-
CISO Canberra 2026 - AGENDA
-
08:15
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
08:45
Welcome from the Chairperson
Roma Singh - Portfolio Security Advisor - VIC Department of Transport and Planning
-
08:55
Speed Networking – Making new connections!
During this 5-minute networking session, participants can build their network. Have fun!
-
09:00
Opening Keynote Discussion
Interpreting Global Cyber Threat Patterns in a Fragmented WorldThis keynote panel brings international and national perspectives together to help government cyber leaders make sense of global threat signals shaped by geopolitical tension, cross‑border crime, and coordinated activity.
- What are you seeing across borders that genuinely stands out right now?
- How are those patterns being understood within law enforcement and intelligence communities?
- Where do organisations tend to misjudge the significance of what they are seeing?
- How should government cyber leaders use these insights to inform action without overstating certainty or urgency?
Moderator:
Dr Rajiv Shah Director AISA
Panelists:
Tori Lamb Assistant Secretary Cyber Affairs and Critical Technology Department of Foreign Affairs and Trade
Sandra Booth Assistant Commissioner Cyber & Special Investigations AFP
Mark Rysanek Cyber Liaison Officer Royal Canadian Mounted Police
-
09:35
Agentic Runtime Security - Solving Identity and Access Gaps in Agentic AI
Andrew Brydon - Field CTO Leader, APJ - HashiCorp, an IBM company
AI agents are poised to transform enterprise operations, but they also introduce unprecedented identity and security challenges. This session discusses the emerging risks associated with agentic AI and share a framework for securing autonomous systems through modern identity, access, and governance controls. Discover how leading organizations are preparing to scale AI adoption while maintaining security, compliance, and operational resilience.
-
10:00
Keynote Presentation
Horizon 2: Moving from Capability Build to Operational MaturityAshley Bell - Assistant Secretary Cyber Policy and Programs - Department of Home Affairs
This keynote explores what maturity looks like as cyber security capability is scaled across government under Horizon 2 of the 2023–2030 Cyber Security Strategy. It focuses on the expected level of operational maturity at this stage, how capabilities are being embedded into real environments, and the key delivery, integration, and coordination challenges that remain as agencies move from build to sustained operation.
-
10:25
Morning Tea Break
-
10:55
Complexity Is Now the Primary Risk Multiplier
Senior representative - - Forescount
Risk is no longer driven primarily by single control failures. It is amplified by interdependencies, overlapping platforms. unclear ownership and fragile integrations. This keynote explores how complexity itself has become the dominant risk multiplier in modern environments, and why CISOs are increasingly focused on reducing coupling and blast radius rather than maximising coverage.
-
11:20
Keynote Panel Discussion
Risk Trade-Offs in Shared Platforms: How Much Vendor Diversity Is Enough?Shared platforms and common vendors continue to underpin government service delivery, but they also concentrate risk in ways that require clearer thinking about how much vendor diversity is enough.
- Where does efficiency in shared platforms become systemic risk?
- How should vendor risk be continuously re-evaluated beyond procurement cycles?
- How do we reduce concentration risk without impacting delivery speed or scale benefits?
Moderator:
Roma Singh Portfolio Security Advisor VIC Department of Transport and Planning
Panellists:
David Norwood CIO & Director Digital Health & Innovation Sydney Local Health District
Daminda Kumara CISO Commonwealth Superannuation Corporation
-
11:55
How to Build Machine Speed Continuous Security Posture for Government Leaders
Matt Waite - Senior Director of Solution Engineering - Tanium
The emergence of Mythos-class AI has permanently changed what defensible security means for government agencies. Attackers can now discover and exploit vulnerabilities at machine speed — making continuous, real-time visibility a baseline requirement, not best practice. This roundtable explores:
- How agencies can move from static compliance reports to continuously updated, executive-ready metrics
- What good looks like: patch status, remediation velocity, and control effectiveness
- How risk-based prioritisation helps leaders direct effort to where it matters most how agencies can reduce exposure and deliver stronger audit outcomes
-
12:20
Keynote Presentation
When Cyber Becomes a Public Issue: An Elected Leader’s PerspectiveCr Stuart James - Councillor for Warrigal Ward & Mayor - City of Monash
This keynote explores what changes when cyber risk, incidents and spending decisions become matters of public visibility in local government. Drawing on three terms as Mayor of the City of Monash and more than two decades of experience in technology and cyber security, Cr Stuart James connects technical understanding with the realities of public accountability. The session examines transparency, media scrutiny, community expectations and service continuity when information is incomplete and public trust is at stake.
-
12:45
Lunch
-
Track A: Identity & Human Factor
Roma Singh - Portfolio Security Advisor - VIC Department of Transport and Planning
-
13:45
Addressing Insider Threats in Modern Operating Models
Kane Robinson - Cyber Security Manager - National Gallery of Australia
A cyber-conscious mindset and security-aware culture are non-negotiable. It is not just about ticking boxes with e-learning or phishing tests. Real success is when cyber security becomes second nature—when people instinctively make safer choices and even share tips with family and friends. That’s when culture truly sticks. This session explores practical ways to embed that mindset and turn everyday behaviours into security habits.
-
14:10
AI Didn't Create Your Data Risk. It Exposed It.
Securing Government Data in the Age of AISteve Moros - Senior Director, Advanced Technologies Group (ATG), Asia Pacific and Japan - Proofpoint
We will explore three relevant use cases to show "hard to stop" real world data exfiltration and compliance violations. As agencies accelerate AI adoption, traditional security controls often lack the visibility to understand how sensitive information is being accessed, shared and used. This session explores how government security leaders can identify AI-driven data risk, close governance gaps and strengthen control over both human and AI activity. Learn practical approaches to improving visibility, reducing data exposure and enabling secure, responsible AI adoption across government.
-
14:35
Fireside Chat
AI Adoption in Government Cyber Security: Workforce Impact and Operational RealityAI is being introduced into government cyber security environments alongside existing systems and responsibilities, raising questions about how much pressure it removes, how much it adds, and what it changes for teams in practice.
- How is AI changing day to day work and expectations for cyber teams?
- Where is pressure building on judgement, accountability, and capacity as AI use grows?
- What does this mean for the future pipeline of skills, roles, and experience in government cyber teams?
Moderator:
Krishna Bagla Manager Cyber Security Operations & Implementation NSW Education Standards Authority
Speakers:
Marc Karahasanoglu CISO NSW Rural Fire Service
Jakub Zvěřina Technical Program Lead for CyberPath ACS
-
15:00
How To Make Your AI Adoption Successful
Sam Brazier-Hollins - Head of Technical Consulting - Fujitsu
AI success is about more than technology. This session explores how organisations can drive meaningful adoption by empowering AI champions, measuring outcomes that matter, and preparing for the evolution from chat-based AI to autonomous agents. Attendees will learn how leading organisations laid the foundations for AI success, overcome common adoption barriers, and balance innovation with governance. Gain practical insights into the people, processes, and cultural changes required to turn AI investments into lasting business value.
-
Track B: Execution & Delivery
Track Chair: Umair Zia - A/Director Infrastructure & Service Delivery - Sydney Local Health District
-
13:45
Fireside Chat
SOC Isn’t Autonomous Yet: Where AI Helps and Where It Doesn’tAI is increasingly embedded in cyber security operations, but SOCs remain human-led in practice. This session explores where AI is genuinely improving visibility, telemetry analysis, and alert prioritisation, and where human judgement is still essential for effective detection and response in complex environments.
Moderator:
Krishna Bagla Manager Cyber Security Operations & Implementation NSW Education Standards Authority
Speakers:
Jessamy Perkins Principal Cyber Security Adviser Australian Government
Rue Maharaj Specialist - Cybersecurity Defence Management Melbourne Water
-
14:10
Agentic AI Quiz
Preventing Agentic AI From Exceeding Its Role – Quiz Time!Peter Baussman - CTO Airlock - Digital
Agentic AI workers are changing the endpoint security model. Tools such as ChatGPT Codex, Claude Code, and Google Antigravity do more than respond to prompts. They reason, persist, adapt, and take action using the privileges of the interactive user, creating new security challenges for organisations embracing AI. Join Airlock Digital’s Canberra-based CTO, Peter Baussman, for a fun and interactive quiz to learn how the public sector can utilise agentic AI workers safely without slowing adoption. Discover why traditional reactive controls are brittle in the face of goal-driven AI agents, and how a prevention-first, deny-by-default application control model can help organisations stay in control.
Plus, put your knowledge to the test for the chance to win prizes celebrating Airlock Digital's South Australian heritage, including a Haigh’s Chocolate Hamper, Menz FruChocsEmergency Kit and a Henschke Wine Gift Pack. -
14:35
Case Studey
Cyber Security Transformation in a Highly Integrated Public Healthcare EcosystemUmair Zia - A/Director Infrastructure & Service Delivery - Sydney Local Health District
This case study explores Sydney Local Health District’s cyber security transformation within a highly interconnected healthcare environment, where resilience depends on shared systems, statewide platforms, and third-party dependencies across more than 200,000 connected devices. Key topics include:
- Managing shared ownership, visibility, and accountability across stakeholders
- Strengthening resilience in clinical and operational environments
- Navigating legacy systems and complex dependencies
- Balancing governance, continuity, and cyber maturity uplift
-
15:00
From Prevention to Resilience: Securing Modern Government
Dominic Lovell - Senior Solutions Engineering Manager - Akamai
Governments and critical infrastructure organisations globally rely on Akamai to protect the applications, APIs, networks, and digital services they depend on.
As environments become increasingly distributed across cloud, legacy systems, APIs, and AI workloads, the focus is shifting toward resilience: reducing the attack surface, stopping threats before they reach critical systems, and containing compromise when it occurs.
Drawing on work across mission-critical government and defence environments, this session explores how capabilities spanning application and API security, DDoS protection, Protective DNS, Zero Trust access, and microsegmentation operate at scale. Attendees will gain actionable insights into why resilience and containment are just as important as prevention for modern CISOs.
-
15:25
Afternoon Refreshments
-
15:55
Presentation
What CISOs Are Being Asked to Carry Right NowThis keynote reflects on the expanding scope of CISO responsibility in today’s environment, where resilience, risk, workforce capacity, regulatory expectations, and evolving threat demands are converging under constrained operating conditions.
- What responsibilities are now realistically expected of CISOs beyond traditional cyber security leadership?
- Where is CISO effectiveness most under strain in today’s operating environment?
- What enables CISOs to sustain effective decision making under continuous pressure?
-
16:20
Closing Panel Discussion
Preparing for the Quantum Era: What It Means in Practice and Where to StartWith ASD outlining Australia’s direction on post-quantum cryptography, this conversation focuses on how security leaders can interpret those signals, balance long‑horizon risk with current delivery pressures, and take sensible, proportionate steps without overstating urgency.
- How should security leaders think about the technical timeline for quantum risk without relying on speculative dates?
- What preparation makes sense today without overinvesting or diverting focus from current risks?
- What is one realistic step teams can take in the next 12 months to start preparing responsibly?
Moderator:
Dr Rajiv Shah Director AISA
Panellists:
Tara Lie Information & Technology Governance Manager WA Department of Water and Environmental Regulation
Dr Muhammed Esgin Deputy Director, Post-Quantum Cryptography in the Indo-Pacific Program Monash University
Roma Singh Portfolio Security Advisor VIC Department of Transport and Planning
-
16:50
CISO Canberra 2026 Chair's Closing Address
-
17:00
Cheers with Peers
Continue the conversations in a fun and entertaining way.
Not Found