September 16, 2026

00:46:11

Episode 385 Deep Dive: Reece Corbett-Wilkins | From Crisis to Resilience - Protecting Our Way of Life

Episode 385 Deep Dive: Reece Corbett-Wilkins | From Crisis to Resilience - Protecting Our Way of Life
KBKAST
Episode 385 Deep Dive: Reece Corbett-Wilkins | From Crisis to Resilience - Protecting Our Way of Life

Sep 16 2026 | 00:46:11

/

Show Notes

Reece takes us behind the scenes of the Instructure incident, where his team fielded 65 instructions in 48 hours, and explains how a catastrophic cyber event actually gets run across insurers, government and thousands of schools at once. KB & Reece get into the hidden cost almost no one budgets for, business interruption, and what the JLR and Change Healthcare cases reveal about how dependent our economy has become on a handful of suppliers.

He also makes the case that AI is quietly splitting security budgets in two, and why that worries him. For any leader thinking seriously about resilience, this one is worth your time.

About Reece:

Reece Corbett-Wilkins is the Head of First Response Australia, and is the Chief Strategy Officer at Atmos. For over 10 years, Reece has focused exclusively on cyber and privacy risk, having helped 1,000+ organisations through some of their most challenging times. Reece is particularly experienced in managing large scale multi-party data breaches, both locally and globally, and ransomware response. Reece works closely with the incident response industry, government, and law enforcement to achieve optimal outcomes for clients.

Keywords: cyber resilience, incident response, business interruption, cyber insurance, critical infrastructure, SPHERE, ransomware, supply chain risk, SOCI reform, AI security budget, CAT event, small business cyber

View Full Transcript

Episode Transcript

[00:00:00] Speaker A: Almost like we've become complacent with cyber risk and focused on AI, when cyber risk itself is arguably only becoming more challenging because of AI. [00:00:10] Speaker B: From KBI Media, I'm Carissa Breen and this is KBCast. My guest today is Reece Corbett Wilkins, head of First Response Australia at utmos. We talk about the AI budget squeeze that's quietly pulling money away from security, why cyber insurance has become a real lifeline for small business. And the question he keeps putting to the industry, are we protecting a checklist or protecting our way of life? If today's episode lands for you, do two things. Hit follow and send it to one person in your network who needs to hear it. That's how shows like this grow. Alrighty, let's get into it. So, Reece, earlier this year KPI Media covered your conference atmosphere here in Sydney and the theme was Building Cyber Beyond Crisis. So be honest, what were you seeing in client work that made you think the industry's obsession with crisis response had really started to hold us back? [00:01:15] Speaker A: So, kb, when I think right back to the early days in 2015 or so, what a lot of the drivers were for cybersecurity to be taken seriously was legislation. So we had the GDPR come in, we had the Notifiable Data Breaches Scheme come in, we had SOCHI come into force. This changed the landscape significantly because organizations needed to do a lot more to become secure. What it created was this compliance driven mindset where people were focusing on the checklist and checking off the legal requirements, but not fundamentally thinking about the issue from a risk perspective or from an outcomes basis. Then if we Fast forward to 2020, we had Covid and remote working and suddenly you had this beautiful playground for threat actors and cybercriminals to play in. You had these distributed ecosystems that were inherently vulnerable and hence where you saw the ransomware as a service economy really kick off. If you fast forward a few more years, we had these major breaches in Australia, this golden era of ransomware, and suddenly we had this evolution where boards and directors and organizations were saying, we don't want to be the next headline or the next victim. And that's what drove activity. And then in the last few years we've had this series of class actions, we've had fines of penalty proceedings from various regulators now across the space. Again, it's very much situational and what I like to refer this to are lightning moments or crescendo moments. Yes, very impactful in their own right, but they're not taken together enough to move the industry away from focusing on the last incident to drive activity. And so what we were thinking about trying to bring us back to a North Star. How do we actually engage with our industry on something much higher order? The North Star that we came up with was this notion of if we're going to move from the moment of crisis to drive resilience, we have to be thinking about how do we protect our way of life. And I think when you speak to cyber security experts, that's ultimately what gets them out of bed. That's what is their higher order purpose and that's where the conversation needs to go to, to drive this conversation more forward. [00:03:17] Speaker B: And would you say that there are these moments when you reference it before this is what gets these practitioners and professionals out of bed? Are there moments that in time when they're seeing the actual impact on people? So you reference major breaches in Australia and obviously we've seen people call up radio stations, give their view. Do you think it's those stories perhaps that may be overshadowed when media folks are writing these stories where it's like, well, hang on, there's the individual that is impacted by something like this and that's what probably moves the needle quite substantially for these professionals. [00:03:51] Speaker A: There's no doubt that the impact to individuals, mums and dads and people on the street is now well known and you know, cyber security is now a dinner table conversation or a water cooler conversation. There's no doubt that these issues have been elevated to that level. What we haven't though had a discussion about, and perhaps we can pick this up later in the conversation, is what is a widespread event impacting our critical infrastructure on an enduring basis actually look like we've had some near misses in Australia, but we haven't actually focused the conversation on real world impact to people and getting that panic scenario really occur in Australia and we've had some examples overseas and we're going to talk about that in a moment. But I think that's really when we're talking about resilience and protecting our way of life. That's the sentiment that we need to lock into to be able to bring our industry and our communities together around this issue. [00:04:37] Speaker B: So rise. Your team helped with the Canvas incident for Australia and New Zealand. When you say how do we deal with that at scale of operation at the same time, say 9,000 entities, what does that sort of look like in practice? And then what do organizations need to be thinking about then to prepare for that level of intensity? [00:05:03] Speaker A: So why don't I tell you what [00:05:05] Speaker C: we experienced behind the scenes, we received [00:05:08] Speaker A: 65 instructions in 48 hours. [00:05:10] Speaker C: And when you do the maths, that's literally the hotline going off every 15 minutes for two days in a row. So pretty intense on our side and thankfully, we'd actually prepared for this. It's what you call in the industry, kb, CAT events or catastrophic cyber events, where a large population of clients can be impacted in a short period of time. We've got three ways that we define a CAT event, but in this case it's where you've got five or more clients impacted by the same event. And so the first step from our side is that we actually declare a CAT event in the team. And this is critical because it activates a series of processes that we've developed in house specifically for this situation. We've got a central intake team and they're responsible for answering the calls and engaging with the client first up. And part of that process is designed to reassure the client what's going on and ensuring that they've mobilized their team, giving them as much information as we can give them and support in the moment. And in this case, that was providing schools and universities with communications packs to speak to students and staff and parents about the event and make sure that they weren't saying anything out of step with others, and importantly, making sure that they operationalize their response to deal with the wave of questions and concerns that they're experiencing. So that's that very first moment. The next step, of course, is, though, we need to mobilise with the insurance industry, who are dealing with hundreds of these notifications coming in through brokers. And so we had centralized reporting in place to ensure that the claims teams could rapidly confirm insurance coverage at scale, some within 24 hours, to provide clients with the confidence that they needed to get on with it and free up the incident response teams. And in this particular case, kb, what was really interesting is that we had calls with insurers in Australia, in New Zealand, in the UK and even in the us, because that's where the brunt of the incident was actually being felt. And we're trying to ensure that there was some global uniformity as to how this was being dealt with. And finally, and this is the key piece is we engaged with the government, the National Office of Cyber Security, to brief them in on the situation. And then they played a really key role. They stepped above the incident, they engaged with Instructure internationally to ensure that they could centralize information that was coming down the line and share that through to schools University so that everyone was working together hand in hand. And I think the key lessons are everybody did a really good job on this, everybody lent in, they activated their responses quickly, they got the support that they needed. But we weren't able to test a couple of things. We weren't able to test how the DFIR community would rapidly respond at scale because in this case it wasn't needed. It was mostly dealt with out of the us. And also whilst we tested a large scale event, we haven't actually tested the upper limits of the capacity of the incident response industry to mobilise. So for example, the conversations that we're having now is how do we deal with a thousand incidents that come in all at once? And thankfully in this case our cap plan activated and worked as intended and didn't impact bau. But we're thinking deeply about how do we deal with this, the next one. And then lastly, from the incident itself, many would have seen in the news that Instructure reached an agreement with a threat actor. And so thankfully data wasn't published, but [00:08:10] Speaker A: if that occurred, there would have been [00:08:12] Speaker C: a whole new layer of response that wasn't. That would have been needed to prevent people from accessing the dark web and seeking out information and having to allay concern among staff, students and parents. [00:08:22] Speaker B: Okay, so there's a couple things in there. So number one would be I literally interviewed someone else today that said to me, kb, there's businesses out there to your point around the ransom payment, they pay the ransom because they think if they don't get their data back in time and how long it's going to take to recover from a resiliency business continuity purposes, it's going to be more expensive than just paying the ransom. [00:08:46] Speaker A: And I think the best news in Australia is that we've actually got some really good options to mitigate against paying a ransom. So for example, on the data recovery piece, organizations in Australia are actually have been focusing quite heavily on being able to restore quickly and we notice that resilience and that maturity. In Australia we have injunctions in place as an option to prevent the publication or the access rather to data if it's been published by a threat actor. We have the National Office of Cybersecurity who can sit across this and try to minimize concern. But you are right, there is a financial question which is sometimes paying the ransom is the cheaper option to recovery and the pathway forward. I know we're going to talk about cyber insurance as well in a moment, but you know, this is one of the reasons why we're advocating so strongly, particularly for small businesses to have cyber insurance because it gives them that capital alternative, it gives them that incident response support to be able to work through this and face up to the threat actor and not have to give in to those demands. [00:09:47] Speaker B: The reason why I think that that is important is because now I'm speaking to people like yourself on the show that are saying that someone uses analogy Today you've got a pizza and AI has taken three quarters of that pizza and the rest of it is left for all the other suppliers. So it means that like companies just don't have the aid budget that they had because AI is completely like blown the budget for them. But then they have to squeeze their other suppliers and it's all downstream. They're even looking at tools. Do we need this particular vendor? So it's a complete shift in, well, how far budget's gone anyway. So we now need to be really resourceful and making sure that the companies we do have in place, we have to be able to divide that up. So it's kind of like the conversation is now going to be a lot more frugal for some of these vendors that people are sort of seeing because I has taken that up. So it's just more. I'm seeing that dynamic shift now and how people are asking those questions at that executive level. [00:10:47] Speaker A: There's lots to tackle in that. And you're right, we are seeing a lot of organizations say it was already hard enough to get security budget. Now we're having to split our security budget with AI spend. And so there's even less in the pot to spend. And that concerns me. I think one of the issues here is we're not actually. It's almost like we've become complacent with cyber risk and focused on AI when cyber risk itself is arguably only becoming more challenging because of AI. And so we do need to be telling stories and working out ways to have conversations with business leaders to understand it's not a trade off. We can't now just decide to spend less on security and spend more on AI. We really have to keep thinking about that resilience piece and about the protecting our way of life as the undercurrent our North Star. [00:11:34] Speaker B: Why do you think Reese, people have, I want to use the word abandon cyber risk, but why do you think there's more of a focus on AI? Is it because we've got Sam Altman? You know, every day we see something and it's his view on this and X and Y And Z, do you think it's more that the, the media headlines is dominating around, you know, open AI and frontier models etc, A new capability has come out from China and look how that's changing the game. Would you think it's that? So therefore what is that saying energy goes or attention flows or something like that? Do you think there's a bit of that in there? [00:12:10] Speaker A: I definitely think energy goes where the attention flows is part of the problem. I also think it's a fundamental mindset shift between cybersecurity was always a spend, a cost, a tax or a drag on a business, whereas using AI is more heavily geared towards productivity, unlocking efficiency, creating value. And so if you're going to ask a cfo, for example, difference between spending a dollar here or a dollar there, we're clearly going to spend the dollar where it makes a dollar as opposed to spend a dollar which cost a dollar. So I really do think there's broader conversations. We're not actually attacking the conversation in the right way. And I do still think that there's a lot of misunderstanding that in the next couple of years, whilst organizations shift to new ways of working and shift to new technologies, including using AI in their environment, we're going to make mistakes, things are going to go wrong and you know, that's why you saw apra, it's why you saw asic, it's why you saw the five eyes come out and say, we're not saying stop, just saying take a breath and make sure that as you invest in AI, that you do it safely, that it's governed well and that you understand how to do it to meet your objectives from a productivity perspective, but without causing your organization or your ecosystem risk at the same time. [00:13:22] Speaker B: One thing I'd like to explore in a little bit more detail is perhaps Australia's view, which sort of leans more towards a national cyber posture, while the United Kingdom is a very different regulatory insurance reality. Where do you believe the UK challenges the conversation in a way that maybe Australia doesn't like, Walk me through that. So we can clearly see the main differences between the two nations from my [00:13:55] Speaker A: perspective, obviously, I'm Australian and I operate in Australia. [00:13:58] Speaker C: And so when I compare what we do here, say, to what others do, it's not to diminish other countries, it's just my perspective of what I sense at the moment in terms of where we're doing well in Australia and perhaps where others might want to think about what we're doing too. [00:14:12] Speaker A: So the first thing I would say is at a Very fundamental level. It makes it very easy when you've got a functioning government that can pass legislation and, and Australia at the moment has a functioning government that can pass legislation. Hence we've been able to pull together really big initiatives like the reforms to Sochi and the cybersecurity laws and the privacy laws, which are still in flux. Whereas if you compare it to the UK at the moment, they're clearly going through some challenges in relation to the government and how they actually then bring forward some of these really big policy agendas. So I think the fundamental simple to it is that there's a difference between the governments in that respect at the moment. But I think the other key difference with the UK is, you know, we are an island nation and so, you know, that kind of drives a lot of our thinking in terms of how resistant we are to cyber risk, for example, whereas in the UK it's a very different operating environment. And so look, I think the ultimate point that I want to make on all of this is I think we should actually be really proud of ourselves as Australians, we have pulled together and look, maybe that's just a function of the fact that we had these large incidents earlier on. What has been really noticeable in the UK is that they obviously had their [00:15:19] Speaker C: big wave of events. Last year you had the MNS breach [00:15:21] Speaker A: co op jlr and those incidents have really brought forward for the UK that they've now got this on their doorstep. The last thing I'd say though is, and you know, coming back to cyber insurance is, you know, the heart of cyber insurance, uk, the heart of cyber risk and technology typically tends to be in the us and so it's really important that we are sharing stories across borders. It's clearly a global risk and not, you know, territory confined. What I challenge Australia to continue to do is look at our neighbors in Singapore and Asia, look at our neighbors in the US and the uk, see what they're doing. Well, copy that. But also be really proud to say we're actually probably a few steps ahead in a lot of ways as well. [00:16:03] Speaker B: And do you believe if we didn't have these major incidents that we've had, do you think Australia would be the steps ahead in what it is today? [00:16:14] Speaker A: Probably not. I think we needed that wake up call back in 2022. It was that watershed moment and that really did change the direction of this. But then cyber risk has always been around for a long time. And so I think for us, because we're in that fortunate position where perhaps we are a few steps ahead. Although I do say that our privacy laws are definitely years behind other jurisdictions as well. So we're not perfect either. I think we've got an opportunity though, to tackle the next big thing, which my view is really trying to understand. Say, you know, where is the invisible cost to our economy? Where is the invisible damage that exists in these incidents? And we talked about this at Sphere. It was its own topic that Stephanie Lewis, one of our partners, in first response, and Jackie Lee, one of our class action partners talked about. And they really revealed from the Net Diligence report and other reporting that the main drivers of incident costs are ID replacements, massive data reviews of large unstructured data sets, long tail privacy litigation or regulatory investigations where the frequency might be low, but the impact is high. And then for highly regulated entities, the main hidden cost is actually having to uplift your security to a standard that is higher than what might have otherwise been adequate in the circumstances because they're under the microscope. But the key thing, KB that surprised me out of that conversation was this concept of business interruption. I think that's the hidden cost. And maybe we can talk about that a bit more. [00:17:33] Speaker B: Yes, I remember speaking to the ladies about this because the key thing, the question that I've been asking is the business interruption cost. That there has to be some type of actuarialist that can say, hey, when you can't operate your business for X amount of time, how much does that then cost you as one factor, the factor of doing all the recovery and paying, you know, the incident response debacle, but then also the long tail impact. So for example, look at Medibank. Is they going to now are they going to be just tainted with, okay, for 20 years you were the company, the medical insurance company that got breached. How long does that go on for? And does anyone have any data on that now? Would you say, Reece? [00:18:19] Speaker A: So the second question is data. I think you've heard me talk a lot about. There is a lot of powering data, but then there's also a lot of gaps in our data and there's a lot of miscommunication in the way that we present data. And even little things like we don't define our companies by revenue consistently. And in my long list of hopes and dreams, I would love to see a day in which the ACSC annual threat report aligned with OAIC's biannual report aligned with CrowdStrike's latest report to define small businesses consistently. So that when we say we've got a small business problem, we know exactly what we're talking about. So just on the point of data, that's a whole conversation we could have another day. But yeah, to answer your question, there is data on this and there are actuarials and loss adjusters that can help help organizations after a breach, but also before a breach to quantify where their risk is. But you know, when I talk about business interruption, you know, when you think about JLR in the uk like that was a massive, massive outage for their economy. It cost them billions of dollars. It impacted 5,000 small suppliers who were heavily dependent on JLR to be operational to get work. And they were waiting for months then to come online in the us. And I think this is a really, really key example of what I'm talking about. When they had the Change healthcare breach several years ago, you literally couldn't go to your GP to get access to health services because they couldn't actually get paid in the back end for providing that services. And if you go on the American Hospital Association's website, they've got a quote on there which I want to read out to you. KB it's really, really powerful. They say the cyber attack on change Healthcare in February 2024 Disrupted healthcare operations on an unprecedented national scale, endangering patients access to care, disrupting critical clinical and eligibility operations and threatening the very solvency of the nation's providers network. It demonstrated that the national consequences of cyber attacks targeting mission critical third party providers can be even more devastating than when hospitals or health systems are attacked directly. And when I'm talking about business interruption, the hidden cost, that's what I'm talking about. [00:20:25] Speaker B: Well, I mean that's quite full on powerful. So, okay, my next question is like, how do we fix that? How do we prevent that from happening? [00:20:36] Speaker A: It's very difficult. But I will say the security of critical infrastructure legislation is now going through reform. And Dr. Jill Slay, who prepared the report into that, has essentially said Sochi needs to be streamlined, easier to follow because it's been kind of bolted together [00:20:51] Speaker C: over the last ten years or so. [00:20:53] Speaker A: It needs wider application, but critically it needs deeper application. So it needs to apply to not just the critical infrastructure asset owners responsible for managing the security and the operations of those assets, but also needs to apply through to key suppliers who could impact the integrity or the availability of those assets. And I think that legislation is going to be a turning point for us as an industry when we're tackling resilience. But at the same time there's other things too. We're not Testing our incident response plans with our ecosystem in mind. We're doing really well at testing single entity response, but we're not bringing in core suppliers, we're not bringing in the incident responders, we're not bringing in the cyber insurance providers into those broader testing conversations to understand how we'd operationally work together through those incidents. And so look, there's lots and lots of more that can be done. But my, my mission on this and my call out to the industry on this is get your house in order. But let's start thinking further left and right. Let's start considering our neighbors in our response to an incident like this. [00:22:01] Speaker B: We'll come back to that after a quick word from our sponsor. In fintech. Trust is everything and proving it shouldn't slow you down. Whether you're dealing with ISO 27001, SOC2, CPS234 or GDPR, Vanta helps you demonstrate security and compliance without derailing your roadmap. Used by thousands of fast moving regulated companies, Vanta automates the hard part. So your team can focus on shipping features, not gathering screenshots. Visit vanta.comkbcas that's V-A-N T A.com KB Cast to learn more. Going back to the JLR incident, what do you believe that incident exposed about how dependent the UK's way of life and economy have become on systems then? Because as we know, we've got a lot of suppliers to run like no one can operate now without leveraging suppliers. There's an issue you mentioned before about the 9,000 schools, the scale that's there, a lot of downstream impacts as well. What's been exposed? What do you think we learn? [00:23:12] Speaker A: There's a lot to learn from it. And if we in Australia reflect on that incident and think about what would we do in response if that happened here? Coming back to my point, we do have a lot of mechanisms in place that would actually greatly assist us. We have really well tested incident response mechanisms in the incident response industry. We've got a lot of capacity in the incident response industry. Industry. We have the National Office of Cyber Security that can help coordinate these major events. You've seen with the recent outages, that the media is quite mature here and can help provide information to the general public at large to mitigate undue alarm and concern and civil unrest. But we haven't yet fully tested that. Now there have been some industries that have tested it, for example, the energy industry and AEMO has taken the lead on that. They've done an incredibly Good job of testing that within the industry. I know the government with the executive Cyber Council is thinking about doing this throughout Horizon 2. So it's not to say that people aren't alive to these issues, it's just we have to work through it and critical infrastructure organizations. I personally think if you've got critical suppliers in your supply chain, particularly that are small businesses, you have to really stress test your assumptions around the, their ability to meet your needs in the moment. They're not going to have the instant response capability or the capital to do it. So do you mandate cyber insurance to ensure that they've got that capital? You really need to think about what's in your control and mitigate that. But then what's out of your control is thinking about the public's perception to them of the impact of an incident to them and how do you then cut through that through effective communications. And lastly, know where to get help. Because if you don't know who your first caller is going to be to and what to expect with your external advisors and others too, then you'll be left wondering in the moment why it didn't activate as intended. So the income is a very long way of saying we just need to stress test this further to really understand where the cracks are, understand when the bottlenecks are, and then try to work through some of those bottlenecks. [00:25:14] Speaker B: So, for example, so taking that incident, planting it into Australia, the systems go down tonight, what starts happening then that night and then into the next day in terms of we've got the infrastructure in place, we've got relatively mature processes, but do you think that people can respond that quickly or do you believe it's just it sounds good on paper, it sounds good when we're talking, but in when there's an actual situation that happens, push, you know, comes to shove, can we get there? [00:25:48] Speaker A: There's always going to be something that doesn't go to plan in incident response land. That's rule number one. So of course there's going to be things that occur that you didn't anticipate. What we want to get to though is, and I think the benefit here in Australia, and this comes back to my point around limited use disclosure, you've got this two ways of running incidents. The first way is very much focus on yourself and pull the shutters down and keep everyone at bay. And when you're back up and running, you're good to go and kind of say, okay, we're ready now, let's go. That's a very defensive Incident response approach. On the other hand, you've got a more proactive engagement approach which is to simply say our systems are going to be down for a period of time and we fully appreciate that that's going to inconvenience you. There's not very much we can do until then other than support you through it in the process and make sure you understand what to expect. What I'm noticing is that those two differences in approach is causing a bit of a shift, particularly in Australia, around how to run a multi party incident well. But my point about the limited use disclosure information framework and then being able to tap into the government for support has been a real game changer. I think Australia actually has done it really well, which is to say you can actually bring people into the tent as you work through these incidents to make sure that everybody can get through it. But yeah, KB to your point, if it happened tonight, of course there's gonna be mistakes that are made along the way. But that's why my call on this is getting organizations to think about how would they deal with an incident of that magnitude. Where are the dependencies on third parties including suppliers and their own incident response providers and how do they make sure that they've got that lined up to activate as they intend then flipping over [00:27:22] Speaker B: to the customers for a moment. Do you also think it's just the day and age that we live in right now, like back in the day, I don't know, maybe when you and I were going up, things were a little bit different. You could be a little bit more patient now something goes down for a second, people are act up straight away. So do you think that there's a. We know that loyalty is not there anymore, but also is it just because how fast everyone can get everything. So therefore when something's inconvenienced, like recently T mobile went down here in the US and it was like, I don't know, maybe an hour. It was super annoying. So I had to drive somewhere and I couldn't get there because my phone, you know there's no cellular data, right. So anyway, I had to get my husband to drive me. It was an inconvenience, but it's fine. But it did impact a lot of people. Now admittedly it was an app. Imagine if that was out for 24 hours, like how much impact it would have. And I couldn't even just drive somewhere and I couldn't imagine what other people are going through. That's just a real life example of how frustrated people seem to get a Lot faster. So do you think it's just how we are today, how humans are being conditioned and wired, that all of that anxiety perhaps comes from we just want everything right now and it always has to work. But at the end of the day what people don't really understand is there are people in the background trying to make this stuff happen. 24 by 7. [00:28:38] Speaker A: Yeah, look, there's a short answer to your first question. I think that there is definitely a lot more noise and people are quicker to react and obviously having social media and technology the like, they're able to do so. There is also though on the other hand a bit of breach fatigue. So people are actually complacent and you know, if the data's been breached again they just roll their eyes and don't take the necessary steps to protect themselves. What I'm really worried about though, and using your telecommunications example, and we've had a couple of outages recently and I know it's very sensitive at the moment, so I won't kind of talk to that. But what I'm challenging organizations to do is think about the people that don't have a voice in that situation. So don't necessarily worry about the people that are inconvenienced. Where are the people that are stuck at home without access to support if they've got life threatening at home, particularly if the triple O line isn't being able to be picked up. Trying to ensure that organizations understand like what's the worst case scenario if something happens and how do we, how do we solve for that issue? How do we solve for the 10% and not necessarily worry about the 90% if we had to make a choice? So I think that's the first point that I'd say it's about thinking differently around this, particularly with that protecting our way of life. North Star in mind, answer your second question. So you talked about there are people wanting to attack organizations 247 overseas and I know AI is an overhyped conversation, particularly with the frontier models that are being released and there's been a lot of noise around this. But I will say at the moment we are absolutely seeing early signs that AI is being used to either scale the frequency attacks or the severity of the attacks. What we're seeing behind the scenes under the hood is more cyber attacks than we've ever seen before since 2020. The frequency is up, the impact might be down, but the frequency is up. We're seeing quicker breakout times after initial access. We're seeing much quicker actions by the threat actors. To steal data and encrypt systems. And by that I mean within hours, not days, we're seeing multiple actors impacting downstream entities at the same time, whereas previously they would work through the network one by one. And we're seeing this all play out in a really short period of time. And so, you know, that's why you've had five eyes and others come out and say, guys, you need to be ready for this. I'm not saying the sky's falling in. I'm simply saying that we are seeing the early signs of this new normal. We have to start to think differently about it, because it won't be long before we're operating in a different environment. [00:30:59] Speaker B: How do we think differently about it? [00:31:01] Speaker A: So I think the first point is, and this came out at Sphere this year, is we have to challenge our comfortable assumptions. We have to revisit the playbooks on our assumptions around downtime and our assumptions around how long it would take us to detect, contain, and restore. We have to think differently around how would we communicate through an event? Well, to mitigate undue alarm of individuals, which then exacerbates their perceived concern, which adds fuel to the fire. We have to make sure that we've got access to support that can activate quickly in the moment so that there's no delay. We really just have to turn the dial on this and take it up a notch. And I think it fundamentally comes from a mindset shift, and that's why it's fear. We asked everybody the one question, which is, what are you doing? What are you doing internally? What are you doing with your industry? What are you doing to change this mindset shift to your point from being obsessed with the moment of crisis, driven by resilience to protect our way of life as the way to look at [00:32:00] Speaker B: this, I then want to come and bring it back to cyber insurance. Do you think there isn't. Now, how do I phrase this correctly? Do you think there may be an element of complacency? Only because, for example, if I'm driving a vehicle on the freeway here in the United States, and apparently the one that I live on is one of the most dangerous, I feel better about myself because I've got insurance on my vehicle. If someone hits me, I hit someone else. Do you think businesses are adapting that same mentality from like a vehicle perspective to be like, well, I've got insurance, so even if something were to go wrong, I'm somewhat covered. I'm somewhat have a bit of a solution in a plan versus actually, no, this is completely going to bankrupt my business. But so does that, do you think? And I know people have to have it. I'm not challenging that. I'm just saying the mindset and the complacency around having it as that safety net. [00:32:55] Speaker A: I think to your point though, if [00:32:56] Speaker C: you're driving a car just because you've got cyber insurance, you're not going to be driving erratically and wanting to have car crashes. So I don't think anybody's suggesting that organizations are then, you know, not taking the appropriate steps, actually. Kb, can I take your analogy one step further? I think the major benefit of car insurance isn't that you have a crash and that your car gets paid out for it. That's obviously part of it, otherwise you wouldn't hop in the car. [00:33:20] Speaker A: I really think the major benefit of [00:33:22] Speaker C: car insurance is that when you hop in your car and drive up the highway like I do every year at Christmas, driving along at 110km an hour to go and see my parents, I've got my two kids, my dog and my wife in the car and you know, the concern there is that you've got cars hurtling down towards you on the other side of the road, separated by really only 2 lines meters away from you, and you wouldn't dare hop in the car if you didn't know that they were insured, if they were licensed, and that they were trained on how to drive a car. And I think that's the main benefit here. When we're talking about resilience at scale. We want to ensure that businesses have the confidence to go into market and can operate safely. [00:33:59] Speaker A: But we also want to know in [00:34:00] Speaker C: our supply chains that if something goes wrong, that they've actually got the help that they need. And that's that feeling of being inherently safe and protected. And that's the point here. [00:34:08] Speaker B: And I asked that question because if I look back to your comment around and I agree, people being desensitized, like, oh, it's another breach. So when there's a breach, I go and look at social media. What are the comments saying? It's like, oh, this is the fifth one. I mean, oh, don't care. Who cares? My data's already out there. So I'm trying to marry up the parallel to that complacency thinking and that people feeling desensitized. So do you think perhaps these small businesses in Australia aren't at that 50, 60% in the insurance space because they're like, oh, well, people are just. Our clients are going to say, well, We've been in like six breaches before yours anyway, and you're a small business, so, like, why should I care? And do you think that now because people are being. People are desensitized to breaches. Like, are companies going to invest less in cyber? Because if they're, for example, if they're like, you know, stock stays the same, that might not be incentivized for them to be like, oh, well, let's want to. No one wants to spend more money on this stuff. But people do it because of compliance reasons and regulatory and yes, for trust and revenue. Yes, people say they can care, but really, at the end of the day, no one's going to overspend on stuff if they don't have to, particularly if their customers are like, oh, well, we're desensitized. [00:35:25] Speaker A: It's a really interesting topic, which is how do we change the sentiment and the mindset of the industry? And Dr. Jill Slay actually spoke about this in her report that she commissioned in relation to the security of critical infrastructure reform. She picked up on this sentiment that. And I've. And I've actually heard CISOs talk about this before as well, which is those that are doing the right thing and overspending and going above and beyond aren't getting rewarded for their efforts. I mean, they're not having breaches, but generally speaking. But that aren't doing the right thing and underspending and underinvesting and causing risk to themselves and to their ecosystems aren't getting punished. Now, I'm not saying that we all need to go out and punish the wrongdoers, but there is a very deep question here around how do we change the mindset so that everybody is spending the right amount and investing in the right way? I funnily think that this all comes back to storytelling and that's why Sphere is so important, because it gets people to share stories and perspectives around what actually happens on the ground in the real world in relation to cyber incidents and the number of small businesses that you see that don't have insurance and the lights get switched off and they can't trade through. I mean, we saw that with medisecure when they had their breach, they filed for insolvency because they couldn't afford to notify the tens of millions of individuals whose data was compromised. And that's clearly not a desirable outcome for them. It's not a desirable outcome for individuals whose information is caught up in the breach. And then on the flip side, you've got many small businesses who do have cyber insurance and MSPS or customers of MSPs, travel companies, health service companies, small financial advisory companies, law firms, you name it, who the benefit, but only after the event. It's almost like they needed the incident occur for them to realize that that was worth investing in it. Now, clearly we can't have a situation where we need organizations to be purchasing this just because they've had an incident. We want to prevent incidents. So I think part of this exercise is actually getting more organizations to speak from the heart about their experiences, share those stories with their neighbors, share those stories with their industry, so that we can learn from the misfortune of others across the board. [00:37:32] Speaker B: So I want to speak to you about Jeremy Kirk and James Taliano, who I interviewed together. Now, their argument was cybercrime is becoming easier and more scalable. And to James's point, it's a very sexy industry. Now. People can make lots of money and flash it around, all that sort of thing. People don't necessarily want to go to university or college and, you know, go up the corporate ranks when they could become a cyber criminal and make lots of money really quickly. So with that in mind, a few months on from that conversation with the, with the guys, are you sort of seeing that then play out in real client environments or is the industry still repeating the same sort of warnings perhaps, but with a new language? [00:38:17] Speaker A: It's interesting that you picked up on the point that the conversation was a few months ago, because in this space, as you know, the conversation moves so quick. So when you interview Jeremy and James, and even when we prepared them for Sphere back in December last year, you know, for context, Frontier models have been around and we were talking about the possibility of AI enabled cyber attacks. But it wasn't until, you know, March and April when those models were released and then obviously we've had all the alerts from apra, asic, the Five Eyes and others, we've now started to see examples. The hugging face incident with OpenAI. Only recently we've seen Dave, the guy that used Open Call to hack his way into a class. This week we are starting to see real examples of where the technology absolutely helps threat actors, bad guys scale. And to my point earlier, hence why we're seeing in our view, an increase of activity. But what I would say is that, you know, my view on this is fairly balanced, right? There is a lot of hype around this and truth be told, we actually haven't seen an incident where we can say hand on heart, that it was a purely autonomous attack or it was a purely cyber enabled attack. Partly that's because it's actually difficult to say when you're doing the investigation. Ultimately it just follows a usual track other than the attacks are quicker. To my point earlier, what I would say though is most of the attacks, most of the losses, most of the incidents being caused by fairly basic and well known control failures, human error, MFA bypass, unpatched vulnerabilities, recycled credentials that have made their way online. They're still very much the root cause of the majority of incidents, but we are keeping a really close eye out. The increased prevalence of incidents due to AI enablement and in particular I'm most worried about is not just increased frequency, them all occurring all at once, perhaps clustered around an MSP or perhaps clustered around a SAS provider or someone like that that has that concentration risk. [00:40:17] Speaker B: Okay, I want to zoom out now. You also had Chris Krebs, Admiral Rogers and Alistair McGibbon who I also interviewed. Now their view was they pushed with different elements around resilience. Right. They had very strong conversation with Alison McGibbon on this as well. So with that in mind, which one really challenge an assumption Atmos had going into Sphere? [00:40:43] Speaker A: You're right that we had big names at Sphere with Alistair and April, Mike Rogers and big opinions. Right. I mean that was, that was part of what Sphere was all about. And so we embraced that. Look, they obviously had a lot to say. I think Mike's overall concern was the disruption of a service or a capability combined with the panic or civil unrest. In his view, that was, you know, the societal impact that was that major concern. And how do we build resilience around that? Rosalistair's approach was a bit more technical in mind. It was thinking less about the confidentiality of data as a risk to manage or address and instead focusing on integrity and availability. So an event that cripples society and the lack of trust in machines and our hyper connected communities. And whilst they kind of came at it from different angles, I think fundamentally they were certainly the same problem. But what the takeaway message is for me was it's the way in which they had the conversation. Alistair is talking about CIA principles and very technical terms which all your SISOs would fully understand. And then Mike Rogers was talking about the impact to humanity. I think the lesson for me is, and to answer your question around assumptions is how we're having this conversation is really important. How are we connecting the impact of your actions to a benefit to the organization financially and societally? How do we frame it up so that you've got multiple C level decision makers within an organization latching on to the opportunity that's before us. I think that was really interesting dynamic when you saw the two because they were actually trying to solve the same problem but from different corners of the room. [00:42:22] Speaker B: Definitely. I mean we could have probably sat there for hours talking about this. And it's good to get those different perspectives as well. And I asked them relatively straightforward questions, hard hitting questions and they just answered them like this is the reality. That's what people want to know when they're going to Sphere in place, that they want to get answers that may be uncomfortable. [00:42:42] Speaker A: Yeah, next year. KB like we're obviously in planning stage for Sphere 27 and we are looking at, you know, who are the people that we want on stage but more importantly who are the people that we want in the room. Because that's ultimately the gift is the audience participation and making sure that it's not just a conversation that happens once a year, but it's a conversation that continues throughout the year between conferences. [00:43:01] Speaker B: So as we know, sphere 2027 is already announced with the theme being Delivering Resilience. So what does the 2027 conversation need to say that perhaps the 2026 conversation either couldn't say or wasn't ready to say? [00:43:20] Speaker A: You're asking me for all the juicy secrets KB before we've worked in the program. But no, we're committed to run Sphere as a platform for change for the next five years. And I think that's a really key starting point because I want people to see this as an opportunity to have a conversation over many, many years. It's not just a once and done each year. Obviously we're going to coincide it with Horizon 2 and 3 of the National Cyber Security Strategy. So we're really excited to elevate some of the good stuff that's coming out of Horizon 2. We're really excited to elevate some of the stuff that's coming out of the Sochi Law reform because I truly think that that's a game changer. I'm really excited to try to get people from New Zealand and Singapore, US and UK to come share their perspectives. To my point earlier around what are they doing and what can we learn and vice versa. I think the inside scoop, if I can, is the focus is going to be about delivering resilience. So this year is all around scene setting and challenging assumptions. That's the easy conversation. Now we've actually got to get down and dirty and do the hard work and a lot of this is much easier said than done and it takes a lot longer. We can obviously identify quick wins if we want to get true resilience. This thing is going to take years to roll through. So I think the answer to your question is next year we're going to be trying to tackle some of those head on. I want to illuminate where organizations have done really well in the last year and are doing things really well. I want people to be honest and say that we're struggling. I want people to be honest and say this is going to take longer than we think. It's costing more than we have available to us. I want to try to understand those issues and as I say, expose the weaknesses in the system, identify the bottlenecks and start to crack through them. And lastly, I just want to flag that Sphere is a different kind of event. It's a community event. It is free. Of course, it's invite only to senior decision makers, but it's only made possible through Atmos's time and financial commitment as well as that of the sponsors. And I just want to say kb massive shout out and massive thanks to all of the sponsors that helped us in 2026 and who have already started to commit for 2027 and beyond. This wouldn't be possible if it weren't for us and for them putting that effort and for everyone getting around it. And we're super excited be coming back on the 4th of March next year for Sphere 2027. [00:45:27] Speaker B: That was Reece everybody. The idea I'll be sitting with is that we can't quietly trade security budget for AI spend and call it progress because AI is making cyber risk harder, not easier. If you're a CEO listening to this, the next time someone frames security and AI as an either or line item, that could be the right moment to push back. I read every reply. If you got some thoughts on this one, send me a message on LinkedIn. Kbcast cyber for the c suite.

Other Episodes