Universität Paderborn

08/13/2026 | Press release | Distributed by Public on 08/13/2026 06:09

When AI acts autonom­ously: 20th Pader­born IT Se­cur­ity Day

In focus: secure software development, NIS-2, the Cyber Resilience Act and digital sovereignty

On 1 and 2 September, the 'Digital Security' competence area of the SICP - Software Innovation Campus Paderborn is hosting the 20th Paderborn IT Security Day. This free event, organised by Paderborn University, centres on the question of how cyber security is changing as artificial intelligence (AI) moves beyond merely providing support to increasingly developing code, accessing systems and making decisions autonomously. In the Zukunftsmeile 2 (research and development cluster located in the Fürstenallee in the city of Paderborn), experts from academia, industry, and politics will discuss current approaches to secure software development, the implementation of the second EU Directive on Network and Information Security (NIS-2) and the Cyber Resilience Act (CRA), as well as Europe's digital sovereignty. Those interested can find the full programme and registration details on the event page.

Agent-based AI and secure software development

The scientific programme kicks off with the English-language keynote 'Agentic Software Development and Security: The Paradigm Shift' by Marcel Böhme from the Max Planck Institute for Security and Privacy. He will demonstrate how large language models and coding agents are fundamentally changing the pace of software development, and what new questions this raises regarding the analysis, trustworthiness, and security of automatically generated code.

Further presentations will cover new methods for the automated analysis of software, the context-dependent detection of sensitive data, and the secure deployment of autonomous AI agents. As the first day draws to a close, the focus will be in particular on measurable quality and security checks, access control, 'Zero Trust', human checkpoints, and digital sovereignty. Dr. Simon Oberthür, Manager of the 'Digital Security' competence area at SICP, explains: "AI systems are currently evolving very rapidly from supporting tools to systems that independently generate code, access applications, and prepare or execute decisions. This not only creates new opportunities, but also new requirements in terms of quality assurance, authorisation, accountability, and digital sovereignty."

Cybersecurity as a political and corporate responsibility

Further presentations demonstrate why cybersecurity is not merely a technical task, but also a political, legal, and organisational one. The focus is on clear lines of responsibility, cybersecurity as a management priority, potential risks of fines and criminal liability, as well as practical experience with the implementation of NIS-2 and the Cyber Resilience Act.

Digital sovereignty and practical implementation

Matthias Muhlert, Group Chief Information Security Officer of the Oetker Group, will open the second day of the event with an English-language keynote entitled 'Rethinking Cybersecurity - A Blueprint for Europe's Digital Future'. The focus will be on a people-centred security strategy, shared responsibility, and the question of how Europe can more closely link digital sovereignty, innovation, and cybersecurity.

In five interactive workshops, participants will also explore IT security culture in the context of NIS-2, the CRA risk assessment in accordance with DIN EN 40000, the practical analysis of TLS connections, a process model for NIS-2 implementation projects, and the step-by-step creation of an IT contingency plan to prepare for cyber-attacks and technical disruptions.

The event is supported by InnoZent OWL e.V., the District of Paderborn, the OWL/Lippe regional group of the German Computer Science Society (GI) and the heise academy.

This text was translated automatically.

Universität Paderborn published this content on August 13, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 13, 2026 at 12:09 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]