Highlights

Highlights From Previous CIO Cyber and Risk Network Gatherings

August 2026

Key take ways from the August session:

  • Board Governance and Cyber Resilience: Boards must be equipped with the right questions to shift the organisational mindset from ‘if’ to ‘when’ an attack occurs. This includes developing robust contingency plans for extended business isolation or significant downtime if critical third party providers fail.
  • Third Party and Supply Chain Risk: Assessing and managing third party cyber risk is theoretically sound but practically difficult. A major focus must be placed on educating executives about these risks, evaluating market readiness, and determining how much security obligation can realistically be shifted down the supply chain.
  • Critical Infrastructure and Evolving Threats: There is an increased likelihood of attacks targeting critical infrastructure, mirroring recent global incidents. Alongside these major threats, everyday vectors are shifting as threat actors exploit standard user expectations around email and communications.
  • AI Proliferation and Internal Controls: The rapid and pervasive spread of AI requires strict internal governance. To safely manage AI embedded in everyday tools, businesses are relying on strict IT access controls, creating dedicated AI working groups with the right personnel, and drafting clear acceptable use policies.
  • Data Sovereignty and Infrastructure Challenges: Addressing global sovereign risk and data privacy is driving a trend toward building in-house, on-premise AI models. However, this is causing massive infrastructure delays and significant cost increases, leading many to explore open-source alternatives and raising underreported concerns regarding telemetry data.

July 2026

In our call this month, the participants (Org A and Org B) shared the details of data breaches each had experienced. Interestingly, both breaches related to hotels that the call participants had used as event venues. In each attack, the hotel staff had clicked on links which had compromised their email accounts, and these accounts were used to send further email attacks to the staff of both Orgs.

The call participants also spoke about the need to make email security easier for humans because it’s not reasonable to expect staff to be wary of emails from third parties (like hotel venues) that the company is legitimately dealing with. Both the efficacy of passkeys and Abnormal for email security were discussed. 

June 2026

On June’s call, hours after Anthropic announced the public availability of Fable 5, the participants shared what their organisations were doing with Copilot rollouts, along with perspectives on governance and data governance emerging through these rollouts. Also shared were the different experiences with business case requirements; some executives wanted business cases, others were asking why they didn’t have Copilot already.

One CIO shared the approach of an ‘AI sandwich’, where the AI is the meat in the middle and a human is responsible for the input and assessing the output.

The CIOs then spent some time sharing the AI usecases their organisations were exploring. While most of these were in their infancy, each held deep specialisation to that organisation with high value outcomes, but equally mission critical impact if the AI stopped working.

Links and references shared during the call:

May 2026

Our call for May covered the following discusssions:
  • Navigating between the real versus the hyped abilities of Anthropic’s Mythos Preview 
  • What the participants expect from other emergent frontier models, and the subsequent impact on patching and architecture, 
  • Existing challenges within their organisations that have prevented better ICT hygiene to this point and what the roadblocks are for changing these in the near term, 
  • The regulator statements from APRA and ASIC regarding AI and implications for board members, 
  • Different approaches to using and accessing AI within their organisations, 
  • Minimised impact of a vulnerability tsunami on enterprises that largely use SaaS. However, this also depends on how quickly their SaaS vendors gain access to and respond to the outputs of Mythos and other frontier models, 
  • The race for other AI vendors to produce frontier models that are close to, level with, or exceed the asserted capabilities of Mythos Preview

Further Information:

March 2026

In our call this month, the following topics were covered:
  • Post-Quantum Cryptography Planning: Some organisations are being asked by their boards about planning for post-quantum cryptography, with a focus on adding to their risk register, long-term thinking (e.g., 2030), and addressing the problem by focusing on the weakest encryption first.
  • AI Tool Trust and Observability: Discussions centered on the risks of machine-controlled processing (MCP) servers and AI tools like large language models, specifically regarding data leakage, limited observability, and the challenge of trusting that information is not being sent externally.
  • Geopolitical Conflict Impacts: Participants discussed the potential for conflict to cause supply chain shortages (memory/chips, laptops, fuel), drive up costs, and affect platform availability. Some organisations are looking at reducing offshore dependency and using geoblocking as mitigation.
  • Rising Costs and Budget Pressure: The group noted significant budget constraints, vendor price increases (especially for ISPs, storage, and backup servers), and cost blowouts, leading to mitigation strategies such as going to market to fulfill multiple functions with one person, trimming services, and using chargeback.
  • Black Swan Event Planning: There is an increasing regulatory expectation for industries to more seriously plan for and understand the potential impact of ‘black swan’ events.

Interesting Links: