-
Day 1
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
08:50
Welcome from Corinium and the Chairperson
Chirag Joshi - Founder & CISO - 7 Rules Cyber
-
09:00
Opening Keynote: Dynamic Risks, Strategic Moves – Embracing Change for Success
- Discuss the rapidly evolving landscape of cybersecurity threats and their profound impact on business success.
- Highlight the transformational power of aligning technology risk with your core business strategy, creating a strong defence against emerging threats.
- Explore the complexities of managing enterprise-scale cybersecurity risks, including third-party and supply chain vulnerabilities.
- Emphasise the importance of building and nurturing a resilient workforce, equipped to tackle the evolving challenges of the digital age.
-
09:25
Self-Governing DevSecOps: Navigating Towards Continuous Security
This session will guide you through the stages of the DevSecOps transformation journey, illustrating the benefits of autonomous DevSecOps in enhancing efficiency, security, and scalability while addressing the challenges that come with it. Discover how to navigate the path towards a self-sustaining security framework that is ready for the future. -
09:50
Taking full advantage of diversity in your cyber teams
Imtiaz Khan - CISO - Roads and Maritime Services
Creating our own cybersecurity unicorns is possible when we shift the lens we see them through. By taking transferable skills, valuable professional background, and the right attitude into account, we can bridge the cybersecurity talent gap. In this session, we will explore how to encourage non-cybersecurity executives to break into cyber roles with confidence.
-
10:15
NETWORKING BREAK
-
10:45
“Know Thy Enemy” – Effectively managing AI risks
- Strategies to protect data from poisoning and manipulation, disclosure of sensitive information, and bias and discrimination issues
- Mitigating adversarial prompts and risks for generative AI systems
- Preventing systemic vulnerabilities such as DoS attacks and overreliance and misuse of AI
-
11:10
Mitigating Risk to the #1 Target for Attackers: Your Enterprise Identity System
Senior representative - TBC - HashiCorp
- Why AD is such a target
- How you can increase operational resilience of this mission critical identity system by
- Mitigating attacks against your AD
- Significantly reducing its recovery time objective (RTO)
-
11:35
PANEL: Keeping up with a constantly changing regulatory environment
- An overview of new security regulations and standards affecting Australian businesses
- Complying with SOCI, SoNS, CPS 234, CPG 234, CPG 235, and other standards such as ISO27001, AESCSF, NIST and Essential 8
- Insights into the current proposed legislation NIS 2.0 and DORA, which have been said to be the GDPR for Information Security
- Strategies to balance the benefits against the cost-impact of compliance based on the enterprise’s risk appetite
Panellists:
Nathan Lewis, Head of Cyber, Technology and Data Risk, Newcastle Permanent
Gaurav Vikash, Head of Security and Risk, APAC, Axon Enterprise
Sebastian Tymoszuk, CISO, Autosports Group
Umair Zia, Head of Cyber Security, Sydney Local Health District
-
12:10
Keeping your company’s Crown Jewels safe
Credentials, API tokens, certificates, keys. All these secrets are growing at a rapid rate as we work towards building least privilege patterns. This proliferation introduces significant challenges for visibility, lifecycle, and user experience, and poses significant risk when they fall into the hands of bad actors. During this session, we will look at the necessary shifts that you need to make to keep your secrets safe.
-
12:35
Sobering Up the AI Hype – Making Strategic Cyber Investments and Delivering Business Value
Nivi Newar - Head of Cyber Security Strategy & Governance - UNSW
- Understanding the risks and implications of AI and how it will change our threat landscape
- Influencing and guiding the business to make strategic investment decisions
- How cyber leaders are successfully governing the use of AI
- How can AI be used in cyber defence?
-
13:00
Lunch
-
TRACK A - Standards & Regulations
Chair: Chirag Joshi - Founder & CISO - 7 Rules Cyber
-
14:10
PANEL: Strategies to keep up with increased regulatory changes in security
In recent years, with the increasing activity and exploitation of organisations; governments have started to see the importance of Information Security.
To address this governments have been implementing legislation and regulations around Information Security, to ensure that critical systems and infrastructure are protected.
Europe last year released their versions which will come into effect in 2024 and 2025, that looks to address Information Security in Europe.
These new directives and regulations could have implications and impacts, for any business working with EU organisations.
Panellists:
Jihad Zein, Global Head of GRC, Technology, Toll Group
Matthew Duckworth, Director, IT Risk and Security, MetLife Australia
Leron Zinatullin, CISO, Linkly
-
14:35
Advancing your cyber maturity through improved resilience
Senior representative - TBC - Varonis
- Developing risk assessment strategies with the emerging risks and threat landscape in mind
- Conducting gap analysis to identify where resilience can be improved
- Analysing metrics for visibility of the effectiveness of your cyber programs
- Selecting the best maturity model for your organisation and creating an advancement plan
-
15:00
PANEL: Driving the need for AI security regulations
- Strategies to increase awareness of AI risks to senior management and the board to support informed business decisions
- How can cyber leaders collaborate with regulatory bodies to create effective AI security standards and guidelines
- Overview of the ISO/IEC CD 27090 guidance and ASD’s Guidelines for Secure AI System Development – where to from here
Panellists:
Nathan Lewis, Head of Cyber, Technology and Data Risk, Newcastle Permanent
Pearse Courtney, Cyber Project Manager, AEMO
-
15:25
Automating compliance – hype or reality?
Senior representative - TBC - Axonius
During this session, we’ll explore how compliance management platform can help you take the manual work out of your security and compliance process and replaces it with continuous automation
-
TRACK B - Risk Management
Chair: Dan Haagman - - Doctoral Security Researcher
-
14:10
Leveraging Offensive Security for Proactive Risk Management
Dan Elliott - Head of Cyber Resilience - Zurich
- Integrate offensive security teams into a proactive risk management strategy to prioritise and address critical vulnerabilities.
- Foster a culture of continuous improvement within teams to stay agile and responsive to evolving threats.
- Align offensive security efforts with organisational risk reduction goals, ensuring they support broader security objectives.
- Apply offensive security skills beyond traditional penetration testing to identify emerging threats and reinforce the organisation's overall risk posture
-
14:35
Risk and Vulnerabilities - Managing your attack surface and prioritising vulnerabilities
Senior representative - TBC - Ping Identity
In today's digital landscape, managing your attack surface and prioritizing vulnerabilities are crucial for robust cybersecurity. Join us for a 20-minute session where we'll explore effective strategies to identify, assess, and mitigate potential threats. Learn how to streamline your vulnerability management process and allocate resources efficiently to safeguard your organization against cyberattacks.
-
15:00
PANEL: Elevating cyber risks to boards, senior management, and across departments
- Effective ways to influence boards and senior management on how security is aligned with the business goals
- Engaging the Steering Committee: How to get cross-functional representatives to be security cheerleaders
- The power of joining forces to assess risks, implement security controls, and ensure tech infrastructure is compliant to regulations
Moderator:
Madhuri Nandi, Head of Security, Till Payments
Panellists:
Vasyl Nair, Group CEO, Mine Super
Christopher Johnson, Group Head of Technology, Charter Hall
Saleshni Sharma, Regional CISO, Berkley
Nick Stanton, Head of Technology Risk, Tyro
-
15:25
Harnessing global threat intelligence to stay ahead of the game
Senior representative - TBC - Infoblox
As we explore leveraging threat intelligence, machine learning, and AI for proactive protection, learn how consolidating vendors and platforms simplifies operations while enhancing visibility and efficiency.
Join us to unlock new strategies for bolstering cybersecurity resilience and how you can revolutionise your cybersecurity strategy.
-
TRACK C - Enabling Growth
-
14:10
Measuring the effectiveness of security programs and uplifting maturity
Anil Yellamati - Head of Cyber Security & Risk - Blackmores Group
- Getting buy-in from the board and steering committee
- Deciding on the most suitable techniques to implement a successful program
- How to ensure internal stakeholders understand the objectives and needs of security controls
- Defining metrics and adopting assurance frameworks
- Uplifting your program’s maturity by focusing on continuous improvement
-
14:35
Reinforcing your boundaries with IAM
Senior representative - TBC - Okta
- What are the key challenges organisations face when implementing identity access management?
- What are your recommendations to navigate these challenges?
- What does a successful approach look like?
- How can IAM help safeguard organisations upgrading business operations, modernising aging infrastructure, and protecting network perimeters, and scaling up?
-
15:00
PANEL: Educate, educate, educate – simple steps to improve accountability across the business
Effective ways to educate – engaging diverse people with cybersecurity and online safety
People centric – adopting an in-person tone and using real-life examples of how a cyberattack can impact everyone’s lives
Relevant – what’s in it for them and why they should care
Providing resources – setting clear expectations and providing resources
Moderator:
Lisa Dethridge, Research Fellow, RMIT University
Panellists:
Hani Arab, CIO, Seymour Whyte
River Nygryn, CISO, HammondCare
Naveen Sharma, Head of Information Security, Superloop
-
15:25
Continuous Exposure Management - Why thinking like an attacker is an efficient way to shape your remediation
Senior representative - TBC - SecurityScorecard
Cyber-attacks are getting more regular and sophisticated, often they go undetected. Improving security posture is an ever-growing priority; however, as organizations continue to struggle with remediation, this gives adversaries more opportunities to exploit not just vulnerabilities but also identity-related issues and misconfigurations. Join this session to learn how organizations mature their security posture by looking at their environment through the lens of an attacker, giving them a common language for discussing, and prioritising measurable risk reduction.
-
15:50
NETWORKING BREAK
-
16:20
PANEL: Influencing Human Behaviour and Reducing Cyber Risks
- Importance of human factor to cyber security and why most cyber awareness efforts fail
- Tailoring security awareness programs to address cyber risks and business priorities
- Strategies to influence behaviour and create a cyber-safe culture
Panellists:
Oliver Sebastian, Director, Information Technology, Landcom
Bradley Busch, Non-Executive Director, Shire Christian School
Sophia Barbour, Cyber Awareness and Intelligence Lead, Commonwealth Superannuation Corporation
-
16:45
Fortifying your Security Operations with Enhanced Visibility
Due to the constant evolution of our internal networks and in the face of an unforgiving threat landscape, Security Operations teams are constantly looking at new ways to enhance their visibility to better anticipate cyber threats. This session will explore the importance of how clarity of goals, visibility of your attack surface, and cyber threat intelligence can be helpful in better focusing your cyber security defences.
-
17:10
On-stage Interview: Nurturing high-performing, positive teams
Cybersecurity can seem like an unrewarding career. Preventing breaches depends on a variety of factors, including the company's risk-appetite, senior management buy-in and adequate budgets. If the company is not hacked, whether you have a robust and mature cyber strategy or just luck, you're just doing your job. But if it is does, the cyber team often gets the blame. It's essential for CISOs to ensure their teams are motivated and engaged. During this interview, we will review KPIs and discuss successful ways to ensure the wellbeing of the team and prevent burnout.
Interviewer:
Chirag Joshi, Founder & CISO, 7 Rules Cyber
Interviewee:
Jan Zeilinga, CISO, James Cook University
-
17:30
Closing Remarks
-
17:40
Day One Close and Networking Drinks
Continue your conversations in a fun and entertaining Wine Tasting Competition to discover different ranges and categories of some of Australia’s best wines.
Not Found
-
Day 2
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
08:50
Welcome from Corinium and the Chairperson
Jason Murrell - Chair - Australian Cyber Network
-
09:00
Leading a business value driven team
Lieutenant General Michelle McGuinness CSC - National Cyber Security Coordinator - Department of Home Affairs
- Uncover what lies ahead - a brief guide outlining key initiatives, strategic imperatives and the challenges that CISOs must navigate
- Deepen your understanding of the vision of the 2023-2030 Australian Cyber Security Strategy to empower you with actionable strategies to craft a path to success
- Learn about the key challenges and success factors identified for the strategy, including the need for long-term commitment, flexibility, and alignment with global allies
-
09:25
Accelerating Cloud Security to enable AI: How Security teams can adopt a new operating model to enable agile AI adoption
Cloud and AI are empowering organisations to meet their business goals quickly and effectively, however, also presents a tectonic shift for cyber security teams. Today, CISO’s are forced to enable the adoption of Cloud and AI use cases at the speed of dev, requiring new operating models to continue to protect their environments and eliminate critical risks. Join this session to learn how you can enable your team to build faster in the cloud, ensuring security, Dev and DevOps can work together in a self-service model built for the scale and speed of your cloud and AI developments. -
09:50
Unravelling the complexities of security architecture
Ilya Polyakov - Chief Security Architect and Head of Identity Management - NSW Department of Planning, housing and Infrastructure
- Exploring the importance of security architecture
- Several misconceptions about what security architects do
- 3 important jobs of security architect and how they differ
- Making it easy and fast for business
-
10:15
Cyber strategy – creating robust and future-oriented frameworks
Devraj Chakraborty - Head of Information Security APAC - ABN AMRO Clearing Bank
Designing a cybersecurity operating model with people, processes, and technology at the core of your strategy is key. How to factor in the business strategy into the operating model, and how to take your business requirements as part of that process. During this session, we’ll explore strategies to:
- Build a well-developed program that supports and is tailored to the organisation’s needs
- Create a well-designed program with cooperation and support from stakeholders and management
- Develop effective metrics and KPIs for program design, implementation, and management performance assessment
-
10:40
NETWORKING BREAK
-
TRACK A - Presentations
-
11:10
Data on the move: The hidden risks of employee turnover
Sandeep Taileng - CISO - State Trustees
-
11:35
Why SaaS breaches are the best kept secrets
Secrets such as APIs, tokens, valid and stolen credentials act as keys to unlock protected resources. They are the leading threat vector for data exposures and breaches of enterprise SaaS applications. In this session, learn the anatomy of a SaaS breach and best practices to build a viable SaaS threat model.
-
12:00
Where security and business meet – advancing cyber maturity and helping the business scale up
Roxanne Pashaei - CISO - NSW Rural Fire Service
Dive into a comprehensive exploration of strategic security planning amid the dynamic landscape of cyber threats. This session will discuss a useful framework of to-do’s for formulating a robust and future-oriented security strategies. By asking the right questions, we'll uncover critical insights and approaches that help your organisation anticipate and mitigate risk, thereby securing a more resilient future in an era of growing uncertainty.
-
12:25
Delivering security of applications and APIs
- Identifying and mitigating API bugs and vulnerabilities
- The importance of doing API threat modelling early in the development process
- Addressing API-related compliance concerns and keeping up with changing security requirements
- Can AI improve Zero Trust of APIs?
-
TRACK B - Panels
-
11:10
PANEL: Evolving your supply chain security practices and advancing its maturity
- How security is changing and how to ideally address it
- The shift-left reality and how the solution didn't work
- The cost implications of a wrong security workflow
- How to make DevSecOps work, strategically
Moderator:
Pablo Reys, Associate Director, DevSecOps National & Cyber Security, Optus
Panellists:
Chris Grisdale, Head of Information Security, hipages Group
Jess Thomas, Assistant Director Cyber Security Outreach, National Office of Cyber Security, Department of Home Affairs
Sam Mackay, Chief Information Security Officer, Department of Customer Service
-
11:45
PANEL: Advancing your cyber maturity through effective GRC
- How to leverage GRC as a strategic framework to drive continuous improvement in your cyber security capabilities and overall resilience
- Successful practices to advanced techniques for aligning GRC initiatives with your business objectives and key risk indicators to maximise the impact of your cyber investments
- Sharing practical approaches to navigating the challenges of implementing cyber into GRC strategy
Moderator:
Lisa Dethridge, Research Fellow, RMIT University
Panellists:
Madhuri Nandi, Head of Security, Till Payments
Siddharth Rajanna, Head of Cyber Security, Bingo Industries
River Nygryn, CISO, HammondCare
Peter Brooks, Head of IT, Billbergia
-
12:20
PANEL: Reinforcing your boundaries with IAM
- What are the key challenges organisations face when implementing identity access management?
- What are your recommendations to navigate these challenges?
- What does a successful approach look like
- How can IAM help safeguard organisations upgrading business operations, modernising aging infrastructure, and protecting network perimeters, and scaling up?
Moderator:Paul dos Santos, Group Head of Information Security, SG Fleet AU
Panellists:
Sebastian Tymoszuk, CISO, Autosports Group
Ilya Polyakov, Head of Identity Management, NSW Department of Planning, housing and Infrastructure
Enrico Conte, CISO, IMB Bank
-
12:50
Lunch
-
13:50
PANEL: Overcoming common Incident Management issues
- Importance of having a team who’s well-prepared and well-rehearsed during incidents to go through crisis
- Reactive Incident response vs Proactive Incident response – how well organisation manage that and how well those tasks are defined and segregated among defensive teams
- How much can we trust AI in the incident response capability? What place do AI and automation have in incident response – is it possible to embed it to a place where you can trust them?
- Taking the communication component seriously – strategies to prepare and prevent reputational losses because of cyber incidents
Moderator:
Edwin Kwan, Head of Cyber Security
Panellists:
Siddharth Rajanna, Head of Cyber Security, Bingo Industries
Jayden Le, Global Head of IT & Security, Zoomo
Simona Dimovski, Technology & Security Expert
-
14:20
ACSC Insights: The Impact of Cyber-Attacks and the Path Forward
Daniel Tripovich - Assistant Director General Incident Management - ASD
-
14:45
New CISO: A toolkit for your first 90 days
Harsh Rasik Busa - CISO - Avant Mutual
In the ever-evolving landscape of cybersecurity, the path to leadership is often as unpredictable as the threats we face. In this presentation, we’ll explore successful ways to becoming an effective leader in a critical domain. Attendees will gain a deeper understanding of the strategic and operational adjustments required, the importance of rapid learning and adaptation, and the value of leveraging diverse experiences to build a resilient security posture.
-
15:10
NETWORKING BREAK
-
15:40
Comprehensive Ransomware Defense: Safeguarding Business Continuity
Shalbin Samuel - Head of Cybersecurity - Intesa Sanpaolo
Ransomware strategies because of the growing threat and potentially devastating consequences of attacks. With ransomware incidents increasing in frequency and cost, businesses aim to protect their valuable data, maintain operational continuity, avoid financial losses, and safeguard their reputation by implementing comprehensive prevention, detection, and response measures
-
16:05
The aftermath: Learning lessons from cyber-attacks and breaches
Alexander Moskvin - CISO - Steadfast Group
Join us as we'll dissect a real-life cybersecurity breach, revealing the vulnerabilities exploited and the cascading consequences. We'll explore the attacker's methods, the organisation's response, and the aftermath. Most importantly, we'll extract crucial lessons to fortify our defenses and create a more resilient cybersecurity posture for the future.
-
16:30
Close of CISO Sydney 2025
Not Found
-
Main Conference Day One
-
07:15
VIP Breakfast – Invite only
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
09:00
Welcome from Corinium and the Chairperson
Kevin Fleming - Chief Technology Officer - ExperstDirect
-
09:15
Keynote: Leveraging cybersecurity as a business growth enabler
Wouter Veugelen - Former CISO - Santos
-
09:40
Top Cloud Threats in 2023
Matt Preswick - APAC Solutions Engineer - Wiz
Cloud adoption is expanding rapidly, and with that expansion comes new complexities. The speed of growth and change in the cloud creates an ever-changing threat landscape. Wiz Research is at the forefront of the cloud's threat landscape and is behind the discovery of vulnerabilities like ChaosDB, ExtraReplica, AttachMe and OMIGOD. In this session, we will cover the major cloud threats recently seen by the Wiz Research team which includes supply chain risks, data exposure, API security threats, and attack patterns used by groups such as LAP$U$. This session summarizes key insights across customers, Wiz and third-party threat research, and numerous other sources
-
10:05
Ministerial Virtual Keynote: Australian Government & Industries partnering up to tackle the talent gap through skills and training
The Hon. Brendan O’Connor - Minister for Skills and Training - Australian Government
-
09:50
How Deep Learning is Unlocking a $362B Value Creation Opportunity in Financial Services
Sergio Rego - AI Customer Engineer - SambaNova Systems
In the highly competitive age of digital transformation financial service organizations are facing accelerated urgency to improve their customer and employee experience while simultaneously reducing operating costs, and managing risk and compliance.
To meet these competing demands on their business, these organizations are racing to deploy deep learning to achieve a new competitive edge by optimizing their back office operations with intelligent document processing, personalizing their customer experience with cutting edge NLP models, and reducing fraud and risk using state-of-the-art deep learning.
AI is here and delivering new capabilities to help businesses solve large and complicated challenges. Join Bob Gaines to learn what that means for your business and how deep learning is helping organizations:
• Achieve higher compliance, faster and with lower costs • Dramatically improve Customer Experience • Reduce time to value from years to weeks
Sergio Rego is a customer engineer at SambaNova Systems where he helps clients deploy purpose-built, deep learning solutions in weeks rather than years. Sergio started his career in financial services, where he worked in strategy; active and index management; and product design and management. Sergio also served as a senior data scientist and team manager for a system integrator where he helped federal government agencies deploy ML and AI solutions.
-
10:15
NETWORKING BREAK
-
10:50
Keynote: Proactive cybersecurity – stepping up your efforts
Keith Howard - CISO - CommBank
As the severity of scams and frauds increase and cybercrime becomes more sophisticate than ever, staying ahead of the game is critical. During this session, you’ll hear how cybersecurity is “front of mind” for one of Australia’s largest banks by investing in the right skills, creating robust defence and control systems, and employing effective detection and response plans.
-
11:15
Minimising User Exposure to Threats
Tim Bentley - Regional Director APAC - Abnormal Security
Three-quarters of Australian CISOs see human error as their organisation’s biggest cyber vulnerability. What if there was a way to stop rolling the human dice every day?
Learn how organisations can leverage advanced behavioural science and automation for informed and near instantaneous decision-making on what is good and what is bad email. As well as removing the increasing burden that is placed on employees as a last line of defence.
In this session we will discuss:- Account takeover techniques and measures that can be taken to help protect against them
- New insights and controls over protecting against supply chain attacks
- The accuracy of advanced behavioural data science in identifying anomalous behaviour
-
11:40
Inspirational Keynote: Don’t blame the victim
Bradley Busch - CISO - AUB Group
-
12:05
Ransomware, Risk & Recovery - Is Your Hybrid Active Directory Secure from Cyberattacks?
Jacquie Young - VP APAC - Semperis
With the threat of cyber warfare becoming ever more serious, every organisation needs a “this is not a drill” cyber-first recovery plan. If cyberattackers targeted your organisation, the most likely business-crippling scenario would be a direct attack on Active Directory (AD)—the system that authenticates users and grants access to business-critical applications and services. AD has become a prime target for cybercriminals—implicated in 90% of the incidents Mandiant researchers investigate—because it has systemic vulnerabilities and because it gives attackers the means to unleash devastating malware.
The NotPetya attack that crippled Maersk in 2017 was a harbinger of the chaos to come. In this session, we’ll examine the action plan every organisation needs to execute to protect against a business-disrupting cyber incident.
- How long does an incident response take usually and what normally brings down the AD?
- How common is it that the Active Directory is used in a data breach ransomware scenario?
- What does ADFR require to be able to recover AD?
-
12:30
Panel discussion: Harnessing cyber awareness to your company’s advantage
CISOs committed to creating risk awareness and building a cybersecurity driven culture are facing several challenges, from getting senior management buy-in, to implementing organisational change and engaging employees. During this session, you’ll explore:
- What are the biggest challenges when getting buy-in from top management?
- Successful ways of incorporating cybersecurity into the organisation’s risk management strategy
- How to encourage everybody to take ownership of cyber?
- Why leaders must be committed to continually improve their teams’ skills and knowledge in IT and cybersecurity – and how do to this?
Moderator:
Kevin Fleming, Chief Technology Officer, ExperstDirectPanellists:
Frances Bouzo, CISO, Ampol
Anna Aquilina, CISO, UTS
Jo Stewart-Rattray, Chief Security Officer, Silverchain
Grant Lockwood, CISO, Virtus Health
Varun Acharya, CISO, Healthscope
-
13:05
Lunch
-
Track A - PREVENTION, DETECTION & RESPONSE
-
14:15
Creating a robust security strategy
John Morcos - Cyber Security Program Manager -
- How to go about defining your Cyber Security Strategy?
- What metrics should you use to measure progress and success of the strategy?
- What frameworks should you consider when building the Cyber Security Strategy?
- What are example capabilities to consider?
- What does your roadmap look like?
- What budget will you be asking for per year based on the roadmap?
- How do you plan on operating these capabilities?
-
14:40
Why PAM is Essential for the Essential Eight
Scott Hesford - Director of Solutions Engineering, APJ - BeyondTrust
As more organisations look to align to the Essential Eight many are finding significant challenges around the aspects of removing Admin Privileges, Application Control and User Application Hardening. Yet as many organisations are finding, leveraging a modern Privilege Access Management solution can provide significant coverage across the requirements of the Essential Eight and more.
Join Scott Hesford, Director of Solutions Engineering, APJ, BeyondTrust, as he dives into some of the more challenging aspects of the Essential Eight and, bringing first-hand experience, shows you how you can solve many of the challenges you might be facing in adopting the Essential Eight.
By attending this session, you will learn:- How modern PAM helps organisations cover multiple aspects of the Essential Eight
- Where you can leverage the Essential Eight for your zero-trust journey
- Key questions to ask in consideration to Application Control and User Application Hardening
-
15:05
Cyber’s best friend: Have you brought them into the tent?
Jennifer Firbank - Strategy and Influence Principal - Telstra
There’s a cyber superpower out there, but have you discovered them yet? If you’ve discovered them, have you brought them into the tent? When it all goes pear shaped, they’ll be the second call you make (after your boss!) When all is going well, you’ll want to speak to them regularly to drive strong security outcomes. Let me introduce them to you and share the why and how. You’ll want one too!
-
15:30
End-to-End Customer Journeys Optimized for Security and Convenience
Ashley Diffey - Head of APAC & Japan - Ping Identity
Businesses have embraced digital to engage with their customers. As quickly as brands have delivered digital experiences, bad actors have been just as fast in figuring out how to use credential stuffing, account takeover, and other types of attacks to their advantage. Keeping pace in this rapidly evolving threat landscape requires businesses to look for innovative ways to build experiences that optimize both security and convenience. But, ensuring one doesn’t overshadow the other often requires multiple integrations and custom development that adds internal friction and slows down innovation. A customer identity strategy that expands beyond access management, but includes fraud detection and identity verification capabilities that can seamlessly be orchestrated together can eliminate integration challenges and drive innovation. Join this session to learn Ping Identity’s drag-and-drop approach to customer identity that streamlines bringing together all the tools a business needs to rapidly build, test and optimize end-to-end customer journeys.
-
15:55
How to adopt a security by design approach
Ashwani Ram - GM, Cybersecurity, IT Infrastructure and Operations - Chartered Accountants Australia and New Zealand
-
Track B - CLOUD SECURITY
-
14:15
What do you need to know about the Cloud before totally going for it?
Freddie Ghahremani - Data Strategy & Cloud Senior Development Manager - TAL Australia
- How the lack of understanding and false sense of security impacts your cloud journey
- How save your data really is when you move to the cloud?
- What factors you must consider to ensure you are getting a reliable, secure product
- Strategies to trust and rely on your providers with a full, clear picture of what you are getting as part of your contract
-
14:40
Adversarial Hygiene: Security that doesn’t Stink!
Anthony Rees - Senior Sales Engineer - Lacework
Securing the cloud is a never-ending task that becomes more challenging each year as clouds accrue new features and functionality. The same can be said for the ever increasing responsibilities and mandates expected of CISOs, including driving the probability of intrusions, data exfiltration, ransomware, etc., to effectively zero. With new technologies and tools come great opportunities for businesses; however, if they are not used appropriately and securely, they can do more damage than good. In this session we will address the elephant in the room: how can CISO’s do more with less, while ensuring the integrity of their resilience based security architecture, and prepare for enterprise obstacles and opportunities ahead.
-
15:05
SOC Automation – dos and don’ts
Nimesh Mohan - Group Threat and Vulnerability Lead - Coca-Cola Europacific Partners Australia
In a world where the pressure to deliver new and innovative ICT capability is only ever growing, and the threat actors are also increasingly sophisticated and pervasive, how can companies ensure they meet these challenges whilst still ensuring cyber resilience? During this interactive discussion, hear challenges and benefits of SOC Automation, explore experiences and lessons learned, and discuss different ways of improving and driving efficiency of your SOC.
-
15:30
Organisational Considerations for Impending GPDR like Regulations to Cyber, Data Governance and Data Privacy Teams
John Cunningham - Vice President and General Manager APAC - Securiti
With the growth of the digital services industry and AI technologies, data has arguably become one of the most valuable economic resources of the modernized economy. However, it is also becoming increasingly the most regulated and riskiest to handle.
The emergence of the GDPR in Europe, which is based on a set of comprehensive principles and obligations for data controllers, extra-territorial application, and strict enforcement mechanisms has been followed by countries and jurisdictions around the world passing similarly prescriptive data privacy and protection laws all with their own unique requirements.Today more than 200+ countries have passed data privacy and protection laws which keep getting more complex and demanding - countries like New Zealand, Indonesia, and India are now also morphing these regulations into Data Protection and Privacy requirements including for Sensitive Data. Australia is also embarking on its own uplifts to Privacy Laws.
The scope of responsibilities for data controllers under these global data privacy and protection laws are also growing - with many modern
Thus, organizations in APAC are encountering experiences in which they are seeing Data Sovereignty Laws as well as banking regulations around PII and MetaData that require audit and compliance at cloud scale.
We will explore the organizational impacts we are seeing across the region in meeting these challenges.- The key impacts and considerations for organizations who are impacted by the merger of PI and SI into multiple regulations
- Technology is being developed and adopted to help organizations to manage these regulations at scale and where possible autonomously
- An overlap of roles and responsibilities across Policy, Classification, and Protection is occurring and the adoption of cloud and multicloud is accelerating this
-
15:55
Sharpening your Cloud standards and compliance practices
Nancy Wong - IT Audit Manager - Lion
-
16:20
VIP Think Tank
-
16:20-17:20
Cocktail in the Cloud - API Security and Visibility in the Cloud
In a world where the information age is at its zenith, with hundreds of thousands of applications being launched every day, the use and demand for application programming Interfaces (APIs) has increased significantly. Powered by open web technologies, APIs have transformed interdependence and partnerships between various commercial enterprises and sectors, allowing them to extend their offerings through in-app connections. With increased API usage, however, comes with it complications -- a major one being security.
In this session, cyber security experts from Orca Security, Daniel Keidar and Scott van Kalken, will share how the company’s first patented agentless cloud security technology helps security teams identify and address API misconfigurations and security risks across a multi-cloud environment.
Gil Geron, Co-Founder, Orca SecurityDaniel Keidar, Associate Vice President, Orca Security
Scott van Kalken, Senior Systems Engineer, Orca Security
-
16:20
NETWORKING BREAK
-
16:50
Be the Thermostat not a Thermometer
Chirag Joshi - Best Selling Author - 7 rules to Influence Behaviour and win at Cyber Security Awareness, 7 Rules to Become Exceptional at Cyber Security
It's said that smooth seas never make skilled sailors. If you're a cyber security leader, the good news then is that you definitely don't have "smooth seas" to reckon with. The challenging times presented by increasing connectivity, speed of business transformation, evolution of cyber threats and ever rising expectations can and do overwhelm even the best amongst us.
This unique session will focus on providing cyber leaders with tangible, real-world tips to build the right mindset, emotional intelligence and differentiating skills that will allow them to deliver massive value to their organisations and optimise their own well-being. -
17:15
Keynote of Success: Like being challenged? Strategies to report risks to the board
Doug Hammond - CISO - Uniting
-
17:40
Fireside chat: Can CEOs and CISOs work better together & collaborate?
- How can CISOs speak the CEOs’ language?
- What does the board expect from CISOs when evaluating and reporting inherent and evolving risks?
- How can the board support CISOs in conducting a cybersecurity mission & strengthening their posture?
- Working together in mastering the company’s digital governance & risk management practices
- Exploring challenges and opportunities to adopt a secure-by-design approach in the business
Panellists:
Greg Sawyer, CEO, CAUDIT
Walter Kmet, CEO, Macquarie University Hospital
Vasyl Nair, CEO, Mine Super
Faizal Janif, Executive Advisory Board Member, AISA
-
18:05-19:00
Day One Close and CISOs Cocktail Reception & Networking - Continue the conversations in a fun and entertaining way
-
18:30
VIP Executive Dinner
Not Found
-
Main Conference Day Two
-
08:50
Welcome from Corinium and the Chairperson
Jo Stewart-Rattray - Chief Security Officer - Silverchain
-
09:00
Earning the 'O' in your CISO role
Gail Coury - CISO - F5
To be successful, today’s CISO needs to bring more than their security acumen to the table. The role has expanded exponentially to address executive and board concerns, endless business challenges and customer and product confidence. While positive outcomes are the goal, it is critical for CISOs to work with full transparency to protect the business and themselves. In this session Gail will share best practices from her experience negotiating the evolving role of the CISO in an expanding threat landscape.
-
09:25
Keynote: Battling the threat evolution – trends, advice and key considerations for Australian businesses
Stephanie Crowe - First Assistant Director General, Cyber Security Resilience - Australian Cyber Security Centre, Australian Signals Directorate
- How has the threat landscape evolved in Australia?
- How malicious cyber activities are impacting organisations across the country?
- What strategies can organisations adopt to create robust cyber security measures to prevent incidents and exploitations?
- Government, industry, academia and citizens working in collaboration to safeguard our country and communities
-
09:50
Keynote: Implementing successful ransomware protection strategies
Daniela Fernandez - Head of Information Security - PayPal Australia
-
10:15
NETWORKING BREAK
-
11:00
Keynote: Cyber strategy – Creating a secure innovation pathway
Faizal Janif - Executive Advisory Board Member - AISA
-
11:25
Cybercrime as a Service (CaaS): How Criminals are Bypassing MFA, SMS Toll Fraud, and More
Kevin Gosschalk - Founder and CEO - Arkose Labs
Join us to hear how to deter attackers, apply similar new techniques that the world’s biggest companies, like Adobe, Snap, PayPal, are using, and adapt your strategies to deliver measurable cost savings.
During the session, we’ll discuss:
- How criminals are conducting account takeovers and credential stuffing attacks that bypass MFA SMS toll fraud, and more to monetise CISOs’ own security defenses against themselves
- How attackers overcame MFA and how we worked with a top gaming merchant to prevent it
- A tour of the modern areas where adversaries share techniques and learn, the latest networks in play, and other threats, like SMS Toll Fraud and much more.
-
11:50
Keynote: Building a sound and effective cybersecurity program
Nivedita Newar - Head of Cyber Strategy & Governance - UNSW
-
12:15
Mental Health Roundtable
Sam Hewett - Account Director - Wiz
-
12:45
Lunch
-
TRACK A - INTERACTIVE CASE STUDIES
-
13:55
Adopting good cyber-hygiene across your supply chain
Mazino Onibere - Head of Cyber Security, Risk and Compliance - Regis Aged Care
-
14:20
Harnessing asset data to transform your cyber security program
Paul Thomas - Senior Solutions Architect, ANZ - Axonius
Cyber Security Programs are challenged by the sprawl of devices, device types, and the quantity of solutions continues to skyrocket and environments only grow more siloed and complex.
But there’s good news: Asset data can now be harnessed to transform your cyber security program. Today’s “asset intelligence” moves from a spreadsheet approach to an API-driven, rich and always up-to-date view into all assets via integrations of existing solutions, data correlation at scale, and querying capabilities to find and respond to gaps. Join this session to learn how asset intelligence improves security hygiene, allocate resources, accelerate incident responses and remediates gaps. -
14:45
Strengthening your Zero Trust Security Model
Michael Poezyn - Chief Security Officer - Derivco
This session is designed for cybersecurity leaders who are currently implementing Zero Trust architecture models. Join us to hear common challenges and explore ways to overcome them. Key discussion points:
- The evolution of Zero Trust
- What are the key challenges you are trying to overcome
- How to develop a roadmap and implementing specific initiatives to your projects
- Discover effective ways to build a zero-trust security framework
- Identify key components of a zero-trust model to protect the current environment
-
15:10
Applying real-life lessons and advancing your security maturity journey
Richard Williams - CIO - MoneyMe
During this session, we’ll explore various methods utilised in building a stronger, more secure company to prepare and protect against cybercrime. Richard will share his experiences of what has worked and hasn’t worked over the years and how getting certified really helped the organisation maturity journey.
-
TRACK B - EXECUTING STRATEGY
-
13:55
Cyber Awareness ‘Gamification’ for Executives
How will you overcome a cyber-attack on your organisation?
In our rapidly-evolving digital world, cyber skills are critical to ensure reasonable, appropriate and informed business decisions can be made at an executive level.
In less than an hour, you can learn how
We will lead participants through an interactive cyber-attack, which includes ‘live’ news reports and calls for quick responses and decision making. Our user friendly physical boardgame is the centrepiece of the Gamification experience, designed to help participants better understand the cyber security application. The game facilitates open discussion in a fast-paced, fun and memorable environment, an innovative way to introduce cyber security into an organisation’s security awareness training and to complement routine computer-based education.
In a collaborative project, the Cyber Security Cooperative Research Centre (CSCRC), CSIRO’s Data61, Government of Western Australia through the Office of Digital Government, with the support of Edith Cowan University, have created an interactive board game to raise awareness and encourage critical thinking about how to prepare and respond to a ransomware attack.
Facilitators:
Helge Janicke, Research Director, Cyber Security Cooperative Research Centre
Carl Celedin, Project Manager, Cyber Security Cooperative Research Centre
-
14:45
Data Security Predictions: Staying Cyber Resilient in 2023
Nathan Smith - Regional Director Security - Splunk
Join Splunk's Regional Director for Security, as he takes us through cyber predictions wins and losses of 2022 and looks forward into 2023 for Splunk's Data Security predictions. During this presentation you will hear more about ransomware, cyber-crime-as-a-service, Supply chain and Hiring cyber talent. All of this plus a little bit of fun with Open AI
-
15:10
Mastering the skills of effective communication with the board
Marco Figueroa - Senior Manager, Cyber Security Risk & Compliance - Australian Institute of Company Directors
-
15:35
NETWORKING BREAK
-
16:05
Overview of Cyber City - the Cyber Security Learning Experience
Duncan Burck - MD - MCB Business Partners (Cyber City Collaborator)
NSW has added cyber education to school curriculum, and secondary students will learn in ‘smart city sandbox’. The 10-week course was development between NSW Department of Education, Cyber Security NSW, and industry firms including MCB Business Partners and Core Electronics. During this session, you’ll get inspired on how the project came about, and what the profession can expect for 1000s of kids every year doing this course in NSW schools.
-
16:30
Wrap-up Panel: What’s Next?
Jo Stewart-Rattray - CSO - Silverchain
Join our interactive wrap-up discussion to share your key take-aways from CISO Sydney 2023 and hear how your peers will be address their key learnings moving forward.
-
16:55
Closing remarks from the Chair
-
17:00
Close of CISO Sydney 2023
Not Found
-
08:00
REGISTRATION & LIGHT BREAKFAST
-
09:50
How Deep Learning is Unlocking a $362B Value Creation Opportunity in Financial Services
Sergio Rego - AI Customer Engineer - SambaNova Systems
In the highly competitive age of digital transformation financial service organizations are facing accelerated urgency to improve their customer and employee experience while simultaneously reducing operating costs, and managing risk and compliance.
To meet these competing demands on their business, these organizations are racing to deploy deep learning to achieve a new competitive edge by optimizing their back office operations with intelligent document processing, personalizing their customer experience with cutting edge NLP models, and reducing fraud and risk using state-of-the-art deep learning.
AI is here and delivering new capabilities to help businesses solve large and complicated challenges. Join Bob Gaines to learn what that means for your business and how deep learning is helping organizations:
• Achieve higher compliance, faster and with lower costs • Dramatically improve Customer Experience • Reduce time to value from years to weeks
Sergio Rego is a customer engineer at SambaNova Systems where he helps clients deploy purpose-built, deep learning solutions in weeks rather than years. Sergio started his career in financial services, where he worked in strategy; active and index management; and product design and management. Sergio also served as a senior data scientist and team manager for a system integrator where he helped federal government agencies deploy ML and AI solutions.
-
08:00
REGISTRATION & LIGHT BREAKFAST
-
09:50
How Deep Learning is Unlocking a $362B Value Creation Opportunity in Financial Services
Sergio Rego - AI Customer Engineer - SambaNova Systems
In the highly competitive age of digital transformation financial service organizations are facing accelerated urgency to improve their customer and employee experience while simultaneously reducing operating costs, and managing risk and compliance.
To meet these competing demands on their business, these organizations are racing to deploy deep learning to achieve a new competitive edge by optimizing their back office operations with intelligent document processing, personalizing their customer experience with cutting edge NLP models, and reducing fraud and risk using state-of-the-art deep learning.
AI is here and delivering new capabilities to help businesses solve large and complicated challenges. Join Bob Gaines to learn what that means for your business and how deep learning is helping organizations:
• Achieve higher compliance, faster and with lower costs • Dramatically improve Customer Experience • Reduce time to value from years to weeks
Sergio Rego is a customer engineer at SambaNova Systems where he helps clients deploy purpose-built, deep learning solutions in weeks rather than years. Sergio started his career in financial services, where he worked in strategy; active and index management; and product design and management. Sergio also served as a senior data scientist and team manager for a system integrator where he helped federal government agencies deploy ML and AI solutions.
Not Found