Monika Kullberg, Sandvik Group

Cybersecurity has always been about more than code. As the Cyber Resilience Act (CRA) reshapes the regulatory landscape, the real challenge isn’t just technical adaptation, but organizational transformation. This session explores how psychology, behaviour, and systems thinking can help us build organizations that are not only compliant, but resilient.

This session will unpack:

  • Why our current approaches to change often fall flat
  • What really drives human behaviour in complex systems
  • How to move from checkbox compliance to engagement
  • What it takes to embed secure habits into workflows
  • The future of cybersecurity depends not just on what we deploy, but on how we behave, organize and adapt. It’s about completing it with the one element we’ve underestimated: us.


Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)