Cybersecurity: the 2026 to 2027 circuit

The EMEA cybersecurity calendar looks like one market and behaves like four. Eleven events carry this tag on the index, running from mid September 2026 to June 2027, and choosing between them on size alone is the most common planning error a security team makes. it-sa in Nuremberg and Infosecurity Europe in London are exhibition floors: their function is market survey and procurement. Black Hat Europe is a research and training event whose value sits in the briefing rooms. Les Assises in Monaco is a closed matchmaking programme where the schedule is fixed before anyone arrives. The InCyber Forum in Lille is where European regulation gets argued over with the institutions present. GISEC in Dubai and Black Hat MEA in Riyadh are state-backed showcases operating at a scale no European event matches.

That difference in function matters more than geography. A vendor deciding between Nuremberg and Monaco is choosing between meeting a thousand people briefly and meeting forty people properly. A CISO deciding between London in June and London in December is choosing between market coverage and technical depth, in the same halls, six months apart.

Who is in the room

The exhibition floors draw the widest audience. it-sa reported 28,267 trade visitors and 993 exhibitors in 2025, mostly German-speaking security officers, integrators and public administration buyers. Infosecurity Europe reported over 13,000 visitors and more than 400 exhibitors in 2026, predominantly British. Cybersec Europe in Brussels serves the Benelux market with over 7,300 professionals, and Cloud & Cyber Security Expo in Paris puts a free French security floor inside a wider technology show.

The research and community events are smaller and more specific. Black Hat Europe brings security researchers, red teams and detection engineers to ExCeL London for briefings selected through a call for papers, plus multi-day paid training. Swiss Cyber Storm fits the Swiss community into one room at the Kursaal Bern for one day and one theme, this year Shadow IT. Cyber Security Nordic in Helsinki draws 2,600 Nordic practitioners and government officials with an unusually direct national resilience framing.

The closed and institutional formats work differently again. Les Assises admits French decision-makers by invitation after they declare active projects, then builds their timetable from booked one-to-one meetings with vendor partners. The InCyber Forum in Lille registered 24,558 attendees for its 2026 edition and puts European institutions, national agencies, law enforcement cybercrime units and industry in the same building for three days.

The Gulf showcases operate at a different scale entirely. GISEC Global expects over 25,000 visitors and 750 exhibitors at Dubai World Trade Centre. Black Hat MEA expects more than 40,000 attendees near Riyadh, which makes it roughly ten times the size of the European event sharing its brand.

How the room actually works

The commercial models are worth reading before booking. Entry to the exhibition-led shows is generally free for qualified trade visitors, because exhibitors pay: this is true of Infosecurity Europe, Cloud & Cyber Security Expo Paris and, for the exhibition, GISEC. it-sa charges visitors but includes several hundred free forum presentations in the ticket, with the Congress@it-sa programme sold separately.

Black Hat Europe inverts that. Its trainings are the largest line item in the budget, its briefings pass is real money, and its business hall is small. Anyone comparing ticket prices across this circuit without noticing that difference will draw the wrong conclusion about value.

Les Assises is the outlier: decision-makers attend at no charge but only on invitation, and vendors fund the entire event through partner packages that carry a meeting quota. The InCyber Forum has historically admitted qualified end users free while charging vendors for partnership, with some specialised conferences ticketed separately.

The seasonal structure

The circuit has a clear shape. Mid September opens with GISEC in Dubai. October carries the heaviest concentration in Europe: Les Assises in Monaco from the 7th, Swiss Cyber Storm in Bern on the 20th, it-sa in Nuremberg from the 27th and Cyber Security Nordic in Helsinki on the 28th and 29th. November brings the Paris floor. December closes the year with Black Hat MEA in Riyadh from the 1st and Black Hat Europe in London from the 7th.

The calendar then goes quiet until March, when the InCyber Forum reopens it in Lille, moved earlier than its 2026 slot. May brings Cybersec Europe in Brussels and June closes the cycle with Infosecurity Europe in London. Teams with a limited travel budget should note that October and the following June carry most of the weight, and that the December pair are the two events on this list that reward technical staff rather than buyers.

The 2026 context

Three shifts show up across the programmes. Regulatory implementation has moved from anticipation to enforcement: NIS2 transposition, the Cyber Resilience Act and sector-specific rules now generate concrete compliance workload, which is why Brussels-adjacent events and the InCyber Forum have grown their institutional content. Securing machine learning systems has become a programme category rather than a novelty track, with the InCyber Forum running a Secure AI conference and the 2027 theme, "Agentic vertigo", built explicitly around autonomous systems. And Gulf spending continues to reshape the map: the two largest events on this circuit by attendance are now in Dubai and Riyadh, both state-backed.

Trends 2027

The distinction between the exhibition shows will get harder to defend. Cloud, identity, data platforms and security are converging in the buyer's organisation, and the co-location model that Cloud & Cyber Security Expo already uses in Paris, sharing a badge with cloud infrastructure, DevOps and data centre events, is the direction of travel for shows that need to keep growing.

Defence and national resilience content will keep expanding at the northern and eastern European events, where the threat framing is not theoretical. Cyber Security Nordic is the clearest example, but the pattern extends across the Baltic and central European calendar.

The research conferences face a different pressure: the economics of a small, expensive, technically deep event are difficult when the sponsors funding the sector are drawn to 40,000-person showcases. Black Hat Europe's continued focus on briefings and training rather than floor space is a deliberate choice, and worth watching.

Methodology and data standards

Every event on this page has been verified against the organiser's own published material at the date shown in each record, and each fiche states the date it was last verified. Where an organiser blocks automated retrieval, as Black Hat and Space-Comm do, facts are drawn from the organiser's published pages and cross-checked against institutional or partner announcements, and the fiche says so.

Attendance and exhibitor counts are reported as the organiser states them, labelled as organiser figures, and dated to the edition they describe. Where only third-party show listings exist, as for the Paris exhibition, the fiche marks the figure as indicative rather than presenting it as confirmed. Where an organiser publishes no figures at all, as with Les Assises and Swiss Cyber Storm, none are invented.

Scope limitation, stated plainly: this circuit covers eleven events across Europe, the Middle East and Africa selected for scale, distinct function and a confirmed forward date. It is not a complete inventory of the region's security events. National conferences, vendor user conferences, community meetups and the large number of smaller regional expos are outside the current scope, and several will be added as the vertical is extended.

Upcoming events

11 listed
EventCityDate
GISEC Global Dubai, United Arab Emirates 16–18 September 2026
Les Assises de la Cybersecurite Monaco, Monaco 7–10 October 2026
Swiss Cyber Storm Bern, Switzerland 20 October 2026
it-sa Expo&Congress Nuremberg, Germany 27–29 October 2026
Cyber Security Nordic Helsinki, Finland 28–29 October 2026
Cloud & Cyber Security Expo Paris Paris, France 18–19 November 2026
Black Hat MEA Riyadh, Saudi Arabia 1–3 December 2026
Black Hat Europe London, United Kingdom 7–10 December 2026
InCyber Forum Europe Lille, France 9–11 March 2027
Cybersec Europe Brussels, Belgium 26–27 May 2027
Infosecurity Europe London, United Kingdom 8–10 June 2027