
CISO ANZ Series - February-Edition 2023
The road ahead for the CISO in 2023
Crown Hotels, Sydney
Hosted by Factor
- 500 attendees
- 27000 hours
Overview
High profile cyber-attacks on two prominent organisations in Australia last year brought into focus the financial and reputational damage that hackers can do to even the most prepared enterprises.
More than ever, CEOs and their boards need guidance from their senior cyber team around the risks that their organisations face and how they will deal with an inevitable attack.
Cyber risks will be even greater in 2023 and organisations that still view cyber security as an IT, not a business issue and fail to make the required investments in securing their infrastructure and providing the education that their staff need to stay safe are at a higher risk
Join CISO Sit-Down in February as we explore:
- How the threat landscape has evolved this year and the key risks enterprises face in 2023.
- Case study examples of cyber security approaches that focus on giving users and customers peace of mind.
- Using the ‘value-at-risk’ methodology to help quantify cyber risk in language that the CEO and executive board members can understand.
- How a ‘zero-trust’ approach helps to ensure cyber resilience across all business units.
What to expect
- In-person attendees 150+
- Practitioner : Vendor 20:1
- Speakers 20+
- 20+ Sessons Full day program
- In-deep Interactions 1:1
What we will cover
- Speaking the board's language Quantifying cyber risk in language that the CEO and executive board members can understand.
- Transparency and privacy What customer-centric cyber security looks like and how to deploy it across your organisation.
- Managing risk How to manage cyber risk across your entire supply chain and keep disruptions to a minimum.
- Zero trust approach An approach that ensures resilience across all business units.
Agenda
- Registration & welcome coffee(CISO Sit-Down)
- Welcome address & introduction(CISO Sit-Down)
- Data Integrity: From speed dating to lifelong partnership - Precisely(CISO Sit-Down) Governance has little to do with governance…it’s about delivering and demonstrating value. It’s one thing for your colleagues to intellectually believe in the value of data, good data, and governed data, but it’s another thing entirely to have them emotionally engaged and excited to be involved. Shaun will share his thoughts and experience on approaches to win over reluctant leaders and business teams and describe the key components of successful programs.
- Australian tech leaders discuss their plans for 2023(CISO Sit-Down) The past three years have been tough for technology leaders. In 2020, tech teams scrambled to support workers forced out of the office environment and into their homes due to the pandemic, some organisations put the brakes on their transformation plans due to economic uncertainty while others delivered tech projects with more urgency than ever before. Join Sit-Down’s Director of Research & Production, Byron Connolly, as he chats to three technology, data, and cyber leaders about their technology objectives for 2023. Panelists will discuss: The technology and business lessons they have learned over the past few years and how they will apply those learnings in 2023. The technology and digital projects their teams will be working on this year and what is driving these initiatives. Their plans to deal with important issues such as the ongoing technology skills shortage, cost pressures across their organisations and increasing cyber threats.
- Executing a cost-effective data & AI strategy in a bear market - Datiku(CISO Sit-Down) A bear in the wild swipes its paws in a downward motion to claim its prey. With the current downturn, how do we make the most of the economic conditions? This presentation provides three approaches for overcoming implementation risks when advancing an AI strategy in a bearish environment. Bringing our experience working on the front lines of global enterprise AI initiatives, Colleen will explore cost-reduction use cases and identify best practices for optimising data and AI resources.
- Morning tea and networking break(CISO Sit-Down)
- Benchmark Your Third-party Sensitive Content Communications Maturity Level(CISO Sit-Down) Digital transformation is accelerating sharing and transfer of sensitive content to third parties across all industry sectors. Nearly all of this data is regulated and protected by governmental and industry standards. In addition to a cyber-threat landscape that is growing in complexity and maliciousness, maturity of governance and security tracking and controls directly translates into risk. This presentation explores key findings from a new cross-industry global survey focused on third-party sensitive content communications and spells out key takeaways that will help attendees improve their risk posture as it relates to compliance and security.
- The cyber threat landscape in 2023(CISO Sit-Down) Jihad Zein, Global Head of Governance, Risk and Assurance at Toll Group will discuss how the threat landscape has evolved this year and key risks enterprises are facing in 2023. He will cover how approaches to technology risk have changed over the past 12 months; the recent legislative changes to Australia's Security of Critical Infrastructure Act and Privacy Act and what they mean for enterprises; as well as how organisations can manage cyber risk across their entire supply chains and keep disruptions to a minimum.
- Securing the Software Supply Chain: Tip of Cloud Native Security Iceberg(CISO Sit-Down) Recent data breaches have proven that large organisations continue to struggle with security and that supply chain attacks are on the rise. Executive Order 14028 charges multiple agencies with enhancing cybersecurity through a variety of initiatives related to the security and integrity of the software supply chain underpins the growing demand for enterprises to secure them. Join us in the session for insights into what those software supply chain risks and how some customers have approached and overcome these challenges
- The importance of cyber security literacy and awareness to keep us safe online(CISO Sit-Down) It’s a brutal fact that cyber criminals around the world use social engineering – manipulating people to divulge confidential information – in most of their attacks. What this means is that people are often a weak link that criminals can exploit. Join Sit-Down’s Director of Research & Production, Byron Connolly, as he chats to PayPal Australia’s Head of Information Security, Daniela Fernandez, about rising cyber threats that have a human factor. They will discuss: - The latest cyber threats that involve social engineering as an attack surface. - Why cyber security awareness and literacy are so important and what PayPal is doing to educate its staff and customers about the risks. - Recommended actions that CISO and their teams need to take to increase cyber security awareness inside and outside their organisations. - How the cyber skills shortage is impacting enterprises and what needs to be done to make cyber specialist a desired career, particularly for younger people. - How creating a more diverse cyber workforce can help solve the skills crisis.
- Lunch break & networking(CISO Sit-Down)
- Eliminate friction and improve user experience in the World of Multi-Cloud and Hybrid Working.(CISO Sit-Down) Humans naturally strive to avoid friction in their daily lives, and organisations are no different. We can improve security posture by adopting strategies that minimize friction while still ensuring the protection of sensitive data. Adopting a frictionless strategy that seamlessly integrates security measures into habits, rather than solely relying on strict policies, is more likely to be successful in achieving a secure environment. Join us to discuss friction faced by modern CISOs and how we can help eradicate them. We will highlight: * Challenges with integrating and managing environments across multiple platforms * Quick adoption and transformation into Zero Trust with improved Security Controls * Wow your users with a great experience across your whole application stack
- How the ‘value at risk’ methodology illustrates potential harm from cyber attacks(CISO Sit-Down) The devastating cyber attacks on Optus and Medibank in Australia have many CEOs and their boards losing sleep at night, wondering if their organisations are in the sights of cyber criminals. Understandably, they want to know how to respond to a serious breach when data is stolen, and importantly, how they would recover from significant financial losses and reputational damage. The finance sector uses the ‘value-at-risk’ (VaR) methodology to measure the riskiness of financial entities or portfolios of assets. But what if this model was used to calculate the business risks posed by cyber incidents? Ben Doyle, Chief Information Officer at large defence and aerospace giant, Thales has done just that, creating a scaled-back version of the VaR methodology that helps quantify cyber risk in language that the CEO and executive board members can understand. Ben will highlight: How the methodology enables him to produce a cyber risk analysis for non-technical executives that provides them with more confidence in their decision making (for example, by illustrating risk using numbers and probabilities). How the methodology gives these executives a grounding in cyber risk so they can better plan investments in technology and staff.
- Tale of a cyber breach: Why you might be missing the signs(CISO Sit-Down) Join Aaron Jacobs, a global engineer at Sophos as he tells a compelling story about a recent customer call to the cyber security organisation’s Rapid Response service. The signs that this customer’s network had been compromised by a hacker were there, but the organisation failed to see them. Believe it or not, during more than 85 percent of incident response calls taken by Sophos last year, it was apparent that the customer did not see that an adversary had breached their network. Jacobs will discuss: Why most cyber teams don’t have time to review logs and alerts from their various ‘point products’ and what needs to be done to rectify this issue. The risks to your organisation if you don’t have around-the-clock visibility of threats to your IT infrastructure. How attacks have changed and the high rates of breaches due to social engineering that have crippled organisations in the past.
- Maintaining your disaster recovery strategy in a tight economy(CISO Sit-Down) Global economic growth is expected to fall this year, driven largely by the impact of the pandemic, the war in Ukraine and high inflation. For many organisational leaders, reining in costs will be high on their list of priorities. CISOs will be under pressure to maintain their incident response and disaster recovery strategies in an economy where cyber security budgets need to be stretched as far as possible. Join Sit-Down’s Director of Research & Production, Byron Connolly, as he asks Toll Group’s Head of Governance, Risk and Assurance, Jihad Zein, and Thales’ Chief Information Security Officer, Ben Doyle, about how companies can protect their environments and maintain their cyber resilience in a tight economy. Panelists will discuss: - How they expect the economic downturn to impact cyber budgets and the conversations they are having with their CEOs and boards around how they will maintain a strong cyber posture in a tight market. - How they maximise the value from their cyber security investments and the role automation technologies will play to save money and augment the capabilities of their cyber staff. - How a potential recession will impact an already very tight market for cyber security specialists who are demanding big salaries.
- End of day and closing remarks by Sit-Down(CISO Sit-Down)
Speakers
Ashwin Sridhar · Chief Data & Technology Officer, Commonwealth Bank Ashwin Sridhar is a technologist at heart with a full toolkit of digital, product, strategic and leadership experience. He has 15+ years’ experience working in the US, UK, APAC and ANZ across both B2C and B2B segments within a range of industries that include publishing, broadcast, sports, e-commerce and real estate, working in both start-ups and mature multinational organisations.
Lu Luc · Chief Data Officer, Westpac Lu Luc is an analytics, decisioning and technology leader. He helps organisations become intelligent businesses. This is possible by rethinking how data and analytics can be combined with decisioning, machine learning and business acumen to create systems that automatically detect, understand and react as customer, external and business events occur.
Oleg Kravets · Global Head of Data and Analytics, TTC (The Travel Corporation) Oleg Kravets CPA is an experienced Data&Analytics leader, Advisory Board member and international keynote speaker. As a Global Head of Data and Analytics at The Travel Corporation (TTC), his goals include creating enterprise D&A vision and strategy, driving Data Science, AI/ML initiatives and delivering Data Management and Analytics platforms. With a background in Data&Analytics, Finance and Commerce, his career expands over several industries including Tourism, Energy and Retail. He helps companies deliver business value and impact through digital innovation and change, create and implement visions and strategies, find and explore new opportunities as well as develop and mentor high-performing teams.Vincent Koc · Head of Data, Hipages Vincent is a commercially focused technologist with a passion for all things data. Vincent brings more than a decade of experience across a range of data-driven disciplines from customer analytics to market research and more recently as the Head of Data for the iconic technology brand hipages. He has a wealth of diverse experience working across the spectrum both client side, agency and consulting for enterprise companies on the ASX 100 and Fortune 500 as well as peak government bodies. Some of the organisations Vincent has driven a range of data-driven projects include Qantas, Telstra, Coles Group, Woolworths, Volkswagen, Expedia, Australian Federal Government, and NSW Government to name a few. As a thought leader, lecturer at MIT and fellow at the Institute of Managers and Leaders Australia, Vincent is sharing, developing and working with industry to embed data into the culture and fabric of organisations.
Kirk Downey · Head of IT AP, CHG-MERIDIAN Group Senior Executive with over 25 years of experience in Management Consulting and Leadership roles. Strategically focused particularly in turnaround and transformational environments. Proven track record of results across industries at scale.
Jihad Zein · Global Head of Governance, Risk and Assurance, Toll Jihad Zein has international experience leading IT roles across both developed and emerging markets.Ben Doyle · Chief information security officer, Thales Australia Ben is an accomplished information security executive with over 20 years of international information security experience. Due to his many years of providing strategic C-level/board advice, he is able to apply technical threats into appropriate business contexts to determine overall risk to organisations. During this time Ben has been required to manage complex environments that requires balancing local and global organisational policies, domestic regulations, national security requirements, export control and international trade control restrictions, and applying the process, people and technology to ensure successful compliance.
Aaron Jacobs · Global Solutions Engineer, MDR, Sophos Aaron Jacobs is a Sophos Global Solutions Engineer, specialising in Managed Detection and Response. With more than two decades of experience in the IT industry, Aaron has delivered a variety of successful projects both with Sophos and as a general manager of a leading Australian MSP. Aaron has enabled a range of organisations to grow in an ever-changing business and threat landscape, utilising his skills as a systems engineer to advise customers on cybersecurity and business continuity. He is an experienced speaker and established thought leader in the MSP space and cybersecurity industry.
Jarryd Pagonis · Strategic Account Director, Darktrace Jarryd is a Strategic Account Director at Darktrace. Based in Melbourne, Jarryd is responsible for educating the market on harnessing the power of Artificial Intelligence in an ever-changing threat landscape. He works closely with CISOs and IT experts to understand their unique security challenges, and how Darktrace can help address these concerns. Prior to Darktrace, Jarryd worked in the IT industry for numerous years, and he holds a Bachelor of Business from Monash University with majors in Strategy and International Business.Daniela Fernandez · Head of Information Security, PayPal Australia With over 18 years' experience in information technology, Daniela Fernandez is a cyber security and analytics leader, who values integrity, diversity of thought, continuous learning, sense of achievement and ensuring a healthy work/life integration. Through the years, Daniela has become an expert in different domains including fraud detection, cyber security, risk management and analytics. Daniela is the Head of Information Security at PayPal Australia where she focuses on making security a business enabler, helping PayPal to achieve their mission to democratise financial services while ensuring that PayPal Australia delivers secure products to customers and meets local regulatory requirements.
Moutasem Khater · Strategic Solutions Engineer - ANZ, Cloudflare Moutasem Khater, the Strategic Solutions Engineer at Cloudflare, is a seasoned cybersecurity professional with 15+ years of experience in the field. He built trusted technical advisor relationships with strategic customers worldwide, has hands-on experience with Zero Trust Framework and SASE-related technologies and is an expert in developing and deploying Internet security solutions. Before joining Cloudflare, Moutasem served as a Cybersecurity Architect at Cisco and led influential SE teams to build regional presences for leading technologies such as Zscaler and FireEye. Moutasem is a passionate advocate for people, the internet, and the frictionless ways to connect them securely.
Liam Dermody · Director of Threat Analysis, Darktrace Liam is a cyber security expert with almost a decade of experience in the broader security landscape. As Director of Threat Analysis, Australia and New Zealand (ANZ), Liam leads a team of analysts who investigate and respond to threats on customer networks. He works with Darktrace’s customers to help them better understand, investigate and remedy anomalous incidents. Prior to joining Darktrace, Liam held multiple positions within the Australian government, and has worked alongside domestic and international partners to detect and defend against malicious actors. He holds a Graduate Certificate in Security, Policing and Intelligence from Charles Sturt University, and has a Bachelor of Psychology from Western Sydney University.
Partners
- Kiteworks Kitework's mission is to empower organizations to effectively manage risk in every send, share, receive and save of sensitive content. To this end, we created Kiteworks a Content Governance, Compliance, and Protection platform. The platform enables customers to unify, track, control and secure sensitive content moving within, into, and out of their organization to reduce risk exposure and ensure regulatory compliance.
- Aqua Security
- Sophos
- Cloudflare
- Darktrace Darktrace's mission is to free the world from cyber disruption. Its AI technology is relied on by over 7,700 customers worldwide to prevent, detect, and respond to cyber-attacks. Headquartered in Cambridge, UK, the company has 2,200 employees and over 30 offices worldwide. Darktrace was named one of TIME magazine’s ‘Most Influential Companies’ for 2021.
More events from this host
- Canva Melbourne Roundtable August 2026, Melbourne
- AI Systems Scale August 2026
- Agentic Brand Control August 2026, The Rocks
- Modern Govt Day September 2026, Canberra
- CTO Day | Melbourne September 2026, Southbank
- Beyond The Data Centre: Building Government At The Edge September 2026, Canberra
- Executive Confidence in Identity and Security September 2026, Chicago
- Secure Scalable Ecosystems September 2026, Sydney