08 Sep 2027
Sydney
97d 17h 34m
until doors open
Inaugural Event

Sydney Cyber in FSI Summit 2027

Security

Join us at the inaugural Sydney Cyber in FSI Summit. CISOs, risk, and technology leaders from banking, superannuation, and insurance come together for one day of practitioner-led sessions on AI-enabled fraud, CPS 230 and CPS 234 in practice, and securing an increasingly outsourced financial system. Free-to-attend.

September 8, 2027
Wednesday
8:30am - 4:45pm
AEST
Doltone House Hyde Park
3/181 Elizabeth St, Sydney NSW 2000
Free to attend
Industry practitioners

The resilience playbook for security leaders in financial services.

Free to attend
60-second registration
Instant confirmation
What you'll walk out with

Concrete deliverables, not just notes.

1

Roundtable Discussions

Small groups, real problems, peers in your seat.

2

Keynote Presentations

Practitioners sharing what worked, not vendor theory.

3

Panel Discussions

Live debate. Vote and contribute from your phone.

4

1-2-1 Meetings

Matched to your challenges. Optional, never a pitch.

agenda preview

A day designed for momentum.

2 keynotes · 3 panels · 4 "How I Solved" case studies · 1 live audience simulation · roundtables · drinks.

9:20 am

Opening Keynote: The Trillion-Dollar Target: Why Financial Services Sits at the Centre of Australia's Cyber Threat Landscape

Why financial services sits at the centre of Australia's threat landscape.

As Australia's banking, superannuation, and insurance sectors manage the nation's most valuable and sensitive pools of capital and data, they've become the most consistently targeted industry in the country's threat landscape. This keynote looks at the scale of what's at stake and what it demands of security leaders.

  • Understanding what makes the Financial Services sector uniquely attractive to attackers, from systemic economic impact to the sheer concentration of personal and financial data.
  • How AI-accelerated attacks are outpacing security architectures built for a slower-moving threat environment, particularly across institutions carrying significant legacy infrastructure.
  • What does genuine resilience look like under APRA's CPS 230 and CPS 234 expectations, and how do leaders balance regulatory compliance with the reality of an accelerating threat environment?
Collapse
Read more
Keynote
11:25 am

Audience Activity

Tackle a real financial services cybersecurity scenario together with your peers.

A hands-on, interactive session working through a real financial services cybersecurity scenario as a room. Details announced soon.

Collapse
Read more
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real financial services cybersecurity challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
3:10 pm

Think Tank: Securing an Increasingly Outsourced Financial System

Managing exposure to failures originating outside your direct control.

As Australian financial institutions rely on growing networks of cloud providers, fintech partners, and outsourced technology vendors, this session explores how security and risk leaders are managing exposure to failures and breaches originating outside their direct control.

  • How institutions are building continuous visibility into third-party risk rather than relying on annual questionnaires that go stale within months.
  • Lessons on managing incident response, customer communication, and APRA notification when the root cause sits with a service provider, not the institution itself.
  • What happens to institutional resilience when multiple financial services organisations depend on the same small set of critical cloud or technology providers.
Collapse
Read more
8:30 am

Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Collapse
Read more
SOCIAL
9:15 am

Welcome & Opening Remarks

Kick off the day with a welcome from your MC and a look at what's ahead.
Collapse
Read more
9:20 am

Opening Keynote: The Trillion-Dollar Target: Why Financial Services Sits at the Centre of Australia's Cyber Threat Landscape

Why financial services sits at the centre of Australia's threat landscape.

As Australia's banking, superannuation, and insurance sectors manage the nation's most valuable and sensitive pools of capital and data, they've become the most consistently targeted industry in the country's threat landscape. This keynote looks at the scale of what's at stake and what it demands of security leaders.

  • Understanding what makes the Financial Services sector uniquely attractive to attackers, from systemic economic impact to the sheer concentration of personal and financial data.
  • How AI-accelerated attacks are outpacing security architectures built for a slower-moving threat environment, particularly across institutions carrying significant legacy infrastructure.
  • What does genuine resilience look like under APRA's CPS 230 and CPS 234 expectations, and how do leaders balance regulatory compliance with the reality of an accelerating threat environment?
Collapse
Read more
Keynote
9:40 am

Keynote: AI Fraud Meets AI Defence

Matching AI-enabled financial crime with AI-driven defence.

As fraudsters increasingly use AI to generate convincing deepfakes, synthetic identities, and automated social engineering at scale, financial institutions are locked in an accelerating arms race. This keynote examines how fraud and cyber teams are adapting their defences to match the sophistication of AI-enabled financial crime.

  • How AI-generated voice, video, and identity documents are being used to bypass verification processes that weren't designed to detect synthetic media.
  • The tension between deploying increasingly sophisticated AI-driven fraud detection and maintaining the auditability and explainability regulators and customers expect.
  • Why identity verification processes built for a pre-AI threat environment need fundamental redesign, not incremental patching.
Collapse
Read more
Keynote
10:10 am

Panel: From CISO to the Boardroom: Cybersecurity Accountability and Governance in Practice

How CISOs and boards actually work together under rising accountability.

As director and officer accountability for cybersecurity outcomes intensifies under CPS 234 and broader governance expectations, this panel examines how CISOs and boards are actually working together, and where the relationship between technical risk owners and governance bodies still needs to mature.

  • What's actually working in cybersecurity reporting that gives directors genuine ability to exercise informed oversight.
  • How the role is shifting as personal accountability expectations rise, and whether CISOs are being given commensurate authority and resourcing to match that accountability.
  • Lessons on embedding cybersecurity into the same rigorous governance and reporting discipline institutions already apply to credit and market risk.
Collapse
Read more
Panel
10:40 am

How I Solved… Modernising Legacy Core Banking Security

Layered protection for core banking systems too critical to replace.

Carrying decades-old core banking infrastructure too critical and costly to replace outright, one security leader built a layered protection strategy that meaningfully reduced legacy system risk exposure while a longer modernisation program continued in parallel.

  • Why the team abandoned an unrealistic "replace everything fast" ambition in favour of a phased approach that acknowledged genuine business constraints.
  • How network segmentation, enhanced monitoring, and strict access boundaries around legacy systems delivered durable risk reduction in the interim.
  • How the team secured sustained funding for protecting systems slated for eventual retirement, when institutional appetite naturally favoured funding the new platform instead.
Collapse
Read more
case study
10:55 am

Morning Tea & Networking

Recharge with refreshments and structured networking with your peers.
Collapse
Read more
SOCIAL
11:25 am

Audience Activity

Tackle a real financial services cybersecurity scenario together with your peers.

A hands-on, interactive session working through a real financial services cybersecurity scenario as a room. Details announced soon.

Collapse
Read more
11:40 am

How I Solved… Giving the Board Actionable Cybersecurity Reporting

Translating technical exposure into decisions directors can act on.

Facing a board frustrated by cybersecurity reports full of technical jargon and unclear risk implications, one CISO redesigned board reporting to translate technical exposure into decisions directors could genuinely own and act on.

  • How the team identified that technical completeness was actually obscuring the risk picture rather than clarifying it for a non-technical board.
  • The specific changes made to translate vulnerability counts and threat intelligence into potential business impact and financial exposure.
  • How reporting frequency and format were redesigned so the board could track risk trends over time, not just react to point-in-time snapshots.
Collapse
Read more
case study
11:55 am

How I Solved… Consolidating Third-Party Risk Visibility

One consolidated third-party risk view satisfying CPS 230 and reality.

With operational risk increasingly concentrated in a sprawling, poorly tracked network of technology vendors and service providers, one institution built a consolidated third-party risk view that satisfied both CPS 230 obligations and genuine operational need.

  • How the team uncovered far more third-party dependencies than existing records showed, and why that gap itself was the first risk finding.
  • Building a risk-based approach that focused monitoring effort on vendors whose failure would genuinely disrupt critical operations.
  • How the team moved from point-in-time vendor assessments to continuous monitoring that could flag emerging risk between review cycles.
Collapse
Read more
case study
12:10 pm

Panel: Operational Resilience in Practice

What genuine CPS 230 implementation looks like beyond the paperwork.

With APRA's CPS 230 operational risk standard now fully in force, this panel brings together risk and resilience leaders from banking, superannuation, and insurance to share what genuine implementation has looked like in practice; beyond the compliance documentation.

  • Common blind spots surfaced once organisations moved from documenting resilience to actually testing it under CPS 230's requirements.
  • How leading institutions are keeping their understanding of critical operations current as systems, vendors, and dependencies constantly change.
  • How risk leaders are managing the tension between meeting APRA's expectations on schedule and building resilience that will actually hold up in a real incident.
Collapse
Read more
Panel
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real financial services cybersecurity challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
1:30 pm

Lunch & Networking

Enjoy a complimentary lunch while connecting with fellow attendees.
Collapse
Read more
SOCIAL
2:20 pm

QuickFire Quiz: Test Your Knowledge Against Your Peers

Test your knowledge in a fast-paced quiz — the top scorer takes the crown.

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

Collapse
Read more
SOCIAL
2:35 pm

How I Solved… Detecting Deepfake-Enabled Fraud

Catching AI-generated fraud attempts before they succeed.

After a near-miss involving a convincing deepfake voice call attempting to authorise a large funds transfer, one financial crime leader built a detection and verification framework specifically designed to catch AI-generated fraud attempts before they succeeded.

  • How the team used a caught attempt as the catalyst for systemic change, rather than treating it as a one-off close call.
  • Designing additional verification steps for high-risk transaction types without slowing down the vast majority of legitimate customer interactions.
  • How human judgement and escalation protocols were rebuilt alongside the technical detection layer.
Collapse
Read more
case study
2:50 pm

Keynote: Board Accountability and the CPS 234 Reality Check

What 'reasonable steps' actually means under CPS 234.

As boards face growing personal and institutional accountability for cybersecurity outcomes under APRA's CPS 234 and broader director duties, this keynote explores what regulators and courts are actually expecting when they assess whether an institution took "reasonable steps" to protect its systems and data.

  • Drawing on recent regulatory actions and enforcement guidance to clarify what evidence institutions need to demonstrate adequate cybersecurity governance.
  • How CISOs and risk leaders are building reporting that gives boards genuine ability to exercise oversight, rather than simply satisfying a compliance reporting obligation.
  • How growing individual liability for directors and officers is changing the seriousness and rigour with which cybersecurity risk is discussed in the boardroom.
Collapse
Read more
Keynote
3:10 pm

Think Tank: Securing an Increasingly Outsourced Financial System

Managing exposure to failures originating outside your direct control.

As Australian financial institutions rely on growing networks of cloud providers, fintech partners, and outsourced technology vendors, this session explores how security and risk leaders are managing exposure to failures and breaches originating outside their direct control.

  • How institutions are building continuous visibility into third-party risk rather than relying on annual questionnaires that go stale within months.
  • Lessons on managing incident response, customer communication, and APRA notification when the root cause sits with a service provider, not the institution itself.
  • What happens to institutional resilience when multiple financial services organisations depend on the same small set of critical cloud or technology providers.
Collapse
Read more
3:40 pm

Closing Remarks & Prize Draw

Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Collapse
Read more
3:45 pm

Networking Drinks Hour

Unwind with your peers for a couple of drinks on us!

Unwind with your peers for a couple of drinks on us!

Collapse
Read more
SOCIAL
4:45 pm

Event Closed

Collapse
Read more
8:30 am

Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Collapse
Read more
SOCIAL
9:15 am

Welcome & Opening Remarks

Kick off the day with a welcome from your MC and a look at what's ahead.
Collapse
Read more
9:20 am

Opening Keynote: The Trillion-Dollar Target: Why Financial Services Sits at the Centre of Australia's Cyber Threat Landscape

Why financial services sits at the centre of Australia's threat landscape.

As Australia's banking, superannuation, and insurance sectors manage the nation's most valuable and sensitive pools of capital and data, they've become the most consistently targeted industry in the country's threat landscape. This keynote looks at the scale of what's at stake and what it demands of security leaders.

  • Understanding what makes the Financial Services sector uniquely attractive to attackers, from systemic economic impact to the sheer concentration of personal and financial data.
  • How AI-accelerated attacks are outpacing security architectures built for a slower-moving threat environment, particularly across institutions carrying significant legacy infrastructure.
  • What does genuine resilience look like under APRA's CPS 230 and CPS 234 expectations, and how do leaders balance regulatory compliance with the reality of an accelerating threat environment?
Collapse
Read more
Keynote
9:40 am

Keynote: AI Fraud Meets AI Defence

Matching AI-enabled financial crime with AI-driven defence.

As fraudsters increasingly use AI to generate convincing deepfakes, synthetic identities, and automated social engineering at scale, financial institutions are locked in an accelerating arms race. This keynote examines how fraud and cyber teams are adapting their defences to match the sophistication of AI-enabled financial crime.

  • How AI-generated voice, video, and identity documents are being used to bypass verification processes that weren't designed to detect synthetic media.
  • The tension between deploying increasingly sophisticated AI-driven fraud detection and maintaining the auditability and explainability regulators and customers expect.
  • Why identity verification processes built for a pre-AI threat environment need fundamental redesign, not incremental patching.
Collapse
Read more
Keynote
10:10 am

Panel: From CISO to the Boardroom: Cybersecurity Accountability and Governance in Practice

How CISOs and boards actually work together under rising accountability.

As director and officer accountability for cybersecurity outcomes intensifies under CPS 234 and broader governance expectations, this panel examines how CISOs and boards are actually working together, and where the relationship between technical risk owners and governance bodies still needs to mature.

  • What's actually working in cybersecurity reporting that gives directors genuine ability to exercise informed oversight.
  • How the role is shifting as personal accountability expectations rise, and whether CISOs are being given commensurate authority and resourcing to match that accountability.
  • Lessons on embedding cybersecurity into the same rigorous governance and reporting discipline institutions already apply to credit and market risk.
Collapse
Read more
Panel
10:40 am

How I Solved… Modernising Legacy Core Banking Security

Layered protection for core banking systems too critical to replace.

Carrying decades-old core banking infrastructure too critical and costly to replace outright, one security leader built a layered protection strategy that meaningfully reduced legacy system risk exposure while a longer modernisation program continued in parallel.

  • Why the team abandoned an unrealistic "replace everything fast" ambition in favour of a phased approach that acknowledged genuine business constraints.
  • How network segmentation, enhanced monitoring, and strict access boundaries around legacy systems delivered durable risk reduction in the interim.
  • How the team secured sustained funding for protecting systems slated for eventual retirement, when institutional appetite naturally favoured funding the new platform instead.
Collapse
Read more
case study
10:55 am

Morning Tea & Networking

Recharge with refreshments and structured networking with your peers.
Collapse
Read more
SOCIAL
11:25 am

Audience Activity

Tackle a real financial services cybersecurity scenario together with your peers.

A hands-on, interactive session working through a real financial services cybersecurity scenario as a room. Details announced soon.

Collapse
Read more
11:40 am

How I Solved… Giving the Board Actionable Cybersecurity Reporting

Translating technical exposure into decisions directors can act on.

Facing a board frustrated by cybersecurity reports full of technical jargon and unclear risk implications, one CISO redesigned board reporting to translate technical exposure into decisions directors could genuinely own and act on.

  • How the team identified that technical completeness was actually obscuring the risk picture rather than clarifying it for a non-technical board.
  • The specific changes made to translate vulnerability counts and threat intelligence into potential business impact and financial exposure.
  • How reporting frequency and format were redesigned so the board could track risk trends over time, not just react to point-in-time snapshots.
Collapse
Read more
case study
11:55 am

How I Solved… Consolidating Third-Party Risk Visibility

One consolidated third-party risk view satisfying CPS 230 and reality.

With operational risk increasingly concentrated in a sprawling, poorly tracked network of technology vendors and service providers, one institution built a consolidated third-party risk view that satisfied both CPS 230 obligations and genuine operational need.

  • How the team uncovered far more third-party dependencies than existing records showed, and why that gap itself was the first risk finding.
  • Building a risk-based approach that focused monitoring effort on vendors whose failure would genuinely disrupt critical operations.
  • How the team moved from point-in-time vendor assessments to continuous monitoring that could flag emerging risk between review cycles.
Collapse
Read more
case study
12:10 pm

Panel: Operational Resilience in Practice

What genuine CPS 230 implementation looks like beyond the paperwork.

With APRA's CPS 230 operational risk standard now fully in force, this panel brings together risk and resilience leaders from banking, superannuation, and insurance to share what genuine implementation has looked like in practice; beyond the compliance documentation.

  • Common blind spots surfaced once organisations moved from documenting resilience to actually testing it under CPS 230's requirements.
  • How leading institutions are keeping their understanding of critical operations current as systems, vendors, and dependencies constantly change.
  • How risk leaders are managing the tension between meeting APRA's expectations on schedule and building resilience that will actually hold up in a real incident.
Collapse
Read more
Panel
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real financial services cybersecurity challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
1:30 pm

Lunch & Networking

Enjoy a complimentary lunch while connecting with fellow attendees.
Collapse
Read more
SOCIAL
2:20 pm

QuickFire Quiz: Test Your Knowledge Against Your Peers

Test your knowledge in a fast-paced quiz — the top scorer takes the crown.

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

Collapse
Read more
SOCIAL
2:35 pm

How I Solved… Detecting Deepfake-Enabled Fraud

Catching AI-generated fraud attempts before they succeed.

After a near-miss involving a convincing deepfake voice call attempting to authorise a large funds transfer, one financial crime leader built a detection and verification framework specifically designed to catch AI-generated fraud attempts before they succeeded.

  • How the team used a caught attempt as the catalyst for systemic change, rather than treating it as a one-off close call.
  • Designing additional verification steps for high-risk transaction types without slowing down the vast majority of legitimate customer interactions.
  • How human judgement and escalation protocols were rebuilt alongside the technical detection layer.
Collapse
Read more
case study
2:50 pm

Keynote: Board Accountability and the CPS 234 Reality Check

What 'reasonable steps' actually means under CPS 234.

As boards face growing personal and institutional accountability for cybersecurity outcomes under APRA's CPS 234 and broader director duties, this keynote explores what regulators and courts are actually expecting when they assess whether an institution took "reasonable steps" to protect its systems and data.

  • Drawing on recent regulatory actions and enforcement guidance to clarify what evidence institutions need to demonstrate adequate cybersecurity governance.
  • How CISOs and risk leaders are building reporting that gives boards genuine ability to exercise oversight, rather than simply satisfying a compliance reporting obligation.
  • How growing individual liability for directors and officers is changing the seriousness and rigour with which cybersecurity risk is discussed in the boardroom.
Collapse
Read more
Keynote
3:10 pm

Think Tank: Securing an Increasingly Outsourced Financial System

Managing exposure to failures originating outside your direct control.

As Australian financial institutions rely on growing networks of cloud providers, fintech partners, and outsourced technology vendors, this session explores how security and risk leaders are managing exposure to failures and breaches originating outside their direct control.

  • How institutions are building continuous visibility into third-party risk rather than relying on annual questionnaires that go stale within months.
  • Lessons on managing incident response, customer communication, and APRA notification when the root cause sits with a service provider, not the institution itself.
  • What happens to institutional resilience when multiple financial services organisations depend on the same small set of critical cloud or technology providers.
Collapse
Read more
3:40 pm

Closing Remarks & Prize Draw

Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Collapse
Read more
3:45 pm

Networking Drinks Hour

Unwind with your peers for a couple of drinks on us!

Unwind with your peers for a couple of drinks on us!

Collapse
Read more
SOCIAL
4:45 pm

Event Closed

Collapse
Read more
What attendees say

Why engineering leaders return year after year.

4.7 / 5
Average attendee rating
Across all 2025 events
94%
Rate our content extremely relevant
Keynotes
panels
case studies
100%
Would recommend us to a colleague
2025 post-event survey
It was inspiring to attend today's live discussions with technology leaders exploring the future of AI innovation, strategy, security, and responsible adoption. One key message stood out: AI success is not just about selecting the right model, it is about building the right ecosystem around it.
Souparna Chatterjee
Technology Lead, Bupa
Fantastic event, great speakers, strong discussions and a genuinely interactive format. The live audience polls, scenario-based group activities, and infrastructure think tank were particular highlights. Seeing the room vote on real trade-offs, discuss them, and then change its position as new perspectives emerged showed just how complex many AI infrastructure decisions remain.
Chris Yang
Principal Consultant, Data & AI, Davidson
Clutch Events, it was a top tier event. Loved the interactive session.
Sunit Saha
Software Engineer, AI Systems & Product Engineering, Funlab
Past Speakers
No items found.
Past Sponsors
No items found.
Partners

Backed by the platforms your team actually runs on

Looking to partner? Get in touch
Reach Danny Perry, Director of Sales
Get the partner pack
Register

Register in under 60 seconds.

Complimentary Full-day access to keynotes, panels & case studies

Includes catering & post-event drinks.
Opens a 60-second form
no payment details
Instant confirmation
FAQ's

Common questions.

What do I need to bring?

Just bring yourself, your laptop or a notebook and get ready to collaborate!

Will sessions be recorded or live-streamed?

No. You'll have to be there to enjoy the sessions.

Will there be WiFi?

Yes, absolutely! Stay connected at the event with complimentary wifi - we'll share the details at the event.

Will food and drinks be provided?

Yes, morning tea, lunch, and afternoon refreshments will be provided. Please indicate any dietary requirements during registration.

Are Chatham House Rules in effect?

Absolutely! No media, recordings, or live streaming... what happens in the room, stays in the room.

What is the dress code?

Smart casual or business casual is recommended, no need for a suit and tie! Keep it comfortable.

Are there any fees to attend?

Nope! The conference is completely free for industry professionals. Contact us if you are not sure whether you qualify.

Venue

Getting there.

Sydney
Doltone House Hyde Park
3/181 Elizabeth St, Sydney NSW 2000
Sydney
·
September 8, 2027

97 days left.
Register free today.

Be the engineering leader in the room — not the one reading the LinkedIn recap.

Free to attend
60-second registration
Instant confirmation

Contact our event team for any enquiry

Director of Sales
Danny Perry
For sponsorship opportunities.
danny@clutchgroup.co
Director of Client Relations
Lili Munar
For guest and attendee enquiries.
lilibeth@clutchgroup.co
Director of Conference Production
Steph Tolmie
For speaking opportunities & content enquiries.
stephanie@clutchevents.co
Director of Operations
Taylor Stanyon
For event-related enquiries.
taylor@clutchgroup.co