Program

14-16 October 2026
Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations
Breakout

Getting ready for the post-quantum cryptography transition - how is it going?

Rajiv Shah
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 208
Building Secure Technology
Post-Quantum Cryptography and Cryptographic Transition Planning

Progress against the ACSC's 2026 post-quantum migration milestone is reviewed, covering education, cryptographic inventory and mitigation priorities.

26101610552208
General
Breakout

Cybercrime revenue streams and money laundering techniques

Alexander Wilczek
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 209
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Four years of research into how cybercriminals launder crypto proceeds through mixers and privacy chains, and the countermeasures that can disrupt it.

26101610552209
General
Breakout

When abuse goes digital: Applying cyber security to domestic and family violence

Emerald Sage
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 210
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Intelligence tradecraft used in cyber security can identify technology-facilitated abuse in domestic violence cases that defy conventional detection models.

26101610552210
General
Breakout

Safeguarding AI through neurodiversity: Responsible leadership for a sustainable cyber workforce

Christine Ferguson
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 211
People, Culture and Workforce
Diversity, Equity and Inclusion

Safeguarding AI-enabled cyber systems depends on who shapes risk decisions, making neurodiversity and inclusive leadership a genuine resilience factor.

26101610552211
General
Breakout

The visibility gap: What security teams miss in modern enterprise environments

Ben Archie
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 212/213
Running Secure Operations
Vulnerability, Exposure and Attack Surface Management

SaaS sprawl, unsanctioned AI and fragmented telemetry mean security teams see only part of their real attack surface, and this session shows where to look.

26101610552212
Intermediate
Breakout

From hallucinations to deepfakes: Four real AI failures and the governance gap behind them

Swapnil Jain
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 216
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

AI features are shipping without clear risk ownership, and this session sets out how ISO 42001 closes the accountability gap teams keep avoiding.

26101610552216
General
Breakout

Securing the agentic frontier: Using DNS AID as a trust foundation for autonomous AI

Tim Hartman
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 218
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

DNS-AID offers a practical, standards-based way to let autonomous AI agents discover and trust each other without handing control to a single private registry.

26101610552218
Intermediate
Breakout

Beyond human insiders: Emerging autonomous AI risks to organisations

Anagi Gamachchi & Ruwan Nagahawatta
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Room 219/220
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Research on incidents including Gemini memory poisoning introduces the Digital Insider framework for governing AI agents that cause harm with legitimate access.

26101610552219
Intermediate
Think Tank

Is our sandstone approach to building a security culture actually accelerating modern day supply chain threats? or mitigating them?

Trevor Lau
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Think Tank 1
Building Secure Technology
Supply Chain, Dependency and Provenance Risk

Ageing assumptions about trusted registries and pre-release reviews are accelerating supply chain risk, and only verified, signed provenance closes the gap.

26101610553010
Intermediate
Think Tank

Refactoring the law - Why ignoring legal requirements turns in a technical debt

Kate Basta
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Think Tank 2
Law, Policy and Global Power
Cyber Law, Regulation and Compliance

Treating privacy and legal requirements as blockers rather than embedding them in user stories quietly builds technical debt that surfaces later.

26101610553020
Intermediate
Think Tank

From compliance to conviction — Leading cyber security as a business imperative

Asaf Ahmad
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Think Tank 3
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

A new governance and accountability model shifts cyber security ownership onto business leaders, embedding it as a core business management process.

26101610553030
Intermediate
Think Tank

Facial recognition technology and privacy law in Australia: lessons from the Bunnings decision

Nicholas Blackmore
Fri
 
16 Oct
10:55 am
 - 
11:35 am
Think Tank 4
Law, Policy and Global Power
Privacy, Surveillance and Civil Liberties

The Bunnings tribunal ruling sets the first Australian benchmark for facial recognition technology, outlining what organisations must do to deploy it lawfully.

26101610553040
Intermediate
Workshop

Qbits in the mirror are closer than they appear

Kelly Robertson & Lloyd Peacock
Fri
 
16 Oct
10:55 am
 - 
12:25 pm
Workshop Room 1 - Room 111
Building Secure Technology
Post-Quantum Cryptography and Cryptographic Transition Planning

Using the military SMEAC planning framework, this workshop turns Australia's 2030 post-quantum cryptography deadline into a one-page operational order.

26101610555010
General
Workshop

Before you commit: The art and science of cyber decision‑making

Emily Holyoake & Keryn McMartin
Fri
 
16 Oct
10:55 am
 - 
12:25 pm
Workshop Room 2 - Room 109
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

A device-free, hands-on workshop uses drawing and collage to build the bias-recognition and evidence-based reasoning skills that AI can't replace.

26101610555020
General
Workshop

How to prepare for an IRAP assessment

Shane Moffitt & Charles Wale
Fri
 
16 Oct
10:55 am
 - 
12:25 pm
Workshop Room 3 - Room 110
Leadership, Governance and Accountability
Board Oversight, Assurance and Risk Appetite

Defining system boundaries, building a defensible evidence package, and managing the assessor relationship are the keys to a smooth IRAP assessment.

26101610555030
Intermediate
Panel

The risks boards should know about AI… but don’t

Christopher Hamilton, Leah Mooney & David Rudduck
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Melbourne Room 1
Leadership, Governance and Accountability
Board Oversight, Assurance and Risk Appetite

Treating AI as one monolithic risk category leads boards to apply generic controls that miss how differently AI systems actually behave, fail and expose data.

26101611451010
Intermediate
Panel

Running security programs on the smell of an oily rag

Craig Ford, Maryam Shoraka, Peter Gigengack & Dan Goldberg
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Melbourne Room 2
Leadership, Governance and Accountability
Aligning Cyber Investment to Organisational Outcomes

Breaches often exploit small, preventable gaps created by limited capacity and unrealistic coverage expectations, not more advanced adversaries.

26101611451020
General
Think Tank

LLM-driven autonomous and process aware industrial control system threat detection

Zubair Baig & Naeem Syed
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 103
Building Secure Technology
Autonomous and AI-Enabled Systems Security

A multi-agent framework combining graph theory and large language models helps SOC analysts reason about physical dependencies when detecting ICS threats.

26101611452103
General
Breakout

The Essential Eight and software supply chain attacks: What fits, what fails, and what is missing

Gowri Ramachandran
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 104
Building Secure Technology
Supply Chain, Dependency and Provenance Risk

Testing the Essential Eight against SolarWinds, XZ Utils and a real malicious package shows it covers barely half of a modern supply chain attack surface.

26101611452104
General
Breakout

The human factor - An aviation lense on cyber security

Matt Berry & Kathleen Cowan
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 105
People, Culture and Workforce
Human Risk, Judgement and Decision-Making Under Pressure

An airline captain and cyber practitioners apply aviation safety models, including Swiss Cheese and SHELL, to redesign security around real human performance.

26101611452105
General
Panel

Age-identification-gate honeypot: Why 2026 compliance is a hacker's best friend

Nicholas Commins, Melissa Clare & Simone Herbert-Lowe
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 203
Law, Policy and Global Power
Cyber Law, Regulation and Compliance

Age-verification and AML/CTF rules force mass collection of biometric and identity data. A legal and technical panel asks who is liable for these honeypots.

26101611452203
General
Breakout

You’re fired! (not quite) - How to thrive in a security operations career in the age of AI

Bahar Fard & E-Yang Tang
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 204
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

AI is transforming SOAR and SIEM workflows, and this session shows how tier one and two analysts can move up the value chain rather than lose their roles.

26101611452204
Intermediate
Breakout

DPRK cybercrime vs Australia’s sovereign security roadmap to 2030 : The dual threat: A nation-state with a P&L

Mick McCluney
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 207
Law, Policy and Global Power
National Security, Geopolitics and Cyber Conflict

North Korean state-linked actors combine espionage with large-scale cryptocurrency theft, and Australia's 2030 security plan must defend against both.

26101611452207
General
Breakout

Cryptography in 2026: Moving from curves to lattices (and the engineering challenges)

Trill White
Fri
 
16 Oct
11:45 am
 - 
12:25 pm
Room 208
Building Secure Technology
Post-Quantum Cryptography and Cryptographic Transition Planning

ML-KEM keys are far larger than the ECC keys engineers optimised for, and this session covers the real handshake latency and hybrid deployment trade-offs.

26101611452208
Intermediate

Secure your place at cybercon 2026

Register now and save! Discount ends Wednesday 30 September 2026.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on