Speed Is the New Security Currency – Reflections from Phish & Chips 2026

von | 21. Juli 2026 | English, Events, Security

Bastian Hafer

Lead Developer

On 15 July 2026, I visited Phish & Chips in Bonn, a cybersecurity conference hosted by DIGITALHUB.DE. The event brought together companies, startups, security experts, investors and enthusiasts to discuss the future of cybersecurity in a professional and very well-attended setting.

The format combined keynotes in the main hall, startup pitches, an expo area, hands-on workshops and plenty of opportunities for networking. Bonn felt like a fitting place for this discussion. The city is home to important institutions and players in the German cybersecurity ecosystem, including the BSI and the Bundeswehr’s Cyber and Information Domain Service.

For me, one message clearly stood out throughout the day:

Cybersecurity is becoming a speed problem.

The next wave will be AI-driven

Several talks circled around the same uncomfortable observation: artificial intelligence will not only help defenders, it will also make attackers faster, more scalable and more professional.

The image of the lone “pizza hacker in the basement” is outdated. Today, many attacker groups operate like well-run companies: specialised, structured and continuously optimising their methods. AI lowers the entry barrier further. Tasks that once required deep technical knowledge can increasingly be supported by natural language interfaces, code generation and automated vulnerability discovery.

This matters especially in the context of CVEs and zero-days. If AI makes it easier to find vulnerabilities, we should expect the volume and density of exploitable weaknesses to increase. One of the key warnings at the conference was that the next two years could become particularly rough: more findings, more attacks, shorter reaction times.

The implication is simple but challenging: organizations cannot wait until the storm starts. They need to prepare now.

“Assume breach” becomes more than a slogan

A strong contribution came from Manuel Bach from the BSI, who argued that cybersecurity must be treated as a board-level topic. The BSI’s perspective was sobering: many companies believe they are well protected, while the real threat landscape suggests a different picture.

One example that stayed with me was the number of exposed, outdated systems still reachable from the internet. In practice, many organizations are not failing because nobody knows that security matters. They are failing because updates, inventories, emergency procedures and management attention are still too slow or too fragmented.

This leads to a mindset shift: companies should prepare for the possibility that they will be successfully attacked. “Assume breach” is not pessimism. It is operational realism.

That includes emergency processes, crisis communication, technical recovery plans and even the ability to maintain a minimum level of business operations without functioning IT. Security is not only about prevention. It is also about resilience.

Supply chain security starts with knowing what you run

The startup and tooling perspectives made the discussion very concrete. L3montree’s DevGuard pitch focused on software supply chain security, vulnerability management and upcoming regulatory pressure.

This connects directly to the Cyber Resilience Act, which will make security and vulnerability handling even more important for many digital products. The key message for software engineering teams is clear: security obligations do not stop at your own code. They also include the open-source dependencies, container images and libraries that become part of your product.

From an engineering perspective, the first step is not glamorous, but essential: inventory.

  • What do we run?
  • Which dependencies are part of our systems?
  • Which container images, libraries and transitive dependencies are used in production?
  • Where do we have known vulnerabilities?
  • Which vulnerabilities are actually likely to be exploited soon?

This is where SBOMs, SCA tooling, vulnerability scanners such as Trivy, exploit prediction scores like EPSS and centralised vulnerability management become relevant. The important point is not merely to collect findings. The real value lies in turning them into prioritised, actionable decisions.

Not every patch should be applied immediately — but every patch needs a process

One interesting point from the supply chain discussion was that “patch immediately” is not always the best possible rule. In some dependency ecosystems, it can be reasonable to wait for a short, controlled period before updating, giving the community time to detect malicious releases or zero-day issues in newly published packages.

That does not mean postponing security. It means professionalising it.

A mature organisation needs policies for dependency updates, automated checks, emergency patch paths, rollback capabilities and risk-based prioritisation. Whether an update is applied within hours or after a short waiting period, the decisive factor is that the decision is intentional, visible and repeatable.

This is where modern software delivery capabilities become security capabilities.

Speed is the new security currency

The strongest takeaway for me was a simple sentence:

Speed is the new security currency.

If vulnerabilities appear faster, exploits are generated faster and attackers adapt faster, then organizations must become faster as well. Not chaotic, not reckless, but structurally faster.

That means:

  • knowing what is running in production,
  • detecting relevant vulnerabilities quickly,
  • deciding what matters most,
  • implementing fixes without waiting for the next quarterly release,
  • deploying frequently and safely,
  • rolling back when necessary,
  • and maintaining a stable release management process at the same time.

This is also where Senacor can create concrete value for clients. Many companies do not primarily lack awareness anymore. They lack the ability to translate awareness into fast, reliable delivery.

Helping organizations move towards agile delivery models, automated pipelines, frequent deployments, secure release processes and efficient dependency update strategies is not “just” software engineering. It is cybersecurity work.

A team that can deploy safely several times a week has a different security posture than a team that needs months to bring a fix into production.

Hybrid threats connect cyber, information and society

Oberstleutnant Peter Leffler from the Bundeswehr’s Cyber and Information Domain Service broadened the perspective beyond enterprise IT. Cybersecurity is not limited to systems, networks and malware. In a hybrid threat landscape, cyber operations, the electromagnetic spectrum and the information space are connected.

This includes hacking, malware and cyber operations, but also propaganda, disinformation, GPS spoofing, electronic warfare and attempts to destabilise society. The information space is especially sensitive because disinformation becomes more effective when it is mixed with true stories.

The goal is not always to convince everyone. Often, it is enough to weaken trust, create confusion or undermine institutions.

For businesses, this is an important reminder: cybersecurity is part of a larger resilience discussion. Technical controls matter, but so do communication, situational awareness, cooperation and trust.

AI changes the rules — also for defenders

Hannah Dahl’s keynote on AI and cybersecurity made clear that we are only at the beginning of a major shift. Deepfakes, automated fraud, AI-supported phishing, scalable reconnaissance and AI-generated code all change the attacker’s economics.

One point resonated strongly:

We will not win against AI-enabled attackers if we refuse to use AI ourselves.

This does not mean blindly automating security decisions. AI systems are fallible and need governance. But in areas defined by complexity, speed and volume, AI-first thinking becomes necessary.

Vulnerability triage, log analysis, anomaly detection, threat intelligence, secure coding assistance and incident response support are obvious candidates.

The question is no longer whether AI belongs in cybersecurity. The question is how we use it responsibly, effectively and with the right guardrails.

Security culture cannot be bought

Technology was only one side of the conference. Several speakers and panelists emphasised the human factor.

Cybersecurity is not a luxury anymore. It is a sign of professional maturity. It creates the foundation on which innovation and growth can safely happen. Companies can buy tools, platforms and services, but they cannot buy culture. Culture has to be built.

That includes management attention, clear responsibilities, regular knowledge sharing, pragmatic training, security-by-design practices and the courage to talk openly about risks. It also means making security understandable. Fear alone rarely leads to sustainable improvement. Good analogies, realistic scenarios and practical exercises can help people understand why security matters in their daily work.

One panel discussion made this especially clear for startups: “startup first, security later” is dangerous. Security has to be designed into products and organizations early enough, otherwise the cost of fixing it later becomes much higher.

Impressions of the Phish & Chips Conference 2026

Digital sovereignty needs collaboration

The presentations from the Cyberagentur and from isecng added another important angle: digital sovereignty. Germany and Europe need strong cybersecurity capabilities, disruptive innovation and sovereign services.

This includes research, startup cooperation, secure infrastructure, SOC and SIEM capabilities, and open-source-based approaches that keep data and expertise closer to home.

At the same time, no single organization can solve the challenge alone. The conference showed how much value lies in collaboration between public institutions, startups, established companies, research organizations and operational security teams.

Cybersecurity is a network discipline. The defenders need to become at least as connected as the attackers already are.

My conclusion

Phish & Chips 2026 was a dense and valuable day. The venue was professional, the audience was engaged and the mix of keynotes, startup pitches, panels and workshops worked well. But more importantly, the conference made the current shift in cybersecurity very tangible.

The next phase will be shaped by AI, more vulnerabilities, more automation, more supply chain risks, more regulatory expectations and more geopolitical pressure.

The good news: awareness is no longer the main bottleneck.

The harder news: awareness is not enough.

Organizations now need execution capability. They need to know their systems, manage their dependencies, prepare for incidents, use AI defensively, build security culture and drastically reduce the time between identifying a risk and deploying a fix. In that sense, cybersecurity is becoming a core competence of modern software delivery.

And that is exactly where we, as Senacor, should continue to help our clients: building organisations, architectures and delivery processes that are fast enough, resilient enough and professional enough for the storm ahead.