Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What are the best practices for turning a…
Governance, Ownership & Risk

What are the best practices for turning a governance conference into a useful learning and networking forum?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Governance, Ownership & Risk

Best practice is to mix keynote sessions, practitioner-led case studies, interactive workshops, and peer networking in one agenda. That combination helps attendees move from abstract ideas to workable actions. A strong programme also gives participants access to subject matter experts, implementation lessons, and discussion space for comparing programme designs and operating models.

Design the agenda around learning transfer, not just speaking slots

A useful governance conference is built to help attendees move from policy language to operating decisions. The agenda should mix keynote framing, practitioner case studies, interactive workshops, and structured peer discussion so participants can compare how different organisations actually govern similar problems and where implementation choices diverge.

The strongest programmes make each session type do a different job. Keynotes set context, case studies show what was tried and what changed, workshops turn concepts into decisions or artefacts, and networking sessions let people test assumptions against peers who face the same constraints.

That mix matters because governance topics are often discussed at the level of principles while the practical challenge sits in ownership, controls, operating model, and accountability. A conference becomes useful when attendees can leave with a clearer view of what good looks like in practice, not just a better vocabulary.

Build in enough specificity for the right people to self-select

Broad governance themes attract a wide audience, but usefulness rises when the programme is segmented by maturity, role, or problem type. Practitioners typically learn more from sessions that speak directly to their context, such as board reporting, programme design, risk oversight, control testing, or implementation lessons from comparable environments.

For that reason, strong conference design usually includes subject matter experts who can answer detailed questions, not just presenters who deliver high-level commentary. Attendees should be able to compare design patterns, ask about trade-offs, and understand where a model works well or breaks down under real operating pressure.

Networking also becomes more valuable when it is intentionally structured. Informal time helps, but the best forums create opportunities for peer exchange around concrete prompts, such as how teams measure adoption, how they handle exceptions, or how they align governance with execution. For topics tied to identity and secrets governance, Ultimate Guide to NHIs is a useful reference point for the kinds of lifecycle and control issues practitioners often need to discuss.

What to prioritise when the goal is both learning and networking

Conference organisers usually get the best outcome when they prioritise relevance, interaction, and peer comparability over volume. A smaller number of well-chosen sessions tends to produce better discussion than a crowded schedule with too many generic talks, especially when attendees are expected to share operating experience rather than consume product-style presentations.

What to verify: Each session should have a clear practical output, whether that is a lesson learned, a decision rule, a control pattern, or a comparison of operating models. If a session cannot answer “what would the attendee do differently on Monday?”, it probably needs tighter framing.

Common mistake: Treating networking as an afterthought. If peer exchange is important, it needs facilitation, shared context, and enough time for follow-up discussion. Otherwise, attendees leave with notes from talks but no meaningful exchange with the people who have solved adjacent problems.

Practitioner takeaway: The most useful governance conferences are designed like working sessions with social value, not like lecture series with coffee breaks. If the agenda does not help attendees compare decisions, challenge assumptions, and meet peers with comparable problems, it will feel informative but not actionable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernConference governance content benefits from clear oversight, roles, and accountability.
ID — IdentifyUseful forums help attendees identify governance gaps, priorities, and operating-model differences.
RC — RecoverPeer learning sessions often transfer lessons on remediation, improvement, and organisational change.
Recommendation — Define programme ownership, success criteria, and decision rights for the conference agenda. Frame sessions around the governance issues and operating assumptions attendees need to assess. Capture post-event actions that convert conference learning into measurable governance improvements.
CIS Controls v814 — Security Awareness and Skills TrainingA governance conference functions as skills transfer and practitioner education.
17 — Incident Response ManagementCase-study formats help attendees learn from response decisions and operating lessons.
20 — Penetration Testing and Red Team ExercisesInteractive formats work best when participants actively test assumptions and controls.
Recommendation — Use practitioner-led sessions and workshops to improve applied governance skills. Include post-incident lessons and decision trade-offs in relevant case-study sessions. Use workshops to stress-test governance designs and expose weak assumptions.
NIST SP 800-63IAL — Identity Assurance LevelIdentity governance discussions often need precision about assurance, trust, and proofing decisions.
AAL — Authenticator Assurance LevelSessions comparing governance operating models may cover assurance strength and control selection.
Recommendation — Clarify assurance expectations when conference sessions discuss identity governance and trust. Distinguish stronger and weaker authentication choices when they affect governance design.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org