-
Cloud Security Melbourne
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
09:00
Welcome remarks by Corinium & Chair’s opening remarks
Fabiola Martinez - Product Owner - Cloud Security Posture Management - CommBank
-
09:10
Speed Networking – Making new connections!
In this 5-minute networking session, the goal is to connect with three new people. Enjoy the opportunity to expand your network!
-
09:15
Opening panel discussion
Are We Designing for Prevention or Responding Faster?Cloud security has matured across architecture, application defence and incident response. But are we truly reducing the likelihood of incidents, or simply becoming more efficient at handling them? This panel explores how prevention and response influence each other across the cloud lifecycle.
- How do architecture and design choices help prevent incidents rather than just speed up recovery?
- Where does application defence struggle to keep up with fast cloud delivery?
- How does incident response adapt when multi cloud increases complexity?
- Are cyber security leaders effectively closing the loop between incidents and future controls?
Moderator:
Niall McCarthy Engineering Director & Incident Management Leader
Panellists:
Usman Sultan Senior Cyber Security Architect CleanCo Queensland
Abdullah Muhammad Application Defence Manager Bupa
Wayne Rodrigues Membership Director ISACA Melbourne Chapter
-
09:50
From Visibility to Velocity: Operationalising Exposure Management in the Cloud
Ben Mudie - Field CTO APAC - Tenable
As cloud environments expand, traditional vulnerability management falls short against sophisticated threat vectors. This session provides CISOs with a practical blueprint to implement Exposure Management across on-premises and cloud environments, providing the precision needed to prioritise the most critical exposures, drive faster remediation, and secure your modern attack surface with a single, unified experience.
-
10:15
Panel discussion
Who Really Owns Cloud Security?As organisations migrate, modernise, and expand across cloud, SaaS, and hybrid environments, responsibility is increasingly fragmented between platform teams, security, IT, and the business. This panel brings together cloud and security leaders to challenge assumptions around shared responsibility, governance models, and decision-making in complex cloud environments.
- Where does cloud security ownership really sit today?
- Which cloud security decisions must be centralised — and which should not?
- What responsibility still falls through the cracks during migration?
- When do guardrails enable speed, and when do they slow it down?
- How do you know cloud security is working beyond compliance?
Moderator:
Kavita Chetty Senior Manager, Technology Risk NAB
Panellists:
James Galbraith Cloud Services Manager APA Group
Kanik Sachdeva Security Engineering Manager Medibank
-
10:50
How CTEM Reduces Cloud Exposure Before It Becomes Breach
Pouya Ghotbi - Head of Exposure Management - Check Point
Cloud exposure risk is no longer defined by isolated vulnerabilities or misconfigurations. In modern cloud environments, risk forms as attack paths across public assets, APIs, workloads, identities, secrets, sensitive data and inconsistent controls. This session explores how Continuous Threat Exposure Management, CTEM, helps organisations move beyond static visibility and ticket-driven remediation by continuously identifying, prioritising, validating and reducing the paths that matter most. The key message: mature cloud security is not about finding more issues, but preventing exposures becoming breaches.
-
11:15
Get Refreshed! Mingle
-
11:55
Cloud Security at the Edge of the World: Lessons from Critical Infrastructure with No Room for Error
Shanil Chetty - Manager ICT & Cybersecurity - Civil Aviation Authority of Fiji
When your cloud goes down and the nearest help is a 4-hour flight away, you figure out very quickly what actually matters. This session draws on real experience securing aviation infrastructure across the Pacific, a region where misconfiguration isn’t a compliance finding, it’s a safety event. No hyperscaler support office. No IR retainer. No second chances. What that environment forces you to build is a different kind of discipline, one that large enterprises with large budgets rarely develop. We’ll cover what constraint teaches you about cloud security that tooling never will.
-
12:20
Beyond Exposure Management: The Age of Autonomous Cyber Assurance
Nirav Kamdar - Senior Solution Architect, Cloud Risk and DevOps - Qualys
Cloud security is moving from visibility to evidence. Beyond CNAPP dashboards and CTEM frameworks, Continuous Cyber Assurance focuses on continuously proving what is exploitable, what is reachable, which controls are effective, and whether remediation has genuinely reduced risk.
Drawing on real-world cases and lessons learnt, this session will delve into:
- Moving beyond vulnerability identification to understand which exposures create genuine business risk and require action.
- Validating whether security controls are working as intended and whether remediation efforts have actually reduced exposure.
- The role of Agentic AI in supporting validation, prioritisation, remediation, revalidation and executive reporting beyond simple alert summarisation.
- Continuous discovery across web applications, APIs, cloud assets and AI-related exposures to enable more evidence-led, business-aligned risk reduction.
-
12:45
API Security in Motion: Automating Discovery and Defence
Priya Balasekaran - IT Risk Analyst - Kmart Australia
Most organisations don’t know how many APIs they have in production — or who’s calling them. This session explores automated API discovery, continuous monitoring, and runtime protection techniques that help teams identify shadow APIs, detect credential abuse, and prevent data exfiltration before it spreads.
-
13:10
Lunch
-
14:10
Panel Discussion
Facing the Hidden Risk: Is AI Creating Accidental Insider Risk in the Cloud?Generative AI is transforming how employees interact with sensitive data, often faster than organisations can control. This panel explores how to prevent accidental data exposure, enforce access policies, and balance security with productivity in an AI-driven cloud environment.
- How do you stop sensitive data from leaving the organisation via AI tools?
- Which controls actually work to prevent accidental misuse?
- How can teams enable employees safely without creating a culture of surveillance?
Moderator:
Bernadeth Lucanas Cloud, Data, AI, & Cyber Security Expert
Panellists:
Priya Balasekaran GRC Specialist Kmart Australia
Rue Maharaj Specialist – Cybersecurity Defence Management Melbourne Water
Amreet Prasad Volunteer Marketing Portfolio ISACA Melbourne Chapter
-
14:45
Nature Knows Best: Reimagining Security Architecture through the Lens of Biomimicry
Nature has spent billions of years solving problems we are only beginning to formalise in cyber security. From layered immune responses to cellular repair mechanisms, biological systems offer striking parallels to concepts such as Defence in Depth and resilience engineering. Combining deep technical expertise with a fresh cross-disciplinary perspective, Wayne and Daphne explore how biomimicry, learning from nature’s time-tested patterns, can inspire new approaches to designing secure and resilient systems.
Wayne Rodrigues Membership Director ISACA Melbourne Chapter
Daphne Mantzanidis Recent Graduate of RMIT -
15:10
Closing Keynote Presentation
Mind the Gap: 3 Moves to Secure AI That Acts on IntentMayank Sharma - Security Architect -
Traditional cloud security focuses on detecting bad code but AI-driven threats now exploit intent, bypassing tools and oversight. As adoption accelerates, gaps in governance, compliance and risk control are widening. This closing keynote shares three practical moves cloud defenders can take to mind the gap: defining clear boundaries for agentic AI, enforcing human in the loop controls and deploying defensive AI. Walk away with actionable guidance to secure AI systems based on behaviour and intent, not just code.
-
15:35
Chairperson's Closing Remark
Fabiola Martinez - Product Owner - Cloud Security Posture Management - CommBank
-
15:45
Afternoon Tea & Close of Cloud Security Melbourne 2025 & Afternoon Tea
Not Found