14 Oct 2027
Sydney
97d 17h 34m
until doors open
Inaugural Event

Sydney Data Protection & Security Summit 2027

Privacy

Join us at the inaugural Sydney Data Protection & Security Summit. Privacy, security, and IT leaders come together for one day of practitioner-led sessions on meeting Australia's strengthened privacy obligations, defending against AI-speed attacks, and securing data you don't fully control. Free-to-attend.

October 14, 2027
Thursday
8:30am - 4:45pm
AEST
ICC Sydney
14 Darling Dr, Sydney NSW 2000
Free to attend
Industry practitioners

The protection playbook for leaders safeguarding data in an AI-driven world.

Free to attend
60-second registration
Instant confirmation
What you'll walk out with

Concrete deliverables, not just notes.

1

Roundtable Discussions

Small groups, real problems, peers in your seat.

2

Keynote Presentations

Practitioners sharing what worked, not vendor theory.

3

Panel Discussions

Live debate. Vote and contribute from your phone.

4

1-2-1 Meetings

Matched to your challenges. Optional, never a pitch.

agenda preview

A day designed for momentum.

2 keynotes · 3 panels · 4 "How I Solved" case studies · 1 live audience simulation · roundtables · drinks.

9:20 am

Opening Keynote: The Trust Deficit: Why Data Protection Needs to Become a Growth Strategy

Reframing trust, security, and privacy as the foundation of AI success.

As AI reshapes how organisations collect, process, and act on data, the old framing of data protection as a defensive cost centre is running out of road — this keynote sets the tone for the day by reframing trust, security, and privacy as the foundation for whether AI-driven transformation succeeds or stalls.

  • With customers, regulators, and employees increasingly wary of how their data fuels AI systems, the organisations that treat transparency and control as differentiators (not just compliance obligations) are the ones building durable advantage.
  • Why the mindset shift from "responding to breaches" to "architecting for inevitability" is what separates organisations that recover quickly from those that suffer lasting reputational and regulatory damage.
  • Framing the questions every session will return to: Who's accountable when AI systems handle sensitive data? What does "good enough" security look like when threats and technology are both moving this fast? And how do leaders balance urgency with judgement?
Collapse
Read more
Keynote
11:25 am

Audience Activity

Tackle a real data protection and security scenario together with your peers.

A hands-on, interactive session working through a real data protection and security scenario as a room. Details announced soon.

Collapse
Read more
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real data protection and security challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
3:10 pm

Think Tank: Third-Party and Supply Chain Risk: Securing Data You Don't Fully Control

Securing sensitive data flowing through systems you don't control.

As enterprises rely on growing networks of AI vendors, SaaS platforms, and outsourced service providers, sensitive data increasingly flows through systems organisations neither built nor fully control; turning vendor risk management into one of the hardest unsolved problems in data protection.

  • Why static vendor assessments fail to capture real-time risk, and what continuous monitoring of third-party access actually looks like in practice.
  • The unique challenges of assessing AI and model providers, where questions about training data use, data retention, and model behaviour go beyond traditional security due diligence.
  • Lessons from real incidents on managing incident response, regulatory notification, and reputational fallout when the failure originated outside your own walls.
Collapse
Read more
8:30 am

Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Collapse
Read more
SOCIAL
9:15 am

Welcome & Opening Remarks

Kick off the day with a welcome from your MC and a look at what's ahead.
Collapse
Read more
9:20 am

Opening Keynote: The Trust Deficit: Why Data Protection Needs to Become a Growth Strategy

Reframing trust, security, and privacy as the foundation of AI success.

As AI reshapes how organisations collect, process, and act on data, the old framing of data protection as a defensive cost centre is running out of road — this keynote sets the tone for the day by reframing trust, security, and privacy as the foundation for whether AI-driven transformation succeeds or stalls.

  • With customers, regulators, and employees increasingly wary of how their data fuels AI systems, the organisations that treat transparency and control as differentiators (not just compliance obligations) are the ones building durable advantage.
  • Why the mindset shift from "responding to breaches" to "architecting for inevitability" is what separates organisations that recover quickly from those that suffer lasting reputational and regulatory damage.
  • Framing the questions every session will return to: Who's accountable when AI systems handle sensitive data? What does "good enough" security look like when threats and technology are both moving this fast? And how do leaders balance urgency with judgement?
Collapse
Read more
Keynote
9:40 am

Keynote: Redesigning Access Controls for an AI-Augmented Workforce

Extending access discipline to an AI-augmented workforce.

As AI copilots, agents, and analytics tools require broader, faster access to enterprise data to deliver value, organisations face a widening tension between empowering AI-augmented employees and maintaining the access discipline that data protection has always depended on.

  • How AI agents and copilots blur the traditional boundary between "user" and "system," and why identity and access management frameworks built for people don't cleanly extend to autonomous tools.
  • Moving away from broad, standing permissions toward dynamic, context-aware access that grants AI tools and employees only what's needed for the task at hand.
  • Giving finance and business leaders a practical framework for weighing productivity gains from broader data access against quantifiable increases in breach exposure and regulatory risk.
Collapse
Read more
Keynote
10:10 am

Panel: Navigating Privacy Reform, Cross-Border Data Rules, and AI-Specific Regulation Simultaneously

Managing privacy reform, cross-border rules, and AI regulation at once.

Privacy and security leaders are no longer managing one regulatory relationship; they're navigating overlapping and sometimes conflicting obligations across privacy law reform, sector-specific rules, and emerging AI governance requirements, often with limited resourcing to do it all well.

  • Practical approaches to building compliance programs flexible enough to absorb reform without constant rebuilds.
  • How organisations operating across APAC are managing divergent data residency and transfer requirements without duplicating infrastructure for every jurisdiction.
  • Shifting compliance from a post-hoc legal review into an input that shapes how AI and data systems are architected from day one.
Collapse
Read more
Panel
10:40 am

How I Solved… Shutting Down Shadow AI Without Shutting Down Innovation

Bringing shadow AI into the light without a workforce backlash.

With employees adopting AI tools faster than IT could track or approve them, one security leader built a discovery and governance approach that brought unauthorised AI usage into the light — without triggering a workforce backlash or slowing legitimate innovation.

  • How the team mapped unsanctioned AI tool usage across the organisation before deciding on any policy response, since you can't govern what you can't see.
  • Designing an approval pathway fast enough that employees chose to use it rather than route around it, turning shadow AI into managed AI.
  • Building lightweight, continuous visibility into new AI tools.
Collapse
Read more
case study
10:55 am

Morning Tea & Networking

Recharge with refreshments and structured networking with your peers.
Collapse
Read more
SOCIAL
11:25 am

Audience Activity

Tackle a real data protection and security scenario together with your peers.

A hands-on, interactive session working through a real data protection and security scenario as a room. Details announced soon.

Collapse
Read more
11:40 am

How I Solved… Securing Legacy Systems That Can't Be Replaced Overnight

Layered protection for legacy systems that can't be replaced overnight.

With critical infrastructure and legacy platforms too costly or risky to replace outright, one security leader built a layered protection strategy that meaningfully reduced risk exposure without waiting for a full modernisation program.

  • Triaging legacy system vulnerabilities realistically, rather than pursuing an unachievable "patch everything" strategy.
  • How network segmentation, enhanced monitoring, and strict access controls around legacy systems provided durable risk reduction, not just a stopgap.
  • Building the business case for ongoing investment in legacy security, when the instinct is often to deprioritise spending on systems slated for eventual retirement.
Collapse
Read more
case study
11:55 am

How I Solved… Data Classification That Sticks

Data classification employees actually follow.

After years of data classification policies that existed on paper but were ignored in practice, one data protection leader built a classification approach employees actually followed, turning a compliance exercise into a functioning control.

  • Recognising that asking employees to correctly label sensitive data by hand was never going to scale, and redesigning around automated detection instead.
  • How classification was built into the tools people already used daily, rather than requiring a separate step that competed with getting work done.
  • How accurate classification became the foundation for access controls, DLP policies, and AI governance decisions downstream.
Collapse
Read more
case study
12:10 pm

Panel: Legal Liability and Trust in an AI-Driven Data Landscape

Where liability sits when AI-driven decisions go wrong.

As AI systems make decisions with real legal and financial consequences, organisations are discovering that liability frameworks built for human decision-making don't map cleanly onto AI-driven processes; leaving legal, privacy, and security leaders to navigate accountability, contracts, and customer trust largely without settled precedent.

  • When an AI system's decision leads to a data breach, discriminatory outcome, or regulatory breach, how are legal teams currently allocating fault between the organisation, the AI vendor, and the underlying model provider; and where does existing law simply not have an answer yet?
  • How eroded customer trust following an AI-related incident is increasingly translating into legal action and what that means for how legal and privacy teams collaborate on incident response.
  • Exploring the tension between regulatory and legal expectations for transparency and explainability, and the practical reality that many AI systems can't yet provide a clear, defensible account of how a specific decision was made.
Collapse
Read more
Panel
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real data protection and security challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
1:30 pm

Lunch & Networking

Enjoy a complimentary lunch while connecting with fellow attendees.
Collapse
Read more
SOCIAL
2:20 pm

QuickFire Quiz: Test Your Knowledge Against Your Peers

Test your knowledge in a fast-paced quiz — the top scorer takes the crown.

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

Collapse
Read more
SOCIAL
2:35 pm

How I Solved… Cutting Breach Detection Time from Weeks to Hours

Compressing the time between compromise and containment.

Facing a security team stretched thin and alert fatigue eroding response quality, one CISO restructured detection and triage around automation and prioritisation; dramatically compressing the time between compromise and containment.

  • How the team re-engineered alert prioritisation so analysts spent time on genuine threats instead of drowning in low-value notifications.
  • Where automated containment actions (isolating endpoints, revoking access) were safely delegated to systems versus kept as human decisions.
  • How the leader secured budget and buy-in for detection tooling improvements proactively, before an incident forced the issue.
Collapse
Read more
case study
2:50 pm

Keynote: Breach-Ready by Design: Rethinking Incident Response in the Age of AI-Speed Attacks

Rebuilding incident response for machine-speed attacks.

As AI accelerates both attack sophistication and organisational response capabilities, traditional incident response playbooks are becoming dangerously outdated, forcing security leaders to rebuild readiness around machine-speed detection and response.

  • How AI-powered attacks (automated phishing, deepfake-enabled social engineering, AI-assisted lateral movement) have shrunk the window between initial compromise and material damage, and what that means for detection SLAs.
  • Where automated triage and containment genuinely reduce risk versus where removing human judgement from the incident response chain creates new liability.
  • How faster, more complex breaches are colliding with notification obligations under the Australian Privacy Act, and what "reasonable steps" now looks like when regulators expect speed AI hasn't universally delivered yet.
Collapse
Read more
Keynote
3:10 pm

Think Tank: Third-Party and Supply Chain Risk: Securing Data You Don't Fully Control

Securing sensitive data flowing through systems you don't control.

As enterprises rely on growing networks of AI vendors, SaaS platforms, and outsourced service providers, sensitive data increasingly flows through systems organisations neither built nor fully control; turning vendor risk management into one of the hardest unsolved problems in data protection.

  • Why static vendor assessments fail to capture real-time risk, and what continuous monitoring of third-party access actually looks like in practice.
  • The unique challenges of assessing AI and model providers, where questions about training data use, data retention, and model behaviour go beyond traditional security due diligence.
  • Lessons from real incidents on managing incident response, regulatory notification, and reputational fallout when the failure originated outside your own walls.
Collapse
Read more
3:40 pm

Closing Remarks & Prize Draw

Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Collapse
Read more
3:45 pm

Networking Drinks Hour

Unwind with your peers for a couple of drinks on us!

Unwind with your peers for a couple of drinks on us!

Collapse
Read more
SOCIAL
4:45 pm

Event Closed

Collapse
Read more
8:30 am

Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

Collapse
Read more
SOCIAL
9:15 am

Welcome & Opening Remarks

Kick off the day with a welcome from your MC and a look at what's ahead.
Collapse
Read more
9:20 am

Opening Keynote: The Trust Deficit: Why Data Protection Needs to Become a Growth Strategy

Reframing trust, security, and privacy as the foundation of AI success.

As AI reshapes how organisations collect, process, and act on data, the old framing of data protection as a defensive cost centre is running out of road — this keynote sets the tone for the day by reframing trust, security, and privacy as the foundation for whether AI-driven transformation succeeds or stalls.

  • With customers, regulators, and employees increasingly wary of how their data fuels AI systems, the organisations that treat transparency and control as differentiators (not just compliance obligations) are the ones building durable advantage.
  • Why the mindset shift from "responding to breaches" to "architecting for inevitability" is what separates organisations that recover quickly from those that suffer lasting reputational and regulatory damage.
  • Framing the questions every session will return to: Who's accountable when AI systems handle sensitive data? What does "good enough" security look like when threats and technology are both moving this fast? And how do leaders balance urgency with judgement?
Collapse
Read more
Keynote
9:40 am

Keynote: Redesigning Access Controls for an AI-Augmented Workforce

Extending access discipline to an AI-augmented workforce.

As AI copilots, agents, and analytics tools require broader, faster access to enterprise data to deliver value, organisations face a widening tension between empowering AI-augmented employees and maintaining the access discipline that data protection has always depended on.

  • How AI agents and copilots blur the traditional boundary between "user" and "system," and why identity and access management frameworks built for people don't cleanly extend to autonomous tools.
  • Moving away from broad, standing permissions toward dynamic, context-aware access that grants AI tools and employees only what's needed for the task at hand.
  • Giving finance and business leaders a practical framework for weighing productivity gains from broader data access against quantifiable increases in breach exposure and regulatory risk.
Collapse
Read more
Keynote
10:10 am

Panel: Navigating Privacy Reform, Cross-Border Data Rules, and AI-Specific Regulation Simultaneously

Managing privacy reform, cross-border rules, and AI regulation at once.

Privacy and security leaders are no longer managing one regulatory relationship; they're navigating overlapping and sometimes conflicting obligations across privacy law reform, sector-specific rules, and emerging AI governance requirements, often with limited resourcing to do it all well.

  • Practical approaches to building compliance programs flexible enough to absorb reform without constant rebuilds.
  • How organisations operating across APAC are managing divergent data residency and transfer requirements without duplicating infrastructure for every jurisdiction.
  • Shifting compliance from a post-hoc legal review into an input that shapes how AI and data systems are architected from day one.
Collapse
Read more
Panel
10:40 am

How I Solved… Shutting Down Shadow AI Without Shutting Down Innovation

Bringing shadow AI into the light without a workforce backlash.

With employees adopting AI tools faster than IT could track or approve them, one security leader built a discovery and governance approach that brought unauthorised AI usage into the light — without triggering a workforce backlash or slowing legitimate innovation.

  • How the team mapped unsanctioned AI tool usage across the organisation before deciding on any policy response, since you can't govern what you can't see.
  • Designing an approval pathway fast enough that employees chose to use it rather than route around it, turning shadow AI into managed AI.
  • Building lightweight, continuous visibility into new AI tools.
Collapse
Read more
case study
10:55 am

Morning Tea & Networking

Recharge with refreshments and structured networking with your peers.
Collapse
Read more
SOCIAL
11:25 am

Audience Activity

Tackle a real data protection and security scenario together with your peers.

A hands-on, interactive session working through a real data protection and security scenario as a room. Details announced soon.

Collapse
Read more
11:40 am

How I Solved… Securing Legacy Systems That Can't Be Replaced Overnight

Layered protection for legacy systems that can't be replaced overnight.

With critical infrastructure and legacy platforms too costly or risky to replace outright, one security leader built a layered protection strategy that meaningfully reduced risk exposure without waiting for a full modernisation program.

  • Triaging legacy system vulnerabilities realistically, rather than pursuing an unachievable "patch everything" strategy.
  • How network segmentation, enhanced monitoring, and strict access controls around legacy systems provided durable risk reduction, not just a stopgap.
  • Building the business case for ongoing investment in legacy security, when the instinct is often to deprioritise spending on systems slated for eventual retirement.
Collapse
Read more
case study
11:55 am

How I Solved… Data Classification That Sticks

Data classification employees actually follow.

After years of data classification policies that existed on paper but were ignored in practice, one data protection leader built a classification approach employees actually followed, turning a compliance exercise into a functioning control.

  • Recognising that asking employees to correctly label sensitive data by hand was never going to scale, and redesigning around automated detection instead.
  • How classification was built into the tools people already used daily, rather than requiring a separate step that competed with getting work done.
  • How accurate classification became the foundation for access controls, DLP policies, and AI governance decisions downstream.
Collapse
Read more
case study
12:10 pm

Panel: Legal Liability and Trust in an AI-Driven Data Landscape

Where liability sits when AI-driven decisions go wrong.

As AI systems make decisions with real legal and financial consequences, organisations are discovering that liability frameworks built for human decision-making don't map cleanly onto AI-driven processes; leaving legal, privacy, and security leaders to navigate accountability, contracts, and customer trust largely without settled precedent.

  • When an AI system's decision leads to a data breach, discriminatory outcome, or regulatory breach, how are legal teams currently allocating fault between the organisation, the AI vendor, and the underlying model provider; and where does existing law simply not have an answer yet?
  • How eroded customer trust following an AI-related incident is increasingly translating into legal action and what that means for how legal and privacy teams collaborate on incident response.
  • Exploring the tension between regulatory and legal expectations for transparency and explainability, and the practical reality that many AI systems can't yet provide a clear, defensible account of how a specific decision was made.
Collapse
Read more
Panel
12:40 pm

Peer Roundtables

Small-group problem-solving with people in similar roles — topics announced soon.

Small-group, discussion-based sessions where you'll work through real data protection and security challenges with peers in similar roles. Roundtable topics will be announced soon.

Collapse
Read more
1:30 pm

Lunch & Networking

Enjoy a complimentary lunch while connecting with fellow attendees.
Collapse
Read more
SOCIAL
2:20 pm

QuickFire Quiz: Test Your Knowledge Against Your Peers

Test your knowledge in a fast-paced quiz — the top scorer takes the crown.

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights — and a voucher — as the top scorer takes the crown.

Collapse
Read more
SOCIAL
2:35 pm

How I Solved… Cutting Breach Detection Time from Weeks to Hours

Compressing the time between compromise and containment.

Facing a security team stretched thin and alert fatigue eroding response quality, one CISO restructured detection and triage around automation and prioritisation; dramatically compressing the time between compromise and containment.

  • How the team re-engineered alert prioritisation so analysts spent time on genuine threats instead of drowning in low-value notifications.
  • Where automated containment actions (isolating endpoints, revoking access) were safely delegated to systems versus kept as human decisions.
  • How the leader secured budget and buy-in for detection tooling improvements proactively, before an incident forced the issue.
Collapse
Read more
case study
2:50 pm

Keynote: Breach-Ready by Design: Rethinking Incident Response in the Age of AI-Speed Attacks

Rebuilding incident response for machine-speed attacks.

As AI accelerates both attack sophistication and organisational response capabilities, traditional incident response playbooks are becoming dangerously outdated, forcing security leaders to rebuild readiness around machine-speed detection and response.

  • How AI-powered attacks (automated phishing, deepfake-enabled social engineering, AI-assisted lateral movement) have shrunk the window between initial compromise and material damage, and what that means for detection SLAs.
  • Where automated triage and containment genuinely reduce risk versus where removing human judgement from the incident response chain creates new liability.
  • How faster, more complex breaches are colliding with notification obligations under the Australian Privacy Act, and what "reasonable steps" now looks like when regulators expect speed AI hasn't universally delivered yet.
Collapse
Read more
Keynote
3:10 pm

Think Tank: Third-Party and Supply Chain Risk: Securing Data You Don't Fully Control

Securing sensitive data flowing through systems you don't control.

As enterprises rely on growing networks of AI vendors, SaaS platforms, and outsourced service providers, sensitive data increasingly flows through systems organisations neither built nor fully control; turning vendor risk management into one of the hardest unsolved problems in data protection.

  • Why static vendor assessments fail to capture real-time risk, and what continuous monitoring of third-party access actually looks like in practice.
  • The unique challenges of assessing AI and model providers, where questions about training data use, data retention, and model behaviour go beyond traditional security due diligence.
  • Lessons from real incidents on managing incident response, regulatory notification, and reputational fallout when the failure originated outside your own walls.
Collapse
Read more
3:40 pm

Closing Remarks & Prize Draw

Wrap-up of the day's key takeaways — and your chance to win some epic prizes.
Collapse
Read more
3:45 pm

Networking Drinks Hour

Unwind with your peers for a couple of drinks on us!

Unwind with your peers for a couple of drinks on us!

Collapse
Read more
SOCIAL
4:45 pm

Event Closed

Collapse
Read more
What attendees say

Why engineering leaders return year after year.

4.7 / 5
Average attendee rating
Across all 2025 events
94%
Rate our content extremely relevant
Keynotes
panels
case studies
100%
Would recommend us to a colleague
2025 post-event survey
What a day at the Melbourne AI Engineering & Infrastructure Summit 2026. Had the privilege of attending this enriching summit packed with insights from some brilliant minds in the AI space. The energy in the room was a reminder of how fast this space is moving and how important it is to keep learning, sharing, and building responsibly. Thank you Clutch Events for events like these that bring the community together.
Anshu Shukla
Engineering Manager, Digital Channels, ANZ
I attended the Melbourne AI Engineering and Infrastructure Summit organised by Clutch Events today with 200+ practitioners, and the live poll result said it all: 42% named cost as their top constraint. The through-line: AI delivers when you plan for the whole journey. Full cost, measured outcomes, continuous observability.
Rajan Rana
Head of AI Enablement & Transformation, Village Roadshow
Great to attend the Melbourne AI Engineering & Infrastructure Summit 2026 and hear practical insights from leaders turning AI ambition into real outcomes. AI success is not about having the biggest model, it is about creating the biggest business impact.
Divya Panwar
Technology, Strategy & Delivery, Telstra
Past Speakers
No items found.
Past Sponsors
No items found.
Partners

Backed by the platforms your team actually runs on

Looking to partner? Get in touch
Reach Danny Perry, Director of Sales
Get the partner pack
Register

Register in under 60 seconds.

Complimentary Full-day access to keynotes, panels & case studies

Includes catering & post-event drinks.
Opens a 60-second form
no payment details
Instant confirmation
FAQ's

Common questions.

What do I need to bring?

Just bring yourself, your laptop or a notebook and get ready to collaborate!

Will sessions be recorded or live-streamed?

No. You'll have to be there to enjoy the sessions.

Will there be WiFi?

Yes, absolutely! Stay connected at the event with complimentary wifi - we'll share the details at the event.

Will food and drinks be provided?

Yes, morning tea, lunch, and afternoon refreshments will be provided. Please indicate any dietary requirements during registration.

Are Chatham House Rules in effect?

Absolutely! No media, recordings, or live streaming... what happens in the room, stays in the room.

What is the dress code?

Smart casual or business casual is recommended, no need for a suit and tie! Keep it comfortable.

Are there any fees to attend?

Nope! The conference is completely free for industry professionals. Contact us if you are not sure whether you qualify.

Venue

Getting there.

Sydney
ICC Sydney
14 Darling Dr, Sydney NSW 2000
Sydney
·
October 14, 2027

97 days left.
Register free today.

Be the engineering leader in the room — not the one reading the LinkedIn recap.

Free to attend
60-second registration
Instant confirmation

Contact our event team for any enquiry

Director of Sales
Danny Perry
For sponsorship opportunities.
danny@clutchgroup.co
Director of Client Relations
Lili Munar
For guest and attendee enquiries.
lilibeth@clutchgroup.co
Director of Conference Production
Steph Tolmie
For speaking opportunities & content enquiries.
stephanie@clutchevents.co
Director of Operations
Taylor Stanyon
For event-related enquiries.
taylor@clutchgroup.co