-
CISO FSI Online ANZ
-
11:25 (AEST)
13:25 (NZST)Welcome remarks from Corinium
Parveen Sekhon - Conference Director - Corinium Global Intelligence
-
11:30 (AEST)
13:30 (NZST)
Opening Presentation: FSI Cyber Governance That Boards Can Trust
Luke Ma - Head of Information Security, Technology Controls and Governance - AIA Australia
- Reconciling cyber strategy and business priorities that don't always pull in the same direction
- Defining meaningful risk tolerances and executive accountability
- Security outcomes using metrics that matter to boards
- Turning compliance obligations into sustained risk reduction
-
11:50 (AEST)
13:50 (NZST)
Continuous Assurance for Financial Services
- Visibility across the estate: Keeping pace with what's running and where risk sits
- Assurance as an ongoing practice: Moving beyond point-in-time checks
- Shared ground for security, risk and audit: Reducing duplicated effort across teams
Speaker:
Senior Representative JFrog -
12:10 (AEST)
14:10 (NZST)
AI-Enabled Fraud and Payment Risk
Ashutosh Kochhar - Chief Information Risk Officer - Northern Trust Corporation
- How AI is reshaping payment fraud, account takeover and financial crime
- Strengthening collaboration between cyber, fraud and finance teams
- Fraud prevention and customer experience don't have to be a trade-off: getting the balance right
- AI-enabled attack techniques are emerging faster than most playbooks — how organisations are responding
-
12:30 (AEST)
14:30 (NZST)
How frontier AI changes tolerable risk for open source security in financial services
John Sapp - Field CISO - Chainguard
For decades, financial institutions have managed open source software risk by accepting it. Legacy applications, strict change control, and the operational risk of touching business-critical systems made a growing CVE backlog the cost of doing business.
That calculation no longer holds. Frontier models can now surface dormant vulnerabilities and chain weaknesses across the open source software supply chain faster than traditional security processes can investigate and patch them, while regulators, auditors, and customers demand stronger evidence of software integrity.
Join us to explore how financial institutions can rethink how they govern and adopt open source as risks accelerate. We’ll discuss why reactive vulnerability management is breaking down, and how teams can reduce risk without disrupting business-critical systems, and the practices security and platform leaders can use to establish a more secure, governed approach to open-source consumption.
John will explore:
- Why frontier AI is making previously accepted open source vulnerabilities more urgent
- Why vulnerability exploitation has overtaken phishing as a leading FinServ attack vector
- Best practices for governing open source consumption and vulnerability remediation in regulated environments
- Reducing risk without forcing disruptive upgrades to business-critical applications
- Building stronger software integrity and audit evidence into the software lifecycle
-
12:50 (AEST)
14:50 (NZST)
Operational Resilience in Financial Services: Lessons from the Front Line
Sanja Petrovic - GM Cyber Security & Governance - HUB24
- Not every resilience investment has delivered equal value — what worked and what didn’t
- Recent incidents have changed more than incident response plans — what's shifted in practice?
- How organisations are strengthening readiness for prolonged disruption
- Raising the bar on resilience — what are IT leaders planning?
-
13:10 (AEST)
15:10 (NZST)
Securing Multi Cloud, SaaS and Open Banking Ecosystems
- Visibility gaps across cloud and SaaS environments are where risk tends to hide
- Configuration and identity risk multiply with every new environment added: rethinking oversight itself, not just adding more tools
- Protecting APIs and third-party integrations — the connective tissue of open banking
- Maintaining compliance across distributed infrastructure in every environment
Speaker:
Senior Representative Obsidian -
13:30 (AEST)
15:30 (NZST)
Governing AI: A Second-Line Playbook for Financial Services
Rucha Gatti - Director, Tech & Info Security Risk - National Australia Bank
- Embedding AI into existing risk and control frameworks, rather than building a parallel regime
- Translating AI risk appetite into metrics boards can actually act on
- Closing the assurance gap on vendor and embedded AI tools
-
13:50 (AEST)
15:50 (NZST)
A Practical Zero Trust Playbook for Financial Services
- What does Zero Trust look like once it's applied across identities, networks and workloads?
- Shrinking the attack surface and keeping users unaffected with the right architecture
- Extend existing IAM and PAM investments as the foundation Zero Trust builds on
- Building a phased roadmap for enterprise adoption
Speaker:
Senior Representative Docker -
14:10 (AEST)
16:10 (NZST)
Panel: Third Party and Ecosystem Risk in Financial Services
- Concentration risk across cloud and strategic suppliers is growing — how are organisations managing it?
- Extending resilience across fintech and third-party ecosystems
- Annual vendor reviews are no longer enough — what continuous assurance looks like in practice
- Third-party risk is a sector-wide problem, and stronger collaboration across financial institutions is part of the answer
Speakers:
Aaron McKeown CISO NGM Group
Daminda Kumara CISO Commonwealth Superannuation Corporation
Tony Arnold CISO TSB Bank New Zealand
Rucha Gatti Director, Tech & Info Security Risk, Resilience Risk - Group Risk National Australia Bank (moderator)
-
14:40 (AEST)
16:40 (NZST)
Identity and Access Risk in the AI Era
- How AI is reshaping identity attacks — from credential theft to synthetic and impersonated identities
- Extending IAM and access governance to keep pace with AI-driven threats and AI-powered tools inside the organisation
- Practical steps for strengthening identity assurance without adding friction for legitimate users
Speaker:
Senior Representative Group-IB -
15:00 (AEST)
17:00 (NZST)
People, Not Just Policy: Closing the Human Gap in FSI Cyber Security
Daisy Wong - Head of Security Awareness - Medibank
- Turning the day's governance, AI and resilience frameworks into behaviours that stick across a workforce, not just the security team
- Building an "always-on" security culture instead of annual training and phishing tests
- Communicating cyber risk in language the business and customer trust
-
15:20 (AEST)
17:20 (NZST)Close of CISO FSI Online ANZ
Not Found