Unprompted: at the intersection of state-of-the-art AI and cybersecurity research

It was great to learn more about the state-of-the-art research in cybersecurity applications of AI, both from the attacker and defender’s perspectives at the Unprompted conference in Sydney today.

The talks from engineers at OpenAI, Google, Microsoft, TikTok, Slack and many others demonstrated the practical use cases for threat hunting, vulnerability discovery, detection and response to speed up and automate workflows.

Safety, cost management and scale were the top themes for me – you don’t always need the latest model for every task, deterministic scripts can complement your agentic AI pipelines, guardrails and alignment are still key. Best results live at the intersection of system automation and human judgment.

And, of course, it’s the people who make events like this so worthwhile – it was good to catch-up with old friends (and make some new ones) and exchange ideas and research. AI and cybersecurity is a team sport. Reach out if I can help.

I look forward to experimenting and applying technical insights at work.

Securing critical national infrastructure

I had a great time talking to Peter Davidoff from the Australian Government about the evolving approach to security.

We touched on the challenges and opportunities of securing critical national infrastructure, the increasing role of AI and practical examples of developing a defence-in-depth approach to security architecture.

A big thanks to the audience for great questions!

CISO Interview: Psychology and the Role of a CISO

When both attackers and defenders use AI, it’s the people who become the edge.

Attackers already run at machine speed, and faster tools only close part of that gap.

It was great to sit down with Dan Raywood to talk about building security culture and the evolving role of a CISO 👇

More

Key points from the CIO keynote

Security failures are rarely just a technology problem. They’re a design problem – a mismatch between how controls are built and how people actually work.

That was my message keynoting at CIO Leadership Live.

AI has amplified the security fundamentals.

☑️ Defaults beat persuasion: passkeys by default, automatic updates, SSO. The secure choice should be the easiest choice.
☑️ Shadow AI is a friction signal, not a compliance failure. If people are pasting data into unapproved chatbots, your sanctioned path is too slow. Give them a fast, safe alternative.
☑️ Build trust, not fear. Blameless reviews and visible leadership create the psychological safety people need to report incidents early.

The CIOs who win with AI won’t be the ones with the strictest rules but the ones whose guardrails make the secure way the easy way.

More

Human connection in a digital world

Two leadership programs completed 📚

The AGSM Professional Forum was about complexity – and specifically the costs that never hit a balance sheet: reputational damage, talent attrition, strategic drift. The masterclass dropped us into a scenario that escalated in real time, with no playbook and no obvious right answer. Does your week sometimes look like that?

“Learn to Lead” made the case that human connection as a strategic capability – and one that matters more, not less, as AI reshapes how we work.

Security proves it daily: the strongest controls fail without trust, judgment and people who feel safe enough to flag the thing that looks off.

I particularly liked the idea of cognitive upsizing when using AI – yes, offload tasks to the machine, but use the freed up bandwidth for deeper thinking and to solve even more ambitious challenges.

The throughline across both: lead through uncertainty instead of waiting for a certainty that isn’t coming, and pair the data with real human connection. Neither is enough on its own.

Grateful to the facilitators and the people I learned alongside.

Guest lecture: developing and implementing a security strategy

I had the pleasure of delivering a guest lecture on developing and implementing a cybersecurity strategy to students at the School of Information Systems and Technology Management, UNSW.
 
A security strategy is a set of decisions about what you will and won’t prioritise, made under real constraints – budget, headcount and a threat landscape that doesn’t wait for your roadmap to catch up.
 
Strategy starts with the business. If you can’t explain your security priorities in terms of what the organisation is trying to achieve, you won’t get the backing.
 
With AI, the fundamentals are still important, but the timelines are now compressed.
 
Thank you UNSW for the invitation, and to the students for the great discussion. This cohort is entering the field at a very interesting moment.

A lecture on human-centered approaches to cyber security

I enjoyed talking to students completing their Global MBA and MSc in Digital Transformation with the University of Hull Online about human-centered approaches to cyber security.

My lecture helped reinforce the idea that cyber security is a socio-technical challenge that has deep behavioural contingencies.

Cyber is a business risk and I’m glad it’s increasingly featured in business degree curriculums beyond computer science. My book, the Psychology of Information Security, helps bridge the gap between organisational and cyber strategy.

Global CISO 100

It’s great to be included in the Global CISO 100 🏆

This award recognises key pillars of our industry: innovation, strategic vision, leadership, team development and community contribution.

I’m incredibly grateful for the nomination and want to extend a big thank you to the judges and my network. Cyber security is a team effort, and I’m fortunate to work alongside an exceptional team and peer group every day.

Build Security for People – a keynote at CIO Leadership Live

I delivered a keynote at CIO Leadership Live.

For about a decade, our industry has had a favourite phrase: people are the weakest link. I made the opposite case – that the people we’ve been blaming are the most capable security asset we have, and we’ve spent that decade building systems that fight them instead of fit them.

The talk covered why training and punishment don’t work, why every workaround is actually free user research, and how you design your way to secure behaviour by making the secure path the easy path. And of course, where AI fits into all of it.