Strategic event

CyberCon 2026

Melbourne Convention & Exhibition Centre, Melbourne, Australia
Oct 14, 2026 10:30 AMOct 16, 2026 2:30 PM

Stop by the Wiz Agent Lab!

See firsthand how Wiz AI agents can work for you. Come meet us at booth#26 to chat about Wiz AI agents and watch live demos with our team.

Schedule a meeting with us!

Join us to chat about building secure AI applications and exploring cloud security

For information about how Wiz handles your personal data, please see our Privacy Policy.

Let's Talk About the C-Word: Why Risk Professionals Aren't Using it Enough

In the high-stakes environment of Australian boardrooms, there is a word that remains dangerously underutilized. It's not a profanity — but for many security and risk teams, it's just as uncomfortable, because it's harder to quantify than a CVE score. That word is context.

For years, cybersecurity has been addicted to the list. We present Boards and Risk Committees with thousands of "critical" vulnerabilities, anomaly detections, unpatched assets, and identity alerts — training decision-makers to treat risk as a volume problem. But in 2026, the volume has become noise, and the noise is masking what actually matters.

This session argues that our current approach to risk appetite, prioritisation, and assurance is fundamentally broken — because it lacks context. A CVSS 10.0 vulnerability on an isolated, non-production server is a footnote. A "medium" vulnerability on a public-facing system, connected to sensitive data through an over-privileged identity, is a business-ending event. Without context, they look identical on a spreadsheet. With context, the difference is existential.

This isn’t a hypothetical problem. Drawing on recent threat research, this session introduces the concept of the toxic combination — where individually low-severity issues chain together to create critical, often invisible, paths to compromise. Emerging patterns in control plane exploitation and cross-environment attack paths are producing exactly these scenarios. They don't show up at the top of your vulnerability list. They don't trigger your critical-count dashboard. But they are the risks most likely to end careers and make headlines.

Traditional risk models consistently miss them — not because the data isn't there, but because the data lacks the connective tissue of context: asset criticality, exposure, identity and access, and attack path analysis. When these elements are layered together, raw security data transforms into genuine risk insight — enabling faster prioritisation, more defensible decisions, and stronger alignment between security, compliance, and business objectives. 

This session is not about tools or technology. It is a reframing of how risk is understood and communicated in environments where threats evolve in hours, not months, and where change is the only constant.

Risk professionals have spent too long managing security through a telescope — zooming in on individual vulnerabilities while losing sight of the terrain. Context is the map. It shows you not just where the threats are, but which ones lead somewhere dangerous, and which ones are just noise.

It's time to stop chasing smoke alarms and start finding the fire. The C-Word isn't just a useful concept — it's the missing foundation of modern risk practice. This session is a call to action: use it.

Rodman Ramezanian

Customer Engineer

Melbourne Convention & Exhibition Centre, Melbourne, Australia
Oct 14, 2026 2:40 AM

Scaling AppSec and Cloud Defense When AI Exploits Move at Machine Speed

Recent advancements in AI models mean frontier systems can now autonomously discover zero-days and exploit vulnerabilities at machine speed. Traditional security postures that rely on manual triage are collapsing under the weight of these automated, non-deterministic attack paths.


This session introduces a practical, four-pillar operating model for AI Threat Readiness. Attendees will learn how to reduce exploitable exposure, accelerate remediation, uncover risk through deeper analysis of code and AI systems, and use AI to detect, investigate, and respond to threats at machine speed.

Lucas Jarman

Customer Engineer