AUSCERT
AusCERT2018 DAY 1 - BRIAN BRUSHWOOD (DARREN KITCHEN WELCOME)
updated
Drawing on her background in criminology and her role as Senior Security Influencer at SEEK, Kelsy discusses how organisations can move beyond awareness training to address the behaviours, norms and motivations that shape security culture.
Tune in to discover why changing security behaviours starts with understanding the humans behind the keyboard.
In this episode of Share Today, Save Tomorrow, Lesley Carhart shares what it's really like investigating cyber incidents affecting industrial systems, an area of digital forensics and incident response that few people ever get to see.
Lesley discusses the different types of incidents impacting operational technology (OT) environments, from ransomware and insider threats to nation-state activity, and explains why understanding how systems fail is essential to building resilient critical infrastructure.
What started with a lockpick set at six years old has grown into a passion for ethical hacking, conference speaking and continuous learning. Somindu shares how physical security sparked his interest in cyber security, why curiosity has been his greatest teacher, and how he made the leap from lockpicking competitions to presenting at industry events.
The conversation also explores the importance of hands-on learning, the value of community, the future of cyber security for young people, and Somindu’s perspective on Australia's social media age restrictions.
Join today: https://auscert.org.au/become-a-member/
Join today - https://auscert.org.au/become-a-member/
Join today - https://auscert.org.au/become-a-member/
Join AUSCERT today: https://auscert.org.au/become-a-member/
Learn more about our Tabletops: https://auscert.org.au/services/tabletop-exercises
That’s the reality of running a Grand Theft Auto (GTA) Roleplay server, which is a multiplayer modification of GTA - players create unique characters in a persistent, player-driven world with custom rules, jobs, and interactions.
In the gaming industry, threat actors aren’t always like the ones we deal with in the corporate landscape where things like financial gain or competitive advantage motivate. Our most common threat actors are driven by ego, chaos, and pettiness. They’re not sophisticated APTs - they’re a new evolution of script kiddies who will spend days reverse-engineering server exploits, DDoSing for revenge, or doxxing staff because they lost a virtual shootout.
As the general manager of one of these popular servers, I’ve had to defend against security threats with none of the luxuries of corporate cybersecurity.
This session is a raw, unfiltered look at cybersecurity in an environment with zero safety nets. Using real footage, screenshots, and case studies, I’ll show how we built defences, fought back, and learned valuable security lessons, all with a team of people - some of whom I’ve never met in real life, but had to trust with keeping everything secure.
Beyond just gaming, this talk highlights wider cybersecurity lessons in risk management, security resilience, and defending against persistent threats with limited resources so you, as the listener, can take some of my learnings and make your business more secure and resilient.
In this session, Field CISO Andrew Philp outlines how security strategy needs to evolve for the AI era from the case for consolidation through to what it takes to build a function that can keep pace with both innovation and threat. Andrew is then joined by industry peers for a candid discussion on what this looks like in practice where maturity gaps are most exposed which decisions have materially shifted outcomes and how to move forward while staying aligned to business priorities. You will gain a strategic direction from the field, a practical reality from those navigating it every day.
This session examines the modern cybercrime ecosystem and the common AI-enabled tradecraft used by criminal syndicates and state-aligned actors. It maps how AI is applied across the attack lifecycle, from initial access and payload development to fraud, extortion, and data exploitation.
The session then outlines a practical response and draws on the comprehensive guidance on AI adoption, co-authored by ASD, CISA, NSA, and NCSC. It focuses on governing AI interactions in real time - blocking malicious inputs, preventing sensitive data disclosure, and detecting abnormal usage patterns. It examines how Security teams can move beyond the role of innovation gatekeeper by deploying enabling controls that act as financial and operational guardrails.
We will explore the role of AI runtime defence in anomaly detection and resource abuse prevention, alongside AI Usage Control for visibility, policy enforcement, and Shadow AI governance. The outcome is measurable risk reduction, improved oversight, and a defensible strategy for scaling AI safely across the enterprise.
The session will also include a live demonstration of AI attacks in action and how emerging AI security tools can assist the defender.
This session moves beyond the "Shadow AI" conversation to explore the reality of autonomous threats and the "Oversight Gap." We will analyse recent industry-shifting incidents, such as the Bob-p2p finance compromise and ClawHavoc supply chain poisoning, to demonstrate why traditional perimeter-based security is obsolete. Attendees will learn how to transition from human-speed reactive security to AI-powered Zero Trust and proactive AI Red Teaming, ensuring that defence can finally match the velocity of the modern, autonomous attacker.
Then we flip the script. Using defence-in-depth, gateway controls, guard models, and practical security patterns; you'll see those same attacks stopped cold. And you won't just be watching. The audience plays a part in how this one unfolds.
No death-by-slides. You'll leave with a clear picture of what AI prompt attacks actually look like, why your current setup may not be catching them, and practical defences you can start applying today.
AUSCERT2026 opens with a Welcome to Country, acknowledging the Traditional Custodians of the land and paying respect to Elders past and present.
Hosted by the incomparable Adam Spencer, this high‑energy quiz showdown pits two teams against each other, captained by cyber heavyweights and backed by AUSCERT team. Expect conference lore, unforgettable moments from the last 25 years, and a few clues about what’s still to come as we celebrate the past, present and future of AUSCERT Conferences.
Through a structured breakdown of these core "moves," this session deconstructs real-world attack patterns and shows how attackers consistently succeed—now increasingly accelerated by AI-assisted tooling. By understanding the strategy guide attackers implicitly follow, defenders can stop reacting to individual threats and instead target the underlying mechanics that make compromise possible.
The session provides concrete defensive approaches, including deny-by-default and application control strategies, that materially limit attacker options at the endpoint. The goal is simple: if you understand the rules of the game, you can start to change them.
This talk will reframe cyber defence as "cognitive warfare", where attackers are exploiting psychological inertia, delayed belief updating, culturally reinforced assumptions and more. Drawing on established findings in cognitive and behavioural psychology such as Ocean's Big Five model and the Behavioural Inhibition System (BIS), this talk will frame both blue, and red teaming as practices with deep personal psychological roots which are affected by the neurodiversity and personality traits of any person. I will examine how rapidly evolving actors outperform defenders, not through sophistication, but through flexibility. How in many cases, the fastest adaptations aren’t driven by experience, but by the absence of institutional assumptions.
Rather than focusing on tools or detection logic, based on my experience playing both physical and online team CTF challenges, along with considerable research of the fields of psychology and cyber, this session will explore why adaptive thinkers with minimal institutional grounding often recognise emerging threats faster than highly experienced teams, and why failure to update internal mental world models has become one of the most reliable attack surfaces in modern security operations.
This rapid automation exists alongside a "patient persistence" approach favoured by sophisticated actors who maintain dormant access within critical infrastructure and industrial controls for extended periods. The risk is further expanded by vulnerabilities within emerging technology supply chains and internal corporate AI integrations, which can be turned into high-speed conduits for unauthorised data exfiltration. Consequently, organisation must adopt a dual-track defensive strategy: one that counters the machine-speed execution of adversarial algorithms and another that addresses the deep-seated systemic risks posed by non-human identities and long-term stealth operations.
In 2022, iTnews launched the first State of Security report, a collaborative deep dive into the cyber security sector, analysing the ever-evolving cyber threat landscape. In its fifth iteration, the 2026 State of Security report uncovers the key trends, challenges and end-user CISO case studies.
Drawing on over two decades of hard‑won experience - and an evergreen “back‑to‑basics” session refreshed for today’s reality - you’ll see exactly which foundational controls are still missed, why they’re skipped (because it's always "not now"!), and how to land them across hybrid cloud, SaaS estates, and AI‑enabled workflows.
Expect opinionated guidance, vendor agnostic advice, and field‑tested checklists you can apply on Monday morning, delivered the way only Jess can. Walk away with a starter blueprint for secure‑by‑default builds and the confidence to keep your organisation out of boss‑fight wipeouts. No cheats required - just great fundamentals.
This session presents a practical case study of restructuring a SOC to remove traditional tiers and instead empower the most senior analysts to directly drive alert triage and operational decision-making. By flattening the operational model, the SOC shifted from an escalation-driven workflow to one focused on rapid context-rich analysis, ownership of outcomes, and deliberate use of automation to support—not replace—human judgement.
This session is aimed at SOC leaders, security managers, and senior analysts looking to modernise operations, improve outcomes, and build sustainable teams in an increasingly complex threat landscape.
• Legal obligations during and after a cyber incident
• Breach notification timing, evidence preservation, and legal professional privilege - including when privilege applies (and when it doesn’t)
• Common mistakes that increase regulatory exposure
• Legal risks of ransom payments (sanctions, terrorism financing, AML laws) and how these interact with conflicting disclosure laws and regulator expectations
Abstract:
When a cyber incident occurs, the first 24-72 hours determine both the legal exposure and the quality of recovery.
This session distils what security teams must get right (fast) and provides practical guidance on actions that can be implemented immediately.
The session will cover the triggers and sequencing of legal obligations from discovery to containment, clarify when and how to notify affected parties and regulators, outline the mechanics of preserving evidence and explain how to structure workstreams to maximise legal professional privilege (and avoid pitfalls).
We’ll also cover the evolving rules of engagement on ransom-related risks, including sanctions, terrorism financing, and AML exposure, and Australia’s mandatory ransomware payment reporting regime and show how these elements interact with disclosure expectations from regulators and boards.
Delegates will leave with an incident checklist, an awareness of legal privilege and board ready talking points.
Learning outcomes:
Attendees will gain an understanding of:
• The mandatory steps to take within the first 72 hours of a cyber incident and the information to produce at each step
• Preserving evidence without impeding the response to a cyber incident and how to structure legal engagement to maximise privilege where it applies while avoiding common pitfalls
• Ransom risk – how to assess sanctions and AML exposure, recognise what can and can’t be negotiated and how to comply with Australia’s ransomware payment reporting rules
• How to navigate differing regulator expectations
Designed for CISOs, analysts, and program managers, you will gain a solid understanding of the CTI-CMM's key domains and maturity levels, and how to use it to shape a clear CTI roadmap. We’ll go beyond theory with applications of the CTI-CMM based on our experience, providing practical insights that you can take home to your organisation.
You'll walk away with steps to elevate the value CTI provides in your organisation from the technical to the executive levels. We’ll show you how CTI goes beyond IoCs to inform risk management, link to strategic goals, and inform your stakeholders. We’ll also leave you with a CTI-CMM v1.3 assessment tool that we developed at Cosive.
The perennial debate around this is like incandescent light in that the energy it consumes generates far more heat than light!
This is a debate is that almost always devolves into a false dichotomy where organisations must to choose between someone who can launch nukes by whistling codes into a phone, Vs someone who routinely double clicks on hyperlinks.
Worse, we pretend every CISO role is the same thing, despite knowing that LinkedIn is full of "CISOs" who are essentially firewall salespeople, while others are running security for critical infrastructure.
In well over a decade of consulting I have been fortunate, and sometimes unfortunate enough to work with a large number of CISO’s, ranging from old school pen testers who run Gentoo on a MacBook, to people who required a personal assistant to print out their emails.
My observation has been that the technical ability of a CISO is just one aspect in a much larger group of critical capabilities, and I have come to believe that whilst technical ability is highly desirable, it can be a double edged sword for a variety of reasons.
What this talk will cover.
- The Cases for and against Technical Capability
- What other capabilities should a CISO possess
- What different stakeholders want and why
- Why different organizations need fundamentally different CISOs at different times
- The skills we should be developing and at what point in our career?
Join me in interrogating some of my own observations, biases and beliefs in the hope that we can spare future generations from dying on such pointless hills.
Using the PMESII-PT framework, the study identifies critical single points of failure—most notably, a single cable, which carries up to 85% of active bandwidth between Australia and the United States. The session will explore the analytical process that informed this deduction and three high-impact threat scenarios, each with unique implications for Defence operations, regional stability, and sovereign control of communications infrastructure.
We present findings from OSINT reconnaissance, static firmware analysis, and physical site assessments of cable landing stations in Australia and the Pacific. Key vulnerabilities include outdated firmware, exposed wireless systems integrated with sites, highlighting an urgent need for systemic resilience, sovereign fallback capabilities, and vendor assurance, and considerations for communication systems in the event of loss or degradation of links.
This talk will conclude with actionable recommendations for Defence and industry stakeholders, including securing critical nodes, diversifying connectivity, and elevating communications infrastructure to a strategic planning priority in future contested environments.
This talk explains how using attack surface management and threat intelligence together can provide a more reliable picture of an organisation’s current exposure. Attack surface management shows what is visible from the outside including systems that may have been forgotten, misconfigured, or created without formal approval. Threat intelligence adds context about which weaknesses are being targeted and which issues are most likely to lead to real incidents.
By combining these views, organisations can make more informed decisions about where to direct their attention. Instead of just responding, teams can identify risks earlier, understand why they matter, and act before they turn into incidents. This approach supports clear prioritisation and more effective use of resources especially in environments where teams are managing a large number of competing demands.
The session will outline practical steps that technology and risk leaders can take to strengthen visibility and improve decision making. It will cover how to identify blind spots, how to link external information to internal systems, and how to recognise the areas that genuinely require attention. Attendees will gain an understanding of how external insights can support a more proactive approach to security, reducing uncertainty and improving overall risk management.
In this presentation Hank will share his approach to managing Cyber for some of Australia’s most critical infrastructure and high-profile organisations.
Drawing on life lessons from extreme sports, he’ll share real examples of how he was able to shift Executive Management understanding, Cyber Awareness and Culture over his 20+ career through story-telling, gamification, incident explanation and demonstration.
Hank will share some simple tools for communicating complicated technical topics to non-technical audiences and leave you with a stack of examples you can use when you walk out the door.
This presentation explores the expanding attack surface of the modern connected vehicle, examining the components that pose the greatest security, safety, and privacy risks. It takes the audience under the hood of a vehicle’s telematics box, the gateway that connects vehicles to the outside world via cellular networks and highlights how this access can be leveraged by attackers.
Taking an evidence-based approach, the session dives deep into privacy challenges by analysing real data recovered from Australia’s best-selling vehicle for the past three years: the Ford Ranger. This analysis sheds light on the types of data being collected, stored, and potentially exposed, and what that means for drivers, organisations, and regulators alike.
Beyond the vehicle itself, the presentation examines the broader implications for local, state, and federal governments, as well as industries such as mining, agriculture, and fleet operations where connected vehicles are deeply embedded in daily operations. The risks extend from employers and critical infrastructure all the way to individuals at home.
Recent high-profile cyber incidents such as attacks on Viasat, Orange, iiNet, and iPrimus, highlight the global scale and frequency of these threats, with nine major incidents reported in just three months of Q3, 2025. In the past three years there has been an increase in geopolitical tensions within Europe, Asia and the Middle East, particularly involving China, Russia, Iran, and North Korea, in shaping cyber operations against the global Telco sector.
As geopolitical tensions rise there are observable frequencies of cyber-attacks against levels of all governments and their critical infrastructural assets. The human factor continues to be an Achilles heel within identified attack vectors ranging from sophisticated levels of phishing, spear phishing and supply chain attacks.
Recent cyber-attacks by Nation Sponsored APTs such as Salt Typhoon and Volt Typhoon continue to demonstrate operational pivots towards Telecommunications critical infrastructure and their vendors. A threat hunt conducted in Q3 of 2025 by the NSW Department of Customer Service and NSW Telco Authority uncovered network scanning activity and indicators of compromise linked to Salt Typhoon.
The second part of this talk will discuss the threat hunting process used by DCS and NSWTA, outline how critical intelligence gathering processes are, understanding the Intel Pyramid of Pain and utilising open and closed sources of intelligence.
The presentation concludes by urging greater collaboration across agencies, government and private industry, to deploy rapid patching schedules, and conduct active threat hunting, while emphasising that cybersecurity is a collective responsibility requiring persistent effort using shared intelligence to defend against nation state threat actors.
Collecting data is tricky, but the hard part is knowing what to do with it. Whether you're a threat hunter looking for leaked credentials, an intel analyst tracking data breaches or an investigator on a criminal case, you will leave this presentation with a practical understanding of what information Telegram holds and how to turn it actionable intelligence for your organisation. I will take you through the identification and analysis of message content, the mapping of user relationships, cross-channel activity, forwarding chains and data collection.
Not only will you leave with a deeper interest in OSINT from Telegram, you will be provided with open source tooling so you too can proactively monitor and collect data from Telegram in real time.
After all, "the most valuable commodity I know of is information". It's game on.
Drawing on unique intelligence and visibility into this threat, Okta’s hard won research reveals the true scale and scope of the risk to Australian organisations across all industries, job categories, and roles, far beyond the stereotype of remote software developers.
This presentation will outline the reality of the threat and provide practical steps that organisations can take to reduce the risk of inadvertently hiring sanctioned North Korean operatives. It is a practical, data driven session grounded in real world cases and hands on research with useful takeaways.
Mick McCluney Field CTO ANZ at TrendAI joins a senior security leader from a major Australian organisation to share what’s been seen on the ground. Every organisation is deploying AI, yet fewer are asking the right questions first. We will unpack real world examples such as AI systems making decisions without governance to match, the new attack surfaces that weren't in the architecture diagram, and adversaries who got there first. If you've sat through enough sessions on AI's potential, this one is about what's actually happening, what's working, what's backfiring, and what security leaders are doing about it.
This presentation will showcase the work of two active CLN working groups through presentations delivered by each Group Chair.
Tim Lane (CISO, TURSA), will present on the Cyber Culture Metrics Working Group, exploring approaches to measuring cyber culture maturity, behavioural indicators, and the growing importance of human centred security metrics in organisational resilience.
Mikhail Lopushanski (General Manager, Technology GRISC, Auto & General) unveils the AUSCERT CLN Quantum Computing Working Group's latest actionable artifacts. This session provides critical insights into the emerging "Harvest Now, Decrypt Later" threat, post-quantum cryptography strategies, and the concrete steps security leaders can take to drive immediate organisational preparedness.
But what makes a winning Red Team strategy?
Our panel of industry experts discuss what they expect - from partner, vendor, and client perspectives - from a Red Team. How far is too far when leveraging social engineering to manipulate employees? How can you balance the trust deficit between Red and Blue Teams? What about the operational risks of working on a live production system vs a staged low-risk environment? Whether one expert constitutes a team, and more.
Expect a lively debate over a range of ethical, political, psychological and cost considerations.
This presentation discusses ProfileHound, a new open-source post-escalation tool that collects user profile data from domain machines and exports it to BloodHound using the OpenGraph format. ProfileHound creates a new HasUserProfile edge that maps which domain users have local profiles on specific computers, including profile creation and modification timestamps. This visibility allows operators to identify high-value targets for secret looting, prioritize machines with long-lived profiles likely containing accumulated credentials, and focus collection efforts on systems where privileged users maintain active workstations.
Attendees will learn how ProfileHound enumerates the C$ share to identify domain user profiles by correlating NTUSER.DAT ownership and DPAPI directory SIDs. The presentation covers practical Cypher queries to find profiles belonging to specific groups, identify recently active profiles, and filter out unused profiles that lack valuable secrets. Demonstrations will show how operators can chain ProfileHound data with existing BloodHound edges to build attack paths targeting users with access to sensitive SaaS applications or cloud administrative roles.
Key takeaways include understanding why user profiles represent an underutilized intelligence source in Active Directory environments, how to deploy ProfileHound during authorized engagements, visualizing where profiles exist, and how to write custom Cypher queries that combine profile data with group membership and session information to identify the shortest path to post-exploitation objectives.
For 24 years, Australian CISOs played by guidelines. In 2025, the Referee blew the whistle. With the landmark Australian Clinical Labs (ACL) fine ($5.8M) and the Vinomofo determination, we now have hard case law defining exactly what "Reasonable Steps" look like in the eyes of the Federal Court and the Privacy Commissioner.
This session reviews the "game tape" of these two major regulatory actions to create a winning defensive strategy for 2026. We will deconstruct the specific technical fouls cited in the judgments, from 1-hour firewall log retention and "temporary" cloud databases to the cultural failure of labelling privacy "The Boring Stuff."
This is not a legal lecture; it is a tactical retrospective for technical leaders and directors. We will map these specific regulatory failures directly to the ASD 2025-26 Board Priorities, providing a clear path to compliance.
Attendees will leave with:
A "Cheat Sheet" for the Board: Connecting specific court findings (e.g., legacy IT negligence) to budget line items.
The "Sin Bin" Strategy: Understanding why the "Operational Debt" of mandatory audits (Vinomofo) can be more damaging than a fine, and how to avoid it.
M&A Gatekeeping: A framework for due diligence that treats acquired networks as hostile territory until proven otherwise.
In this arena, the stakes are real. This presentation gives defenders the rulebook they need to stay on the field.
In this talk, phishing is framed as a series of World of Warcraft raids. Early phases taught us to spot the obvious, building confidence in warnings, filters, and training. Then each “expansion” arrived: brand impersonation, mobile phishing, MFA fatigue, QR codes, and AI-generated lures. Every tactic we thought worked punished us again.
The speaker brings a double grind: two decades of phishing research and two decades of far too much World of Warcraft. Using raid encounters as a lens, the talk explores why phishing resists one-shot victories and why real progress depends on learning, adaptation, and designing systems that survive inevitable wipes.
Human analysts.
Human response times.
Human investigation capacity.
Human operational scale.
That model is now completely broken.
In the wake of Claude Mythos, Boards, Executives, and Security Teams have finally seen the reality that advanced AI-driven attacks are upon us. Threat actors are no longer constrained by human speed, human creativity, or human operational limits.
AI-generated attacks are now dynamic, adaptive, scalable, and operating at machine speed.
Exploits can be automatically generated, tuned, modified, and weaponised faster than human teams can realistically defend against them.
This creates a fundamental imbalance. The outcome is inevitable.
Human-speed defence strategies will not keep pace with the next generation of AI-powered threats.
This is not simply a tooling problem.
It is a complete operating model overhaul.
To survive the next wave of attacks, organisations will need to fundamentally reinvent their entire security strategy, including:
• How AI-driven attacks will evolve over the next 6, 12, and 24 months
• What an AI-capable cyber security strategy actually looks like
• How to operationalise AI-powered defence across the organisation — and quickly
• What happens if organisations fail to adapt fast enough
In this presentation, you will learn how organisations can reinvent and operationalise AI-powered cyber security capabilities to survive the next generation of threats.
The future of cyber security is not humans versus AI.
It is AI-powered defenders operating alongside humans at machine speed.
You need to fight AI with AI.
You need to imagine a limitless cyber security team.
Drawing on ground-truth data from over 2,000 Australian engagements, this session presents a strategy to move beyond the adversarial dynamic of compliance to a co-op model. We'll demonstrate how assessors and security leaders can identify critical suppliers and apply practical strategies to level up their cyber maturity. This session provides a playbook for trading static questionnaires for shared resilience, improving collective visibility, and ensuring your partners are ready to respond when it counts.
Join this high-energy session to explore how cyber esports transforms security teams into high-performers. We argue that high-pressure cyber simulations cultivate essential core skills by connecting directly to elevated professional performance. We'll examine cognitive conditioning through gaming to blend implicit and explicit learning, drawing on insights from famous sports coaches for competitive advantage beyond the game. We’ll share research supporting the link between high-level gaming and superior cognitive function (reaction time, decision speed, confidence, attention, and strategic planning).
Cyber esports uniquely fosters critical non-technical skills—problem-solving, critical thinking, teamwork, data analysis, and leadership—which the World Economic Forum highlights as crucial skill gaps. Simulating realistic cyber scenarios through "cognitive conditioning" directly prepares individuals for high-stakes environments like SOCs.
Cognitive conditioning (applied learning) builds intuition and instinct for better problem-solving and expedited decision-making. We will show how "playing" in cybersecurity and AI games translates into more effective "working," exploring new security operational requirements in cognitive security.
We will discuss how lifelong engagement with games and CTFs strengthens neural pathways, leading to measurable improvements in individual and team performance and ultimately productivity. The session will conclude with practical strategies for integrating games into the corporate environment to boost growth and morale.


