Main Program

14-16 October 2026 | Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations
Knowledge Hub

Security in the AI Era: Cybersecurity Through the Eyes of the Attacker & Defender

Presented by 
CrowdStrike
Thu
 
15 Oct
11:45 am
 - 
12:05 pm
Exhibition Hall

Threat actors have moved from early monetisation schemes to AI-driven operations, and the response side has to modernise to keep pace.

26101511451030
Breakout

AI on Kubernetes is a hidden attack surface

Rob Kenefeck
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 103
Building Secure Technology
Autonomous and AI-Enabled Systems Security

Hands-on findings on GPU container escapes, model-weight side channels, and agent trust failures that traditional cloud native tooling misses entirely.

26101511452103
Intermediate
Breakout

The digital detective: How an internal OSINT challenge sparked organisation-wide engagement

Ben Cooper
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 105
People, Culture and Workforce
Security Culture and Behavioural Change

An internal OSINT challenge covering 94 tasks showed staff across a power network how everyday online activity can expose far more than they realise.

26101511452105
General
Breakout

From outreach to early career: What works in building sustainable cyber security pathways

Mary George & Leanne Ngo
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 203
People, Culture and Workforce
Workforce Pathways, Skills and Career Sustainability

National research across school outreach, university and workforce entry reveals a pathway continuity problem, not a talent shortage, and how to fix it.

26101511452203
General
Breakout

Stopping the tank: Centre of gravity analysis for cyber threat prioritisation

Alexander Gould & Yury Sergeev
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 204
Leadership, Governance and Accountability
Aligning Cyber Investment to Organisational Outcomes

Borrowed from military doctrine, centre of gravity analysis identifies the one dependency an attack would need to disrupt, making prioritisation defensible.

26101511452204
Intermediate
Breakout

Cyber warfare: Uncomfortable truths about cyber munitions from the first quarter of the 21st century

Elliot Dellys
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 207
Law, Policy and Global Power
National Security, Geopolitics and Cyber Conflict

From Stuxnet to NotPetya to a 2026 wiper attack on Stryker, this session tracks how state-built cyber weapons keep spilling over onto ordinary enterprises.

26101511452207
General
Breakout

When code replaces blockades: Cyber attacks and the disruption of global trade

Anthony Kumar & Victor Villate Coiduras
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 208
Law, Policy and Global Power
National Security, Geopolitics and Cyber Conflict

As Australian ports automate, cyber operations can create virtual chokepoints that disrupt trade flows, turning digital systems into national security risks.

26101511452208
General
Breakout

The zero budget SOC. Using git, markdown and plain text to stop overthinking playbooks

Jeremy Kerwin
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 209
Running Secure Operations
Security Operations Centres and Continuous Monitoring

Storing SOC playbooks as version-controlled markdown in git preserves institutional knowledge and keeps procedures maintainable without buying another platform.

26101511452209
General
Breakout

Engineering our way out of tool fatigue, together

Peter Gigengack
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 210
Running Secure Operations
Automation, Orchestration and Operational Resilience

GRC engineering applies automation and systems thinking to cut through tool sprawl, building workflows that continuously validate real security risk.

26101511452210
Intermediate
Breakout

One mistake away: The ransomware threat facing Australian organisations

Richard Grainger & Nick Thanos
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 211
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Real ransomware engagements show attackers are typically inside for weeks before systems lock up, and by then the data is already gone.

26101511452211
Intermediate
Breakout

From fake logins to live hijacking: How phishing targeting LastPass customers has evolved

Michael Kosak & Stephanie Schneider
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 212/213
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Threat intelligence findings trace how one phishing campaign evolved from simple lures to real-time credential and session token harvesting using AI.

26101511452212
Intermediate
Breakout

Hiding in plain sight: The shadow AI crisis nobody wants to own

Michael Fitzgerald
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 216
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Employees are feeding sensitive data into unauthorised AI tools daily, and this session argues Shadow AI is a governance failure needing practical controls.

26101511452216
General
Breakout

Words are the new weapons

Alexandra Gada
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 217
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

Simple natural-language prompts can bypass expensive AI security controls, and this session maps roughly 200 documented techniques for manipulating agents.

26101511452217
General
Breakout

Browser extensions: Will you ever look at them the same again?

Matthew Westwood-Hill
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 218
Hacking, Red Teaming
Initial Access and Exploitation

A working proof-of-concept extension with minimal declared permissions exfiltrates page content undetected, exposing weaknesses in store review trust.

26101511452218
Intermediate
Breakout

Safety not guaranteed: What ransomware victims have in common with 1970s construction workers

Craig Martin
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Room 219/220
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Hundreds of ransomware incident responses show the same preventable causes each time, proving the failure is now governance, not technology.

26101511452219
Intermediate
Think Tank

Agentic AI at the edge: The security frontier worth owning

Vriti Magee
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Think Tank 1
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

Autonomous AI agents are now running robotics and logistics systems without a human in the loop, and security architecture hasn't caught up.

26101511453010
Advanced
Think Tank

40,000 CVEs and counting: What 60 years of AppSec tells us

Pedram Hayati
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Think Tank 2
Building Secure Technology
Software and Application Security

Sixty years of AppSec history shows which vulnerability problems are structural, which are self-inflicted, and where security investment finally pays off.

26101511453020
General
Think Tank

Piracy-as-Infrastructure: Access, preservation, and resistance in a post-ownership world

Joel Panther
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Think Tank 3
Law, Policy and Global Power
Digital Sovereignty

As licensing replaces ownership across digital media, this session argues piracy has evolved into infrastructure for access and preservation.

26101511453030
General
Think Tank

The price of convenience: How surveillance capitalism turns your life into a product

Hani Arab
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Think Tank 4
Law, Policy and Global Power
Privacy, Surveillance and Civil Liberties

An audit of Australia's top 50 websites found 74% at high privacy risk, showing how surveillance capitalism turns online behaviour into a tradeable asset.

26101511453040
General
Ask an Expert

Ask me about building secure technology and leadership, governance and accountability

Sriram Raghavan
Thu
 
15 Oct
11:45 am
 - 
12:25 pm
Ask an Expert 1

Building secure technology and leadership, governance and accountability sit with ERQI co-founder Sriram Raghavan at 11.45am Thursday in Ask an Expert 1.

26101511454010
Knowledge Hub

Security operations were built for human scale threats. That era is ending.

Presented by 
Zscaler
Thu
 
15 Oct
12:10 pm
 - 
12:30 pm
Exhibition Hall

Analysts chasing alerts gives way to analysts and AI agents investigating together and acting in real time, which is the shift this session describes.

26101512101030

Lunch

Thu
 
15 Oct
12:25 pm
 - 
1:30 pm
Exhibition Hall
Break
26101512251030
Panel

Shadow IT, shadow AI and insider risk: Why controls fail, and culture matters more

Darren Hopkins, Brad Churcher, Stefanie Luhrs & Reece Corbett-Wilkins
Thu
 
15 Oct
1:30 pm
 - 
2:10 pm
Melbourne Room 1
People, Culture and Workforce
Security Culture and Behavioural Change

A cross-disciplinary panel argues shadow IT, shadow AI and insider risk persist not from weak controls but from a gap between expected and actual behaviour.

26101513301010
General
Panel

Vibing your AI governance - a recipe for a breach of director's duties

Emily Bartlett, Nicholas Commins, Melissa Clare & Dimitri Vedeneev
Thu
 
15 Oct
1:30 pm
 - 
2:10 pm
Melbourne Room 2
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Boards that outsource AI governance decisions to consultants may still breach their directors' duties under the Corporations Act, this panel warns.

26101513301020
General

Secure your place at CyberCon 2026

Join thousands of cyber security professionals in Melbourne this October.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on