Meet Illumio at it-sa Expo&Congress 2026 in Nuremberg
Bitkom asked 1,003 German companies whether they’d been hit by data theft, industrial espionage, or sabotage in the past year. Only 4 in 100 could say no.
The damage comes to at least €211 billion a year, and about three-quarters of it traces back to cyberattacks. With odds like those, a break-in is close to a given. What decides how the incident ends is how far the attacker can move once inside.
That movement turns a single foothold into an outage that can take down the business. Limiting it is the heart of cyber resilience, and it’s the focus of everything Illumio is bringing to it-sa Expo&Congress 2026, 27–29 October at NürnbergMesse.
Visit Illumio at it-sa 2026 in Hall 7, booth 7-710
Our team will run live demos of the Illumio platform, which Forrester recently named a Leader and a Customer Favorite in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.
You’ll see how Illumio Segmentation and Illumio Insights give you visibility into how your applications and workloads communicate, so you can contain lateral movement across hybrid environments.
At the booth, you can:
- See live demos of ransomware containment and application ring-fencing.
- Book time in our meeting area for a one-on-one conversation with the Illumio team.
- Talk with our partners FireMon and KAEMI about how segmentation fits into your broader security stack.
Join our sessions in Forum C, Hall 7
Illumio will take part in two sessions in Forum C, a short walk from our booth in Hall 7. You'll hear a customer perspective from Propan Rheingas along with technical insights from the Illumio team.
Cyber resilience under NIS2 and DORA: containing attacks and protecting critical systems
NIS2 and DORA ask companies to show they can keep critical services running while an attack is underway. That puts pressure on security teams to prove resilience in practice, with evidence and clear controls to back it up.
On Tuesday, 27 October, 4:15–4:30 PM, Alex Goller, Principal Sales Engineer at Illumio, will join Lennart Aldorf, IT Infrastructure and Network Security Team Leader at Propan Rheingas, and Sven Launspach, CEO and Technology Evangelist at KAEMI. They’ll explore how segmentation and breach containment help reduce risk, make lateral movement harder, and protect critical systems.
You’ll leave with a practical view of how containment supports both your security strategy and your compliance goals.
Fighting fire with fire: how agentic AI and MCP bring breach containment up to attacker speed
Attackers are using AI to find and exploit weaknesses faster, which shrinks the time defenders have to respond. Security teams need containment that can keep up.
On Wednesday, 28 October, 12:15–12:30 PM, Alex Goller will lead a live demo showing how agentic AI and the Model Context Protocol (MCP) can help stop lateral movement and isolate applications in seconds. You'll see what AI-assisted breach containment looks like in a real environment and how it helps teams act at the same speed as the threats they face.
Why it-sa Expo&Congress 2026 is worth the trip
it-sa is Europe’s largest trade fair for IT security. Last year’s event drew more than 28,000 visitors from 64 countries, with nearly 1,000 exhibitors.
It’s where CISOs, security architects, and IT leaders from industry, services, and the public sector meet to see what’s changed and compare notes with their peers.
A few reasons to put it on your calendar:
- See the whole market in one place. From large security vendors to early-stage startups, you can explore products and services for cloud, network, data, and industrial security in three days.
- Learn from the people doing the work. Expert forums run right on the show floor, and the Congress@it-sa program runs alongside the expo from 26 to 29 October.
- Get practical about compliance. NIS2 and DORA have raised the bar for how businesses respond to and recover from incidents. it-sa is a good place to see how other teams are putting those rules into practice.
With that many exhibitors, it helps to walk the halls with a clear picture of the outcome you’re after. For teams focused on resilience and segmentation, these three questions are a good place to start:
- Can we clearly see how workloads and applications communicate across our environment?
- Can we restrict lateral movement without redesigning the network or disrupting critical operations?
- Can the same approach work consistently across data centers, endpoints, and cloud environments?
We’ll take on all three at our booth and in our sessions.
Why cyber resilience starts with breach containment
Prevention is critical. Firewalls, endpoint tools, identity controls, and patching stop a huge share of attacks every day.
But no set of controls can close every attack path, especially now that AI is helping attackers find weak spots faster.
A resilient cyber strategy starts from an assume-breach mindset and focuses on keeping an attack’s fallout small. That’s the goal of breach containment: limiting how far an attack can spread, so one compromised system stays one compromised system.
Lateral movement is still a key challenge for security teams
Attackers rarely stop at the first system they land on. They use stolen credentials and trusted connections to move between workloads in search of sensitive data, domain controllers, and backups.
Ransomware groups depend on this movement to do as much damage as possible before they encrypt anything.
Hybrid infrastructure, cloud services, and AI-enabled workflows all add new connections between systems, and many are open by default and rarely reviewed. When a security team can’t say for sure which systems talk to each other, it’s hard to know where an attacker could go next. That’s the core of the lateral movement problem.
How microsegmentation keeps an incident small
Containment starts with visibility into what’s connected, which systems communicate, and where unnecessary pathways exist. From there, microsegmentation restricts those pathways and isolates critical applications and workloads.
If an attacker gets in, segmentation limits how far they can travel and keeps the incident small enough for your team to handle.
This approach also fits where European regulation is heading. NIS2 and DORA put heavy weight on operational continuity and fast recovery. Being able to isolate critical systems during an incident gives teams a concrete way to show that resilience. Illumio Insights Network Posture helps teams report on that posture for compliance.
Plan your visit to it-sa 2026
Bitkom’s numbers show how much is at stake, and AI is only making attacks faster. For security leaders, that leaves one question: if an attacker gets in, how far can they go?
The teams with a good answer have done three things. They’ve mapped how their systems communicate. They’ve closed the connections nobody needs. And they can isolate a critical application in seconds when an attacker gets in. That keeps one incident from becoming a crisis for the whole business, and it gives them the proof NIS2 and DORA ask for.
Bring that question to Hall 7, booth 7-710, and see what breach containment looks like in practice.
Request your free it-sa 2026 ticket code and schedule a meeting with our team. Can’t make it to Nuremberg? Book a demo and see Illumio in action from anywhere.


%20(1).webp)


.webp)