Summary
The session’s core message was that CISOs entering 2026 are pulled between proving cybersecurity maturity and actually improving it, with scarce capacity forcing hard choices about compliance, monitoring, sovereignty, and automation. Davide opened by explaining that IGNH interviewed 27 CISOs or cybersecurity professionals across five industries to ask what they do, where they think cyber is going, what bothers them, where they spend money, and where they feel least prepared. The research was framed around four themes: strategic priorities, biggest concerns, investment areas, and preparedness gaps. The presenters also asked the room to answer a live poll so they could compare audience priorities with the survey results.
Key Topics
5 key topics from Giovanni Ferronato and Davide Bonalumi at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Map controls once, then reuse evidence across audits.
- Measure SOC effectiveness instead of simply buying more coverage.
- Identify where sovereignty risk is genuinely too high.
- Size cybersecurity roadmaps to available team capacity.
- Use automation and AI to complement scarce security talent.
“tracking compliance and keeping compliance over time reminds the real challenge that is burdening a lot of security teams”
Up Next


Next in agenda
Cyber Operations and Critical Infrastructure in Conflict

Also on digital sovereignty
Digital Sovereignty and Cloud Computing: technical criteria as one pillar of the European way forward
Philipp Holzmann


Also on cybersecurity
