Welcome and Opening Remarks
Angelo Frigierri — CyberCX
- Cybersecurity in WA is an economic-resilience, public-safety and national-security issue because fuel, ports, energy, transport, health, defence and communications depend on connected digital systems.
- Security needs to be designed into digital programs from the beginning. Legacy platforms create exposure, but rapid adoption of AI without governance creates a different set of risks.
- Perfect prevention is not realistic. Agencies need to prepare their systems, suppliers and people to withstand disruption, continue essential services and recover safely.
Cybersecurity Incidents: Preparing Executives for the Inevitable
Nicholas Putra — Creative Industries, Tourism and Sport
- Incident readiness combines people, processes, technology and external support. Buying more tools does not replace security culture, planning, testing and clear lines of accountability.
- Executive involvement should be defined before an incident, with leaders prepared to make time-critical operational, funding, reporting and recovery decisions using incomplete information.
- Agencies should rehearse escalation and notification pathways, engage relevant state and national bodies early, and assess every personal-information breach against current privacy obligations.
Can Identity Security Win Votes?
Nam Lam — SailPoint
- Authentication confirms who is logging in; identity security governs what human and non-human identities can access and do after login.
- Agencies need lifecycle controls for joiners, movers and leavers so access is provided when required, adjusted as roles change and removed promptly when people depart.
- A consistent identity model across government can support workforce movement and shared services, while least privilege, access intelligence and delegated administration preserve agency control.
Protecting WA’s Economic Engine from Cyber Disruption in a High-threat World
Adesh Pednekar — Department of Communities; Russell Taylor — Public Transport Authority; Serena King — National Office of Cyber Security
- Operational resilience starts with mapping dependencies across applications, operational technology, suppliers, APIs, information flows, people and physical components supporting essential services.
- Relationships, escalation paths and information-sharing arrangements need to exist before disruption. Exercises should include executives, technical teams, communications staff, suppliers and critical partners.
- Agencies should plan for safe recovery and minimum viable operations, using proportionate controls for older assets and time-bound access for external providers rather than relying on minimum compliance alone.
Recovery Communication and Trust Resilience
Andrew Woodward — Cybersecurity and resilience academic
- A cyber incident is also a trust incident. People judge the response through the accuracy, honesty, clarity and speed of communication rather than through technical terminology.
- Agencies should separate confirmed facts from assumptions, acknowledge uncertainty and explain personal or service impacts in plain language. Premature reassurance can cause further damage when circumstances change.
- Crisis communication is an operational capability. First-day playbooks, trained spokespeople, coordinated messages and exercises involving misinformation and public anxiety should form part of incident preparation.
State of Cyber 2026 Preview
Steve Simpson — Triscoll Labs
- Organisations need to move from periodic assessment and paper compliance to continuous implementation, testing, tuning and recovery preparation.
- AI is accelerating attack and defence, but common weaknesses such as slow patching, missing MFA, default credentials, excessive access and poor configuration still provide practical routes to compromise.
- Incident support, escalation authority and forensic response should be arranged in advance so urgent recovery activity does not destroy evidence, delay specialist help or make the incident harder to understand.
Cyber, Privacy and Data Sharing: One Conversation, Not Three
Philip Ramesh — South Metropolitan Health Service; Dr Daniela Kambaskovik-Schwarz — Cyber Security Unit, Office of Digital Government
- Cybersecurity, privacy and responsible information sharing should be handled as one connected risk conversation rather than separate compliance processes.
- Both excessive and insufficient access can cause harm. Agencies need controls matched to the information, purpose, users, storage arrangements and consequences of withholding or exposing it.
- Suspected incidents should be reported early so cyber, privacy, operational and executive functions can coordinate assessment, containment, continuity and notification requirements.
Securing Innovation Without Stalling It
Stephen Woods — Department of Justice
- Security should provide the guardrails and repeatable patterns that allow teams to deliver safely, rather than acting only as a late-stage approval or rejection function.
- AI and digital pilots require logging, traceability, identity controls, production boundaries and inventories of software, models and cryptographic dependencies before they scale.
- Agencies should make the secure path the easiest path by publishing simple use guidance, educating developers and staff, and rehearsing incidents involving agents and other emerging technology.
What Enables a Cyber-resilient Government?
Andra Campian — Cyber Security Unit, Office of Digital Government
- Resilient entities invest before an incident in governance, controls, backups, response plans, workforce skills and operating models that can be maintained over time.
- The WA Cyber Security Policy provides a common baseline, but each entity must interpret priorities according to its services, information, suppliers and highest operational risks.
- Whole-of-government monitoring, vulnerability assessment, threat intelligence and sector-wide uplift can help one agency’s experience warn others and improve collective resilience.
Has AI Changed the Cyber Threat Landscape?
Anu Sudarshan — Department of Transport and Major Infrastructure; Jacob Timmerman — Data analytics and information governance; Mia Araminta — Cyber resilience and AI enablement
- AI amplifies familiar risks through speed, volume, variety, accessibility and complexity. Cyber hygiene, secure development, secrets management and information governance therefore become more urgent rather than less relevant.
- Organisations need visibility of approved, embedded and shadow AI, including the information used, system access granted and human or machine identity responsible for an action.
- Principle-based governance, practical literacy and business ownership can provide enough friction for safe adoption without driving teams towards workarounds or unmanaged tools.
Closing Remarks
Angelo Frigierri — CyberCX, provisionally attributed from event context
- WA’s resilience depends on connected organisations, systems, suppliers, people and technologies working together; trust is affected when any important part of that ecosystem fails.
- MFA, patching, secure configuration, privileged-access management and supplier assurance remain essential even as agencies address AI agents, post-quantum cryptography and sophisticated actors.
- The mature test is whether agencies can continue essential services, operate safely in a degraded state and support executives to make the right decisions during disruption.
Published by
Help your peers
Share what you've learned with fellow public servants