Welcome to the AdelaideSEC presentation hub!
This is your guide to the conversations shaping the conference.
The hub brings together AdelaideSEC presentations in one place helping you plan your day. The drop down menu is designed for you to access the content by clicking on the arrow.
Time: 10:45am - 11:25am
Location: Gilbert Suite
Facilitators: Jakub Zerina, Technical Program Lead, ACS and Monica Millar, Project Manager, AISA
Overview:
Launched in December 2025 as a collaborative industry effort, CyberPath is Australia’s cyber workforce professionalisation pilot. This interactive workshop brings together community voices to shape CyberPath and create the picture of what good looks like in a modern framework. Your insights will directly support CyberPath's broader goal of building and growing cyber capabilities for Australia, and with a diversity and inclusion by design mindset. We will explore how competency can be defined to address real-world cyber threats and how we could craft a recognition framework together that acknowledges diverse talent and pathways. We will also explore the challenges and opportunities in finding and developing talent today. We will talk through the ‘what’s in it for me’ for both the employers and practitioners and what we can reasonably build together to support the needs of both on their CyberPath journey.
Time: 10:45am - 11:25am
Location: Hall C
Stream: Cyber Readiness
Speakers: Ryan Mclaren, COO & Co-founder, Retrospect Labs and Alex Duffy, Cyber Risk & IT Resilience Manager, SA Power Networks
Overview: In this session, Retrospect Labs and SA Power Networks explore how organisations can build effective incident response capabilities through hands-on cyber security exercises.
Speakers will share real-world experience on designing exercise programmes, delivery quality simulations with real threat actor tradecraft and technical analysis and evaluating what effective response really looks like.
Preparedness is key, so come along for a candid perspective on the learnings from realistic (not tokenistic) exercises focused on practical resilience and improving incident response capabilities.
Time: 10:45am - 11:25am
Location: Hall D
Stream: Emerging Themes
Speaker: David Hill, Dept. of State Development, Senior Adviser Services & Technology Exports
Overview:
Weaponising Promotional NFC Merchandise and the Illusion of Implied Trust
Abstract: The hardest thing to control and contain is human behaviour and exploiting a powerful human vulnerability: implied trust is a major threat vector. In the enterprise landscape, employees are extensively trained to recognize digital threats like suspicious phishing emails or unverified links, QR codes. However, when a clean, beautifully branded piece of corporate merchandise is handed over by a smiling representative at a reputable event, our psychological firewalls drop entirely. We trust the physical asset, and by extension, we trust the digital payload it carries.
This presentation delivers a real-world case study on how easily this illusion of trust can be weaponised. While attending a professional conference, the speaker analyzed a standard promotional pen embedded with a passive Near Field Communication (NFC) chip, designed to automatically push the distributing consultant's website to attendees' smartphones. A technical deep-dive into the silicon architecture revealed a critical manufacturing oversight: the vendor had neglected to configure the static lock bits within the chip's Capability Container (CC). Left in an unprotected Read/Write state, the NDEF (NFC Data Exchange Format) records were entirely exposed.
Using free consumer mobile tools on a smartphone, the speaker successfully executed a real-time overwrite, modifying the payload to redirect subsequent taps to the official Australian Cyber Security Centre (ACSC) scam awareness portal. While this specific disclosure was handled safely and educationally, the underlying systemic risk to enterprises is severe. A malicious actor could easily intercept corporate merchandise, rewrite the payloads to point to look-alike domain credential harvesters or zero-click browser exploit chains, and distribute them to targeted high-value users. Furthermore, because native mobile browsers inherently parse NDEF URI records, even tightly managed corporate and government Mobile Device Management (MDM) profiles seamlessly execute these unprompted redirects.
Beyond the technical hardware mechanics, this session will challenge the audience to look closely at the hidden privacy and compliance implications of ubiquitous passive technology. When an NFC chip forces a phone browser to launch without explicit user intent, it triggers a fundamental breakdown of informed consent, leaking device telemetry, IP addresses, and location data.
Finally, the presentation outlines a model for responsible, high-empathy vulnerability disclosure. By framing the discovery as a collaborative supply chain lesson rather than an adversarial security failure, the speaker demonstrates how the local cyber community can build bridges with non-technical stakeholders to secure the hardware supply chain. Attendees will walk away with practical strategies for vendor governance, a deeper understanding of physical-to-digital attack vectors, and a live demonstration of just how easily a simple plastic pen can compromise an endpoint.
Time: 10:45am - 11:25am
Location: Hall A
Stream: Governance, Risk and Compliance
Speaker: Rodman Ramezanian, Senior Federal Solutions Engineer, WIZ/Google
Overview:
A vast majority of enterprise organisations in Australia are being asked to do two things simultaneously: accelerate mission delivery on cloud and AI platforms, while continuously proving those platforms remain secure, resilient, and privacy-preserving.
Most organisations already operate under Authority to Operate (ATO) frameworks - but in a cloud-first world, where infrastructure changes by the minute and AI models evolve by the day, static accreditation is no longer sufficient. The pace and scale of digital transformation have introduced a new class of cyber risk: complex, often hidden interactions between misconfigurations, vulnerabilities, and adversarial exposure that can quietly erode even well-governed environments.
Supply-chain attacks aren’t new - but their scale, frequency, and impact have surged alongside the growth of cloud and open-source ecosystems.
Everyone understands Software Bills of Materials - but in a cloud-native world of ephemeral workloads and rapidly evolving AI systems, we have to ask: what does a complete bill of materials actually look like now?
Continuous Authority to Operate (cATO) is that next step - an assurance model purpose-built for the velocity of cloud and the unpredictability of AI.
This session explores how Australian organisations can move from periodic compliance to continuous trust, leveraging automation, telemetry, and live evidence to make accreditation as dynamic as the environments it governs.
We’ll unpack how software supply chains, AI model provenance, and cloud-native architectures intersect to create both new opportunities, but also new exposure paths. Attendees will learn practical ways to align cyber defence, compliance, and operational assurance into a single, adaptive framework - one that builds resilience into every stage of the mission lifecycle.
This talk offers a pragmatic vision for the future of cyber governance - because when threats evolve continuously, trust and authority must evolve continuously too.
Time: 11:30am - 12:10pm
Location: Hall C
Stream: Cyber Readiness
Speaker: Nicole Henry, Head of Government Affairs ANZ, Fortinet
Overview:
We operate in digital environments where threats move at machine speed, but still rely on human decisions under pressure to hold the line. That mismatch is becoming a primary source of risk.
Cybersecurity is often framed as a technology, governance or workforce problem. In practice, it is increasingly a question of how well organisations make security decisions under pressure. Today’s environments are shaped by automation, AI-enabled threat activity and high-volume detection systems, while still relying on people to interpret, prioritise and act.
Human cognition has not changed, but the environments in which decisions are made have become faster, noisier and more complex. In this context, many of the conditions described as human error are not simply individual failings. They are predictable outcomes of systems and workflows that overwhelm judgement where it matters most.
This session looks at cybersecurity through a cyberpsychology lens, not as an awareness issue, but as an operational design issue. It explores how tooling fragmentation, workflow design and reporting expectations shape the way people interpret risk, distinguish signal from noise, and act under pressure. It also questions the assumption that more visibility and more volume automatically produce better security outcomes.
You can already see the effects in familiar patterns: misconfigurations, missed signals, alert fatigue, burnout and defensive delay. Social engineering and credential compromise continue to dominate initial access, with attackers deliberately exploiting urgency, trust and cognitive overload as paths into otherwise well-defended systems. In that sense, the human element is often the primary attack surface, but not the root cause. Outcomes are shaped by whether systems absorb or amplify that moment of interaction.
The pressure is increasing as expectations around response, reporting and accountability continue to rise. This is increasingly visible in regulatory shifts, including the move toward faster incident reporting, structured escalation and formalised risk management under frameworks such as SOCI and the next phase of the national cyber strategy. There is a growing risk of building systems that are compliant by design, but difficult to operate effectively under pressure. Governance, reporting and assurance settings can unintentionally increase complexity and cognitive burden, degrading the very decision quality they are meant to support.
What does a more resilient human operating environment look like? The session will point to clearer decision rights, better escalation design, and architectures that reduce unnecessary cognitive load. The core argument is simple: cyber resilience now depends not only on controls, but on the quality of decisions organisations are able to make under pressure.
Time: 11:30am - 12:10pm
Location: Hall D
Stream: Emerging Themes
Speaker: Jesse Hoppo, Cyber Security – Senior Lead, Telstra
Overview:
Comprised credentials are the single most common way that an organisation gets breached. The ASD’s ACSC Annual Cyber Threat Report (2024-25) found that 42% of significant cyber incidents involved a compromised account or credentials and called out the ongoing concern of Information Stealing Malware (Infostealers).
While most security teams know the threat, less understand it – or what else is being taken alongside those credentials.
This talk will use hands-on experience leading the analysis of infostealer logs at scale, walking through how the infostealer ecosystem works from infection through to monetisation.
At the core of the argument – most organisations, and many threat intelligence providers, are looking at infostealer data too narrowly. The industry default is to match exposed credentials to a corporate identity provider and call it solved, but an infostealer log contains much more than just usernames and passwords.
From browser-saved credentials across every corporate and private service an employee has used, to session cookies, autofill data, history, and in many cases local files. It’s not just someone has your email login – they also have your SaaS, AI, the personal Jira board your employee plans their work on, and the various other third-party services where your corporate SSO doesn’t apply, the tokens are long-lived, and the blast radius isn’t understood.
I’ll show what an infostealer log looks like, and how we extract intelligence that goes far beyond the credential, along with real examples of the kinds of exposures that you’re not seeing.
The talk will also cover practical recommendations: why password syncing via browser-saved credentials creates risk, how to think about your organisation's exposure through the lens of an attacker browsing a marketplace, and how you might explore monitoring that looks beyond your own domain.
Time: 11:30am - 12:10pm
Location: Hall A
Stream: Governance, Risk and Compliance
Speaker: Richard Smith, Lead Intelligence Analyst, CyberCX
Overview:
A recurring website contact name led to an OSINT investigation into shell companies and tax havens, showing how public data becomes real intelligence.
Time: 1:15pm - 1:55pm
Location: Hall C
Stream: Cyber Readiness
Speaker: John Karabin, Chief Cyber Security Strategist, McGrathNicol
Overview:
Cyber crises are no longer rare, slow-moving technology events. They are fast, public, data-rich emergencies that test leadership, judgement, coordination and endurance. Drawing on lessons from first responders, the military, major Australian cyber breaches and the accelerating impact of artificial intelligence, this session explores how organisations can prepare for the next generation of cyber incidents before they arrive.
In this session, John Karabin, a 30-year cybersecurity veteran and 20 year volunteer firefighter in the NSW RFS will demonstrate how a “first responder and military” mindset can help organisations lead through crisis, recover stronger, and build lasting resilience. This session bridges the worlds of emergency services and cyber defence, revealing shared principles of preparation, rapid response, teamwork, and recovery under pressure. It will discuss how clarity of roles, disciplined coordination, and effective communication are just as critical as technology in managing cyber incidents.
The session will look into what recent breaches have really taught us about preparedness, why technical capability alone is not enough, and how security teams must build the cognitive, operational and organisational resilience needed to operate at AI speed. As attackers use automation, generative AI, identity compromise and rapid exploitation to increase the tempo of attacks, defenders must prepare people to make better decisions under pressure, filter signal from noise, and work as cohesive teams when information is incomplete and stakes are high.
Time: 1:15 pm - 1:55 pm
Location: Hall D
Stream: Emerging Themes
Speaker: Josh Lemon, Chief of DFIR, SoteriaSEC
Overview:
Everyone has an opinion on AI and cybersecurity. Some people think it's going to replace analysts entirely, others think it's just a glorified autocomplete that hallucinates registry keys that don't exist and confidently tells you a process is malicious because it "looks suspicious." The truth, as always, sits somewhere in the middle, and Josh has spent the last couple of years trying to find exactly where that is.
Having previously researched the intersection of AI and Digital Forensics and Incident Response (DFIR), Josh is back with something more practical: a head-to-head look at how today's leading AI models — ChatGPT, Claude, and Gemini — actually perform when you throw real investigative tasks at them. Not marketing slides. Not a demo with carefully curated prompts and a suspiciously clean dataset. Actual cybersecurity investigation work, the kind you do at 11pm when you've got a compromised endpoint, a mountain of logs, and a client who wants answers by morning.
This talk walks through how each model handles a common DFIR scenario, from parsing artefacts and assisting analysts on what to do next or how to protect the victim's systems. You'll see where these tools genuinely save time, where they confidently lead you down the wrong path with the enthusiasm of a golden retriever, and where they flat-out refuse to help because someone somewhere decided your forensic query looked a bit too spicy.
This presentation will give you an honest, practical account of what these tools can and can't do right now, so you can start using them effectively in your investigations, rather than waiting for the industry to figure it out for you.
Time: 1:15 pm - 1:55 pm
Location: Hall A
Stream: Governance, Risk and Compliance
Speaker: Bobby Simmonds, CISO
Overview:
Every framework says the same thing: know your assets first. And in every large, legacy environment — health networks, government agencies, anywhere with decades of accumulated infrastructure, medical devices, and shadow IT — the complete asset register remains permanently six months away. This talk argues the goal itself is wrong. Large legacy networks aren't complicated systems that yield to better cataloguing; they're complex systems, and complete inventory is theoretically impossible, not just hard. The mature alternative is risk-based asset visibility: crown jewels known precisely, the long tail covered by passive discovery and behavioural monitoring, and honest, executive-signed acceptance of the gap. Far from heresy, this is what CIS v8, NIST CSF 2.0, ISO 27001 and the Essential Eight actually ask for once you read past the checkbox. We'll cover a practical three-tier model, why asset management keeps getting conflated with identity and third-party access (and why the worst incidents live at their intersection), and the three documents that turn this from winging it into defensible governance.
Time: 2:00 pm - 2:40 pm
Location: Hall C
Stream: Cyber Readiness
Speaker: Keld Enoka, Director, Lykos Defence
Overview:
Many organisations have an incident response plan, a playbook, and an annual tabletop exercise. Fewer have validated whether their response capability will hold up when evidence is incomplete, decisions are time-sensitive, regulators are asking questions, insurers want proof, and executives need clear options.
This session explores the gap between documented incident response and operationally defensible response. It will examine the practical failure points that often appear during serious incidents: unclear decision authority, missing or inaccessible evidence sources, weak handoffs between technical and non-technical teams, poorly understood escalation paths, and response actions that are difficult to justify after the fact.
Attendees will learn how to pressure-test incident response capability before a real incident exposes the gaps. The session will cover how to map critical evidence sources, test response assumptions, identify decision bottlenecks, and turn tabletop exercises into a defensible readiness improvement process.
The session is vendor agnostic and focused on practical methodology. It is intended for incident responders, security leaders, governance and risk professionals, legal and privacy stakeholders, and executives responsible for cyber resilience, incident response oversight, and post-incident accountability.
Time: 2:00 pm - 2:40 pm
Location: Hall D
Stream: Emerging Themes
Speaker: Michael Puckridge, Lead: Gover & National Security, DTEX Systems
Overview:
Insider risk is widely recognised as one of the most damaging and difficult security challenges facing organisations, yet most programs remain anchored to reactive, event‑driven models borrowed from cyber threat response. This breakout session introduces a refined, insider‑specific kill chain that reframes insider risk as a progressive human and organisational trajectory, rather than a single malicious act or technical breach.
The presentation challenges conventional approaches by demonstrating how insider incidents typically emerge over extended periods through a combination of access conditions, organisational context, psychological stressors, and behavioural change. Drawing on practitioner experience from government and critical infrastructure environments, the speakers present a non‑linear kill chain model that reflects how insider risk actually develops in practice, including feedback loops and missed early‑warning opportunities.
A key focus of the session is the distinction between risk and intent. Participants are guided through the early phases of the kill chain—preconditions, triggers, and behavioural deviation—highlighting why anomalous behaviour should be interpreted as a signal for understanding and support, not immediate suspicion or enforcement. The session emphasises that insider risk is rarely revealed through single events, and that over‑reliance on alert volume often obscures meaningful patterns that only become visible when behaviour is assessed in context.
The latter part of the session concentrates on intervention and decision points. Rather than focusing on detection technologies, the speakers explore where organisations have genuine opportunities to interrupt the trajectory before it results in policy breach or incident. Practical intervention strategies are discussed, including proportionate access adjustments, non‑punitive engagement, and governance‑led escalation, all supported by clear accountability and documentation.
The session concludes by examining the operating models required to sustain an effective insider risk capability. Attendees will learn how mature programs align security, HR, legal, privacy, and executive stakeholders around shared thresholds and decision frameworks, reducing harm while strengthening organisational trust. Participants will leave with a defensible conceptual model and practical insights they can directly apply within their own environments.
Time: 2:00pm - 2:40pm
Location: Hall A
Stream: Governance, Risk and Compliance
Speaker: Sharon Hunneybell, VP of Products, Firstwave
Overview:
At some point in the last 12 months, most organisations quietly acquired a new workforce. They didn't go through HR. They didn't get onboarded. Nobody set their boundaries or checked their access. They're AI agents - and they're already working inside your systems.
McKinsey research shows 62% of organisations are already using or experimenting with AI agents. Gartner predicts 40% of enterprise applications will embed them by end of 2026. Yet Deloitte found only one in five companies has a mature governance model for autonomous AI agents. For most organisations, the governance
conversation is running well behind the reality.
Working at the intersection of cybersecurity, network management and critical infrastructure, Sharon has come to believe that the tools to solve this problem already exist - we simply haven't applied them yet. Organisations govern human workers through a lifecycle: onboarding, authorisation, monitoring, audit, remediation and offboarding. AI agents sit inside the same environments, operate with the same privileges, and carry the same accountability risks. They deserve exactly the same treatment.
In this session, Sharon will walk through a practical six-stage Agent Workforce Lifecycle framework - Onboard, Authorise, Monitor, Audit, Remediate, Offboard - drawing on emerging standards from OWASP, NIST and the Cloud Security Alliance. The framework is designed to be applied regardless of which AI tools or platforms an organisation uses, and gives security and governance leaders something concrete to take back to their teams.
Time: 2:45 pm - 3:25 pm
Location: Hall C
Stream: Cyber Readiness
Speaker: Jai Minton, Sr Manager DE&TH, Huntress
Overview:
This presentation shines a light on recent threats and tradecraft observed by threat actors in the wild. It practically notes real world cases where AI is being leveraged in attacks (for better or worse - sometimes it makes their attack really sloppy), and also how the industry fails to properly use the right language when performing attribution.
Time: 2:45 pm - 3:25 pm
Location: Hall D
Stream: Emerging Themes
Speaker: Fatima Hanif, Cyber Security Consultant, Arup
Overview:
Modern buildings are no longer passive physical spaces: they are complex, interconnected digital ecosystems. From Building Management Systems (BMS) and HVAC controls to CCTV, access control, IoT devices, and smart energy platforms, today’s built environment relies on a wide range of operational technology (OT) systems that are increasingly networked, remotely accessible, and often poorly understood from a cyber security perspective.
While much of the cyber security conversation remains focused on enterprise IT, a significant and growing attack surface exists within the buildings we occupy every day. In many cases, these systems are deployed, integrated, and operated across multiple stakeholders, such as designers, contractors, vendors, and asset operators, creating fragmented ownership, inconsistent security controls, and limited visibility of risk.
This session explores the hidden cyber risks within modern buildings and infrastructure, drawing on real-world project experience across transport, data centres, campuses, and public domain environments. It will unpack how smart building technologies introduce new vulnerabilities, why traditional IT-centric security approaches fall short, and where common gaps emerge during design, delivery, and operation.
The session will also examine the convergence of cyber and physical security, highlighting how systems such as access control and surveillance are increasingly part of the cyber threat landscape. Practical examples will be used to illustrate how unclear ownership, weak requirements, and lack of integration between disciplines can create systemic vulnerabilities.
The presentation will conclude with a set of pragmatic strategies to better identify, manage, and reduce cyber risk in the built environment, including embedding security into design processes, improving cross-disciplinary coordination, and making security requirements more actionable and verifiable.
Attendees will leave with a clearer understanding of the “hidden” cyber landscape within buildings and how to move beyond compliance towards more resilient, security-informed design and operations.
Time: 2:45pm - 3.25pm
Location: Hall A
Stream: Governance, Risk and Compliance
Speaker: Rizwan Mahmood, CEO, Guardware
Overview:
Open standards are transforming how we design and deliver infrastructure. IFC enables interoperability. Common Data Exchange (CDEs) enable collaboration. ISO 19650 enables information management at scale. These are the foundations of modern digital engineering.
But there is a question the industry has not adequately addressed: what happens to a design file after it leaves your organisation?
In a federated project model, a single IFC export or CAD assembly might pass through the principal contractor, three design consultants, a certification authority, a fabricator, and a maintenance contractor. Every handoff is a potential point of exposure. The more interoperable our data becomes, the more organisations have access to it. That is the promise of open standards. It is also their unexamined risk.
This is not a theoretical concern. Construction and infrastructure firms are now among the most targeted sectors globally for cyber attack. Proprietary designs, facility security information, and engineering IP are high-value targets for both criminal actors and state-sponsored espionage. Yet the industry's security conversation remains anchored in perimeter controls, access lists, and CDE permissions, controls that end the moment a file is exported, downloaded, or shared.
This presentation argues that the infrastructure sector needs a different model: one where the protection travels with the file, not with the boundary. When a drawing, model, or specification is encrypted at creation and remains encrypted wherever it moves, the data itself becomes the perimeter. Access can be revoked. Usage can be logged. Proof of custody can be demonstrated. The design file remains protected even if it is exfiltrated, leaked, or mishandled.
Rizwan will draw on two decades of experience advising engineering and manufacturing clients where cloud-first assumptions break down, where regulatory constraints limit technology adoption, and where the real-world movement of design data across supply chains creates risks that standard security models fail to address. The presentation will be grounded in publicly available research on cyber risk in the construction and infrastructure sector, and will not advocate for any specific product or vendor.
Time: 4:00pm - 5:00pm
Location: Hall D (Plenary)
Speaker: Gus Balbontin
Australian Information Security Association (AISA) Ltd
Level 8, 65 York Street, Sydney NSW 2000 | 02 8076 6012 | ABN: 18 171 935 959
Copyright © 2026 AISA Sec Days All Rights Reserved