Senetas returned for a second year to the Festival City — also known as Australia’s Space & Defence Hub — for AISA’s AdelaideSEC conference. It’s a one-day event, but it pulls a flood of security and network professionals in to hear from some of Australia’s leading voices, on everything from “Cyber at machine speed: human decision-making under pressure” to “Your company through an infostealer’s eyes.”
AI is everywhere. The real conversation is governance.
Walking the expo floor, AI was the flavour of the day — nine out of ten booths referenced it in some form. But the concern we kept hearing from attendees wasn’t “should we use it.” It was data governance: how do we protect our data.
Companies are on very different trajectories. Some are taking careful, deliberate steps with AI. Others are racing to adopt it just to get ahead of the competition. And AI agents are moving even faster than either. The gap between rapid AI adoption and governance capability is widening daily under competitive pressures. Moving fast requires guardrails: Role-Based Access Control (RBAC), Attribute-Based Access Control (ABAC), and distinct agent identities that cut the risk, so you can move fast, safely.
We were the only vendor talking quantum readiness
Senetas was the only cybersecurity vendor at AdelaideSEC calling out quantum readiness. Which meant one of the questions we heard most was one we’ve been expecting for years: why is the Australian Signals Directorate (ASD) advising organisations to be quantum-ready by 2030?
Put simply — today’s encryption is safe because it’s effectively unbreakable, right now. Quantum computers will change that. Worse, threat actors are actively executing ‘Harvest Now, Decrypt Later’ (HNDL) strategy—capturing encrypted traffic today to decrypt once quantum capabilities mature.
Post-quantum cryptography (PQC) is the new, NIST-approved encryption built to resist that threat. Australia’s target for readiness is 2030 — but migration takes years, so starting today matters. That’s why Senetas’ encryptors are PQC-ready now.
Leading a cyber crisis at AI speed

Cyber readiness isn’t just PQC preparedness or good AI governance. It’s also how an organisation holds itself together in the middle of a cyber battle. John Karabin, Chief Cyber Security Strategist at McGrathNicol and a volunteer with Fire and Rescue NSW, kicked off the afternoon sessions by drawing a striking parallel between how major emergencies are managed and how cyber crises are led.
“Recovery” was the word of his talk — not the breach itself, but the long tail of recovery that follows it, which rarely gets published or talked about. His framing: no two cyber incidents are the same, any more than any two fires are. What matters is a battle rhythm — Observe, Orient, Decide, Act (OODA) — and a set of hard-won lessons from the emergency services world that cyber teams are still catching up on:
- Pre-planning and preparation. The work happens before the incident, not during it.
- A shared operating picture and priorities. Frameworks like ITASC — incident, threats, actions, support, command — keep everyone in the room working from the same facts.
- Structure and leadership. Grounded in AIIMS (Australasian Inter-Service Incident Management System), cyber crises demand project management discipline. In one cited case, a government department engaged a wedding event planner to run crisis logistics because the structured discipline mirrored high-stakes event co-ordination. It’s also often the lawyers, not the technical teams, who end up leading stakeholder management once things escalate.
- Crew Resource Management (CRM). There are leaders, but everyone is responsible and everyone has a voice. Poorly handled handovers, and crews that never rotate, are where crises get worse rather than better.
- Post Incident Review (PIR). What did we set out to do, what actually happened, why did it happen, and what will we do differently next time.
One line landed hard: the first hour of a cyber incident shapes the next six, twelve, even thirty-six months of response. Karabin’s closing point was blunt — as we move into a period of more frequent, less predictable breaches, against a very different geopolitical backdrop, referencing the ASD’s Cyber Incident Response Plan, cyber teams have a lot to learn from how the military and first responders operate under pressure.
Where this leaves us
Two years running, AdelaideSEC has told us the same thing in different ways: the technology conversation (AI, quantum) and the readiness conversation (governance, crisis leadership) are the same conversation. If your organisation is thinking through AI governance and quantum readiness, we’d like to talk.