
Security Day | Melbourne
Defending the Digital Enterprise: Strategies for Evolving Threat Landscapes
Rydges, Melbourne, Australia
Hosted by Factor
- 2 attendees
- 8 hours
Overview
In today's dynamic security landscape, the CISO's role is more critical than ever. Gain insights into how security leaders can stay ahead of the rapidly evolving threat landscape, leverage AI and machine learning for threat detection, and foster a culture of security within digital transformation initiatives. Discuss how to create a proactive, resilient security strategy that aligns with regulatory requirements and emerging technologies like quantum computing and IoT security.
What we will cover
- Threat Intelligence Latest insights on how organisations can harness actionable data to anticipate, detect, and counter emerging threats effectively.
- Incident Response Explore key learnings on designing and implementing strategies that minimise downtime and disruption during complex cyber incidents.
- Cloud Security Discover comprehensive approaches for safeguarding workloads, data, and applications in dynamic hybrid and multi-cloud environments.
- Data Privacy Gain a deeper understanding of how to ensure compliance with evolving regulations while protecting sensitive information across diverse systems.
- Identity Management Learn advanced techniques for securing access control through robust authentication and identity governance solutions.
- Ransomware Defence Delve into actionable strategies to prevent, detect, and recover from ransomware attacks, ensuring business continuity.
- Zero Trust Uncover the transformative impact of adopting a never-trust, always-verify security model to protect enterprise systems and data.
- Cyber Resilience Understand how to build systems and processes capable of withstanding, adapting to, and recovering from sophisticated cyber threats.
- Supply Chain Gain insights into identifying and mitigating risks across increasingly interconnected vendor and partner ecosystems.
- Automation Learn how to leverage automation technologies to streamline regulatory adherence and minimise compliance-related risks.
- Risk Mitigation Explore in-depth frameworks for identifying vulnerabilities, assessing threats, and proactively reducing organisational risks.
- Endpoint Protection Latest strategies for securing endpoint devices, addressing vulnerabilities, and defending against advanced cyber attacks.
Agenda
- Welcome Coffee & Registration(Security Day - Plenary)
- Opening Remarks(Security Day - Plenary)
- Cyber Resilience Insights from the Frontlines of National Cybersecurity(Security Day - Plenary) Cyber threats have evolved significantly in the past decade, with adversaries employing advanced tactics to compromise critical infrastructure, supply chains, and sensitive data. Cybercrime is expected to cause $10.5 trillion in damages globally annually by 2025, making it the greatest transfer of economic wealth in history. Joining us in this session, Alan Marjan will provide valuable insights into the evolving landscape of cyber threats and the critical importance of cyber resilience for national security and organisational effectiveness. Drawing on his expertise as the First Assistant Director-General for Cyber Security Resilience at the Australian Signals Directorate, he will share lessons from the frontlines of cybersecurity defence in Australia. The discussion will cover the most pressing emerging threats, the future of cyber resilience, and the vital role that leadership plays in safeguarding organisations against cyber risks. Discussion Points: The evolving threat landscape across the globe. Building organisational resilience: A call to action for executives.
- Operational Resilience needs Cyber Resilience. What to do when the unexpected happens?(Security Day - Plenary) Key Topics Covered: Impact of downtime, brand, revenue and morale What to consider, observability to security Strategies to enhance your cyber resilience Blueprint to best practice
- The Collective Enterprise and Unlocking the Potential of Cyber Resilience for Business Continuity(Security Day - Plenary) Cyber resilience is a cornerstone of effective risk management, enabling organisations to withstand and recover from cyberattacks and incidents without crippling their operations. Research shows that resilient organisations recover 40% faster from breaches than their peers. This session dives into building resilience strategies that prioritise prevention, detection, and recovery while balancing cost and complexity. Attendees will explore tools, processes, and real-world examples to craft a holistic resilience plan that aligns with their organisational goals. Discussion Points: The critical elements of a robust cyber resilience strategy. Balancing prevention, detection, and recovery cost and effort. Leveraging simulation exercises to test and enhance resilience plans.
- Cybersecurity Leadership in Digital Transformation: A CISO's Guide(Security Day - Plenary) Digital transformation promises efficiency and innovation, but without security at its core, it can become a company’s greatest vulnerability. Rushed implementations, misaligned priorities, and over-reliance on automation can leave critical gaps that attackers exploit. According to a 2024 study, 82% of IT security and C-level executives experienced at least one data breach during the implementation of new technologies. This highlights the risk businesses face when security is an afterthought in their transformation journey. Additionally, the global cybersecurity total addressable market is expected to reach $1.5 trillion to $2.0 trillion by 2025, reflecting the increasing demand for robust cybersecurity in digital initiatives. This session explores why security must lead transformation efforts, not follow them. Discussion Points: How digital transformation can introduce more security risks than it solves. Why automation and AI are not enough to fix security gaps in transformation. The hidden dangers of prioritising speed and efficiency over security in business change.
- Morning Tea & Networking(Security Day - Plenary)
- Enhancing Endpoint Security in the Australian Threat Landscape Discuss strategies for fortifying endpoint defences against evolving cyber threats targeting Australian organisations.
- Optimising Security Information and Event Management for Australian Businesses(Incident Monitoring) Delve into enhancing SIEM systems to effectively detect and respond to security incidents within the Australian context.
- Identity and Access Management: Navigating Compliance and Security in Australia(Identity Management) Examine approaches to streamline identity and access management while adhering to Australian regulatory requirements.
- Advancing Network Security: Best Practices for Australian Enterprises(Network Protection) Explore effective methods to safeguard network infrastructures amidst increasing cyberattacks in Australia.
- Proactive Vulnerability Management: Addressing Emerging Threats in Australia(Vulnerability Assessment) Discuss the importance of continuous vulnerability assessment and remediation to protect Australian organisations from cyber threats.
- Securing Web Access: Implementing Effective Gateways in Australian Organisations(Web Security) Explore the deployment of secure web gateways to control and monitor web traffic, ensuring safe internet usage in Australian workplaces.
- Regulatory Horizons – Recent Legal Developments in Cybersecurity(Security Day - Plenary) Cybersecurity is no longer just an IT issue—it’s a boardroom priority shaped by evolving legal and regulatory requirements. With APRA’s CPS 230 introducing stricter operational risk management standards, ASIC increasing scrutiny on directors’ cybersecurity obligations, and new requirements under the Cyber Security Act, organisations must adapt quickly to stay compliant and resilient. Understanding these legal changes is critical to mitigating risk, ensuring supply chain security, and navigating new obligations, including IoT standards and ransom reporting. Leaders who embed cybersecurity into their governance frameworks will be better positioned to protect their businesses and maintain regulatory confidence. Discussion Points: The impact of APRA CPS 230 on operational risk management and supply chain security. ASIC’s increasing focus on directors’ cybersecurity responsibilities and legal exposure. Key requirements under the Cyber Security Act, including IoT standards and ransom reporting obligations.
- Waste Not, Risk Not? Securing Critical Infrastructure in Heavily Regulated Sectors(Security Day - Plenary) [Fireside Chat] In today's digital landscape, critical infrastructure has become a prime target for cyber threats, with over half of reported cyberattacks in recent years aimed at essential sectors. A recent survey revealed that 54% of critical infrastructure managers experienced attempts to control their systems, while in Australia, more than 11% of cybersecurity incidents last year involved critical infrastructure, highlighting the sector's vulnerability. This session will delve into the unique challenges of safeguarding critical infrastructure in heavily regulated industries, focusing on strategies to enhance cyber resilience and ensure compliance with stringent operational requirements. Discussion Points: The paradox of strict regulations potentially hindering agile cybersecurity incident response and recovery. Balancing operational uptime demands with the implementation of robust security measures. The underestimated risks of IoT integration in critical infrastructure environments.
- Optimising Cyber Operations While Maintaining Gold-Standard Security(Security Day - Plenary) Balancing cyber optimisation with gold-standard security is no easy task, yet it is critical in a rapidly evolving threat landscape. In some segments, 60% of businesses shut down within six months of a major cyberattack, highlighting the serious stakes. However, two out of three organisations report moderate-to-critical cyber skills gaps. As organisations seek efficiency, outsourcing and offshoring models are becoming increasingly common. Meanwhile, regulatory requirements like E8 compliance demand stronger security measures, with 91% of companies planning to implement continuous compliance within the next five years. While three in four organisations with continuous compliance report business benefits, 76% of those relying on point-in-time compliance see it as a burden. This session explores strategies for cyber efficiency, compliance, and resilience in an unpredictable environment. Discussion Points: The costs and benefits of outsourcing security operations, particularly in the context of cyber skills gaps, to ensure optimised incident response and recovery times. Why treating E8 compliance as a tick-box exercise is a fast track to failure. How to maintain gold-standard security levels while implementing cyber optimisation and uplift.
- Networking & Lunch Break(Security Day - Plenary)
- Harnessing Data to Predict and Mitigate Emerging Cyber Threats(Threat Intelligence) Discuss how organisations can leverage threat intelligence tools and strategies to stay ahead of cybercriminals.
- Navigating Evolving Regulations and Privacy Standards(Data Privacy) Gain insights into maintaining compliance with global and local privacy laws while protecting organisational data.
- Optimising Incident Response Plans for Rapid Recovery Explore how organisations can enhance their incident response plans to minimise impact during cyberattacks.
- Strengthening Authentication and Identity Governance(Identity Management) Learn how to enhance identity management strategies to better protect organisational assets and data.
- Building a Robust Defence Strategy Against Ransomware(Ransomware Defence) Delve into the latest strategies for preventing, detecting, and responding to ransomware attacks.
- Securing Hybrid and Multi-Cloud Environments(Cloud Security) Discover how to protect sensitive data and applications across hybrid and multi-cloud infrastructures.
- Navigating Australia's Evolving Cyber Security: Implications for Organisations, Insights by Factor(Security Day - Plenary) In 2025, the digital landscape is undergoing another major shift. Australian CISOs and other technology decision makers and leaders are expected to interpret the impacts of technology changes, and play a critical role in influencing C-Level stakeholders. All while organisations navigate financial constraints, increased cyber risks, and the rapid rise of AI-driven transformation. The incredible disruption caused by the launch of DeepSeek and the subsequent scramble by the world’s largest software and tech providers to react has also turned what was almost a stable environment into bedlam. Factor’s local research into Australian tech decision makers intentions reveals that 30% of organisations cite budget constraints when securing funding for their security initiatives. The complexity of integration (24%) and skills and talent shortages (17%) are also barriers to scaling their ICT initiatives – including cyber security. Cyber security continues to be among the top 3 concerns for government policy makers and organisations, business leaders, technology professionals, and consumers. Although still in its early days, the judicious use of AI as a force multiplier rather than a replacement for human intelligence, can assist in improving cyber security, providing greater operational efficiency and improved competitiveness. Organisations that fail to adapt to this new world risk falling behind in an era where technology adoption drives competitive advantage. This presentation will present new research based on your responses to our survey questions, as such it will present extremely relevant and timely information and insights. Discussion Points: What is the current state of cyber security legislation and compliance in Australia What technologies are influencing overall business and ICT Strategy? What investment and other priorities are core to cyber security and related strategies in 2025? What factors are holding CISOs back in the race to cope with an increasingly complex and broad threat landscape? What strategies can decision makers adopt to increase C-Level stakeholder influence in their organisation?
- The Power of Data: Cyber Risk Quantification for Meaningful Boardroom Discussions(Security Day - Plenary) Cyber risk quantification is transforming the way cybersecurity leaders engage with executives and boards. Moving beyond traditional red-amber-green maturity reporting, quantification allows cyber risks to be measured alongside other strategic business risks. Research shows that nearly 90% of executives say measuring cyber risk is crucial for prioritising cybersecurity investment, yet only 15% of organisations have significantly adopted it. By leveraging data-driven insights, businesses can shift cyber conversations from vague assessments to clear, actionable discussions that align with broader organisational objectives. Discussion Points: Why cyber risk quantification is the key to stronger, data-driven boardroom conversations. The limitations of traditional maturity reporting and how to move beyond red-amber-green assessments. How integrating cyber risk metrics with business risk frameworks elevates cybersecurity in strategic decision-making.
- AI Guardrails and Regulations – Securing AI/ML and Shadow AI(Security Day - Plenary) As AI and machine learning technologies continue to evolve, the cybersecurity threat landscape expands, with cyberattacks on critical infrastructure escalating. In the World Economic Forum’s latest Global Risks Report, three of the top 10 risks are technological: misinformation and disinformation, adverse outcomes of AI technologies, and cyber espionage and warfare. At the same time, operational technologies, such as AI/ML systems and connected devices, are becoming more interconnected, increasing vulnerability. Without proper guardrails, AI technologies pose significant risks to organisations. The U.N. Secretary-General António Guterres highlighted these concerns at Davos, emphasizing that AI, if left ungoverned, could erode trust and disrupt industries. Recent legislative changes, such as the Cyber Security Act 2024, require organisations to implement safeguards in AI-heavy environments, ensuring proactive risk management while adopting AI responsibly. This session will explore how AI guardrails and updated regulations can protect critical infrastructure and organisations, while helping leaders stay ahead of emerging threats. Discussion Points: The growing role of AI guardrails in safeguarding critical infrastructure and other investment portfolios. The need for updated cybersecurity regulations to keep pace with AI advancements. How new AI regulations will transform cybersecurity strategies across industries.
- Shaping the Future of Cybersecurity Leadership(Security Day - Plenary) Cybercrime is projected to cost businesses over $10 trillion by 2025, rising to nearly $16 trillion by 2029. At the World Economic Forum’s Cybersecurity Meeting, 71% of cyber leaders said many organisations can no longer secure themselves against growing cyber risks, underscoring the need for stronger leadership. The CISO role is evolving beyond IT security into a strategic business function. Yet, only 47% of CISOs engage with their boards regularly, and just 28% are considered Strategic CISOs with real boardroom influence. Those who align security with business goals are driving greater impact and career growth. With 36% of breaches costing over $1 million and only 2% of businesses recovering within 24 hours, the stakes have never been higher. This panel explores how security executives are strengthening their strategic influence by aligning cybersecurity with business objectives, fostering innovation through diverse teams, and securing stakeholder buy-in. Discussion Points: Aligning cybersecurity strategies with business growth objectives. Building diverse teams to drive innovation and tackle complex challenges. Communicating cybersecurity priorities to highlight risk mitigation, ROI, and business alignment.
- Closing Remarks(Security Day - Plenary)
- End of Day & Networking Drinks(Security Day - Plenary)
Speakers
Josh Heid · CEO, Factor Josh brings with himself years of leadership experience as the driving force behind Factor and Panelist, where he has shaped the future of business strategy through his expertise in Product Design, Customer Experience, and Engineering. An innovator at heart, Josh excels in Product Design, where he combines aesthetic sensibility with functional purpose to create solutions that resonate with users and deliver measurable results. His approach bridges customer needs and cutting-edge technology, ensuring that every product is not only visually compelling but also highly effective in meeting market demands. In the realm of Customer Experience, Josh has consistently championed the importance of understanding user journeys and fostering engagement through intuitive design and seamless interactions. He has implemented frameworks that elevate user satisfaction, ensuring that Factor’s offerings remain at the forefront of customer-centric innovation. Josh's engineering mindset adds a unique layer to his leadership. His ability to translate complex concepts into actionable development processes has resulted in robust, scalable applications and systems. By integrating engineering principles with strategic thinking, Josh has driven operational excellence while maintaining a sharp focus on delivering top-tier solutions to clients. With a deep understanding of Leadership Strategy, Marketing, and Sales, Josh has built Factor and Panelist into trusted names in their industries, continuously setting new benchmarks for innovation and success.
Craig Baty · VP Research & Advisory, Factor As VP Research & Advisory at Factor, Craig drives the company’s research and advisory, editorial, and production teams. With over 30 years of C-level experience in ICT, HR, marketing, sales, operations, research, leadership, and international business, Craig is a notable tech industry leader. He served as Group VP and Head of Research for Gartner AP/J and CEO of Gartner Japan, earning the Gartner Thought Leadership award and pioneering the Gartner SWOT analysis. Craig has held several significant positions throughout his career. At ISG (Information Services Group), he served as the Distinguished Lead Analyst for ISG Provider Lens Research in Asia/Pacific and Japan, delivering numerous projects and custom research. He was the Principal and Founder of DataDriven, a consultancy specialising in ICT research, marketing, and strategy. Craig’s leadership extended to his role as Federal Board Member at the Australian Information Industry Association (AIIA) and Vice Chair of the Australian Computer Society (ACS), where he guided the organisations through significant transitions.
Madeline Palmer · Head of Content, Research & Editorial, Factor Madeline Palmer is a seasoned media and communications professional with extensive experience across journalism, broadcasting, and content creation. As the Head of Content, Research & Editorial at Factor, Madeline is in charge of broad range of strategic, editorial, and managerial tasks aimed at ensuring the production and dissemination of high-quality research content across various platforms. Madeline has hosted and moderated dozens of C-Suite roundtable discussions on topics such as GenAI, Fintech solutions, CX and UX insights, Data Governance and ESG. Madeline has also hosted panels at our larger events, on topics from Cyber Security to DevOps. She also oversees the editorial aspect of Factor’s research reports and white papers. Before joining Factor, she worked as a broadcast journalist in a number of major newsrooms across the country. During this time, Madeline covered breaking national and international news, including the Covid-19 Pandemic, the Medibank and Optus data breaches, several State and Federal Elections, the historical AUKUS Agreement, and the wars in Ukraine and Gaza, among other stories. Madeline has a Bachelor in Communications and a Post-Graduate Diploma in Broadcasting from Edith Cowan University in Perth. In 2018, she was a finalist in the Brian White Radio Journalism Awards. Madeline was also named a finalist for Young Journalist of the Year Award at the Rural Press Club Awards in 2020. While in 2022, she was also a finalist of the 30 Under 30 Awards from Radio Today.
Darren Adams · Director - Data & Business Enablement, Factor As Director of Data, Value Enablement and Research, Darren aligns key industry learnings with extensive data analytics to underpin the business strategies and activities. Darren works with every department in the business to ensure their operations are supported by key metrics and relevant findings, and collating our information to deliver insights to our audiences. He is a highly regarded professional in the APAC event landscape, drawing on his experience in communications, client relations, events, marketing, data, strategy and delivery roles in the aid, development, technology and event sectors. Darren has partnered with multiple large-scale partners to deliver events across the region including Salesforce World Tours across ANZ, Trailhead Basecamp series in India, AWS Cloud Summit Singapore & Sydney, XeroCon ASEAN series and Google Cloud Summit, among others. He holds a Bachelor of Communications (Media Arts & Productions) from the University of Technology Sydney. He is continuously engaged in learning, undertaking short courses in project management, data analytics and various areas in the technology landscape.
Alan Marjan · First Assistant Director-General Cyber Security Resilience, Australian Defence Force
Maxine Harrison · CISO, DEECA Victoria Maxine Harrison is the Chief Information Security Officer (CISO) at the Department of Energy, Environment and Climate Action (DEECA) in Victoria, Australia. In her role, Maxine leads the Cyber Security Unit, which coordinates government responses to cyber incidents and provides critical cyber threat intelligence. Her team supports a vision for a cyber-safe Victoria, ensuring that government services are securely delivered, and communities and industries are protected. Maxine plays a key role in implementing Victoria's Cyber Security Strategy, focusing on enhancing the state's cybersecurity maturity. As part of the Data and Technology Committee, she also provides strategic oversight, guiding DEECA's digital transformation, risk management, and the development of policies to safeguard technology and data across the department. Her leadership has been instrumental in achieving significant milestones within DEECA’s 3-year roadmap for cybersecurity. Maxine's expertise and dedication ensure that DEECA’s cybersecurity controls are robust and adaptive to emerging threats.
James Court · Chief Information Security Officer (CISO), Cleanaway Waste Management
Annie Haggar · Partner | Head of Cybersecurity Australia, Norton Rose Fulbright Annie is a security and technology lawyer with 20 years of experience advising government and private sector clients in cyber and technology law, security risk, strategy and policy, procurement security considerations, global security regulation, and cybersecurity risk mitigation. Prior to joining Norton Rose Fulbright, Annie founded a cyber specialist law firm Cyber GC after spending 12 years as legal counsel for one of the world’s largest technology companies, Accenture, including 6 years as global legal counsel for its global cybersecurity business. Annie has been awarded multiple legal industry awards for her work in these roles.
Onur Taylor · CISO and GM of Technology, Ventia Onur Taylor is a highly accomplished security and technology leader with over 20 years of experience driving digitization and transformation initiatives. As the Chief Information Security Officer and GM of Technology at Ventia, Onur leads efforts to enhance security, improve customer experiences, and deliver innovative product digitization strategies that align with business outcomes. Prior to Ventia, Onur held various leadership roles at Telstra, including GM of Cyber Security Transformation, GM of Enterprise IT Digitization, and GM of Consulting and Technology Delivery. Across his 11+ years at Telstra, he championed enterprise security and spearheaded groundbreaking IT projects that transformed operations and fortified digital resilience. Known for his visionary leadership and expertise in security and technology, Onur is passionate about driving sustainable transformation while ensuring robust information security.
Anya Avinash · (CISO) Head of Cybersecurity, Bank First Anya Avinash is a seasoned cybersecurity leader with over 15 years of experience spanning security strategy, resilience, and risk management. She specializes in uplifting security maturity, managing incidents, and fostering strong governance frameworks, all while prioritizing customer-focused outcomes. Anya excels in creating and embedding organizational security culture and developing risk-aligned security roadmaps tailored to business needs. Currently serving as Head of Cybersecurity at Bank First, Anya has held key roles at Flybuys, Coles, and Transurban, where she spearheaded initiatives in compliance, resilience, and governance. Her expertise includes aligning organizations with ISO 27001, NIST CSF, and PCI DSS standards and driving security awareness through training and mentoring. Anya is also a passionate advocate for cybersecurity knowledge-sharing and has contributed significantly to the industry through public speaking, panel discussions, and mentoring the next generation of cybersecurity professionals.
Huw Sergeant · CISO | Group GM Cybersecurity and Digital Services, Mirvac Huw Sergeant is an experienced cybersecurity, technology, and risk executive with over 30 years’ experience across Technology, risk, cybersecurity and compliance. As Group GM Cybersecurity and Digital Services at Mirvac, he leads the company’s cyber strategy, risk management, and digital governance, ensuring robust protection of critical assets. He also leads the cloud, network and support functions, ensuring that security is at the forefront of all technology. With prior leadership roles at Smartgroup, Allianz, Macquarie Bank and Herbert Smith Freehills, Huw has a proven track record of building and leading high-performing teams, driving security posture enhancements, and engaging closely with executive leadership and boards. His expertise spans cyber risk, technology, data governance, and financial management, making him a trusted advisor in the ever-evolving security landscape. A strategic thinker with deep technical understanding, he excels in delivering pragmatic solutions that balance security, compliance, and business growth.
Colin Renouf · CISO, Healius Limited Colin Renouf is a seasoned cybersecurity leader with deep expertise in critical infrastructure, cloud security, and cyber threat intelligence. As Chief Information Security Officer at Healius Limited, he drives resilient security strategies, ensuring the protection of sensitive healthcare systems. With over two decades of experience, he has shaped security architectures across government, defence, and enterprise sectors, leveraging AI and machine learning for adaptive threat response. Colin has pioneered distributed cloud models, enabling rapid recovery of key services during regional disruptions. He has collaborated with government bodies and industry leaders to enhance critical infrastructure resilience, ISAC integration, and cyber threat intelligence. A published author, he has contributed to industry textbooks and leading security publications. Previously, he held senior cybersecurity roles at Transport for NSW, Commonwealth Bank, and Mastercard, excelling in security architecture, M&A, and digital transformation. His aeronautical engineering background informs his technical approach, making him a trusted expert in safeguarding high-risk environments.
Tara Dharnikota · (Fmr) Head of Information Security Management, PEXA Tara is an information security leader with over 15 years of experience specialising in risk management, security culture, and governance. As the Head of Information Security Management in a highly regulated property industry, she ensures security practices align with business and compliance requirements. With a background leading security teams in telecommunications, she has deep expertise in security resilience, threat intelligence, and business-aligned security management. She also serves as an industry advisor for major universities and a cybersecurity body. Tara actively mentors professionals and aspiring professionals, contributes to cybersecurity initiatives, and speaks at industry conferences. She also holds a Master’s in Network Engineering.
Dan Elliott · Head of Cyber Resilience ANZ, ZRS Australia, Zurich Insurance With nearly two decades of experience in national security and cyber resilience, Dan is a trusted advisor to executive leaders and Boards, helping organisations tackle the complexities of cyber risk. As Head of Cyber Resilience ANZ for Zurich Resilience Solutions (ZRS), Dan leads efforts to strengthen business cyber risk programs and translate technical challenges into actionable business insights. Previously, Dan spearheaded ZRS’ cyber advisory group in Canada, working with global clients to reduce risk and improve resilience. Before that, he spent six years as an Intelligence Officer with the Canadian Security Intelligence Service (CSIS), involved in counterintelligence operations and modernising the agency’s operational risk management program. Dan’s career began with a decade in law enforcement, investigating multinational organised crime online and in-person, and serving on a national counterterrorism taskforce. Drawing on his intelligence background, Dan empowers organisations to navigate an increasingly complex risk landscape. He is a sought-after speaker at conferences, boardrooms, and think tanks worldwide speaking about social engineering, cyber risk and leadership.
Malcolm Eng · Head of Risk, TPG Telecom Group Malcolm Eng is the Head of Risk at TPG Telecom, where he leads enterprise risk management, enabling resilience and adaptability in an evolving regulatory and business landscape. Malcolm brings broad experience in adapting risk strategies to diverse business models. His career spans a range of industries, including financial services, technology, and telecommunications. With expertise in risk management, governance, assurance, and regulatory compliance, he helps organisations navigate uncertainty while driving strategic growth. Prior to joining TPG Telecom, he held senior risk roles at Unisys, Westpac and Commonwealth Bank, where he strengthened risk frameworks, enhanced controls, and delivered strategic risk transformation initiatives.
Tim Pollock · CISO | Head of Cyber Security Operations, Beyond Bank Australia Tim Pollock is an experienced cybersecurity leader with a strong background in security operations, application security, DevSecOps, and security engineering. As the Head of Cyber Security Operations at Beyond Bank Australia, he oversees security operations and application security, ensuring robust protection against evolving threats. With nearly five years at a big-four consultancy firm as a Senior Manager in cybersecurity and previous roles at Aleron, Datacom, Vodafone Australia, and the Australian Signals Directorate, Tim has developed expertise in information security, incident response, and security architecture. His technical skills span programming in C, C++, Perl, Java, and Python, as well as networking and systems administration.
Nathan Smith · Head of Security APAC, Splunk Nathan Smith is a seasoned cybersecurity leader with over 20 years of experience delivering cutting-edge security, networking, and data solutions. As Head of Cybersecurity Sales APAC at Splunk, he drives strategic go-to-market initiatives and leads high-performing teams to help organizations strengthen their security posture. With expertise spanning enterprise and government sectors, Nathan has held key roles in sales leadership, account management, and business development. His deep technical knowledge in security, cloud, and data convergence enables him to craft tailored solutions that align with business objectives. A thought leader in cybersecurity, Nathan has contributed to industry councils and frequently speaks at conferences. His ability to think strategically and differentiate solutions makes him a trusted advisor in the field. He holds sales certifications across leading technologies, including Splunk, VMware, Cisco, and Check Point, ensuring he stays ahead in an evolving security landscape.
Partners
Sumo Logic · Bronze- Northbridge Systems
- Splunk · Platinum Splunk helps make organizations more digitally resilient. Leading organizations use our unified security and observability platform to keep their digital systems secure and reliable. Organizations trust Splunk to prevent infrastructure, application and security incidents from becoming major issues, remediate threats and disruptions faster, and adapt quickly to new opportunities. Splunk helps SecOps, ITOps and engineering teams deliver these outcomes with comprehensive visibility, rapid detection and investigation, and optimized response, all accelerated by AI and at the scale necessary for the world's largest organizations.
- Factor Leading market research in APAC.
More events from this host
- Canva Melbourne Roundtable August 2026, Melbourne
- AI Systems Scale August 2026
- Agentic Brand Control August 2026, The Rocks
- Modern Govt Day September 2026, Canberra
- CTO Day | Melbourne September 2026, Southbank
- Beyond The Data Centre: Building Government At The Edge September 2026, Canberra
- Executive Confidence in Identity and Security September 2026, Chicago
- Secure Scalable Ecosystems September 2026, Sydney