<img height="1" width="1" style="display:none" alt="" src="https://www.facebook.com/tr?id=367542720414923&amp;ev=PageView&amp;noscript=1">

    Not Found

  • CISO BRISBANE 2026 - AGENDA

  • 08:00

    Register; grab a coffee. Mix, mingle and say hello to peers old and new.

    Arrow
  • 08:45

    Welcome from Corinium and the Chairperson

    Arrow
  • 08:55
    Connect _Network-1

    Speed Networking—Making new connections!

    Arrow

    During this 5-minute networking session, participants can build their network. Have fun!  

  • 09:00
    Panel Discussion

    Keynote Panel Headliner
    From Security to Business Confidence: Redefining the CISO’s Purpose

    Arrow
    • Aligning security initiatives with business objectives and board priorities.
    • Defining measurable outcomes to demonstrate the effectiveness of cyber programs.
    • Embedding a culture of resilience: Driving accountability, visibility, and proactive risk management across the enterprise.
    • Preparing for emerging technologies, regulatory pressures, and increasingly sophisticated threats for a future-ready leader.

    Moderator

    Martin Holzworth Chief Information Security Officer UnitingCare Queensland 

    Panellists

    Mick McHugh Chief Information Security Officer Virgin Australia
    Danielle Pentony
    Chief Information Security Officer Australian Digital Health Agency
     

  • 09:30
    Andrew Hashicorp

    From Policy to Pipeline: Operationalising Identity in Modern Infrastructure

    Andrew Brydon - APJ Field CTO Leader - HashiCorp

    Arrow

    Modern infrastructure is now driven by automation, pipelines, machine identities and AI-assisted engineering. This session explores how organisations can embed identity, secrets management and policy enforcement directly into infrastructure delivery to reduce static credentials, govern AI-assisted changes, and ensure every infrastructure change is validated, controlled and auditable before reaching production.

    Speakers

    Andrew Brydon
    APJ Field CTO Leader
    HashiCorp

    Malik Ayub
    Practice Lead, Security & AI Governance

    DevOps1

  • 09:55
    Felipe Abreu Head of IT Infrastructure & Cyber Security VAE Group

    Case Study: From Zero to Enterprise Excellence: A Case Study of Transforming Cyber Security in 36 Months

    Felipe Abreu - Head of IT Infrastructure & Cyber Security - VAE Group

    Arrow
    •  Boards expect security to enable innovation not just prevent breaches. How must CISO adapt to lead this shift? 
    • Showcase how cyber resilience can move beyond compliance to become a strategic advantage.
    • Explain the link between resilience, customer trust, and competitive positioning.
    • Demonstrate practical steps for embedding resilience into business growth strategies.
  • 10:20
    Tim Roughton Concentric AI

    AI is Breaking Data Security… And Fixing It: The New Reality of AI-Driven Risk and How to Stay Ahead 

    Tim Roughton - Country Manager - Australia & NZ - Concentric AI

    Arrow

    AI is rapidly becoming one of the biggest drivers of productivity and innovation in the enterprise — and one of the fastest-growing sources of data security risk. As copilots, assistants, and public AI tools become integrated into daily work, sensitive data is flowing into systems that most security teams can’t fully see, understand, or control.

    The problem is that traditional data security controls were never built for this. In fact, many organizations were already struggling to operationalize data security before AI accelerated the challenge. The good news? AI isn’t just creating the problem — it’s also enabling a smarter, more effective way to solve it.

    In this session, attendees will learn:

    • Why AI has become one of the fastest-growing and least visible sources of enterprise risk
    • How GenAI is creating new exposure points for sensitive data
    • Why legacy data security tools have failed to keep up — and why AI is making those gaps harder to ignore
    • How context-aware, AI-driven data security can deliver more accurate visibility, stronger controls, and real-time enforcement
    • What organizations can do to enable AI innovation without expanding their risk surface

    Attendees will leave with a clearer understanding of how AI is reshaping data security — and how they can use that same technology to gain control, minimize exposure, and support safer AI adoption across the business.

     

  • 10:45

    Morning Coffee and Connect

  • 11:15
    Panel Discussion-1

    Panel Discussion
    Keeping Security in Lockstep: Cyber Resilience at the Speed of Business in a post-Mythos era.

    Arrow

    As organisations race to innovate, security often lags behind, creating friction and risk. This panel asks the critical question: can security truly keep pace with business demands?

    In this post‑Mythos reality, traditional approaches built on detection, prevention, and dwell time are under strain, forcing a rethink of what good, secure maturity looks like. How do we define cyber resilience for a new era, where success is measured not just by protection, but by the ability to respond and recover at the speed of the business.

    • Why the traditional security stack (detection, prevention, dwell‑time response) breaks when attacks execute in zero seconds, and what that means for board‑level risk conversations.
    • How AI driven attack speed is reshaping security maturity and raising expectations for operating with the business.
    • What defines cyber resilience in the post‑Mythos era, including the shift toward machine speed response and recovery.
    • The practical steps and metrics organisations need to embed security into fast moving environments and evolve with modern business standards.

    Moderator 

    Michael Huynh Sales Engineer Rubrik

    Speakers

    Stuart Low Business Information Security Advisor Telstra

    Darron Richardson Director, Digital Resilience and Operations (CISO) Southern Cross University

     

  • 11:45
    Kaj Moorthy - Cribl

    Security in the age of AI and Exploding Data: Why Architecture is the Answer

    Kaj Moorthy - Staff Solutions Engineer - Cribl

    Arrow

    Security and IT teams are facing a structural challenge: data volumes are growing far faster than budgets, and AI is accelerating both the creation and consumption of telemetry. Many organisations are responding with implicit trade-offs, reducing retention, dropping data sources, or limiting visibility, creating blind spots that weaken both security operations and AI-driven detection.


    This session explores why the issue is fundamentally architectural, not budgetary. It outlines a modern approach built on deliberate data tiering, separation of retention from analysis, federated search, and composable architectures that allow AI and security teams to access the right data at scale. Attendees will leave with a practical framework for reducing cost, improving investigation speed, and building a stronger foundation for AI-enabled security operations
     
  • 12:15
    Panel Discussion

    Panel Discussion
    AI, Data Loss, and Human Behaviour: Securing the Tools Staff Already Use

    Arrow

    Employees increasingly rely on AI to manage workloads, often outside approved channels. Sensitive data is pasted into prompts, shadow tools appear, and new exfiltration paths emerge. How should we focus on enabling safe adoption while maintaining trust and protecting business-critical data?

    • Identify role-specific AI risks by mapping how each team uses data, handles sensitive information, and interacts with AI tools.
    • Design tiered access models that balance productivity with risk tolerance across functions with different regulatory and data sensitivities.
    • Embed practical micro-training so employees understand safe AI use within the context of their day-to-day tasks.
    • Monitor usage patterns to catch early signs of unsafe behaviour or shadow AI adoption before it creates broader business exposure.

    Moderator

    Anna Clive GM - Data, Digital & Innovation RACQ

    Speakers

    James Court Chief Security Officer Cleanaway Waste Management

    Jane Hogan France Senior Manager Cyber Security Allianz Australia

    Peter Baussmann Chief Technology Officer Airlock Digital 

  • 12:45
    Anthony Ricci - DigiCertFarelly - Concentric ai

    Future-Proofing Trust: Security in a World of Quantum Computing, AI, and Continuous Automation

    Anthony Ricci - VP of Global Solutions Engineering - DigiCert

    Arrow
  • 13:10

    Lunch and networking

  • Pratima Kushwaha Executive Manager Cyber Security Queensland Ambulance Service NEW

    Track A: Resilience and Maturity

    Chaired by: Pratima Kushwaha - Advisory Board Member - ISACA Brisbane Chapter

    Arrow
  • 14:10
    Sadeed Tirmizey, Deputy CISO, Airservices

    Making Cyber Awareness Work for Your Business – Embedding Practical Frameworks

    Sadeed Tirmizey - CISO - Seqwater

    Arrow
    • Unpack why traditional awareness programs fail to deliver measurable impact.
    • Showcase practical frameworks that embed security awareness into daily workflows.
    • Demonstrate how to tailor awareness initiatives to different roles and risk profiles.
    • Highlight metrics and methods for tracking behavioural change and reducing human risk.
  • 14:35
    Brad Ford INFOBLOX (spex)

    Pre-Emptive Cybersecurity: Blocking Threats at the First Question

    Brad Ford - Security Specialist - Australia and New Zealand - Infoblox

    Arrow
    Almost every connection on the Internet begins with a DNS request. This session demonstrates how Infoblox Protective DNS stops threats at the moment of intent, blocking access to malicious infrastructure before connections are established. Discover how a pre-emptive DNS-based security strategy dramatically shrinks attack surfaces while protecting users, devices, and networks everywhere they operate. 

     

  • 15:00
    Panel Discussion-1

    Panel Discussion
    Cyber Governance in Action: Aligning Security, Risk, and Business Strategy

    Arrow

    Effective cyber governance goes hand-in-hand with robust cyber hygiene. This panel brings together senior CISOs and governance experts to discuss how organisations can embed accountability, oversight, and practical security practices into daily operations. Communicating cyber risks, hygiene gaps, and compliance readiness at the leadership level. Lastly, discussing metrics to track both governance effectiveness and hygiene adherence across teams by translating policies into daily practices that prevent breaches and minimise human error.

    Moderator 
    Qamar Raza PhD GRC Function Head Bayside Health

    Speakers

    Paul Bilic Group Head of Cyber Operations  Domino’s

    Akshay Gupta Head of Cyber Applications & Governance CleanCo Queensland

  • 15:25
    Steve Dillon Ping Identity

    Verified Trust in the Age of AI: Securing Every Identity, Human and Machine

    Steve Dillon - Field CTO - APJ - Ping Identity

    Arrow

    As AI agents, deepfakes and automated attacks outpace traditional IAM, organisations face a widening identity trust gap. Drawing on Ping Identity’s State of Trust research, this session examines how to move from static authentication to continuous, verified trust - helping security leaders assess their current posture and apply practical, risk-adaptive IAM patterns over the next 12–24 months.


     

  • 15:50
    Matt O Kane - Cloudflare

    Fireside Chat
    You Can't Protect What You Can't See: Ausenco’s Data Security Journey in the Age of AI

    Marcin Zyman - Enterprise Account Executive - Cyera

    Arrow

    As AI reshapes how organisations operate, the data underneath it has never been more exposed — or more valuable. In this fireside chat Anuj Anand, Ausenco’s CIO shares how they're rethinking data security with Cyera, to keep pace with AI adoption, cloud expansion, and evolving compliance demands — and what it takes to build a security posture that can grow alongside the business.

    Speakers

    Marcin Zyman
    Enterprise Account Executive
    Cyera

    Anuj Anand
    CIO
    Ausenco
     

     

  • Darron Richardson Director - Cyber Resilience Southern Cross University

    Track B: Tech, Threats and Transformation

    Chaired by: Darron Richardson - Director, Digital Resilience and Operations (CISO) - Southern Cross University

    Arrow
  • 14:10
    Panel Discussion-1

    Fireside Chat
    The Hidden Risk Layer: What’s Really Inside Your Supply Chain?

    Arrow

    Modern organisations depend on deep, interconnected SaaS and cloud ecosystems that few fully understand. Most security programs still overlook the components inside vendor products, the AI tools staff use daily, and the opaque fourth-party services that create silent exposure. This panel unpacks how to build visibility and reduce blast radius when suppliers fail.

    Speakers

    Gabriela Guiu-Sorsa Cyber Security Resilience Manager Cyber Security Champions of Tomorrow

    Rohan Dwyer Head of Information Security Sunwater

  • 14:35
    Shawn Lukye SentinelOne

    When Attackers Use AI: How Defenders Can Respond

    Shawn Luyke - Senior Solutions Engineer - Sentinel One

    Arrow

    Threat actors now use AI to scale social engineering, accelerate vulnerability discovery, and craft targeted prompt injection attacks. Nation-states and cybercrime groups use the same tools to automate reconnaissance, generate malware variants, and refine influence operations. At the same time, employees and developers use AI across daily workflows. This dual use shifts the risk equation. AI is now both a productivity engine and an attack surface.

    This session examines the modern cybercrime ecosystem and the common AI-enabled tradecraft used by criminal syndicates and state-aligned actors. It maps how AI is applied across the attack lifecycle, from initial access and payload development to fraud, extortion, and data exploitation.

    The session then outlines a practical response and draws on the comprehensive guidance on AI adoption, co-authored by ASD, CISA, NSA, and NCSC. It focuses on governing AI interactions in real time - blocking malicious inputs, preventing sensitive data disclosure, and detecting abnormal usage patterns. It examines how Security teams can move beyond the role of innovation gatekeeper by deploying enabling controls that act as financial and operational guardrails.

    We will explore the role of AI runtime defence in anomaly detection and resource abuse prevention, alongside AI Usage Control for visibility, policy enforcement, and Shadow AI governance. The outcome is measurable risk reduction, improved oversight, and a defensible strategy for scaling AI safely across the enterprise.

  • 15:00
    Interactive Discussion

    Interactive Session
    The CISO Confessional: Challenges We Don’t Put on the Board Slides

    Arrow

    This interactive session opens a candid space for security leaders to surface the real, often unspoken challenges shaping their role in 2026. Using live polling, attendees will share what’s keeping them up at night—from AI governance pressures and boardroom dynamics to emerging risks and overhyped industry trends.

     

    Facilitator

    Gabriela Guiu-Sorsa
    Information Security Principal Advisor
    Cyber Security Champions of Tomorrow

  • 15:25
    Nakisa Rezakhani - Qualys

    Are you Mythos Ready?

    Nakisa Rezakhani - Account Executive - Qualys

    Arrow

    As AI‑driven threats compress the time between vulnerability discovery and exploitation, organisations need more than visibility - they need the ability to detect, prioritise, and remediate risk at machine speed. This session will outline how Qualys enables security teams to become Mythos‑ready through a unified, data‑driven approach to exposure management.

      • AI‑Speed Detection: Leverage machine‑speed vulnerability detection and a unified inventory of internal and external assets to stay ahead of attackers.
      • Hyper‑Prioritisation: Focus on what truly matters by combining threat intelligence, business context, and asset criticality, while validating exploitability against existing controls.
      • Zero‑Day Remediation: Respond to zero‑days with operational resilience, using automated patching, mitigation, and continuous validation to shrink exposure windows.
  • 15:50
    Ross Gordon AirServices Au

    Bridging the Divide: Harmonising OT and IT for Resilient Operations

    Ross Gordon - Deputy CISO - Airservices Australia

    Arrow
      • Safety vs. Security considerations amongst critical infrastructure.
      • Secure by Design for OT systems and managing enterprise risk.
      • Integration of service providers into the cyber operations ecosystem.
      • Scalable incident response and enabling crisis management.
  • 16:15
    Matt Berry - Abnormal

    Open Source Intelligence Gathering - How Criminals are Automating this Process to Attack You

    Matt Berry - Field CTO - Abnormal AI

    Arrow

    Building relevant, highly personalised open source intelligence (OSINT) on a C-level target previously took several days, but advances in AI have dramatically changed the equation.

    Threat actors can now generate not only the key intelligence required for a personalised attack, but also the attack email itself, in just minutes!

    In this session, Matt will demonstrate a fully automated OSINT report and attack-generation tool to show how bad actors are creating custom campaigns at scale. You'll see real examples of recent attacks and learn how you can use behavioural AI to build resilience against these evolving threats.


    Speakers

    Peter Hamilton
    Principal – Cyber Security
    Stanmore Resources Ltd.

    Matt Berry
    Senior Sales Engineer
    Abnormal AI

     

  • 16:40

    Afternoon Coffee and Connect

  • 17:10
    Tim Sank - Cythera

    Tools Don’t Defend Organisations. People Do.

    Tim Sank - Co-founder & Sales Director - Cythera

    Arrow

    Most breaches don’t occur because a tool failed. They occur because ownership, context, or response broke down. Despite unprecedented investment in cyber security technology, many organisations remain vulnerable. This presentation explores why, now more than ever, tools alone are not enough, and how human judgement, clear ownership, and decisive action ultimately determine security outcomes.

     

  • 17:15
    Pratima Kushwaha Executive Manager Cyber Security Queensland Ambulance Service NEW

    Turning Threat Intelligence into Action: Staying Ahead of Evolving Risks

    Pratima Kushwaha - Board Director - ISACA Brisbane Chapter

    Arrow
    • Explain why threat intelligence is critical for proactive defense in today’s dynamic threat landscape.
    • Showcase how organisations can integrate threat intelligence into decision-making and incident response.
    • Demonstrate practical use cases for automation and AI in accelerating threat analysis.
    • Highlight strategies for prioritising intelligence to focus on the most exploitable vulnerabilities. 
  • 17:35

    Chairperson's Closing Remarks and End of CISO Brisbane

  • 17:40

    Cheers with Peers: Join us for a time of networking and drinks!