Main Program

14-16 October 2026 | Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations
Breakout

Co-op mode: Re-engineering supplier risk from procurement blocker to business enabler

Adam Selwood
Wed
 
14 Oct
12:00 pm
 - 
12:40 pm
Room 219/220
Leadership, Governance and Accountability
Aligning Cyber Investment to Organisational Outcomes

Drawing on 2,000 SME engagements, this session reframes supplier risk assessment as a partnership model rather than a gate that locks smaller vendors out.

26101412002219
Intermediate
Think Tank

Architecting against fraud: How digitizing credentials helps post-breach

Dale Bowie
Wed
 
14 Oct
12:00 pm
 - 
12:40 pm
Think Tank 1
Building Secure Technology
Secure Architecture and System Design

How the mDL digital credential standard's cryptographic key binding stops leaked identity documents being reused for fraud after a breach.

26101412003010
General
Think Tank

21 CFR Part 11 and the compliance imperative for Australian biomedical businesses

Aiden Alp
Wed
 
14 Oct
12:00 pm
 - 
12:40 pm
Think Tank 2
Law, Policy and Global Power
Cyber Law, Regulation and Compliance

A real GAMP 5 assessment of a SharePoint QMS shows Australian biomedical manufacturers what FDA 21 CFR Part 11 demands before entering the US market.

26101412003020
General
Think Tank

Your security paradigm is shaping your incident response - and you don’t know it

Hani Arab
Wed
 
14 Oct
12:00 pm
 - 
12:40 pm
Think Tank 3
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

PhD research finds that whether organisations adopt a castle-moat or zero trust security paradigm quietly shapes how they actually respond to incidents.

26101412003030
Intermediate
Think Tank

Teaching the future: Integrating cyber security into education

Faraz Khan
Wed
 
14 Oct
12:00 pm
 - 
12:40 pm
Think Tank 4
Law, Policy and Global Power
International Norms, Standards and Cooperation

International research into how leading countries teach cyber security and train teachers offers practical lessons for strengthening Australia's approach.

26101412003040
General
Ask an Expert

Ask me about people, culture and workforce development

Paul Haskell-Dowland
Wed
 
14 Oct
12:00 pm
 - 
12:40 pm
Ask an Expert 1

People, culture and workforce development are the subjects for Professor Paul Haskell-Dowland of Edith Cowan University at 12pm Wednesday in Ask an Expert 1.

26101412004010
Knowledge Hub

What If Isn't Enough: Real-World Verification of Your Microsoft Entra ID Conditional Access

Presented by 
Canberra Cyber Hub
Wed
 
14 Oct
12:25 pm
 - 
12:45 pm
Exhibition Hall

Almost every signal Entra ID Conditional Access trusts is self-reported at sign-in and so can be spoofed, which is what the What If tool cannot show.

26101412251030

Lunch

Wed
 
14 Oct
12:40 pm
 - 
1:40 pm
Exhibition Hall
Break
26101412401030
Breakout

Essentials for Enterprise IT: How we evolved the Essential Eight and lived to tell the tale

Jayden Cooke
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Plenary Theatre
Building Secure Technology
Secure Architecture and System Design

The Essential Eight has been reshaped from prescriptive controls into a principles-based framework, and this session covers the decisions behind it.

26101413401000
General
Knowledge Hub

The Changing Face of Identity: Humans, Machines and AI Agents

Presented by 
Palo Alto Networks
Wed
 
14 Oct
1:40 pm
 - 
2:00 pm
Exhibition Hall

Access and privilege work differently once software and AI agents authenticate on a person's behalf, which puts non-human identities alongside human ones.

26101413401030
Careers Village

Both sides of the screen: What AI in recruitment means for your next application

Kris Rosentreter & Anthony Buccat
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Exhibition Hall

Keeping a CV in your own voice while using AI to tighten it is the main focus, and the talk ends on deepfake fraud in hiring from both sides of the table.

26101413401030
Breakout

Nature knows best: Reimagining security architecture through the lens of biomimicry

Wayne Rodrigues & Daphne Mantzanidis
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 103
Building Secure Technology
Secure Architecture and System Design

Biological systems offer proven resilience patterns that could reshape security architecture beyond perimeter and layered defence thinking.

26101413402103
General
Breakout

Homelabs for hackers: Building a cyber range on a student budget

George Ferres
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 104
Building Secure Technology
Secure Architecture and System Design

A functional cyber security home lab can be built from free tools and secondhand hardware, then scaled into a genuine red and blue team range.

26101413402104
General
Breakout

From attendee to speaker: How to get accepted to speak at a security conference like CyberCon

Bradley Anstis
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 105
People, Culture and Workforce
Workforce Pathways, Skills and Career Sustainability

An insider's guide to submitting a winning conference proposal covers topic selection, abstract writing, and how selection panels evaluate entries.

26101413402105
General
Panel

AI is ruining our future workforce – so what do we do?

Sriram Raghavan, Chris Keune, Rowan Venables, Ivan Wolff & Philip Ngo
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 203
People, Culture and Workforce
Human–Machine Teaming and Skill Displacement Risk

A panel examines whether reliance on AI tooling is quietly eroding the analytical skills the next generation of security professionals will need.

26101413402203
General
Breakout

Let's talk about the c-word: Why risk professionals aren't using it enough

Rodman Ramezanian
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 204
Leadership, Governance and Accountability
Board Oversight, Assurance and Risk Appetite

Vulnerability lists without asset, identity, and exposure context hide the toxic combinations that actually lead to business-ending compromise.

26101413402204
General
Breakout

Trusting digital ID in practice: Accreditation, liability and real‑world controls

Gurvinder Pal Singh
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 207
Law, Policy and Global Power
Cyber Law, Regulation and Compliance

A practical roadmap for becoming or partnering with an accredited Digital ID provider under Australia's new legislated framework and dual-regulator oversight.

26101413402207
Intermediate
Breakout

When 970 ships walked into an airport

Tonee Marqus
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 208
Law, Policy and Global Power
National Security, Geopolitics and Cyber Conflict

GPS spoofing disrupted Strait of Hormuz shipping within hours using cheap open-source tools, exposing a threat largely absent from cyber security conversations.

26101413402208
General
Breakout

Scamouflage - how fraudsters change their stripes

Charlotte Davidson
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 209
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Five years of scam data reveal how fraud tactics, channels and targeted credentials have shifted, with detection improving but overall harm continuing to rise.

26101413402209
General
Breakout

Behind every cybercrime is a supply chain

Sohan Lokula & Christina Macaire
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 210
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

A real ransomware attack chain traces stolen credentials from an infostealer log through a marketplace sale to full network compromise.

26101413402210
General
Breakout

Stop failing the same way: How DFIR findings should shape GRC

Hilary Bea & Alaina Lawson
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 211
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

DFIR investigations keep surfacing the same root causes, and this session shows how translating findings into risk language stops incidents repeating.

26101413402211
General
Breakout

The cyber threat intelligence assumptions adversary AI is already breaking

Alexander Gould & Yury Sergeev
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 212/213
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Documented 2025 cases show adversaries rewriting malware, mass-generating phishing lures and hijacking defenders' own AI tools, breaking key CTI assumptions.

26101413402212
Intermediate
Breakout

IRAP 2.0: The IRAP-ening. What does it take to be an assessor?

Remy Coll
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 216
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

A ground-level look at how the PSPF, ISM, and ASD interlock explains what it actually takes to qualify and work as a registered IRAP assessor.

26101413402216
General
Breakout

Hostile tools aren't a badge of honour: UX for security engineers

Chris Horsley & Lilith La Rose
Wed
 
14 Oct
1:40 pm
 - 
2:20 pm
Room 217
Hacking, Red Teaming
Tool Development, Bug Bounty and Vulnerability Research

Good user experience is a technical requirement for security tooling, not window dressing, and this talk offers low-cost ways to test and improve it.

26101413402217
General

Secure your place at CyberCon 2026

Join thousands of cyber security professionals in Melbourne this October.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on