-
CISO BRISBANE 2026 - AGENDA
-
08:00
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
08:45
Welcome from Corinium and the Chairperson
-
08:55
Speed Networking—Making new connections!
During this 5-minute networking session, participants can build their network. Have fun!
-
09:00
Keynote Panel Headliner
From Security to Business Confidence: Redefining the CISO’s Purpose- Aligning security initiatives with business objectives and board priorities.
- Defining measurable outcomes to demonstrate the effectiveness of cyber programs.
- Embedding a culture of resilience: Driving accountability, visibility, and proactive risk management across the enterprise.
- Preparing for emerging technologies, regulatory pressures, and increasingly sophisticated threats for a future-ready leader.
Moderator
Martin Holzworth Chief Information Security Officer UnitingCare Queensland
Panellists
Mick McHugh Chief Information Security Officer Virgin Australia
Danielle Pentony Chief Information Security Officer Australian Digital Health Agency -
09:30
From Policy to Pipeline: Operationalising Identity in Modern Infrastructure
Andrew Brydon - APJ Field CTO Leader - HashiCorp
Modern infrastructure is now driven by automation, pipelines, machine identities and AI-assisted engineering. This session explores how organisations can embed identity, secrets management and policy enforcement directly into infrastructure delivery to reduce static credentials, govern AI-assisted changes, and ensure every infrastructure change is validated, controlled and auditable before reaching production.
Speakers
Andrew Brydon
APJ Field CTO Leader
HashiCorpMalik Ayub
Practice Lead, Security & AI Governance
DevOps1 -
09:55
Case Study: From Zero to Enterprise Excellence: A Case Study of Transforming Cyber Security in 36 Months
Felipe Abreu - Head of IT Infrastructure & Cyber Security - VAE Group
- Boards expect security to enable innovation not just prevent breaches. How must CISO adapt to lead this shift?
- Showcase how cyber resilience can move beyond compliance to become a strategic advantage.
- Explain the link between resilience, customer trust, and competitive positioning.
- Demonstrate practical steps for embedding resilience into business growth strategies.
- Boards expect security to enable innovation not just prevent breaches. How must CISO adapt to lead this shift?
-
10:20
AI is Breaking Data Security… And Fixing It: The New Reality of AI-Driven Risk and How to Stay Ahead
Tim Roughton - Country Manager - Australia & NZ - Concentric AI
AI is rapidly becoming one of the biggest drivers of productivity and innovation in the enterprise — and one of the fastest-growing sources of data security risk. As copilots, assistants, and public AI tools become integrated into daily work, sensitive data is flowing into systems that most security teams can’t fully see, understand, or control.
The problem is that traditional data security controls were never built for this. In fact, many organizations were already struggling to operationalize data security before AI accelerated the challenge. The good news? AI isn’t just creating the problem — it’s also enabling a smarter, more effective way to solve it.
In this session, attendees will learn:
- Why AI has become one of the fastest-growing and least visible sources of enterprise risk
- How GenAI is creating new exposure points for sensitive data
- Why legacy data security tools have failed to keep up — and why AI is making those gaps harder to ignore
- How context-aware, AI-driven data security can deliver more accurate visibility, stronger controls, and real-time enforcement
- What organizations can do to enable AI innovation without expanding their risk surface
Attendees will leave with a clearer understanding of how AI is reshaping data security — and how they can use that same technology to gain control, minimize exposure, and support safer AI adoption across the business.
-
10:45
Morning Coffee and Connect
-
11:15
Panel Discussion
Keeping Security in Lockstep: Cyber Resilience at the Speed of Business in a post-Mythos era.As organisations race to innovate, security often lags behind, creating friction and risk. This panel asks the critical question: can security truly keep pace with business demands?
In this post‑Mythos reality, traditional approaches built on detection, prevention, and dwell time are under strain, forcing a rethink of what good, secure maturity looks like. How do we define cyber resilience for a new era, where success is measured not just by protection, but by the ability to respond and recover at the speed of the business.
- Why the traditional security stack (detection, prevention, dwell‑time response) breaks when attacks execute in zero seconds, and what that means for board‑level risk conversations.
- How AI driven attack speed is reshaping security maturity and raising expectations for operating with the business.
- What defines cyber resilience in the post‑Mythos era, including the shift toward machine speed response and recovery.
- The practical steps and metrics organisations need to embed security into fast moving environments and evolve with modern business standards.
Moderator
Brooke Nicoll Regional Sales Manager Rubrik
Speakers
Stuart Low Business Information Security Advisor Telstra
Nikki Peever Director Cyber Security CAUDIT
Darron Richardson Director, Digital Resilience and Operations (CISO) Southern Cross University
-
11:45
Security in the age of AI and Exploding Data: Why Architecture is the Answer
Kaj Moorthy - Staff Solutions Engineer - Cribl
Security and IT teams are facing a structural challenge: data volumes are growing far faster than budgets, and AI is accelerating both the creation and consumption of telemetry. Many organisations are responding with implicit trade-offs, reducing retention, dropping data sources, or limiting visibility, creating blind spots that weaken both security operations and AI-driven detection.
This session explores why the issue is fundamentally architectural, not budgetary. It outlines a modern approach built on deliberate data tiering, separation of retention from analysis, federated search, and composable architectures that allow AI and security teams to access the right data at scale. Attendees will leave with a practical framework for reducing cost, improving investigation speed, and building a stronger foundation for AI-enabled security operations -
12:15
Panel Discussion
AI, Data Loss, and Human Behaviour: Securing the Tools Staff Already UseEmployees increasingly rely on AI to manage workloads, often outside approved channels. Sensitive data is pasted into prompts, shadow tools appear, and new exfiltration paths emerge. How should we focus on enabling safe adoption while maintaining trust and protecting business-critical data?
- Identify role-specific AI risks by mapping how each team uses data, handles sensitive information, and interacts with AI tools.
- Design tiered access models that balance productivity with risk tolerance across functions with different regulatory and data sensitivities.
- Embed practical micro-training so employees understand safe AI use within the context of their day-to-day tasks.
- Monitor usage patterns to catch early signs of unsafe behaviour or shadow AI adoption before it creates broader business exposure.
Moderator
Anna Clive GM - Data, Digital & Innovation RACQ
Speakers
James Court Chief Security Officer Cleanaway Waste Management
Jane Hogan France Senior Manager Cyber Security Allianz Australia
Peter Baussmann Chief Technology Officer Airlock
-
12:45
Future-Proofing Trust: Security in a World of Quantum Computing, AI, and Continuous Automation
Anthony Ricci - VP of Global Solutions Engineering - DigiCert
-
13:10
Lunch and networking
-
Track A: Resilience and Maturity
Chaired by: Darron Richardson - Director, Digital Resilience and Operations (CISO) - Southern Cross University
-
14:10
Making Cyber Awareness Work for Your Business – Embedding Practical Frameworks
Sadeed Tirmizey - CISO - Seqwater
- Unpack why traditional awareness programs fail to deliver measurable impact.
- Showcase practical frameworks that embed security awareness into daily workflows.
- Demonstrate how to tailor awareness initiatives to different roles and risk profiles.
- Highlight metrics and methods for tracking behavioural change and reducing human risk.
-
14:35
Pre-Emptive Cybersecurity: Blocking Threats at the First Question
Brad Ford - Security Specialist - Australia and New Zealand - Infoblox
Almost every connection on the Internet begins with a DNS request. This session demonstrates how Infoblox Protective DNS stops threats at the moment of intent, blocking access to malicious infrastructure before connections are established. Discover how a pre-emptive DNS-based security strategy dramatically shrinks attack surfaces while protecting users, devices, and networks everywhere they operate.
-
15:00
Panel Discussion
Cyber Governance in Action: Aligning Security, Risk, and Business StrategyEffective cyber governance goes hand-in-hand with robust cyber hygiene. This panel brings together senior CISOs and governance experts to discuss how organisations can embed accountability, oversight, and practical security practices into daily operations. Communicating cyber risks, hygiene gaps, and compliance readiness at the leadership level. Lastly, discussing metrics to track both governance effectiveness and hygiene adherence across teams by translating policies into daily practices that prevent breaches and minimise human error.
Moderator
Qamar Raza PhD GRC Function Head Bayside HealthSpeakers
Paul Bilic Group Head of Cyber Operations Domino’s
Akshay Gupta Head of Cyber Applications & Governance CleanCo Queensland
-
15:25
Verified Trust in the Age of AI: Securing Every Identity, Human and Machine
Steve Dillon - Field CTO - APJ - Ping Identity
As AI agents, deepfakes and automated attacks outpace traditional IAM, organisations face a widening identity trust gap. Drawing on Ping Identity’s State of Trust research, this session examines how to move from static authentication to continuous, verified trust - helping security leaders assess their current posture and apply practical, risk-adaptive IAM patterns over the next 12–24 months.
-
15:50
Securing Innovation: Delivering a 5-Year Airport Transformation Strategy
Hamza Maharoof - General Manager – Technology - Queensland Airports
- Executing a 5-year strategic plan to modernise airport operations and enable future-ready innovation.
- Embedding cybersecurity as a foundational pillar to support scalable, compliant transformation.
- Uplifting core infrastructure across multiple airports to create a secure, resilient baseline.
- Aligning cross-functional teams to accelerate delivery while maintaining strong cyber governance.
-
16:15
Fireside Chat
You Can't Protect What You Can't See: Ausenco’s Data Security Journey in the Age of AIMarcin Zyman - Enterprise Account Executive - Cyera
As AI reshapes how organisations operate, the data underneath it has never been more exposed — or more valuable. In this fireside chat Anuj Anand, Ausenco’s CIO shares how they're rethinking data security with Cyera, to keep pace with AI adoption, cloud expansion, and evolving compliance demands — and what it takes to build a security posture that can grow alongside the business.
Speakers
Marcin Zyman
Enterprise Account Executive
CyeraAnuj Anand
CIO
Ausenco -
Track B: Tech, Threats and Transformation
-
14:10
SOCI in Action: A Strategic Implementation Journey
- Demonstrate how SOCI compliance strengthens cyber and operational resilience.
- Explain the collaborative approach to integrating IT, OT, and business teams through development, implementation and ongoing management of the CIRMP.
- Highlight lessons learned from embedding cyber and the CIRMP into broader enterprise risk management.
- Showcase practical steps for continuous improvement of the CIRMP and using Essential Eight adoption as the base control framework.
-
14:35
Rethinking Detection in a Decentralised World
- Senior Representative - Sentinel One
In the modern enterprise responding to cyber threats is harder than ever. Even the largest businesses with vast resources are getting breached.
In this session we'll discuss a new approach to detect and respond faster, to help keep enterprises running even when a breach occurs, and how we can stay one step ahead of the most advanced threat actors.
-
15:00
Panel Discussion
The Hidden Risk Layer: What’s Really Inside Your Supply Chain?Modern organisations depend on deep, interconnected SaaS and cloud ecosystems that few fully understand. Most security programs still overlook the components inside vendor products, the AI tools staff use daily, and the opaque fourth-party services that create silent exposure. This panel unpacks how to build visibility and reduce blast radius when suppliers fail.
Speakers
Gabriela Guiu-Sorsa Cyber Security Resilience Manager Cyber Security Champions of Tomorrow
Rohan Dwyer Head of Information Security Sunwater
-
15:25
Are you Mythos Ready?
Nakisa Rezakhani - Account Executive - Qualys
As AI‑driven threats compress the time between vulnerability discovery and exploitation, organisations need more than visibility - they need the ability to detect, prioritise, and remediate risk at machine speed. This session will outline how Qualys enables security teams to become Mythos‑ready through a unified, data‑driven approach to exposure management.
- AI‑Speed Detection: Leverage machine‑speed vulnerability detection and a unified inventory of internal and external assets to stay ahead of attackers.
- Hyper‑Prioritisation: Focus on what truly matters by combining threat intelligence, business context, and asset criticality, while validating exploitability against existing controls.
- Zero‑Day Remediation: Respond to zero‑days with operational resilience, using automated patching, mitigation, and continuous validation to shrink exposure windows.
-
15:50
Bridging the Divide: Harmonising OT and IT for Resilient Operations
Ross Gordon - Deputy CISO - Airservices Australia
- Safety vs. Security considerations amongst critical infrastructure.
- Secure by Design for OT systems and managing enterprise risk.
- Integration of service providers into the cyber operations ecosystem.
- Scalable incident response and enabling crisis management.
-
16:15
Navigating the Future of Cyber Security Leadership in a Volatile Digital Landscape
- Senior Representative - Abnormal
- Navigating the rapid rise of AI-driven attacks and sophisticated cyber threats.
- Building agile cyber security strategies while fostering team resilience in times of uncertainty.
- Balancing risk management with innovation to drive organizational growth and trust.
-
16:40
Afternoon Coffee and Connect
-
17:10
Tools Don’t Defend Organisations. People Do.
Tim Sank - Co-founder & Sales Director - Cythera
Most breaches don’t occur because a tool failed. They occur because ownership, context, or response broke down. Despite unprecedented investment in cyber security technology, many organisations remain vulnerable. This presentation explores why, now more than ever, tools alone are not enough, and how human judgement, clear ownership, and decisive action ultimately determine security outcomes.
-
17:15
Turning Threat Intelligence into Action: Staying Ahead of Evolving Risks
Pratima Kushwaha - Board Director - ISACA Brisbane Chapter
- Explain why threat intelligence is critical for proactive defense in today’s dynamic threat landscape.
- Showcase how organisations can integrate threat intelligence into decision-making and incident response.
- Demonstrate practical use cases for automation and AI in accelerating threat analysis.
- Highlight strategies for prioritising intelligence to focus on the most exploitable vulnerabilities.
-
18:10
Chairperson's Closing Remarks and End of CISO Brisbane
-
18:15
Cheers with Peers: Join us for a time of networking and drinks!
Not Found