Program
14-16 October 2026
Melbourne Convention & Exhibition Centre
Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Results 1
Showing1 to 3 of 6
Arrival Coffee
Registration
Conference Opening and Welcome
Keynote with Jen Easterly
RSAC chief executive Jen Easterly keynotes CyberCon. A West Point graduate and combat veteran, she helped create U.S. Cyber Command.
Opening of Exhibition & Morning Tea
Featured Speaker with Tracy Hall
A tech marketing executive of over 25 years, Tracy Hall works with PayPal, Bumble and VISA on fraud awareness and advises CyberTrace.
Designing systems for resilience in an uncertain world
Drawing on major incidents from 2020 to 2025, this talk sets out engineering principles and metrics for systems that withstand and recover from compromise.
From attendee to speaker: How to get accepted to speak at a security conference like Cybercon
An insider's guide to submitting a winning conference proposal covers topic selection, abstract writing, and how selection panels evaluate entries.
Under pressure: How human performance shapes cyber security outcomes
Stress, fatigue and cognitive overload shape security outcomes as much as technical controls, reframing human error as a systemic design problem.
Transforming the board in times of uncertainty and threat
Boards without cyber security expertise cannot properly assess emerging threats, and this session argues for bringing that perspective into governance.
Litigious by design: Preparing for cyber security litigation before it occurs
Australian breaches increasingly trigger litigation, and building a defensible security program and contracts before an incident occurs limits legal exposure.
From boots on the ground to cyber mercenaries: lessons from Russia's Wagner Group
Russia's Wagner Group has evolved from mercenary operations into disinformation and offensive cyber capability, raising fresh risks for Australian security.
The year of agents: Achieving machine-speed defence in the modern SOC
With AI-driven attacks reaching impact in as little as eleven minutes, this session sets out the architecture needed for autonomous, machine-speed SOC defence.
Security by design in practice - How early choices made our SaaS platform easier to build and run
Building a SaaS platform security-first from day one sped up delivery and simplified operations far more than the team building it originally expected.
When cyber plans fail: A pre‑mortem approach
A pre-mortem exercise imagines a cyber incident has already occurred, then asks why the response failed, surfacing real gaps in decision-making and governance.
Thinking like the adversary: Applying cyber counterintelligence to defensive security
Applying cyber counterintelligence principles shifts detection from reactive indicators toward understanding adversary intent, targeting and likely adaptation.
Building AI governance from the ground up: What actually works in a complex enterprise
The blueprint behind a working AI governance program at a major logistics provider, covering assurance, vendor risk, and what actually broke along the way.
MCP: The "USB-C for AI" or the "USB stick for malware"?
The Model Context Protocol simplifies connecting AI agents to tools and data, but that same convenience opens dynamic, often unguarded runtime access.
Umpiring AI decisions: The Decision Review System (DRS) framework for contestable and board-ready security governance
A cricket umpire's decision review framework translates into a governance model for making AI outputs contestable, logged and defensible under audit.
When generative AI goes to war: Why ethics theatre, human-in-the-loop myths, and weak governance are failing cyber security today at scale
Ethics statements and human-in-the-loop reviews are not real controls for autonomous AI agents; this session argues for hard runtime limits instead.
People, Process, Technology - Who done it? A security architecture investigation
An interactive whodunit investigation puts attendees in the jury's seat to examine how gaps across people, process, and technology cause real breaches.
How I (my bots) went from developer to hacker in 2 hours
A developer with no security background used autonomous AI coding agents to place first in a CTF, revealing how agentic tools reshape attacker economics.
Threat Modelling is not an audit: The creative, human work behind real security
Threat modelling outcomes are bounded by the quality of the conversation in the room, and this session offers techniques for facilitating creative sessions.
Frameworks tell you what to do - Law decides if it’s enough
Framework alignment and legal accountability are not the same thing, and incidents get judged against obligations and reasonable steps, not maturity.
Secure your place at cybercon 2026
Register now and save! Discount ends Wednesday 30 September 2026.







