Summit Speakers



Ryan Saunders, Chief Information Security Officer, RMIT University

As Chief Information Security Officer at RMIT University, Ryan leads the protection of the institution’s digital infrastructure, safeguarding the trust of our staff, students, alumni and industry partners. With over three years in this role and more than 18 years’ experience in information security and risk, Ryan brings deep expertise in Identity and Access Management programme management, cyber strategy development, auditing, IT security assessments, and people leadership to drive robust security operations and compliance. 

Ryan’s work focuses on embedding secure-by-design practices, modernising security capabilities and building high-performing, multidisciplinary teams. Ryan is committed to growing a diverse cyber workforce through internship programmes and strategic partnerships, ensuring our approaches align with regulatory obligations and organisational priorities. Guided by a pragmatic balance of cost and risk, Ryan aims to deliver security outcomes that not only protect the university but also enable innovation and continuous improvement. 



Craig Costello, Professor of Computer Science, Queensland University of Technology

Craig Costello is a Professor of Computer Science at QUT and one of Australia's leading experts in post-quantum cryptography. After completing his PhD in mathematics at QUT, he held research positions in Europe and the United States before spending more than 12 years at Microsoft Research in Seattle, where he became a Principal Researcher.

Craig's research focuses on the cryptographic technologies that secure the internet, with a particular emphasis on preparing for the security challenges posed by quantum computers. His work has influenced international cryptographic standards and has been deployed in real-world systems worldwide.

Today, Craig leads research at QUT on post-quantum cryptography, quantum cryptanalysis, and advanced privacy technologies. He is passionate about helping organisations understand the opportunities and risks emerging at the intersection of cybersecurity, quantum computing, and artificial intelligence.



Fiona Collie, Cyber Awareness and Outreach Manager, Monash University

In her role, Fiona leads initiatives focused on improving cybersecurity culture and awareness across the university community.  In addition, Fiona is part of the Security, Information and Trust planning group and is a committee member for the national Cross Link project to optimise and streamline solutions for data linkage in clinical registries.



Ui Cheng Loh, The University of Queensland

Ui Cheng Loh is a Senior Cybersecurity Trainer with a proven track record of designing and delivering impactful training programs. Focused on practical, real-world learning, she helps professionals build essential skills and confidence, while making sure no one dozes off, thanks to a well-timed quiz.



Emily Woodhams, Cybersecurity Engagement Manager, University of Melbourne

Emily leads the development and delivery of a university‑wide cybersecurity engagement and awareness program, focused on driving positive security behaviours across staff, students, contractors, and partners. Emily is responsible for shaping cybersecurity communication strategies, delivering targeted engagement initiatives, fostering a strong cybersecurity culture across a diverse community and ensuring alignment with the University’s risk management, policy, and compliance frameworks. Through strategic engagement and clear communication, Emily helps strengthen the University’s resilience to cyber threats.



Brendan Walker-Munro, Associate Professor (Law), Faculty of Business & the Arts, Southern Cross University

 Brendan's focus is on "research security", the use of law and policy to protect university research from national security threats such as espionage, foreign interference, hacking, and technology transfer. He also researches other aspects at the intersection of national security law and higher education, such as research funding, privacy, and digital security.



Mandy Turner, Adjunct Lecturer in Cyber Criminology, The University of Queensland

A multi-award-winning cyber security and cybercrime specialist, author, artist, and senior cybersecurity leader with extensive experience in cyber security strategy, cybercrime intelligence, and security operations. Mandy has led whole of business cyber security programmes and focuses on understanding threat actor behaviours and motivations to develop flexible approaches to emerging threats. She has authored books on cybercrime, writes a regular column for Women in Security Magazine, and actively mentors and supports those entering or developing skills in cybersecurity to help future-proof the industry.  Mandy is a passionate advocate for diversity in all its form knowing it not only supports inclusion, but also drives innovation, enabling stronger solutions to the complex challenges facing our world. 



Simon Pengilly, Chair, INFIN (Informal Foreign Interference Network)

Simon Pengilly is the Chair of INFIN (Informal National Foreign Interference Network), which is a member-based organisation for practitioners working on counter-foreign interference and research security in the Australian university and research sector. In his day job Simon manages national security compliance at The University of Queensland and is UQ's Primary Security Officer for the DISP. He works closely with UQ’s cybersecurity team to deliver research security solutions for defence and other sensitive research. Prior to UQ Simon had a thirteen year career with the Department of Home Affairs, which included postings to China, South Korea and Japan. He recently completed a Graduate Certificate in Cybersecurity at UQ and is interested in the intersection of research security and cybersecurity. 



Rachel Mansson, Associate Director, Cybersecurity Threat Intelligence, Deakin University

An accomplished cyber security leader, Rachel brings a unique blend of intelligence‑led defence and human‑centric security, with a strong track record across risk management, behaviour change, and culture uplift. From delivering actionable threat insights to shaping security awareness and behaviour programs, Rachel is passionate about empowering people and organisations to navigate an increasingly complex cyber landscape with confidence. Her career spans diverse initiatives across cyber security, research, student learning, infrastructure, and digital networks, giving her a broad perspective on managing risk in complex environments. Rachel is a strong advocate for practical, people‑focused security that drives real‑world outcomes and sustainable resilience.



Simon Moss, University Professor and Organisational Psychologist, Monash University

Simon Moss is a university professor and organisational psychologist.  He has published 10 books and over 120 scientific papers, primarily on how the policies and practices of organisations and governments affect the wellbeing, productivity, and integrity of individuals.  For example, he is the author of “The negative side of positive thinking”, “Where should I work”, and “Emotional Intelligence: Journey to the Source”.  More recently, he founded radical humility: a movement that helps researchers, practitioners, leaders, and the general public nullify the adverse impacts of narcissism on workplaces and society.



Raj Udayanga, Cyber Security Operations, Monash University

Raj leads the Cyber Security Operation Center (C-SOC), overseeing disciplines such as cyber security engineering, cyber threat intelligence and vulnerability management, security automation, and cyber defence and response.



Sophia Moss, Project Manager

Sophia Moss is an experienced project manager, research manager, and operations manager.  In Australia, she has assumed leadership and management positions in many sectors, including the Northern Territory Government, Australian Universities, and the emergency services.  In the United States, she managed IT projects and community projects with many large organisations, including City University of Seattle, University of Washington, Amazon, and Microsoft.  



Jack Cross, Chief Information Officer, Queensland University of Technology

Jack is responsible for leading the university's cyber security strategy, governance, risk management, and resilience programs. Prior to joining QUT, Jack held roles across Defence and the national security community, working alongside law enforcement, intelligence, and cyber security organisations to address complex security challenges.

Jack has extensive experience in incident response, cyber resilience, security transformation, and executive governance. He led QUT's response to a significant ransomware incident and has since focused on strengthening organisational resilience, cyber governance, and security culture across the institution. He is an active contributor to the Australian higher education cyber security community, regularly sharing lessons learned and collaborating with peers to improve the sector's collective cyber maturity.

Jack is passionate about aligning security outcomes with organisational objectives and helping leaders make informed, risk-based decisions in an increasingly complex threat environment.



Mona Taylor, Manager Digital Research Infrastructure, University of Tasmania

Mona Taylor is the Manager Digital Research Infrastructure and Cyber Security at University of Tasmania. Mona’s session will articulate why and how University of Tasmania treats research cyber security as a distinct but aligned program to corporate cyber security. This session will share the University of Tasmania’s wins and challenges in separating research and corporate cyber programs, providing other universities with actionable lessons to inform their future program development.



Nicole Henry, Head of Government Affairs, Australia and New Zealand, Fortinet 

Nicole brings more than 20 years of senior experience across science, industry, and international policy. Nicole has led national and bilateral initiatives on clean energy, digital trade, and research commercialisation, with a focus on technology policy, infrastructure security, and standards development.

At Fortinet, Nicole leads engagement across government, industry, and academia on cybersecurity, critical infrastructure, and digital trust. She works across the organisation to align external engagement with national priorities and sector expectations. Her role helps position Fortinet as a trusted partner in secure digital transformation, trusted technology adoption, and national resilience.

Before joining Fortinet, Nicole held senior executive roles within the Department of Industry, Science and Resources. She was responsible for leading international strategy and national security engagement across the Trade, Americas,

Europe, and India branch, developing strategic relationships and opportunities aligned with the Australian Government’s priorities. Nicole also served as the Department’s inaugural industry Counsellor to Indonesia, based in Jakarta, where she drove collaboration on bilateral industrial priorities, regional supply chains, and environmental, social, and governance initiatives.

Prior to this, Nicole was the senior executive for business engagement and program management for the Simplified Trade System Implementation Taskforce. She led strategic engagement across government and industry to drive support for Australia’s cross-border trade reforms.

As an executive strategist, Nicole operates at the intersection of digital security, sovereign capability, and strategic partnerships, bringing a forward-thinking perspective to national technology challenges.



Jason Ha, Supply Chain Cyber Assurance Specialist, MyCISO

Jason is an experienced security leader with more than 25 years of experience helping organisations strengthen security, manage risk, and make informed decisions. He has led national security risk practices, served as Chief Information Security Officer at Ethan Global, and advised organisations across the public and private sectors. Known for his practical, risk-based approach, Jason helps organisations focus on initiatives that deliver the greatest value. At MyCISO, he works closely with customers to simplify risk management, strengthen security programs, and build practical, sustainable solutions that support organisational goals while enabling confident decision-making.



Brad McGrath, Principal Consultant Information Security Governance, Risk and Compliance, Queensland University of Technology

Brad leads strategic governance, risk, assurance and compliance activities across the University's information security program, providing advice to executive stakeholders on cyber risk, regulatory obligations and organisational resilience. Brad's work focuses on security governance, third-party risk management, assurance, audit, data protection and the implementation of risk-based security practices across complex university environments. He is an active contributor to sector collaboration through CAUDIT and other higher education cybersecurity forums, with a particular interest in strengthening pragmatic governance approaches that improve security outcomes while enabling teaching, research and business operations.



Mario Morella, Director, National Office of Cybersecurity

Mario leads the Preparedness Government Section, responsible for delivering collaborative programs designed to uplift cyber incident preparedness across Australian Government departments and agencies, as well as state and territory entities. The section administers the National Cyber Exercise Program and co-delivers the National Office of Cyber Security Exercise Program, both of which are key deliverables under the 2023-2030 Australian Cyber Security Strategy. Prior to this appointment, Mario served as Executive Officer to the Secretary of the Department of Home Affairs.

With more than eight years of experience in national security, Mario has worked across operational and strategic roles spanning counter-terrorism, critical infrastructure security, and cyber security. He has worked across several government portfolios, including the Department of Home Affairs, the Department of the Prime Minister and Cabinet, the Department of Defence, and the Australian Border Force.



James Price, Cybersecurity Advisor, Cyber Resilience Unit, National Cyber Security Centre (NCSC)

James helps enhance resilience and maturity across critical infrastructure. As part of a broader range of services, James delivers threat briefings, shares information on emerging threats and trends, facilitates tabletop exercises and offers guidance and advice to strengthen cybersecurity posture. James also chairs Security Information Exchanges with industry leaders to foster collaboration and improve sector-wide cybersecurity resilience. With a diverse background in military service, international work and volunteering, James focuses on leadership, strategic planning, and problem-solving. He is committed to driving meaningful outcomes through collaboration, innovation, and dedication to continuous improvement.



Matt Dawson, Senior Solutions Engineer, Okta

Based in Sydney, with more than eight years' experience across identity, security, cloud architecture and enterprise technology, James works with large organisations across Australia and New Zealand to modernise how they secure workforce, customer and non-human identities.

His experience spans identity and access management, identity governance, privileged access and emerging approaches to securing AI agents. Matt's focus is on connecting security architecture to practical outcomes - reducing breach risk, accelerating agentic process transformation, reducing operational overhead and more.



Samantha Beattie, Senior Manager, Cyber Risk & Advisory, Atmos

Samantha is a Senior Manager in Atmos’ Cyber Risk & Advisory team, helping organisations prepare for and navigate cyber crises through tabletop exercises and incident simulations. With extensive incident response experience, she has supported organisations of all sizes through complex cyber incidents, providing practical, real-world advice to boards and executive teams. A qualified lawyer, Samantha also advises on director duties, privacy obligations, and regulatory issues arising from cyber incidents, including data extortion and ransomware events.



Stephanie Tewson, Senior Manager, Crisis Communication, Atmos

Stephanie leads Atmos Group’s crisis communication readiness and resilience practice. She specialises in helping organisations prepare for and communicate effectively through cyber incidents and other complex, high-consequence events. With 14+ years’ experience across corporate affairs and strategic communication, Stephanie has advised executives, boards and government stakeholders on crisis preparedness, issues management and reputation protection. Her experience spans critical infrastructure, transport and water utilities across the public and private sectors in Australia and internationally.