Experts discuss secure software development, NIS-2, the Cyber Resilience Act and digital sovereignty
The ‘Digital Security’ competence area of the SICP – Software Innovation Campus Paderborn – is hosting the 20th Paderborn IT Security Day on Tuesday and Wednesday, 1 and 2 September. This free event, organised by Paderborn University, focuses on the question of how cyber security is changing as artificial intelligence moves beyond merely providing support to increasingly developing code, accessing systems and making decisions autonomously. Experts from academia, industry and politics will discuss, in the Zukunftsmeile (research and development cluster located in the Fürstenallee in the city of Paderborn), current approaches to secure software development, the implementation of NIS-2 and the Cyber Resilience Act, as well as Europe’s digital sovereignty.
Agent-based AI and secure software development
The academic programme will open with the English-language keynote address ‘Agentic Software Development and Security: The Paradigm Shift’ by Marcel Böhme from the Max Planck Institute for Security and Privacy. He will demonstrate how large language models and coding agents are fundamentally changing the pace of software development, and what new questions this raises regarding the analysis, trustworthiness and security of automatically generated code.
Further presentations will cover new methods for the automated analysis of software, the context-dependent detection of sensitive data, and the secure deployment of autonomous AI agents. As the first day draws to a close, the focus will be in particular on measurable quality and security checks, access control, Zero Trust, human checkpoints and digital sovereignty.
“AI systems are currently evolving very rapidly from supporting tools to systems that independently generate code, access applications and prepare or execute decisions. This not only creates new opportunities, but also new requirements in terms of quality assurance, authorisation, accountability and digital sovereignty,” explains Dr Simon Oberthür, Manager of the “Digital Security” competence area at SICP.
Cybersecurity as a political and corporate responsibility
Further articles demonstrate why cybersecurity is not merely a technical task, but also a political, legal and organisational one. The focus is on clear lines of responsibility, cybersecurity as a management task, potential risks of fines and criminal liability, as well as practical experience with the implementation of NIS-2 and the Cyber Resilience Act.
Digital sovereignty and practical implementation
Matthias Muhlert, Group Chief Information Security Officer at the Oetker Group, will open the second day of the event with the keynote address ‘Rethinking Cybersecurity – A Blueprint for Europe’s Digital Future’. The focus will be on a people-centred security strategy, shared responsibility and the question of how Europe can more closely link digital sovereignty, innovation and cybersecurity.
In five interactive workshops, participants will explore IT security culture in the context of NIS-2, the CRA risk assessment in accordance with DIN EN 40000, the practical analysis of TLS connections, a process model for NIS-2 implementation projects, and the step-by-step creation of an IT contingency plan to prepare for cyber-attacks and technical disruptions.
The 20th Paderborn IT Security Day will take place on 1 and 2 September 2026 at Zukunftsmeile 2 in Paderborn. Attendance is free of charge. Those interested can find the full programme and complete registration at:
The event is supported by InnoZent OWL e.V., the District of Paderborn, the OWL/Lippe regional group of the German Computer Science Society (GI) and the heise academy.