Cyber Voices podcast artwork

PODCAST · technology

Cyber Voices

Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.

Publisher-supplied feed metadata · PodParley refreshed Sep 2, 2026 · Source feed

  1. 85

    AI Agents as Workers, with Sharon Hunneybell

    Most organisations still treat AI agents as software. Their staff do not. Agents are being used as colleagues, confidants and co-developers; they are being handed access to multiple systems, and a good number of them belong to proof-of-concept projects that quietly ended without anyone shutting off the credentials.Recorded at AdelaideSEC, David Savva-Willett speaks with Sharon Hunneybell, VP of Products at FirstWave, ahead of her talk on a governance framework for AI agents as workers. Sharon describes realising midway through writing that framework that she had missed a step, and that discovery has to come before onboarding, because these things arrive in the workplace unannounced and increasingly as features inside software that is already approved.The conversation covers where accountability sits when an agent acts, why access should be task-based and time-limited rather than granted to one broad agent, how far traditional HR frameworks actually translate, and what Sharon expects from regulation over the coming months. It closes on her practical checklist: give every agent its own identity, log what it does, scope its access to a single task, review it on a schedule, and know how to offboard it before you build it.

  2. 84

    Post-Quantum Cryptography and Passkeys, with Geoff Schomburgk and Alex Wilson (Yubico)

    Quantum computers will one day break the cryptography that protects almost everything online. The harder questions are how much of the alarm is warranted, and what security leaders should be doing now.David Savva-Willett is joined by Geoff Schomburgk, Regional Vice President for Asia Pacific and Japan at Yubico, and Alex Wilson, who leads solutions engineering for the region. They unpack harvest now, decrypt later and how much of it is a device for grabbing attention; what it took to get post-quantum algorithms running on the secure element inside a YubiKey; and why crypto agility, not any single algorithm, is the thing to design for.The conversation turns to authentication, where passkeys are becoming the root of trust for digital wallets, mobile driver licences and financial transactions, and to the difference between device bound and copyable passkeys that many organisations have not thought through. Both guests make the case that this is a project management and governance problem rather than a technology one, and that the apocalyptic framing does more harm than good.

  3. 83

    Everyone Has a Unique Talent: Christine Ferguson on Neurodiversity in Cyber

    Recorded live at AISA SydneySec 2026, host David Savva-Willett is joined by Christine Ferguson, Inclusion Specialist Lead in DXC Technology's Social Impact Practice, where she leads the DXC Dandelion Program. Since 2014 the program has supported over 350 neurodivergent people into sustainable technology and cyber security careers across Australia, Europe, Asia and now the Middle East.Christine had just come off stage with her SydneySec session Neurodiversity in Cyber: People, Pressure and Performance, and the conversation follows the same three threads. What neurodivergent professionals bring to a cyber team that routinely gets overlooked. What pressure and masking actually feel like from the inside, and why an escalating manager and an escalating analyst never produce a good outcome. And what genuinely changes for a team, not just an individual, when a workplace gets the accommodations right.Christine speaks openly about her own dyslexia and about wearing the Hidden Disabilities Sunflower lanyard at the conference so that people could see an invisible disability made visible. She closes with the one small change she would ask of any leader listening, which turns out to cost nothing at all.Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at [email protected].

  4. 82

    The Only Criminologist in the Room: Nakshathra Suresh on Human Centred Resilience

    Recorded live at AISA SydneySec 2026, host David Savva-Willett sits down with Nakshathra Suresh, a cyber criminologist and one of very few people in Australia bringing a social science lens to artificial intelligence and emerging technology safety.Nakshathra is co-founder of eiris, a safety technology consultancy, Oceania Youth Ambassador for the Internet Society, and teaches with the Faculty of Law and Justice at UNSW where she created the university's first criminology backed cyber security course.The conversation covers what a cyber criminologist actually does and why the discipline is still so young, how generative AI has turned catfishing and cyberstalking into something that runs itself once a public profile is scraped, the long tail of harm for victim survivors who end up retiring their online lives entirely, and why human centred resilience is a question of culture and conduct rather than another vulnerability to patch. Nakshathra also makes a direct case about who is missing from the room when security decisions get made.Content note: this episode includes discussion of cyberstalking, technology facilitated abuse, image based abuse and harm to children in online environments. If anything here raises something for you, support is available. 1800RESPECT on 1800 737 732 or Lifeline on 13 11 14, and image based abuse can be reported to the eSafety Commissioner at esafety.gov.au.Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at [email protected].

  5. 81

    Fighting Back: Glenn Maiden on Putting a Bounty on Cybercrime

    Cybercrime is not a lone hacker in a hoodie any more. It is an economy, and by some estimates a staggeringly large one. In this episode of Cyber Voices, host David Savva-Willett flips the usual script and asks not how we defend, but how we fight back.Glenn Maiden is Chief Security Officer for Fortinet Australia and Director of Threat Intelligence at FortiGuard Labs for Australia and New Zealand. He spent years in Defence and the Australian Intelligence Community working in geospatial and human terrain intelligence, including during Operation Slipper, before moving into commercial threat intelligence. He established the team behind the World Economic Forum's Cybercrime Atlas and, most recently, helped create a first of its kind cybercrime bounty program with Crime Stoppers International.The conversation covers how mapping tribal structures, community leaders and wells in a conflict zone translates to mapping the humans behind ransomware crews, why our industry has become excellent at indicators of compromise and knows almost nothing about the actual people, and what the Cybercrime Atlas found when it started pulling names, aliases, bank accounts, crypto wallets and bulletproof hosting together into targeting packages for Interpol, Europol and the FBI.David and Glenn also dig into why better defence alone was never going to be enough, the gap that sits on the people and process side rather than the technology side, and the unreported soft underbelly of an economy built on small and medium business. Glenn explains how the new bounty program works, how someone with intelligence on a threat actor can submit an anonymous tip and potentially collect a reward when that person is arrested and prosecuted, and why the same infrastructure mapping may help pull far worse criminals off the streets.There is a human side too. Glenn talks about the young man in Eastern Europe committing cybercrime to get his family out, the scam compounds operating a couple of hours to Australia's north, and his own experience of being scammed through Facebook Marketplace. He explains why he tells that story publicly and how shame keeps victims silent.Glenn closes with practical advice for CISOs, SOC leads and analysts who will never run a takedown themselves.Content note: this episode includes brief references to human trafficking, forced labour in scam centres and child exploitation material in the context of organised crime.Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at [email protected].

  6. 80

    The Ones Who Do Nothing: Ant Cohen on What Your Phishing Metrics Are Missing

    On this episode of Cyber Voices, host David Savva-Willett is at the tail end of Canberra CyberConnect 2026, AISA's first ever event in the nation's capital, sitting down with a guest who has one of the best job titles in Australian cyber.Ant Cohen is Head of Security Influence and Trust at nbn. Before cyber, he built some of the most recognisable marketing campaigns this country has seen, from Oprah's Australian adventure to 25 Wallabies campervans touring New Zealand during the Rugby World Cup to a gold medal winning campaign for the Australian Olympic and Paralympic teams in London. He now brings that storytelling firepower to human centred cyber defence, and sits on a NSW Crime Stoppers advisory committee.David and Ant get into why security awareness has a well earned reputation for being boring and occasionally condescending, and Ant's diagnosis of the problem: an oversupply of supply. The industry has indulged in training, drills and metrics reporting without ever building the demand.The idea that stops David in his tracks is the do nothing cohort. Security teams obsess over the people who click and celebrate the people who report, but the largest group by far is the people who open the simulation, leave it sitting in the inbox and take no action at all. Ant explains why the time of day, the device and the out of office setting tell you far more about your culture than a click rate ever will, and why he is a believer in small data over big data.The conversation also covers whether phishing simulations remain tenable after a decade of use, the difference between decisions made cold and decisions made in the heat of the moment, closing the loop so people know a human actually reads what they report, and the scale of nbn's responsibility given the proportion of Australia's daily data traffic that crosses the network. Ant's team of four works alongside nbn Local to reach regional and rural communities, libraries and the Country Women's Association with scams education aimed squarely at the Australians most often targeted.And his one thing for cyber leaders heading back to work on Monday: learn your audience, and learn the language they actually speak.Recorded live at Canberra CyberConnect 2026.

  7. 79

    The Human Firewall: Darren Fleming on Staying Clear Headed in a Crisis

    Every playbook and SOP you have ever written assumes it will be picked up by a calm, fully regulated human. My guest this episode reckons that assumption is exactly where incident response quietly falls apart.Recorded live at AISA's inaugural CyberConnect Canberra 2026 at the Hotel Realm, David Savva-Willett sat down with Darren Fleming, peak performance strategist, author, and the man better known as That Mindfulness Bloke. Darren represented Australia in elite sailing, studied psychology and philosophy at Oxford, has written seven books on communication, leadership and mindset, sat in complete silence for ten days, and spent more than twenty years coaching global organisations including Caterpillar, Cisco, BHP and Rio Tinto on how to perform under pressure.His CyberConnect talk, The Human Firewall, covers the thing no runbook touches: what actually happens to a responder's brain in the first hours of a Sev1.They get into why the nervous system, not the playbook, makes the decision. How adrenaline and cortisol cut off access to long term memory, and why "it made sense at the time" is a physiological answer rather than an excuse. The difference between situational awareness, stretched awareness and tunnel vision, and why "I just didn't see it" keeps turning up in the debrief. Why incident teams start turning on each other under pressure, and why that is the body working exactly as designed rather than a culture problem. What ten days of Vipassana taught Darren that a psychology degree could not. The collapse of the average attention span from roughly two and a half minutes to under a minute in twenty years. How a SANFL club lifted its win rate by changing what three senior players did during the half time break. And the one technique Darren would hand a CISO heading into a tabletop next week.Find out more about Darren's work at thatmindfulnessbloke.comCyber Voices is the official podcast of the Australian Information Security Association. Subscribe wherever you get your podcasts and leave us a five star rating, it genuinely helps others find the show. Learn more about AISA or become a member at aisa.org.au

  8. 78

    Earning the Chair: How Graham Fairley Became PEXA's CISO

    Most people arrive at the CISO chair from the outside. Graham Fairley did the opposite — he earned it from within.In this episode, host David Savva-Willett sits down with Graham Fairley, Chief Information Security Officer at PEXA (Property Exchange Australia), for a candid and personal conversation. Davey held the CISO role at PEXA before Graham, and the two have been friends and colleagues for the better part of a decade — which makes this a rare, honest look at what it actually takes to grow into one of the most demanding seats in Australian cyber.Graham progressed through identity and access management, security consulting and a security services lead role before stepping into the CISO chair in late 2024. Eighteen months in, he reflects on the learning curves nobody warns you about: winning executive and board buy-in, sitting with the weight of accountability, learning to let go of the technical work he loves, and becoming the kind of storyteller a modern security leader has to be.They also get into what PEXA actually protects — a platform underpinning Australia's ~$10 trillion property market and designated critical infrastructure — including the 6.5 million intrusion attempts PEXA blocked in a single financial year, four times the previous year's volume. Graham unpacks PEXA's layered defence approach, and the harder problem beyond the platform: the consumer. As he puts it, criminals don't need to compromise systems — they just need to compromise trust. In this episode:Why the "internal" route to CISO is undervalued — and the edge it gives youThe first 18 months in the chair, and the skills that sharpened fastestWhy every CISO has to be a storyteller (and where AI genuinely helps)Learning to step back so the team — not the CISO — becomes the heroDefending critical infrastructure at scale: layered controls, threat intel and speed-to-detectSocial licence, shared accountability and PEXA's Safeguarding Your Property Settlement white paperAI-supercharged business email compromise, and the "stop and think" habits that stop itReal advice for anyone who wants the CISO job one dayCyber Voices is the official podcast of the Australian Information Security Association (AISA). If you're enjoying the show, a five-star rating (about five seconds of your time) genuinely helps more people find it.Interested in sponsoring Cyber Voices or reaching the AISA community at CyberCon? Contact the AISA national events and sponsorship team via [email protected].#CyberSecurity #CISO #AISA #CyberVoices #PEXA #CriticalInfrastructure #InfoSec #Leadership

  9. 77

    Breachonomics Redux: Grant McKechnie on the Untold Cost of a Data Breach

    On this episode of Cyber Voices, host David Savva-Willett is on the ground at Canberra CyberConnect 2026, AISA's inaugural event in the nation's capital, sitting down with Grant McKechnie for a conversation that CFOs and board members need to hear.Grant is Managing Partner at Cyber Resilience Group and a two-decade CISO veteran of Endeavour Group, Telstra and NBN. He was named one of the top 10 CISOs in Asia Pacific in 2022 and has built greenfield cyber security functions across some of Australia's most critical infrastructure. Today at CyberConnect he has returned with Breachonomics Redux, a follow up to the passion project he has been researching for the past four years on the untold economic and human impacts of a data breach.We get into the share price data behind major Australian and global breaches, from Medibank's 198 days back to parity to Live Nation's share price actually climbing after a breach affecting 560 million records. Grant unpacks why the market is becoming ambivalent, why Australian penalties never match the crime, and why trust and communications have overtaken share price as the impact he now leads with when advising boards. We also dig into how threat actors are adapting (including calling the regulators on their own victims), why information sharing has quietly gotten worse even as we appear to share more, the three critical first hires when building a cyber function from a blank page, the underrated art of finding a board sponsor before you need one, and the crucial difference between what belongs in an ARC pack versus a full board pack. If you have a CFO or a board member in your life, this is the one to forward on

  10. 76

    Rain, Hail or Shine: Chris Stannage on Cyber Run Club, Community and Mental Health

    This episode is a little bit different. Yes, my guest works in cyber security, but we are not here to talk about breach containment or zero trust architecture. We are here to talk about the people behind the industry and what it actually takes to show up and do this job sustainably.Chris Stannage is a Scottish born, Melbourne based Senior Account Executive at Illumio, a former competitive rugby player, and the founder of Cyber Run Club, a monthly gathering at the Tan that brings cyber professionals together for movement, fresh air and honest conversation with zero pressure and zero sales pitches.We chat about the lunch that sparked the whole idea, the strictly sales free ethos and why it works, the organic connections made along the way (including an analyst picking the brain of a CISO mid jog), mental health in our industry and why talking early matters, what competitive rugby taught Chris about teams and discipline, and his unlikely path from a microbiology degree to cyber sales.Cyber Run Club meets on the last Thursday of every month at the Tan in Melbourne. Walk, jog or run, everyone is welcome, from students to CISOs. Find the group by searching Cyber Run Club on LinkedIn.A note on mental health: our conversation is general in nature and we are not experts in this space. If anything in this episode raised something for you, support is available. Lifeline 13 11 14 or lifeline.org.au. Beyond Blue 1300 22 4636 or beyondblue.org.au.

  11. 75

    Emily Holyoake on Security Culture, Human Risk and Canberra Roundabouts

    Recorded live at the inaugural Canberra CyberConnect 2026, David sits down with Emily Holyoake, Executive Director and co-founder of Not A Standard and one of the creators of the SAFE Framework, a multidisciplinary approach that brings cyber security, criminology and behavioural science together to map how adversaries exploit people, technology and systems. Emily is a proud Wurundjeri woman and a passionate advocate for neurodiversity in cyber.In this conversation, Emily unpacks the thinking behind one of the best titled talks on the program, Navigating Human Risk: What to Do When Your Security Culture Handles Like a Canberra Roundabout. She explains why great security culture is really a design problem, when you want people safely on autopilot and when you want them to slow down and think, and why phishing simulations so often do more harm than good. Along the way she makes the case that humans are our greatest asset rather than the weakest link, that looking after our people is the best defence against insider risk, and that we all need to be wrong more.Whether you are a new CISO building your first 30-day plan or you simply want to bring your security program back to the people it serves, this one is full of practical and genuinely human thinking.Please note this episode contains a brief reference to suicide. If anything in this episode affects you, support is available in Australia through Lifeline on 13 11 14 or at lifeline.org.au. If this conversation resonates with you, subscribe to Cyber Voices on your podcast app of choice and leave us a five-star review. It helps others find the show.Cyber Voices is the official podcast of the Australian Information Security Association (AISA).

  12. 74

    The Sword Cuts Both Ways: Professor Toby Walsh on AI, Mythos and the New Normal in Cyber

    On this episode of Cyber Voices, host David Savva-Willett is at Canberra CyberConnect 2026, AISA's inaugural event in the nation's capital, for a wide-ranging conversation with Professor Toby Walsh, one of the world's most influential voices in artificial intelligence.Toby is a Professor of AI at UNSW Sydney and Chief Scientist of UNSW AI. He has advised the United Nations and heads of state on the limits we need to place on AI, and his outspoken stance on the military uses of the technology famously earned him an indefinite ban from Russia.In this conversation, Toby and David dig into what AI really means for cyber defenders right now. They discuss Anthropic's Mythos and the wave of decades-old zero-day vulnerabilities now being uncovered, why this is the new normal rather than a one-off event, and how AI has democratised offensive capability so that sophisticated attacks no longer require deep technical expertise.They also explore the questions that matter most for security leaders: whether defenders are really losing the AI arms race, why dwell time has collapsed from 200 days to a smash-and-grab measured in hours, the rise of shadow AI arriving both top down and bottom up, the sovereignty risk when powerful tools are released only to a select few, and the lessons from the Canvas breach where attackers did not hack the front door, they simply logged in.Toby also lifts the lid on the ideas behind his latest book, The Shortest History of AI: Six Ideas Are All You Need to Know, including why AI is a 70-year overnight success and why the human brain, running on the power of a dim light bulb, still puts our most advanced machines to shame.Whether you are a CISO being asked to govern AI while still learning it yourself, or simply trying to separate the signal from the hype, this is a clear-eyed and occasionally very funny look at where AI and cyber security collide.Topics covered:Why AI is a double-edged sword for cyber, threat and defence at onceAnthropic's Mythos and the discovery of zero-day flaws nearly 30 years oldHow AI has lowered the barrier to entry for sophisticated attacksWhether defenders are losing the AI arms raceDwell time collapsing from 200 days to under two hoursShadow AI, and how security leaders can actually govern itSovereignty risk and the case for stronger regulationThe Canvas breach and the era of just logging inSix big ideas from The Shortest History of AICyber Voices is the official podcast of the Australian Information Security Association (AISA).

  13. 73

    When Everything Is On Fire: Shane Fitzsimmons on Leading Through Crisis

    Recorded live at CyberConnect Canberra 2026, Cyber Voices host David Savva-Willett sits down with Shane Fitzsimmons AO AFSM, Managing Director of SAF Leading Advisory, former Commissioner of the New South Wales Rural Fire Service and inaugural Commissioner of Resilience New South Wales. David grabbed Shane straight off the main stage, minutes after his opening keynote on leadership in unprecedented times.Few people understand leadership under sustained pressure the way Shane does. He led New South Wales through the Black Summer bushfires, the floods that followed, biosecurity threats, critical infrastructure incidents and a global pandemic. His message to a room full of cyber leaders is strikingly simple. No matter the crisis, we are all part of a people organisation, and people are the anchor.Across the conversation Shane and David explore why a security leader's most important job is translation, turning complex and jargon heavy detail into plain language that paints an accurate picture for the board and the community. They dig into leadership as a culture rather than the sole purview of the person at the top, why trust and shared values have to be banked in the quiet times before any siren sounds, and why the most powerful thing a leader can say in a crisis is "I don't know, but I will find out."Shane also shares hard won lessons on looking after people in sustained pressure roles, the kind of burnout that incident responders and volunteers know all too well, and his belief that professionalism has nothing to do with whether you are paid. The pair turn to resilience and the discipline of learning from others rather than waiting for the crisis to find you, the value of after action reviews that capture what went well and not just what went wrong, and the knowledge transfer that readies the next team to step up.He closes with a single piece of advice for any cyber leader walking into the boardroom in the middle of an incident. Listen, keep it real, drop the ego, and let people know you care.This is an episode for every level of a security team, and one worth sharing well beyond our industry. If it lands with you, subscribe to Cyber Voices on your favourite podcast app and leave us a five star review. Full show notes are in the episode description.

  14. 72

    Turning Off the Tap: Andrew Haschka on AI, Vulnerabilities and the Software Supply Chain | GitLab

    In this episode of Cyber Voices, the official podcast of AISA, host David Savva-Willett is joined by Andrew Haschka, Field CTO for Asia Pacific and Japan at GitLab, for a candid look at the question almost every enterprise is wrestling with right now: how do we let developers move faster with AI without flooding production with vulnerabilities we cannot keep up with? With more than two decades across cyber security, cloud and digital transformation, and prior leadership roles at Google and VMware, Andrew advises organisations and governments across the region on delivering software securely and at speed.At the heart of the conversation is what Andrew calls the AI paradox. AI can make writing code dramatically faster, yet the flow on effects in testing, security validation, compliance and release often slow teams down, because the volume of code rises while the team stays the same size. Much of that AI generated code is drawn from the internet, where not everything is secure by design, so vulnerabilities can increase exponentially. Andrew and David explore the memorable goal of one CISO to turn off the tap of vulnerabilities running in production, and why prevention beats endless triage.From there the discussion moves to the consumerisation of AI and the sprawl of unmanaged tools, the importance of a traceable system of record that evolves into a knowledge graph, and the defender's advantage in the arms race between teams shipping AI assisted code and attackers using AI to find weaknesses. Andrew makes the case that a defender whose AI understands the specific code base, threat model and compliance posture will spot what a generic attacker AI misses.Andrew also unpacks what secure software supply chains look like in an AI assisted world, from integrity and attestation to provenance and traceability, and shares practical guidance for any security leader being asked to enable AI for their development teams. His advice centres on building intelligent orchestration across three layers: a unified data layer and system of record, strong control and access with purpose built agents, and a governed experience delivered through an AI gateway rather than uncontrolled sprawl, all with humans firmly in the loop. It is a practical and forward looking conversation for any CISO, engineering leader or developer trying to capture the benefits of AI without inheriting a new generation of risk.

  15. 71

    The Chair's Check In: Michael Burchell on AISA at the Halfway Mark of 2026 | CyberConnect Canberra

    In this episode of Cyber Voices, the official podcast of AISA, host David Savva-Willett sits down with Michael Burchell, Chair of the Australian Information Security Association, for a mid year check in on the state of Australia's peak body for cyber security. Recorded on the floor at the inaugural CyberConnect Canberra in the nation's capital, it is a candid look at where AISA sits at the halfway point of 2026, and, fittingly, it is Michael's very first podcast.The conversation opens with the reimagining of the event itself, the move from CyberCon Canberra to CyberConnect Canberra, and why a smaller, more curated and more local gathering is the right way to connect industry and professionals with government on regulation, consultation and cyber strategy. Michael and David also reflect on the proud tradition of the Australian Parliament House dinner in the Great Hall.From there the discussion turns to the year so far for an association now representing more than 14,000 members. Michael shares an update on the professionalisation town halls held around the country, the launch of the new Learning Portal for ongoing professional development, the scholarship program and its diversity work alongside partners such as AWSN, and the board's new long term strategy built around strategic pillars and a horizons approach.He also looks ahead to the SEC days still to come in Sydney, Adelaide, Perth and Darwin, and to the flagship CyberCon in Melbourne, with early bird registrations now open. Above all it is a thank you to the volunteers and branch committees who, in Michael's words, are the reason the association exists at all.Links to resources mentioned in this episodeAISA professionalisation pilot, including the key questions and responses Michael mentioned: https://aisa.org.au/public/Public/News_and_Media/Professionalisation/Professionalisation.aspxAISA Learning Portal, available now to all members (accessed through the AISA member area) https://www.aisa.org.auCyberCon Melbourne, early bird registrations open: https://www.cyberconference.com.au/ Australian Women in Security Network (AWSN): https://www.awsn.org.au/

  16. 70

    Nicole Stephensen on Privacy Impact Assessments and Securing Personal Information | BrisSEC 2026

    In this episode of Cyber Voices, the official podcast of AISA, recorded live on the floor at BrisSEC in Brisbane, host David Savva-Willett sits down with Nicole Stephensen, a strategic risk and privacy professional recognised for her local and international expertise in privacy program management and her work as an expert witness on the reasonable steps needed to secure personal information across its lifecycle.Nicole is a Fellow of the Australian Information Security Association (FAISA) and a leading member of the International Association of Privacy Professionals (IAPP). Fresh from a panel alongside Queensland Privacy Commissioner Alexander White and IDCARE interim Group CEO Charlotte Davidson, Nicole unpacks what a privacy impact assessment really is, why it belongs in every cyber security toolkit, and what happens when organisations skip it.She also shares a memorable reframe from the panel: think of a privacy impact assessment less like a yes or no gate and more like a navigation system. The question stops being can we do this and becomes how do we get there safely, steering around the potholes, roadblocks and unnecessary costs along the way.The conversation explores where privacy and security overlap and where they differ, the reasonable steps expected under Australian privacy law, the recent alignment of Queensland privacy law with the federal approach, and the most common mistake of all, which is simply not doing a privacy impact assessment when you could. As Nicole explains, a good PIA does not have to be onerous or expensive, with free toolkits and templates available from both the federal and state privacy regulators.Links to resources mentioned in this episode:Federal resources, from the Office of the Australian Information Commissioner (OAIC): Guide to undertaking privacy impact assessments https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/guide-to-undertaking-privacy-impact-assessmentsPrivacy impact assessment tool (the free, adaptable template) https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/privacy-impact-assessment-tool10 steps to undertaking a privacy impact assessment https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/10-steps-to-undertaking-a-privacy-impact-assessmentQueensland resources, from the Office of the Information Commissioner (OIC): Privacy impact assessments (step by step guide) https://www.oic.qld.gov.au/guidelines/for-government/guidelines-privacy-principles/privacy-impact-assessmentsUndertaking a Privacy Impact Assessment (the full guideline) https://www.oic.qld.gov.au/guidelines/for-government/guidelines-privacy-principles/privacy-impact-assessments/undertaking-a-privacy-impact-assessmentPIA templates, including the threshold privacy assessment and the PIA report templates https://www.oic.qld.gov.au/information-for/information-privacy-officersPIA assessments from the Queensland OIC:https://www.oic.qld.gov.au/government/privacy/privacy-impact-assessments

  17. 69

    The 2026 Threat Landscape, Iran, and AI-Powered Phishing with Michael Kosak

    Mike Kosak joins Cyber Voices to deliver a frank assessment of the 2026 cyber threat environment: it's not great, and it's getting worse. Mike is Director of Threat Intelligence at LastPass, with nearly 25 years of experience that began in the US Department of Defense as a counterterrorism intelligence officer. He served three deployments to Iraq supporting Operation Iraqi Freedom, led the Pentagon office responsible for intelligence updates to the Chairman of the Joint Chiefs of Staff, and acted as senior command representative to Joint Special Operations Command for the Defence Intelligence Agency. Since moving into the private sector he has led strategic cyber intelligence at Bank of America, headed the Cyber Threat Intelligence team at TIAA, and now drives threat intelligence at LastPass.In this conversation Mike and David unpack what the ongoing conflict in the Middle East means for Australian defenders, why Five Eyes membership puts Australia squarely in scope regardless of physical proximity, and how Iran targets opportunistically and then retrofits the rationale to fit. They look at China and Taiwan as a potential 2027 flashpoint, with critical infrastructure, education, and the defence industrial base already in frequent crosshairs. The conversation then shifts to phishing, where AI has lowered the barrier to entry and lifted operational tempo dramatically. Mike shares what his team has been observing as a single threat actor group develops its own AI-assisted phishing kit across three increasingly sophisticated versions, evolving from a basic login page to an attacker-in-the-middle reverse proxy.The episode closes with practical guidance for the Australian cyber community: the Essential Eight still gets you 80% of the way there, and getting a real handle on your tech stack, including shadow AI and shadow tech, will pay enormous dividends as the gap between vulnerability detection and exploitation continues to shrink. Subscribe to Cyber Voices wherever you get your podcasts, and find us on YouTube for the video version.

  18. 68

    Responding to a Cyber Crisis You Don’t Control with Darren Hopkins | BrisSEC 2026

    In this episode of Cyber Voices, recorded live at BrisSEC 2026, host David Savva-Willett speaks with Darren Hopkins, Partner at McGrathNicol and a Brisbane-based cybersecurity professional with more than 30 years’ experience across law enforcement, digital forensics, incident response and cyber crisis management.Darren shares insights from his BrisSEC talk, “When You’re Already Losing: Responding to a Cyber Crisis You Don’t Control,” exploring the messy reality of cyber incidents where the playbook does not match the crisis. From third-party suppliers and SaaS dependencies to ransomware negotiations, regulators, media pressure, board expectations and limited information, Darren explains why effective incident response requires more than a neatly documented plan.David and Darren discuss why cyber crisis simulations matter, how organisations can build decision-making muscle memory, the importance of update cadence, the risks of over-communication, and why many incidents remain preventable through basic cyber hygiene, prioritisation and executive support. This episode is essential listening for CISOs, security leaders, board members, risk teams, communications professionals and anyone involved in preparing for or responding to a cyber incident.In this episode, we cover:How to respond when you do not control the cyber crisisWhy incident response plans still matter, even when reality gets chaoticThe role of executives, legal, communications, HR and technical teams during a breachWhy third-party and SaaS risk changes crisis responseHow cyber simulations can prepare boards and leadership teamsThe importance of clear communication and update cadenceWhy are many cyber incidents still preventableWhat cyber leaders should start doing differently today

  19. 67

    Inside the Mind of an Attacker — Atticus D'mello on Bypassing Social Media's Security Controls | BrisSEC 2026

    Recorded live on the floor at BrisSEC 2026 in Brisbane, David Savva-Willett sits down with Atticus D'mello, higher degree research student, vulnerability researcher, and emerging cybersecurity specialist with Safety Net Cyber, to unpack his BrisSEC talk Inside the Mind of an Attacker.Atticus walks us through how he and his team approached one of the most under-discussed problems in consumer cybersecurity: how attackers bypass account creation limits on the world's biggest social media platforms to spin up anonymous accounts at scale. Working with nothing more than a laptop and a typical home internet connection, they mapped the controls, found the gaps, and responsibly disclosed the vulnerabilities, many of which have now been fully patched.The conversation goes beyond the technical, exploring why burner accounts are the gateway to online bullying, mass phishing, artificial engagement, and large-scale scams, and the very real human toll that follows. Atticus also shares his work helping victims regain access to compromised Instagram and Facebook accounts, the rise of fake "Meta verification" phishing emails, why TikTok's security-by-default model is worth paying attention to, and what every one of us can do to make social media a safer space. If you've ever wondered how those random accounts in your DMs come from nowhere — this one's for you.

  20. 66

    Quantum Safe Queensland: A Practical Roadmap with Prof. Craig Costello | BrisSEC 2026

    Q-Day is coming — and the encryption protecting your most sensitive data may already be on borrowed time. In this episode of Cyber Voices, host David Savva-Willett sits down at AISA's BrisSec 2026 with Professor Craig Costello, cryptographer at the Queensland University of Technology and one of the global researchers shaping post-quantum cryptography (PQC) standards. Craig demystifies what post-quantum cryptography actually is, why "harvest now, decrypt later" attacks mean the threat is already here, and what recent breakthroughs from Google AI, UC Berkeley and Caltech mean for the timeline. He unpacks Google's bold 2029 Q-Day prediction, explains why PQC runs on the classical hardware you already own, and walks through a pragmatic transition roadmap aligned to the Australian Signals Directorate's guidance — from naming a transition lead and running an inventory scan, to prioritising key exchange over digital signatures, and managing vendor migrations. Whether you're a CISO, security architect, or just trying to understand what quantum computing really means for your organisation, this is a clear-eyed, panic-free conversation about preparing for the biggest cryptographic shift in 50 years.Topics covered:• What post-quantum cryptography is (and isn't)• Harvest now, decrypt later attacks explained• Why Google says Q-Day arrives by 2029• Recent algorithmic breakthroughs lowering qubit requirements• A practical PQC transition plan: 90 days and beyond• ASD guidance and the road to 2030• Crypto agility as a long-term security disciplineCyber Voices is the official podcast of the Australian Information Security Association (AISA).Planning for Post-Quantum Cryptography (the page Craig referenced directly) The ASD's practical framework covering inventory scans, transition timelines, and milestones — including the recommended deadline of end of 2030 to cease use of traditional asymmetric cryptography. 🔗 https://www.cyber.gov.au/business-government/secure-design/planning-for-post-quantum-cryptographyInformation Security Manual (ISM) — landing page The full ISM, intended for CISOs, CIOs, and cyber security professionals. 🔗 https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ismISM — Guidelines for Cryptography The chapter that contains the specific PQC controls Craig mentioned, including ISM-2073 (PQC transition plan requirement) and the list of ASD-approved post-quantum algorithms. 🔗 https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-cryptography Professor Craig Costello — QUT profile For listeners who want to take Craig up on his offer to engage directly with industry partners. 🔗 https://www.qut.edu.au/about/our-people/academic-profiles/craig.costello

  21. 65

    Inside the Dark Web Economy: Anastasia Tikhonova on 2026's Top Cyber Threats

    The Problem of Trust: Identity Fraud, Deepfakes & APAC Threat Trends with Anastasia TikhonovaWhat happens when cybercriminals stop attacking your CEO and start targeting your developers instead? In this episode of Cyber Voices, host David Savva-Willett sits down with Anastasia Tikhonova, Global Threat Research Lead at Group-IB, joining live from Phuket, Thailand, to unpack the threat trends defining 2026 — and why Australia remains squarely in the crosshairs. Anastasia shares how her team connects threat intelligence dots across APAC, EMEA, and Latin America, and explains why she calls 2026 the year of "the problem of trust" — where attackers no longer need just your email and password. They want your voice, your face, your LinkedIn, and your professional connections to impersonate you convincingly enough to compromise the organisations you work with. In this episode, you'll hear about:The rise of identity fraud, deepfakes, and AI-powered social engineeringWhy Scattered Spider, Lazarus Group and others are shifting from mass campaigns to highly targeted persona attacksThe Axios NPM supply chain compromise (80 million weekly downloads) and what it means for every organisationHow dark web marketplaces, arbitration "courts," and Telegram-based criminal communities operate todayWhy Australia is the #2 ransomware target in APAC — and the lessons from the April 2025 super fund attacksThe role of hacktivism, geopolitical conflict, and national state actors in Australian threat activityPractical advice on managing your digital footprint when you, your family, or your executives have a public profileWhether you're a CISO, security analyst, developer, or simply curious about how cybercrime is evolving, this conversation delivers global perspective with sharp Australian relevance. Cyber Voices is the official podcast of the Australian Information Security Association (AISA) — bringing you the voices shaping cybersecurity in Australia and beyond. 🎧 Subscribe wherever you get your podcasts and follow AISA for more.

  22. 64

    Year One in the Seat: Tara Dharnikota on What It Really Takes to Be a CISO

    What does it really take to step into the CISO seat, and thrive? In this episode of Cyber Voices, the official podcast of AISA and the home of Australia's cybersecurity community, host David Savva-Willett sits down with Tara Dharnikota, Chief Information Security Officer at Victoria University. With a career spanning Telstra, PEXA, and now one of Australia's leading universities, Tara brings a rare blend of offensive security expertise, OSINT, and executive leadership. In this candid conversation, she reflects on her first year as CISO, what surprised her, what she'd do differently, and what the role of the future really looks like. In this episode, you'll hear:Why the CISO role is fundamentally about translation, not just technologyHow to communicate security risk to boards and executives in a language they actually understandThe trap of trying to prove yourself too fast — and why influence matters more than expertiseWhat "building security with people" rather than for them really means in practiceThe convergence of cyber and physical security in complex environments like universitiesTara's vision for the CISO of 2030 — and what aspiring CISOs should be doing right nowThe role that communities like AISA play in shaping future security leadersWhether you're an aspiring CISO, a seasoned security leader, or an executive trying to better understand your security function — this episode is essential listening.🎟️ Early bird registrations for the Australian Cyber Conference 2026 are open now — 14–16 October. AISA members grab a full 3-day Gold Pass for just $899. Head to cyberconference.com.au before 30 June.Subscribe, leave a 5-star review, and share this episode with someone on their path to the CISO seat.

  23. 63

    Navigating the Passkey Revolution with VicRoads

    In a groundbreaking move, Igor Gjorgjioski from VicRoads embarked on a digital transformation journey to enhance security and user experience by eliminating traditional passwords. Collaborating with Vincent Delitz from Corbado, a passkeys-as-a-service provider, they successfully implemented one of the largest public sector deployments of passkeys. This initiative aimed to address user friction and bolster security against phishing, with a keen focus on mobile-friendly, phishing-resistant logins. The project's success rested on a phased rollout, careful selection of partners, and strategic nudging of users towards adopting passkeys, setting a new standard for digital authentication in the public sector.

  24. 62

    Building Cyber Communities with Jasmine McCrudden

    In this episode of Cyber Voices, Jasmine McCrudden shares her inspiring journey from a tech recruiter to a key player in the Australian cybersecurity community. As the Deputy Chair of the Australian Information Security Association (AISA) in New South Wales, Jasmine emphasises the importance of community and networking for career development in cybersecurity. She discusses how overcoming imposter syndrome and volunteering with AISA have shaped her leadership style. Jasmine's dedication to uplifting women and creating pathways in cybersecurity is evident in her impactful contributions to the industry, recognised by multiple awards and her dynamic role within AISA.

  25. 61

    Rebranding Cyber with Emily Woodhams

    At CyberCon Australia 2025, Emily Woodhams shared her experience as the Cybersecurity Engagement Manager at Melbourne University. Her role involves enhancing communication and culture around cybersecurity by using innovative branding strategies, including Australian animal imagery linked with cyber behaviors. This approach moves away from clichéd cyber imagery like hackers in hoodies, aiming to demystify and humanize the field. Woodhams' journey from a communications background to a cyber role highlights the demand for storytelling skills in cybersecurity, a theme echoed throughout the conference. University branding changes prompted a larger initiative to create relatable and engaging cybersecurity messaging.

  26. 60

    Tackling Abuse Material Online with Joel Scanlan

    Content WarningIn this episode, we discuss topics that some may find triggering, relating to child sexual abuse material on the internet. David Willett hosts Joel Scanlan from the University of Tasmania to discuss strategies in preventing child sexual abuse material (CSAM) online. Joel highlights the importance of integrating safety by design on mainstream platforms, following alarming statistics of accidental exposure to CSAM. Emphasising deterrent measures, they explore the effectiveness of warning messages and chatbots in dissuading potential offenders. Both highlight the role of large tech firms and regulators in enhancing transparency and accountability, aiming to create a safer digital environment with fewer opportunities for CSAM to proliferate.https://www.stopitnow.org.au/ "Stop It Now! Australia is a child sexual abuse prevention program which works with adults concerned about their own, or someone else’s sexual thoughts or behaviours towards children."https://www.csamdeterrence.com/ 

  27. 59

    Gaurav Vikash Asks: Are Our Cars Spying on Us?

    In this episode, cybersecurity expert Gaurav Vikash discusses the privacy risks associated with smart cars and connected vehicles. As vehicles become more technologically advanced, they are equipped with features that collect and transmit user data, ranging from voice recordings to health information. Gaurav emphasises that many consumers remain unaware of the extent of data collection in modern vehicles, falsely assuming their privacy is protected like in traditional cars. He discusses industry practices, including Tesla's case where their app was used for stalking, and highlights the lack of comprehensive regulations, urging for better awareness and legal protections.

  28. 58

    Navigating Insider Threats with Jordan Carmichael

    Jordan Carmichael, CEO of Helix Services, discusses the intricacies of insider threats and digital vetting in today's cyber landscape. With a focus on critical infrastructure, Carmichael emphasises the importance of identifying and managing human risk, especially as online radicalisation becomes more prevalent. The conversation pivots around the delicate balance between using open source intelligence for security and safeguarding individual privacy. 

  29. 57

    Protecting Kids Online with Bailey Marshall

    In this episode of Cyber Voices, host David Willett discusses the critical issue of children's online safety with Bailey Marshall, co-founder of Future Proof Security. Bailey shares insights on common online threats facing children today, ranging from cyber scams to issues of privacy and data misuse. Emphasising the importance of communication, she advocates for a balanced approach where parents and educators are equipped to have non-judgmental, trust-building conversations with kids. This empowers them to navigate the digital world safely, reducing the fear and embarrassment that often keep kids from reporting online issues.Find more info HERE

  30. 56

    Unmasking Trust Attacks with Max Heinemeyer

    In this insightful episode of Cyber Voices, David Willett dives into the complexities of trust attacks with Max Heinemeyer at CyberCon 2025. Max brings an innovative perspective by simulating a politically motivated cyberattack on Australian infrastructure. He emphasises the growing concern over trust attacks, differentiating them from traditional cyber threats that focus on confidentiality and availability. Trust attacks, involving the manipulation of critical data, pose a severe risk to national stability. Through this discussion, the episode highlights the pressing need for improved cybersecurity frameworks to address the evolving threat landscape driven by hyper automation and modern AI technologies.Further reading provided by Max: On the Feasibility of Using LLMs to Autonomously Execute Multi-host Network Attacks https://arxiv.org/abs/2501.16466v3Teams of LLM Agents can Exploit Zero-Day Vulnerabilitieshttps://arxiv.org/abs/2406.01637Hexstrike AI Open Source Offensive Security AI Orchestrator - https://www.hexstrike.com/AI Agent XBOW making number one on Hackerone leaderboard - https://xbow.com/blog/top-1-how-xbow-did-itAI-enabled prototype ransomware PromptLocker - https://www.eset.com/us/about/newsroom/research/eset-discovers-promptlock-the-first-ai-powered-ransomware/?srsltid=AfmBOop67a943J8-_KuK_8dNC497RoWo1YCELz4eR8wSFUV6NqJy6R1RAnd then this happened since we recorded our podcast, but is highly relevant - https://www.anthropic.com/news/disrupting-AI-espionage

  31. 55

    The Cyber Escape Room Challenge with Tony Nicholls

    At the 2025 CyberCon in Melbourne, Tony Nicholls from CGI Australia introduced a new concept - a cyber escape room housed in a shipping container. Originally developed in the UK to raise cyber awareness, the escape room gamifies cybersecurity education, targeting both novices and professionals. It offers a hands-on approach to learning about phishing, social engineering, and malware, promoting a no-shame, team-based environment ideal for schools and businesses alike. With the ability to adjust difficulty on the fly, participants of all ages leave with a better understanding of cybersecurity threats and defenses, with a smile on their face.

  32. 54

    Unmasking Insider Threat with Jason Plumridge

    In this episode, Jason Plumridge from Thales Cyber discusses the growing threats posed by foreign intelligence entities. He explains how these operatives target individuals within organisations to access sensitive data. The conversation highlights the role of physical and personal security in mitigating these risks and stresses the importance of identifying employee behavioral changes as potential red flags. The discussion delves into recruitment strategies used by operatives and underscores the need for robust insider threat programs, including continuous employee monitoring and strategic controls at both the personnel and physical levels.

  33. 53

    Igniting a Global STEM Revolution with Kari Byron

    In this episode of Cyber Voices, Kari Byron, known for her role on MythBusters, discusses her evolution from television host to STEM advocate. She is spearheading a global mission to promote STEM through a reimagined version of the White House Science Fair, now a national festival that transcends politics by involving industry sponsors. Byron explains how this initiative not only highlights young talent but also creates vital connections between students and industry leaders. The end goal is to empower the next generation of innovators, making STEM careers more accessible and fostering a worldwide community of future leaders.Make sure you check out Kari's podcast, Mythfits! 

  34. 52

    Spotting Malicious Remote IT Applicants with Michael Puckridge and Jamie Lindsay

    In this gripping episode of Cyber Voices, we delve into the intricate web of North Korean cyber operations, revealing how the nation operates more like an international criminal network than a traditional state entity. Michael Puckridge and Jamie Lindsay from DTEX discuss their investigations into North Korea's covert cyber workforce. These malevolent actors pose as legitimate IT professionals to penetrate organizations, siphoning funds back to their homeland. This episode uncovers how these operatives exploit the remote work trend to bypass security and steal advanced intellectual property, showing the nuances of modern cyber warfare in a world still grappling with the aftermath of the pandemic.

  35. 51

    From White House to CyberCon: Theresa Payton's Impactful Journey

    In an engaging session at CyberCon Melbourne 2025, Theresa Payton shared insights from her pivotal career spanning from her role as the first female White House CIO to becoming the CEO of Fortalice. Payton captivated the audience by discussing her innovative approaches to cybersecurity, emphasising the importance of understanding human factors. She shares the success of her 'White House Happy Meal' initiative, a creative strategy to enhance cybersecurity training participation at the White House. Her keynote not only highlighted the serious cybersecurity work happening in Australia but also offered inventive solutions to global challenges.

  36. 50

    The Trident Exercise Series Explained with Tom Huth & Ryan Mclaren

    Tom Huth and Ryan Mclaren stop by to discuss the Trident exercise series, a collaborative effort by the Australian Energy Market Operator (AEMO) and Retrospect Labs, is a large-scale cybersecurity exercise designed to enhance incident response in the energy sector. With participation from over 27 organizations and 560 individuals, the exercises simulate real-world cyber threats to practice and strengthen response capabilities. Through a flexible scenario framework, the exercises cater to varying maturity levels, focusing on delivering technically credible scenarios that participants can customize to fit their environments. This initiative not only boosts sector-wide resilience but also fosters collaboration across different organisations.

  37. 49

    Meet The Incident Response Champions

    In this episode of Cyber Voices, David Willett chats with former participants of the Australian Women in Security Network (AWSN) and Retrospect Labs Incident Response Competition. The panelists, including competition winners and runners-up, share their transformative experiences in this hands-on, teamwork-based event. The competition, which simulates real-world cybersecurity incidents, highlights the importance of both technical and non-technical skills. Participants discuss how this immersive experience has propelled their careers in cybersecurity and fostered personal growth, while offering networking opportunities. The episode captures the competition's potential to redefine career paths and nurture talent in Australia’s cybersecurity landscape.Register for this years competition here: https://events.humanitix.com/2025-awsn-incident-response-competition  Get more detailed information here: https://www.retrospectlabs.com/events/awsn-2025-incident-response-competition  Or, Chek out the AWSN Events Page: https://www.awsn.org.au/initiatives/incident-response-competition/

  38. 48

    The Invisible Backbone: Why APIs Matter More Than Ever with Jeremy Snyder

    In this episode of Cyber Voices, David discusses with Jeremy Snyder, founder and CEO of Firetail, the critical yet often overlooked significance of API security in the modern digital landscape. Jeremy explains how APIs underpin most online interactions, from mobile apps to AI systems, and the large volume of personal data transferred through these gateways. Despite the rise of AI topics, API security should remain a primary focus due to its central role in Internet infrastructure. The discussion also highlights common security oversights, such as unauthenticated endpoints and unretired zombie APIs, stressing the need for diligence and organizational alignment.

  39. 47

    The Future of Non-Human Identities with Abbas Kudrati

    In this episode of Cyber Voices, cybersecurity expert Abbas Kudrati discusses the emerging challenge of non-human identities in the digital landscape. These identities, which include API keys, machine identities, and AI agents, are becoming crucial security concerns as technological advancements accelerate. Abbas shares insights into how non-human identities are defined, their inherent risks, and the shift towards them as major targets for cyber attackers. He explains the necessity of visibility and governance over these identities. He offers some strategies for securing them, emphasising the need for a proactive approach in an increasingly complex cyber environment.

  40. 46

    Beyond the Questionnaire with Yvonne Sears

    Yvonne Sears discusses innovative strategies for rethinking third-party risk assessments. Moving beyond traditional checklists, Yvonne emphasises the importance of aligning assessments with organisational goals and risk profiles. By focusing on specific objectives and measurable outcomes using OKRs, organisations can enhance trust, transparency, and resilience across their supply chains. The conversation highlights the limitations of standard questionnaires and advocates for a risk-based approach tailored to individual vendors and service providers, paving the way for more meaningful and effective partnerships.

  41. 45

    Stop Playing Whack-A-Mole with Karl Sellmann

    In this episode of Cyber Voices, host David Willett sits down with Karl Sellmann, Chief Information Security Officer at Flinders University, to discuss the ongoing challenges in cybersecurity. Sellmann emphasises the importance of moving away from a reactive, 'whack-a-mole' approach to a more strategic, long-term plan that incorporates quick wins as building blocks.By focusing on broader strategies and risk management, organisations can better align their efforts with emerging threats and maintain resilience. This involves leadership engagement, understanding organisational complexities, and ensuring ongoing adaptability and transparency in cybersecurity operations.

  42. 44

    Kill The Runbook with Zoe Adam

    In this insightful episode of Cyber Voices, David Willett interviews Zoe Adam, a seasoned cybersecurity professional leading dynamic teams at CyberCX. Newly energised after her talk at AdelaideSEC, Zoe shares her revolutionary approach to security operations. She argues for adaptability over rigid runbooks, emphasising the necessity for curiosity in incident management. Through anecdotes and personal experience, Zoe highlights how a monotonous tiered system stymies growth and curiosity. Her innovative method focuses on letting analysts own their work from start to finish, thereby unleashing their full potential and empowering them to make significant impacts.

  43. 43

    Championing Change in Cybersecurity Leadership with Dr. Susan McGinty

    In this enlightening episode of Cyber Voices, host David Willett talks with Dr. Susan McGinty, a leader in the realm of cybersecurity and STEM leadership. Dr. McGinty shares her journey from being a scientist to a passionate advocate for diversity and inclusion in cybersecurity. The discussion highlights her initiatives aimed at fostering leadership skills among women and promoting inclusive cultures within organisations.Her work through AYA Leadership and The Asstembly emphasises the need for female representation at all levels, urging companies to embrace inclusivity as a driving force for innovation and effective decision-making.The Asstembly website: https://theasstembly.com/  Susan's white paper Advancing the Cyber Security Sector: Pathway to a Diverse and Inclusive Cyber Security Workforce, https://ayaleadership.com/advancing-the-cyber-security-sector-white-paper/  The Asstembly Women's Leadership Programs: https://theasstembly.com/womens-leadership-programs/

  44. 42

    Operationalising SIEM and SOAR with Jessica Clarence

    In this special episode recorded live at AISA SydneySEC 2025, David Willett sits down with Jessica Clarence from the Australian Signals Directorate (ASD) to explore the agency’s latest efforts to uplift cybersecurity across all levels of government.Jessica offers a deep dive into the SIEM and SOAR implementation guidelines developed by the ASD, highlighting how these frameworks are helping Australian organisations—both public and private—build more resilient and responsive cyber capabilities.She also unpacks the Government Uplift mission and the role of the Australian Cyber Security Centre (ACSC) in driving practical, scalable security strategies.From resource constraints and skills shortages to the limitations of emerging tech like AI, this episode tackles the real-world challenges facing cybersecurity leaders today. Whether you're in government or the private sector, Jessica’s insights offer actionable takeaways for strengthening your cyber posture.

  45. 41

    Embracing Disability Confidence in Cyber with Rudy Haruta

    In this episode of CyberVoices, David sits down with Rudy Haruta, a passionate advocate for disability inclusion and program lead at the Australian Disability Network. Rudy shares his personal journey and struggles with dyslexia, anxiety, and depression, and how these experiences shape his work today. They discuss the importance of organisations becoming disability confident, highlighting the need for tailored support and the challenges posed by traditional recruitment methods. The conversation aims to inspire listeners in the tech and cyber industries to consider more inclusive hiring practices and to better understand the unique perspectives of individuals with disabilities.

  46. 40

    Expanding the Third Party Risk Conversation with William Oh

    In this episode of Cyber Voices, David Willett hosts William Oh, Senior VP at BlueVoyant, as they dive into the critical issue of third party cybersecurity risk. William shares his extensive background in intelligence and highlights the growing importance of cybersecurity. They discuss how cyber attacks have become the silent initiators of warfare and emphasise the increasing risks associated with third-party vendors. This conversation sheds light on the often-overlooked threats that lurk beneath the surface of conventional warfare.

  47. 39

    Building Trust into Biometrics with Gaurav Vikash

    In this episode of Cyber Voices, David Willett interviews Gaurav Vikash, Head of Security and Risk for Asia Pacific at Axon, about the complex interplay of technology, compliance, and trust in today's security landscape. Gaurav discusses Axon's mission to create transparent policing tools, emphasising community trust. He also explores the exciting developments in biometric authentication and the risks associated with deepfake technology used to exploit static biometric systems. The conversation highlights the continuous need for innovative yet responsible solutions that enhance security while maintaining individual privacy and safety.

  48. 38

    Mastering Cyber Tabletop Exercises with Ella Donald

    In this episode of Cyber Voices, Ella Donald, a change and communications manager for cybersecurity at the University of Queensland, shares her insights. Ella discusses her expertise in running successful tabletop exercises for both technical and executive audiences. She emphasises the importance of having clear aims, maintaining a proper scope, and understanding that these exercises are meant for practice rather than a test. Her approach focuses on relationship building and open communication, thereby enhancing organisational preparedness and resilience without amplifying egos or hierarchical barriers.

  49. 37

    The Power of Volunteering with James Pemberton

    In this episode of Cyber Voices, host David Willett chats with James Pemberton, chair of the AISA's Tasmanian branch. James shares his journey from service desk roles into cybersecurity leadership and reflects on nearly a decade as an AISA member and volunteer. He highlights the branch's significant growth, with membership skyrocketing from 48 to 208. The conversation discusses the symbiotic relationship between seasoned professionals and students in Tasmania, emphasising community involvement and mentorship. James underscores the branch's challenges and rewards, stressing the importance of volunteer-driven initiatives to foster a vibrant cybersecurity community in Tasmania.

  50. 36

    Rats and Freeloaders with Peter Watson

    In another interview recorded live at CyberCon Canberra 2025, David chats with with Peter Watson from Recorded Future. Peter provides insights into malware loaders and Remote Access Trojans (RATS), shedding light on their evasive tactics and the complexity of defending against them. Additionally, he delves into techniques like DLL hijacking, illustrating their subtlety and effectiveness. The conversation highlights the challenges faced by security teams in detecting such activities, emphasising the role of threat intelligence.

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.

HOSTED BY

Australian Information Security Association (AISA)

CATEGORIES

Frequently Asked Questions

How many episodes does Cyber Voices have?

Cyber Voices currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Cyber Voices about?

Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the...

How often does Cyber Voices release new episodes?

Cyber Voices has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Cyber Voices?

You can listen to Cyber Voices on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Cyber Voices?

Cyber Voices is created and hosted by Australian Information Security Association (AISA).
URL copied to clipboard!