Highlights
Highlights From Previous CIO Cyber and Risk Network Gatherings
July 2026
In our call this month, the participants (Org A and Org B) shared the details of data breaches each had experienced. Interestingly, both breaches related to hotels that the call participants had used as event venues. In each attack, the hotel staff had clicked on links which had compromised their email accounts, and these accounts were used to send further email attacks to the staff of both Orgs.
The call participants also spoke about the need to make email security easier for humans because it’s not reasonable to expect staff to be wary of emails from third parties (like hotel venues) that the company is legitimately dealing with. Both the efficacy of passkeys and Abnormal for email security were discussed.
June 2026
On June’s call, hours after Anthropic announced the public availability of Fable 5, the participants shared what their organisations were doing with Copilot rollouts, along with perspectives on governance and data governance emerging through these rollouts. Also shared were the different experiences with business case requirements; some executives wanted business cases, others were asking why they didn’t have Copilot already.
One CIO shared the approach of an ‘AI sandwich’, where the AI is the meat in the middle and a human is responsible for the input and assessing the output.
The CIOs then spent some time sharing the AI usecases their organisations were exploring. While most of these were in their infancy, each held deep specialisation to that organisation with high value outcomes, but equally mission critical impact if the AI stopped working.
Links and references shared during the call:
May 2026
- Navigating between the real versus the hyped abilities of Anthropic’s Mythos Preview
- What the participants expect from other emergent frontier models, and the subsequent impact on patching and architecture,
- Existing challenges within their organisations that have prevented better ICT hygiene to this point and what the roadblocks are for changing these in the near term,
- The regulator statements from APRA and ASIC regarding AI and implications for board members,
- Different approaches to using and accessing AI within their organisations,
- Minimised impact of a vulnerability tsunami on enterprises that largely use SaaS. However, this also depends on how quickly their SaaS vendors gain access to and respond to the outputs of Mythos and other frontier models,
- The race for other AI vendors to produce frontier models that are close to, level with, or exceed the asserted capabilities of Mythos Preview
Further Information:
- For critical infrastructure: CI Fortify – Guidance for Australian critical infrastructure service continuity and resilience
March 2026
- Post-Quantum Cryptography Planning: Some organisations are being asked by their boards about planning for post-quantum cryptography, with a focus on adding to their risk register, long-term thinking (e.g., 2030), and addressing the problem by focusing on the weakest encryption first.
- AI Tool Trust and Observability: Discussions centered on the risks of machine-controlled processing (MCP) servers and AI tools like large language models, specifically regarding data leakage, limited observability, and the challenge of trusting that information is not being sent externally.
- Geopolitical Conflict Impacts: Participants discussed the potential for conflict to cause supply chain shortages (memory/chips, laptops, fuel), drive up costs, and affect platform availability. Some organisations are looking at reducing offshore dependency and using geoblocking as mitigation.
- Rising Costs and Budget Pressure: The group noted significant budget constraints, vendor price increases (especially for ISPs, storage, and backup servers), and cost blowouts, leading to mitigation strategies such as going to market to fulfill multiple functions with one person, trimming services, and using chargeback.
- Black Swan Event Planning: There is an increasing regulatory expectation for industries to more seriously plan for and understand the potential impact of ‘black swan’ events.
Interesting Links:
- Micron to Exit Crucial Consumer Business, Ending Retail SSD and DRAM Sales
- Impact on laptops market
- Cisco Catalyst SD-WAN Vulnerabilities
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files. - A GitHub Issue Title Compromised 4,000 Developer Machines
On February 17, 2026, someone published cline@2.3.0 to npm. The CLI binary was byte-identical to the previous version. The only change was one line in package.json: or the next eight hours, every developer who installed or updated Cline got OpenClaw – a separate AI agent with full system access – installed globally on their machine without consent. Approximately 4,000 downloads occurred before the package was pulled. - ShinyHunters claims ongoing Salesforce Aura data theft attacks
Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give guest users access to more data than intended. However, the ShinyHunters extortion gang claims to be actively exploiting a new bug to steal data from instances. - Stay ahead of the quantum threat with post-quantum cryptography
Anybody pro-actively doing anything about planning for post-quantum cryptography – or will we wait for the market/vendors to respond.
