August 6, 2026
08:30am - 3:30pm
Collins Square Events Centre

Melbourne Secure Software and AppSec Summit 2026

Strengthen your development process with cutting-edge security practices. Connect with experts, explore automation, secure containers, and gain practical insights through interactive sessions and real-world case studies.

Melbourne Secure Software and AppSec Summit 2026
Fortify your software development lifecycle.

We're bringing together developers, security experts, and industry leaders to seamlessly integrate security into every step of your development process.

Discover best practices for shifting left, automating security, and managing open-source risks. Explore how to improve DevSecOps adoption, secure containers and microservices, and weigh in on the debate: automation vs. manual testing. Engage in interactive sessions, real-world case studies, panel discussions, and debates to stay ahead of the latest trends in application security.

Key Themes:

  • Integrating Security into the Software Development Lifecycle
  • Shift Left Strategies
  • Application Breach Response
  • Automating Security Processes
  • Managing Open Source Risks
  • Improving DevSecOps Adoption
  • Container and Microservices Security
  • Automation vs. Manual Testing: What Works Best
Speakers & Full Agenda Announced Soon!

Our speaker lineup will be released in May 2026.

Register now to secure your place and receive announcements when our full program launches.

Our Speakers

Cole Cornford

Cole Cornford

Chief Executive Officer

Agenda

8:30 AM
Registration, Breakfast and Barista Coffee

Get in early avoid the queue hot coffee and fresh made barista coffee.

No items found.
9:15 AM
Welcome & Opening Remarks
No items found.
9:20 AM
Opening Keynote: Securing Autonomous AI Agents: The New Attack Surface No One Is Ready For

AI has shifted from assistants that make suggestions to autonomous agents that can read files, execute commands, call APIs, and modify systems on their own. That change expands the attack surface from prompt injection to full system compromise, lateral movement between agents, and persistent access through memory and tooling.

This session explores how autonomous agents are reshaping the threat model, what early adopters are discovering in practice, and the questions AppSec teams must confront as AI systems gain more autonomy and more potential for harm.

The speaker will cover:

  • New risks from code-executing prompt injection to agent-to-agent lateral movement
  • How teams are designing permissions, audit trails, sandboxing, and monitoring agent behavior
  • Examples of agents being manipulated to exfiltrate data or modify configurations
  • The security shifts required to safely deploy autonomous agents in the next year
No items found.
9:40 AM
Keynote
No items found.
10:10 AM
Panel: The Evolving Supply Chain Risk Landscape: What’s Actually Breaking in Production

Modern applications run on layered platforms, third-party extensions, and AI assisted development and tooling, each introducing dependencies that traditional supply chain controls struggle to track. Even with SBOMs and automated scanning, teams are seeing supply chain risk surface in production through transitive packages, platform abstractions, and components that weren’t visible at build time.

This panel explores how supply chain risks are actually surfacing in real environments and what effective control looks like when dependency sprawl is structural, not accidental.

We'll Cover

  • Where SBOMs help in practice and where they still fall short
  • How layered platforms, third-party extensions, and AI era tooling introduce new blind spots
  • What transitive dependencies, dormant packages, and platform abstractions mean for real-world risk
  • Practical approaches for regaining control without killing development velocity
No items found.
10:40 AM
How I Solved...
No items found.
10:55 AM
Morning Tea and Networking
No items found.
11:25 AM
Audience Activity

In this innovative session, attendees will be faced with a series of scenarios that they may face in their roles. Attendees will discuss the possible courses of action with their peers to consider the ramifications of each option before logging their own course of action.

Results will be tallied and analysed by our session facilitator and results will impact the way the group moves through the activity.

Will we collectively choose the right course of action?

No items found.
11:40 AM
How I Solved...
No items found.
11:55 AM
How I Solved..
No items found.
12:10 PM
Panel: Security vs Velocity: When to Say Yes to Risk (and How to Track What You Said Yes To)

Modern engineering teams move fast, and AppSec teams are constantly negotiating when to block, when to slow down, and when to accept risk to keep delivery on track. As exceptions, waivers, and temporary approvals become part of everyday workflows, many organizations struggle to understand what risks they’ve accepted, why they accepted them, and whether those decisions are still defensible months later.

This panel explores how high-performing teams balance speed with security, how they document and monitor accepted risk, and the frameworks that keep fast-moving environments accountable.

The panel will cover:

  • How teams decide when risk acceptance is justified and when it isn’t
  • Practical approaches to tracking exceptions, waivers, and approvals over time
  • Techniques for documenting context so decisions remain defensible later
  • How AppSec and engineering collaborate to keep velocity without losing control
No items found.
12:40 PM
Roundtable Discussions
No items found.
1:30 PM
Lunch and Networking
No items found.
2:20 PM
QuickFire Quiz: Test Your Knowledge Against Your Peers

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights - and a travel voucher - as the top scorer takes the crown.

No items found.
2:35 PM
Keynote: Building AI-Ready Data Foundations

AI initiatives succeed or fail on the quality of their data. This session explores how organisations are preparing their data environments to support enterprise-scale AI  ensuring information is trustworthy, accessible, and structured for learning. You’ll hear practical strategies for transforming fragmented data pipelines into reliable, high-performance foundations that turn AI experiments into operational success.

We'll cover:

  • Assess Readiness: Learn how to evaluate whether your data is fit for AI adoption.
  • Build Trust: Discover governance, quality, and accessibility practices that scale.
  • Deliver Value: See how mature data foundations accelerate measurable AI outcomes.
No items found.
2:55 PM
Think Tank: The Future Enterprise Workforce: How AI Changes Roles, Teams, and Skills

AI is beginning to influence how teams operate, how work is coordinated, and how roles evolve across the enterprise. But there’s still little agreement on what this means in practice, from where AI assistants fit into daily workflows, to how management layers, team structures, and training approaches may change.

This interactive session puts these questions directly to the audience. Participants vote live on a series of real-world scenarios, explore the results together, and vote again as perspectives shift through the discussion.

We'll Cover:

  • How AI assistants are starting to support individual roles
  • How team structures and management practices may evolve
  • Which skills and training pathways become more critical
  • Early lessons from organisations experimenting with AI in daily work
No items found.
3:25 PM
Closing Remarks
No items found.

Past Speaker Highlights

Warren Bailey

General Manager - DevSecOps Customer and Product, nbn® Australia

Cole Cornford

Chief Executive Officer, Galah Cyber

Neha Malik

Head of Product Security, REA Group

Bari Singh

Technology Executive - Strategic Capabilities, Cloud and Advanced Technologies , GPC Asia Pacific

m Brennan

Group Owner - Developer eXperience, Telstra

Hayden MacKellar

Head of Cyber Security & Assurance, Nuix

Who Attends?

Chief Information Officer

Chief Information Security Officer

Head of DevSecOps and AppSec

Application Security Manager

Head of Application Security

Application Development Director

Application Architects and Engineers

DevOps Director

DevOps Engineer

Head of DevOps

Software Development Director

Head of Development Technology

VP Engineering

Head of Engineering

Man in gray blazer holding a laptop and talking to another man wearing a black jacket with a conference badge, surrounded by other attendees with badges at an indoor event.Audience seated in a conference room watching a speaker present slides about winning fantastic prizes on large screens.Crowd of people networking indoors at a conference or event with informational booths in the background.Audience attentively listening to a speaker in a conference room with round tables and water pitchers.

Attendee Testimonials

No items found.
No items found.
No items found.
No items found.

Our event sponsors

For sponsorship opportunities, please get in touch with Danny Perry, danny@clutchgroup.co

Past Sponsors

Event Location

Collins Square Events Centre

Level 5, Tower 2/727 Collins St, Docklands VIC 3008
Melbourne Secure Software and AppSec Summit 2026

Frequently Asked Questions

No items found.

Get In Touch

Contact our event team for any enquiry

Danny Perry

Director of Sales
For sponsorship opportunities.
danny@clutchgroup.co

Lili Munar

Director of Client Relations
For guest and attendee enquiries.
lilibeth@clutchgroup.co

Steph Tolmie

Director of Conference Production
For speaking opportunities & content enquiries.
stephanie@clutchevents.co

Taylor Stanyon

Director of Operations
For event-related enquiries.
taylor@clutchgroup.co