This podcast series is an extension of our highly successful book 'The Secure Board'.
With a new episode each week, we will provide you, Australian company directors and executives, with relevant and timely information to enhance your understanding of cyber risk and how to help protect your organisation given the constantly evolving threat landscape.
In this week’s episode, Anna is joined again by Vijay Krishnan, the Chief Information Security Officer at UniSuper. In this episode, Vijay shares his insights as a CISO into what questions he dreads being asked the most, and what questions he wished board members asked. He also discusses the security of critical infrastructure changes that have come through and how he interprets new regulatory requirements, and how to integrate those into existing strategy and roadmap.
Vijay leads UniSuper's Information Security including Security Operations, Security Governance, Risk & Compliance, Security Strategy, Architecture & Design, Identity & Access Management, and Enterprise Observability. He leads a multi-year security program to reduce UniSuper security risk, thus protecting UniSuper members. Vijay has extensive experience negotiating clear and concise security and technology outcomes in regulatory, policy, and outsourcing agreements delivering value-creation opportunities. He has considerable, diverse national and international experience with extensive executive and Board level exposure. Previously he was leading Information security at Transurban, accountable for IT and OT security including accountability for PCI DSS compliance.
Links:
Vijay LinkedIn
For the full episode transcript, please visit our website.
In this week’s episode, Anna is joined by Vijay Krishnan, the Chief Information Security Officer at UniSuper. In this episode, Vijay shares his journey working in cyber, including his time working at UniSuper with Anna, the value that one can bring when beginning a new role in an organisation, and his advice on engaging a board on cyber.
Vijay leads UniSuper's Information Security including Security Operations, Security Governance, Risk & Compliance, Security Strategy, Architecture & Design, Identity & Access Management, and Enterprise Observability. He leads a multi-year security program to reduce UniSuper security risk, thus protecting UniSuper members. Vijay has extensive experience negotiating clear and concise security and technology outcomes in regulatory, policy, and outsourcing agreements delivering value-creation opportunities. He has considerable, diverse national and international experience with extensive executive and Board level exposure. Previously he was leading Information security at Transurban, accountable for IT and OT security including accountability for PCI DSS compliance.
Links:
Vijay LinkedIn
For the full episode transcript, please visit our website.
Over several episodes, Anna and Claire will take turns sharing a chapter from their book, The Secure Board, in audiobook form, so you can hear how to be confident that your organisation is cyber safe.
In this episode, Anna shares the book's fifth chapter, Element 5, where Anna and Claire discuss understanding the role of the CISO, and if you need one.
Previous episodes:
Episode 64: Introduction to The Secure Board
Episode 70: Element 1 of The Secure Board
Episode 72: Element 2 of The Secure Board
Episode 73: Element 3 of The Secure Board
Episode 74: Element 4 of The Secure Board
In this week’s episode, Anna is joined again by Cosi Robinson, the Cyber Security Analyst within the Security Operations team and part of the Information Security team at UniSuper. In this sequel episode, Cosi continues sharing her unique experience of having her identity compromised, along with changing to a career in cyber security.
In her prior role as the Cyber Resilience & Education Analyst, Cosi assisted in developing creative ways to ensure cyber security was front of mind through communication and training to help educate, influence, and engage UniSuper employees about cyber security risks and their responsibilities relating to cyber security policies, standards, and controls. Cosi developed and ran phishing simulation campaigns, and training and analyzed and reported the statistics and success rates. She also monitored and identified top human risks and behaviours that required education to mitigate them and protect UniSuper. Cosi now works in the Security Operations team as the Cyber Security Analyst and performs the analysis of phishing emails reported. She is transitioning into this role to develop and further enhance her skills and expertise. She completed her Certificate IV in Cyber Security and previously worked as the Executive Assistant supporting the Chief Information Security Officer and Information Security team at UniSuper. In prior years, she has worked as an Executive Assistant at top ASX organisations.
Links:
Cosi LinkedIn
Part 1
For the full episode transcript, please visit our website.
In this week’s episode, Anna is joined by Cosi Robinson, the Cyber Security Analyst within the Security Operations team and part of the Information Security team at UniSuper. In this episode, Cosi shares her unique experience of having her identity compromised by a company that supplied a service to her.
In her prior role as the Cyber Resilience & Education Analyst, Cosi assisted in developing creative ways to ensure cyber security was front of mind through communication and training to help educate, influence, and engage UniSuper employees about cyber security risks and their responsibilities relating to cyber security policies, standards, and controls. Cosi developed and ran phishing simulation campaigns, and training and analyzed and reported the statistics and success rates. She also monitored and identified top human risks and behaviours that required education to mitigate them and protect UniSuper. Cosi now works in the Security Operations team as the Cyber Security Analyst and performs the analysis of phishing emails reported. She is transitioning into this role to develop and further enhance her skills and expertise. She completed her Certificate IV in Cyber Security and previously worked as the Executive Assistant supporting the Chief Information Security Officer and Information Security team at UniSuper. In prior years, she has worked as an Executive Assistant at top ASX organisations.
Links:
Cosi LinkedIn
For the full episode transcript, please visit our website.
Over several episodes, Anna and Claire will take turns sharing a chapter from their book, The Secure Board, in audiobook form, so you can hear how to be confident that your organisation is cyber safe.
In this episode, Anna shares the book's fourth chapter, Element 4, where Anna and Claire discuss meaningful metrics, measurement, and reporting.
Previous episodes:
Episode 64: Introduction to The Secure Board
Episode 70: Element 1 of The Secure Board
Episode 72: Element 2 of The Secure Board
Episode 73: Element 3 of The Secure Board
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Over several episodes, Anna and Claire will take turns sharing a chapter from their book, The Secure Board, in audiobook form, so you can hear how to be confident that your organisation is cyber safe.
In this episode, Claire shares the book's third chapter, Element 3, where Anna and Claire discuss creating a cyber safe business with a cyber security strategy.
Previous episodes:
Episode 64: Introduction to The Secure Board
Episode 70: Element 1 of The Secure Board
Episode 72: Element 2 of The Secure Board
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Myth: You’ll never keep up with the pace of cyber risk. Fact: Planning provides a path forward.
In this episode, Claire discusses the importance of preparation before a cyber incident occurs.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Over several episodes, Anna and Claire will take turns sharing a chapter from their book, The Secure Board, in audiobook form, so you can hear how to be confident that your organisation is cyber safe.
In this episode, Anna shares the second chapter of the book, Element 2, where Anna and Claire discuss taking a risk-based approach to governing cyber security.
Previous episodes:
Episode 64: Introduction to The Secure Board
Episode 70: Element 1 of The Secure Board
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Your time is precious. But so is your company data.
In this episode, Anna shares their three tips to get the most out of your cyber security board updates.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
This week’s episode is a repost of The Security Collective podcast, where Claire is joined by Alla Valente, a senior analyst at Forrester. In this episode, they discuss the role of procurement, talk about supply chain risk as an enterprise-wide risk and discuss who might own this risk. They covered how businesses are struggling to give third parties limited access to data and systems, and the flow on effects of managing the right level of access to get the job done.
Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.
Links:
Alla LinkedIn
The Security Collective
For the full episode transcript, please visit our website.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
The World Economic Forum’s 2023 Global Risk Report ranks “widespread cybercrime and cyber security” as number 8 in the global risk ranked by severity over the next ten years.
Inspired by a recent article by Anna Leibel and Claire Pales, in this bonus episode Anna shares some tips for governing cyber security.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Over several episodes, Anna and Claire will take turns sharing a chapter from their book, The Secure Board, in audiobook form, so you can hear how to be confident that your organisation is cyber safe.
In this episode, Claire shares the first chapter of the book, Element 1, where Anna and Claire discuss cyber as a business risk, not an ‘IT problem’.
Links:
Episode 64: Introduction to The Secure Board
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
The “culture of your business” might be a buzzword used in recruiting. But when it comes to cyber, culture can be the difference between protecting customers and protecting your bottom line.
In this episode, Claire explores the necessary steps to build a stronger cyber security culture within your organisation.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Mitra Minai, National Cyber Partner at KPMG - Health, Aging & Human Services and Vic Gov, joins Claire in the second part of a two-part series to continue sharing her insights on cyber in the healthcare sector. In this episode, Mitra and Claire cover how ransom payment conversations are playing out for hospitals, and the impact of the security of critical infrastructure legislation changes on the healthcare industry.
Mitra is a senior Technology and Security Transformation executive with over 20 years’ experience working in the Health, Financial and Professional Services industries. Mitra is a recognised leader in successfully defining and implementing Centres of Excellence Technology and Cybersecurity functions across major International and Australian Banks and most recently in the Health Sector. Mitra is a trusted advisor to senior stakeholders including Board of Directors and Risk and Audit Committees, enabling effective governance and insights for investment and decision-making. Mitra joined KPMG Australia in July 2022 as the National Cyber Partner to the Health Sector and Cyber Partner to the Victorian Government after two and a half years as the Chief Information Security Officer at Healthscope.
Links:
Mitra Minai’s LinkedIn
Part 1 of Mitra's conversation with Claire
For the full episode transcript, please visit our website.
To learn more about our Cyber Security Board Education online course click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
If you’re only aware of cyber incidents from a quarterly report, you’re not meeting your obligations as a board member. It is important to understand how you can successfully support your organisation through a cyber event.
In this episode, Claire explains the Board's role during a cyber incident, and how their role can change depending on the circumstances of an incident.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Mitra Minai, National Cyber Partner at KPMG - Health, Aging & Human Services and Vic Gov, joins Claire in a two-part series to discuss data protection, some of the barriers to cyber resilience, and the need for a better understanding of cyber being a way of doing business and not just an IT project. In this episode, Mitra set the scene of cyber in healthcare and what she experienced over the past few years in the sector, particularly exploring the risks for hospitals and the flow on impact of the pandemic on cyber controls and projects.
Mitra is a senior Technology and Security Transformation executive with over 20 years’ experience working in the Health, Financial and Professional Services industries. Mitra is a recognised leader in successfully defining and implementing Centres of Excellence Technology and Cybersecurity functions across major International and Australian Banks and most recently in the Health Sector. Mitra is a trusted advisor to senior stakeholders including Board of Directors and Risk and Audit Committees, enabling effective governance and insights for investment and decision-making. Mitra joined KPMG Australia in July 2022 as the National Cyber Partner to the Health Sector and Cyber Partner to the Victorian Government after two and a half years as the Chief Information Security Officer at Healthscope.
Links:
Mitra Minai’s LinkedIn
No matter your level of cyber knowledge, you will gain insights from our online education series. To learn about The Armoury click here.
Click here to discover the Top 3 questions we are asked by Boards and how we answer them.
Your typical risk governance strategies can be ineffective when applied to cyber security.
In this episode, Anna explains the 3 reasons the typical approach to risk governance won’t work for cyber security, and what you need to do differently to meet your due diligence.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Walking the walk on cyber security: do you know the right steps? A strong CEO stance on cyber security makes all the difference.
In this episode, Anna and Claire share their advice on leading from the front, and discuss the CEO's role in keeping an organisation safe.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Mergers can be where it all falls apart. Are your company’s growth aspirations exposing you to cyber risk?
This episode explains how to learn the crucial steps that will protect you while the company strategy is being executed.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Not all Cyber incidents are made equal. As a result, it can be hard to know what you need to do and when to manage the crisis. Set yourself up to withstand the worst.
In this episode, Anna and Claire explain how to understand what you’ll need to move forward post-incident.
Click here to listen, or wherever you enjoy your podcasts.
To learn more about our Cyber Security Board Education online course click here.
Not all Cyber incidents are made equal. As a result, it can be hard to know what you need to do and when to manage the crisis. Set yourself up to withstand the worst. Inspired by a recent article by Anna and Claire, this episode explains how to understand what you'll need to move forward post-incident.
To read the article on how to know if a cyber crisis is really over, please visit our LinkedIn.
Brendan Read, a partner at KordaMentha, joins Anna in the second part of a two-part series to continue sharing his insights working with clients around emerging cyber risk. Brendan and Anna discuss the importance of multi-factor authentication, the new amendments to the Privacy Act and what should come next, and the emerging cyber threats for this calendar year.
Brendan’s two decades of experience in digital and cyber investigations includes 10 years within the Queensland Police Service. A founding member of the High-Tech Crime Investigation Unit, he worked alongside State, Federal, and International law enforcement agencies, including the US Secret Service, co-ordinating multijurisdictional investigations involving covert operations into computer hacking and financial crimes spanning multiple countries. Brendan has given evidence in many matters before District and Magistrates courts and in civil proceedings where digital evidence has been critical to the outcome. He has performed complex computer forensic examinations on computer systems for businesses, government agencies, criminal investigations, and civil litigation.
Links:
Brendan Read’s LinkedIn
KordaMentha LinkedIn
For the full episode transcript, please visit our website.
The Secure Board exists to educate on cyber security without the jargon, to enable Directors to uplift their confidence in important decision-making, and provide executives with an understanding of cyber security as an enterprise risk.
This episode proudly announces the launch of our online education series ‘ The Armoury’, to translate Board obligations for Directors and executives and continue to uplift literacy in relation to cyber security.
No matter your level of cyber knowledge, you will gain insights from our online education series. To learn more about The Armoury click here.
Brendan Read, a partner at KordaMentha, joins Anna in a two-part series to discuss his career progression from working with Queensland Police to being a partner with KordaMentha, cyber-related class action, the need to monitor access of people within an organisation, and company culture, particularly in relation to insider threats.
Brendan’s two decades of experience in digital and cyber investigations includes 10 years within the Queensland Police Service. A founding member of the High-Tech Crime Investigation Unit, he worked alongside State, Federal and International law enforcement agencies, including the US Secret Service, co-ordinating multijurisdictional investigations involving covert operations into computer hacking and financial crimes spanning multiple countries. Brendan has given evidence in many matters before District and Magistrates courts and in civil proceedings where digital evidence has been critical to the outcome. He has performed complex computer forensic examinations on computer systems for businesses, government agencies, criminal investigations, and civil litigation.
Links:
Brendan Read’s LinkedIn
KordaMentha LinkedIn
For the full episode transcript, please visit our website.
In honour of International Women’s Day, this week’s episode revisits some of the amazing women that have joined Anna and Claire on the podcast over the past 64 episodes. These inspiring guests have represented diversity and inclusion through topics like the social license to operate, building sustainable rural communities, building a pipeline of cyber professionals, providing expertise to small businesses to help them prepare for a cyber event, ethics, culture, and trust, and the role the law plays in keeping pace with new technologies.
Links:
International Women’s Day
For the full episode transcript, please visit our website.
Over several episodes, Anna and Claire will take turns sharing a chapter from their book, The Secure Board, in audiobook form, so you can hear how to be confident that your organisation is cyber safe. In this episode, Claire shares the introductory chapters of the book, where Anna and Claire set the scene for the chapters to come.
For the full episode transcript, please visit our website.
In this episode, Claire shares the top five cyber security concerns of not-for-profit organisations, including Shadow IT and the use of unsecured devices. Alongside these concerns, Claire discusses how not-for-profits can better protect themselves in relation to cyber.
Links:
Episode 33: Shadow IT
For the full episode transcript, please visit our website.
‘The days of cyber as an afterthought are gone.’
'In this episode, Anna and Claire discuss cyber as a strategic enabler for businesses by reflecting on Deloitte’s 2023 Global Future of Cyber Survey.
Anna and Claire focus on Deloitte’s methodologies and insights including focusing their efforts on understanding the business value and impact of cyber that organisations are experiencing, and the distinct actions leading organisations are taking to gain more value from cyber. Multi-directional engagement, the criticality of digital transformation initiatives in relation to cyber, robust planning, and appreciating and investing in talent are the key learning and findings that Anna and Claire explore further in this episode.
Links:
Deloitte’s 2023 Future of Cyber Report
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where Anna and Claire answer questions sent in by our audience.
In this episode, Anna and Claire answer the questions ‘what can an organisation do to hire new workforce and retain existing teams?’, ‘what is the risk to organisations having to pay compensation to customers or those impacted by a cyber breach?’, ‘what can an organisation do to protect their reputation during and after a cyber breach?’, ‘what can the Australian Cyber Security Centre do for organisations?’, and ‘as a director, how concerned should one be about solvency during a cyber incident?’
Links:
The Australian Cyber Security Centre
For the full episode transcript, please visit our website.
This week's episode is a part of the 'In case you missed it' series. The topic of today's podcast is developing cyber literacy. Presented by Anna, this curated episode brings together non-Executive Directors and cyber experts, including Anna and Claire, on building cyber literacy in the boardroom.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
Liza McDonald, Head of Responsible Investments at Aware Super joins Anna in this episode dedicated to Environment, Social and Governance or ESG. In this episode, Liza and Anna discuss Liza’s roles at Aware Super, and how they have evolved with ESG, the benefits of having cyber as a part of ESG, as well as the challenges around integrating cyber into ESG. Liza and Anna also shared how an incident playing out for another company can be used as a learning lesson for others.
Liza has over 24 years’ experience in the superannuation sector and is a specialist and passionate advocate for Responsible Investments and Sustainable Finance. As Head of Responsible Investments , she has led the development and implementation of the Fund’s Responsible Investment policies, the execution of the Climate Change Strategy and also manages the ESG policy implementation including manager and asset class ESG reviews. Liza joined Aware Super through our merger partner Health Super in December 2006 as an analyst in the Compliance, Legal and Risk Team. Before joining Aware Super, Liza held various roles at Mercer Legal where her primary focus was on trustee education and corporate secretarial duties. Liza represents Aware Super on a number of working groups and committees including Investors Against Slavery & Trafficking APAC (IAST-APAC); ESG Research Australia; the Australian Sustainable Finance Initiative (ASFI); the Responsible Investment Association Australasia (RIAA); 40:40 Vision; the Australian Council of Superannuation Investors (ACSI) and the UN convened Global Investors for Sustainable Development Alliance (GISD). Liza holds a Post Graduate Diploma of Applied Finance at Kaplan Education and is a Graduate of AICD.
Links:
Liza McDonald’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week’s episode is a recast of Grant Chisnall’s podcast ‘Crisis Talks’, where Claire and Anna were guests sharing their insights amidst recent high-profile cyber-attacks targeting Medibank and Optus. Grant, Anna, and Claire discussed as you might imagine the impact of a cyber crisis on boards, the need for solid, effective communication during a cyber crisis, and how directors might navigate the future of cyber risk in Australia.
Grant has supported some of the world's leading organisations through crisis events ranging from cyber attacks to coronavirus; activism to air crashes; and from Natural disasters to workplace fatalities. His podcast ‘Crisis Talks’ tells the extraordinary stories of people who have led through crises and their stories of leadership and resilience in the face of adversity. Grant’s aim is to help leaders prepare for the worst-case scenarios and respond proactively and with confidence to any incidents that threaten their people, operations or reputation.
Links:
Grant Chisnall’s LinkedIn
Left of Boom website
LastPass LinkedIn
This week's episode is an 'Ask Me Anything' where Anna and Claire answer questions sent in by our audience.
In this episode, Anna and Claire answer the questions ‘how should directors connect the intersection between physical security and cyber security?’, ‘what cybersecurity concerns should new board members be looking for?’, ‘is it okay to be reactive to cyber threats?’, and ‘what is the board’s role during a cyber incident?’.
Links:
LastPass LinkedIn
Episode 45: Ask Me Anything #8
For the full episode transcript, please visit our website.
‘But what does it mean to be a good corporate citizen in 2022, when it comes to data collection, retention, protection, and deletion?’
Kieran Pender, lawyer, writer, and academic, joins Anna in this week’s episode to discuss Kieran’s insights on the severity and frequency of cyber-attacks recently in Australia, whether or not CEOs should lose their jobs after experiencing a cyber incident, the variety of Kieran’s work and how his current blend of work came about, and important areas of cyber law that Boards should be aware of today. Kieran also shares how technology is changing the landscape of whistleblowing, and how that impacts transparency, which he was due to speak about at TEDx in Canberra.
Kieran Pender is a lawyer, writer and academic. He is an honorary lecturer at the ANU College of Law and is one of Australia's leading experts on whistleblowing law. Kieran is also an award-winning writer, contributing to The Guardian, The New York Times and The Saturday Paper.
Links:
Kieran Pender’s LinkedIn
LastPass LinkedIn
Episode 39: Lynn Warneke Part I
Episode 40: Lynn Warneke Part II
For the full episode transcript, please visit our website.
Jo Plummer, Experienced Board Chair, Goverance Professional, and Strategist, joins Claire as our second guest in a series dedicated to Environment, Social, and Governance or ESG. In this episode, Jo and Claire discuss ESG goals and how the reporting of these goals is evolving, the use of insurance as an opportunity to transfer risk, and also Jo shares her insights on the importance of ongoing education for Directors.
Jo is known for her optimistic, energetic style and has been affectionately coined the ‘positive provocateur’. She is relentless in her drive to positively shape the futures of the organisations who she is engaged with. Her trademark is aligning sound commercial, social and environmental outcomes with customer and community expectations. Jo’s portfolio includes numerous board chair and committee roles, professional mentoring (boards, directors and executives) and facilitation. In addition, Jo also pursues what she calls ‘fun with purpose projects such as presenting, educating and emceeing.
Links:
Jo Plummer’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
'Most roads lead back to preparation.’
In this episode, Claire discusses what Directors can learn from recent cyber events. Following recent cyber events in Australia this year, Claire shares her five key learnings for Directors, which include how Directors can learn from incidents experienced by other organisations, the cost of a cyber incident beyond a ransom demand, and the importance of asking questions.
Links:
LastPass LinkedIn
Episode 47: What Directors can learn from recent cyber events #1
For the full episode transcript, please visit our website.
This week’s episode is a repost of KordaMentha's Behind Business podcast, where Anna was a guest along with Brendan Read, a partner of the cyber practice at KordaMentha. In this episode, Anna and Brendan talk about regulation, directors’ duties, third-party vendors, ransomware, and phishing.
Links:
KordaMentha’s LinkedIn
Brendan Read’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
Bernie Lloyd, Chair of Bank First, and Michelle Bagnall, CEO of Bank First, join Anna again in Part II to continue discussing and sharing their knowledge and experience of keeping an organisation cyber safe. In this episode, Bernie and Michelle discuss how to create a relationship with the Board, how to set a culture of trust and transparency, how to ensure adequate oversight of cyber risk governance, and the importance of continuous learning for Directors.
Bernie brings to the Board extensive educational experience in rural and metropolitan schools as a classroom teacher as well as executive manager. Her leadership expertise resides in long-term strategic planning, building capacity in teams and sustaining and expanding growth in organisations. She has coached individuals and teams, and facilitated workshops for aspiring leaders with an emphasis on building positive environments which sustain and empower. Her governance experience includes school councils and executive roles with VASSP (Victorian Association of State Secondary Principals). She led the Victorian chapter of Principals Australia for three years. Bernie joined the Board as Intern in 2010, was elected by the Members in 2011, and was appointed Chair of the Board in 2015. Bernie is also a Director of Youthrive, a rural foundation which provides support and opportunities for young people in order to build agency and capability.
Michelle is the Chief Executive Officer of Bank First and brings over 25 years of financial services experience in Australia and internationally. Prior to joining Bank First in February 2021, Michelle was CEO of RACQ Bank and held senior positions at Suncorp, National Australia Bank, The Royal Bank of Scotland and Insurance Australia Group. She is driven by a deep respect for people and passionate about the powerful combination of people leadership, partnership and organisational competencies. Michelle is a member of FINSIA, a graduate of AICD and has completed an MBA (with Distinction). She has previously held Executive Director positions on the Boards of a superannuation trustee at Suncorp, and the Board of RACQ Financial Planning Pty Ltd. On a personal level, Michelle directs her energies toward issues related to women, education, equality, inclusion, and empowerment.
Links:
Bernie Lloyd’s LinkedIn
Michelle Bagnall’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
Bernie Lloyd, Chair of Bank First, and Michelle Bagnall, CEO of Bank First, join Anna in a two-part series to discuss and share their knowledge and experience of keeping an organisation cyber safe. In this episode, Bernie and Michelle discuss what a board can do to influence their focus and commitment to cyber risk management, their approach to meeting the requirements of CPS 234, human error as a risk to cyber, and their mindset when it comes to navigating a member-focused business.
Bernie brings to the Board extensive educational experience in rural and metropolitan schools as a classroom teacher as well as executive manager. Her leadership expertise resides in long-term strategic planning, building capacity in teams and sustaining and expanding growth in organisations. She has coached individuals and teams, and facilitated workshops for aspiring leaders with an emphasis on building positive environments which sustain and empower. Her governance experience includes school councils and executive roles with VASSP (Victorian Association of State Secondary Principals). She led the Victorian chapter of Principals Australia for three years. Bernie joined the Board as Intern in 2010, was elected by the Members in 2011, and was appointed Chair of the Board in 2015. Bernie is also a Director of Youthrive, a rural foundation which provides support and opportunities for young people in order to build agency and capability.
Michelle is the Chief Executive Officer of Bank First and brings over 25 years of financial services experience in Australia and internationally. Prior to joining Bank First in February 2021, Michelle was CEO of RACQ Bank and held senior positions at Suncorp, National Australia Bank, The Royal Bank of Scotland and Insurance Australia Group. She is driven by a deep respect for people and passionate about the powerful combination of people leadership, partnership and organisational competencies. Michelle is a member of FINSIA, a graduate of AICD and has completed an MBA (with Distinction). She has previously held Executive Director positions on the Boards of a superannuation trustee at Suncorp, and the Board of RACQ Financial Planning Pty Ltd. On a personal level, Michelle directs her energies toward issues related to women, education, equality, inclusion, and empowerment.
Links:
Bernie Lloyd’s LinkedIn
Michelle Bagnall’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week's episode is a part of the 'In case you missed it' series. The topic of today's podcast is ransomware. Presented by Claire, this curated episode brings together non-Executive Directors and cyber experts, including Anna and Claire, on the challenges faced by organisations in relation to ransomware, ransom payments and the recovery from such devastating cyber events.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where Anna and Claire answer questions sent in by our audience.
In this episode, Anna and Claire answer the questions ‘following COVID over the past two years, what is expected in the next year in relation to cyber?’, ‘why won’t cyber insurance keep me safe?’, ‘in relation to outsourcing of IT to a third party, is that third-party IT service provider responsible for cybersecurity?’, and ‘how much money does one need to invest in cyber to be safe?’.
Links:
LastPass LinkedIn
Episode 32: more information on creating a cyber culture
For the full episode transcript, please visit our website.
Dr. Lisa Caffery, board chair of Sunwater, joins Anna in this week’s episode to discuss Lisa’s professional background, what she plays in helping the community progress down a digital path, her work for Sunwater, the topic of cyber simulations, and their importance.
Dr Lisa Caffery is the board chair of Sunwater – a government owned bulk water utility that owns 19 dams and delivers around 40 per cent of the water used commercially in Queensland. Lisa lives in regional Queensland and also holds board director roles in health, community services and STEM education. She is the founder and managing director of an independent advisory firm that provides governance, strategy, engagement and research services to clients in health, higher education, resources, not-for-profit and government sectors. In 2021, Lisa completed her PhD at Central Queensland University and her current research interests are in health, rural and remote communities and social impact. When not working, you’ll find Lisa outside enjoying the Queensland sunshine and at ParkRun trying to beat her PB!
Links:
Lisa Caffery's LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
'We are not immune to cyber events.’
In this episode, Anna discusses what Directors can learn from recent cyber events. This episode focuses on what Directors can learn from the recent Optus cyber incident, as well as other cyber events, and what actions can be taken into consideration for businesses in the future. Additionally, Anna provides advice for all Optus customers, including contacting IDCARE.
Check out IDCARE on 1800 595 160 for advice. IDCARE are a not for profit helping individuals who are concerns that their identity may have been compromised. They have a dedicated Optus page here https://www.idcare.org/optus-db-response.
Links:
LastPass LinkedIn
Episode 14: what motivates CEOs in relation to cyber?
For the full episode transcript, please visit our website.
Brodi Coghlan, ESG Specialist for Reece Limited, joins Claire as our first guest in a series dedicated to Environment, Social and Governance or ESG. In this episode, Brodi and Claire discuss how ESG came about, where cyber fits into ESG reporting, and the global standards for ESG or the current lack thereof.
Brodi is an ESG advisor with more than 5 years’ experience in sustainability and ESG reporting and strategy. She works closely with corporate stakeholders at all levels to advise and engage on various ESG topics, develop supporting strategies, and empower individuals and teams to own their impact. She’s passionate about the combined power of data-driven decision-making and creativity to create positive, sustainable change.
Links:
Brodi Coghlan’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where Anna and Claire answer questions sent in by our audience.
In this episode, Anna and Claire answer the questions ‘as a board, what should the expectations be of the role of the CEO and their obligations in relation to cybersecurity?’, ‘why is it important that a company has a cybersecurity strategy?’, ‘should businesses be considering cyber as part of their due diligence in mergers and acquisitions activity?’, and ‘should small businesses manage the risk of cyber if they do not manage sensitive customer information?’.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
Gartner expects to see a shift in formal accountability for the treatment of cyber risks from the security leader to senior business leaders.
This week’s episode is a little different as Anna and Claire reflect on some of the latest industry predictions for cyber for the coming years. Last year, Gartner, technological research and consulting firm, unveiled their latest round of cybersecurity predictions as they have done every year for the past few years. Given their own experiences with clients, Anna and Claire discuss a couple of the key predictions that are necessary for boards to consider.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where Anna and Claire answer questions sent in by our audience.
In this episode, Anna and Claire answer the questions ‘do insurance policies have conditions on paying ransoms?’, ‘with the rise of remote working, what are the implications for managing cyber risk?’, ‘would cyber criminals target not-for-profits more in the future than they do today?’, and ‘ what are IOCs?’.
Links:
LastPass LinkedIn
Episode 33 - Shadow IT
For the full episode transcript, please visit our website.
Chris McLaughlin, APAC Cyber Advisory leader at Clyde & Co, and Reece Corbett-Wilkins, Clyde & Co partner, join Claire again in this episode to discuss third-party risk, particularly about a focus not just on data, but on what business processes third parties might be responsible for, and the impact of supply chain dependency.
Chris is a Principal, Cyber Risk in the Sydney office with more than twenty-five years’ experience in information security and risk management. Chris’ practice focuses on strengthening clients’ readiness for, response to and recovery from cyber incidents. He works closely with clients to offer information and operational technology risk assessments, breach compromise and threat assessment, cyber strategy development and related advisory services. Chris holds a BSc(Hons) in Communications Systems Engineering, MSc in Information Security, is a Chartered IT Professional a Fellow of the British Computer Society and holds several professional qualifications including CISSP.
Reece is a leading member of Clyde & Co's cyber incident response team and has experience acting in a range of local, regional, and global incidents affecting government agencies and private sector organisations of all sizes, operating across all industry sectors. Acting as 'breach coach', Reece is well regarded for his ability to advise boards and other senior members in the executive, legal, IT, risk management, and public relations functions to navigate their strategic response to Australia’s complex cyber landscape.
Links:
Chris McLaughlin’s LinkedIn
Reece Corbett-Wilkins LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
Chris McLaughlin, APAC Cyber Advisory leader at Clyde & Co, and Reece Corbett-Wilkins, Clyde & Co partner, join Claire in this episode to primarily discuss third-party risk, as well as Reece providing an update on changes in the cyber landscape since the last time he spoke with Claire back in episode eight.
Chris is a Principal, Cyber Risk in the Sydney office with more than twenty-five years’ experience in information security and risk management. Chris’ practice focuses on strengthening clients’ readiness for, response to and recovery from cyber incidents. He works closely with clients to offer information and operational technology risk assessments, breach compromise and threat assessment, cyber strategy development and related advisory services. Chris holds a BSc(Hons) in Communications Systems Engineering, MSc in Information Security, is a Chartered IT Professional a Fellow of the British Computer Society and holds several professional qualifications including CISSP.
Reece is a leading member of Clyde & Co's cyber incident response team and has experience acting in a range of local, regional, and global incidents affecting government agencies and private sector organisations of all sizes, operating across all industry sectors. Acting as 'breach coach', Reece is well regarded for his ability to advise boards and other senior members in the executive, legal, IT, risk management, and public relations functions to navigate their strategic response to Australia’s complex cyber landscape.
Links:
Chris McLaughlin’s LinkedIn
Reece Corbett-Wilkins LinkedIn
LastPass LinkedIn
Episode 8
For the full episode transcript, please visit our website.
This week’s episode is the second part of our podcast with Lynn Warneke as our guest. In this episode, Anna and Lynn discuss how the dependency on technology puts the privacy of citizens at risk, how boards being engaged in cyber risk management in different ways to more traditional risks, and how Lynn’s corporate experience and studies are influencing her role as the Chair and Member of the Financial Risk and Audit committees.
Lynn is a Non-Executive Director specialising in digital and data strategy, transformation, innovation, cyber and risk management, with multi-industry experience in government, tertiary education, retail/wholesale, professional services and consulting, and technology sectors. She holds a number of board, industry and advisory roles, and is also a diversity advocate with ACS and the #TechDiversity Foundation, and start-up mentor with Stone & Chalk and AustCyber. Lynn’s executive career has included business, consulting and ICT leadership roles for a diverse range of organisations, in both highly regulated and high-growth settings. Lynn is currently completing a Master of Laws in New Technologies at ANU.
Links:
Lynn Warneke’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
Lynn Warneke, a former COO and award-winning CIO, joins Anna in this episode to discuss her impressive career to date, including her transition from a corporate to a portfolio career, and her recent decision to study the law of new technologies. Additionally, Anna and Lynn consider whether there is such thing as cyber law, and Lynn shares the top three shifts she has observed in relation to the frequency and severity of cyber-attacks.
Lynn is a Non-Executive Director specialising in digital and data strategy, transformation, innovation, cyber and risk management, with multi-industry experience in government, tertiary education, retail/wholesale, professional services and consulting, and technology sectors. She holds a number of board, industry and advisory roles, and is also a diversity advocate with ACS and the #TechDiversity Foundation, and start-up mentor with Stone & Chalk and AustCyber. Lynn’s executive career has included business, consulting and ICT leadership roles for a diverse range of organisations, in both highly regulated and high-growth settings. Lynn is currently completing a Master of Laws in New Technologies at ANU.
Links:
Lynn Warneke’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
Do you feel that your board has a compliance-based mindset that could be putting you at risk?
This week’s episode is the final episode of a six-part series, where Anna and Claire discuss the hidden risks of cybersecurity. In partnership with LastPass, Caire explains the hidden risk of compliance. In today’s episode, Claire explores how compliance acts as a risk for organisations, highlighting that there is more to securing a business than meeting a standard or regulatory requirement.
Links:
LastPass LinkedIn
Episode 32 - unpacks the impact of a compliance-based culture
For the full episode transcript, please visit our website.
If cyber risk is not being considered, it can lead to much more than unexpected costs.
This week’s episode is the fifth of a six-part series, where Anna and Claire discuss the hidden risks of cybersecurity. In partnership with LastPass, Anna explains the hidden risks of partnering with merger and acquisition activity, commonly known as M&A. In today’s episode, Anna explores how M&A acts as a risk for organisations and how detrimental the consequences can be, providing multiple company examples.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
Michael Gorton AM, who is a senior partner at Russell Kennedy Lawyers and has more than 30 years of experience advising the health and medical sector, joins Anna in partnership with LastPass for this episode. Michael and Anna discuss a wide range of subjects, including his career progression and what led him to make the decision to transition from a commercial lawyer to working in the health industry, the importance of cyber for the health sector, Michael’s concerns around cyber as a board chair and board member, and much more.
Michael is the Chair of Alfred Health and Chair of Wellways Australia. He is a Board member of the Holmesglen Institute (TAFE), past Board member of Ambulance Victoria and is the former Chair of the Australian Health Practitioner Regulation Agency (AHPRA) and former Board member of the Australasian College for Emergency Medicine. He is a former Chair of the Victorian Equal Opportunity and Human Rights Commission. Michael has had a successful career to date advising industries on all aspects of commercial law, assisting boards of health organisations to understand their legal obligations for effective governance structures, and governance policies, and implementing risk management strategies.
Links:
Michael Gorton’s LinkedIn
LastPass LinkedIn
For the full episode transcript, please visit our website.
Most organisations are not prepared to respond to a third party experiencing a cyber event as we generally don't prepare to respond to incidents that are out of our control.
This week’s episode is the fourth of a six-part series, where Anna and Claire discuss the hidden risks of cybersecurity. In partnership with LastPass, Claire explains the hidden risks of partnering with third parties. In today’s episode, Claire explores how third parties act as a risk for organisations and how to manage this type of risk.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where we answer questions sent in by our audience.
This week Anna and Claire answer the questions ‘how does a business need to prepare for a cyber incident?’, ‘is on-premise safer than cloud?’, ‘are ransom payments covered by insurers?’, ‘should CEO KPIs include cyber?’, and many more.
Links:
LastPass LinkedIn
Episode 31 - more information around the risk of on-premise solutions and aging applications
Episode 8 - discussion about negotiation with cybercriminals
For the full episode transcript, please visit our website.
Shadow IT has been going on for decades and remains one of the most overlooked cyber threats.
This week’s episode is the third of a six-part series, where Anna and Claire discuss the hidden risks of cybersecurity. In partnership with LastPass, Anna explains the hidden risks of shadow IT. In today’s episode, Anna explores what shadow IT is, and the six elements of shadow IT that explain how it contributes to cyber risk.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
Culture can be incredibly powerful towards a shared purpose, and foster an organization's capacity to thrive.
This week’s episode is the second of a six-part series, where Anna and Claire discuss the hidden risks of cybersecurity. In partnership with LastPass, Claire explains the hidden risks of the security culture of organisations. In today’s episode, Claire explores the different types of security cultures, in particular, the culture of entrepreneurial spirit, the culture of complacency, and the positive security culture.
Links:
LastPass LinkedIn
Last week’s episode where Anna speaks about patching
For the full episode transcript, please visit our website.
So as a Board, are you getting enough visibility of the risk of aging applications?
This week’s episode is the first of a six-part series, where Anna and Claire discuss the hidden risks of cybersecurity. In partnership with LastPass, Anna explains the hidden risk of aging applications. In today’s episode, Anna explores the three areas to consider in the hidden risks of aging applications.
Links:
LastPass LinkedIn
For the full episode transcript, please visit our website.
This week's episode is a part of the 'In case you missed it' series. The topic of today's podcast is taking a companywide approach to cybersecurity. Presented by Anna, this curated episode brings together IT leaders and board directors to discuss how cyber is an enterprise risk that needs to be owned by the entire business. This episode explores how technical boards need to be, and also covers the evolving legislative requirements in relation to cyber.
For the full episode transcript, please visit our website.
This week’s episode follows a different format from previous episodes. When Anna and Claire launched their book, The Secure Board, in 2021, they were fortunate to speak with Paul Rehder, managing partner from Deloitte, about how the book came about and their passion for uplifting confidence and cyber literacy for directors. This week is a repost of that conversation, in which Paul Rehder is behind the host mic.
Paul's extensive financial services experience running a broad range of strategy, business architecture and delivery programs and initiatives in Australia and abroad, as well as being a trusted advisor to both executive and non-executive directors, seems fitting as he hosts this episode of In Pursuit of The Secure Board podcast discussing with Claire and Anna 'The Secure Board'.
Links:
Paul LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the second of the 'In case you missed it' series. The topic of today's podcast is cyber security culture. Presented by Claire, this curated episode brings together cyber professionals, experts, and directors to share the importance of making security part of how companies make decisions and grow as an organisation.
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where we answer questions sent in by our audience.
This week we answer the questions ‘is IT responsible for the recovery efforts after a cyber event?’, ‘what can directors do as a board or through management to help understand the options when it comes to cybersecurity investments?’, ‘how often should directors be seeking or receiving education training on cyber risk?’, and many more.
For the full episode transcript, please visit our website.
Rhoda Phillippo, a globally experienced executive with more than 35 years of experience in the telecommunications, energy, and IT sectors, joins Anna in this episode to discuss a wide range of subjects, including her career progression and what led her to make the decision to transition from a corporate career to sitting on boards, the impact of the amendments to the critical infrastructure bill on organisations, and as a board director, how should one approach meeting their responsibilities in relation to cyber.
Rhoda holds an MSc in Telecommunications Engineering and Business Management from University College London, where she was awarded the Founders Prize for best academic dissertation and the Masters Challenge Prize for leadership. She is a Graduate Member of the Australian and New Zealand Institute of Company Directors. While having a passion for running marathons and triathlons, Rhoda is currently a Non Executive Director of APA where she is a member of the Remuneration and People and WHS Committees, a Non Executive Director of Pacific Hydro, Chair of Kinetic IT, and is an Advisor to the Board of the Tally Group.
Links:
Rhoda Phillippo's LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the first of a new series titled 'In case you missed it.' The topic of today's podcast is being prepared for a cyber incident. Presented by Anna, this curated episode brings together cyber professionals, experts, and directors to share the importance of being prepared for a cyber event, the role that the board plays in incident planning, and what we can learn from others.
For the full episode transcript, please visit our website.
Links:
Episode 1: How can I gain confidence that we are executing an effective Incident Response Plan?
Kelly Butler, Managing Director and Cyber Practice Leader Pacific at Marsh and McLennan Companies, joins Claire in this episode to break down cyber insurance today and help listeners develop an understanding of what the value of working with a specialised broker is, the recognition that buying cyber insurance can be quite a minefield and the top five things that you should be considering in a policy, including understanding and assessing your own risk before considering buying a policy.
Kelly oversees client advisory and placement services for Cyber and Technology risk throughout the region. In addition, Kelly serves as the senior cyber risk advisor for some of Marsh’s largest clients and sits on the Marsh global Cyber board. Kelly joined Marsh in 2016 to build Marsh’s Cyber practice and has over 21 years insurance experience gained in Australia, New Zealand, and the UK, with the last 10 years spent designing Cyber and financial lines insurance programs for large corporate and publicly listed clients. Kelly is an industry leader in cyber, educating insurers, clients, and brokers on business risks and customising coverage to manage specific challenges across all industry verticals. She was recently named the Advisen’s 2021 Cyber Risk Industry Person of the Year APAC category.
Links:
Kelly Butler's LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the final episode of a three-part series that will explain the difference between various cyber-related topics.
This week Dr. Catherine Lopes, one of the top 25 analytics leaders in Australia, talks about the differences between data governance and cyber, and the critical role that they play together. Dr. Catherine Lopes is a strategist and thought leader with 20+ years of experience in data, analytics, Data Science, and AI. Her recent focus is on helping organizations uplift business performance by developing data analytics strategy, building broad range analytics use cases including machine learning and AI, and establishing data analytics capability and culture through a governed enterprise data management framework and process. Additionally, Catherine serves on multiple advisory boards and is an entrepreneur in data analytics and AI. She founded Ada’s Tribe, an Australian-based community supporting women in analytics, Data Science and AI.
In this episode, Catherine explains the basic concept of data governance, the different roles and responsibilities within data governance, and why data governance is related and essential to cyber security.
Links:
Dr. Catherine Lopes' LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the second episode of a three-part series that will explain the difference between various cyber-related topics.
This week Claire talks about the difference between privacy and cyber, and how the two are closely related. She explains that the difference between privacy and cyber comes down to who and what data is being protected from.
For the full episode transcript, please visit our website.
This week's episode is the first episode of a three-part series that will explain the difference between various cyber-related topics.
This week Anna talks about the difference between terms that are often used in relation to business continuity and cyber. She thoroughly explains the difference between BCP, which is business continuity plan, and disaster recovery, which is often referred to as DR, and discusses how both of those terms and plans relate to cyber.
For the full episode transcript, please visit our website.
Megan Haas, an experienced business adviser to boards and executives, joins Claire in this episode to discuss the diversity of the cyber conversations that happen across industries, the security law reforms for critical infrastructure, and if cyber decision making is left to her, given her expertise, when the boardroom conversation starts to talk about cyber.
Megan is a non-executive director of a portfolio of organisations spanning public sector, higher education, and ASX listed companies. Her core competencies are centred around cyber risk governance, technology, and operational process, which she developed over 30 years in Australia and internationally. Formerly a PWC cybersecurity and forensics partner, Megan is passionate about developing future leaders through organisations such as the Women's Foundation in Hong Kong, the Women's Leadership Initiative, which is focused on the Pacific Islands, and the Australian women in the security network.
Links:
Megan Haas' LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the final episode of a three-part series around cyber insurance.
This week Anna and Claire talk about the shifting cyber insurance landscape. In this episode, Anna and Claire emphasise the importance of understanding how the landscape is shifting , primarily for organisations with an insurance policy in place or if you are planning to apply for cyber insurance, and how these changes are impacting businesses.
For the full episode transcript, please visit our website.
Sonya Beyers, director of Governance by Design, joins Anna in this episode to discuss the role of the CEO when setting cyber performance measures, the current thinking around having IT skills on boards, whether boards and CEOs have a line of sight to hidden risks around cyber, and much more.
Through her consultancy and advisory business, Sonya Beyers assists boards to evaluate governance and organisational legal frameworks to redefine the relationship between the director and the board and foster leadership from the boardroom. She also leverages her expertise as a qualified solicitor and experience across corporate and non-profit sectors to help directors gain focus, troubleshoot a range of issues and optimise organisational performance. Sonya sits on the boards of All About Living Limited, Affordable Housing Solutions Limited, and The Forde Foundation. She is an accredited facilitator and Fellow of the Australian Institute of Company Directors, Fellow of the Governance Institute of Australia, and has obtained IDP-C from INSEAD.
Links:
Sonya Beyer's LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the second of a three-part series around cyber insurance.
This week Anna and Claire talk about cyber insurance as a risk management strategy, and the risks associated with taking this approach. They reflect on two important questions; Are we overly reliant on our cyber insurance policy? and is the insurance policy our only strategy?
Links:
Episode 9
For the full episode transcript, please visit our website.
Marcus Thompson, appointed chair of Penten and board member of Engineers Australia, joins Claire in this episode to discuss the current state of cyber in Australia, the importance of cyberculture conversations at the boardroom table, and the impact of the changing legislative landscape in relation to cyber in Australia.
Marcus is a retired Major General who served 34 years in the Australian Army. He served in a variety of command, regimental and special operations appointments, as well as deployments to East Timor, Iraq and Afghanistan. His final appointment was the inaugural head of information warfare for the Australian Defence Force. Marcus holds multiple qualifications including bachelor's degrees, masters and a PhD in cyber, and in 2014, was appointed a member of the Order of Australia in the Queen's Birthday Honours List. Since leaving the Army, Marcus has founded cyber compass, an independent advisory company focused on improving cybersecurity and developing sovereign Australian capability.
Links:
Marcus Thompson's LinkedIn
For the full episode transcript, please visit our website.
This week's episode is the first of a three-part series around cyber insurance.
This week Anna and Claire answer two of the most common questions from boards - should we pay the ransom and will cyber insurance keep us cyber safe? Narrowing down the topic of cyber insurance, episode one of the three-part series thoroughly explores and discusses how insurance may influence your response to a cyber event.
For the full episode transcript, please visit our website.
Dr. Alana Maurushat, professor of cybersecurity and behaviour at Western Sydney University, joins Anna in this episode to discuss her upcoming Cyber Incident Response centre, her research on the topic of cyber, the fear and complexity around jargon associated with cyber, and the impact of COVID-19 on the number of cyber incidents. Dr. Alana Maurushat is currently researching payment diversion fraud and ransomware, tracking money laundering through Bitcoin blenders, distributed extreme edge computing for micro-clustered satellites, and ethical hacking. She is the cyber ambassador for the New South Wales cybersecurity network. And Alana is also on the board of directors for the Cybercrime investigation company called IFW Global. She lectures and researches cybersecurity, privacy, and security by design, cyber risk management, and artificial intelligence across the disciplines of law, criminology, business, political science, and information communication technology.
Links:
Dr. Alana Maurushat LinkedIn
For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where we answer questions sent in by our audience.
This week we answer 'what do other directors do with all their old board papers?', 'what role do business executives play in incident response?', 'are manual processes the only way to ensure that a business can continue to operate when a critical third party is impacted by a cyber event?', and many more.
For the full episode transcript, please visit our website.
Unpacking the topic of Risk Appetite Statements, this week Anna discusses the importance of understanding how management will use the risk appetite statements to make decisions, whether some of the risk appetites actually may conflict, and once a risk is within appetite, how does the board have confidence that decisions will not be made, which could contribute to the risk being outside of appetite again. For the full episode transcript, please visit our website.
This week's episode is an 'Ask Me Anything' where we answer questions sent in by our audience.
This week we answer 'do I need to know the different types of cyber incidents and threats?', 'what the role is for the CEO in relation to cybersecurity?', 'if the board is hearing from the CIO, does that mean that the cybersecurity problems are being solved by tech?', and many more.
Links:
Episode 8 - Clyde & Co
First episode
For the full episode transcript, please visit our website.
Lynwen Connick, the Chief Information Security Officer of ANZ Bank in Australia, joins Claire in this episode to discuss board metrics, the role of the CISO, security versus compliance in a heavily regulated sector, and the introduction of banking into the list of industries recognised as critical infrastructure here in Australia.
As the Global Chief Information Security Officer at ANZ, Lynwen drives the enterprise information security strategy to ensure it evolves with the changing cyber security threat and technology landscape and enables the bank’s digital transformation. Lynwen is also responsible for Cyber Security Operations– (both detection and protection capabilities), information protection services, security advisory services, security architecture, security policy and standards and ANZ’s security education program. Prior to joining ANZ five years ago, Lynwen worked across a number of Australian government departments, including the Australian Signals Directorate and the Department of Prime Minister and Cabinet.
Links:
Lynwen Connick LinkedIn
For the full episode transcript, please visit our website.
For directors asking the question of what is going to be different once the cybersecurity strategy is delivered, you must be prepared for the answer.
This week Anna and Claire discuss and share, to answer the question 'What will be different when a cybersecurity strategy is implemented?'.
For the full episode transcript, please visit our website.
John Moran and Reece Corbett-Wilkins, two great leaders of global law firm Clyde & Co, join Claire in this episode to discuss preparation for incidents, some of the misconceptions about cyber attacks, and how they play out, and the value of cyber insurance.
John is a recognised expert in the cyber risk and incident response space, leading one of the largest, dedicated cyber incident response teams in Australia and New Zealand. His team have advised on over 1,500 cyber incidents in recent times, including some of the most high profile and complex incidents, both locally and globally.
Reece is a leading member of Clyde & Co's cyber incident response team and has experience acting in a range of local, regional, and global incidents affecting government agencies and private sector organisations of all sizes, operating across all industry sectors. Acting as 'breach coach', Reece is well regarded for his ability to advise boards and other senior members in the executive, legal, IT, risk management and public relations functions to navigate their strategic response to Australia’s complex cyber landscape.
Links:
John Moran LinkedIn
Reece Corbett-Wilkins LinkedIn
Clyde & Co LinkedIn
For the full episode transcript please visit our website.
This week's episode is an 'Ask Me Anything' where we answer questions sent in by our audience.
This week we answer 'should a small business, who doesn't collect personal data about their customers, be concerned about cyber?', 'what is NIST?', 'should an organisation pay the ransom?', and many more.
For the full episode transcript, please visit our website.
Debbie Goodin is an experienced non-executive director and Chairman of Boards and Audit and Risk Committees. Debbie joins Anna in this episode to discuss the topic of cyber risk management.
Through her portfolio of companies, two of which will be subject to the SOCI Act, Debbie has significant exposure to the risk associated with cyber security. She is currently the Chairman of Atlas Arteria Limited the owner and operator of toll roads in Europe and the US; is the Chairman of Audit and Risk for APA Group - Australia’s largest owner of gas pipelines and producer of gas-fired and renewable energy; and is the Chairman of Audit and Risk for Australian Pacific Airports Corporation, the owner and operator of Melbourne and Launceston Airports. Prior to this Debbie has been the Chairman of Audit and Risk in a range of sectors including oil and gas, television and media, healthcare and water.
Links:
Debbie LinkedIn
For the full episode transcript please visit our website.
To address and govern cyber risk, the first step is to understand it.
This week Anna and Claire discuss and share, to answer the question 'Are you aware of the hidden cyber risks in your business?'.
For the full episode transcript, please visit our website.
Alastair MacGibbon is Australia’s most recognised cyber security leader, and is the Chief Strategy Officer at CyberCX. Alastair joins Claire in this episode to discuss the role of directors in cybersecurity governance.
Alastair's leadership experience includes serving in senior cyber roles across government, as National Cyber Security Adviser, head of the Australian Cyber Security Centre and Special Adviser to the Prime Minister on Cyber Security, as well as serving as Australia’s inaugural eSafety Commissioner. Alastair has also held senior roles across the private sector, including head of eBay’s Asia Pacific Trust & Safety operations, and previously served in the Australian Federal Police for 15 years.
For the full episode transcript please visit our website.
This week’s episode is an 'Ask Me Anything' where we answer questions sent in by our audience.
This week we answer 'how much cyber is too much?', 'what is the role of a CISO?', how to prepare your board for a cyber incident, and many more.
For the full episode transcript, please see our website
It’s not just the knowledge of threats and risks the organisation could face that’s keeping your cyber leader up at night.
This week Anna and Claire discuss and share, to answer the question ‘What’s keeping your cyber leader awake at night?’.
For full episode transcript, please visit our website
Cybersecurity is a critical business issue that must be a priority for every organisation. This week Anna and Claire discuss and share, to answer the question 'How can I gain confidence that we are executing an effective Incident Response Plan?'
For the full episode transcript, please visit our website
Welcome to In Pursuit of The Secure Board with Claire Pales and Anna Leibel.
We are both passionate about building knowledge and confidence in the topic of cyber security. The natural progression from our book ‘The Secure Board’ is an ongoing conversation with you on this increasingly important topic. Together we have a combined 50 years experience as experts in cyber, digital, IT risk management and fiduciary obligations.
Join us, together with business leaders, as we remove the complexity of cyber risk management and learn from others In Pursuit of The Secure Board.