Skip to main content

This event is now complete

Agenda

Government Cyber Security Showcase Federal

 Wednesday, 12 Nov 2025

Sessions

8:00AM

Registration and Networking Coffee

8:00 AM - 8:45 AM (45 mins)

Exhibition Hall

8:55AM

Opening from Public Sector Network

8:55 AM - 9:00 AM (5 mins)

Royal Theatre

9:00AM
Ministerial Address

Ministerial Address: APS Reform: Reform, AI and delivering for Australians

9:00 AM - 9:30 AM (30 mins)

Royal Theatre

Senator the Hon Katy Gallagher
Minister for Finance, Minister for Women, Minister for the Public Service, Minister for Government Services

Senator the Hon Katy Gallagher will deliver her fourth annual address on APS Reform, as well as explaining how AI will drive the next wave of transformation for the APS to deliver better outcomes for Australians.

This session will explore what the government has already done to promote innovation and explore future opportunities, and how the public service is upskilling itself to capture these benefits to enhance service delivery for Australians.

9:35AM

Chair Opening

9:35 AM - 9:45 AM (10 mins)

Ballroom

Zoe Thompson
Director – Critical Infrastructure Resilience, Thales - Cyber Services
9:45AM
Keynote

National Office of Cyber Security - Insights from major cyber incidents and exercises

9:45 AM - 10:05 AM (20 mins)

Ballroom

Tony Chapman
Deputy National Cyber Security Coordinator and First Assistant Secretary, National Office of Cyber Security

Recent cyber incidents and national exercises have provided valuable lessons on where defences are strong, where vulnerabilities persist and how government and industry can better collaborate in response.

In this keynote, the National Office of Cyber Security will share key insights from recent major incidents and coordinated exercises. The session will highlight:

  • Cybersecurity incidents from the last 12 months
  • Australian cyber security - where we are and what’s next.
  • Strengthening collaboration between government, industry and international partners.
10:05AM
Industry Insights

The trust equation: Balancing innovation and security in a connected world

10:05 AM - 10:25 AM (20 mins)

Ballroom

Nicole Henry
Head of Government Affairs Australia and New Zealand, Fortinet
10:25AM
Panel Discussion

Emerging cyber threats and strategic responses for Australia's Federal Government

10:25 AM - 10:50 AM (25 mins)

Ballroom

Miranda Shaw
Chief Information Security Officer, Australian Bureau of Statistics
Tanya Milczarek
Director, Cyber Services, Department of Agriculture, Fisheries and Forestry
Yifan Zhang
a/g Assistant Secretary, CISO Internal Services and Cyber Branch ICT Division, Department of Finance

From state-sponsored adversaries and supply chain vulnerabilities to the risks introduced by generative AI, the challenges facing federal government agencies are becoming more complex, interconnected and persistent. Protecting sensitive government data, safeguarding citizen trust and ensuring continuity of essential services requires a coordinated and forward-looking approach.

This panel will bring together senior leaders to examine:

  • Addressing the vulnerabilities introduced by interconnected global supply chains and third-party vendors
  • Exploring the growing threats to sensitive government and citizen data.
  • Examining the evolving risks posed by generative AI technologies
10:50AM

Morning Tea / Tech Talk Theatres

10:50 AM - 11:30 AM (40 mins)

Exhibition Hall

11:05AM
Tech Talk

Overcoming Developer Inertia - The Human Side of Security Tool Adoption

11:05 AM - 11:20 AM (15 mins)

Andre Kolodochka
Solutions Engineer, Sonar

Government agencies are investing heavily in code analysis tools (like SonarQube) to secure critical services. This talk confronts the central challenge: Deploying the tool is easy; ensuring developers actually use it is the true test of national cyber resilience. New tools often fail due to behavioral friction, leading to alert fatigue and workflow collisions. This session provides senior leaders with three actionable strategies to convert passive tools into active, trusted parts of the developer mission.

11:25AM
Tech Talk

Discover Plus: No clicks. No screens. Just conversations.

11:25 AM - 11:40 AM (15 mins)

Harry Ryan
Product Owner, R&D LG & Core Service, TechnologyOne

Join us to discover how Plus proactively surfaces insights from your enterprise data, using natural language requests that simplify complex processes into a single conversation, all within a new single interface to manage your entire system.

See how you can supercharge your ERP with Plus

Two tracks · 11:30 AM - 1:20 PM · Pick one and follow it Innovation Track Resilience Track

Innovation Track Resilience Track
11:30AM

11:30 AM - 11:40 AM (10 mins) Industry Insights

11:30AM
Innovation Track

Opening track chair

11:30 AM - 11:40 AM (10 mins)

Ballroom

Zoe Thompson
Director – Critical Infrastructure Resilience, Thales - Cyber Services
11:30AM
Resilience Track

Opening track chair

11:30 AM - 11:40 AM (10 mins)

Fitzroy/Murray

Judy Hurditch
Managing Director and Principal Analyst, Intermedium
11:40AM

11:40 AM - 12:00 PM (20 mins) Keynote

11:40AM
Innovation Track

Strategies to bolster female participation in the cyber workforce for optimised outcomes

11:40 AM - 12:00 PM (20 mins)

Ballroom

Miranda Shaw
Chief Information Security Officer, Australian Bureau of Statistics

Australia’s cyber workforce is facing critical skills shortages at the same time as the threat landscape grows in scale and complexity. Yet women remain significantly underrepresented across cyber roles, limiting the diversity of perspectives needed to address evolving risks. Boosting female participation is not simply a matter of equity—it is a strategic imperative for capability, innovation and resilience.

This session will explore:

  • Unlock diverse thinking to strengthen problem-solving and innovation in cybersecurity.
  • Close the skills gap by tapping into an underrepresented and capable talent pool.
  • Boost performance through inclusive teams proven to deliver stronger outcomes.
11:40AM
Resilience Track

The role of the AFP-led Australian Centre to Counter Child Exploitation (ACCCE) in combatting online child exploitation.

11:40 AM - 12:00 PM (20 mins)

Fitzroy/Murray

Helen Schneider
Commander, Australian Federal Police

The Australian Centre to Counter Child Exploitation (ACCCE) plays a pivotal role in safeguarding children from one of the most confronting threats in the digital age: online exploitation. As technology advances, so too do the methods used by offenders—requiring government, law enforcement and industry to continually evolve their defences.

This session will examine how the ACCCE is working to disrupt criminal networks, protect children and strengthen national cyber resilience through:

  • Harnessing intelligence and analytics to proactively identify, monitor and disrupt online threats targeting children across digital platforms
  • Enhancing cross-agency collaboration between law enforcement and cyber teams to respond faster and more effectively
  • Exploring the role of emerging technologies — including AI and encrypted data analysis — in strengthening early threat detection and prevention efforts
12:00PM

12:00 PM - 12:20 PM (20 mins) Industry Insights

12:00PM
Innovation Track

From Audits to Automation: Continuous Compliance for Secure-by-Design Government

12:00 PM - 12:20 PM (20 mins)

Ballroom

Ken Melero
Regional Vice President Public Sector - Global, Chainguard

Federal agencies are required to prove compliance while accelerating digital delivery. Yet traditional, audit-based approaches to IRAP, PSPF and Essential Eight compliance weren’t designed for today’s cloud-native environments. This session explores how teams can build compliance into every stage of development - turning constant audits into automated assurance.

Learn how leading agencies and partners are operationalising continuous compliance across cloud and containerised systems to strengthen their Secure-by-Design maturity and reduce manual overhead.

Key Takeaways:

  • Practical ways to align Essential Eight controls to modern architectures.
  • How to automate compliance evidence collection across CI/CD pipelines.
  • Lessons from early adopters moving toward continuous assurance models.
12:00PM
Resilience Track

The Future of Trust: Governing Humans, Machines and AI Agents in the Digital Age

12:00 PM - 12:20 PM (20 mins)

Fitzroy/Murray

Michael Smith
Identity Security Lead, SailPoint

As automation and artificial intelligence become embedded across the Australian Public Sector, the concept of identity now extends far beyond people. Modern government environments contain vast numbers of machine identities, APIs, service accounts and autonomous agents, each capable of accessing data, executing actions and influencing decisions.

While these non-human identities are critical to digital transformation, most operate without clear ownership, oversight or lifecycle management. Many agencies now manage more machine identities than human ones, yet few have established custodianship or governance frameworks to match. This creates significant challenges for auditability, accountability and public trust.

This session explores how Identity Security can provide the foundation for trusted and transparent automation within government. Drawing on practical examples, it examines how agencies can:

  • Govern AI and machine identities through identity-based controls
  • Achieve auditable AI decision making and continuous compliance
  • Ensure every digital actor, human or non-human, is observable and accountable
  • Enhance resilience and assurance without constraining innovation

Ultimately, trust in the digital state depends on knowing not just who has access, but what has access, and ensuring every human, system and AI agent operates under accountable, identity-driven governance.

12:20PM

12:20 PM - 12:40 PM (20 mins) Panel Discussion

12:20PM
Innovation Track

The future of secure digital government services

12:20 PM - 12:40 PM (20 mins)

Ballroom

Jamie Rossato
Chief Information Security Officer, CSIRO
Dimitar Dimitrovski
Chief Information Officer, Fair Work Ombudsman
Zoe Thompson Facilitator
Director – Critical Infrastructure Resilience, Thales - Cyber Services

Secure and trusted online services are fundamental to citizen confidence and effective government. From payments and licensing to healthcare and social services, government systems are becoming more connected, data-driven and AI-enabled, bringing both opportunities and new risks.

This panel will discuss:

  • Ensuring security and usability in government digital transformation.
  • Embedding security into citizen-facing digital platforms.
  • Protecting sensitive government data from evolving cyber threats.
12:20PM
Resilience Track

Australia as a cyber powerhouse: Leading in innovation & resilience

12:20 PM - 12:40 PM (20 mins)

Fitzroy/Murray

Anne-Louise Brown
Head of Strategy and Insights, Akin Agency and Former Director of Policy, Cyber Security Cooperative Research Centre
Daminda Kumara
Chief Information Security Officer, Commonwealth Superannuation Corporation
Judy Hurditch Facilitator
Managing Director and Principal Analyst, Intermedium

Australia is uniquely positioned to lead on the global cyber stage—leveraging a world-class research community, innovative public-private partnerships and a government agenda that prioritises both resilience and trust. Yet, as threat actors grow more sophisticated, the challenge is not just to keep pace, but to set the pace.

This panel will unpack:

  • Positioning Australia as a leader in global cyber security.
  • Investing in homegrown cybersecurity research and technology.
  • Strengthening public-private partnerships to drive national resilience.
12:40PM

12:40 PM - 1:00 PM (20 mins) Industry Insights

12:40PM
Innovation Track

Cyber Resilience & Organisational Uptime Using Microsegmentation

12:40 PM - 1:00 PM (20 mins)

Ballroom

Raja Ukil
Senior Vice President APAC and Global Head GSI Alliances, ColorTokens
12:40PM
Resilience Track

Operational Resilience needs Cyber Resilience. What to do when the unexpected happens?

12:40 PM - 1:00 PM (20 mins)

Fitzroy/Murray

Nathan Smith
Head of Security, APJC, Splunk

Key takeaways from this session:

  • Understanding the impact of downtime when the unexpected happens
  • What Strategies should you implement?
  • What is the blueprint for success?
1:00PM

1:00 PM - 1:20 PM (20 mins)

1:00PM
Interactive Innovation Track

Securing the supply chain: Managing third-Party risk in government

1:00 PM - 1:20 PM (20 mins)

Ballroom

Dr Rosetta Romano
President, Association for Information Systems, Special Interest Group, Education and Assistant Professor, Information Technology and Systems, Information Systems Capability Faculty of Science and Technology, University of Canberra

Government agencies rely on a complex network of suppliers, contractors and service providers. While these partnerships drive efficiency, they also introduce significant security risks.

Come prepared with your questions and real-world scenarios — This interactive session will explore practical strategies to identify, assess, and mitigate third-party risks, ensuring your supply chain remains secure and resilient.

  • Assessing third-party dependencies to uncover hidden vulnerabilities.
  • Strengthen procurement and compliance frameworks to enforce risk controls.
  • Building resilience through continuous monitoring and shared intelligence.
1:00PM
Keynote Resilience Track

Building Capacity and Collaboration Amongst Like-Minded Partners: Addressing Shared Challenges and Leveraging Shared Opportunities

1:00 PM - 1:20 PM (20 mins)

Fitzroy/Murray

James Corera
Director - Cyber, Technology and Security, Australian Strategic Policy Institute

In today’s complex environment, organisations and agencies face challenges that extend beyond individual capabilities. This session focuses on fostering collaboration and building capacity among partners with aligned goals. Participants will explore strategies to tackle shared challenges, maximise collective strengths, and uncover opportunities for joint innovation and impact.

Through discussion and knowledge sharing, attendees will gain practical insights into:

  • Countering threats through collaboration.
  • Building resilience by focusing on adaptive responses and policies.
  • Fostering innovation by illuminating risks to intellectual property and critical and emerging technologies
1:20PM

Lunch / Tech Talk Theatre

1:20 PM - 2:20 PM (60 mins)

Exhibition Hall

1:35PM
Tech Talk

How Not to Get Hacked: Turning Threat Intelligence Into Real-Time Defense

1:35 PM - 1:50 PM (15 mins)

Ben Menzies
Senior Sales Engineer, Recorded Future

Federal agencies are flooded with threat data but struggle to act on it. This session explores how Recorded Future enables security teams to automate, prioritise, and operationalise intelligence at mission speed. Learn how to cut through noise, enrich workflows, and accelerate decisions, turning threat intelligence into a force multiplier for cyber defense.

2:20PM

Choose one · 2:20 PM - 3:20 PM (60 mins) · 8 options Roundtables

2:20PM

Roundtable 1: Future-proofing our nation's critical infrastructure through collaboration and supply chain management

2:20 PM - 3:20 PM (60 mins)

Ballroom

Zoe Thompson Facilitator
Director – Critical Infrastructure Resilience, Thales - Cyber Services
Mitchell Loughlan Facilitator
Director - Risk & Resilience, Critical Infrastructure, Thales - Cyber Services

A trusted future relies on effectively managing third-party dependencies within critical infrastructure operations, many of which remain unseen and underestimated.

To ensure resilience, we must take a comprehensive approach to security, spanning physical, cyber, supply chain, and personnel risks.

In this roundtable, we will explore:

  • The current state of Critical Infrastructure and its evolving security landscape.
  • The critical impact of third-party risks, highlighting sector-specific examples and the importance of a robust risk management framework.
  • Strategies to prioritise supplier diversification, including the role of sovereign suppliers in enhancing national security.

As nationally significant operators, Critical Infrastructure providers must cultivate strong local partnerships with vendors, service providers, and industry leaders to build a more secure and resilient future.

2:20PM

Roundtable 2: Cybersecurity in action: Proactive security & AI for government agencies

2:20 PM - 3:20 PM (60 mins)

Ballroom

Martyn Beal Facilitator
Federal Government Lead, Trend Micro
Andrew Philp Facilitator
Field CISO, ANZ, TrendAI™
  • Engage with real-world challenges – Cyber-attacks on Federal agencies are increasing. How prepared is your organisation?
  • Vote and debate – Share your stance on key cybersecurity issues and discuss solutions with peers.
  • Turn insights into action – Explore AI-driven security and best practices to strengthen cyber resilience in your agency.
  • What "Proactive Cybersecurity" measures do you take now?
  • How well do you believe you are progressing to meet the 2023-2030 Australian Cyber Security Strategy from Home Affairs
  • Could you show your Deputy Secretary/Minister a Cyber risk score across your organisation?
2:20PM

Roundtable 3: The Invisible Threat: Who or What Has Access in Your Agency

2:20 PM - 3:20 PM (60 mins)

Ballroom

Michael Smith Facilitator
Identity Security Lead, SailPoint
Nicholas Harris Facilitator
Manager Federal Government, SailPoint

Non-Human Identities and automated systems are rapidly transforming public sector operations. However, as AI agents begin to initiate actions, make decisions and access sensitive data across government systems, the traditional concept of identity is no longer limited to people. This roundtable will explore how agencies can maintain accountability, transparency and control in an environment where both humans and machines are operating at speed and scale.

Discussion Themes

  • How can agencies maintain clear lines of accountability as automated decision-making increases across programs and service delivery
  • Do you have full visibility of who or what has access to your critical systems and data today
  • Should AI agents be governed as identities with roles, attributes and permissions similar to human users
  • How can explainability and auditability be embedded into AI enabled processes for compliance and assurance
  • What safeguards are required before granting AI agents access to sensitive information or privileged actions
  • What capability uplift will be required across the APS to govern machine scale access and identity risk
  • Looking ahead to 2030 what does trusted automation and secure identity assurance look like across the Australian Government
2:20PM

Roundtable 4: From Policy to Practice: What the 2025 PSFP Changes Mean for Government as Critical Infrastructure Now and in the Future

2:20 PM - 3:20 PM (60 mins)

Ballroom

Sarah Sloan Facilitator
Senior Director, Government Strategy Asia, the Pacific and Japan, Splunk
  • Unpack the 2025 Protective Security Policy Framework (PSPF) updates and what they mean for federal, state, and territory agencies.
  • Explore new PSPF guidance on managing AI and other risks, adopting Zero Trust security, and preparing for quantum threats.
  • Gain insights into potential government cyber security priorities, and changes under Horizon 2 of the Cyber Security Strategy.
2:20PM

Roundtable 5: Securing the Software Supply Chain: Evolving regulations to account for modern software risks

2:20 PM - 3:20 PM (60 mins)

Ballroom

Ken Melero Facilitator
Regional Vice President Public Sector - Global, Chainguard
Mike Pamphilon Facilitator
Defence & Defence Industry Lead APAC, Chainguard

As government agencies and firms providing software to the government agencies accelerate their adoption of cloud-native architectures and open source components, traditional compliance and assurance models are struggling to keep pace with modern software delivery.

In this roundtable, we will explore how to modernise regulatory guardrails to meet the realities of continuous delivery, open source dependencies, and cyber resilience, and how we can ensure that rules truly raise the security floor for both organisations and citizens.

Key Topics to Be Covered:

  • Why it’s critical to account for cloud-native, DevSecOps paradigms
  • Integrating supply chain security (SBOMs, provenance, cryptographic integrity) into compliance
  • Balancing prescriptiveness vs flexibility in government security policy
  • Measuring real security impact—how do we know regulation is making us safer?
2:20PM

Roundtable 6: Maintaining Organisational Uptime During a Cyber-Attack

2:20 PM - 3:20 PM (60 mins)

Ballroom

Daniel Churches Facilitator
Sales Director, ColorTokens

Australia’s new Cyber Security Act 2024 and updated SOCI Act have raised the stakes for government agencies, with penalties of up to $50 million for non-compliance. Traditional defence-only strategies are no longer sufficient—federal agencies must shift to “breach-ready” architectures that ensure continuity of critical services during an attack.

This closed-door roundtable will explore how agencies can bridge the gap between policy frameworks and operational resilience. Participants will engage with an evidence-based approach to legislative compliance, risk reduction, and business continuity planning that leverages existing investments rather than requiring full infrastructure replacement.

Discussion Focus

  • Meeting new compliance requirements with confidence
  • Why EDR, NDR, and firewalls alone won’t keep services running
  • Designing breach-ready architectures for minimum viability and rapid recovery
  • Resource planning and implementation strategies

Key Benefits

Gain a clear roadmap to compliance, methodologies to maintain uptime during cyber incidents, strategies to minimise penalties and data risk, and cost-effective pathways to resilience.

2:20PM

Roundtable 7: How to combat offensive AI: Defending government apps and APIs from smarter cyber threats

2:20 PM - 3:20 PM (60 mins)

Ballroom

Graeme Queen Facilitator
Regional Sales Manager, Radware

AI is now a weapon in the hands of bad actors—creating self-morphing malware, automating breaches, and outpacing legacy defences. This session will show you how to embed AI in your security posture so you can stay ahead of evolving threats, protect exposed APIs, and boost resilience with limited resources.

  • Explore how AI is being weaponised to evade traditional government cyber defences
  • Unpack why AI adoption remains low despite rising threat levels
  • Identify where your third-party APIs are most vulnerable to exploitation
  • Discover how AI can offset the growing cyber skills shortage
  • Learn how to integrate AI into your detection and response architecture
2:20PM

Roundtable 8: Beyond the Bin: Making Federal ICT End-of-Life Disposal Safe, Auditable and Sustainable

2:20 PM - 3:20 PM (60 mins)

Ballroom

Duncan Inkster Facilitator
Chief Growth Officer, WV Technologies

Everyone is worried about the front door. We’re worried about the back door. Because building cyber resilience across Australia doesn’t end when a device is retired. Cybersecurity matters from start to finish - so how are the nation’s governments, and enterprises addressing end of life cyber vulnerabilities in devices?And are we doing it right?

We’ll explore:

  • The hidden risks in your end-of-life ICT equipment - who is left exposed, non-compliant, and vulnerable to attack.
  • How do the right strategies on end-of-life decommissioning/disposal impact overarching government goals
    • ESG – Scope 3, Circularity, Sustainability
    • Reconciliation Action Plans
    • Indigenous Procurement
3:20PM
Fireside Chat

AI Risks — Safeguarding Services and National Security

3:20 PM - 3:40 PM (20 mins)

Ballroom

James Kay
Assistant Director-General, Standards, Technical Advice and Research, Australian Signals Directorate

Artificial intelligence is reshaping the cyber threat landscape, creating brand-new risks for government services and national security. As adversaries adopt AI-driven tactics, agencies must act now to build resilience and maintain citizen trust.

• Unpack brand-new risks.  How is AI reshaping the Australian cyber threat landscape.
• Gain forward-looking insights — hear what government is seeing now that will shape defences in the next 12–18 months.
• Practical steps agencies can take today to stay ahead of AI-driven adversaries.

3:40PM
Industry Insights

Navigating cybersecurity’s future: Advancing proactive security across Australian government agencies

3:40 PM - 4:00 PM (20 mins)

Ballroom

Andrew Philp
Field CISO, ANZ, TrendAI™
  • Escalating cyber threats nationwide – Government agencies across Australia face a growing volume and sophistication of cyber attacks. Proactive security measures are critical to safeguarding public sector systems and citizen data.
  • Quantifying and managing cyber risk – Government audits show agencies with structured risk assessments and proactive security drills are far more resilient. Learn how to measure and mitigate cyber risk effectively.
  • AI-driven security – The ACSC recommends shifting to proactive, AI-enhanced risk management. Explore how AI can help detect threats faster, automate responses, and strengthen security across public sector systems.
4:00PM
Keynote

Policy Development of Horizon 2 of the Government Cyber Security Strategy

4:00 PM - 4:20 PM (20 mins)

Ballroom

Ash Bell
Assistant Secretary - Cyber Policy, Department of Home Affairs

Australia’s Cyber Security Strategy sets an ambitious roadmap for strengthening national resilience against evolving threats. As Horizon 2 moves into focus, the policy work underway will determine how government, industry and citizens collectively prepare for the next wave of challenges. Ash Bell from the Department of Home Affairs will share insights into the development process, the priorities shaping Horizon 2 and how delegates can align their agency strategies with national objectives.

  • Key policy considerations driving the next stage of the Cyber Security Strategy and what they mean for government agencies.
  • How policy decisions translate into practical outcomes for cyber resilience, service delivery, and workforce readiness.
  • The role of interagency collaboration, industry partnerships, and community engagement in securing Australia’s digital future.
4:20PM
Panel Discussion

Strength in diversity: Unlocking cyber security’s full potential

4:20 PM - 4:45 PM (25 mins)

Ballroom

The Hon. Victor Dominello
Chief Executive Officer, Future Government Institute
Jacqui Loustau
AWSN Executive Director, Australian Women in Security Network
Shyvone Forster
Director - Cyber Operations, Department of Home Affairs

This Panel explores how fostering diversity across skills, backgrounds and thought can strengthen cyber resilience, drive innovation and uncover creative solutions to complex threats.

Panelists will discuss:

  • How diversity can bring fresh perspectives to security challenges.
  • Why increasing gender, cultural and neurodiverse representation leads to stronger, more adaptive threat response.
  • Practical steps for government to create inclusive hiring practices, career pathways and leadership opportunities.
4:45PM
Industry Insights

Closing remarks

4:45 PM - 4:55 PM (10 mins)

Ballroom

Zoe Thompson
Director – Critical Infrastructure Resilience, Thales - Cyber Services
4:55PM

Networking drinks

4:55 PM - 5:55 PM (60 mins)

Exhibition Hall

Questions?

See our FAQs or get in touch