Uninterrupted Care: Engineering Resilience for the Next Surge

Vaughan Estates, Sunnybrook

80 Armistice Dr, Toronto, ON

June 9, 2026

Full-Day Executive Summit

Executive-Level Forum

Healthcare Cyber Leaders

PARTNERS & SPONSORS

0

Full-Day Summit

0 +

Past Sponsors

0 +

Healthcare Org Partners

0 +

Speakers

ABOUT THE SUMMIT

A Landmark Collaboration in Healthcare Security

The Healthcare Security & Risk Summit (HSRS) 2026 is a curated, executive-level forum co-hosted by Sunnybrook Health Sciences Centre, one of Canada’s most distinguished academic health institutions, a fully affiliated teaching hospital of the University of Toronto and home to the country’s largest trauma centre, and NKST, a trusted cybersecurity research and collaboration organization.

HSRS is a focused, high-signal environment where strategic security conversations translate into real partnerships and measurable outcomes. Attendees are the leaders accountable for the resilience of EHR systems, medical IoT environments, clinical infrastructure, AI-enabled diagnostics, and patient data platforms.

Together, Sunnybrook and NKST bridge frontline healthcare operations with cybersecurity strategy, ensuring that the systems supporting patient care remain resilient, secure, and uninterrupted in the face of evolving threats.

SUMMIT THEME

Uninterrupted Care: Engineering Resilience for the Next Surge.

Healthcare has entered an era where cyber incidents are not hypothetical, they are inevitable. HSRS 2026 focuses on building operational resilience across the entire healthcare ecosystem.

01 / PILLAR

Threat Continuity

Strategies for maintaining uninterrupted care delivery under active cyberattack. How do hospitals keep patients safe when systems are compromised?

02 / PILLAR

Resilient Architecture

Implementing zero-trust frameworks, network segmentation, and redundancy protocols purpose-built for complex clinical environments.

03 / PILLAR

Surge Readiness

Security scaling strategies for periods of peak patient volume. Ensuring robust protection precisely when operational pressure is at its highest.

04 / PILLAR

AI & Innovation Risk

Governing emerging health technologies responsibly — balancing the promise of AI-enabled diagnostics with rigorous, proportionate risk management.

SUMMIT FORMAT

What to Expect at HSRS 2026

A full day of high-impact programming, structured for senior leaders and practitioners who need real answers, not generic sessions.

01

Keynote Presentations

Visionary addresses from Canada's foremost healthcare security leaders on ransomware response, AI risk governance, and the future of clinical cybersecurity.

02

Panel Discussions

Multi-perspective conversations on the most pressing challenges facing health systems: data breaches, regulatory compliance, cross-border threats, and emerging attack vectors.

03

Workshops & Interactive Sessions

Hands-on simulation exercises, tabletop scenarios, and technical deep-dives designed to build practical, immediately deployable skillsets.

04

Exhibition Area

A curated showcase floor featuring cutting-edge healthcare cybersecurity products, live solution demonstrations, and direct access to leading providers.

05

Networking & Roundtables

Structured roundtables and open networking sessions connecting CISOs, vendors, and policy leaders in a high-trust, executive-grade environment.

06

Research & Intelligence Briefs

Exclusive threat intelligence briefings and sector research releases — giving attendees first access to the latest healthcare security data and trend analysis.

Conference Agenda
Click each session to view details.
Time
Session Type
Session Name
Speaker Name
7:30 AM – 9:30 AM
Workshop
Operation Blindspot
Facilitators
Dan Ohlemeier
Josh Leclerc
+

Step into the war room of a fictional hospital ransomware scenario. What begins as a routine day quickly escalates into a full-scale cyber incident impacting identity systems, operational technology, and healthcare that communities depend on.

Participants will be guided through unfolding events, forced to make decisions in real time, and challenged to respond as the situation evolves. The objective is not to “win,” but to uncover blind spots that exist in even the most mature security programs.

This is a simulation. No systems are accessed. No real-world environments are touched. The learning, however, is very real.

Sponsors: Arancia & Semperis

Facilitators:
Dan Ohlemeier, Principal Solutions Architect, Semperis
Josh Leclerc, Director of Cyber Strategy, Architecture & Solutions, Arancia

8:30 AM – 9:25 AM
Welcome
Breakfast and Registration
+

Breakfast and registration.

9:25 AM – 9:30 AM
Welcome
Land Acknowledgment, National Anthem
Master of Ceremonies
Penny Longman
Ter Govang
+

Master of Ceremonies:
Penny Longman, CEO, NKST
Ter Govang, Integrated Security Lead, Eastern Canada, PBX Engineering Ltd.

9:30 AM – 9:45 AM
Welcome
Welcome Address & Opening Remarks
Speaker
Rob Lee
+

Speaker:
Rob Lee, Vice President Digital Health and Chief Information Officer, Sunnybrook

9:45 AM – 10:00 AM
Remarks
Remarks | Minister of Long-Term Care, Ontario
Speaker
Natalia Kusendova-Bashta
+

Speaker:
Natalia Kusendova-Bashta, Minister of Long-Term Care, Ontario

10:00 AM – 10:30 AM
Keynote
Operationalizing a CPS Program: 5 Steps to Resilience
Speaker
Randy Guerette
+

Healthcare organizations face an escalating cybersecurity crisis where Operational Technologies are prime targets. In a Healthcare Delivery Organization, OT devices manage the physical environment. Attacks on these systems often evade standard IT defenses, disrupting operations and directly impacting patient care.

Join us for a practical breakdown of the challenges HDOs face in securing OT. We will move beyond the theoretical to provide a concrete roadmap of five actionable steps to reduce risk and improve resilience.

Sponsor: Claroty

Speaker:
Randy Guerette, Solution Engineer, Claroty

10:30 AM – 10:55 AM
Break
Morning Break
+

Sponsor: Heidi Health

10:55 AM – 11:40 AM
Panel
Cyber Defense in the Era of Mythos Class AI Threats
Moderator / Panelists
Josh Leclerc
Amer Khan
Lia Sana
Patrick Harkins
+

Adversarial use of large-scale AI models is materially changing the threat landscape facing healthcare organizations by accelerating reconnaissance, enabling targeted social engineering at scale, and lowering the barrier for sophisticated intrusion campaigns against clinical infrastructure.

This session brings together CISOs from healthcare organizations to examine the implications of AI-augmented threat actors and discuss adjustments required to address an asymmetric and rapidly evolving threat class.

Moderator: Josh Leclerc, Arancia

Panelists:
Amer Khan, Chief Information Security Officer, Salvation Army
Lia Sana, Director, Information Security, Fraser Health Authority
Patrick Harkins, Chief Technology and Security Officer, Mackenzie Health

11:40 AM – 12:25 PM
Panel
The Zero Trust Revolution: Moving Beyond Perimeter Defence
Moderator / Panelists
Carlos Akhilele
Kajeevan Rajanayagam
David Cooper
Ali Desheshi
+

This session examines how Ontario healthcare organizations are building on Zero Trust foundations to architect systems that remain resilient under active attack, maintain continuity of critical patient care services through disruption, and recover with the speed and integrity that clinical environments demand.

Sponsors: CrowdStrike & Netskope

Moderator: Carlos Akhilele, Sales Engineering Manager, CrowdStrike

Panelists:
Kajeevan Rajanayagam, Cyber Security Director, University Health Network
David Cooper, Solutions Engineer, Netskope
Ali Desheshi, BC Public Sector

12:25 PM – 1:30 PM
Break
Lunch
+

Sponsor: Darktrace

12:30 PM – 2:00 PM
Workshop
How AI is Reshaping Red Team Operations
Speaker
Diego Marques
+

Artificial intelligence hasn't rewritten the attacker's playbook; it has accelerated it. The kill chain remains familiar, but every phase is now faster, cheaper, and more accessible to less-experienced operators. This session walks through a complete red team engagement and examines exactly where AI changes the economics of the attack.

We'll cover identity-based attacks and how AI streamlines the supporting infrastructure; external reconnaissance, where AI's real value is orchestration and triage at scale rather than novel discovery; and social engineering, where fluent, tailored pretexts have quietly retired old detection heuristics. Moving internal, we'll look at AI as an OPSEC and tradecraft advisor that augments operator judgment during privilege escalation, lateral movement, and persistence.

Crucially, the session closes on the other side of the coin: the privacy and data-governance risks of feeding sensitive engagement data into AI systems, and practical mitigations, including redaction, human-in-the-loop controls, and local models. Attendees will leave understanding not just how adversaries are weaponizing AI, but how the same capabilities strengthen defense.

Sponsor: Arancia

Speaker:
Diego Marques, Director of Offensive Security, Arancia

1:30 PM – 2:00 PM
Keynote / Fireside
Keynote / Fireside Chat
Speaker
Rafi Wanounou
+

Sponsor: Fortinet

Speaker:
Rafi Wanounou, Vice President and CTO, Fortinet

2:00 PM – 2:45 PM
Panel
Bill 194 and Third-Party Risk and Reporting Requirements
Moderator / Panelists
Sharon Bauer
Brent Arnold
Victoria Ghandour
+

Ontario's Strengthening Cyber Security and Building Trust in the Public Sector Act, Bill 194, establishes binding obligations for designated public sector entities, including healthcare organizations, with significant implications for how third-party vendor relationships are governed, contracted, and monitored.

This session brings together legal practitioners to examine the compliance frameworks, liability exposure, and disclosure obligations that counsel and healthcare leaders must navigate as regulatory enforcement begins to take shape.

Moderator: Sharon Bauer, Founder, Bamboo Data Consulting

Panelists:
Brent Arnold, Partner, Breach Coach, INQ Law
Victoria Ghandour, Director, Cybersecurity, Privacy and Health Information Management, William Osler Health System

2:45 PM – 3:15 PM
Break
Afternoon Break
+

Afternoon networking break.

3:15 PM – 4:00 PM
Panel
The New Attack Surface: IoT, Research Networks, and the Future of Healthcare Resilience
Moderator / Panelists
Raheel Qureshi
+

Moderator: Raheel Qureshi, Chief Strategy Officer & COO, NKST

4:00 PM – 4:45 PM
Panel
LDG Expansion: Beyond Hospital Walls
Moderator / Panelists
Penny Longman
Mark Watmough
Supriya Gade
+

A focused discussion on fostering collaboration and knowledge sharing within the long-term care sector, similar to how LDGs operate for primary care institutions.

Moderator: Penny Longman, CEO, NKST

Panelists:
Mark Watmough, Executive Director, IT & Cyber Security, CarePartners
Supriya Gade, Vice President, Quality and Safety, SPRINT Senior Care

4:45 PM – 4:50 PM
Closing
Closing Remarks
+

Closing remarks.

WHO SHOULD ATTEND?

Built for Healthcare

Decision-Makers

HSRS 2026 convenes the cross-functional leaders and practitioners driving security, risk, and innovation across Canada’s healthcare landscape.

GALLERY

HSRS Over the Years

SUMMIT VENUE

The Vaughan Estate at Sunnybrook

Nestled just minutes from Toronto’s downtown core, the historic Vaughan Estate of Sunnybrook, built in 1931, stands as a stunning architectural landmark that seamlessly blends old-world elegance with a sophisticated event setting.

As an institution that has shaped healthcare in Canada for decades, Sunnybrook’s Vaughan Estate provides a fitting backdrop for Canada’s premier healthcare security summit: a place where history meets urgency, and where the conversations held within its walls carry genuine consequence for patient care.

Address: 80 Armistice Dr, Toronto, ON M4N 3M5
Google Map Directions Here

JOIN HSRS 2025

The adversaries are evolving.

So must we.

Join the leaders building resilient, adaptive, and human-centred security in the age of autonomous risk.