Highlights

Highlights From Previous CIO Cyber and Risk Network Gatherings

July 2026

In our call this month, the participants (Org A and Org B) shared the details of data breaches each had experienced. Interestingly, both breaches related to hotels that the call participants had used as event venues. In each attack, the hotel staff had clicked on links which had compromised their email accounts, and these accounts were used to send further email attacks to the staff of both Orgs.

The call participants also spoke about the need to make email security easier for humans because it’s not reasonable to expect staff to be wary of emails from third parties (like hotel venues) that the company is legitimately dealing with. Both the efficacy of passkeys and Abnormal for email security were discussed. 

June 2026

On June’s call, hours after Anthropic announced the public availability of Fable 5, the participants shared what their organisations were doing with Copilot rollouts, along with perspectives on governance and data governance emerging through these rollouts. Also shared were the different experiences with business case requirements; some executives wanted business cases, others were asking why they didn’t have Copilot already.

One CIO shared the approach of an ‘AI sandwich’, where the AI is the meat in the middle and a human is responsible for the input and assessing the output.

The CIOs then spent some time sharing the AI usecases their organisations were exploring. While most of these were in their infancy, each held deep specialisation to that organisation with high value outcomes, but equally mission critical impact if the AI stopped working.

Links and references shared during the call:

May 2026

Our call for May covered the following discusssions:
  • Navigating between the real versus the hyped abilities of Anthropic’s Mythos Preview 
  • What the participants expect from other emergent frontier models, and the subsequent impact on patching and architecture, 
  • Existing challenges within their organisations that have prevented better ICT hygiene to this point and what the roadblocks are for changing these in the near term, 
  • The regulator statements from APRA and ASIC regarding AI and implications for board members, 
  • Different approaches to using and accessing AI within their organisations, 
  • Minimised impact of a vulnerability tsunami on enterprises that largely use SaaS. However, this also depends on how quickly their SaaS vendors gain access to and respond to the outputs of Mythos and other frontier models, 
  • The race for other AI vendors to produce frontier models that are close to, level with, or exceed the asserted capabilities of Mythos Preview

Further Information:

March 2026

In our call this month, the following topics were covered:
  • Post-Quantum Cryptography Planning: Some organisations are being asked by their boards about planning for post-quantum cryptography, with a focus on adding to their risk register, long-term thinking (e.g., 2030), and addressing the problem by focusing on the weakest encryption first.
  • AI Tool Trust and Observability: Discussions centered on the risks of machine-controlled processing (MCP) servers and AI tools like large language models, specifically regarding data leakage, limited observability, and the challenge of trusting that information is not being sent externally.
  • Geopolitical Conflict Impacts: Participants discussed the potential for conflict to cause supply chain shortages (memory/chips, laptops, fuel), drive up costs, and affect platform availability. Some organisations are looking at reducing offshore dependency and using geoblocking as mitigation.
  • Rising Costs and Budget Pressure: The group noted significant budget constraints, vendor price increases (especially for ISPs, storage, and backup servers), and cost blowouts, leading to mitigation strategies such as going to market to fulfill multiple functions with one person, trimming services, and using chargeback.
  • Black Swan Event Planning: There is an increasing regulatory expectation for industries to more seriously plan for and understand the potential impact of ‘black swan’ events.

Interesting Links: