles for autonomous attackers.

Attendees will gain a realistic perspective on the current capabilities of Offensive AI, understand its practical limitations, and learn why the future of offensive security is likely to be built on collaboration between skilled human operators and AI—not full autonomy.

Audience

Offensive Security
Red Teams
Security Architects
CISOs
Enterprise Architects
AI Security Engineers

Session Length

30–45 minutes

Level

Intermediate

Takeaways

Where Offensive AI works today
Why enterprise environments are fundamentally different from lab environments
The role of identity, governance and legacy systems
What organizations should prepare for over the next 3–5 years

No live hacking demonstrations. Focus on enterprise strategy, operational reality and emerging AI capabilities.

Warum Offensive AI Agents in realen Enterprise-Umgebungen scheitern en de

Autonome KI-Agenten verändern derzeit die Welt der Offensive Security. Fast täglich erscheinen neue Demonstrationen zu AI-gestützter Aufklärung, Schwachstellenanalyse, Exploit-Entwicklung oder autonomen Penetrationstests.

Doch eine entscheidende Frage wird dabei oft übersehen:

Was passiert, wenn diese Agenten das Labor verlassen und auf die Realität großer Unternehmen treffen?

Enterprise-Umgebungen bestehen selten aus überschaubaren Testsystemen. Stattdessen treffen AI-Agenten auf jahrzehntealte Legacy-Systeme, hybride Cloud-Landschaften, komplexe Identitätsstrukturen, technische Schulden, regulatorische Anforderungen sowie tausende voneinander abhängige Anwendungen und Prozesse.

Dieser Vortrag zeigt, wo Offensive AI heute bereits beeindruckende Ergebnisse erzielt – und warum sie in realen Unternehmensumgebungen dennoch häufig an organisatorischer und technischer Komplexität scheitert.

Anstatt spektakuläre Demos oder Buzzwords in den Mittelpunkt zu stellen, betrachten wir die Realität großer Unternehmen und diskutieren, warum Kontext, Identitäten, Governance und gewachsene IT-Landschaften auch künftig entscheidende Faktoren erfolgreicher Angriffe und Verteidigungsstrategien bleiben.

Die Teilnehmer erhalten einen realistischen Blick auf den aktuellen Stand von Offensive AI, ihre Grenzen sowie darauf, warum die Zukunft der Offensive Security wahrscheinlich in der Zusammenarbeit von erfahrenen Sicherheitsexperten und KI liegt – nicht in vollständig autonomen Angreifern.

Zielgruppe

Red Teams
Offensive Security
Security Architects
Enterprise Architects
CISOs
AI Security Engineers

Dauer

30–45 Minuten

Level

Fortgeschritten

Die Teilnehmer lernen

Wo Offensive AI heute bereits eingesetzt werden kann
Warum Enterprise-Umgebungen grundlegend anders funktionieren als Laborumgebungen
Welche Rolle Identitäten, Governance und Legacy-Systeme spielen
Wie sich Unternehmen auf die nächsten 3–5 Jahre vorbereiten können

Keine Live-Hacking-Demonstrationen. Der Schwerpunkt liegt auf Enterprise-Realität, strategischen Zusammenhängen und den praktischen Möglichkeiten sowie Grenzen von Offensive AI.

The AI Attack Surface Nobody Talks About - Hidden Risks Beyond Prompts, Models and Chatbots en de

Most discussions about AI security focus on prompt injection, model poisoning or jailbreaks.

Those are important—but they are only the beginning.

As organizations deploy AI agents, Model Context Protocol (MCP), autonomous workflows, API orchestration and agent-to-agent communication, an entirely new attack surface is emerging.

Unlike traditional applications, AI systems continuously consume external data, invoke tools, exchange context and make decisions across multiple systems. Every connector, identity, API, memory store and autonomous action becomes a potential entry point for attackers.

This session explores the hidden enterprise attack surface created by modern AI ecosystems.

We will discuss identity propagation, agent permissions, API trust relationships, MCP security considerations, supply-chain risks, Shadow AI, data exposure and the governance challenges introduced by autonomous systems.

Instead of focusing on theoretical attacks, this presentation provides practical guidance for architects, security leaders and engineering teams preparing their organizations for the next generation of AI-enabled enterprise systems.

Because protecting AI is no longer about protecting a model.

It is about protecting an entire ecosystem.

Audience

Security Architects
AI Engineers
Platform Engineers
Enterprise Architects
CISOs
DevSecOps
AI Governance Teams

Session Length

30–45 minutes

Level

Intermediate

Takeaways

Understanding the emerging AI attack surface
Risks introduced by AI Agents and MCP
Identity and API security in autonomous systems
Governance recommendations for enterprise AI adoption
Practical controls beyond prompt security

No live hacking. Enterprise-focused architecture and security strategy.

Die AI-Angriffsfläche, über die kaum jemand spricht Versteckte Risiken jenseits von Prompts en de

Die meisten Diskussionen über AI Security drehen sich um Prompt Injection, Jailbreaks oder Model Poisoning.

Diese Themen sind wichtig – sie bilden jedoch nur einen kleinen Teil der tatsächlichen Herausforderung.

Mit AI Agents, dem Model Context Protocol (MCP), autonomen Workflows, API-Orchestrierung und Agent-zu-Agent-Kommunikation entsteht eine völlig neue Angriffsfläche.

Im Gegensatz zu klassischen Anwendungen greifen KI-Systeme kontinuierlich auf externe Datenquellen zu, verwenden Werkzeuge, treffen Entscheidungen und kommunizieren eigenständig mit anderen Systemen. Jeder Connector, jede Identität, jede API, jeder Memory Store und jede autonome Aktion kann dabei zu einem potenziellen Angriffspunkt werden.

Dieser Vortrag beleuchtet die oft übersehene Enterprise-Angriffsfläche moderner KI-Ökosysteme.

Wir betrachten Risiken rund um Identitäten, Berechtigungen, API-Vertrauensbeziehungen, MCP, Shadow AI, Lieferketten, Datenexposition und Governance-Anforderungen, die mit autonomen KI-Systemen entstehen.

Anhand praxisnaher Beispiele wird gezeigt, warum die Absicherung von KI heute weit über den Schutz eines einzelnen Modells hinausgeht.

Denn künftig schützen wir nicht mehr nur ein Modell.

Wir schützen ein gesamtes KI-Ökosystem.

Zielgruppe

Security Architects
AI Engineers
Enterprise Architects
Platform Engineers
DevSecOps
CISOs
AI Governance Teams

Dauer

30–45 Minuten

Level

Fortgeschritten

Die Teilnehmer lernen

Die neue Enterprise-Angriffsfläche moderner KI-Systeme zu verstehen
Risiken von AI Agents und MCP einzuordnen
Identitäts- und API-Sicherheit für autonome Systeme zu bewerten
Governance-Maßnahmen für Enterprise AI abzuleiten
Praktische Sicherheitskontrollen jenseits von Prompt Security umzusetzen

Keine Live-Hacking-Demonstrationen. Fokus auf Enterprise-Architektur, Governance und praktische Sicherheitsstrategien.

AI Doesn't Hack Your Company. Complexity Does. Why Enterprise Architecture Is the Biggest Challenge en de

Artificial Intelligence is often portrayed as the next major cybersecurity threat.

But what if we're asking the wrong question?

AI does not create complexity.

It exposes it.

Years of technical debt, fragmented architectures, disconnected identities, legacy systems, shadow IT, inconsistent governance and poorly understood business processes have created environments that are already difficult for humans to manage.

AI simply operates within that reality—whether used by attackers or defenders.

This session challenges common assumptions about AI-driven cyber threats and explores why organizational complexity has become the true attack surface of modern enterprises.

Rather than focusing on individual vulnerabilities or AI models, we will examine the systemic risks hidden inside large organizations and discuss why architecture, governance, identity and operational transparency matter more than ever.

Attendees will leave with a practical framework for reducing enterprise complexity, improving cyber resilience and preparing their organizations for an AI-driven future.

Because the strongest defense against AI is not another AI.

It is a well-understood enterprise.

Audience
- Enterprise Architects
- CISOs
- Security Architects
- Technology Leaders
- IT Executives
- AI Governance Teams

Session Length
30–45 minutes

Level
Intermediate

Takeaways
- Why complexity is becoming the real attack surface
- How AI amplifies existing weaknesses
- The relationship between enterprise architecture and cyber resilience
- Practical governance recommendations
- Reducing complexity before introducing AI

No live hacking. Enterprise strategy, architecture and governance.

KI hackt Ihr Unternehmen nicht. Komplexität tut es. Die wahre Cybersecurity-Fragen im KI-Zeitalter en de

Künstliche Intelligenz wird häufig als die nächste große Bedrohung für die Cybersicherheit dargestellt.

Doch vielleicht stellen wir die falsche Frage.

KI erzeugt keine Komplexität.

Sie macht sie sichtbar.

Jahrelang gewachsene IT-Landschaften, technische Schulden, fragmentierte Architekturen, unklare Identitäten, Legacy-Systeme, Shadow IT und fehlende Governance haben Unternehmensumgebungen geschaffen, die bereits heute kaum noch vollständig beherrschbar sind.

KI arbeitet lediglich innerhalb dieser Realität – unabhängig davon, ob sie von Angreifern oder Verteidigern eingesetzt wird.

Dieser Vortrag stellt gängige Annahmen über KI-gestützte Cyberangriffe infrage und zeigt, warum organisatorische und technische Komplexität zur eigentlichen Angriffsfläche moderner Unternehmen geworden ist.

Anstatt einzelne Schwachstellen oder Sprachmodelle zu analysieren, betrachten wir die strukturellen Risiken komplexer Enterprise-Landschaften und diskutieren, weshalb Architektur, Governance, Identitätsmanagement und Transparenz entscheidend für die Cyber-Resilienz der Zukunft sind.

Die Teilnehmer erhalten konkrete Ansätze, wie Unternehmen ihre Komplexität reduzieren, ihre Widerstandsfähigkeit erhöhen und sich nachhaltig auf den Einsatz von KI vorbereiten können.

Denn die beste Verteidigung gegen KI ist nicht noch mehr KI.

Sie beginnt mit einer Organisation, die ihre eigene Komplexität versteht.

Zielgruppe
- Enterprise Architects
- CISOs
- Security Architects
- IT-Leiter
- Technologieverantwortliche
- AI Governance Teams

Dauer
30–45 Minuten

Level
- Fortgeschritten

Die Teilnehmer lernen
- Warum Komplexität zur eigentlichen Angriffsfläche moderner Unternehmen wird
- Weshalb KI bestehende Schwächen verstärkt, statt neue zu schaffen
- Wie Enterprise-Architektur und Cyber-Resilienz zusammenhängen
- Welche Governance-Maßnahmen nachhaltige Sicherheit ermöglichen
- Wie Komplexität reduziert werden kann, bevor KI skaliert wird

Keine Live-Hacking-Demonstrationen. Fokus auf Enterprise-Architektur, Governance und strategische Cyber-Resilienz.

Your Newest Teammate Is AI – But Who Is Actually in Charge? en de

AI is no longer just a tool employees occasionally use. It is increasingly becoming an active participant in everyday work: researching information, drafting content, writing code, analyzing data, preparing decisions, and coordinating tasks across functions.

But adding AI to a team changes more than productivity. It changes roles, responsibilities, communication, accountability, and ultimately the operating model itself.

Who assigns work to an AI teammate? What context and permissions does it receive? Who validates its output? Who remains accountable when decisions are influenced—or tasks are executed—by AI? And how can organizations benefit from greater autonomy without losing human judgment and control?

This session introduces a practical model for integrating AI into human teams. It explores how leaders can define clear roles, decision rights, workflows, validation points, and guardrails while preserving trust, ownership, and effective collaboration.

The central message is simple: AI can become a valuable teammate—but it must never become an undefined one.

Designed for executives, business leaders, product and technology teams, HR and organizational development professionals, transformation leaders, and AI governance practitioners. No advanced technical knowledge is required. The session can be delivered as a 30–45-minute keynote, a 60-minute interactive session, or an extended workshop. It can be adapted to different industries and organizational maturity levels. The presentation focuses on practical operating models, team design, accountability, governance, and responsible AI adoption rather than specific AI products or vendors.

Ihr neuestes Teammitglied ist eine KI – aber wer hat eigentlich das Sagen? en de

KI ist längst nicht mehr nur ein Werkzeug, das Mitarbeitende gelegentlich verwenden. Sie wird zunehmend zu einem aktiven Bestandteil der täglichen Zusammenarbeit: Sie recherchiert Informationen, erstellt Inhalte, schreibt Code, analysiert Daten, bereitet Entscheidungen vor und übernimmt Aufgaben über verschiedene Funktionen hinweg.

Doch wenn KI Teil eines Teams wird, verändert sich nicht nur die Produktivität. Rollen, Verantwortlichkeiten, Kommunikation, Entscheidungswege und letztlich das gesamte Betriebsmodell verändern sich mit.

Wer erteilt einem KI-Teammitglied seine Aufgaben? Welchen Kontext und welche Berechtigungen erhält es? Wer prüft seine Ergebnisse? Wer trägt die Verantwortung, wenn Entscheidungen durch KI beeinflusst oder Aufgaben von ihr ausgeführt werden? Und wie können Unternehmen mehr Autonomie ermöglichen, ohne dabei menschliches Urteilsvermögen und Kontrolle zu verlieren?

Dieser Vortrag stellt ein praxisnahes Modell für die Integration von KI in menschliche Teams vor. Er zeigt, wie Führungskräfte klare Rollen, Entscheidungsbefugnisse, Arbeitsabläufe, Validierungspunkte und Leitplanken definieren können – und dabei Vertrauen, Verantwortung und wirksame Zusammenarbeit erhalten.

Die zentrale Botschaft ist einfach: KI kann ein wertvolles Teammitglied werden – aber niemals eines mit einer ungeklärten Rolle.

Control First. Then Autonomy.

Geeignet für Geschäftsleitungen, Führungskräfte, Produkt- und Technologieteams, HR und Organisationsentwicklung, Transformationsverantwortliche sowie Fachpersonen aus AI Governance, Risiko und Compliance. Technische Vorkenntnisse sind nicht erforderlich. Die Session kann als 30- bis 45-minütige Keynote, als interaktiver 60-Minuten-Vortrag oder als vertiefender Workshop durchgeführt werden. Inhalt und Beispiele können an Branche, Zielgruppe und organisatorischen Reifegrad angepasst werden. Im Mittelpunkt stehen Betriebsmodell, Teamgestaltung, Verantwortlichkeit, Governance und die verantwortungsvolle Integration von KI – nicht einzelne Produkte oder Anbieter.

Keynote: Legacy Modernization: Turning Enterprise Risk Into Controlled, Agile Transformation en de

Built for all which need navigating scale, complexity, and accountability, this keynote examines how long-standing systems can quietly slow momentum, limit visibility, and strain decision-making. It reframes large-scale change as a deliberate and structured shift that strengthens control while enabling adaptability across the organization.Through real-world leadership perspectives, the session will highlight how founders can reduce uncertainty, reinforce governance, and introduce flexibility without unsettling core operations. Attendees will leave with a clearer path to strengthening what already exists, accelerating decisions, and building an organization that is ready to grow with intent, not urgency.

Agile Beyond the Buzzwords: Swiss Quality, Global Teams, and Sustainable Leadership en de

Agile has become mainstream - yet many organizations still struggle with confusion, dogma, and superficial adoption. This talk reframes Agile software development not as a collection of methods or frameworks, but as a mindset rooted in responsibility, clarity, and long-term quality.

Drawing from the principles behind Swiss Quality with Digital Nomads, the session explores how Swiss precision and global collaboration can coexist in modern, distributed teams. Through real-world examples, reflective insights, and practical observations, the talk cuts through hype and shows what actually makes Agile work in complex, international environments.

Based on the concepts and real-world experience behind the book Agile Software Development – Swiss Quality with Digital Nomads

Suitable for both academic and industry audiences

No deep technical knowledge required; accessible to non-engineers

Preferred formats: 45–60 minute presentation or keynote

Focus on leadership, mindset, and organizational impact rather than tools or frameworks

From Founder to Treaty Investor: What the E-2 Visa Really Takes in Practice en de

The E-2 Treaty Investor visa is often described in vague terms—“substantial investment,” “active business,” “non-immigrant intent.” In reality, success depends far less on theory and far more on preparation, structure, and execution.

This session offers a first-hand, experience-based perspective on what it actually takes to obtain and use an E-2 visa successfully. The talk walks through the real journey from company formation and capital structuring to documentation, interviews, and operational realities after approval.

Rather than providing legal advice, the session focuses on practical lessons learned, common misconceptions, and typical mistakes that delay or derail E-2 applications. Participants will gain clarity on timelines, investment logic, business credibility, and how U.S. authorities evaluate intent, risk, and substance.

The session can be delivered in English or German, or as a bilingual format, depending on audience needs.

Experience-based session, not legal or immigration advice

Based on a real E-2 Treaty Investor journey (U.S. company formation, investment, approval, and operation)

Suitable for founders, executives, researchers, and international professionals

No prior visa knowledge required

Session language: English and/or German (bilingual option available)

Preferred format: 45–60 minute presentation or keynote with Q&A

HCMM ¦ Beyond Compliance: Why Most Cybersecurity Programs Still Fail in the Real World en de

Organizations today are overwhelmed by cybersecurity frameworks, audits, scorecards, compliance requirements, and vendor promises — yet many still struggle to answer fundamental operational questions:
- Where are we actually vulnerable?
- Which weaknesses matter most?
- What should we improve first?
- How do we measure real progress?
- And how resilient are we beyond compliance checklists?

Frameworks such as ISO 27001, NIST CSF, CIS Controls, Zero Trust architectures, and various maturity assessments provide valuable guidance. However, in real-world environments, many organizations still face a dangerous gap between documented compliance and actual operational cyber resilience.

This session introduces the Helvetic Cybersecurity Maturity Model (HCMM), a practical and structured approach designed to help organizations assess, visualize, prioritize, and improve cybersecurity maturity in a measurable and operationally meaningful way.

Rather than introducing “yet another framework,” this talk focuses on the real-world challenges many organizations face today:
- security programs driven by compliance instead of resilience
- fragmented tooling without strategic visibility
- unclear prioritization of investments
- leadership blind spots
- and the growing disconnect between technical controls and business risk

The session explores how maturity-based approaches can help organizations:
- identify operational weaknesses
- improve governance visibility
- prioritize security initiatives
- align cybersecurity with business objectives
- and build realistic improvement roadmaps instead of checkbox-driven activities

Attendees will gain practical insights into:
- where traditional cybersecurity maturity initiatives often fail
- why compliance alone is not enough
- how organizations can evaluate cyber resilience more realistically
- and how structured maturity models can support better operational and strategic decision-making

The presentation includes practical examples, governance considerations, operational perspectives, and lessons learned from complex transformation and cybersecurity environments.

Participants will leave with:
- a clearer understanding of the gap between compliance and resilience
- practical ideas for evaluating cybersecurity maturity
- approaches for prioritizing security improvements
- and actionable concepts for building measurable cyber resilience programs

Target audience:
Cybersecurity professionals, CISOs, security architects, governance leaders, auditors, risk managers, transformation leaders, IT leadership, and practitioners interested in operational cyber resilience and measurable security improvement.

Preferred session length:
45 minutes including Q&A. (+/- 15 min.)

Session style:
Practical, strategic, and operationally focused. The session combines governance perspectives with real-world cybersecurity and transformation observations. No vendor promotion. No product sales. No theoretical “framework-only” discussion.

Primary focus areas:
Cyber resilience, governance, operational maturity, security prioritization, risk visibility, leadership alignment, and measurable cybersecurity improvement.

Key takeaway:
Compliance may help organizations pass audits — but resilience determines whether organizations survive real-world cyber incidents.

HCMM: Beyond Compliance — Warum die meisten Cybersecurity-Programme in der Realität oft scheitern. en de

Organisationen werden heute von Cybersecurity-Frameworks, Audits, Compliance-Anforderungen, Scorecards und Security-Tools regelrecht überflutet — und dennoch kämpfen viele Unternehmen weiterhin mit grundlegenden Fragen:
- Wo sind wir tatsächlich verwundbar?
- Welche Risiken sind wirklich kritisch?
- Wo sollten wir zuerst investieren?
- Wie messen wir echten Fortschritt?
- Und wie resilient sind wir tatsächlich — jenseits von Compliance-Checklisten?

Frameworks wie ISO 27001, NIST CSF, CIS Controls oder Zero-Trust-Architekturen liefern wertvolle Orientierung. In der Realität entsteht jedoch häufig eine gefährliche Lücke zwischen dokumentierter Compliance und tatsächlicher operativer Cyber-Resilienz.

Diese Session stellt das Helvetic Cybersecurity Maturity Model (HCMM) vor — einen praxisorientierten und strukturierten Ansatz, um Cybersecurity-Reifegrade messbar zu bewerten, Schwachstellen sichtbar zu machen und realistische Verbesserungs-Roadmaps abzuleiten.

Dabei geht es ausdrücklich nicht darum, „noch ein weiteres Framework“ vorzustellen. Im Fokus stehen vielmehr die realen Herausforderungen moderner Sicherheitsorganisationen:

Compliance-getriebene Security statt echter Resilienz
Fragmentierte Security-Landschaften ohne strategische Transparenz
Unklare Priorisierung von Investitionen
Fehlende Management-Sichtbarkeit
Und die wachsende Lücke zwischen technischen Kontrollen und tatsächlichem Geschäftsrisiko

Die Session zeigt anhand praxisnaher Perspektiven:
- warum viele Reifegradmodelle in der Praxis scheitern
- weshalb Compliance alleine nicht ausreicht
- wie Unternehmen Cyber-Resilienz realistischer bewerten können
- und wie strukturierte Maturity-Ansätze helfen können, Sicherheitsmaßnahmen strategisch und operativ sinnvoll zu priorisieren

Teilnehmer erhalten konkrete Impulse für:
- die Bewertung von Cybersecurity-Reifegraden
- die Priorisierung von Security-Initiativen
- die Verbesserung von Governance-Transparenz
- und den Aufbau messbarer Cyber-Resilienz statt reiner „Checkbox Security“

Die Session kombiniert Governance-, Security- und Transformationserfahrung aus komplexen internationalen Umgebungen mit praxisorientierten Beobachtungen und umsetzbaren Ansätzen.

Zielgruppe
Cybersecurity-Professionals, CISOs, Security-Architekten, Auditoren, Governance- und Risk-Manager, IT-Leitung, Transformationsverantwortliche sowie Fach- und Führungskräfte mit Interesse an messbarer Cyber-Resilienz und operativer Security-Reife.

Session-Länge
45 Minuten inklusive Q&A. (+/- 15 min.)

Stil der Session
Praxisnah, strategisch und operativ orientiert. Die Session verbindet Governance-, Sicherheits- und Transformationsperspektiven mit realen Erfahrungen aus komplexen Unternehmensumgebungen.
...und wichtig: Keine Produktwerbung. Keine Vendor-Pitches. Kein rein theoretischer Framework-Vortrag.

Fokusbereiche
Cyber-Resilienz, Governance, Security-Maturity, Risikotransparenz, Priorisierung von Sicherheitsmaßnahmen, Leadership Alignment und messbare Verbesserung von Sicherheitsorganisationen.

Kernaussage
Compliance hilft Unternehmen möglicherweise dabei, Audits zu bestehen.
Resilienz entscheidet jedoch darüber, ob Unternehmen reale Cyberangriffe überstehen.

Control First. Then Autonomy. – Why Most AI Initiatives Fail Before They Scale en de

Everyone is talking about AI capabilities, autonomous agents, and rapid innovation.

But in reality, most organizations are not struggling with AI itself.
They are struggling with structure, governance, ownership, and control.

In this keynote, Dr. Siegfried Isele shares a pragmatic and executive-level perspective on why many AI initiatives fail long before the technology becomes the real problem.

The session focuses on:

Why AI is not primarily a tooling problem
The hidden risks of autonomy without governance
Why data reality matters more than model hype
The importance of operating models and ownership
Local AI, sovereignty, and controlled architectures
How organizations can scale AI without losing control

Drawing from real-world consulting, enterprise transformation, and international project experience, this session connects Agile thinking, governance, and AI execution in a practical and business-oriented way.

This is not another “AI hype session.”
It is a reality check for leaders, architects, transformation managers, and organizations trying to move from experimentation to sustainable AI adoption.

Agilität jenseits der Buzzwords: Schweizer Qualität, globale Teams und nachhaltige Führung. en de

Agilität ist mittlerweile Mainstream – doch viele Unternehmen kämpfen nach wie vor mit Verwirrung, Dogmatismus und einer oberflächlichen Umsetzung. In diesem Vortrag wird agile Softwareentwicklung nicht als eine Ansammlung von Methoden oder Frameworks betrachtet, sondern als eine Denkweise, die auf Verantwortung, Klarheit und langfristiger Qualität basiert.

Ausgehend von den Prinzipien von „Swiss Quality with Digital Nomads” erforscht die Sitzung, wie sich Schweizer Präzision und globale Zusammenarbeit in modernen, verteilten Teams miteinander vereinbaren lassen. Anhand von Beispielen aus der Praxis, reflektierenden Einblicken und praktischen Beobachtungen durchbricht der Vortrag den Hype und zeigt, was Agilität in komplexen, internationalen Umgebungen tatsächlich zum Erfolg führt.

Die Konzepte und praktischen Erfahrungen aus dem Buch „Agile Softwareentwicklung – Schweizer Qualität mit digitalen Nomaden“ bilden die Grundlage.

– geeignet für akademisches und industrielles Publikum

Es sind keine tiefgreifenden technischen Kenntnisse erforderlich, sodass auch Nicht-Ingenieure den Inhalt verstehen können.

Bevorzugte Formate: 45–60-minütiger Vortrag oder Keynote.

Der Schwerpunkt liegt auf Führung, Denkweise und organisatorischen Auswirkungen statt auf Tools oder Frameworks.

Vom Gründer zum Treaty Investor: Was das E-2-Visum in der Praxis wirklich erfordert en de

Das E-2-Visum für Investoren im Rahmen des Investitionsabkommens wird oft mit vagen Begriffen beschrieben – „erhebliche Investition“, „aktives Geschäft“, „Nicht-Einwanderungsabsicht“. In Wirklichkeit hängt der Erfolg weit weniger von der Theorie als vielmehr von der Vorbereitung, der Struktur und der Umsetzung ab.

Diese Veranstaltung bietet einen aus erster Hand stammenden, erfahrungsbasierten Einblick in die tatsächlichen Voraussetzungen für die erfolgreiche Beantragung und Nutzung eines E-2-Visums. Der Vortrag führt durch den realen Prozess von der Unternehmensgründung und Kapitalstrukturierung bis hin zu Dokumentation, Interviews und den betrieblichen Realitäten nach der Genehmigung.

Anstatt Rechtsberatung zu bieten, konzentriert sich die Veranstaltung auf praktische Erfahrungen, verbreitete Missverständnisse und typische Fehler, die E-2-Anträge verzögern oder zum Scheitern bringen. Die Teilnehmer erhalten Klarheit über Zeitpläne, Investitionslogik, geschäftliche Glaubwürdigkeit und darüber, wie US-Behörden Absicht, Risiko und Substanz bewerten.

Die Veranstaltung kann je nach den Bedürfnissen des Publikums auf Englisch oder Deutsch oder in einem zweisprachigen Format abgehalten werden.

Erfahrungsbasierte Veranstaltung, keine Rechts- oder Einwanderungsberatung

Basierend auf dem realen Werdegang eines US-amerikanischen E-2-Vertragsinvestors (Gründung eines US-Unternehmens, Investition, Genehmigung und Betrieb)

Geeignet für Gründer, Führungskräfte, Forscher und internationale Fachkräfte

Keine Vorkenntnisse im Visumbereich erforderlich

Veranstaltungssprache: Englisch und/oder Deutsch (zweisprachige Option verfügbar)

Bevorzugtes Format: 45–60-minütige Präsentation oder Keynote mit Frage-und-Antwort-Runde

Zunächst Kontrolle. Dann Autonomie. Warum die meisten KI-Initiativen scheitern, bevor sie skalieren en de

Alle reden von KI-Fähigkeiten, autonomen Agenten und rascher Innovation.

In Wirklichkeit kämpfen die meisten Unternehmen jedoch nicht mit der KI selbst.
Vielmehr kämpfen sie mit Strukturen, Governance, Verantwortlichkeiten und Kontrolle.

In dieser Keynote vermittelt Dr. Siegfried Isele eine pragmatische Perspektive auf Führungsebene und erklärt, warum viele KI-Initiativen scheitern, lange bevor die Technologie selbst zum eigentlichen Problem wird.

Im Mittelpunkt der Sitzung stehen folgende Themen:

- Warum KI nicht in erster Linie ein Problem der Werkzeuge ist,
- Die versteckten Risiken von Autonomie ohne Governance,
- Warum Datenrealität wichtiger ist als der Hype um Modelle,
- Die Bedeutung von Betriebsmodellen und Verantwortlichkeiten,
- Lokale KI, Souveränität und kontrollierte Architekturen,
- Wie Unternehmen KI skalieren können, ohne die Kontrolle zu verlieren.

Auf der Grundlage praktischer Erfahrungen aus der Beratung, der Unternehmenstransformation und internationalen Projekten verbindet diese Sitzung agiles Denken, Governance und die Umsetzung von KI auf praktische und geschäftsorientierte Weise.

Auf der Grundlage praktischer Erfahrungen aus der Beratung, der Unternehmenstransformation und internationalen Projekten verbindet diese Sitzung agiles Denken, Governance und die Umsetzung von KI auf praktische und geschäftsorientierte Weise.

Dies ist keine weitere „KI-Hype-Sitzung“.
Es ist eine Realitätsprüfung für Führungskräfte, Architekten, Transformationsmanager und Unternehmen, die den Schritt vom Experimentieren zur nachhaltigen KI-Einführung vollziehen möchten.

Modernisierung von Altsystemen. Risiken kontrolliert in agile Transformationen verwandeln. en de

In dieser Keynote wird beleuchtet, wie langjährige Systeme unbemerkt die Dynamik bremsen, die Transparenz einschränken und die Entscheidungsfindung erschweren können. Die Keynote richtet sich an alle, die sich mit Skalierung, Komplexität und Verantwortlichkeit auseinandersetzen müssen. Dabei werden umfassende Veränderungen als bewusster und strukturierter Wandel betrachtet, der die Kontrolle stärkt und gleichzeitig die Anpassungsfähigkeit im gesamten Unternehmen fördert. Anhand von Führungserfahrungen aus der Praxis wird aufgezeigt, wie Gründende Unsicherheiten verringern, die Unternehmensführung stärken und Flexibilität einführen können, ohne den Kernbetrieb zu beeinträchtigen. Die Teilnehmenden erhalten einen klaren Fahrplan, um Bestehendes zu stärken, Entscheidungen zu beschleunigen und eine Organisation aufzubauen, die bereit ist, zielgerichtet statt aus der Dringlichkeit heraus zu wachsen.

Dr. S. Isele

HelveticMinds - SwissShore LLC, President and Agilist

St. Petersburg, Florida, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top