Government Cyber Security Showcase Queensland 2026
Sessions
Registration, Coffee & Hellos
8:00 AM - 8:50 AM (50 mins)
Settle in, grab a coffee, and meet a few friendly faces before we begin.
Welcome & How to Make the Most of Today
8:50 AM - 9:00 AM (10 mins)
A short welcome, plus a few quick tips to help you connect, share, and get real value from the day. We’ll also run a couple of quick polls to see what everyone’s interested in and what people are working on right now.
Ministerial Address
9:00 AM - 9:10 AM (10 mins)
Chair's Opening Remarks
9:10 AM - 9:20 AM (10 mins)
A short briefing from the Chair to get everyone aligned, comfortable, and ready for a great day of ideas and connection.
Turning Strategy into Action: Advancing Queensland’s Cyber Security Priorities
9:20 AM - 9:40 AM (20 mins)
As Queensland continues to implement its Cyber Security Strategy, attention is shifting from policy and planning to delivery across government systems, services and infrastructure. This session will explore how agencies are progressing key initiatives, strengthening coordination across government, and embedding cyber security into digital service delivery. It will highlight early progress, emerging lessons and how Queensland can sustain momentum as cyber threats continue to evolve.
- Strengthening whole-of-government coordination to accelerate cyber maturity across agencies
- Progress and lessons emerging from early implementation of Queensland’s cyber priorities
- Embedding cyber security into the design and delivery of digital government services
- Sustaining momentum and capability as Queensland prepares for an increasingly complex cyber environment
Industry Insights - Presented by Sailpoint
9:40 AM - 10:00 AM (20 mins)
Vendors, Platforms, Partners: Strengthening Resilience and Response Across the Supply Chain
10:00 AM - 10:30 AM (30 mins)
As agencies depend on more SaaS platforms, managed providers and digital partners, supply chain cyber security now relies on shared resilience, not just stronger contracts or controls. This session explores how public sector organisations and their vendors can prepare for disruption, clarify responsibilities and work together when a third-party incident affects critical services.
- Strengthen resilience across critical vendors, platforms and managed service partners.
- Move beyond traditional assurance, including ISO certification, SOC 2 reports and contract clauses.
- Clarify shared responsibilities across SaaS, cloud and outsourced service models.
- Plan for longer outages, limited visibility and unclear escalation paths.
- Use trusted networks, sector collaboration and vendor partnerships to support response and recovery.
Industry Insights - Modernising Cyber Guardrails Against an Evolving AI-Driven Threat
10:30 AM - 10:50 AM (20 mins)
Artificial intelligence is transforming the way government operates, innovates and builds trust. It is also reshaping the cyber threat landscape. Cybercriminals are using AI to automate attacks, craft convincing phishing campaigns, evade traditional security controls, and accelerate the speed and scale of compromise. As AI adoption grows across government and critical infrastructure, legacy security frameworks are struggling to keep pace. This session explores how agencies can modernise their cyber guardrails for an AI-driven threat environment. It examines the risks of generative AI, autonomous attack techniques and increasingly sophisticated adversaries, and shares practical strategies to strengthen resilience.
Morning Tea & Mingling
10:50 AM - 11:35 AM (45 mins)
Perfect time to swap notes and compare what’s working across teams and sectors
Human Error, Real Harm: Rethinking Risk and Response Under MNDB
11:35 AM - 12:00 PM (25 mins)
MNDB is now one year in and has recently been extended to local government, with agencies beginning to see its real-world impact. While the framework itself is clear, applying it in practice is proving more complex—particularly when it comes to assessing breaches, determining what constitutes “serious harm,” and coordinating effective responses. These challenges are reshaping how agencies approach breach management and accountability, while driving more consistent and coordinated decision-making during incidents.
- Applying MNDB in practice: assessing breaches and determining “serious harm”
- Strengthening breach response, incident management and coordinated decision-making
- Embedding risk assessment and secure-by-design to build resilient digital services
- Enhancing whole-of-government collaboration to strengthen resilience and maintain public trust
Industry Insights
12:00 PM - 12:20 PM (20 mins)
Future Proofing Cyber Security: Why Culture, Trust and Human Behaviour Define Cyber Resilience
12:20 PM - 1:00 PM (40 mins)
As cyber threats continue to evolve, organisations are recognising that resilience extends beyond technology alone. Many of the greatest risks, and opportunities, sit within people, behaviours and organisational culture. This discussion will explore how trust, leadership and accountability can strengthen cyber resilience, while balancing secure systems with the usability needed to deliver effective digital services. .
- Moving beyond a technology-first mindset: why tools alone cannot mitigate cyber risk
- Understanding human behaviour as a core driver of vulnerability and resilience
- Embedding a culture of security through education, accountability and leadership
- Balancing trust, usability and safeguarding in the delivery of digital services
The Future of Encryption: Preparing Government for the 2030 Post-Quantum Shift
1:00 PM - 1:20 PM (20 mins)
As quantum computing accelerates, the security foundations that underpin today’s digital government are being fundamentally challenged. With a national shift towards post-quantum cryptography mandated by 2030, government agencies must begin preparing now to ensure sensitive data, critical infrastructure and citizen services remain secure in the decades ahead.
- What the 2030 post-quantum mandate means for government policy, systems and long-term data security
- Identifying cryptographic risk across legacy systems, infrastructure and supply chains
- Preparing for “harvest now, decrypt later” threats and protecting sensitive data over time
- Embedding cryptographic agility into digital infrastructure, procurement and transformation programs
- Building a practical roadmap for transitioning to quantum-safe encryption across government
Lunch: Wander, Discover, Connect
1:20 PM - 2:20 PM (60 mins)
Grab lunch, have a wander, and chat with industry partners and peers about practical ideas you can take back to work. Arguably the most important part of the day!
Choose one · 2:20 PM - 3:20 PM (60 mins) · 7 options Roundtables
Roundtable 1: Preventing Agentic AI from Exceeding Its Role - Facilitated by Airlock Digital
2:20 PM - 3:20 PM (60 mins)
Roundtable 2: Doing More with Less: Prioritising Cyber Investment for Maximum Impact
2:20 PM - 3:20 PM (60 mins)
Explore how government cyber leaders can make smarter security investment decisions amid tightening budgets and growing threats. This session examines how to prioritise investment for maximum impact, demonstrate cyber security value and strengthen resilience, while also exploring practical approaches to quantifying risk and delivering measurable outcomes.
Roundtable 3: Cyber Risk You Don't Own: Third-Party and Supply Chain Assurance Across Queensland Government
2:20 PM - 3:20 PM (60 mins)
Government agencies increasingly depend on vendors, cloud providers and delivery partners to deliver critical services, yet when a supplier fails, the accountability stays with the agency. This session explores how agencies can build genuine assurance over third-party risk, from vendor onboarding and contract controls through to responding when a supplier is breached.
Roundtable 5: AI vs. AI: Defending Government Systems Against Machine-Driven Attacks
2:20 PM - 3:20 PM (60 mins)
With adversaries weaponising AI, agencies must evolve their defences. This session examines how AI/ML can detect, predict and counter novel threats faster than human-only teams.
Roundtable 6: Keeping Queensland Running: Cyber Resilience for Critical Services Ahead of 2032
2:20 PM - 3:20 PM (60 mins)
From transport and energy to health and education, Queensland's essential services now run on connected systems that can't afford downtime. With Brisbane 2032 fixing a hard deadline for readiness, this session explores how agencies can protect the systems citizens rely on every day, build resilience across converged environments, and keep services running when incidents occur.
Roundtable 7: 84% of Breaches Start with Identity — Practical First steps for government agencies
2:20 PM - 3:20 PM (60 mins)
The traditional network perimeter has dissolved. Government is now borderless - spanning contractors, partners, legacy platforms, SaaS, and emerging AI systems. With the majority of breaches originating from compromised or misused credentials, identity has become the primary control point for cyber resilience.
This roundtable will explore how agencies can reduce breach risk by improving identity visibility, enforcing least privilege, and operationalizing zero trust in complex environments. Discussion will also address the challenge of balancing compliance obligations with seamless access, while managing cost pressures and operational efficiency.
Roundtable 8: From Audit Finding to Assurance: Getting Ahead of the Cyber Audit Cycle
2:20 PM - 3:20 PM (60 mins)
Queensland agencies face growing scrutiny of their cyber posture from auditors, executives and central agencies, yet most are still assembling evidence manually after the fact. This session explores how agencies can maintain a continuous, accurate picture of their exposure, turn it into reporting that executives and auditors trust, and fix the issues that matter before they become findings.
To be confirmed
3:20 PM - 3:40 PM (20 mins)
Securing Brisbane 2032 on the World Stage: From Global Insight to Local Execution
3:40 PM - 4:10 PM (30 mins)
Brisbane 2032 will place Queensland’s digital services, public safety systems and critical infrastructure under global scrutiny. This session will explore how cyber security, operational planning and cross-sector coordination can support secure delivery at scale, from protecting essential services to maintaining public trust during a globally significant event.
- Strengthening cyber governance and operational readiness for Brisbane 2032
- Coordinating security across Games delivery, emergency services and critical infrastructure
- Preparing for high-impact incidents through prevention, monitoring, response and recovery planning
- Protecting public-facing systems, essential services and trusted information during a globally significant event
Closing Remarks: What We're Taking With Us
4:10 PM - 4:20 PM (10 mins)
We’ll pull out a few highlights from the day, share what’s coming next, and point you to ways to stay connected.
Networking Reception: Stay for a Chat
4:20 PM - 5:20 PM (60 mins)
Wrap up the day with good conversation and a few new connections. Thanks for making GIW your one-stop shop for benchmarking, industry updates, and great conversations.