
Security Day | Sydney - Test
What the Modern CISO Must Own, Influence, and Rethink
Crown, Sydney, Barangaroo, Australia
Hosted by Factor
- 101 attendees
- 8 hours
Overview
In a year defined by rapid shifts in digital infrastructure, regulatory expectations, and AI-enabled innovation, Australia’s cyber leaders are stepping into a more expansive role, one that blends technical depth with business foresight, and operational resilience with cultural influence.
Security is no longer just about prevention; it’s about precision, knowing where your assets are, who has access, and how fast you can respond when something moves out of bounds.
As hybrid architectures evolve, the perimeter continues to dissolve. Identity is now infrastructure, and misconfiguration, not malware, is the fastest-growing breach vector. At the same time, government policy is maturing, boards are asking sharper questions, and security teams are being invited earlier into transformation initiatives.
This event brings together Australia’s top CISOs and cybersecurity executives for a pragmatic conversation on how to lead in this moment:
How do you scale visibility without creating friction?
How do you accelerate innovation while embedding trust?
And how do you architect for agility, not just defence, in a world where cyber maturity is business maturity?
What we will cover
- Threat Intelligence Latest insights on how organisations can harness actionable data to anticipate, detect, and counter emerging threats effectively.
- Incident Response Explore key learnings on designing and implementing strategies that minimise downtime and disruption during complex cyber incidents.
- Cloud Security Discover comprehensive approaches for safeguarding workloads, data, and applications in dynamic hybrid and multi-cloud environments.
- Data Privacy Gain a deeper understanding of how to ensure compliance with evolving regulations while protecting sensitive information across diverse systems.
- Identity Management Learn advanced techniques for securing access control through robust authentication and identity governance solutions.
- Ransomware Defence Delve into actionable strategies to prevent, detect, and recover from ransomware attacks, ensuring business continuity.
- Zero Trust Uncover the transformative impact of adopting a never-trust, always-verify security model to protect enterprise systems and data.
- Cyber Resilience Understand how to build systems and processes capable of withstanding, adapting to, and recovering from sophisticated cyber threats.
- Supply Chain Gain insights into identifying and mitigating risks across increasingly interconnected vendor and partner ecosystems.
- Automation Learn how to leverage automation technologies to streamline regulatory adherence and minimise compliance-related risks.
- Risk Mitigation Explore in-depth frameworks for identifying vulnerabilities, assessing threats, and proactively reducing organisational risks.
- Endpoint Protection Latest strategies for securing endpoint devices, addressing vulnerabilities, and defending against advanced cyber attacks.
Agenda
- Welcome Coffee & Registration(Security Day)
- Welcome Address & Introduction(Security Day)
- Cybersecurity at the Edge of National Security: Lessons from the AFP(Security Day) As CTO of the Australian Federal Police, Krissie Auld leads the secure delivery of critical technology infrastructure that supports national law enforcement operations. In this session, she shares practical lessons on embedding cybersecurity into complex, sovereign infrastructure, ensuring resilience, compliance, and operational readiness in an evolving threat landscape. Discussion Points: Integrating cybersecurity into network and cloud architecture: How the AFP builds security into SD-WAN, SASE, and sovereign cloud platforms from the ground up. Balancing innovation with regulation and operational demands: Managing risk and compliance in a tightly governed, mission-critical public sector environment. Building resilient and adaptable infrastructure: Practical insights on designing infrastructure that ensures high availability and security, with strategies that enterprise tech leaders can apply to their own complex environments.
- Guardrails for Growth: An essential guide to Secure AI Adoption(Security Day) As GenAI adoption surges, businesses are racing to turn AI into business advantage, but often without secure measures in place. As sensitive data flows into AI, the risk of leakage, compliance failures, and eroded trust grows. This session offers a framework for aligning business stakeholders on a data-centric approach to GenAI.
- The Collective Enterprise: C-Suite Fusion Amid Global Disruption and Opportunity(Security Day) In an era defined by AI acceleration, economic turbulence, and geopolitical unpredictability, cross-functional leadership has never been more critical. This panel brings together top C-Suite leaders to explore how collaborative decision-making and integrated strategies can future-proof organisations against global shocks—while unlocking new avenues for growth. Moving past the jargon of “fusion teams,” this discussion will spotlight what real C-suite cohesion looks like today—and how executive alignment is becoming the defining trait of resilient, forward-moving enterprises. Discussion Points: Harnessing diverse leadership lenses to respond to macro shifts in real time. Rethinking governance, cyber resilience, and agility models to keep pace with AI, regulatory complexity, and escalating digital threats. Aligning across business, tech, and finance functions to turn disruption into competitive advantage. Navigating external pressures—from trade tensions and shifting tariffs to geopolitical uncertainty—with unified, enterprise-wide strategies.
- Digital Resilience: What To Do When The Unexpected Happens(Security Day)
- Networking Break & Morning Tea
- Active Directory: The Ultimate Prize for Cybercriminals and How to Secure It.(Executive Round Table) Active Directory remains at the centre of identity and access management for most organisations. Yet, it is also a prime target for cyber attackers. Once breached, it can provide hackers with the keys to the kingdom, allowing them to move laterally, escalate privileges, and exfiltrate data. Despite its criticality, many security programs overlook Active Directory, assuming it to be a stable back-end service. The reality is that attackers exploit its complexity, misconfigurations, legacy dependencies, and lack of visibility to gain persistence and control. Organisations need to understand the risks, strengthen controls, and adopt modern security practices to defend against increasingly sophisticated threats.
- Gaining Control of Sensitive Data Across Hybrid Environments(Data Security & Governance) Explore how CISOs are discovering, classifying, and protecting sensitive data across cloud and on-premises systems while managing compliance and reducing risk.
- Securing Hybrid and Multi-Cloud Environments(Cloud Security) Discover how to protect sensitive data and applications across hybrid and multi-cloud infrastructures.
- Advancing Network Security: Best Practices for Australian Enterprises(Network Protection) Explore effective methods to safeguard network infrastructures amidst increasing cyberattacks in Australia.
- Harnessing Data to Predict and Mitigate Emerging Cyber Threats(Cyber Resilience & AI) Discuss how organisations can leverage advanced threat intelligence, AI, and automation to strengthen resilience against evolving attacks.
- Optimising Security Analytics and Event Management(Security Analytics & Threat Detection) Delve into enhancing SIEM systems to effectively detect and respond to security incidents within the Australian context.
- Enhancing Endpoint Security in the Australian Threat Landscape Discuss strategies for fortifying endpoint defences against evolving cyber threats targeting Australian organisations.
- AI-Powered Threats, AI-Powered Defence: The Next Cybersecurity Arms Race(Security Day - Plenary) The rise of generative AI has created a new frontier for both attackers and defenders. While threat actors are using AI to scale phishing, deepfakes, and ransomware, security leaders are under pressure to harness the same tools for faster detection, response, and resilience. This session unpacks how CISOs can strike the right balance, leveraging AI for defence without opening new vulnerabilities. Discussion Points: How attackers are weaponising AI today, and the most effective defence strategies in response. Practical use cases of AI in cyber defense: detection, response automation, and predictive analytics. Governance, ethics, and accountability: ensuring AI-driven security practices remain transparent and compliant.
- Elevating Cyber to the C-Suite and Boardroom(Security Day - Plenary) [Fireside Chat] In today’s environment of relentless cyber threats, evolving regulation, and rising stakeholder expectations, cybersecurity can no longer be siloed in the IT department. It is a business issue, and a board-level mandate. In this fireside chat, Maryam Bechtel, Chief Information Security Officer at AGL Energy, shares how cybersecurity is being redefined as a strategic business enabler. Drawing on her leadership of cyber strategy across critical infrastructure and her experience embedding cyber accountability across executive teams, Maryam will unpack what it truly takes to elevate security from a technical function to an organisation-wide priority. Discussion Points: Why business leaders — not just CISOs — must own cyber risk How to create clear, measurable cybersecurity KPIs at the executive level Practical approaches for engaging boards and senior leaders in meaningful cyber dialogue Lessons from leading cyber uplift across one of Australia's most high-profile critical infrastructure providers
- Cyber Governance and Compliance at a Global Scale(Security Day - Plenary) Leading cyber governance and compliance across multiple countries requires more than policies—it demands strategic leadership that builds trust, fosters accountability, and navigates complex regulatory landscapes. Stephen Bennett, Global CISO at Domino’s Pizza Enterprises, shares his experiences managing governance frameworks spanning 12 countries, emphasizing clear communication with boards, culturally aware risk management, and creating resilient, aligned teams. This session offers practical strategies for chiefs and executives to drive effective cyber governance and compliance that supports global business growth and risk resilience. Discussion Points: Establishing Consistent Governance Across Diverse Regions: Balancing regulatory requirements and cultural differences while maintaining unified cyber policies and standards. Building Accountability and Risk Awareness Within Global Teams: Using leadership and empathy to align teams behind governance goals and improve compliance adherence. Innovating Governance through Practical Automation.
- Networking & Lunch Break
- Building Trust to Transform: Identity as the CISO’s Innovation Lever(Executive Round Table) Australians CISOs are under pressure to secure ever-expanding digital estates while enabling their organisations to innovate at speed. Too often, security is seen as a blocker—but when identity sits at the core, it can unlock secure and rapid innovation, unlock multi-cloud adoption, resilient operations, and frictionless experiences for customers, partners and employees alike. This roundtable will bring security leaders and experts together to discuss how identity-first strategies and zero-trust principles can shift security from a barrier to a catalyst for transformation, while strengthening compliance and preparing for the next wave of AI-driven disruption.
- AI & Insider Threats: The Hidden Risk Redefining Cyber Resilience(Executive Round Table) Insider threats are rapidly evolving in the age of AI, creating one of the most urgent challenges for security leaders. From malicious insiders leveraging generative AI to negligent employees or compromised credentials, these risks often slip past traditional rule-based defences. The consequences are high: financial loss, regulatory exposure, and long-term repetitional damage.
- Optimising Incident Response Plans for Rapid Recovery Explore how organisations can enhance their incident response plans to minimise impact during cyberattacks.
- Harnessing Data to Predict and Mitigate Emerging Cyber Threats(Threat Intelligence) Discuss how organisations can leverage advanced threat intelligence, AI, and automation to strengthen resilience against evolving attacks.
- Strengthening Authentication and Identity Governance(Identity Management) Learn how to enhance identity management strategies to better protect organisational assets and data.
- Proactive Vulnerability Management: Addressing Emerging Threats in Australia(Vulnerability Assessment) Discuss the importance of continuous vulnerability assessment and remediation to protect Australian organisations from cyber threats.
- Securing Web Access: Implementing Effective Gateways in Australian Organisations(Web Security) Explore the deployment of secure web gateways to control and monitor web traffic, ensuring safe internet usage in Australian workplaces.
- Building a Robust Defence Strategy Against Ransomware(Ransomware Defence) Delve into the latest strategies for preventing, detecting, and responding to ransomware attacks.
- From Awareness to Action: Making Culture Your Cyber Shield(Security Day - Plenary) Peter Drucker once said, “Culture eats strategy for breakfast.” In cyber security, the truth is, even the best frameworks and roadmaps won’t succeed without the right culture behind them. In this presentation, Tara Dharnikota, CISO of Victoria University, explores how aligning culture with strategy creates lasting resilience. Drawing on lessons from both universities and enterprise environments, she demonstrates how stakeholder buy-in, shared accountability and everyday behaviours together form the backbone of a strong security culture. Discussion Points: Why strategies fail without cultural alignment and how to close the gap. Creating real ownership and shared accountability beyond awareness training. Leveraging culture as a driver of resilience across the organisation.
- Cybersecurity as a Strategic Business Enabler: Aligning Security and Innovation(Security Day - Plenary) In today’s rapidly evolving digital landscape, cybersecurity is no longer just a defensive necessity but a critical driver of business innovation and growth. This panel brings together seasoned cybersecurity leaders to explore how organisations can leverage cybersecurity not only to protect but to empower and accelerate their strategic objectives. The discussion will cover key areas including building organisational resilience through effective incident response, adopting zero trust and identity-first security models, managing technology risks amidst continuous innovation, and aligning cybersecurity strategies with broader business goals. Attendees will gain practical insights on transforming cybersecurity from a cost centre to a strategic business enabler. Discussion Points: Building Resilience through Effective Incident Response: Strategies to prepare for, detect, and rapidly respond to cyber incidents to minimise business impact. Implementing Zero Trust and Identity-First Security Models: How adopting zero trust principles and strong identity management transforms security posture. Managing Cyber Security and Technology Risk in a Dynamic Environment: Balancing innovation with risk mitigation as technology landscapes evolve rapidly. Aligning Risk and Resilience Strategies with Business Objectives: Integrating cybersecurity risk management and resilience planning into overall business continuity and strategy.
- Factor Closing Remarks(Security Day - Plenary)
- End of Day & Networking Drinks(Security Day - Plenary)
Speakers
Stephen Bennett · Global Chief : Information Security Officer, Domino's Australia A versatile Senior Security Leader with 30 years of experience in the IT industry with a strong background in building security capability from the ground up for large enterprise organisations covering such verticals as Gaming, Law Enforcement, Healthcare and Retail in both Asia Pacific and European markets.
Hank Opdam · Chief Information Security Officer, Ausgrid Hank Opdam is the Chief Information Security Officer at Ausgrid, leading cybersecurity strategy and risk management for one of Australia’s largest electricity distributors serving Sydney and surrounding regions. With over 25 years of IT experience and more than 18 years in cybersecurity leadership, Hank brings deep expertise in protecting critical infrastructure while fostering a culture of security awareness and shared responsibility. Prior to Ausgrid, Hank held senior security roles including CISO at The Star Entertainment Group and leadership positions at AMP. He is a graduate of the Australian Institute of Company Directors and holds multiple industry certifications such as CISM and CISSP. Hank is a passionate advocate for inclusion, continuous learning, and collaboration within the cybersecurity community, regularly speaking at industry events and mentoring emerging leaders.
Nathan Smith · Head : Cybersecurity Sales APAC, Splunk Nathan Smith is a seasoned cybersecurity leader with over 20 years of experience delivering cutting-edge security, networking, and data solutions. As Head of Cybersecurity Sales APAC at Splunk, he drives strategic go-to-market initiatives and leads high-performing teams to help organizations strengthen their security posture. With expertise spanning enterprise and government sectors, Nathan has held key roles in sales leadership, account management, and business development. His deep technical knowledge in security, cloud, and data convergence enables him to craft tailored solutions that align with business objectives. A thought leader in cybersecurity, Nathan has contributed to industry councils and frequently speaks at conferences. His ability to think strategically and differentiate solutions makes him a trusted advisor in the field. He holds sales certifications across leading technologies, including Splunk, VMware, Cisco, and Check Point, ensuring he stays ahead in an evolving security landscape.
Tara Dharnikota · Chief : Information Security Officer, Victoria University Tara Dharnikota is the Chief Information Security Officer at Victoria University, where she leads cybersecurity strategy and governance across the newly formed Digital and Campus Services division. With over a decade of experience spanning higher education, financial services, and telecommunications, Tara has built a reputation for driving resilient security cultures and embedding cyber risk management into enterprise decision-making. Prior to joining Victoria University, Tara served as Head of Information Security Management at PEXA Group and held senior cybersecurity roles at Telstra. She is an active contributor to the global security community, serving on the GIAC Advisory Board and speaking regularly at industry conferences. Tara holds a Master of Engineering in IT from RMIT University, alongside multiple advanced cybersecurity and networking certifications, and is passionate about shaping the next generation of security leaders.
James Ng · General Manager : Cyber Security (CISO), Insignia Financial James is currently the General Manager Cyber Security (CISO) at Insignia Financial leading the overall cyber strategy and capability across the organisation with experience across technology and information security-focused roles in several organisations, including Telstra, Belong, Tabcorp and Deloitte. Prior to Insignia Financial, James was most recently the General Manager Security Operations at AARNet (Australia Academic and Research Network), where he led teams responsible for establishing cyber governance and providing security operations services.
Maryam Bechtel · Chief : Information Security Officer - General Manager : Cyber Security, AGL As the Chief Information Security Officer at AGL Energy, Maryam Bechtel is responsible for safeguarding one of Australia's most critical infrastructures, ensuring the protection of energy and telecommunications services for over 4 million customers. Before joining AGL in 2022, Maryam led IT security operations at NBN Co for three years. Her career also includes significant roles at Deloitte, Deutsche Telekom, and Saab, where she collaborated with C-level executives across multiple continents to develop and implement comprehensive cybersecurity strategies. Recognised for her leadership and commitment to the cybersecurity community, Maryam was honoured with the Cyber Security Professional of the Year award by the Australian Information Security Association (AISA) in 2022. A passionate advocate for integrating cybersecurity with business objectives, Maryam is dedicated to transforming security from a protective function into a strategic enabler, fostering resilience and trust in the digital age.
Krissie Auld · Chief : Technology Officer, Australian Federal Police Krissie Auld is the Chief Technology Officer at the Australian Federal Police, leading technology strategy and digital transformation initiatives. She previously held senior technology roles at IMB Bank and spent over 20 years in the New South Wales State Government driving major ICT projects. Krissie holds multiple certifications including ISO27001 and is a Graduate Certificate holder in Public Sector Innovation.
Christopher Neal · Group Chief : Information Security Officer, Ramsay Health Care Christopher Neal brings over 20 years of expertise in information security and risk management. As the Global Chief Information Security Officer at Ramsay Health Care, he leads the organisation’s global cybersecurity strategy, safeguarding digital assets and infrastructure across its extensive network of hospitals and healthcare facilities. Neal has driven key initiatives to enhance data security and governance, including the development and implementation of a comprehensive data retention and deletion policy aimed at protecting patient information while meeting operational needs. He champions practical cybersecurity solutions, empowering data owners with self-service tools to manage access permissions efficiently, which improves operational workflows without compromising security. Beyond Ramsay, Christopher contributes to the cybersecurity community as a member of the Innovation Advisory Council at Vation Ventures, collaborating with industry leaders to advance emerging cybersecurity trends.
Mark Harris · Director : Solutions Sales, Diligent With over 30 years of experience in Governance, Risk, and Compliance (GRC) including Enterprise Risk Management, and Internal Audit, Mark Harris brings deep expertise and strategic insight to helping organisations navigate complexity, enhance resilience, and drive performance. He has worked with a number of leading global organisations, including KPMG, EY, Nasdaq and SAI Global, delivering risk transformation programs and advising clients on aligning risk, audit, and compliance strategies with organisational objectives. Mark’s core capabilities include the design and implementation of enterprise GRC frameworks and helping clients assess and deploy GRC technology solutions. He has supported both global and regional organisations across sectors such as financial services, government, mining, telecommunications, property, and hospitality. A passionate advocate for innovation in risk and compliance, Mark champions the use of data-driven insights, automation, and AI-enabled platforms to streamline processes and ensure compliance with evolving regulatory requirements. His mission is to empower organisations to take a proactive, integrated approach to GRC, supporting better decision-making and long-term sustainability.
Miranda Ratajski · Chief : Information Officer, Group Business Units, Westpac Miranda is the CIO of Group Business Units for Westpac. She is a leader of large-scale and complex technological and digital transformations. Miranda has developed strategic and tactical direction, built high-performing teams, and enabled service to uplift customer experiences. Her leadership, focus, and business direction result in improved engagement and productivity through enhanced employee experience, delivering significantly engaged teams who have more time to delight customers. Driving excellence in product delivery is key to having systems that provide the right experience—Miranda has 25 years of global experience and is a master of this craft. Her experience spans Federal Government, Telecommunications, and Financial Services sectors across Europe, Asia, and Australia. Miranda is passionate about diversity and promoting women in technology. Community is a strong anchor for Miranda, and she is also a volunteer yoga teacher. Miranda’s recent awards and nominations include: WiBF Award for Inclusive Leadership Ranked #37 in the Top 100 Women in Finance Technology (Globally) Recognised #9 on the Power List
Marli Lozoya · Producer : Executive, Factor
Partners
- HashiCorp · Bronze
- Splunk · Platinum Splunk helps make organizations more digitally resilient. Leading organizations use our unified security and observability platform to keep their digital systems secure and reliable. Organizations trust Splunk to prevent infrastructure, application and security incidents from becoming major issues, remediate threats and disruptions faster, and adapt quickly to new opportunities. Splunk helps SecOps, ITOps and engineering teams deliver these outcomes with comprehensive visibility, rapid detection and investigation, and optimized response, all accelerated by AI and at the scale necessary for the world's largest organizations.
- Hack the Box · Bronze
- HPE · Bronze
- Exabeam · Gold Exabeam is a leader in intelligence and automation that powers security operations for the world’s smartest companies. As a global cybersecurity innovator, Exabeam provides industry-proven, security-focused, and flexible solutions for faster, more accurate threat detection, investigation, and response (TDIR). Cutting-edge technology enhances security operations center performance, optimizing workflows and accelerating time to resolution. With consistent leadership in AI innovation and a proven track record in security information and event management (SIEM) and user behavior analytics, Exabeam empowers global security teams to combat cyberthreats, mitigate risk, and streamline operations. Learn more at www.exabeam.com.
Quest Software · Gold- Netskope · Platinum Netskope, a leader in modern security and networking, addresses the needs of both security and networking teams by providing optimised access and real-time, context-based security for people, devices, and data anywhere they go. Thousands of customers, including more than 30 of the Fortune 100, trust Netskope to reduce risk and gain full visibility and control over cloud, SaaS, web, and private application activity - providing security and accelerating performance without trade-offs. Netskope solves deeply embedded user experience issues within security architectures in order to remove the barriers that stop organisations optimising their security posture. Netskope prioritises both security and user experience to deliver a modern converged solution that completely reimagines the architecture of security and networking for the era of cloud and AI.
- Ping Identity · Gold
- Phriendly Phishing · Bronze
- Cohesity · Bronze
- Cyera · Platinum
- Diligent · Platinum About Diligent Leading GRC SaaS company with over 1 million users, and more than 700,000 board members from 25,000+ customers worldwide Diligent One Platform that delivers a unified and connected GRC experience. Consolidate all your solutions on the broadest platform for GRC applications designed to deliver comprehensive insights into a single view of risk and associated controls. Helping free you from the unnecessary costs and frustrations of point solutions. How We Help Organizations Diligent provides a full suite of software and services across a number of business functions to help organizations lead with purpose: Audit and Analytics – Deliver strategic advantages through better insights and visibility. Boards and Governance – Connected solutions for better governance in a complex business landscape. ESG and Diversity – Turn ESG initiatives into measurable outcomes. Ethics and Compliance – Enable a purpose driven culture of compliance that protects and drives businesses forward. Risk and Strategy – A single source of truth that helps leaders make risk-informed decisions. Headquartered in New York, Diligent also has offices in Washington D.C., London, Galway, Budapest, Vancouver, Bengaluru, Munich, Singapore and Sydney. Learn more at diligent.com . Follow Diligent on LinkedIn , X (Twitter) and Facebook .
More events from this host
- Security Day | Singapore October 2026, Singapore
- Security Day | Singapore October 2026, Singapore
- Security Day | Sydney October 2026, Barangaroo
- Security Day | Dubai November 2026
- Security Day | Singapore June 2027, Barangaroo
- Security Day | Singapore June 2027
- Security Day | Singapore | Sponsor | Invitations July 2026
- Security Day | Singapore June 2026, Singapore