A one-day Swiss security conference at the Kursaal in Bern, run by a non-profit association, built around a single annual theme and a curated speaker list rather than an exhibition floor.
Swiss Cyber Storm is the annual conference of the Swiss Cyber Storm association, a non-profit that also runs the Swiss national team for the European Cyber Security Challenge. The conference is held in one day at the Kursaal Bern and takes a single theme each year: the 2026 edition, on 20 October, is built around Shadow IT, the technology that enters an organisation without passing through its security review. The organiser describes an audience running from students to engineers to security officers and CISOs, which is unusual for a conference of this size.
The conference is deliberately positioned against the trade-show model. There is no large vendor hall, no parallel tracks fighting for attention, and no series of product pitches. The stated intent is to present proven solutions to structural security problems rather than a parade of new vulnerabilities. In practice it functions as the annual meeting point of the Swiss security community, with international speakers brought in around the chosen theme.
Shadow IT covers the software, cloud services and now the AI tools that teams adopt directly without security review. The theme sits at the intersection of governance and technical control: discovery of unmanaged assets, identity sprawl across unsanctioned software as a service, data leaving the organisation through tools nobody approved. Choosing one theme a year gives the programme a coherence that multi-track conferences lose.
Swiss Cyber Storm is small by design. It is not competing with it-sa in Nuremberg or Infosecurity Europe in London, which are exhibition-led shows measured in tens of thousands of visitors. Its closest relatives are the national single-track community conferences: one room, one day, one theme, a mailing list that returns every year. The Swiss corporate market, with its concentration of banking and pharmaceutical security teams, gives it a stronger enterprise audience than its size suggests.
Both, deliberately. The organiser targets students, engineers, security officers and CISOs in the same room, and the single-track format forces the programme to stay legible to all of them.
No exhibition floor in the trade-show sense. Sponsors support the non-profit and are present, but the day is built around the talks.
The programme brings in international speakers and runs in English, in a country where the security community works across German, French and English.
Swiss Cyber Storm is run by a Swiss non-profit whose other main activity is selecting and training the Swiss national team for the European Cyber Security Challenge. That gives the conference an unusual link to the country's talent pipeline, and explains the presence of students alongside CISOs.
A single-day, non-profit conference that keeps the Swiss security community in one room, picks one theme a year and refuses the vendor-floor model entirely.
Tickets are sold through an external ticketing platform linked from the official site, with a reduced student rate. Prices for the 2026 edition are published on that platform rather than on the conference homepage. Capacity is limited by the Kursaal's main hall, and past editions have sold out ahead of the date.
20 October 2026 at the Kursaal Bern, Kornhausstrasse 3, 3000 Bern, Switzerland.
One day. There is no multi-day training programme attached, unlike the larger commercial conferences.
The association has published recordings and slides from previous editions on its website and video channels; 2026 publication follows the same practice.
| Official website | https://www.swisscyberstorm.com/ |
| Venue | https://www.kursaal-bern.ch/ |