
CISO ANZ Series - March Edition 2023
The road ahead for the CISO in 2023
The Langham Hotel, Melbourne
Hosted by Factor
- 500 attendees
- 27900 hours
Overview
High profile cyber-attacks on two prominent organisations in Australia last year brought into focus the financial and reputational damage that hackers can do to even the most prepared enterprises.
More than ever, CEOs and their boards need guidance from their senior cyber team around the risks that their organisations face and how they will deal with an inevitable attack.
Cyber risks will be even greater in 2023 and organisations that still view cyber security as an IT, not a business issue and fail to make the required investments in securing their infrastructure and providing the education that their staff need to stay safe are at a higher risk
Join CISO Sit-Down as we explore:
- How the threat landscape has evolved this year and the key risks enterprises face in 2023.
- Case study examples of cyber security approaches that focus on giving users and customers peace of mind.
- Using the ‘value-at-risk’ methodology to help quantify cyber risk in language that the CEO and executive board members can understand.
- How a ‘zero-trust’ approach helps to ensure cyber resilience across all business units.
What to expect
- Speakers 40+
- 30+ Sessions Full day program
- Discovery Meetings 1:1
- In-person Attendees 150+
- Practitioner : Vendor 20:1
What we will cover
- Speaking the board's language Quantifying cyber risk in language that the CEO and executive board members can understand.
- Transparency and privacy What customer-centric cyber security looks like and how to deploy it across your organisation.
- Managing risk How to manage cyber risk across your entire supply chain and keep disruptions to a minimum.
- Zero trust approach An approach that ensures resilience across all business units.
Agenda
- Registration & welcome coffee(CISO Sit-Down)
- Welcome address & introduction by Sit-Down(CISO Sit-Down)
- Benchmark Your Third-party Sensitive Content Communications Maturity Level(CISO Sit-Down) Digital transformation is accelerating sharing and transfer of sensitive content to third parties across all industry sectors. Nearly all of this data is regulated and protected by governmental and industry standards. In addition to a cyber-threat landscape that is growing in complexity and maliciousness, maturity of governance and security tracking and controls directly translates into risk. This presentation explores key findings from a new cross-industry global survey focused on third-party sensitive content communications and spells out key takeaways that will help attendees improve their risk posture as it relates to compliance and security.
- Australian tech leaders discuss their plans for 2023(CISO Sit-Down) The past three years have been tough for technology leaders. In 2020, tech teams scrambled to support workers forced out of the office environment and into their homes due to the pandemic, some organisations put the brakes on their transformation plans due to economic uncertainty while others delivered tech projects with more urgency than ever before. Join Sit-Down’s Director of Research & Production, Byron Connolly, as he chats to three technology, data, and cyber leaders about their technology objectives for 2023. Panelists will discuss: - The technology and business lessons they have learned over the past few years and how they will apply those learnings in 2023. - The technology and digital projects their teams will be working on this year and what is driving these initiatives. - Their plans to deal with important issues such as the ongoing technology skills shortage, cost pressures across their organisations and increasing cyber threats.
- Executing a cost-effective data & AI strategy in a bear market.(CISO Sit-Down) A bear in the wild swipes its paws in a downward motion to claim its prey. With the current downturn, how do we make the most of the economic conditions? This presentation provides three approaches for overcoming implementation risks when advancing an AI strategy in a bearish environment. Bringing our experience working on the front lines of global enterprise AI initiatives, Vicent will explore cost-reduction use cases and identify best practices for optimising data and AI resources.
- Morning tea and networking break(CISO Sit-Down)
- Why Data Security is Essential in Cyber Resilience and Ransomware Recovery(CISO Sit-Down) Organisations are under attack. As organisations have become more digital, cyber attackers have found opportunity in digitisation. Their prize? Your data. With increased vulnerabilities in existing infrastructure and threats penetrating infrastructure security defenses, organisations remain highly vulnerable to cyber attacks. With the rise of the ransomware economy, cyber warfare, and software supply chain attacks, organisations face a growing gap in their ability to secure data and ensure business continuity. Cyber attackers know when they take out your data, they take down your business. In this session we'll look at three pillars to strengthen your security posture and protect your data and your business: Data Resilience Data Observability Data Recovery
- Why it's time to take a fresh look at your data and reconsider what it's worth(CISO Sit-Down) The next time you hire a new employee or change the status of a contractor, do you consider what the information you are collecting is worth? This data may seem innocuous, but it is worth millions to attackers and proper protections must be in place to lock data down and encrypt it to foil attackers. Trevor Goldman, Head of Cyber Assurance at Visy as he discusses the history of data collection, while providing some real-world examples of the dark web and what happens after a data breach. He will also discuss what companies are collecting, asking if they need to collect certain data, and how valuable it is to attackers.
- Rethinking cloud security: Streamlining solutions and minimising risk(CISO Sit-Down) Organisations today are facing numerous attacks on their cloud environments and are implementing multiple solutions to protect themselves. These security measures require a significant allocation of resources, including manual processes and the involvement of developers. The current approach raises questions about whether there is a better solution and whether the status quo will persist. Furthermore, this approach has implications for protecting the software supply chain process.
- Network Security Approaches for a Multi-Cloud, Hybrid IT World(CISO Sit-Down) The hybrid and multi-cloud environment provides significant benefits for enterprises, including functionality, scalability and agility, and specialized deployments. However, hybrid and multi-cloud environments create a host of security challenges for businesses, including misconfiguration, exfiltration of sensitive data, and unauthorized access. Enforcing security control consistently across different cloud and on-premise environments requires first understanding these challenges, then implementing tools and processes to prevent and/or remediate threats.
- Lunch break & networking(CISO Sit-Down)
- Convincing executives to start thinking like their cyber adversaries(CISO Sit-Down) It is understandable that the CEO and executive board members at any organisation would want to kill every cyber threat as quickly as possible and get back to business-as-usual operations. But to be truly effective against cyber criminals, senior decision makers need to start thinking more strategically. Join Chathura Abeydeera, Director, Cyber Security and Incident Response at KPMG, as he discusses why CISOs and their teams must convince top executives to adopt an ‘adversarial mindset.’ This will help them better understand how cyber criminals spend time gaining access to systems and identifying vulnerabilities before they start stealing data. He will provide insights from KPMG’s own experiences in helping key business decision makers to start thinking like their cyber adversaries so they can more effectively deal with inevitable attacks.
- Tale of a cyber breach: Why you might be missing the signs(CISO Sit-Down) Join Aaron Jacobs, a global engineer at Sophos as he tells a compelling story about a recent customer call to the cyber security organisation’s Rapid Response service. The signs that this customer’s network had been compromised by a hacker were there, but the organisation failed to see them. Believe it or not, during more than 85 percent of incident response calls taken by Sophos last year, it was apparent that the customer did not see that an adversary had breached their network. Jacobs will discuss: Why most cyber teams don’t have time to review logs and alerts from their various ‘point products’ and what needs to be done to rectify this issue. The risks to your organisation if you don’t have around-the-clock visibility of threats to your IT infrastructure. How attacks have changed and the high rates of breaches due to social engineering that have crippled organisations in the past.
- Maintaining your disaster recovery strategy in a tight economy(CISO Sit-Down) Global economic growth is expected to fall this year, driven largely by the impact of the pandemic, war in Ukraine and high inflation. For many organisational leaders, reining in costs will be high on their list of priorities. CISOs will be under pressure to maintain their incident response and disaster recovery strategies in an economy where cyber security budgets need to be stretched as far as possible. Join Sit-Down’s Director of Research & Production, Byron Connolly, as he asks leading CISOs about how they will maintain their disaster recovery strategies in a tight economy. Panelists will discuss: - How they expect the economic downturn to impact cyber budgets and the conversations they are having with their CEOs and boards around how they will maintain a strong cyber posture in a tight market. - How they maximise the value from their cyber security investments and the role automation technologies will play to save money and augment the capabilities of their cyber staff. - How a potential recession will impact an already very tight market for cyber security specialists who are demanding big salaries.
- How to lead and communicate with influence(CISO Sit-Down) Join Linda Scott as she deep dives into what it means to be a successful modern c-suite executive. Learn what true leadership is, how to think and behave like a leader, and how to communicate and influence others, so you can achieve your leadership potential.
- End of Day & closing remarks by Sit-Down(CISO Sit-Down)
- Networking drinks(CISO Sit-Down)
Speakers
Aaron Jacobs · Global Solutions Engineer, MDR, Sophos Aaron Jacobs is a Sophos Global Sales Engineer, specialising in Managed Threat Response. With more than two decades experience in the IT industry, Aaron has delivered a variety of successful projects both with Sophos and as a general manager of a leading Australian MSP. Aaron has enabled a range of organisations to grow in an ever-changing business and threat landscape, utilising his skills as a systems engineer to advise customers on cybersecurity and business continuity. He is an experienced speaker and established thought leader in the MSP space and cybersecurity industry.
Eilon Elhadad · General Manager, Aqua Security Eilon is General Manager, Software Supply Chain Security at Aqua Security. He was formerly CEO and Co-Founder of Argon Security, a company acquired by Aqua in 2021 considered one of the largest and fastest acquisitions in the ecosystem. Argon was the industry's first dedicated solution to protect the full lifecycle of the software supply chain. Prior to founding Argon, he served in the elite 8200 Unit in the Israeli Intelligence Corps where he led development projects in defensive cybersecurity
Alex Apt · Solutions Architect, Tufin
Vigyan Jain · Data Management and Data Security Solutions Architect APJ, Rubrik Vigyan Jain is a Data Management and Data Security Solutions Architect for Asia Pacific and Japan at Rubrik. He has over 14 years of leadership experience in the IT industry with a specialized specialised focus on data management and governance. He has been assisting customers globally with their Digital Transformation efforts, Cloud Migration & Data Management moderniszation requirements. Prior to joining Rubrik, Vigyan served many roles at MongoDB and Oracle. Before working at Oracle, Vigyan served as a consultant for McKinsey & Company’s digital practice. Vigyan has a background in instrumentation and control engineering and loves solving real world problems. Vigyan lives in Melbourne and tries to spend his free time hanging out with his awesome son, in fear of the day he wakes-up and decides his father is no longer cool enough to hang out with.Vicent Osabel · Principal Solutions Engineer, Dataiku Vicent Osabel is a senior solutions engineer from Dataiku based in Melbourne. She has 20+ years experience in Data and Analytics by supporting large organisations realise their data science vision and roadmap through defining AI solution roadmaps, implementing data science projects and conducting training and enablement for customers and prospects. Having worked predominantly in the Financial Services sector both in A/NZ and SE Asia, she has accumulated expertise in the areas of regulatory compliance, credit risk management and customer analytics during her careers at SAS (PH and AU), Businessminds (now merged with Bain & co) and Deloitte Australia. She is also an advocate of women pursuing careers in Data Science and has been a trainer and judge for a datathon sponsored by TechWomenNZ late last year."
Linda Scott · Managing Director and Founder, Thinking Leaders I work with CEOs, business owners, executives and senior leadership teams to unlock their potential, achieve high performance, and fast track growth and results, for themselves and their businesses. I have worked in and for businesses as a finance executive for nearly 30 years. After a very successful career both locally and internationally, I founded Thinking Leaders to focus on leadership, career and business growth, decision making, time management, productivity, communication effectiveness, problem solving, increasing profits and results, and creating professional businesses to maximise monetisation value, through changing the way you think, behave and respond. A speaker and facilitator in the space of self-leadership and perspective, and how this impacts your environment and results, I teach strategies to help you understand that you have choice about your thinking, which in turn impacts how you respond and the results you create.
Ben Dexter · Chief Innovation Officer, Newpath Innovation Strategy, Digital Solution Design, and Digital Product Commercialisation specialist.
Richard Magalad · Chair of cloud branch, Australian Information Security Association Richard Magalad is a 30 year veteran of the ICT industry starting his career at the Commonwealth bank where he received world-class training on Oracle, COBOL, NEC, IBM, Unisys and many other enterprise vendors. He was a 10-year IT director from 2010 working at a mining company with uranium, gold and diamond projects in Australia, Laos and Canada. Current major projects involve two of the large Telcos, several agencies in Federal Government and he is also active in providing strategic IT advice
Partners
- Kiteworks Kitework's mission is to empower organizations to effectively manage risk in every send, share, receive and save of sensitive content. To this end, we created Kiteworks a Content Governance, Compliance, and Protection platform. The platform enables customers to unify, track, control and secure sensitive content moving within, into, and out of their organization to reduce risk exposure and ensure regulatory compliance.
- Aqua Security
- Sophos
- Rubrik Rubrik, the Zero Trust Data Security Company™, delivers data security and operational resilience for enterprises. Rubrik’s big idea is to provide data security and data protection on a single platform, including: Zero Trust Data Protection, ransomware investigation, incident containment, sensitive data discovery, and orchestrated application recovery. This means data is ready at all times so you can recover the data you need, and avoid paying a ransom. Because when you secure your data, you secure your applications, and you secure your business. For more information please visit www.rubrik.com and follow @rubrikInc on Twitter and Rubrik, Inc. on LinkedIn. Rubrik is a registered trademark of Rubrik, Inc. Other marks may be trademarks of their respective owners.
Tufin- Dataiku Dataiku is the centralized data platform that moves businesses along their data journey from analytics at scale to enterprise AI. By providing a common ground for data experts and explorers, a repository of best practices, shortcuts to machine learning and AI deployment/management, and a centralized, controlled environment, Dataiku is the catalyst for data-powered companies. Customers like Unilever, GE, and Comcast use Dataiku to ensure they are moving quickly and growing exponentially along with the amount of data they’re collecting. By removing roadblocks, Dataiku ensures more opportunity for business-impacting models and creative solutions, allowing teams to work faster and smarter.
More events from this host
- Canva Melbourne Roundtable August 2026, Melbourne
- AI Systems Scale August 2026
- Agentic Brand Control August 2026, The Rocks
- Modern Govt Day September 2026, Canberra
- CTO Day | Melbourne September 2026, Southbank
- Beyond The Data Centre: Building Government At The Edge September 2026, Canberra
- Executive Confidence in Identity and Security September 2026, Chicago
- Secure Scalable Ecosystems September 2026, Sydney