-
CISO NEW ZEALAND - DAY ONE
-
08:15
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
08:50
Ngāti Whātua Ōrākei - Mihi Whakatau by Te Aroha Grace
-
09:00
Welcome from Corinium and the Chairperson
Denise Carter-Bennett - Co-Chair - New Zealand Network for Women in Security (NZNWS)
-
09:10
Speed Networking - Making New Connections!
In this 5-minute networking session, the goal is to connect with three new people. Enjoy the opportunity to expand your network! -
09:15
Executive Panel Discussion
How Do Executive Teams Align Under Pressure During a Cyber Incident?Cyber incidents require fast, coordinated decision-making across leadership teams as organisations navigate uncertainty, operational disruption and competing priorities. Bringing together senior leaders, this session explores key dynamics in real-time incident response:
- How different executive roles frame risk and urgency during a live incident
- What triggers executive escalation and board involvement
- How decisions change as facts emerge and assumptions are challenged
- How leaders align internal and external communication strategies to maintain trust and confidence during a rapidly evolving crisis
Panellists:
Catherine Buhler, CISO Fonterra
Shivali Kukreja Head of Risk & Compliance nib New Zealand
Julie Watson, CIO WorkSafe
Sharyn Reichstein Chief Risk Officer Tower Insurance
-
09:50
Presentation
Agentic Runtime Security - Solving Identity and Access Gaps in Agentic AIAndrew Brydon - Field CTO ANZ - HashiCorp
AI agents are poised to transform enterprise operations, but they also introduce unprecedented identity and security challenges. In this session, HashiCorp and IBM will discuss the emerging risks associated with agentic AI and share a framework for securing autonomous systems through modern identity, access, and governance controls. Discover how leading organizations are preparing to scale AI adoption while maintaining security, compliance, and operational resilience.
-
10:15
Cross-Industry Panel
Critical Infrastructure Regulation on the Horizon: What Does Resilience Look Like Across Sectors?New Zealand is moving toward a single critical infrastructure cyber security system defined by shared minimum expectations, increased visibility, and coordinated oversight but built on sectors with very different maturity, capacity, and operational realities. This panel brings together a few critical infrastructure perspectives to discuss how the shift is actually being interpreted on the ground.
- Is a more coordinated cyber security regime seen as incremental uplift or structural change? Where are organisations already aligned?
- Where does coordination help vs create new friction?
- Is resilience still sector-defined, or is it becoming something defined at a system level?
Panellists:
Eli Hirschauge, Head of Info Security ANZ
Laura Ross, CISO One NZ
Alastair Miller, GM Network & Security Genesis Energy -
10:45
Get refreshed! Morning Coffee Break
-
11:15
Influencing Decisions When Risk Competes with Business Priorities
Cathy Sneyd - Senior Security Consultant - Woolworths New Zealand
Speaking the language of business is often presented as the key to securing executive support. But what happens when the board understands the risk and still chooses another priority? This session explores the decision-making dynamics behind executive funding choices and how security leaders can move beyond explaining risk to influencing business outcomes. We’ll delve into:
- What separates funded initiatives from those that fail to gain traction
- Five questions security leaders can use immediately to diagnose why a cyber initiative is not progressing
- Techniques for building support before critical executive and board discussions
- Ways to maintain momentum when a proposal is rejected, deferred, or only partially approved
-
11:40
Securing the AI Supply Chain
TBC - Senior representative - Fortinet
AI embedded capabilities rapidly enter the enterprise, organisations are facing growing challenges around visibility, accountability, and third-party risk. This session explores how cyber leaders are approaching trust, governance, and supply chain security in increasingly AI-driven ecosystems.
-
12:05
Keynote Presentation
The Upcoming Arrival of Micro-Breaches: Defining the New Reality of Cyber ResilienceAlastair Miller - GM Network & Security - Genesis Energy
With the rise of AI-driven threats and increasingly complex digital ecosystems, organisations are moving towards an assumed breach world where preventative controls alone are no longer enough. Drawing on the journey of strengthening cyber resilience in a critical infrastructure environment, this keynote explores the emerging reality of “micro-breaches” and how organisations can improve their ability to detect incidents early, contain impact quickly and continuously learn from disruption.
-
12:30
Making Data Risk Visible, Governed and Actionable
TBC - Senior representative - Concentric AI
This plenary explores how organisations can better understand and manage data risk across cloud and SaaS environments. As sensitive information becomes more distributed, leaders need greater visibility, clearer accountability, and stronger governance. The discussion focuses on turning data insights into informed decisions that reduce risk and support business objectives.
-
12:55
Lunch
-
13:55
Track A: Detect & Defend
-
14:00
Presentation
Beyond the Inbox: Detecting and Defending Against Human-Centric ThreatsTBC - Senior representative - Proofpoint
As phishing, business email compromise and identity-driven threats continue to evolve, attackers are focusing less on systems and more on people. This discussion examines how security teams can identify risky behaviour signals, improve visibility across communication channels, and strengthen early detection capabilities.
-
14:25
Case Study
Beyond the Scan: Turning Vulnerability Management into Risk ReductionAndy Pace - Head of Network & Information Security - MediaWorks
As vulnerability volumes continue to grow, many organisations are finding that scanning more does not necessarily translate into reducing real risk. The challenge is shifting focus from identifying issues to actually driving meaningful remediation and prioritisation.
- Prioritisation versus volume-based scanning
- What does remediation reality look like in your environment?
- How are you applying exposure-based thinking to decision-making?
- What actually gets fixed in practice, and why?
-
14:50
Presentation
Closing the Exposure Gap Before Attackers DoTBC - Senior representative - Tenable
As attack surfaces expand across cloud, hybrid environments and third party systems, visibility alone is no longer enough. The discussion looks at how security teams can detect high risk assets, prioritise what matters most, and accelerate remediation before threats are exploited. It also examines how continuous exposure management helps strengthen defensive posture and reduce the window of opportunity for attackers across the enterprise.
-
13:55
Track B: Evolve & Adapt
Denise Carter-Bennett - Co-Founder - New Zealand Network for Women in Security (NZNWS)
-
14:00
Presentation
Seeing the Human Signals Behind Email AttacksTBC - Senior representative - Abnormal AI
This session explores how modern email and collaboration attacks increasingly bypass traditional security controls by targeting people rather than systems. As phishing and impersonation techniques evolve, organisations need to identify subtle behavioural signals that indicate risk. The discussion focuses on how behavioural AI can surface early indicators of compromise in real time, improving detection accuracy and response across the human layer.
-
14:25
Informal Debate
AI vs Shift Left: Has Shift Left Security Had Its Day?This structured debate looks at how AI is reshaping security in the software development lifecycle. With AI now supporting code generation, testing, and security automation, there is growing discussion about whether shift-left security remains the dominant approach, or whether control is shifting toward more continuous, embedded models across the SDLC. Panellists will explore both perspectives through structured opposing views.
Speakers:
Chandan Kumar Head of Software Engineering & Integration Fisher & Paykel Appliances
-
14:50
Presentation
Securing the Software Supply Chain by DesignTBC - Senior representative - Chainguard
This session explores how organisations can rethink software supply chain security as open source and containerised environments reshape modern development. As risk increasingly originates upstream, reactive patching is no longer enough. The discussion looks at how teams can build trust into the software lifecycle, reduce dependency risk, and adopt secure-by-default approaches through stronger provenance, build integrity, and earlier security integration.
-
15:15
Get refreshed! Afternoon Tea Break.
-
Track A: Detect & Defend (cont'd)
-
15:45
Case Study
Secure by Design vs Secure by Behaviour in PracticeAI is making phishing, impersonation and social engineering more convincing than ever, challenging traditional approaches to human-centred cyber defence. This session explores how one organisation has balanced secure by design principles with behavioural interventions, examining where technology can reduce exposure and remove reliance on human judgement, where people still play a critical role in defence, and how security leaders can build resilience against increasingly sophisticated threats.
-
16:10
Presentation
Stopping What You Can’t See: Threat Detection in an AI-Driven Attack EraTBC - Senior representative - CrowdStrike
This session explores how organisations can detect and respond to increasingly sophisticated threats that evade traditional security controls. As adversaries use automation, AI and credential-based attacks, visibility alone is no longer enough. The discussion focuses on how security teams can identify subtle behavioural signals, detect early-stage compromise, and respond at machine speed. It also examines how unified endpoint, identity and cloud telemetry helps reduce dwell time and improve defensive effectiveness across increasingly complex and distributed environments.
-
16:35
Fireside Chat
When Malicious Activity Looks Like Normal BehaviourTraditional detection approaches often struggle when malicious actions mimic normal patterns or unfold slowly over time. This case study explores:
- Why detection failures occur in highly dynamic environments
- How insider-like and low-and-slow behaviours evade traditional controls
- Why defining “normal” has become a core detection challenge
Speakers:
Deepak Veerasamy Director of Information Security (Group CISO) Restaurant Brands
Puva K CISO/Cybersecurity Governance & Strategy/OT Cybersecurity Global Manufacturing & Critical Infrastructure
Puva K CISO Global Manufacturing & Critical Infrastructure
-
17:00
Closing Remarks by the Track Chair
-
Track B: Evolve & Adapt (Cont'd)
-
15:45
Case Study
Measuring Security Behaviour Without Reducing Humans to MetricsAlistar Vickers - CIO - Horizon Energy Group
This case study explores how one organisation measures security behaviour and culture in practice, examining which metrics provide useful insight, where measurement can become misleading, and how security leaders can better demonstrate the impact of awareness and culture initiatives.
-
16:10
Presentation
The Human Side of Incident Response: Communicating Under PressureTBC - Senior representative - KnowBe4
This session explores how to keep messages clear, consistent, and credible under pressure, from briefing executives and coordinating teams to managing regulators and public statements. Learn practical techniques to maintain trust, reduce confusion, and keep everyone aligned when the stakes are highest.
-
16:35
Case Study
Rethinking Third-Party Risk: How GRC is Evolving with AI EcosystemsAdwin Singh - Cyber Security Domain Lead - CISO Office - Inland Revenue NZ
This case study explores how GRC is evolving its approach by combining human expertise with AI capabilities. The session discusses where the existing approach was falling short, how AI was introduced to enhance and streamline the process, and the lessons security leaders can take away when considering AI-enabled GRC in their own organisations.
-
17:00
Closing Remarks by the Track Chair
-
17:00
Cheers with Peers!
Not Found
-
CISO NEW ZEALAND - DAY TWO
-
08:20
Register; grab a coffee. Mix, mingle and say hello to peers old and new.
-
08:50
Day 2 Chair’s Opening Remarks
Lakshya Mehra - National Security Awareness & Phishing Lead - Health New Zealand Te Whatu Ora
-
09:00
Panel Discussion
Has Cloud-First Shifted Risk Responsibility Rather Than Reducing It?New Zealand was an early adopter of cloud services, driven by geography, scalability needs, and resilience expectations. While cloud has changed how enterprises operate, it has also redistributed risk across providers, platforms, and dependencies rather than reducing it.
- Where does cloud-first actually fail in practice: design, operations, or decision latency between teams?
- Which part of the stack is now hardest to secure in reality: identity, data, or the control plane and why?
- What risk are we systematically underestimating in cloud environments today that still doesn’t show up in reporting or dashboards?
Moderator:
Matt Ramsey Senior Solutions Engineer Wiz
Panellists:
Jamie Smith, Head of Architecture, Platforms, Cloud & Security The Warehouse Group
Andrew Meyer, Head of Cyber Security TVNZ
Cristian Ares, Senior Manager - Head of Cyber Security Governance & Compliance SkyCity Entertainment Group
-
09:30
Presentation
Rethinking Security for Continuous ChangeTBC - Senior representative - Zscaler
This keynote explores how accelerating cloud adoption, AI-driven threats, and increasingly distributed environments are reshaping the fundamentals of cyber security. As organisations modernise, security teams are under pressure to move faster while maintaining control and visibility. The session examines how leaders can rethink architecture, operating models, and decision-making to build resilience in environments where change is constant and attack surfaces continue to expand.
-
09:55
Keynote Presentation
Supply Chain Blind Spots: What Threat Intelligence Reveals in an Era of Geopolitical UncertaintyTBC - Senior representative - NCSC
Supply chain attacks are no longer isolated incidents but part of a broader geopolitical and cyber landscape. This keynote explores what today's threat intelligence is revealing about adversary behaviour, third party risk, and the strategic decisions CISOs can make to strengthen resilience before disruption occurs.
-
10:20
Get refreshed! Morning Coffee Break
-
11:00
Panel Discussion
Can Zero Trust Survive the Complexity of Modern SaaS Ecosystems?Zero Trust was designed for a world of defined systems, identities, and enforceable boundaries. The environments today challenge these assumptions through continuous change in applications, identities, and access paths.
- Is Zero Trust still a meaningful journey in dynamic AI-driven systems?
- What happens when systems and decisions are continuously changing?
- Can identity realistically remain the primary control plane in SaaS sprawl?
- Is Zero Trust becoming a mindset rather than an enforceable architecture?
Panellists:
Sam Johnstone, Group IT Security Manager Fulton Hogan
Adarsh Lal, Cyber Security Manager REANNZ
Reza Khaleghparast Head of Information Security Naylor Love
Nick Draper A/Head of Cyber & Architecture Foodstuffs South Island
-
11:30
Presentation
Non-Human Identities and the Expanding Attack SurfaceTBC - Senior representative - Ping Identity
As AI systems, agents, automation, and machine-driven processes expand, organisations are facing an identity challenge that goes far beyond human users. Explore how leaders are approaching non-human identity, access control, and trust in increasingly automated environments.
-
11:55
Fireside Chat
Are We Over-Engineering Security While Missing the Basics?A practical, peer-led discussion exploring whether increasing security complexity is actually improving outcomes, or whether organisations are losing focus on foundational controls. Join this interactive session to compare approaches, share your experiences and discuss where simplification could improve overall risk reduction.
- Where are basic controls failing in your environment?
- What security capability is actually reducing risk and what is just adding complexity?
- If you had to simplify your security programme, what would you strengthen first?
Moderator:
Andy Pace Head of Network & Information Security MediaWorks
Speakers:
Shivali Kukreja Head of Risk & Compliance/CRO nib New Zealand
Hassham Idris Manager Cyber Risk and Assurance Ministry of Justice NZ
-
12:20
Presentation
Making Security Delivery Work at ScaleTBC - Senior representative - ConnectWise
This keynote explores how IT and security teams are adapting to rising operational complexity across distributed environments, growing toolsets, and increasing service demands. Explore how teams can streamline workflows, improve coordination across tools and services, and ensure security outcomes remain reliable without adding unnecessary operational overhead.
-
12:45
Presentation
The Security Decisions That Didn’t Make It and What That Tells Us About RiskCristian Ares - Senior Manager - Head of Cyber Security Governance & Compliance - SkyCity Entertainment Group
Security strategy is shaped as much by what organisations choose not to do as by what they implement. This session explores real-world risk trade-offs made by security leaders under operational and resource constraints, and how these decisions influence risk exposure, resilience, and long-term security outcomes.
-
13:10
Lunch
-
14:10
Keynote Panel Discussion
AI Ecosystem Maze: Can Organisations Maintain Data Sovereignty?Enterprise data now flows through SaaS platforms that embed AI capabilities and introduce additional processing layers beyond the original system boundary. Visibility over how data is handled across these environments is increasingly limited. This panel delves into:
- How can organisations maintain visibility over how and where their data is processed?
- Does data sovereignty still hold meaning in AI-embedded SaaS ecosystems?
- How should accountability be assigned when data is processed across multiple third-party AI layers?
- Do current privacy and disclosure expectations (e.g. IPP3A-type obligations) reflect operational reality?
Moderator:
Jason Wood, Chair ISACA Auckland
Panellists:
Eric Troebner, CTO Tax Management NZ
Oleg Zavivaev, Data Security and Privacy Manager Les Mills International
Manuel Miguez, Service Group Owner - Cyber Operations Westpac NZ
-
14:40
Fireside Chat
Humans and Machines in the Security Workforce: What Changes in Practice?This candid discussion explores how security leaders are adapting their workforce, skills, and operating models as humans and machines increasingly work side by side.
- How is AI changing your day-to-day work and expectations?
- Where is pressure increasing on judgment, accountability, and capacity?
- What does the future pipeline of skills, roles, and experience in cyber security teams look like?
Speakers:
Deepak Veerasamy, Director of Information Security Restaurant Brands
Phil Ross, CISO Air New Zealand
-
15:05
Closing Keynote Presentation
Given Everything We’re Carrying, How Do We Move Forward Together?This closing keynote explores how CISOs and security leaders can respond to expanding responsibilities across resilience, risk, workforce capacity, regulatory expectations and evolving threats, while navigating increasingly constrained operating conditions.
- How can leaders respond to growing responsibilities without simply adding more to the load?
- What enables effective decision-making and resilience under continuous pressure?
- How can security leaders foster greater shared ownership and collective action across their organisations?
-
15:30
Chair Closing Remark
Lakshya Mehra - National Security Awareness & Phishing Lead - Health New Zealand Te Whatu Ora
-
15:40
Close of CISO New Zealand 2026 & Networking Afternoon Tea
Not Found