
The 12th annual IoT Security Foundation Conference took place on Wednesday 26th August 2026 at the Novotel London West as part of the sold-out TechWorks 30th anniversary ‘Semiconductors to Systems’ summit with over 700 in attendance.
The conference brought together experts from across cybersecurity, IoT, semiconductors, AI, embedded systems, regulation and quantum computing to examine how we can build trust and resilience into an increasingly connected world.
The IoTSF conference was structured around four key themes: Cyber risk, trust and resilience, governance, regulation and emerging threats, secure foundations and trusted infrastructure, and quantum security and future readiness.
Cyber risk, trust and resilience
The opening sessions examined the rapidly changing cyber threat landscape and the challenges organisations face as connected devices become increasingly sophisticated and AI becomes embedded throughout the technology stack.
Hugo Vincent (Arm) opened the technical programme with a keynote on security architecture, followed by discussions on the security pitfalls of AI-assisted development, enterprise cyber resilience and the challenge of establishing verifiable trust across IoT and OT environments. The session highlighted the need to move beyond traditional perimeter security towards security that is built into products and systems from the outset.
Sassy Safe: When AI meets IoT security
Ken Munro and Aaron Thacker of Pen Test Partners brought some fun – and some important lessons – to the conference with their interactive ‘Sassy Safe’ demonstration – an LLM-powered safe controlled through voice prompts, designed to highlight the security risks that can arise when AI is used poorly in IoT applications.
The demonstration provided a very entertaining illustration of the pitfalls of vibe coding and relying on AI without sufficient security controls. The safe was remarkably willing to cooperate, revealing its passcode on the first hacking attempt before going one step further and changing its own passcode.
Beyond the laughs (including the surreal experience of arguing with a safe through a microphone), the demo made a serious point – adding AI to connected devices does not automatically make them smarter or safer. Without appropriate security engineering and controls, it can introduce entirely new vulnerabilities.
Governance, regulation and emerging threats
The second part of the programme focused heavily on the changing regulatory environment, particularly the EU Cyber Resilience Act (CRA) and what it means in practice for manufacturers and technology companies.
Sessions explored threat modelling, agentic AI, real-world security testing and preparing organisations for the simultaneous arrival of increasingly capable AI and quantum computing. A major CRA panel brought together representatives from industry, testing and assurance organisations to discuss how regulation can be translated into practical security improvements rather than simply becoming a compliance exercise.
Secure foundations and trusted infrastructure
The afternoon moved towards the technical foundations on which secure connected systems depend.
Speakers examined CHERI and memory safety, hardware-enforced security for AI, FPGA-based edge AI, silicon assurance and tamper-evident supply chains. The central message was that trust cannot simply be added at the software layer, it needs to extend down through hardware, silicon, firmware, software and ultimately the entire supply chain.
A dedicated supply-chain panel explored how organisations can establish confidence in components and systems from chip manufacture through to deployment.
Quantum security and future readiness
The final technical track looked beyond today’s threats towards the security challenges that organisations need to prepare for now.
Sessions covered post-quantum cryptography, memory safety, crypto-agility, quantum risk and the practical steps required to make IoT systems quantum-ready. Speakers stressed that organisations should not wait for large-scale quantum computing to arrive before addressing the issue, systems and cryptographic infrastructure have long lifecycles, meaning preparation needs to begin today.
The programme brought together perspectives from open-source security, industry, academia and major technology organisations, culminating in a discussion of how trust can be maintained in the post-quantum era.
Keynote – Dex Hunter-Torricke: Technology, space and the future we choose
The conference concluded with a wide-ranging keynote from Dex Hunter-Torricke, Founder & President of The Center for Tomorrow.
Rather than delivering a conventional technical security presentation, Dex took a much broader view of the forces that are shaping the future. Drawing on his experience at the United Nations, Google, Facebook, SpaceX and Google DeepMind, he explored the extraordinary pace of technological change and what it means for humanity, governments and society.
A significant part of his keynote focused on space and the implications of humanity becoming an increasingly spacefaring civilisation. Space provides a powerful lens through which to consider technological progress – the capabilities being developed for space exploration are advancing rapidly, while the infrastructure on which future societies will depend is becoming increasingly digital, autonomous and interconnected.
Dex connected this to the wider transformation being driven by AI. His argument was not simply that AI will make technology more powerful, but that it is arriving at a moment when geopolitics, democratic institutions, inequality, climate change and international relationships are already under considerable pressure.
The keynote therefore returned to a fundamental question, what kind of future are we choosing to build?
This was particularly relevant to an IoT security audience. As connected systems expand from today’s devices and infrastructure towards increasingly autonomous systems, AI-enabled technologies and eventually space-based infrastructure, the question of security becomes inseparable from the question of trust. The technologies we build will increasingly influence critical infrastructure, economies and everyday life, making resilience and responsible technological development essential.
Dex’s message complemented the more technically focused sessions throughout the day by placing IoT security within this much larger picture – we are not simply securing today’s connected devices, we are helping to establish the foundations of the technological world that comes next.
Looking ahead
The 2026 IoTSF conference demonstrated how rapidly the definition of IoT security is expanding. The challenge is no longer simply protecting individual connected devices. It encompasses AI, regulation, hardware security, supply-chain assurance, memory safety, critical infrastructure and quantum resilience, while increasingly intersecting with wider questions about technological sovereignty, geopolitics and the future of society.
The overarching message of the conference was clear: Trust has to be built in from the foundations upwards, and organisations need to prepare for the technologies and threats of tomorrow rather than simply responding to those of today.
Look out for selected 2026 conference talks on our YouTube channel soon.
