On 29 September, from 12:15 to 12:55, Thilina Manana joins a panel on two of the ways attackers now get into small companies: a convincing email, or a supplier with more access than it needs. The setting is the second SME cybersecurity conference run by CyberMadrid, the Madrid cybersecurity cluster, at Digitaliza Madrid. Hard2bit is there as a cluster member and Silver sponsor, with a stand open from registration to the closing reception.
What is the SME cybersecurity conference?
It is the second edition of an annual event that CyberMadrid aims at SMEs, sole traders, start-ups and security leads. Digitaliza Madrid, an initiative of the regional government, backs it and provides the venue at Calle de Embajadores 181. The Madrid regional Cybersecurity Agency and the City Council's Cybersecurity Centre lend institutional support.
According to the figures the organisers quote in the event listing, 70% of cyberattacks recorded in Spain target SMEs, and the average cost of an incident is around €35,000. That matches what we see in the cases we handle: for a company of twenty to fifty people, a serious incident can be the end of the business.
The announced topics cover most of what an SME actually has to worry about: supply chain, security assessments, SOCs, the virtual CISO, low-budget measures, staff awareness, cloud, incident response and business continuity, regulatory compliance, artificial intelligence, and what an incident really costs.
What is Hard2bit doing there?
A stand in the exhibition area
We will be there from registration at 8:30 through to the closing reception, including the coffee break from 10:45 to 11:15. If you have a ticket and a specific problem in mind (an audit you keep postponing, a supplier you do not trust, a managed SOC you are not sure is paying off), bring it to the stand. We would rather spend ten minutes on your situation than hand you a brochure.
Panel on people and the supply chain
From 12:15 to 12:55, Thilina Manana takes part in the round table "The human factor: employees, suppliers and the supply chain, the weakest link", with other practitioners from the sector. Thilina is Hard2bit's COO and technical security director, and has handled incidents where initial access came from a well-written email or a supplier account with far more privileges than it needed, with no exploit involved at all.
The panel looks at the risks that come with people and with third parties who hold access to your systems, and at the practices that reduce the attack surface. Nobody is selling anything in that slot. It is the part of the programme where the conversation should turn to how attackers get into an SME whose perimeter is already in reasonable shape.
Why are people and suppliers the way in?
Because that is where a small or medium-sized company has the least control. A firewall is configured once and checked now and then; a person receives a hundred emails a day and makes a hundred decisions. A supplier with remote access to your ERP or your file server is another employee in all but name; the difference is that nobody trained them and nobody watches what they do.
Our own review of the 2026 threat landscape made the point that attacks now arrive through identity and through the supply chain rather than the perimeter. Campaigns such as ClickFix show the pattern: they exploit no software flaw; they talk the user into running the malicious command themselves. That is social engineering with a technical veneer, and tools stop only part of it. Somebody has to recognise it.
The same goes for suppliers. A supply chain attack comes in through your supplier's defences, often weaker than yours, and reaches you with legitimate credentials. For an SME, third-party risk management means knowing who can get into your systems, and how far.
NIS2 adds pressure. Many SMEs fall outside its scope on size alone, but some of their customers do not, and those customers are starting to push controls down the chain by contract. We cover this in NIS2: practical obligations for SMEs in the supply chain and in our NIS2 service.
What else is on the programme?
The full programme is on the CyberMadrid website, in Spanish. Sessions an SME should not miss:
- The institutional welcome at 9:00 by Agustín Muñoz-Grandes, president of CyberMadrid, followed by speakers from the regional Cybersecurity Agency and the City Council's Cybersecurity Centre.
- At 10:05, a round table with SME security leads on the threats they see, the incidents they have suffered and how they responded.
- At 11:15, the session on artificial intelligence and cybersecurity: the opportunities it opens for advanced protection and what the programme calls an "agentic SOC", applied to small companies.
- At 11:55, a session on external exposure: how shadow IT and the supply chain widen an SME's attack surface, and how to monitor it continuously.
- At 13:15, threat intelligence: using information about attackers to work out which assets are most attractive and which techniques are in use right now.
- At 13:35, legitimate access, illegitimate activity: detecting risk after sign-in, with cases involving privileged users and external suppliers.
The closing address at 14:00 is by Miguel Garrido de la Cierva, president of CEIM, the Madrid business confederation.
Hard2bit, a CyberMadrid member
Hard2bit is a member of CyberMadrid, the cluster set up by Madrid City Council so that companies, associations and institutions can develop good practice in cybersecurity. Sponsoring the conference and sitting on one of its panels is the least you can expect from a company that has worked in this field since 2013, always from Madrid, and has learnt much of what it knows about SMEs by responding to their incidents.
If you want to know who we are before you come to the stand, our team and certifications page has the background. And if the panel topic sounds familiar, security awareness training and incident response are the two services companies most often come to us for after a scare.
Practical details
- Date: Tuesday 29 September 2026.
- Times: registration from 8:30; opening at 9:00; closing at 14:00, followed by a reception.
- Venue: Digitaliza Madrid, Calle de Embajadores 181, 28045 Madrid.
- Tickets: sold out; Eventbrite has closed sales.
If you are in the room at 12:15 on the 29th, the question worth bringing is a simple one: who, outside your own staff, can reach your systems today, and with what permissions? If you cannot answer it, you already have something to raise at the stand. And if you could not get a ticket, contact us through the website and we will look at it before the conference.
Programme, speaker and capacity details come from the conference organisers (CyberMadrid and Digitaliza Madrid) and from the event's Eventbrite page, as published at the time of writing. The programme may change; check the organiser's website for the current version. The figures on cyberattacks against SMEs in Spain are those quoted by the organisers in their announcement, not Hard2bit's own measurements.
Frequently asked questions
When and where is the second SME cybersecurity conference held?
▾
On Tuesday 29 September 2026 at Digitaliza Madrid, Calle de Embajadores 181, 28045 Madrid. Registration opens at 8:30, the opening session is at 9:00 and the conference closes at 14:00, followed by a reception.
Who organises the conference?
▾
CyberMadrid, the Madrid cybersecurity cluster set up by Madrid City Council. It is backed by Digitaliza Madrid, a regional government initiative, and endorsed by the regional Cybersecurity Agency and the City Council's Cybersecurity Centre.
What is Hard2bit's role?
▾
Hard2bit is a CyberMadrid member and a Silver sponsor of the conference. It has a stand in the exhibition area, and Thilina Manana, COO, takes part in the round table on the human factor, suppliers and the supply chain from 12:15 to 12:55.
Can I still get a ticket?
▾
No. At the time of writing the organisers had closed ticket sales because capacity had been reached, as stated on the event's Eventbrite page. The next edition, when it is called, will be announced on the CyberMadrid website.
Who is the conference for?
▾
SMEs, sole traders, start-ups, CISOs and security leads. The focus is practical: which threats hit small and medium-sized companies hardest, what an incident costs, and what can be put in place on a limited budget.
How is Hard2bit connected to CyberMadrid?
▾
Hard2bit is a cluster member and takes part in its activities; at this conference it is also a Silver sponsor. CyberMadrid brings together firms, associations and public and private bodies from the cybersecurity sector in Madrid.
What is the panel Hard2bit sits on about?
▾
How people and third parties with access to your systems become the entry point for an attack, and which practices reduce that risk: training, access control and supplier risk management. None of the three comes down to buying technology.