ROCC26 SCHEDULE

Thursday, 27 August 2026 | Brisbane Powerhouse

Main Theatre

08:00 – 09:00

Registration

09:00 – 09:10

Wade Alcorn
Wade Alcorn
Founder & Host, Realms of Cyber

Opening

Wade Alcorn opens ROCC26 by framing the day ahead: why cyber risk now moves through supply chains, physical systems and the infrastructure Australians rely on every day, not just the network. That's why ROCC26 exists - getting the people building, operating and defending these systems in the same room, before a crisis forces it.

09:10 – 09:35

Malcolm Turnbull
Malcolm Turnbull
29th Prime Minister of Australia, Keynote Speaker

Keynote from the 29th Prime Minister

A long-standing advocate for technology, national security and sovereign capability, Mr Turnbull will speak to this year's theme, Sovereignty in a Connected World: Where Reality Meets Resilience, exploring the strategic, geopolitical and technological forces shaping Australia's future in an increasingly contested global environment. The keynote will be followed by an interactive audience Q&A, giving attendees a chance to engage directly with Mr Turnbull about the issues shaping Australia's sovereign future.

09:35 – 10:10

Q&A Panel

Interactive Q&A session with Malcolm Turnbull and Wade Alcorn.

10:10 – 10:45

BREAK – Morning Break

10:45 – 11:00

Sanja Marais
Sanja Marais
Managing Consultant, Marais Consulting

You can't patch a human: when the endpoint is your brainstem

Biological Realm
We spent about thirty years learning to secure the enterprise. We have about five to secure the body, and unlike a server, you can't reboot or patch a human.

In 2011, a researcher hacked an insulin pump from across a room. By 2012, it was a pacemaker. Dick Cheney had his pacemaker disabled by the Secret Service, because "cardiac assassination via Bluetooth" became a real threat model. In January this year, ethical hackers rewrote the therapy schedule of an implanted neurostimulator from 15 metres away using a $35 transceiver. No password. No alarm. No log entry.

The attack surface moved from 150 centimetres to zero, yet governance is years behind. Over $1B has poured into brain-computer interfaces - with an Aussie player in the race.

Join me as I follow the money, the shrinking attack surface, and the question that they forgot to ask the cyber experts: when a neural implant is compromised, what exactly does a person lose?

11:00 – 11:15

Vu Tran
Vu Tran
Co-founder, Go1 & Black Sky Industries

Building Sovereign Physical Capability: A Black Sky Industries Case Study

Space Realm
Dr Vu Tran will present on the practical challenge of building sovereign physical capability in Australia, using Black Sky Industries as a case study.

The session will explore what it takes to scale a company operating at the intersection of defence manufacturing, advanced materials, AI-enabled operations and national preparedness. Rather than treating cyber as a purely digital problem, Vu will frame it as part of a broader capability stack - trusted supply chains, resilient manufacturing, secure operational systems, secure data-driven sustainment, and the ability to move quickly when national circumstances change.

11:15 – 11:30

Matthew Walker
Matthew Walker
Chief AI & Innovation Officer, City of Gold Coast

Do proper risk management, and you'll end up managing AI-related risks too

Cognitive Realm
Artificial intelligence is being adopted faster than most organisations can govern it. In response, many have created new frameworks, standards and assessment models, often adding complexity while slowing decision making.

This presentation challenges the assumption that AI requires an entirely new governance paradigm. Most AI risks are simply existing organisational risks viewed through a new lens. The challenge is not creating more governance, but applying the governance foundations organisations already have.

Attendees will leave with a practical approach for connecting AI governance to organisational risk appetite, enabling faster, better informed decisions while balancing cyber, legal, operational, financial and workforce considerations.

11:30 – 11:45

Ross Gordon
Ross Gordon
Deputy CISO, Airservices Australia

Managing AI risks and opportunities within Critical Infrastructure

Air Realm
The explosion of AI capabilities presents new and emerging risks to IT networks, and is beyond comprehension for use within sensitive Operational Technology (OT) systems. However, with the pressure to adopt AI solutions to drive business efficiency, is there an opportunity within Critical Infrastructure organisations to safely leverage the benefits from AI capabilities?

This session will explore the potential for the safe use of AI to enhance OT system reliability, performance and security.

11:45 – 12:15

Panel Discussion

All four presenters from the session will come together for a fireside Q&A panel, giving attendees the opportunity to explore the themes, practical lessons and operational realities raised during the presentations.

12:15 – 13:30

BREAK – Lunch & Networking

13:30 – 13:45

Alex Tilley
Alex Tilley
Global Threat Research Coordinator, Okta

The Enemy in the Org Chart: DPRK Use of AI Platforms in Workforce Infiltration

Cognitive Realm
Nation states and criminal syndicates are using AI platforms to generate, test, iterate and submit fraudulent identity documents and job applications to western organisations across every sector and size. Beyond the application stage, the same tools are used to translate communications, summarise meetings and assist operators in performing the work once hired. The sustained, systematic use of legitimate AI platforms to refine applications and execute employment fraud is a real and current threat -- one that receives far less attention than it deserves.

13:45 – 14:00

Dr Hon Weng Chong
Dr Hon Weng Chong
Founder & CEO, Cortical Labs

Wetware at the Edge of Cyber: Biological Compute Beyond the GPU

Biological Realm
As the cost of AI, cryptography, and large-scale security computation continues to rise, the cyber industry is increasingly dependent on power-hungry GPU infrastructure. Dr Hon Weng Chong, CEO and founder of Cortical Labs, will explore a radically different path: biological computing built from living neurons.

Cortical Labs' CL1 biological computer and Cortical Cloud platform point to a future where adaptive biological systems may complement, and in some cases challenge, traditional silicon-based compute. This session will examine what that could mean for cyber security, including real-time network penetration, closed-source 0-day exploit mitigation, true random number generation, and future approaches to training AI systems with less data than conventional methods.

Rather than treating biological compute as science fiction, Hon will frame it as an emerging sovereign technology with practical implications for resilience, energy use, and the next generation of secure computation.

14:00 – 14:15

Mick McHugh
Mick McHugh
CISO, Virgin Australia

Same Arms Race, New Weapons: Leading Through Frontier AI

Air Realm
Frontier AI has moved from theoretical risk to operational reality, compressing attack timelines, increasing attack autonomy and scaling adversary tooling. But the fundamentals haven't changed: identity is still the perimeter, legacy systems remain a weak link, and third-party risk still travels through the supply chain. The same technology arming attackers is arming defenders too, and the sectors that win this race will be the ones that put AI to work on faster detection, faster triage and faster decision-making, rather than treating it solely as a threat to defend against.

Drawing on experience leading cyber defence in the aviation sector, this session explores what is genuinely new for Critical Infrastructure, aviation and space organisations - and what is simply existing risk moving faster.

14:15 – 14:30

Shane Bennett
Shane Bennett
Space Launch Mission Systems & Cyber Mission Assurance, Defence Science and Technology Group (DSTG)

Launch, On our Own Terms

Space Realm
Australia's sovereign space capability depends on more than successful launches-it depends on resilient Cyber-Physical Systems. Drawing on more than 25 years in cyber, intelligence and the Australian space sector, Shane Bennett explores why compliance alone is no longer enough, sharing a mission assurance approach built for real-world operations. Through practical lessons from Australian launch campaigns, this session demonstrates how organisations can identify mission-critical functions, manage cyber, supply chain and RF threats, and strengthen operational resilience in an increasingly contested world.

14:30 – 14:50

Panel Discussion

All four presenters from the session will come together for a fireside Q&A panel, giving attendees the opportunity to explore the themes, practical lessons and operational realities raised during the presentations.

14:50 – 15:15

BREAK – Afternoon Break

15:15 – 15:30

Sasha Biskup
Sasha Biskup
CISO, DroneShield

When Security Maslow Breaks: Building a sovereign defence technology company at startup speed

Air Realm
In most technology scale-ups, security maturity is expected to follow a familiar path: identity, product, detection, endpoints, governance, then compliance.

In defence, that sequence breaks.

Sovereign defence technology companies face customer assurance, product security, physical security, personnel security, regulatory obligations, and market-access controls far earlier than most maturity models expect. For organisations building hardware, software, cloud, AI and manufacturing capability at the same time, security is not a support function. It is part of the licence to operate.

This talk explores what happens when “Security Maslow” collapses under defence-sector pressure, and shares practical lessons on what controls to build first, why a canonical control spine beats fragmented compliance programmes, how to prioritise without burning out the team, and when to hire security capability before assurance becomes the bottleneck.

15:30 – 15:45

Hugh Brassil
Hugh Brassil
Client Services Director, M&C Saatchi World Services

How to make Australia more resilient to disinformation

Cognitive Realm
In the grey-zone between conflict and peace, malign actors exploit identity, fear, anger, and social division to shape perception and behaviour.

This presentation examines how Australia can build cognitive resilience to disinformation by moving beyond fact-checking and engaging the same psychological terrain that disinformation targets: identity, emotion, belonging, and trust.

15:45 – 16:00

Rue Maharaj
Rue Maharaj
Cybersecurity Defence Manager, Melbourne Water

Silence Of The LANs - Protecting Critical Infrastructure from Going Dark

Cognitive Realm
This presentation explores the system environments found within Critical Infrastructure organisations, including SCADA, and the psychological profiles of the different types of cyber attackers targeting them. It examines why Critical Infrastructure has become such a high-value target, and why attacks are growing more common, before turning to practical approaches for reducing the risk of compromise. The session also covers the strategies needed to effectively respond to and recover from malicious attacks, and what it takes to maintain an effective, fit-for-purpose Cyber Incident Response Program for Critical Infrastructure organisations.

16:00 – 16:15

Tim Daly
Tim Daly
CISO, AEMO (Australian Energy Market Operator)

ROCC26 Featured Presentation

Land Realm
This session will draw on the presenter's experience across cyber security, technology and industry to examine an issue relevant to Australia's evolving security environment.

Further details, including the presentation title and topic, will be announced closer to ROCC26.

16:15 – 16:45

Panel Discussion

All four presenters from the session will come together for a fireside Q&A panel, giving attendees the opportunity to explore the themes, practical lessons and operational realities raised during the presentations.

16:45 – Late

Networking Event

Join us for drinks and networking immediately following the final session.

OT Stream (Knocknoc Underground)

10:10 – 10:45

BREAK – Morning Break

10:45 – 11:00

Kenneth Radke
Kenneth Radke
Technical Director, Cyber Security Resilience, Australian Signals Directorate

Practical essential cybersecurity for Operational Technology (OT) systems

Prioritising the security, reliability, and fast recovery of essential systems must be a central concern for Critical Infrastructure (CI) operators nationwide. As part of the broader update to the Essential Eight, a dedicated OT Essentials chapter is being designed to best enable CI entities to protect their OT environments from escalating cyber threats. This is because OT environments have challenges and consequences that require additional consideration not relevant to corporate information technology networks. This presentation will discuss the approach to the draft of the OT Essentials, which will be open for public comment and feedback upon release in October 2026.

11:00 – 11:15

Sadeed Tirmizey
Sadeed Tirmizey
CISO, Seqwater

Bridging IT and OT: Building Cyber Resilience for Critical Infrastructure

As Critical Infrastructure becomes increasingly connected, the challenge is not whether IT and Operational Technology (OT) should converge, it is how organisations can securely operate as one while maintaining safety, reliability and resilience. Many organisations continue to face challenges created by fragmented ownership, competing priorities, legacy environments and evolving regulatory obligations. At the same time, AI-enabled threats, sophisticated adversaries and growing executive accountability are raising expectations for cyber resilience across Critical Infrastructure.

Drawing on practical experience leading cyber transformation across Australia's Critical Infrastructure sectors, this session explores what it really takes to bridge the gap between IT, OT and the broader business. Attendees will gain practical insights into establishing clear governance, defining accountability, integrating cyber into operational decision-making, and building an operating model that enables resilience without compromising operational outcomes.

This session will present a pragmatic view of embedding cyber security as an enterprise capability to strengthen resilience in an increasingly complex threat and regulatory landscape.

11:15 – 11:30

Linh Ngo
Linh Ngo
IT/OT Engineer, EEHA Automation

PLC Honeypots: Turning Industrial Decoys into OT Threat Intelligence

Programmable Logic Controllers are the quiet workhorses behind industrial operations, but they are also increasingly visible to attackers targeting Operational Technology (OT) and Cyber-Physical Systems. This session explores the practical use of PLC honeypots as a way to observe adversary behaviour, generate useful threat intelligence, and improve defensive readiness without placing production environments at risk. Drawing on EEHA Automation's experience across PLC, SCADA, control system integration, and industrial machinery automation in sectors such as mining, utilities, water, and manufacturing, the presentation will examine how realistic industrial decoys can be designed, deployed, monitored, and maintained. Attendees will gain a grounded view of what PLC honeypots can reveal, where they fit in an OT security programme, and the operational considerations needed to make them useful rather than just interesting.

11:30 – 11:45

Pippa Flanagan
Principal OT Cyber Security Consultant, Founder, OT Cyber Speakeasy

The Process Is the Customer: Designing OT Security from the Physics Up

Where is resilience measured in OT? Not by whether the network stayed online, but by whether the physical process continued to deliver its intended outcome safely and reliably.

As the Enhanced SOCI reforms sharpen the focus on operational resilience and reliability, OT security must move beyond a control-first mindset. This session explores a process-first approach by examining what the process is designed to do, how it can fail, and what those failures cost. From there, security controls can be designed around consequence, just as engineers design safety functions.

In OT, the process is not just something security protects. It is the reason security exists.

11:45 – 12:15

Panel Discussion

All four presenters from the session will come together for a fireside Q&A panel, giving attendees the opportunity to explore the themes, practical lessons and operational realities raised during the presentations.

12:15 – 13:30

BREAK – Lunch & Networking

13:30 – 13:45

Ravi Toor
Ravi Toor
Discipline Manager, Systems and Cyber Security, Australian Defence Prime

Built Today, Defended for Decades

Australia is investing in Critical Infrastructure at a scale it has not seen before. Its national infrastructure pipeline is at a record high, tracking more than a trillion dollars of public and private investment across energy transmission, water, transport and communications, alongside the largest renewal of defence capability in a generation under AUKUS and continuous shipbuilding. The Operational Technology (OT) and Cyber-Physical Systems (CPS) at the heart of that investment are being designed today, will be fielded over the coming decade, and are expected to run well into the 2050s and beyond. They will have to stay safe and survivable across a threat environment that will look nothing like the one that shaped their design.

13:45 – 14:00

Michael Keating
Michael Keating
Senior IT/OT Architect, Downer

Rail Security in the Age of AI

Railways have long been engineered around safety, reliability, and measured change. Every technology decision is carefully assessed because the consequences of failure can extend far beyond IT, affecting passenger safety, critical services, and national infrastructure. While this deliberate pace has helped build resilient Operational Technology environments, it now faces an unprecedented challenge.

Artificial Intelligence is advancing at a speed unlike any previous technology shift. New capabilities, new attack techniques, and new operational opportunities are emerging almost weekly. Rail operators are therefore confronted with two opposing forces: an industry with the handbrake firmly applied by necessity, and a technology racing ahead with the accelerator fully engaged.

This presentation explores how rail organisations can navigate this growing tension. Drawing on practical experience designing and securing large-scale Operational Technology environments, it examines the cyber security challenges unique to modern rail networks, the opportunities and risks AI introduces, and the architectural and governance decisions needed to safely adopt AI without compromising the resilience, safety, and availability of critical railway operations.

14:00 – 14:15

Michael Carmody
Michael Carmody
Critical Infrastructure Solution Architect

Technical Supply Chain Risk in Critical Infrastructure

Foreign Ownership, Control or Influence (FOCI) is often treated as a governance or compliance issue, but in Critical Infrastructure it can become a deeply technical problem. Who can access the build systems, remote management tools, support channels, firmware pipelines, cloud tenants, telemetry paths and maintenance networks that keep operational environments running?

This session takes a technical walk through how FOCI and supply chain exposure show up inside Operational Technology (OT) and Cyber-Physical Systems (CPS), from vendor architecture and privileged access paths to software updates, managed service dependencies, data flows and recovery assumptions. Using technical implementations to manage foreign-based vendors currently deployed and in operation on Critical Infrastructure assets in ANZ, the presentation will examine practical design points for asset owners and operators: mapping influence paths, identifying concentration risk, designing technical controls, separating operational trust zones and translating sovereignty concerns into engineering decisions.

Attendees will leave with a clearer view of how foreign influence risk can move from corporate structure into technical dependency, and what defenders can do before procurement, integration and operations lock those risks in.

14:15 – 14:30

Nicole Murdoch
Nicole Murdoch
Principal, Eaglegate Lawyers

From Control Room to Courtroom

As cyber threats escalate, modern regulatory frameworks now hold executives and security leaders personally liable, including the threat of prison time for failing to protect Operational Technology (OT) environments. Drawing on a career that began in cyber, military systems, and encryption before almost 20 years in law, including serving as a director of the Australian Information Security Association (AISA). Nicole Murdoch will explain how to walk a tightrope between the control room and the courtroom, decoding the legal landmines embedded in OT security. This rapid-fire session will arm you with practical knowledge to align your technical reality and risk matrix with strict legal compliance, keeping your critical systems online and yourself out of a cell.

14:30 – 14:50

Panel Discussion

All four presenters from the session will come together for a fireside Q&A panel, giving attendees the opportunity to explore the themes, practical lessons and operational realities raised during the presentations.

14:50 – 15:15

BREAK – Afternoon Break


Lunch Session (Turbine Platform)

12:15 – 13:30

BREAK – Lunch & Networking

12:25 – 12:35

Andi Gynn
Andi Gynn
Founder, DISCoE

Facilitating Compromise: Ignorance is not bliss

System compromise by a trusted insider is a downstream problem to an upstream failure. Unpack the back engineering of Role Based Access Control and understand how information protection starts at a Board level long before a person even walks through the office door.

12:35 – 12:45

Heath Moodie
Heath Moodie
Cyber Threat Intelligence Advisor, Threat Informed Advisory

Understanding and defeating Australia's Most Likely Adversary Toolset

Based on three years of comprehensive ICS threat research, this session analyses the core methodologies and tools employed in successful organisational compromises. It equips ICS operators and executive leadership with the targeted defence strategies required to intercept and mitigate critical incidents. Utilising visual frameworks to simplify complex adversary attack paths, the presentation offers high-impact, actionable guidance for modern industrial security.

12:45 – 12:55

Daniel Castillo
Daniel Castillo
Founder & Director, OT Cybersecurity Advisor, Skadi Solutions

Resilient Teams, Resilient Systems: Building an OT Cybersecurity Culture That Endures

There's an under-recognised epidemic quietly undermining Critical Infrastructure security, and it's not a zero-day: it's the slow breakdown of alignment between the people who run OT and the people who secure it. Critical Infrastructure security is a contact sport: engineering, operations, IT, vendors, and security all touch the same risk surface - but they operate with different incentives, language, and definitions of “success.” The result is predictable friction: enthusiastic engineers who want uplift collide with cyber teams that bring corporate patterns that don't fit safety-critical environments; IT assumes it owns identity and endpoints; OT assumes cyber is a blocker; vendors get treated as “necessary evil” instead of a managed risk relationship. ASD's Principles of Operational Technology Cybersecurity make this explicit: people are essential for OT cyber security - you can't prevent, detect, or respond without trained, competent people, and a safety-based culture where field staff are empowered to raise concerns. This talk is a practical blueprint for leaders and practitioners in CI to build a durable OT cybersecurity culture: how to identify and sponsor OT cyber champions inside engineering, how to reduce friction without watering down security outcomes, how to create pathways that convert engineers into credible OT cyber operators, and how to measure whether culture is actually improving.

12:55 – 13:05

Finn Foulds-Cook
Finn Foulds-Cook
Principal Penetration Tester, Loc Cyber

The Attack Path Nobody Cared About

A regional council IT's team is small and overtasked. IT infrastructure is deployed quickly to support operational goals, but what happens when 'infrastructure' starts to cover all devices maintained by the business? First its printers, then its laptops, then its remote servers, then its those pesky devices used to manage Critical Infrastructure. What could go wrong?

13:05 – 13:25

Panel Discussion

All four presenters from the session will come together for a fireside Q&A panel, giving attendees the opportunity to explore the themes, practical lessons and operational realities raised during the presentations.