
Free Daily Podcast Summary
by Australian Information Security Association (AISA)
Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.
The most recent episodes — sign up to get AI-powered summaries of each one.
Threat actors are already using large language models to accelerate the early stages of a compromise. Josh Lemon wanted to know what the same tools could do for the responders on the other side.Recorded at AdelaideSEC 2026, David Savva-Willett speaks with Josh Lemon, Chief of Digital Forensics and Incident Response at SoteriaSec and a SANS principal instructor, immediately after his talk on that question. Josh has been putting the major models in front of forensic evidence for years, and reports real movement: where they once sent an inexperienced analyst off in entirely the wrong direction, they now answer factual questions reliably. What they still lack is the creativity to ask why something is wrong, or what a threat actor is likely to do next.The discussion ranges across where LLMs are genuinely saving hours in a SOC, from one off Python tooling to threat intelligence summaries to executive status updates; a response Josh received that read unmistakably like vendor advertising; why he warns his students that an AI written report may one day be read by an expert witness in court; how MCP servers are being folded into SANS forensics classes; and whether any of this helps with the on call burden and burnout that have dogged the profession for years.It closes on the exchange every responder knows by heart, where no evidence of exfiltration gets heard as no exfiltration, and Josh's observation about what a model eager to please would say if a lawyer asked it the same question.
Most organisations still treat AI agents as software. Their staff do not. Agents are being used as colleagues, confidants and co-developers; they are being handed access to multiple systems, and a good number of them belong to proof-of-concept projects that quietly ended without anyone shutting off the credentials.Recorded at AdelaideSEC, David Savva-Willett speaks with Sharon Hunneybell, VP of Products at FirstWave, ahead of her talk on a governance framework for AI agents as workers. Sharon describes realising midway through writing that framework that she had missed a step, and that discovery has to come before onboarding, because these things arrive in the workplace unannounced and increasingly as features inside software that is already approved.The conversation covers where accountability sits when an agent acts, why access should be task-based and time-limited rather than granted to one broad agent, how far traditional HR frameworks actually translate, and what Sharon expects from regulation over the coming months. It closes on her practical checklist: give every agent its own identity, log what it does, scope its access to a single task, review it on a schedule, and know how to offboard it before you build it.
Quantum computers will one day break the cryptography that protects almost everything online. The harder questions are how much of the alarm is warranted, and what security leaders should be doing now.David Savva-Willett is joined by Geoff Schomburgk, Regional Vice President for Asia Pacific and Japan at Yubico, and Alex Wilson, who leads solutions engineering for the region. They unpack harvest now, decrypt later and how much of it is a device for grabbing attention; what it took to get post-quantum algorithms running on the secure element inside a YubiKey; and why crypto agility, not any single algorithm, is the thing to design for.The conversation turns to authentication, where passkeys are becoming the root of trust for digital wallets, mobile driver licences and financial transactions, and to the difference between device bound and copyable passkeys that many organisations have not thought through. Both guests make the case that this is a project management and governance problem rather than a technology one, and that the apocalyptic framing does more harm than good.
Recorded live at AISA SydneySec 2026, host David Savva-Willett is joined by Christine Ferguson, Inclusion Specialist Lead in DXC Technology's Social Impact Practice, where she leads the DXC Dandelion Program. Since 2014 the program has supported over 350 neurodivergent people into sustainable technology and cyber security careers across Australia, Europe, Asia and now the Middle East.Christine had just come off stage with her SydneySec session Neurodiversity in Cyber: People, Pressure and Performance, and the conversation follows the same three threads. What neurodivergent professionals bring to a cyber team that routinely gets overlooked. What pressure and masking actually feel like from the inside, and why an escalating manager and an escalating analyst never produce a good outcome. And what genuinely changes for a team, not just an individual, when a workplace gets the accommodations right.Christine speaks openly about her own dyslexia and about wearing the Hidden Disabilities Sunflower lanyard at the conference so that people could see an invisible disability made visible. She closes with the one small change she would ask of any leader listening, which turns out to cost nothing at all.Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.
Recorded live at AISA SydneySec 2026, host David Savva-Willett sits down with Nakshathra Suresh, a cyber criminologist and one of very few people in Australia bringing a social science lens to artificial intelligence and emerging technology safety.Nakshathra is co-founder of eiris, a safety technology consultancy, Oceania Youth Ambassador for the Internet Society, and teaches with the Faculty of Law and Justice at UNSW where she created the university's first criminology backed cyber security course.The conversation covers what a cyber criminologist actually does and why the discipline is still so young, how generative AI has turned catfishing and cyberstalking into something that runs itself once a public profile is scraped, the long tail of harm for victim survivors who end up retiring their online lives entirely, and why human centred resilience is a question of culture and conduct rather than another vulnerability to patch. Nakshathra also makes a direct case about who is missing from the room when security decisions get made.Content note: this episode includes discussion of cyberstalking, technology facilitated abuse, image based abuse and harm to children in online environments. If anything here raises something for you, support is available. 1800RESPECT on 1800 737 732 or Lifeline on 13 11 14, and image based abuse can be reported to the eSafety Commissioner at esafety.gov.au.Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.
Cybercrime is not a lone hacker in a hoodie any more. It is an economy, and by some estimates a staggeringly large one. In this episode of Cyber Voices, host David Savva-Willett flips the usual script and asks not how we defend, but how we fight back.Glenn Maiden is Chief Security Officer for Fortinet Australia and Director of Threat Intelligence at FortiGuard Labs for Australia and New Zealand. He spent years in Defence and the Australian Intelligence Community working in geospatial and human terrain intelligence, including during Operation Slipper, before moving into commercial threat intelligence. He established the team behind the World Economic Forum's Cybercrime Atlas and, most recently, helped create a first of its kind cybercrime bounty program with Crime Stoppers International.The conversation covers how mapping tribal structures, community leaders and wells in a conflict zone translates to mapping the humans behind ransomware crews, why our industry has become excellent at indicators of compromise and knows almost nothing about the actual people, and what the Cybercrime Atlas found when it started pulling names, aliases, bank accounts, crypto wallets and bulletproof hosting together into targeting packages for Interpol, Europol and the FBI.David and Glenn also dig into why better defence alone was never going to be enough, the gap that sits on the people and process side rather than the technology side, and the unreported soft underbelly of an economy built on small and medium business. Glenn explains how the new bounty program works, how someone with intelligence on a threat actor can submit an anonymous tip and potentially collect a reward when that person is arrested and prosecuted, and why the same infrastructure mapping may help pull far worse criminals off the streets.There is a human side too. Glenn talks about the young man in Eastern Europe committing cybercrime to get his family out, the scam compounds operating a couple of hours to Australia's north, and his own experience of being scammed through Facebook Marketplace. He explains why he tells that story publicly and how shame keeps victims silent.Glenn closes with practical advice for CISOs, SOC leads and analysts who will never run a takedown themselves.Content note: this episode includes brief references to human trafficking, forced labour in scam centres and child exploitation material in the context of organised crime.Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.
On this episode of Cyber Voices, host David Savva-Willett is at the tail end of Canberra CyberConnect 2026, AISA's first ever event in the nation's capital, sitting down with a guest who has one of the best job titles in Australian cyber.Ant Cohen is Head of Security Influence and Trust at nbn. Before cyber, he built some of the most recognisable marketing campaigns this country has seen, from Oprah's Australian adventure to 25 Wallabies campervans touring New Zealand during the Rugby World Cup to a gold medal winning campaign for the Australian Olympic and Paralympic teams in London. He now brings that storytelling firepower to human centred cyber defence, and sits on a NSW Crime Stoppers advisory committee.David and Ant get into why security awareness has a well earned reputation for being boring and occasionally condescending, and Ant's diagnosis of the problem: an oversupply of supply. The industry has indulged in training, drills and metrics reporting without ever building the demand.The idea that stops David in his tracks is the do nothing cohort. Security teams obsess over the people who click and celebrate the people who report, but the largest group by far is the people who open the simulation, leave it sitting in the inbox and take no action at all. Ant explains why the time of day, the device and the out of office setting tell you far more about your culture than a click rate ever will, and why he is a believer in small data over big data.The conversation also covers whether phishing simulations remain tenable after a decade of use, the difference between decisions made cold and decisions made in the heat of the moment, closing the loop so people know a human actually reads what they report, and the scale of nbn's responsibility given the proportion of Australia's daily data traffic that crosses the network. Ant's team of four works alongside nbn Local to reach regional and rural communities, libraries and the Country Women's Association with scams education aimed squarely at the Australians most often targeted.And his one thing for cyber leaders heading back to work on Monday: learn your audience, and learn the language they actually speak.Recorded live at Canberra CyberConnect 2026.
Every playbook and SOP you have ever written assumes it will be picked up by a calm, fully regulated human. My guest this episode reckons that assumption is exactly where incident response quietly falls apart.Recorded live at AISA's inaugural CyberConnect Canberra 2026 at the Hotel Realm, David Savva-Willett sat down with Darren Fleming, peak performance strategist, author, and the man better known as That Mindfulness Bloke. Darren represented Australia in elite sailing, studied psychology and philosophy at Oxford, has written seven books on communication, leadership and mindset, sat in complete silence for ten days, and spent more than twenty years coaching global organisations including Caterpillar, Cisco, BHP and Rio Tinto on how to perform under pressure.His CyberConnect talk, The Human Firewall, covers the thing no runbook touches: what actually happens to a responder's brain in the first hours of a Sev1.They get into why the nervous system, not the playbook, makes the decision. How adrenaline and cortisol cut off access to long term memory, and why "it made sense at the time" is a physiological answer rather than an excuse. The difference between situational awareness, stretched awareness and tunnel vision, and why "I just didn't see it" keeps turning up in the debrief. Why incident teams start turning on each other under pressure, and why that is the body working exactly as designed rather than a culture problem. What ten days of Vipassana taught Darren that a psychology degree could not. The collapse of the average attention span from roughly two and a half minutes to under a minute in twenty years. How a SANFL club lifted its win rate by changing what three senior players did during the half time break. And the one technique Darren would hand a CISO heading into a tabletop next week.Find out more about Darren's work at thatmindfulnessbloke.comCyber Voices is the official podcast of the Australian Information Security Association. Subscribe wherever you get your podcasts and leave us a five star rating, it genuinely helps others find the show. Learn more about AISA or become a member at aisa.org.au
Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.
AI-powered recaps with compact key takeaways, quotes, and insights.
Get key takeaways from Cyber Voices in a 5-minute read.
Stay current on your favorite podcasts without falling behind.
It's a free AI-powered email that summarizes new episodes of Cyber Voices as soon as they're published. You get the key takeaways, notable quotes, and links & mentions — all in a quick read.
When a new episode drops, our AI transcribes and analyzes it, then generates a personalized summary tailored to your interests and profession. It's delivered to your inbox every morning.
No. Podzilla is an independent service that summarizes publicly available podcast content. We're not affiliated with or endorsed by Australian Information Security Association (AISA).
Absolutely! The free plan covers up to 3 podcasts. Upgrade to Pro for 15, or Premium for 50. Browse our full catalog at /podcasts.
Cyber Voices publishes weekly. Our AI generates a summary within hours of each new episode.
Cyber Voices covers topics including Technology. Our AI identifies the specific themes in each episode and highlights what matters most to you.
Free forever for up to 3 podcasts. No credit card required.
Free forever for up to 3 podcasts. No credit card required.