Program

14-16 October 2026
Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations

Arrival Coffee

Wed
 
14 Oct
7:30 am
 - 
9:00 am
Plenary Foyer
Break
26101407301005

Registration

Wed
 
14 Oct
7:30 am
 - 
4:30 pm
Exhibition Concourse
Break
26101407301035

Conference Opening and Welcome

Wed
 
14 Oct
9:00 am
 - 
9:30 am
Plenary Theatre
Opening
26101409001000
Keynote

Keynote with Jen Easterly

Jen Easterly
Wed
 
14 Oct
9:30 am
 - 
10:30 am
Plenary Theatre

RSAC chief executive Jen Easterly keynotes CyberCon. A West Point graduate and combat veteran, she helped create U.S. Cyber Command.

26101409301000

Opening of Exhibition & Morning Tea

Wed
 
14 Oct
10:30 am
 - 
11:10 am
Exhibition Hall
Opening
26101410301030
Featured

Featured Speaker with Tracy Hall

Tracy Hall
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Plenary Theatre

A tech marketing executive of over 25 years, Tracy Hall works with PayPal, Bumble and VISA on fraud awareness and advises CyberTrace.

26101411101000
Breakout

Designing systems for resilience in an uncertain world

Sriram Raghavan
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 104
Building Secure Technology
Secure Architecture and System Design

Drawing on major incidents from 2020 to 2025, this talk sets out engineering principles and metrics for systems that withstand and recover from compromise.

26101411102104
Intermediate
Breakout

From attendee to speaker: How to get accepted to speak at a security conference like Cybercon

Bradley Anstis
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 105
People, Culture and Workforce
Workforce Pathways, Skills and Career Sustainability

An insider's guide to submitting a winning conference proposal covers topic selection, abstract writing, and how selection panels evaluate entries.

26101411102105
General
Panel

Under pressure: How human performance shapes cyber security outcomes

Savitri Bevinakoppa, Morshed Chowdhury & Raza Nowrozy
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 203
Leadership, Governance and Accountability
Executive Decision-Making Under Uncertainty

Stress, fatigue and cognitive overload shape security outcomes as much as technical controls, reframing human error as a systemic design problem.

26101411102203
Intermediate
Breakout

Transforming the board in times of uncertainty and threat

Pauline Willis
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 204
Leadership, Governance and Accountability
Board Oversight, Assurance and Risk Appetite

Boards without cyber security expertise cannot properly assess emerging threats, and this session argues for bringing that perspective into governance.

26101411102204
General
Breakout

Litigious by design: Preparing for cyber security litigation before it occurs

Wouter Veugelen & Sophie Bradshaw
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 207
Law, Policy and Global Power
Cyber Law, Regulation and Compliance

Australian breaches increasingly trigger litigation, and building a defensible security program and contracts before an incident occurs limits legal exposure.

26101411102207
General
Breakout

From boots on the ground to cyber mercenaries: lessons from Russia's Wagner Group

Charlotte Morton
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 208
Law, Policy and Global Power
National Security, Geopolitics and Cyber Conflict

Russia's Wagner Group has evolved from mercenary operations into disinformation and offensive cyber capability, raising fresh risks for Australian security.

26101411102208
General
Breakout

The year of agents: Achieving machine-speed defence in the modern SOC

Mandy Andress
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 209
Running Secure Operations
Security Operations Centres and Continuous Monitoring

With AI-driven attacks reaching impact in as little as eleven minutes, this session sets out the architecture needed for autonomous, machine-speed SOC defence.

26101411102209
Intermediate
Breakout

Security by design in practice - How early choices made our SaaS platform easier to build and run

Kyle Winters
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 210
Running Secure Operations
Automation, Orchestration and Operational Resilience

Building a SaaS platform security-first from day one sped up delivery and simplified operations far more than the team building it originally expected.

26101411102210
Intermediate
Breakout

When cyber plans fail: A pre‑mortem approach

Emile Ghadiminejad
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 211
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

A pre-mortem exercise imagines a cyber incident has already occurred, then asks why the response failed, surfacing real gaps in decision-making and governance.

26101411102211
General
Breakout

Thinking like the adversary: Applying cyber counterintelligence to defensive security

Daryl Sheppard
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 212/213
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Applying cyber counterintelligence principles shifts detection from reactive indicators toward understanding adversary intent, targeting and likely adaptation.

26101411102212
Intermediate
Breakout

Building AI governance from the ground up: What actually works in a complex enterprise

Jackie Orchard
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 216
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

The blueprint behind a working AI governance program at a major logistics provider, covering assurance, vendor risk, and what actually broke along the way.

26101411102216
Intermediate
Breakout

MCP: The "USB-C for AI" or the "USB stick for malware"?

Pratik Khasnabis
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 217
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

The Model Context Protocol simplifies connecting AI agents to tools and data, but that same convenience opens dynamic, often unguarded runtime access.

26101411102217
General
Breakout

Umpiring AI decisions: The Decision Review System (DRS) framework for contestable and board-ready security governance

Akhilesh Das
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 218
Leadership, Governance and Accountability
Executive Decision-Making Under Uncertainty

A cricket umpire's decision review framework translates into a governance model for making AI outputs contestable, logged and defensible under audit.

26101411102218
Intermediate
Breakout

When generative AI goes to war: Why ethics theatre, human-in-the-loop myths, and weak governance are failing cyber security today at scale

Timothy McIntosh & Sherry Wu
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Room 219/220
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Ethics statements and human-in-the-loop reviews are not real controls for autonomous AI agents; this session argues for hard runtime limits instead.

26101411102219
General
Think Tank

People, Process, Technology - Who done it? A security architecture investigation

Grace Wright
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Think Tank 1
Building Secure Technology
Secure Architecture and System Design

An interactive whodunit investigation puts attendees in the jury's seat to examine how gaps across people, process, and technology cause real breaches.

26101411103010
Intermediate
Think Tank

How I (my bots) went from developer to hacker in 2 hours

Jun Yamog
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Think Tank 2
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

A developer with no security background used autonomous AI coding agents to place first in a CTF, revealing how agentic tools reshape attacker economics.

26101411103020
Intermediate
Think Tank

Threat Modelling is not an audit: The creative, human work behind real security

Ning Sun
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Think Tank 3
Building Secure Technology
Secure Architecture and System Design

Threat modelling outcomes are bounded by the quality of the conversation in the room, and this session offers techniques for facilitating creative sessions.

26101411103030
Intermediate
Think Tank

Frameworks tell you what to do - Law decides if it’s enough

Biljana Roksandic
Wed
 
14 Oct
11:10 am
 - 
11:50 am
Think Tank 4
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Framework alignment and legal accountability are not the same thing, and incidents get judged against obligations and reasonable steps, not maturity.

26101411103040
Intermediate

Secure your place at cybercon 2026

Register now and save! Discount ends Wednesday 30 September 2026.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on