Skip to main content

Agenda |

Victoria 2027

Government Cyber Security Showcase Victoria 2027

 Thursday, 18 Mar 2027

TapClick any track name on a session to show only that track. TapClick a highlighted track name, or choose All tracks, to see everything again. This track runs as its own stream below the main agenda. Jump to it, or choose All tracks to see everything again.

Sessions

8:00AM

Registration, Coffee & Hellos

8:00 AM - 9:00 AM (60 mins)

Settle in, grab a coffee, and meet a few friendly faces before we begin.

8:45AM

Welcome & How to Make the Most of Today

8:45 AM - 8:55 AM (10 mins)

A short welcome, plus a few quick tips to help you connect, share, and get real value from the day. We’ll also run a couple of quick polls to see what everyone’s interested in and what people are working on right now.

9:00AM

Chair Opening

9:00 AM - 9:10 AM (10 mins)

9:10AM
Ministerial Address

Ministerial Address

9:10 AM - 9:20 AM (10 mins)

9:20AM
Keynote

Cyber Response in Practice: What We've Learned and What Comes Next

9:20 AM - 9:40 AM (20 mins)

Matt Wong
Assistant Secretary, National Office of Cyber Security, Department of Home Affairs

As cyber threats become more complex and technology adoption accelerates, agencies must build confidence in their ability to protect services, manage risk and maintain public trust. This keynote explores how Victoria is strengthening cyber resilience through leadership, governance and whole-of-government collaboration.

  • Moving beyond cyber security as an IT function towards organisational resilience
  • Embedding cyber risk into risk-based investment, governance and service delivery
  • Strengthening confidence in essential government services
  • Protecting critical public services and community trust
9:40AM
Industry Insights

Protecting Critical Infrastructure from AI-Powered Ransomware

9:40 AM - 10:00 AM (20 mins)

10:00AM
Panel Discussion

When Government Can’t Go Offline: Keeping Essential Services Running Through Cyber Disruption

10:00 AM - 10:30 AM (30 mins)

With government increasingly dependent on connected digital services, cyber disruption can quickly become an operational and service delivery challenge, not simply a technology issue. For government leaders, the question is no longer whether an incident can be contained, but how essential services continue when systems, data or critical dependencies are under pressure.

Bringing together senior leaders from across Australia, this discussion will explore:

  • How government determines what must continue, what can operate in a degraded state and where the greatest dependencies sit.
  • Strengthening coordination between CISOs, executives, operational teams and critical service owners before disruption occurs.
  • What exercises, incidents and cross-jurisdictional experience are revealing about preparedness, recovery and the gaps government needs to address now.
10:30AM
Industry Insights

The Intelligence Advantage: Turning Threat Signals Into Better Security Decisions

10:30 AM - 10:50 AM (20 mins)

10:50AM

Morning Tea & Mingling

10:50 AM - 11:30 AM (40 mins)

It's time to grab a coffee - connect, recharge and explore our exhibition floor before the next discussions begin!

10:50AM

Morning Tea & Mingling

10:50 AM - 11:30 AM (40 mins)

It's time to grab a coffee - connect, recharge and explore our exhibition floor before the next discussions begin!

Two tracks · 11:30 AM - 1:10 PM · Pick one and follow it

11:30AM

11:30 AM - 11:40 AM (10 mins)

11:30AM

Welcome from Track Chair

11:30 AM - 11:40 AM (10 mins)

Setting the tone for the priorities and thorniest challenges facing cyber governance, strategy and risk professionals.

11:30AM

Welcome from Track Chair

11:30 AM - 11:40 AM (10 mins)

Setting the tone for the priorities and thorniest challenges facing cyber governance, strategy and risk professionals.

11:40AM

11:40 AM - 12:00 PM (20 mins) Keynote

11:40AM

Building Victoria’s AI Future – Strategy, Trust and Critical Infrastructure Resilience

11:40 AM - 12:00 PM (20 mins)

Portfolio Director – Business Enablement - Enterprise Planning and Delivery, VicGrid

As Victoria develops its approach to artificial intelligence, government agencies and critical infrastructure operators must balance innovation with security, resilience and public trust. The next phase requires a coordinated strategy that enables responsible AI adoption while strengthening the foundations that keep essential services operating.

  • Developing a Victorian AI strategy that supports innovation, accountability and public confidence
  • Ensuring critical infrastructure is prepared for AI-driven opportunities and emerging risks
  • Embedding responsible AI governance into investment, operational and risk decision-making
11:40AM

Cyber Budget Chronicles: Success and Failures

11:40 AM - 12:00 PM (20 mins)

Executive Director Information Security and Data Governance, Court Services Victoria

Securing funding for cyber programs can be just as challenging as delivering them. This practical session shares real lessons from winning investment for cyber initiatives, what has worked, what has not and how to build a compelling case for funding in a competitive government environment.

  • Translating cyber risk into language that resonates with executives, finance and decision makers.
  • The strategies, evidence and approaches that can turn cyber priorities into funded programs.
  • What did not work, common funding mistakes and how to strengthen the next funding pitch.
12:00PM

12:00 PM - 12:20 PM (20 mins) Industry Insights

12:00PM

Supply Chain Blind Spots: Tackling Third-Party Risk in Government

12:00 PM - 12:20 PM (20 mins)

12:00PM

AI vs. AI: Defending Government Systems Against Machine-Driven Attacks

12:00 PM - 12:20 PM (20 mins)

12:20PM

12:20 PM - 12:50 PM (30 mins) Panel Discussion

12:20PM

Cyber Leadership Beyond the CISO to Build Organisation-Wide Accountability

12:20 PM - 12:50 PM (30 mins)

Tara Dharnikota
Chief Information Security Officer, Victorian University

Cyber security responsibility is expanding beyond technical teams. This panel explores how executives, business leaders and frontline teams can work together to create stronger cyber cultures and shared accountability.

  • Improving executive cyber literacy
  • Building security ownership across agencies
  • Creating stronger partnerships between business and technology teams
12:20PM

Operating in an Era of Intelligent Threats

12:20 PM - 12:50 PM (30 mins)

Co Chair - National Committee For Information Access & Protection Requirements and Information Security Leader, State Trustees (Victoria)
Business & Cyber Resilience Manager, Victoria Legal Aid
Sharif Abuadbba
Team Leader, Distributed Systems and Security, Data61, CSIRO

Threat actors are increasingly leveraging automation, artificial intelligence and sophisticated techniques to target government environments. This session explores how agencies can adapt their security strategies to anticipate emerging threats while maintaining operational agility.

  • Understanding the changing threat landscape
  • Preparing for AI-enabled attacks
  • Strengthening proactive defence strategies
  • SaaS compromise / identity abuse / data extortion
12:50PM

12:50 PM - 1:10 PM (20 mins) Industry Insights

12:50PM

Secure-by-Design Cloud Transformation for Victorian Agencies

12:50 PM - 1:10 PM (20 mins)

12:50PM

Identity at the Core: Securing Access in a Borderless Government

12:50 PM - 1:10 PM (20 mins)

12:50PM

12:50 PM - 1:10 PM (20 mins) Keynote

12:50PM

Cutting Through the Noise: What Should Cyber Leaders Really Be Focusing On?

12:50 PM - 1:10 PM (20 mins)

Dr Greg Adamson
Portfolio Chief Information Security Officer, Department of Transport and Planning Victoria

From AI-driven attacks and ransomware to quantum computing and evolving regulation, cyber leaders are faced with a constant stream of new risks, predictions and competing priorities. This session explores how Victorian government leaders are separating genuine strategic risks from short-term hype.

  • Distinguishing emerging risks from industry hype and media headlines
  • Prioritising investment in a rapidly evolving threat landscape
  • Balancing immediate operational pressures with long-term cyber resilience
  • Defining what success looks like for government cyber leaders over the next five years
12:50PM

Adapting Hospital Incident Response Strategies to Cyber Security

12:50 PM - 1:10 PM (20 mins)

Ursula Harrisson
Manager Harm Prevention, Victorian Managed Insurance Authority

Hospitals are accustomed to managing high-pressure incidents where lives, services and critical operations cannot simply stop. Cyber incidents increasingly create the same challenge for government. Drawing on lessons from healthcare incident response, this session explores how stronger planning, clear prioritisation and tested recovery arrangements can reduce disruption and help organisations maintain essential services when systems are compromised.

  • Ensure Cyber Incident Response, Business Continuity and Crisis Management plans are connected and understood before an incident occurs.
  • Strong business impact analysis and recovery priorities can reduce ‘bleed time’ and prevent critical services waiting behind lower-priority systems.
  • Outdated disaster recovery plans, legacy systems and key-person dependencies can significantly delay restoration. Regular testing helps expose these weaknesses before a real incident.
1:10PM

Lunch: Wander, Discover, Connect

1:10 PM - 2:20 PM (70 mins)

Grab lunch, have a wander, and chat with industry partners and peers about practical ideas you can take back to work. Arguably the most important part of the day!

2:20PM

Interactive Roundtable Discussion

Choose one · 2:20 PM - 3:20 PM (60 mins) · 10 options Roundtables

2:20PM

From AI Governance to AI Security Operations

2:20 PM - 3:20 PM (60 mins)

As AI moves into production across government, the conversation is shifting from whether AI should be governed to how it is secured in practice. This discussion will explore the emerging security risks of AI-enabled systems, autonomous agents and AI-driven attacks, and what security operations need to do differently. Delegates will consider how to build the visibility, controls and response capabilities needed as AI becomes part of critical government operations.

2:20PM

Securing Non-Human Identity in an AI-Enabled Government

2:20 PM - 3:20 PM (60 mins)

AI agents, bots, APIs and automated services are creating a rapidly expanding layer of non-human identities across government environments. Understanding what these identities can access, who owns them and when their privileges should change is becoming a significant security challenge. This roundtable will explore how organisations can establish accountability and control over machine access without limiting the benefits of automation and AI.

2:20PM

Trust, Privacy and Cyber Risk in Data Sharing

2:20 PM - 3:20 PM (60 mins)

Greater data sharing creates significant opportunities for better services, AI and cross-government decision making, but it also expands the potential impact of a security or privacy failure. This discussion will explore how organisations can enable responsible data sharing while maintaining appropriate security, privacy and accountability. Delegates will consider where trust needs to be built into the architecture, governance and operating model rather than added after the fact.

2:20PM

Managing Digital Supply Chain and SaaS Risk Beyond Procurement

2:20 PM - 3:20 PM (60 mins)

Government's dependence on SaaS, cloud platforms and managed service providers means significant cyber risk now sits outside the traditional organisational boundary. This discussion will examine how agencies can maintain meaningful oversight of third-party technology and services throughout their lifecycle, not simply at the point of procurement. Delegates will explore how to establish ongoing assurance, understand concentration risk and respond when a trusted provider becomes a source of exposure.

2:20PM

Sovereign Capability and Knowing Where Your Security Actually Runs

2:20 PM - 3:20 PM (60 mins)

Digital sovereignty is increasingly about more than where government data is hosted. It raises questions about where security operations are performed, who has access to critical systems and intelligence, and whether essential capabilities remain available during geopolitical or technology disruption. This roundtable will explore how organisations can identify their critical dependencies and determine where sovereign capability genuinely matters.

2:20PM

Life After the Essential Eight: Defining the Next Era of Cyber Assurance

2:20 PM - 3:20 PM (60 mins)

The next phase of cyber maturity requires organisations to look beyond foundational controls and consider whether they can demonstrate genuine security and resilience. As the Essential Eight evolves, this discussion will explore what effective assurance could look like across identity, cloud, AI, supply chain and critical services. Delegates will consider how to move from demonstrating compliance to demonstrating that risk is actually being reduced.

2:20PM

Beyond Trust by Default: Making Zero Trust Operational

2:20 PM - 3:20 PM (60 mins)

Zero Trust is moving from a strategic aspiration towards an operational priority, but implementation remains challenging across complex government environments. This discussion will explore how organisations are translating Zero Trust principles into practical changes across identity, devices, applications, networks and data. Delegates will consider how to prioritise the journey, overcome legacy constraints and demonstrate measurable improvements in cyber risk.

2:20PM

Identity as the New Security Perimeter: Securing the Modern Government

2:20 PM - 3:20 PM (60 mins)

Identity has become a central point of control as government services move across cloud, hybrid environments and interconnected platforms. This discussion will explore how organisations can secure access across employees, contractors, partners, applications and machines while reducing unnecessary privilege. Delegates will consider how stronger identity foundations can support Zero Trust, reduce attack paths and improve confidence in who or what is accessing critical services.

2:20PM

The Borderless Government: Securing an Expanding Digital Attack Surface

2:20 PM - 3:20 PM (60 mins)

Government's attack surface now extends across edge devices, remote access, cloud environments and connected services, making traditional perimeter-based security increasingly difficult to sustain. This discussion will explore how organisations can maintain visibility and control as infrastructure and users become more distributed. Delegates will consider where the greatest exposure sits and how security strategies need to adapt to an increasingly borderless environment.

2:20PM

The Security Operating Model for an AI-Enabled Government

2:20 PM - 3:20 PM (60 mins)

Security teams are being asked to defend more systems, more identities and more complex environments without a corresponding increase in people or resources. This discussion will explore how automation and AI can reshape the security operating model while maintaining appropriate human oversight and accountability. Delegates will consider which capabilities should be automated, where specialist expertise remains essential and how to build sustainable security operations.

3:20PM

Scenario Session: The Incident Room: A Cyber Crisis Simulation

3:20 PM - 3:40 PM (20 mins)

The Audience make the decisions. The consequences unfold.

3:40PM

Preparing Leaders for Cyber Disruption

3:40 PM - 4:00 PM (20 mins)

Chief Information Security Officer, Victorian Managed Insurance Authority

Cyber incidents require more than technical responses - they require effective leadership, communication and decision-making. This session explores how government leaders can sort through the noise to effectively manage an incident.

  • The role of executives during cyber incidents
  • Strengthening crisis management capability
  • Lessons learned from real-world incidents
4:00PM
Panel Discussion

The Resilient Government of 2030: Are We Ready for What Comes Next?

4:00 PM - 4:30 PM (30 mins)

Elizabeth Wilson
Chief Information Officer, Victorian Department of Education
Michael Franco
Deputy Head - Monash Medical School, Adjunct Associate Professor - Faculty of Information Technology, Monash University
Head of PMO and Transformation Lead, Building & Plumbing Commission

The cyber challenges facing government are no longer defined by individual attacks or isolated vulnerabilities, they are shaped by a constantly changing operating environment where technology, society and expectations are evolving at pace. This closing discussion brings together Victorian leaders to look beyond today’s priorities and explore the capabilities, culture and partnerships required to build a government that can adapt, recover and continue serving the community through whatever comes next.


• What will distinguish truly resilient government organisations over the next decade
• How agencies can build adaptability into their people, processes and technology environments
• The future role of cyber leaders in enabling trusted digital government
• Strengthening collaboration across government, industry and communities to prepare for emerging challenges

4:30PM

Closing Remarks: What We’re Taking with Us

4:30 PM - 4:40 PM (10 mins)

4:40PM

Networking Reception: Stay for a Chat

4:40 PM - 5:40 PM (60 mins)

We’ll pull out a few highlights from the day, share what’s coming next, and point you to ways to stay connected.

Questions?

See our FAQs or get in touch

Ready to register?

Registration is free for government