Main Program

14-16 October 2026 | Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations
Breakout

The AI assurance gaps nobody is talking about

Andrew Robinson
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Room 216
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Enterprise AI governance is maturing, but independent assurance for what deployed models and autonomous agents actually do in practice barely exists yet.

26101414302216
General
Breakout

A practical look at whether ChatGPT, Claude, and Gemini are actually useful in a cyber security data breach investigation

Josh Lemon
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Room 217
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

A head-to-head test of leading AI models against real DFIR tasks reveals where each genuinely saves time and where it confidently misleads investigators.

26101414302217
Intermediate
Breakout

The AI data centre, securing the physical foundation of the Australian AI boom

Martin Barnier
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Room 218
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Australia's AI data centre boom creates critical infrastructure risk most cyber security conversations still stop short of, from OT convergence to supply chain.

26101414302218
General
Breakout

CMMC 2.0: A strategic governance imperative for Australian defence contractors in the AUKUS era

Bharat Bajaj & Ross Khan
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Room 219/220
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

CMMC 2.0 is now contractually enforceable, and Australian defence contractors relying only on DISP and the Essential Eight face a real compliance gap.

26101414302219
Intermediate
Think Tank

Secure by design doesn't mean secure by default

Jackson Henry
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Think Tank 1
Hacking, Red Teaming
Cloud, Infrastructure and Supply Chain Attacks

A scan of 250 Australian Salesforce Experience Cloud sites found 56% exposing sensitive data, showing SaaS risk sits in configuration, not vendor code.

26101414303010
Intermediate
Think Tank

Tracking third-party data theft across the dark web

Alexander Wilczek
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Think Tank 2
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Dark web research into ransomware groups reveals how stolen data cascades through supply chains, leaving third parties unaware their information was exposed.

26101414303020
General
Think Tank

Cyber awareness isn’t boring - we just designed it that way

Wei Lerr Wong
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Think Tank 3
People, Culture and Workforce
Security Culture and Behavioural Change

Cyber awareness, but make it interesting: what Star Wars, Dora, scams and coffee taught me about engaging people at ANU.

26101414303030
Think Tank

Employment is dead: Why the cyber workforce crisis demands a new model for careers

Josh Drean
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Think Tank 4
People, Culture and Workforce
Workforce Pathways, Skills and Career Sustainability

With over 30,000 cyber roles unfilled, this keynote argues rigid job models are the real barrier and makes the case for skills-based, outcome-driven careers.

26101414303040
Intermediate
Ask an Expert

Ask me about running secure operations or leadership, governance and accountability

Jacqui Kernot
Wed
 
14 Oct
2:30 pm
 - 
3:10 pm
Ask an Expert 1

For running secure operations or leadership, governance and accountability, the expert at 2.30pm Wednesday is Model Security CEO Jacqui Kernot.

26101414304010
Knowledge Hub

Rethinking Security for Agentic AI — From Control to Orchestration

Presented by 
Cyera
Wed
 
14 Oct
2:55 pm
 - 
3:15 pm
Exhibition Hall

Data becomes the control surface once agents hold broad access to identities and business processes, and it converges with outbound actions at machine speed.

26101414551030

Afternoon Tea

Wed
 
14 Oct
3:10 pm
 - 
3:50 pm
Exhibition Hall
Break
26101415101030
Knowledge Hub

Empowered Together: Redefining How Security Operations Teams See, Respond and Prevail

Presented by 
Cyble
Wed
 
14 Oct
3:50 pm
 - 
4:10 pm
Exhibition Hall

Alert triage by hand, with no dark web or attack surface context, is the gap, and the fix offered is a four-level threat intelligence maturity framework.

26101415501030
Breakout

Fighting fire with fire: Securing the AI DevSecOps factory

David Luchi
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 103
Building Secure Technology
Software and Application Security

As AI accelerates code production, this talk maps where it strengthens DevSecOps and where it exposes weak points in trust and review quality.

26101415502103
Intermediate
Breakout

Re-engineering supply chain risk management: From compliance engine to risk-adaptive control

John Hare
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 104
Building Secure Technology
Supply Chain, Dependency and Provenance Risk

Compliance-driven supply chain reviews can mask real service-level exposure, and this session outlines a shift toward risk-adaptive vendor oversight.

26101415502104
Intermediate
Breakout

From classroom to consulting: A student’s first year inside the cyber industry

Jerica Macaraeg
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 105
People, Culture and Workforce
Security Culture and Behavioural Change

A student reflects on the gap between university's technical framing of cyber security and the organisational reality of a first year as a security analyst.

26101415502105
General
Breakout

Understanding and protecting the data you hold: Industry data classification framework

Peter Rosewarne & Paul Tyler
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 106
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

A session on a voluntary, non-regulatory framework whose data security levels label data by risk and handling needs, so protection stays proportionate.

26101415502106
Panel

Where should AI be refused? Human limits, cyber risk, and the boundaries of automation

Pauline Willis, Oliver Guidetti & Timothy Bednall
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 203
Running Secure Operations
Operational Limits and Failure Modes of AI-Assisted Security

Automation in cyber security can erode judgement and obscure accountability, and this panel debates when AI use should be constrained or refused.

26101415502203
General
Breakout

What 7,500 penetration tests tell us about the state of cyber security in Australia & NZ

Liam O'Shannessy
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 204
Leadership, Governance and Accountability
Aligning Cyber Investment to Organisational Outcomes

Three years of penetration testing data across Australia and New Zealand reveal which vulnerabilities are worsening and where security investment pays off.

26101415502204
General
Breakout

Find my... and yours: Exploiting tracker ecosystems to track individuals

Carter Smith
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 207
Law, Policy and Global Power
Privacy, Surveillance and Civil Liberties

Passive Bluetooth tracking data can defeat the rotating identifiers meant to protect privacy, re-identifying devices and reconstructing movement histories.

26101415502207
General
Breakout

The invisible attack surface: Disinformation as the most pressing security threat

Meg Tapia
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 208
Law, Policy and Global Power
National Security, Geopolitics and Cyber Conflict

National survey data shows Australians rate disinformation a bigger threat than foreign military attack, and this briefing sets out what teams should do now.

26101415502208
General
Breakout

Don't be the last to know: Threat intelligence for supply chain defence

Saba Bagheri
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 209
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Third-party breaches are rising fast, and this session sets out a low-cost threat intelligence model for spotting supply chain compromise before it reaches you.

26101415502209
Intermediate
Breakout

Everybody saw the scams. Nobody owned them: Why fake news investment campaigns still slip past brands, platforms and enforcement

Jason Liu
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 210
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Fake news investment scams expose an ownership failure hiding inside a technical problem, and this session shows how brands and regulators can close it.

26101415502210
General
Breakout

Bad cyber crisis decisions: An incident responder’s greatest hits and how to avoid repeating them

Jay Banerji
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 211
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Anonymised DFIR case studies show how delayed escalation and misaligned executive priorities routinely turn a manageable incident into a worse one.

26101415502211
Intermediate
Breakout

Are we secure? Empowering the enterprise through continuous, validated defense

Mayur Kriplani
Wed
 
14 Oct
3:50 pm
 - 
4:30 pm
Room 216
Leadership, Governance and Accountability
Aligning Cyber Investment to Organisational Outcomes

A framework combining continuous security testing with adversary-based risk validation closes the gap between compliant on paper and secure in practice.

26101415502216
Intermediate

Secure your place at CyberCon 2026

Join thousands of cyber security professionals in Melbourne this October.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on