Main Program

14-16 October 2026 | Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations
Breakout

Finding the weak spot: Rethinking how we assess control effectiveness

Jennifer Vu
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 204
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Borrowing Formula 1's shift to proactive failure analysis, this session introduces a method for testing whether security controls hold under pressure.

26101612352204
Intermediate
Breakout

Can cyber regulation keep pace with a fragmented threat environment?

Nicole Henry
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 207
Law, Policy and Global Power
Public Policy, Regulatory Reform and Enforcement

As cyber obligations multiply across jurisdictions, the real risk is regulatory fragmentation diverting effort into coordination rather than resilience.

26101612352207
Intermediate
Breakout

How I learned to stop worrying and build a CBOM - practical steps for quantum resilience

Zoe Thompson
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 208
Building Secure Technology
Post-Quantum Cryptography and Cryptographic Transition Planning

A cryptographic bill of materials is the essential first step toward quantum-resilient architecture, and this session gives a practical blueprint for one.

26101612352208
General
Breakout

When fraud stops looking like fraud: Why detection fails in cross-chain financial crime and what we must do next?

Yasaman Samadi
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 209
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Cross-chain financial crime increasingly mimics legitimate blockchain activity, so detection needs to shift from anomalies to behavioural context.

26101612352209
Intermediate
Breakout

Real-time data breach assessments: Bridging data governance and security logging

Blare Sutton
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 210
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

A practical architecture bridges security logging and data governance so organisations can identify affected individuals fast enough for reporting deadlines.

26101612352210
Intermediate
Breakout

Human still matters: How security culture professionals stay relevant in the age of AI

Daisy Wong & Cheryl Wong
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 211
People, Culture and Workforce
Security Culture and Behavioural Change

Human in the Loop and Human on the Loop are the concepts used to sort security awareness work into what AI can automate and what must stay human-led.

26101612352211
Breakout

When the playbook burns: AI accelerated incidents and the response gap killing Australian organisations

Ashwin Pal & Kaustubh Vazalwar
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 212/213
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

An AI-augmented ransomware attack made a rehearsed incident response plan irrelevant within 90 minutes, exposing gaps regulators now penalise.

26101612352212
Intermediate
Breakout

Who's accountable when AI acts with credentials

Ramon Rodriguez
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 216
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Identity frameworks built for humans fail when AI agents act autonomously with legitimate credentials, and this session maps that accountability gap.

26101612352216
Intermediate
Breakout

Your website has a new front door: Generative AI wants in, and the attackers are already there

Jason Liu & Timothy McIntosh
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 217
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

As generative AI crawlers and agentic browsers surge, websites need a framework to distinguish trustworthy automation from attackers using the same access.

26101612352217
General
Breakout

Experts as a service: Crowd-based forecasting for cyber risk quantification

Samuel Keogh
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 218
Leadership, Governance and Accountability
Board Oversight, Assurance and Risk Appetite

Crowd-based expert forecasting turns distributed security knowledge into a calibrated, dollar-denominated risk signal for assets no scanner can reach.

26101612352218
Intermediate
Breakout

Perception is not assurance: What validated assessments reveal about SME cyber security

Alladean Chidukwani
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Room 219/220
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Multi-year research into validated SME assessments reveals a governance blind spot where self-reported confidence still substitutes for real cyber assurance.

26101612352219
General
Think Tank

Beyond the credential: What Telegram knows about your company that you don’t

Jesse Hoppo
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Think Tank 1
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Infostealer logs expose far more than usernames and passwords, including session cookies and SaaS access most security teams never think to monitor.

26101612353010
General
Think Tank

Compliant, but still exposed: Rethinking OT cyber risk as an architectural problem

Praveen Gauravaram
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Think Tank 2
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Using Colonial Pipeline and Stuxnet as examples, this session shows why OT risk increasingly comes from architecture and dependencies, not missing controls.

26101612353020
General
Think Tank

The first 24 Hours: Checklists, choices and chaos in cyber crisis response

Jesse Pearce
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Think Tank 3
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Well-designed checklists for the first two, eight and twenty-four hours of a cyber incident turn chaotic decision-making into calm, coordinated response.

26101612353030
General
Think Tank

Finding meaning in the signal: Why detection needs adversarial ground truth

Julian Brownlow Davies
Fri
 
16 Oct
12:35 pm
 - 
1:15 pm
Think Tank 4
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Detection engineering should be driven by continuous adversarial simulation as ground truth, closing the gap between telemetry and real assurance.

26101612353040
Intermediate

Lunch

Fri
 
16 Oct
1:15 pm
 - 
2:15 pm
Exhibition Hall
Break
26101613151030

Exhibition Closes

Fri
 
16 Oct
2:00 pm
 - 
2:15 pm
Exhibition Hall
Other
26101614001030
Featured

Anthropic CISO session with Jason Clinton

Jason Clinton
Fri
 
16 Oct
2:15 pm
 - 
2:55 pm
Plenary Theatre

Anthropic Deputy CISO Jason Clinton spent more than a decade at Google, where he led Chrome infrastructure security against advanced persistent threats.

26101614151000

Conference Close with AISA

Fri
 
16 Oct
2:55 pm
 - 
3:05 pm
Plenary Theatre
Other
26101614551000
Keynote

Keynote with Sir Tim Berners-Lee

Sir Tim Berners-Lee
Fri
 
16 Oct
3:05 pm
 - 
4:05 pm
Plenary Theatre

Sir Tim Berners-Lee, founder of the World Wide Web Foundation and co-founder of the Open Data Institute, on where data and privacy are heading online.

26101615051000

Secure your place at CyberCon 2026

Join thousands of cyber security professionals in Melbourne this October.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on