Program
14-16 October 2026
Melbourne Convention & Exhibition Centre
Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Results 1
Showing1 to 3 of 6
Lunch
Nature knows best: Reimagining security architecture through the lens of biomimicry
Biological systems offer proven resilience patterns that could reshape security architecture beyond perimeter and layered defence thinking.
Homelabs for hackers: Building a cyber range on a student budget
A functional cyber security home lab can be built from free tools and secondhand hardware, then scaled into a genuine red and blue team range.
The movie "Hackers" and the lessons we still haven't learned
Thirty years on, the password habits and social engineering flaws the film Hackers depicted remain unresolved, with lessons for teaching cyber awareness.
AI is ruining our future workforce – So what do we do?
A panel examines whether reliance on AI tooling is quietly eroding the analytical skills the next generation of security professionals will need.
Let's talk about the c-word: Why risk professionals aren't using it enough
Vulnerability lists without asset, identity, and exposure context hide the toxic combinations that actually lead to business-ending compromise.
Trusting digital ID in practice: Accreditation, liability and real‑world controls
A practical roadmap for becoming or partnering with an accredited Digital ID provider under Australia's new legislated framework and dual-regulator oversight.
When 970 ships walked into an airport
GPS spoofing disrupted Strait of Hormuz shipping within hours using cheap open-source tools, exposing a threat largely absent from cyber security conversations.
Scamouflage - how fraudsters change their stripes
Five years of scam data reveal how fraud tactics, channels and targeted credentials have shifted, with detection improving but overall harm continuing to rise.
Behind every cybercrime is a supply chain
A real ransomware attack chain traces stolen credentials from an infostealer log through a marketplace sale to full network compromise.
Stop failing the same way: How DFIR findings should shape GRC
DFIR investigations keep surfacing the same root causes, and this session shows how translating findings into risk language stops incidents repeating.
The cyber threat intelligence assumptions adversary AI is already breaking
Documented 2025 cases show adversaries rewriting malware, mass-generating phishing lures and hijacking defenders' own AI tools, breaking key CTI assumptions.
IRAP 2.0: the IRAP-ening. What does it take to be an assessor?
A ground-level look at how the PSPF, ISM, and ASD interlock explains what it actually takes to qualify and work as a registered IRAP assessor.
Hostile tools aren't a badge of honour: UX for security engineers
Good user experience is a technical requirement for security tooling, not window dressing, and this talk offers low-cost ways to test and improve it.
Zero to compliant: One person, two frameworks, zero burnout; a practitioner's playbook for ISO 27001 and essential eight
One practitioner achieved ISO 27001 and Essential Eight compliance simultaneously with no dedicated team, and this session shares the prioritisation method.
Lost in translation: Why Australian and New Zealand boards are still getting cyber wrong, and what it's costing them
Most Australian and New Zealand cyber failures start in the boardroom, where technical risk language and business priorities still fail to connect.
Terraforming the blast radius: building secure, scalable cloud foundations with policy and automation
Modular infrastructure as code, policy guardrails and approval-gated pipelines shrink the blast radius of cloud mistakes before the first workload ever lands.
CTFs that fight back: Building adaptive and procedural hacking environments for offensive security education
A narrative-driven, procedurally generated CTF platform replaces static challenges with adaptive difficulty so players solve problems, not memorise answers.
Who is Igor Gilmutdinov? Using OSINT to track the tech contact for shell company websites in tax havens
A recurring website contact name led to an OSINT investigation into shell companies and tax havens, showing how public data becomes real intelligence.
Have you been paying attention: A live game show on scams, social engineering and why smart people still get caught
This interactive game show reframes scams as social engineering, testing snap decisions under pressure to reveal the gap between confidence and reality.
Overcoming the fog of more in cyber war: Strategic thinking frameworks for leaders navigating uncertainty in a complex world
A strategic thinking workshop helps cyber leaders act decisively through the fog of excess data, opinions, and urgency rather than waiting for certainty.
Lumify Work Workshop - Chatham House rules: A security governance self-check
Score your organisation's cyber governance maturity live in an anonymous Chatham House workshop, and leave with a reusable framework and boardroom confidence.
Turning IEC 62443 into action: A practical path to critical infrastructure resilience
A tested sequence turns IEC 62443 from a compliance checklist into a prioritised resilience roadmap spanning governance, asset visibility and incident response.
The code you didn't write - Invisible threats in modern software development
Most of an application's attack surface now comes from dependencies nobody on the team wrote or vetted, and traditional CVE scanning alone can't catch it.
Secure your place at cybercon 2026
Register now and save! Discount ends Wednesday 30 September 2026.







