Program

14-16 October 2026
Melbourne Convention & Exhibition Centre

Browse the program and start planning your CyberCon 2026 experience across three days of keynotes, panels, workshops, and more.

Format
Location
Audience Level
Themes & Topics
Building Secure Technology
Hacking, Red Teaming
Law, Policy and Global Power
Leadership, Governance and Accountability
People, Culture and Workforce
Running Secure Operations
Breakout

Intelligence at scale: Engineering the AI-Driven CTI pipeline

Velushomaz & Melissa Egan
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 210
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

A human-in-the-loop AI pipeline turns messy OSINT into structured intelligence, validated data, and automated threat hunts at scale.

26101514202210
Intermediate
Breakout

Everyone has a plan until they get phished

Callum Wilkin
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 211
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Incident response tabletops need real technical friction, log analysis and failed fixes to test decisions under pressure, not a rehearsed script.

26101514202211
General
Breakout

Built to survive: Lessons in cyber resilience from nature’s toughest creature

Brian Odian
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 212/213
Running Secure Operations
Vulnerability, Exposure and Attack Surface Management

What the tardigrade's extreme survival mechanisms suggest about building cyber resilience against AI-accelerated and geopolitically driven threats.

26101514202212
General
Breakout

Your SaaS product just grew an AI attack surface - here's how to govern it

Swapnil Jain
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 216
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

Four documented AI incidents each trace back to missing ISO 42001 controls, and this session maps the specific safeguards that would have reduced their impact.

26101514202216
General
Breakout

Breaking AI systems like an attacker: Practical threat modelling for LLMs

Daryl Sheppard
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 217
Hacking, Red Teaming
AI/ML and Emerging Attack Surfaces

An adversary-led threat modelling approach adapted from PASTA maps how prompt manipulation and dynamic outputs create attack surfaces standard models miss.

26101514202217
Intermediate
Breakout

If this, then breach - AI-Assisted red teaming without malware, infrastructure, or exploits

James Anderson
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 218
Hacking, Red Teaming
Post-Exploitation and Red Team Operations

AI now lets red teamers chain everyday SaaS access and automation into high-impact breaches without deploying malware or touching an endpoint.

26101514202218
General
Breakout

The new cyber security topography: Sovereign risk, AI readiness & the evolving cyber landscape

Peter Soulsby
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Room 219/220
Leadership, Governance and Accountability
Cyber Governance, Ownership and Accountability Models

National briefing findings on sovereign risk and AI readiness show organisations still need to nail identity, access and data governance basics first.

26101514202219
Think Tank

Trusting agents with your secrets: What OpenBao taught us about Agentic Identity

Rob Kenefeck
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Think Tank 1
Building Secure Technology
Identity-Centric Design and Zero-Trust Architectures

A practitioner's account of testing OpenBao as a secrets management foundation for autonomous agents, covering what worked and where it fell short.

26101514203010
Intermediate
Think Tank

What GDPR taught me about power and why Australia needs it / What does privacy feel like

Lina Condon
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Think Tank 2
Law, Policy and Global Power
Privacy, Surveillance and Civil Liberties

Living under GDPR revealed that privacy is fundamentally about power, offering a grounded case for why Australia needs stronger data protection.

26101514203020
General
Think Tank

Domain Zero: Human threat intelligence is cyber's unfinished business

Emily Holyoake
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Think Tank 3
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

Cyber threat intelligence methodology extends to human-motivated threats, showing how structured behavioural indicators can detect social engineering earlier.

26101514203030
General
Think Tank

DMARC can’t see this: Where brand impersonation hides in plain sight

Bradley Anstis
Thu
 
15 Oct
2:20 pm
 - 
3:00 pm
Think Tank 4
Running Secure Operations
Vulnerability, Exposure and Attack Surface Management

Brand impersonation is shifting from email to social platforms, bypassing DMARC entirely, and this session shows how to extend detection beyond the inbox.

26101514203040
Intermediate

Afternoon Tea

Thu
 
15 Oct
3:00 pm
 - 
3:50 pm
Exhibition Hall
Break
26101515001030
Panel

Challenges of governing the ungovernable & security leadership in the age of AI autonomy

Sam Fariborz, Nigel Hedges, Faizal Janif & Sheena Peeters
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Melbourne Room 1
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Security executives share lessons from real AI-driven incidents on governing autonomous agents that already make decisions with minimal human oversight.

26101515501010
Intermediate
Panel

Navigating cyber insurance in uncertain times – Wars, systemic events, AI and beyond

Raymond Loh, Ben Di Marco, Melissa Tan & Anne Hoffmann
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Melbourne Room 2
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Geopolitical instability, systemic events, and AI are reshaping cyber insurance markets, changing how insurers price and assess risk for buyers.

26101515501020
General
Breakout

Same humans, smarter attacker: What three years of AI development has done to security awareness training

Sarah Assaf
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 103
Building Secure Technology
Autonomous and AI-Enabled Systems Security

New research shows AI now runs personalised social engineering attacks as effectively as it once simulated them, testing today's training frameworks.

26101515502103
General
Breakout

Guarding the pipeline: Hardening GitHub actions against supply chain attacks

Pratik Khasnabis
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 104
Building Secure Technology
Supply Chain, Dependency and Provenance Risk

Misconfigured GitHub Actions pipelines are an increasingly attractive supply chain target, and this talk offers practical guidance for hardening CI/CD.

26101515502104
General
Breakout

Phishing isn't an awareness strategy: The behavioural science behind why your human risk program Is broken

Chantelle Ralevska
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 105
People, Culture and Workforce
Security Culture and Behavioural Change

Behavioural science explains why annual training and phishing simulations rarely change behaviour, and what an evidence-based human risk program needs instead.

26101515502105
General
Breakout

Hacked attention: A father–son story of ADHD as a cyber security superpower

Abbas Kudrati & Murtaza Kudrati
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 203
People, Culture and Workforce
Diversity, Equity and Inclusion

A father and son in cyber security share how ADHD traits such as hyperfocus become strengths in threat detection and incident response.

26101515502203
General
Breakout

Human out of the loop: The AI success story nobody is planning for

Pippa Flanagan
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 204
Leadership, Governance and Accountability
Governing Autonomous and AI-Driven Systems

Compensating human workarounds inside operational data pipelines become invisible risk once AI quietly replaces the people who were fixing broken data.

26101515502204
General
Breakout

The front line – Scambaiters – a need to develop a closer relationship with authorities

Chris Peacock & Leslie Baker
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 207
Law, Policy and Global Power
Public Policy, Regulatory Reform and Enforcement

Four years of scambaiting data shows the real intelligence value of disrupting fraudsters, and why closer ties with authorities would help victims more.

26101515502207
General
Breakout

Quantum automation for cyber defence: Moving beyond classical limits in real-time threat response

Robin Doss
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 208
Law, Policy and Global Power
Strategic Competition in AI and Quantum Capability

Quantum computing's ability to process vast data quickly could move cyber defence beyond the limits of classical real-time threat response.

26101515502208
General
Breakout

BTCScamFinder: Catching crypto scam sites before the first victim pays and tracing the criminals behind them

Arvin Ghalansouii
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 209
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

An open-source pipeline flags crypto scam sites within hours of launch and traces stolen funds through a fully auditable evidence chain.

26101515502209
General
Breakout

Better plumbing in security: Bringing pipes to SQL

John Stoner
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 210
Running Secure Operations
Threat Intelligence, Detection and Adversary Behaviour

SQL pipe syntax makes SQL usable for security hunts and detection logic, potentially breaking down the query-language silos between SIEMs and analysts.

26101515502210
General
Breakout

When the victim panics: the missing layer in cyber incident response

Jessica Sears
Thu
 
15 Oct
3:50 pm
 - 
4:30 pm
Room 211
Running Secure Operations
Incident Response, Crisis Coordination and Recovery

Victims under pressure delay reporting, hide evidence and make rash decisions, so response models need to stabilise people before technical response begins.

26101515502211
General

Secure your place at cybercon 2026

Register now and save! Discount ends Wednesday 30 September 2026.

Speaker in a grey suit presenting at a lectern on stage
Woman being interviewed with a Ticker microphone on the expo floor
Audience members smiling and taking photos on their phones during a session
Speaker presenting on stage against a blue and pink backdrop
Attendees wearing CyberCon headphones listening during a session
Panellists seated in white armchairs on stage during a conference discussion
Keynote speaker presenting on stage with a title slide behind him
Speaker addressing the audience with a microphone as a colleague looks on