Cyber Voices

Australian Information Security Association (AISA)

Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.

  1. Sep 24

    Agentic GRC and the Limits of AI, with Ian Yip and Jack Hedges

    Governance, risk and compliance generates a great deal of manual work, and not all of it is work anyone would miss. Ian Yip's argument is that this is exactly where AI earns its place in a security team, provided nobody mistakes it for judgment. Ian is the founder and CEO of Avertro, the company behind the cyber and AI governance platform CyberHQ, and he recently delivered a standing room only session on agentic GRC at Infosecurity Europe in London. He joins David Savva-Willett along with Jack Hedges, a strategic account executive at Avertro who works with security leaders across Australia. Ian sets out a way of thinking rather than a technology: build an agentic team the way you would build a human one, as an org chart of narrow specialists that collaborate, because models do their best work when given one task rather than many. Chained together and scheduled, that team absorbs the evidence collection, the framework crosswalks and the board reporting, leaving the humans the work they would rather be doing. What cannot be delegated is taste, which Ian describes as the ability to look at what a model hands back and know what to strip away. The conversation covers how much of GRC is theatre and which of that is still necessary for auditability, why he believes everyone is now a builder, what European regulators do differently and why their real effect is on budgets rather than behaviour, and Jack's view from the field, where a lack of visibility over what staff are already using has overtaken cyber GRC as the pressing concern.

    Agentic GRC and the Limits of AI, with Ian Yip and Jack Hedges
  2. Sep 16

    Are ChatGPT, Claude or Gemini Useful in a Breach Investigation? with Josh Lemon

    Threat actors are already using large language models to accelerate the early stages of a compromise. Josh Lemon wanted to know what the same tools could do for the responders on the other side. Recorded at AdelaideSEC 2026, David Savva-Willett speaks with Josh Lemon, Chief of Digital Forensics and Incident Response at SoteriaSec and a SANS principal instructor, immediately after his talk on that question. Josh has been putting the major models in front of forensic evidence for years, and reports real movement: where they once sent an inexperienced analyst off in entirely the wrong direction, they now answer factual questions reliably. What they still lack is the creativity to ask why something is wrong, or what a threat actor is likely to do next. The discussion ranges across where LLMs are genuinely saving hours in a SOC, from one off Python tooling to threat intelligence summaries to executive status updates; a response Josh received that read unmistakably like vendor advertising; why he warns his students that an AI written report may one day be read by an expert witness in court; how MCP servers are being folded into SANS forensics classes; and whether any of this helps with the on call burden and burnout that have dogged the profession for years. It closes on the exchange every responder knows by heart, where no evidence of exfiltration gets heard as no exfiltration, and Josh's observation about what a model eager to please would say if a lawyer asked it the same question.

    Are ChatGPT, Claude or Gemini Useful in a Breach Investigation? with Josh Lemon
  3. Aug 19

    The Only Criminologist in the Room: Nakshathra Suresh on Human Centred Resilience

    Recorded live at AISA SydneySec 2026, host David Savva-Willett sits down with Nakshathra Suresh, a cyber criminologist and one of very few people in Australia bringing a social science lens to artificial intelligence and emerging technology safety. Nakshathra is co-founder of eiris, a safety technology consultancy, Oceania Youth Ambassador for the Internet Society, and teaches with the Faculty of Law and Justice at UNSW where she created the university's first criminology backed cyber security course. The conversation covers what a cyber criminologist actually does and why the discipline is still so young, how generative AI has turned catfishing and cyberstalking into something that runs itself once a public profile is scraped, the long tail of harm for victim survivors who end up retiring their online lives entirely, and why human centred resilience is a question of culture and conduct rather than another vulnerability to patch. Nakshathra also makes a direct case about who is missing from the room when security decisions get made. Content note: this episode includes discussion of cyberstalking, technology facilitated abuse, image based abuse and harm to children in online environments. If anything here raises something for you, support is available. 1800RESPECT on 1800 737 732 or Lifeline on 13 11 14, and image based abuse can be reported to the eSafety Commissioner at esafety.gov.au. Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.

    The Only Criminologist in the Room: Nakshathra Suresh on Human Centred Resilience
  4. Aug 12

    Fighting Back: Glenn Maiden on Putting a Bounty on Cybercrime

    Cybercrime is not a lone hacker in a hoodie any more. It is an economy, and by some estimates a staggeringly large one. In this episode of Cyber Voices, host David Savva-Willett flips the usual script and asks not how we defend, but how we fight back. Glenn Maiden is Chief Security Officer for Fortinet Australia and Director of Threat Intelligence at FortiGuard Labs for Australia and New Zealand. He spent years in Defence and the Australian Intelligence Community working in geospatial and human terrain intelligence, including during Operation Slipper, before moving into commercial threat intelligence. He established the team behind the World Economic Forum's Cybercrime Atlas and, most recently, helped create a first of its kind cybercrime bounty program with Crime Stoppers International. The conversation covers how mapping tribal structures, community leaders and wells in a conflict zone translates to mapping the humans behind ransomware crews, why our industry has become excellent at indicators of compromise and knows almost nothing about the actual people, and what the Cybercrime Atlas found when it started pulling names, aliases, bank accounts, crypto wallets and bulletproof hosting together into targeting packages for Interpol, Europol and the FBI. David and Glenn also dig into why better defence alone was never going to be enough, the gap that sits on the people and process side rather than the technology side, and the unreported soft underbelly of an economy built on small and medium business. Glenn explains how the new bounty program works, how someone with intelligence on a threat actor can submit an anonymous tip and potentially collect a reward when that person is arrested and prosecuted, and why the same infrastructure mapping may help pull far worse criminals off the streets. There is a human side too. Glenn talks about the young man in Eastern Europe committing cybercrime to get his family out, the scam compounds operating a couple of hours to Australia's north, and his own experience of being scammed through Facebook Marketplace. He explains why he tells that story publicly and how shame keeps victims silent. Glenn closes with practical advice for CISOs, SOC leads and analysts who will never run a takedown themselves. Content note: this episode includes brief references to human trafficking, forced labour in scam centres and child exploitation material in the context of organised crime. Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.

About

Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.

You Might Also Like