Skip to main content

Key Takeaways: Government Cyber Security Showcase New South Wales 2026

Government Cyber Security Showcase NSW 2026 brought cyber, privacy, policing, policy and industry leaders together to reframe public sector cyber as a trust, resilience and service-continuity issue, with AI, identity, incident response and data governance running through every discussion.

Avatar
Ashley D 13 August 2026 · 9 min read
Key Takeaways: Government Cyber Security Showcase New South Wales 2026

Chair Opening

Amran Majid - Chief Information Security Officer, NSW Government

  1. Cyber has moved from the technical back room to the public-service boardroom. AI has pushed cybersecurity into everyday executive and service-delivery conversations. The challenge is no longer just whether a control exists, but whether leaders understand the service context, public impact and trust consequences behind it.
  2. The basics still matter, especially when the pace of change is accelerating. Patching, identity management, service assurance and recovery remain hard to execute because they do not always translate cleanly into business outcomes. The work for cyber leaders is to explain these basics in the language of essential services, not technical compliance.
  3. Standing still is now a strategic risk. AI is shortening decision, procurement, implementation and threat cycles. Agencies need to consider not only the risk of moving too quickly, but the risk of doing nothing when public services, data and trust are already operating in a tightly connected ecosystem.

Identity as a Cyber Control Point

Will Harrington - Identity Strategist, SailPoint

  1. Recent breaches show identity is now a front-line security issue. The Qantas breach example was framed as a failure across authentication, privileged access and process control, not simply a failure of perimeter security. A phone call to a help desk can bypass layers of cyber tooling if identity controls are weak.
  2. Agencies need an identity model that covers more than staff accounts. Human identities, machine identities, third parties and AI agents all need ownership, context, entitlement mapping and lifecycle controls. Without that breadth, privileged non-human and third-party accounts become hidden attack paths.
  3. Identity governance should feed the SOC, not sit beside it. HR attributes, accounts, entitlements, data access and activity can help answer business-relevant questions such as who has sensitive access and whether they still need it. Shared signals between identity systems and security operations can change access decisions dynamically when user risk changes.

Moving from Essential Eight Compliance to Risk-Based Resilience

Andrew Philip - Field CISO, Trend AI

  1. The move from Essential Eight to the Essentials series is a chance to leave checkbox security behind. The coming Essentials model was positioned as more risk-based, context-aware and better suited to AI, cloud, operational technology and legacy environments where one control does not fit every asset.
  2. Agencies need to prioritise the risks that can actually be exploited in their environment. Vulnerability volume is rising, but only a small proportion of vulnerabilities are actively exploited. Risk-based prioritisation should combine asset criticality, exploitability, exposure, known exploitation and threat intelligence.
  3. Continuous threat exposure management gives teams a shared language for action. A single risk score across endpoints, identities, cloud, containers and misconfigurations can help identity, cloud, endpoint and SOC teams agree on the top issues to fix first. Compliance data becomes more useful when it shows where risk is reducing, not just where a control is declared present.

Digital Government Runs on Trust, and Cyber Now Decides It

Sonia Minutillo - Privacy Commissioner, NSW · Sam Mackay - Chief Information Security Officer, Department of Customer Service NSW · Mark Messina - Chief Information Security Officer, NSW Rural Fire Service · Amran Majid (Facilitator) - Chief Information Security Officer, NSW Government

  1. Public trust depends on what government collects, how clearly it explains that collection, and how it responds when things go wrong. NSW privacy sentiment data shows very high community expectations that government will protect personal information. Agencies need to be specific, honest and plain-language in breach communication, not generic or overly legalistic.
  2. Cyber needs to be communicated as resilience and service confidence, not only threat prevention. The panel argued that breach fatigue is real. Leaders respond better when cyber is tied to continuity of public services, community confidence and the ability to recover, rather than only hackers, vulnerabilities and worst-case scenarios.
  3. Security must be designed into delivery, but without becoming the "no" function. Agencies need guardrails that let digital teams move quickly inside clear boundaries. For AI and new digital services, the practical task is to set secure platforms, review pathways and cultural expectations early, so cyber is not left as a late-stage penetration test or approval hurdle.

Can Government Move Fast and Still Be Trusted?

Jess Thomas - Assistant Director, National Office of Cyber Security · Masindra - Director, NSW Reconstruction Authority · Andrew - Proofpoint · Maryam Shoraka - Head of OT Cyber Security, ISACA · Amran Majid (Facilitator) - Chief Information Security Officer, NSW Government

  1. Responsible pace depends on the risk profile of the service. Fast delivery is appropriate for prepared disaster-response infrastructure, but systems collecting sensitive personal information need stronger foundations before acceleration. Moving too slowly can also erode trust if government fails to use available technology responsibly.
  2. AI adoption needs transparency, governance and public agency. Public trust is most vulnerable when people feel decisions are being made by systems they cannot understand, challenge or appeal. High-risk AI use cases need explainability, human accountability and clear communication about how data is used and protected.
  3. Governance is what allows speed, not what prevents it. The strongest message was not to choose between speed and security as a binary. Good brakes let the car move faster. For AI, that means understanding purpose, permissions, guardrails, monitoring and consequences before scaling use cases.

Agentic AI for Proactive Cyber Defence

Sharif Abuadbba - CSIRO

  1. AI should be used to anticipate and adapt, not only to respond. The session challenged traditional defence-in-depth thinking by arguing for more proactive systems: autonomous threat modelling, AI system risk assessment, secure code filtering, SOC campaign detection and agentic red teaming.
  2. Agentic AI can reduce the manual load in threat modelling and assurance. For complex systems and AI deployments, agentic workflows can map threats against frameworks, suggest mitigations and provide clearer deployment assurance. This is especially valuable where agencies must connect high-level AI principles to practical system-level controls.
  3. Threat intelligence becomes more valuable when it is shared across agencies. Attackers rarely build entirely unique campaigns for one agency. Using AI to cluster SOC alerts into campaigns, prioritise them and identify intent creates intelligence that can help other agencies detect the same pattern earlier.

Addressing AI Data Risk in Practice

Andrew Chisholm - Information Protection Platform Lead, Proofpoint

  1. AI risk is moving from tools people use to systems that act. The first wave was staff pasting sensitive data into public AI tools. The second was AI inside enterprise platforms such as email, Teams and documents. The next wave is autonomous agents accessing data and taking action across systems.
  2. Classification, permissions and behavioural context need to work together. Copilot and similar tools amplify overshared data risk because they return information based on user permissions. Agencies need data discovery, auto-classification, permission remediation and DLP controls that understand both data sensitivity and user or agent behaviour.
  3. Centralised visibility is needed before AI risk can be managed operationally. Cyber teams need to see what data is going into prompts, what is returned, which AI tools are being used, where OAuth connections exist, and which agents can access which systems. Without that joined view, AI controls become fragmented across DLP, insider risk, SaaS and data posture tools.

Cyber After the Breach

Matthew Kraft - NSW Police Cybercrime Squad · Melissa Clemens - ID Support NSW · Jackie Muir - Cyber Security NSW · Harry - Cyber resilience leader · Maryam Shoraka (Facilitator) - Head of OT Cyber Security, ISACA

  1. The first 24 hours are determined long before the incident starts. Playbooks, roles, escalation paths, police contacts, reporting obligations and technical visibility need to be rehearsed in advance. During an incident, agencies should not be discovering who legal, privacy, police or executive contacts are for the first time.
  2. Recovery depends on visibility, communication and support beyond the cyber team. High-performing teams know their environment, crown jewels, data flows and normal activity before an incident. They also communicate early, ask for help, involve Cyber Security NSW, ID Support NSW and police where appropriate, and consider the people affected by a breach.
  3. Incident response must become a learning system. Post-incident improvement should not wait for a polished report months later. Teams should identify fatigue, resourcing, detection gaps, communications gaps and decision bottlenecks during and immediately after the response, then feed those lessons back into playbooks and exercises.



Governance, Strategy and Risk Opening

Anna Mascarello - Vice President, Public Sector Practice, Elastic

  1. The strategic question is whether defences are moving as quickly as threats. Five Eyes agencies have warned that frontier AI is shifting offensive and defensive cyber capability in months, not years. Vulnerability exploitation timelines and AI-assisted phishing costs are compressing rapidly.
  2. Trust is now a security outcome for government. The track framed security as a core business function, not a support function. For public agencies, cyber is increasingly tied to whether communities trust digital services, data handling and continuity.
  3. Fragmentation is becoming a material risk. Security, observability, data and AI decisions are often made on disconnected information. If attackers can move across those gaps faster than agencies can see them, visibility and shared digital foundations become a governance issue, not only a technology issue.

Responsible AI Governance in Cyber

Michael Warnock - Government Practice Lead NSW and Queensland, Fortinet

  1. AI systems should be treated as critical digital assets. The session argued that AI is no longer a future issue. It is already embedded in operations, decision-making and products, so security, governance and accountability need to be built into the AI lifecycle.
  2. Responsible AI governance brings together cyber risk, privacy, data and third-party controls. Agencies need to consider data classification, secure procurement, third-party risk, assurance, legal obligations and the NSW AI ethics and assessment frameworks as part of one operating model, not separate compliance streams.
  3. Leadership needs simple visibility of AI maturity and decision points. A practical maturity view can show whether an agency has AI policies, continuous monitoring, assurance, ethics and compliance in place. The starting questions are: what problem are we solving, how will success be measured, what direction does the organisation want to take, and what guardrails are needed?

Cyber Leadership for the Digital State

Nivedita Nivar - Deputy CISO, UNSW · Andrew McAllister - Vice President Asia Pacific, CoreView · Diraj - Cyber Uplift and Optimisation, icare · Anna Mascarello (Facilitator) - Vice President, Public Sector Practice, Elastic

  1. Brand impersonation and identity attacks are becoming more sophisticated. The panel pointed to vishing, help-desk impersonation, OAuth consent attacks and AI-enabled lookalike domains. The common control point is identity, especially reducing the blast radius attached to compromised users, administrators and service accounts.
  2. Copilot readiness depends on information governance. AI search has ended "security by obscurity" across platforms such as SharePoint and OneDrive. Agencies need data classification, DLP, permission cleanup and governance before scaling AI tools that can surface overshared content.
  3. Cyber investment needs to be framed as business risk and service continuity. Executive support is easier when cyber uplift is mapped to business objectives, community-facing services, resilience and compliance outcomes. The strongest cyber leaders build trust by delivering what they promised, measuring uplift and showing how controls protect core assets.

Why Yesterday's Cyber Strategies May Already Be Dated

Daniel Smith - Secure Agility

  1. Static strategies are struggling to match AI-era threat cycles. Traditional cyber strategies assumed more predictable threats, clearer perimeters, periodic risk reviews and compliance as a proxy for security. AI has shifted those assumptions by accelerating both threat discovery and attack variation.
  2. Strategy needs to move from periodic assessment to continuous risk visibility. Continuous risk assessment is not more dashboards. It is governance that can absorb new risk information, bring it to the right decision-makers and act quickly when the threat environment changes.
  3. Security must become an enabler of digital and AI adoption. A default "no" posture pushes teams toward unsanctioned tools. Agencies need risk-proportionate pathways for AI adoption, written alongside digital strategy, with controls designed in from the start.

Turning Staff into Cyber Defenders

Mona Sidhu - Cyber Awareness and Behaviour Change Lead, NSW Department of Education

  1. The most attacked endpoint is the person. In education, teachers, admin staff, students and support teams make millions of small security decisions every day. Phishing, credential theft, scams and human error remain major breach drivers, so behaviour change has to sit beside technical controls.
  2. Awareness is not the same as behaviour change. Annual tick-box training raises completion rates, not necessarily reporting rates or safer decisions. Cyber teams should measure whether staff report suspicious emails, pause before clicking, know who to call and improve over time.
  3. Storytelling and repetition make cyber advice stick. The Department of Education uses fairy tales, Hollywood references, game-based learning, phishing simulations, positive reinforcement and calendar-led campaigns to make cyber messages memorable. The goal is not just awareness, but staff who recognise risk and act before harm spreads.

Closing Pattern Across the Day

  1. Cyber is now a trust function. Across privacy, identity, AI, incident response and national strategy, the recurring message was that communities experience cyber through reliable services, clear communication and responsible data handling.
  2. AI changes the pace, but not the need for fundamentals. Identity, patching, vulnerability management, logging, data classification, backups, third-party assurance and rehearsed incident response remain the controls agencies keep returning to.
  3. Resilience is the operating model. NSW agencies are being pushed to move faster, adopt AI, share intelligence and respond transparently. The practical test is whether they can keep services operating, protect people and recover trust when something goes wrong.

Published by

Ashley D Marketing Coordinator, Marketing - Training