Skip to content
PodcastsTechnologyCyber Voices

Cyber Voices

Australian Information Security Association (AISA)
Cyber Voices
Latest episode

82 episodes

  • Cyber Voices

    Fighting Back: Glenn Maiden on Putting a Bounty on Cybercrime

    12/08/2026 | 33 mins.
    Cybercrime is not a lone hacker in a hoodie any more. It is an economy, and by some estimates a staggeringly large one. In this episode of Cyber Voices, host David Savva-Willett flips the usual script and asks not how we defend, but how we fight back.

    Glenn Maiden is Chief Security Officer for Fortinet Australia and Director of Threat Intelligence at FortiGuard Labs for Australia and New Zealand. He spent years in Defence and the Australian Intelligence Community working in geospatial and human terrain intelligence, including during Operation Slipper, before moving into commercial threat intelligence. He established the team behind the World Economic Forum's Cybercrime Atlas and, most recently, helped create a first of its kind cybercrime bounty program with Crime Stoppers International.

    The conversation covers how mapping tribal structures, community leaders and wells in a conflict zone translates to mapping the humans behind ransomware crews, why our industry has become excellent at indicators of compromise and knows almost nothing about the actual people, and what the Cybercrime Atlas found when it started pulling names, aliases, bank accounts, crypto wallets and bulletproof hosting together into targeting packages for Interpol, Europol and the FBI.

    David and Glenn also dig into why better defence alone was never going to be enough, the gap that sits on the people and process side rather than the technology side, and the unreported soft underbelly of an economy built on small and medium business. Glenn explains how the new bounty program works, how someone with intelligence on a threat actor can submit an anonymous tip and potentially collect a reward when that person is arrested and prosecuted, and why the same infrastructure mapping may help pull far worse criminals off the streets.

    There is a human side too. Glenn talks about the young man in Eastern Europe committing cybercrime to get his family out, the scam compounds operating a couple of hours to Australia's north, and his own experience of being scammed through Facebook Marketplace. He explains why he tells that story publicly and how shame keeps victims silent.

    Glenn closes with practical advice for CISOs, SOC leads and analysts who will never run a takedown themselves.

    Content note: this episode includes brief references to human trafficking, forced labour in scam centres and child exploitation material in the context of organised crime.

    Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.
  • Cyber Voices

    The Ones Who Do Nothing: Ant Cohen on What Your Phishing Metrics Are Missing

    05/08/2026 | 27 mins.
    On this episode of Cyber Voices, host David Savva-Willett is at the tail end of Canberra CyberConnect 2026, AISA's first ever event in the nation's capital, sitting down with a guest who has one of the best job titles in Australian cyber.

    Ant Cohen is Head of Security Influence and Trust at nbn. Before cyber, he built some of the most recognisable marketing campaigns this country has seen, from Oprah's Australian adventure to 25 Wallabies campervans touring New Zealand during the Rugby World Cup to a gold medal winning campaign for the Australian Olympic and Paralympic teams in London. He now brings that storytelling firepower to human centred cyber defence, and sits on a NSW Crime Stoppers advisory committee.

    David and Ant get into why security awareness has a well earned reputation for being boring and occasionally condescending, and Ant's diagnosis of the problem: an oversupply of supply. The industry has indulged in training, drills and metrics reporting without ever building the demand.

    The idea that stops David in his tracks is the do nothing cohort. Security teams obsess over the people who click and celebrate the people who report, but the largest group by far is the people who open the simulation, leave it sitting in the inbox and take no action at all. Ant explains why the time of day, the device and the out of office setting tell you far more about your culture than a click rate ever will, and why he is a believer in small data over big data.

    The conversation also covers whether phishing simulations remain tenable after a decade of use, the difference between decisions made cold and decisions made in the heat of the moment, closing the loop so people know a human actually reads what they report, and the scale of nbn's responsibility given the proportion of Australia's daily data traffic that crosses the network. Ant's team of four works alongside nbn Local to reach regional and rural communities, libraries and the Country Women's Association with scams education aimed squarely at the Australians most often targeted.

    And his one thing for cyber leaders heading back to work on Monday: learn your audience, and learn the language they actually speak.

    Recorded live at Canberra CyberConnect 2026.
  • Cyber Voices

    The Human Firewall: Darren Fleming on Staying Clear Headed in a Crisis

    29/07/2026 | 27 mins.
    Every playbook and SOP you have ever written assumes it will be picked up by a calm, fully regulated human. My guest this episode reckons that assumption is exactly where incident response quietly falls apart.

    Recorded live at AISA's inaugural CyberConnect Canberra 2026 at the Hotel Realm, David Savva-Willett sat down with Darren Fleming, peak performance strategist, author, and the man better known as That Mindfulness Bloke. Darren represented Australia in elite sailing, studied psychology and philosophy at Oxford, has written seven books on communication, leadership and mindset, sat in complete silence for ten days, and spent more than twenty years coaching global organisations including Caterpillar, Cisco, BHP and Rio Tinto on how to perform under pressure.

    His CyberConnect talk, The Human Firewall, covers the thing no runbook touches: what actually happens to a responder's brain in the first hours of a Sev1.

    They get into why the nervous system, not the playbook, makes the decision. How adrenaline and cortisol cut off access to long term memory, and why "it made sense at the time" is a physiological answer rather than an excuse. The difference between situational awareness, stretched awareness and tunnel vision, and why "I just didn't see it" keeps turning up in the debrief. Why incident teams start turning on each other under pressure, and why that is the body working exactly as designed rather than a culture problem. What ten days of Vipassana taught Darren that a psychology degree could not. The collapse of the average attention span from roughly two and a half minutes to under a minute in twenty years. How a SANFL club lifted its win rate by changing what three senior players did during the half time break. And the one technique Darren would hand a CISO heading into a tabletop next week.

    Find out more about Darren's work at thatmindfulnessbloke.com

    Cyber Voices is the official podcast of the Australian Information Security Association. Subscribe wherever you get your podcasts and leave us a five star rating, it genuinely helps others find the show. Learn more about AISA or become a member at aisa.org.au
  • Cyber Voices

    Earning the Chair: How Graham Fairley Became PEXA's CISO

    22/07/2026 | 36 mins.
    Most people arrive at the CISO chair from the outside. Graham Fairley did the opposite — he earned it from within.

    In this episode, host David Savva-Willett sits down with Graham Fairley, Chief Information Security Officer at PEXA (Property Exchange Australia), for a candid and personal conversation. Davey held the CISO role at PEXA before Graham, and the two have been friends and colleagues for the better part of a decade — which makes this a rare, honest look at what it actually takes to grow into one of the most demanding seats in Australian cyber.

    Graham progressed through identity and access management, security consulting and a security services lead role before stepping into the CISO chair in late 2024. Eighteen months in, he reflects on the learning curves nobody warns you about: winning executive and board buy-in, sitting with the weight of accountability, learning to let go of the technical work he loves, and becoming the kind of storyteller a modern security leader has to be.

    They also get into what PEXA actually protects — a platform underpinning Australia's ~$10 trillion property market and designated critical infrastructure — including the 6.5 million intrusion attempts PEXA blocked in a single financial year, four times the previous year's volume. Graham unpacks PEXA's layered defence approach, and the harder problem beyond the platform: the consumer. As he puts it, criminals don't need to compromise systems — they just need to compromise trust. In this episode:
    Why the "internal" route to CISO is undervalued — and the edge it gives you
    The first 18 months in the chair, and the skills that sharpened fastest
    Why every CISO has to be a storyteller (and where AI genuinely helps)
    Learning to step back so the team — not the CISO — becomes the hero
    Defending critical infrastructure at scale: layered controls, threat intel and speed-to-detect
    Social licence, shared accountability and PEXA's Safeguarding Your Property Settlement white paper
    AI-supercharged business email compromise, and the "stop and think" habits that stop it
    Real advice for anyone who wants the CISO job one day
    Cyber Voices is the official podcast of the Australian Information Security Association (AISA). If you're enjoying the show, a five-star rating (about five seconds of your time) genuinely helps more people find it.

    Interested in sponsoring Cyber Voices or reaching the AISA community at CyberCon? Contact the AISA national events and sponsorship team via sponsorship@aisa.org.au.
    #CyberSecurity #CISO #AISA #CyberVoices #PEXA #CriticalInfrastructure #InfoSec #Leadership
  • Cyber Voices

    Breachonomics Redux: Grant McKechnie on the Untold Cost of a Data Breach

    15/07/2026 | 19 mins.
    On this episode of Cyber Voices, host David Savva-Willett is on the ground at Canberra CyberConnect 2026, AISA's inaugural event in the nation's capital, sitting down with Grant McKechnie for a conversation that CFOs and board members need to hear.

    Grant is Managing Partner at Cyber Resilience Group and a two-decade CISO veteran of Endeavour Group, Telstra and NBN. He was named one of the top 10 CISOs in Asia Pacific in 2022 and has built greenfield cyber security functions across some of Australia's most critical infrastructure. Today at CyberConnect he has returned with Breachonomics Redux, a follow up to the passion project he has been researching for the past four years on the untold economic and human impacts of a data breach.

    We get into the share price data behind major Australian and global breaches, from Medibank's 198 days back to parity to Live Nation's share price actually climbing after a breach affecting 560 million records. Grant unpacks why the market is becoming ambivalent, why Australian penalties never match the crime, and why trust and communications have overtaken share price as the impact he now leads with when advising boards. We also dig into how threat actors are adapting (including calling the regulators on their own victims), why information sharing has quietly gotten worse even as we appear to share more, the three critical first hires when building a cyber function from a blank page, the underrated art of finding a board sponsor before you need one, and the crucial difference between what belongs in an ARC pack versus a full board pack.

     If you have a CFO or a board member in your life, this is the one to forward on
More Technology podcasts
About Cyber Voices
Welcome to CYBER VOICES, where we highlight and celebrate the diverse voices of the Australian cyber community. From top-ranking CISOs and government officials to threat hunters and vulnerability analysts, if there’s a voice to be heard, you’ll hear it on CYBER VOICES. Join us as we delve into the stories, insights, and expertise that shape the world of cybersecurity in Australia.
Podcast website

Listen to Cyber Voices, Search Engine and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features