35 Best Cybersecurity Thought Leaders in ANZ 2026
- Jonno White
- May 12
- 35 min read
Updated: Jun 3
Introduction
Australia is now the world's fifth most powerful cyber nation, and finding the people who are genuinely shaping how the region thinks about cyber risk has never been more important. The Australian cyber security market is projected to reach USD 16.52 billion by 2029, growing at a compound annual rate of 18.44 per cent. New Zealand has just completed the integration of CERT NZ into the National Cyber Security Centre, creating a single front door for incident reporting across the entire economy. Across both countries, an incident is reported to authorities every six minutes, and the Insurance Council of Australia reports that extreme weather and cyber-enabled disruption combined have cost insurers more than $22.5 billion over the past five years.
The voices on this list are the people doing the actual work of building defences, shaping policy, prosecuting offenders, training the next generation, and explaining a complicated field to the people who need to understand it. They include CISOs at major Australian and New Zealand institutions, the academics whose research defines what the profession knows, the lawyers who turned cybersecurity from an IT problem into a board problem, the founders who built businesses solving niche challenges, and the public servants tasked with protecting a nation. Some are household names within the industry. Many are not, and that is the point.
Jonno White, bestselling author of Step Up or Step Out with over 10,000 copies sold globally and Certified Working Genius Facilitator, works with leadership teams across Australia, New Zealand, and around the world to navigate the organisational and cultural challenges that sit alongside every cyber programme. The technical capability of the people on this list is not in question. The harder work is often building the team culture, the cross-functional relationships, and the executive conversations that allow that capability to be deployed effectively. That is where Jonno's work complements the expertise profiled below.
This list deliberately moves past the familiar names that appear on every leadership-adjacent SEO ranking to surface voices the reader may not yet have encountered. Each person here is actively contributing to public discourse through original writing, conference speaking, podcast appearances, regulatory engagement, or open-source projects. To engage Jonno White for a leadership keynote or workshop on culture, accountability, or change in a security context, email jonno@consultclarity.org.

Why Cybersecurity Thought Leadership Matters
Cybersecurity is a discipline where the gap between what experts know and what most leaders understand is dangerously wide. Boards are asked to sign off on cyber strategies they do not fully comprehend. CEOs are asked to communicate publicly during incidents they did not anticipate. Mid-tier organisations adopt frameworks designed for global enterprises and wonder why compliance does not equal security. The thought leaders profiled here close that gap, translating technical reality into language that decision-makers can act on, and translating governance and policy into requirements that practitioners can implement.
The cost of getting this wrong is now measured not in IT budget overruns but in failed organisations, prosecutions of directors, and material damage to citizens. The 2022 Optus and Medibank breaches reset the conversation in Australia entirely, leading to the Cyber Security Act 2024, mandatory ransomware reporting, and a new regulatory environment that boards cannot ignore. New Zealand's open banking regulations, which took effect on 1 December 2025, are a similar inflection point. The Australian Cyber Security Strategy 2023 to 2030 sets the goal of making Australia the world's most cyber-secure nation by 2030, a target that depends entirely on the people doing the work.
The thinkers on this list are the people closing those gaps. Following them is not a substitute for technical capability inside your organisation, but it is the most efficient way for any leader to develop the cyber literacy that the next decade will demand. For a leadership development perspective on building the kind of executive team culture where these conversations actually happen, contact Jonno White at jonno@consultclarity.org.
How This List Was Compiled
This directory profiles 35 of the most influential thought leaders shaping cybersecurity discourse across Australia and New Zealand in 2026. We evaluated candidates against criteria that distinguish genuine thought leadership from positional authority alone. We looked for people actively contributing to public conversation through published commentary, conference presentations, podcasting, original research, regulatory engagement, or community building. We assessed the scope of their influence, whether their work shapes policy, practice, education, or innovation at a national or trans-Tasman level.
We deliberately weighted the list toward mid-tier voices who genuinely engage rather than the most-cited household names that already dominate every directory. We prioritised geographic diversity across both Australia and New Zealand, gender diversity across the leadership pipeline, and disciplinary diversity across policy, practice, research, law, advocacy, and community building. We valued recency, focusing on people whose contributions are particularly relevant to the issues facing organisations in 2026, including AI security, critical infrastructure protection, ransomware response, and regulatory transformation. The result is a directory designed to give the reader new voices to follow and new perspectives to consider.
Policy and Strategy Voices
The people in this category are the architects of how Australia and New Zealand approach cybersecurity at a national and organisational level. They draft the strategies, shape the legislation, advise the boards, and run the public conversation about what good looks like. Their influence reaches far beyond their immediate roles because they translate complex regulatory, geopolitical, and operational realities into frameworks that thousands of practitioners then implement.
1. Rachael Falk
Rachael is one of Australia's foremost cybersecurity policy experts and now a Partner at Ashurst Risk Advisory in the firm's cyber and digital risk practice. She spent over six years as the founding Chief Executive Officer of the Cyber Security Cooperative Research Centre, leading collaboration between government, industry, and research institutions. She was appointed by the Minister for Home Affairs and Cyber Security to the three-person Expert Advisory Board on Australia's 2023 to 2030 Cyber Security Strategy, and she led the independent review into the Department of Home Affairs management of the Optus and Medibank breaches.
Falk co-authored the Australian Institute of Company Directors' Governing Through a Cyber Crisis guidance with Ashurst Risk Advisory partner John Macpherson, a publication that has reshaped how Australian boards approach incident response. She is also co-author of the influential Five Knows of Cyber Security framework. Her commentary on regulation, board accountability, and incident response appears regularly in The Australian Financial Review and across Australian broadcast media.
2. Alastair MacGibbon
Alastair is Chief Strategy Officer at CyberCX and arguably Australia's most recognised cybersecurity public figure. He served as Australia's inaugural eSafety Commissioner before going on to become National Cyber Security Adviser, head of the Australian Cyber Security Centre, and Special Adviser to the Prime Minister on Cyber Security. He spent fifteen years as a Federal Agent in the Australian Federal Police, where he established Australia's High Tech Crime Centre.
MacGibbon is a regular commentator on Channel 10's The Project and ABC's Q and A, and his perspective on geopolitical cyber threats and the evolution of Australia's response is sought by every major Australian publication. His current role at CyberCX, Australia's largest pure-play cybersecurity firm, gives him a unique vantage point across the entire commercial sector. He continues to serve on Australian Government advisory bodies on cyber and online safety policy.
3. Lieutenant General Michelle McGuinness CSC
Lieutenant General McGuinness commenced as Australia's National Cyber Security Coordinator on 26 February 2024, leading the National Office of Cyber Security within the Department of Home Affairs. The role coordinates the national response to significant cyber incidents, leads the Executive Cyber Council that delivers on the 2023 to 2030 Australian Cyber Security Strategy, and engages with industry through the National Cyber Intel Partnership.
McGuinness chairs the National Cyber Intel Partnership, which convenes Australian Government and industry stakeholders to discuss cyber threat intelligence sharing and to inform the deployment of automated threat-blocking capabilities. Her appointment placed a senior Defence intelligence officer at the centre of Australia's domestic cyber resilience effort, reflecting the operational rather than technical nature of national incident response. Her public engagements at events such as the Australian Cyber Conference Canberra have shaped how government communicates with the private sector during incidents.
4. Hamish Hansford
Hamish was Deputy Secretary of the Cyber and Infrastructure Security Group at the Department of Home Affairs from 2023 to 2025 and the inaugural head of the Cyber and Infrastructure Security Centre from 2021. On 17 July 2025 he commenced as Head of National Security at Home Affairs, where he integrates the national security mission across the department and serves as Commonwealth Counter-Terrorism Coordinator and National Counter Foreign Interference Coordinator.
In his cyber and critical infrastructure role, Hansford led the regulatory authority for eleven critical infrastructure sectors and shaped the SOCI Act reforms that have changed how Australian utilities, transport, and telecommunications providers think about cyber risk. He was the architect of the inaugural Annual Risk Review and has been a consistent public voice on the partnership between government and industry that the 2023 to 2030 Cyber Security Strategy depends on. His commentary at the AFR Infrastructure Summit and the Australian Cyber Conference has been widely cited by practitioners.
5. Abigail Bradshaw CSC
Abigail was appointed Director-General of the Australian Signals Directorate in September 2024, taking over from Rachel Noble. She previously served as Deputy Director-General ASD and Head of the Australian Cyber Security Centre from March 2020, leading Australia's operational cyber security advice to government, business, and the public. She began her career in the Royal Australian Navy and was awarded the Conspicuous Service Cross in 2005.
Bradshaw led ASD's response to nationally significant cyber incidents during her time at the ACSC and spearheaded the partnership with industry that underpins Australia's national resilience. ASD now publishes the annual Cyber Threat Report, which sets the public baseline for understanding the threat landscape facing Australian organisations, and she is responsible for delivery of the REDSPICE program, the largest cyber capability investment in Australia's history. Her leadership has continued ASD's transition from an opaque intelligence agency to a public partner for the cyber sector.
6. Annie Haggar
Annie is a Partner and Head of Cybersecurity for Australia at Norton Rose Fulbright, based in Canberra. She founded and was the principal lawyer at Cyber GC, a specialist cybersecurity and technology law firm, before joining Norton Rose Fulbright in 2024. She has twenty years of experience advising government and private-sector clients on enterprise security risk, procurement security, global security regulation, and cyber risk in mergers and acquisitions.
Haggar was awarded Sole Practitioner of the Year at the Lawyers Weekly Australian Law Awards 2024, and she previously won General Counsel of the Year and Technology, Media and Telecommunications Lawyer of the Year at Lawyers Weekly's 2021 awards. She spent twelve years as legal counsel for Accenture, including six years as global legal counsel for its global cybersecurity business, where she supported the acquisition of fourteen cybersecurity businesses. She is a regular speaker at the Australian Cyber Conference and Black Hat Asia Executive Summit.
7. Helaine Leggat
Helaine is the Managing Partner of the Australia office of ICT Legal Consulting, an international firm with offices in twelve countries and partner firms in fifty-four more. She is one of very few lawyers globally to hold the CISSP, CISM, CIPP, and CIPP IT certifications alongside her legal qualifications, giving her a depth of technical credibility that is rare in legal practice. She is a Non-Executive Director of CI-ISAC Australia and Co-Chair of the Australian Women in Security Network.
Leggat co-founded Information Legal in Melbourne in 2013 after immigrating to Australia from South Africa, and the firm became ICTLC Australia in 2018. She was a member of the working group for the Prime Minister's Advisory Council on Cyber Security and serves as an Expert Network member for the Australian Department of Industry and Science. She teaches at the European Centre for Privacy and Cybersecurity at Maastricht University Faculty of Law and presents regularly at conferences in Australia, China, the United States, and Malaysia on cyberlaw and the Security of Critical Infrastructure legislation.
To build the leadership and communication capability that turns sophisticated cyber strategy into consistent execution, email jonno@consultclarity.org.
Practitioner Leaders
The people in this category are the operators. They run the security functions inside Australian and New Zealand organisations, advise boards directly during incidents, and translate strategy into the controls, processes, and behaviours that determine whether a cyber programme succeeds. Their voices matter because they speak from the experience of doing the work, not just commenting on it.
8. Tony Vizza
Tony is the Managing Partner and Founder of Novera, a digital risk management advisory providing cybersecurity, AI, and privacy risk management services. He has over twenty-five years of experience in information security, privacy, and cyber law, and he provides court-appointed expert evidence services in cybersecurity breach legal matters. He was previously Executive Director leading cyber advisory at KordaMentha and Director of Cybersecurity Advocacy for ISC2, the largest global association of certified cybersecurity professionals.
Vizza holds an unusual combination of credentials including the CISSP, CCSP, CIPP/E, CRISC, CISM, and ISO 27001 Senior Lead Auditor certifications, alongside a Computer Science degree from UTS, a Global Executive MBA from the University of Sydney, and a Juris Doctor from UNSW. He is a Fellow of the Governance Institute of Australia and a former board member of AISA, and he has been one of the most consistent commentators on the implications of the ASIC v RI Advice Group case for board-level cyber accountability.
9. Asaf Ahmad
Asaf is the founder of CyberGlobal Australia, a managed security service provider he launched in 2025, and a senior cybersecurity leader with over thirty years of experience. He was previously Pacific Zone Chief Security Officer at Schneider Electric, Chief Information Security Officer at Fire and Rescue NSW, and continues to serve as president of the board of directors for ISACA Sydney. He volunteers as the NSW Cyber Security Ambassador for Investment NSW.
Ahmad is a vocal contributor to industry conversations on AI governance, cloud security, and the genuine dollar value of Australia's $7.5 billion cybersecurity spend. He is a regular keynote speaker at the Cyber Security Summit Australia and has been a steady advocate for the integration of security into critical infrastructure thinking. His work with ISACA on professional certification has helped shape how Australian practitioners enter and progress in the profession.
10. Anna Aquilina
Anna is the Chief Information Security Officer at the University of Technology Sydney, a role she took on in February 2021. She brings over twenty-five years of experience across government and national security, including time in the Cyber Command at the United Kingdom's Serious Organised Crime Agency, where she helped build the UK's response to cyber threats from 2011 onwards. She has worked across intelligence agencies, law enforcement, and various government roles in both the UK and Australia.
Aquilina has become a leading voice on cybersecurity in higher education, a sector facing distinct challenges around open research environments, large student populations, and intellectual property protection. Her presentations at the CISO Leaders Summit Australia and Security Edge events have focused on top-down cyber leadership, the cultural dimensions of security uplift in academia, and the value of diverse cybersecurity teams. Her perspective on translating intelligence-agency threat assessments into operational university security programmes is uncommon and consistently practical.
11. Madhuri Nandi
Madhuri is Head of Security at Nuvei, the global payments company that acquired Till Payments where she previously held the same role. She is co-chair of the Australian Women in Security Network and brings close to two decades of experience spanning technical, operational, and strategic security across services, retail, storage, and fintech. She is the author of the Cyber Smart book and writes regularly for cybersecurity magazines.
Nandi designed and deployed security awareness frameworks at Till Payments and now Nuvei that emphasise the human dimension of security, arguing that effective security begins with informed and empowered employees rather than with tools alone. She is a sought-after speaker at conferences including the Australian Cyber Conference and the IAM Summit Sydney, and a vocal advocate for diversity in the profession and for the next generation of women in cybersecurity. Her commentary on the Australian Privacy Act reforms and the Cyber Security Act 2024 is regularly cited by practitioners.
12. Sandeep Taileng
Sandeep is the Information Security Leader at State Trustees in Melbourne, with over twenty years of cybersecurity experience across government, healthcare, academia, and telecommunications. He has built and led security programmes in environments where regulatory complexity, legacy technology, and constrained budgets create the kind of practical challenges that most CISO commentary glosses over. He is recognised across the Australian cyber community as a leader who consistently delivers under those constraints.
Taileng is a regular speaker at the Australian Cyber Conference and the CISO Leaders Summit Australia, where he focuses on practical, risk-based approaches to security strategy. His sessions on aligning complex technical challenges with business outcomes, rather than dressing technical work as strategic transformation, have made him a credible voice for mid-market and public-sector security leaders who are navigating the same realities. His emphasis on continuous learning and collaborative strategy creation has shaped how a cohort of emerging Victorian security leaders approach their craft.
13. Catherine Buhler
Catherine is the Global Chief Information Security Officer at Fonterra, the New Zealand dairy cooperative that ranks among the world's largest dairy exporters. She moved into the Fonterra role in 2025 after senior CISO and executive consulting roles in Australia, including at EnergyAustralia, Australia Post, and the IT and cybersecurity consultancy Impleo. She has been one of the most experienced enterprise CISOs across Australia and New Zealand over the past two decades.
Buhler is widely sought for her perspective on critical infrastructure security, the practical reality of implementing cyber strategy in regulated industries across both sides of the Tasman, and the executive-level conversations that determine whether cyber programmes succeed. Her move to Fonterra brings senior Australian CISO experience into the New Zealand market at a moment when food security, supply chain integrity, and trans-Tasman cyber cooperation are all under intensified scrutiny. Her commentary at industry events focuses on the lived experience of board-level cyber engagement.
14. Manasseh Paradesi
Manasseh is an experienced CISO and executive advisor known for delivering pragmatic, risk-based cybersecurity leadership across top-tier Australian organisations. He has spent over two decades building security functions in environments ranging from financial services to critical infrastructure, with a focus on translating complex technical risk into business language that boards can act on. He is a regular speaker at the CISO Leaders Summit Australia and the Cyber Security Summit Australia.
Paradesi has become a recognised voice in the conversation about how to harness cyber threat intelligence to identify the risks that matter most to a specific business, rather than over-investing in generic defences. His sessions on strategic resilience, prioritising the threats most likely to target a specific industry, and aligning security investment to actual threat profiles have resonated with mid-market and enterprise CISOs alike. His commentary on the integration of AI into the SOC and on the future of CISO role design is widely shared across the Australian security community.
To turn the sophisticated thinking these practitioners share into the kind of accountable executive culture that delivers consistent security outcomes, email jonno@consultclarity.org.
Researchers and Educators
The people in this category build the tools, run the platforms, train the practitioners, and produce the public goods that the rest of the industry depends on. Their work is often less visible than the policy debate or the C-suite commentary, but the cybersecurity profession across Australia and New Zealand could not function without it.
15. Troy Hunt
Troy is an Australian web security researcher based on the Gold Coast and the founder of Have I Been Pwned, a free data breach search service that has become one of the most widely used cybersecurity tools in the world. The service tracks hundreds of breaches, supports hundreds of thousands of website visitors a day, and is used by the governments of Australia, the United Kingdom, and Spain to monitor their official domains. He runs HIBP with his wife Charlotte Hunt as Chief Operating Officer.
Hunt is a Microsoft Regional Director and Microsoft Most Valuable Professional, and he has authored more than twenty cybersecurity courses on Pluralsight covering topics from HTTPS to ethical hacking to OWASP. He testified before the United States House Committee on Energy and Commerce on the impact of data breaches in 2017, and he received the M3AAWG Mary Litynski Award for lifetime contribution to internet safety in 2022. Have I Been Pwned 2.0 launched in May 2025 with a complete rebuild of the platform.
16. Casey Ellis
Casey is the Founder, Chairman, and Chief Technology Officer of Bugcrowd and the co-founder of disclose.io, the open-source vulnerability disclosure standardisation project. A native of Sydney now based in the San Francisco Bay Area, he pioneered the crowdsourced security as a service model when he launched the first programs on the Bugcrowd platform in 2012. Bugcrowd has since raised over USD 230 million in venture capital and was named to The Australian's Top 100 Innovators 2024.
Ellis has personally advised the United States White House, the Department of Defense, the Department of Justice, the Department of Homeland Security, the Australian and United Kingdom intelligence communities, and various US House and Senate cybersecurity initiatives, including preemptive cyberspace protection ahead of the 2020 and 2024 Presidential Elections. He is a regular keynote at DEF CON, Black Hat USA, RSA Conference, AISA, and AusCERT, and a vocal advocate for the rights of good-faith security researchers including as amicus curae to the United States Supreme Court.
17. Pedram Hayati
Pedram is the Founder and CEO of SecDim, a developer-oriented secure code training platform that uses Fix the Flag wargames to embed security thinking into engineering workflows. He holds a PhD in Computer Science and lectures at the University of New South Wales and the Australian Defence Force Academy. He is the founder of SecTalks, the largest non-profit security community in Australia with chapters across the country, and was a founding partner at boutique security firm elttam.
Hayati has reported thousands of vulnerabilities to Fortune 500 companies, published over twenty-five zero-days, and has hosted application security contests at DEF CON, Black Hat, HITB, and FirstCon. His work pushes back hard against what he describes as the failure of conventional secure code training, arguing that contrived WebGoat-style examples do not change developer behaviour. His thinking on developer experience as the prerequisite for any successful application security program has shifted how Australian organisations approach the developer relationship.
18. Daniel Grzelak
Daniel is the Chief Innovation Officer at Plerion, a cloud security company, and one of Australia's most experienced cloud-native security thinkers. He has had a storied career across a range of Australian technology firms and has become a leading voice on cybersecurity workforce realities, the limitations of conventional security recruitment, and the practical question of whether security professionals need to know how to code.
Grzelak's commentary tackles common myths within the cybersecurity industry directly. He has been one of the more honest voices on whether there is genuinely a workforce shortage in security, on what questions actually matter when interviewing candidates, on the limitations of penetration testing as a primary control, and on the importance of writing as a career skill for security practitioners. His perspective resonates particularly with senior security leaders who have grown weary of vendor-driven narratives about the state of the profession.
19. Edward Farrell
Edward is the Founder and Director of Mercury Information Security Services, an independent Australian cybersecurity practice he established in 2015. He has fourteen years of experience in cybersecurity and nineteen years in technology overall, and he has overseen the delivery of more than one thousand security assessment activities and incident responses through Mercury. He was rated in the top two hundred bug bounty hunters globally in 2015.
Farrell lectures at the Australian Defence Force Academy and is a regular speaker at the Australian Cyber Conference and AusCERT. His areas of expertise include penetration testing, threat emulation, wireless technologies, and defensive practices in the face of sophisticated adversaries. His commentary on the implementation of SIEM and SOAR platforms, on the strengths of Australia's collaboration with the United States Cybersecurity and Infrastructure Security Agency, and on the practical limits of frontline security operations is consistently cited by Australian SOC leaders.
20. Cole Cornford
Cole is the Founder and CEO of Galah Cyber, a Newcastle-based application security consultancy, and the host of Secured by Galah Cyber, one of the most listened-to Australian cybersecurity podcasts. The podcast has built a substantial following by sitting down with Australia's top software security experts to unpack their unconventional career paths and the practical realities of building application security programs at Australian organisations.
Cornford has used the podcast as a platform to surface the voices of mid-tier Australian practitioners who do not appear on the major conference keynote circuits, including Madhuri Nandi, Pedram Hayati, Tara Whitehead, Susie Jones, Kat McCrabb, and many others. His own commentary tackles AI hype in the security marketing space directly, including his unfiltered take on Claude Code security claims, on Aikido's continuous penetration testing proposition, and on the gap between AI marketing and AI reality in the security tooling market. His combination of technical depth and willingness to be openly sceptical of vendor narratives has made him a trusted voice.
21. Paul McCarty
Paul is the CEO and Founder of SecureStack, a DevSecOps visibility and automation company, and the GitLab Red Team leader. He has been involved in software security in Australia since the early 2000s, with a career spanning Unix engineering, ISP infrastructure, early Linux firewall projects, and the SOX and PCI compliance era of the early 2000s. His perspective is shaped by having watched the Australian security industry evolve from a niche concern into the regulated, board-level discipline it is today.
McCarty's commentary at the Australian Cyber Conference and on the Secured podcast tackles the question of whether security professionals need to know how to code, the trajectory of the Australian software security industry, and the practical lessons from data breaches that the industry tends to gloss over. His combination of operational engineering background, founder experience, and Red Team leadership at a major DevSecOps platform gives him a vantage point that few Australian security commentators can match. His perspective on responsible disclosure and on the relationship between victim-blaming and learning from breaches is consistently nuanced.
If you are leading a security or engineering team and need help building the kind of cross-functional culture where these practitioners' insights actually take root, email jonno@consultclarity.org.
Academia and Research
The people in this category produce the research that the cybersecurity profession depends on, train the next generation of practitioners, and provide the independent analysis that policy makers and journalists rely on. Australia and New Zealand punch well above their weight in cybersecurity research, and the academics on this list are a major reason why.
22. Professor Asha Rao
Asha is Professor of Mathematics and Cybersecurity at RMIT University and was the Associate Dean of Mathematical Sciences at RMIT from 2017 to 2023. In 2020 she became the first female Director, Interim, of the Australian Mathematical Sciences Institute, the joint venture of fourteen Australian universities that is the peak body advocating for mathematics in Australia. She is a 2019 to 2020 Science and Technology Australia Superstar of STEM and a 2021 inductee into the Victorian Honour Roll of Women.
Rao's research applies algebraic techniques to cybersecurity problems including money laundering detection, complex network analysis, and small business cybersecurity. She has been invited to closed and open meetings of the United Nations intergovernmental meetings on cybercrime, and in 2025 she was invited to the closed second ASEAN Thinktank Summit on Building Digital Trust and Resilience. She is a regular voice on Australian broadcast media on cybersecurity issues and a winner of the 2021 India Australia Science and Technology Development award.
23. Professor Monica Whitty
Monica is Head of the Department of Software Systems and Cybersecurity at Monash University and Professor of Human Factors in Cyber Security. She has been a member of the World Economic Forum Cyber Security Centre and the WEF Cyber Security Global Futures Committee. She founded the UNSW Institute for Cyber Security before moving to Monash and has held academic posts at the University of Warwick, Queen's University Belfast, and the University of Leicester during her time in the United Kingdom.
Whitty is the author of more than one hundred articles and five books, with research that focuses on the prevention, disruption, and detection of cyber fraud, particularly romance scams and investment scams, alongside cybersecurity training, online identity, insider threat, and mis and disinformation. She has been awarded over AUD 20 million in research funding and has served as expert witness in more than ten cases globally for cyber fraud victims wrongly accused of drug trafficking and money laundering. Her work has contributed to policy and tools in both the United Kingdom and Australia.
24. Professor Nigel Phair
Nigel is Director, Enterprise at the UNSW Institute for Cyber Security and Professor at Monash University. He spent eighteen years as a Federal Agent at the Australian Federal Police, including time at the Australian High Tech Crime Centre, before transitioning into academia and consulting. He has authored three books on the international impact of cybercrime, the most recent of which is Cybercrime in Australia: 20 Years of Inaction.
Phair's research argues that Australia's response to cybercrime over the past two decades has been characterised by repeated legislation that has not produced commensurate change in outcomes. He estimates that there are around three hundred thousand cybercrimes committed in Australia each year, with only a fraction reported and even fewer investigated by the approximately one hundred Australian police officers dedicated to cybercrime nationally. His commentary on the gap between policy and law enforcement capacity is consistently cited by Australian journalists covering cybercrime.
25. Professor Helge Janicke
Helge is Deputy CEO and Research Director of the Cyber Security Cooperative Research Centre, leading the centre's research programme across multiple Australian universities and industry partners. The CSCRC was established to deliver cybersecurity research with real-world impact, solving industry-led problems and developing intellectual property that benefits Australian organisations. Helge previously held senior cybersecurity research roles in the United Kingdom before moving to Australia.
Janicke has been a consistent public voice for the value of applied cybersecurity research and the role of cooperative research centres in bridging the gap between academic capability and practitioner need. His commentary at events including the CISO Perth conference and the Cyber WA Showcase has shaped how Australian organisations think about engaging with academic research as a source of operational capability. His perspective on managing cyber risks at the organisational level draws on both his deep technical research background and on years of working alongside Australian industry participants.
For the leadership development perspective on what these academic insights mean for executive teams, contact Jonno White at jonno@consultclarity.org.
Community Builders and Advocates
The people in this category have done the unglamorous, sustained work of building the institutions, networks, and advocacy efforts that allow the Australian and New Zealand cybersecurity community to function as a community rather than as a collection of competing firms. Their influence is durable because it is structural.
26. Jacqui Loustau
Jacqui is the Founder and Executive Director of the Australian Women in Security Network, the not-for-profit organisation she founded in 2015 to grow and retain the number of women in cybersecurity. AWSN now has eight chapters across Australia and runs networking events, mentoring programmes, training, workshops, career panels, research, and competitions. The organisation marked its tenth year of operation in 2025.
Loustau spent fourteen years as a security consultant in London, Brussels, and Paris, working on projects with the European Commission, UK government, NHS, and the financial sector before returning to Australia in 2014 and taking a senior role at ANZ. In April 2021 she left her paid role to dedicate herself full-time to AWSN, and she received the AusCERT 2021 Information Security Excellence award and was named on the IFSEC Global Top Influencers in Security list. Women still make up only seventeen per cent of the Australian cybersecurity workforce, and Loustau's work has reshaped how the industry approaches inclusion.
27. Susie Jones
Susie is the Co-Founder and CEO of Cynch Security, a Melbourne-based cyber fitness advisor for Australian small businesses. She co-founded Cynch in 2017 after seeing first-hand at Australia Post how poorly served small business owners were by the broader cybersecurity industry, which builds and prices its tools for large enterprises. Cynch is built on a SaaS model that profiles cyber risk in five-minute interactions at a price point small businesses can sustain.
Jones is the most consistent public advocate for cybersecurity for small businesses in Australia, a segment that represents around 2.5 million businesses and that the federal government's funding allocations have repeatedly underfunded. She serves on Victoria's Cyber Strategy Mission 2 Expert Advisory Panel and on the RMIT University Cyber Industry Advisory Board. She won the 2017 Risk Revolution Delegate Award from RIMS Australasia for her thought piece on Risk Management in an Agile World, and her commentary in publications including Xero's Open Letters to the Treasurer has shaped the policy conversation on small business cyber.
28. Anne-Louise Brown
Anne-Louise is Director of Policy at the Cyber Security Cooperative Research Centre, leading the centre's policy engagement with government, industry, and research institutions. She co-authored the influential Australian Strategic Policy Institute brief on the global rise of ransomware and Australia's policy options, and she has been a steady voice in the Australian cybersecurity policy conversation for over a decade. She moderates senior industry events including the Police Technology Forum.
Brown's policy work at the CSCRC has shaped Australian discourse on cyber insurance, on the relationship between policy levers and incentivisation in the fight against ransomware, and on the practical implementation of the Cyber Security Strategy. Her writing distils complex regulatory and threat landscape questions into formats that government policy makers can act on, which is a rarer skill than the cybersecurity industry tends to acknowledge. Her commentary on the Australian regulatory environment is frequently cited in The Australian and across the policy press.
29. Jamie Norton
Jamie is Chief Information Security Officer at the Australian Securities and Investments Commission and Vice Chair of the ISACA Global Board of Directors for the 2025 to 2026 term. He has more than twenty-five years of experience in cybersecurity, governance, AI safety, and risk management, with leadership roles spanning the Australian Taxation Office, McGrathNicol, and the World Health Organization. He is a sought-after security industry keynote speaker and a frequent media commentator on Australian cyber strategy.
Norton's appointment as ISACA Global Vice Chair places an Australian voice at the centre of the international conversation about digital trust, professional certification standards, and the global cyber workforce. He has contributed substantively to ISACA's CISM certification programme, the Australian Cyber Security Strategy, and the ASD IRAP and Cloud programmes. His public commentary on the foundational hygiene that shifts the security needle, on legacy environments in government, and on the importance of building executive narrative skills for the CISO role has made him a credible voice for senior practitioners.
30. Jay Hira
Jay is one of Australia's most active independent cybersecurity advisors and a frequent presence at the Australian Cyber Conference and on cybersecurity podcasts including the Secured by Galah Cyber series. He has spent over two decades in cybersecurity leadership roles across financial services, payments, and consulting, and he has become a trusted commentator on the practical realities of building security programmes in Australian financial institutions. His perspective combines deep technical knowledge with the operational pragmatism of a practising leader.
Hira's commentary tackles the gap between cybersecurity strategy as it is presented at industry conferences and cybersecurity strategy as it actually plays out inside Australian organisations. He has been a consistent voice on the importance of culture, communication, and accountability in security programmes, and on the limits of frameworks and tools in the absence of those organisational fundamentals. His willingness to publicly discuss the messy realities of incident response and the difficult conversations that happen behind closed doors has made him a credible voice for senior practitioners.
If your security team is technically capable but struggles to land its message at the executive level, email jonno@consultclarity.org for a workshop on the executive conversations that cyber programmes depend on.
New Zealand Voices
New Zealand is too often treated as an afterthought in trans-Tasman cybersecurity coverage, despite operating distinct regulatory, threat, and industry environments and producing world-class talent of its own. The people in this category are shaping how Aotearoa thinks about and practises cybersecurity in 2026.
31. Lisa Fong
Lisa joined Defend, a New Zealand cybersecurity firm, in November 2025 as a senior leader after thirteen years at the Government Communications Security Bureau. She had served as Deputy Director-General Cyber Security responsible for the National Cyber Security Centre since May 2016, and she oversaw the integration of CERT NZ with the NCSC to create New Zealand's lead operational cyber security agency. The integration completed in mid-2025 and unified incident reporting across the New Zealand economy.
Under Fong's leadership the NCSC strengthened New Zealand's ability to detect, prevent, and respond to cyber threats and built the international partnerships, particularly with Pacific neighbours, that underpin the country's resilience. She joined the GCSB in 2013 as Chief Legal Advisor before moving into the cyber leadership role, and her transition to Defend places one of New Zealand's most experienced cybersecurity executives in the private sector at a moment when the country's cyber market is maturing rapidly. Her commentary on the relationship between government and industry continues to shape the New Zealand conversation.
32. Adrian van Hest
Adrian is a senior cybersecurity leader who recently departed EY after more than 13 years, during which he served as EY Global Incident Response Solution Lead and Senior Consulting Partner for EY Asia Pacific based in Wellington. He has since moved into a New Zealand public sector role, bringing his 30 years of international cybersecurity experience into government service. He was a founder and board member of the New Zealand Internet Task Force and has served on the New Zealand CERT Enablement board across successive governments.
During his time at EY and previously as partner and cyber practice leader at PwC New Zealand, van Hest was the public face of annual Global State of Information Security Survey coverage for over a decade. His commentary in CIO New Zealand and across New Zealand business media consistently pushed New Zealand organisations toward a more holistic risk-based approach to security. His perspective on the maturity gap between New Zealand and global cyber practice has shaped a generation of New Zealand security leaders.
33. Andy Prow
Andy is the Founder and CEO of RedShield Security, a New Zealand-founded cybersecurity company with staff and customers in New Zealand, Australia, the United States, and the United Kingdom. He previously founded Aura Information Security, which became New Zealand's leading cybersecurity company before being acquired by Kordia in 2015. He won the EY Entrepreneur of the Year in the Services Business Category in 2019 and represented New Zealand at Pitch at the Palace Commonwealth in London in 2018.
RedShield raised AUD 14 million in capital funding in 2021 from New Zealand private equity firm Pencarrow and existing shareholder Sage Technologies, supporting the company's expansion into the United States, Australia, and the United Kingdom. RedShield's web application shielding model addresses one of the most stubborn problems in enterprise security, namely that organisations cannot patch known vulnerabilities as fast as they need to. Prow has been a consistent advocate for the global potential of New Zealand's cybersecurity sector and a vocal voice for sovereign Kiwi technology businesses competing internationally.
34. Hilary Walton
Hilary is a senior cybersecurity leader at Microsoft Australia and New Zealand and was previously the Chief Information Security Officer at Kordia Group, one of New Zealand's largest mission-critical technology providers. She has over twenty-three years of IT experience including more than fifteen years in cybersecurity, and she is the author of work on security culture and people risk management that has shaped how organisations across both countries think about the human dimensions of security.
Walton has been one of the most prominent female CISOs in New Zealand and a consistent advocate for the next generation of women in technology and security leadership. Her commentary on the value of investment in security culture rather than tools alone, on the importance of human-in-the-loop controls in an AI-driven security environment, and on the operational realities of distributed denial-of-service attack response has resonated across New Zealand and Australia. Her current role at Microsoft places her at the centre of the conversation about how AI is reshaping cybersecurity practice across the region.
35. Daniel Ayers
Daniel is one of New Zealand's most experienced independent forensic IT investigators and cybersecurity consultants. He has testified in Australian and New Zealand courts on IT and computer forensics matters and has been the public voice of New Zealand cybersecurity expertise during major incidents including the 2020 NZX distributed denial-of-service attack and the 2021 Waikato District Health Board ransomware incident. He is co-author of the New Zealand Law Society training course on computer forensics with His Honour Judge David Harvey.
Ayers's analysis on the NZX incident emphasised that redundancy and diversity are the keys to risk mitigation, a perspective that shaped subsequent industry conversations about resilience in New Zealand critical infrastructure. His commentary on Newstalk ZB's Mike Hosking Breakfast and on Radio New Zealand has consistently translated complex incident realities into language that the New Zealand public can understand. His independent forensic practice gives him a vantage point on the real frequency and severity of New Zealand cybersecurity incidents that few in the country can match.
To bring leadership development thinking to your trans-Tasman cyber programme, email jonno@consultclarity.org for keynote and workshop options.
Notable Voices We Almost Included
Several other thinkers deserve mention for the contribution they have made or are making to the trans-Tasman cybersecurity conversation. Mike Burgess, Director-General of Security at ASIO and former Director-General of the Australian Signals Directorate, did not feature in the numbered thirty-five because his current focus has shifted from cybersecurity specifically to broader national security including counter-foreign-interference. His public engagements remain among the most significant in Australia, but the specific cyber lens has narrowed.
Rachel Noble PSM, Bradshaw's predecessor as Director-General of ASD, has stepped back from public commentary since her departure in September 2024 and now serves in non-executive director roles. Sandra Ragg PSM, the architect of the 2016 to 2020 Australian Cyber Security Strategy, is now based at the OECD and contributes primarily to international rather than domestic cyber conversations. Toby Walsh, the AI scholar, focuses primarily on artificial intelligence rather than cybersecurity specifically. Dr Pedram Hayati, Susie Jones, and Madhuri Nandi were genuine borderline calls for the Researchers and Educators category versus the Practitioner Leaders category, and were assigned based on the dominant focus of their public work in 2026.
Common Mistakes to Avoid
The first common mistake is treating cybersecurity thought leadership as a substitute for cybersecurity capability. Following the people on this list is valuable, but it does not replace the need for skilled practitioners inside your organisation, mature processes, and adequate technical investment. The thinkers profiled here would be the first to point out that no amount of public commentary will protect an organisation that has not done the basic work of asset inventory, patching, identity management, and incident response planning. Use these voices to inform your strategy, not as your strategy.
The second common mistake is confusing seniority for thought leadership. The Australian and New Zealand cybersecurity ecosystems include many senior executives whose roles give them visibility but who do not contribute original thinking to public discourse. Title is not the same as insight. The people on this list earn their place through what they have written, said, built, researched, or advocated for, not through where they sit in an organisational chart. When evaluating any cybersecurity commentator, ask what they have actually said publicly that shaped how others think about the field.
The third common mistake is treating Australia and New Zealand as a single market. The two countries operate distinct regulatory environments, distinct threat profiles, distinct industry structures, and distinct cultural contexts for cybersecurity. The people working on the trans-Tasman conversation know this. Treating Auckland's cybersecurity questions as identical to Sydney's, or assuming that the Cyber Security Act 2024 maps cleanly onto the New Zealand regulatory environment, leads to the kind of policy and product errors that cost real money. Engage with both countries as the related-but-different markets they are.
The fourth common mistake is engaging with cybersecurity thought leadership only in crisis. The organisations that handle incidents best are those that have built ongoing relationships with the thinking in this field, developed their own internal cybersecurity literacy, and rehearsed their response before they needed it. Reading the work of the people on this list once a quarter, attending one or two of the major conferences a year, and following the policy debate in The Australian Financial Review and The New Zealand Herald is not optional preparation. It is part of basic cyber readiness for any leader operating in either country.
The fifth common mistake is assuming cybersecurity is a technical discipline that can be delegated entirely to specialists. The thinkers on this list, particularly the lawyers, the academics, and the human-factors researchers, would point out that cybersecurity is increasingly a discipline that demands board-level fluency, executive-level prioritisation, and organisation-wide cultural change. The technical layer matters enormously, but it is the layer that the rest of the organisation either supports or undermines. Treating cyber as someone else's problem is the most expensive mistake an Australian or New Zealand leader can make in 2026.
Implementation Guide: Taking Action
Start by following five to ten of the people on this list on LinkedIn, choosing across the categories rather than concentrating on any single discipline. Make the policy voices, the practitioners, the researchers, the lawyers, and at least one or two New Zealand voices part of your regular feed. Spend fifteen minutes a week reading what they have posted in the last seven days, not necessarily commenting or engaging, just absorbing the patterns of what is occupying serious minds in the trans-Tasman cyber conversation. After a month you will start to recognise themes, debates, and inflection points that did not register before.
Move beyond LinkedIn to the longer-form work. The Cyber Security Cooperative Research Centre publishes substantive policy papers throughout the year and is one of the best free resources for understanding Australian cyber policy. The Australian Cyber Conference papers and recordings, the Have I Been Pwned breach summaries, the AWSN reports on the workforce, and the academic publications from RMIT, Monash, and UNSW give depth that LinkedIn cannot. Subscribe to one or two podcasts including Secured by Galah Cyber and Authorised Access from Microsoft Australia and New Zealand. Block thirty minutes a week to listen.
Attend one major conference a year and treat it as a business investment rather than a perk. The Australian Cyber Conference run by AISA, CyberConnect Canberra, the Cyber Resilience Summit, the CISO Leaders Summit Australia, and the AusCERT Conference are all events where many of the people on this list speak and where the next year of cyber strategy is debated in the corridors and over coffee. Plan in advance which sessions you will attend, which people you want to meet, and what specific questions you want answered. Treat it as professional development for your most senior leaders, not just your security team.
Build a relationship with a small number of these voices. Most of the people on this list are surprisingly accessible to genuine, well-prepared inquiries. A specific question, sent privately, that respects their time and expertise will often produce a generous response. Do not pitch them. Do not ask them to do free consulting. Ask them what they think about something specific that you have already done your own work on, and they will often share insight that materially improves your thinking. The cybersecurity community across Australia and New Zealand is smaller than its size suggests, and reputation moves quickly.
Translate what you learn into action inside your organisation. Cyber thought leadership is only useful if it produces behavioural change, programme investment, or executive conversations that did not happen before. After every conference, every report, every podcast, ask what one thing inside your organisation should change as a result. Make the connection explicit between the public conversation and the private decisions. Otherwise, following these voices becomes a form of professional entertainment rather than a contribution to your organisation's resilience. To bring leadership development thinking to that translation work, email jonno@consultclarity.org.
Frequently Asked Questions
How was this list compiled? Each person was evaluated against criteria including originality of thought, recency and depth of public contribution, geographic and disciplinary diversity, and demonstrated impact on how the trans-Tasman cybersecurity profession thinks, operates, or evolves. We deliberately moved past the most-cited household names that appear on every directory to surface fresher voices the reader may not yet have encountered, while ensuring genuine credentials and active public engagement throughout 2025 and 2026.
Who is the most important cybersecurity leader in Australia? There is no single answer because the question depends on the question being asked. For national policy and strategy, Lieutenant General Michelle McGuinness as National Cyber Security Coordinator and Abigail Bradshaw as Director-General of ASD are the most consequential public sector figures. For commercial commentary and incident response visibility, Alastair MacGibbon at CyberCX and Rachael Falk at Ashurst have unmatched profiles. For research and education, the academics on this list carry the field.
What about cybersecurity thought leaders in New Zealand specifically? New Zealand's cybersecurity ecosystem is smaller than Australia's but produces world-class voices, and several feature prominently on this list, including Adrian van Hest at EY, Andy Prow at RedShield Security, Lisa Fong at Defend, Hilary Walton at Microsoft, and Daniel Ayers as an independent forensic investigator. The New Zealand National Cyber Security Centre's integration of CERT NZ has reshaped the country's incident reporting environment, and the open banking regulations that took effect on 1 December 2025 are driving fresh commentary across the New Zealand financial sector.
How do I follow these thought leaders effectively? Start with LinkedIn, where most of the people on this list post original content regularly. Subscribe to two or three podcasts including Secured by Galah Cyber and Authorised Access. Read the publications from the Cyber Security Cooperative Research Centre, AISA, and the major Australian and New Zealand academic centres. Attend one major conference a year and use the time deliberately to meet the people whose work you have been reading. Avoid trying to follow everyone equally, focus on five to ten across the categories.
Can I hire someone to facilitate cybersecurity-related leadership workshops or sessions for my team? Yes. Jonno White facilitates leadership offsites, executive workshops, and keynote sessions specifically for organisations whose cybersecurity programmes are technically sound but where the culture, communication, and accountability inside the executive team are limiting outcomes. The technical capability of the people on this list is not in question. The harder leadership work is what Jonno does. Email jonno@consultclarity.org.
What is the difference between an Australian and a New Zealand cybersecurity environment? The two countries operate distinct regulatory environments, distinct threat profiles, distinct cyber agency structures, and distinct industry compositions. Australia has the Cyber Security Act 2024, the SOCI Act, the National Office of Cyber Security under Home Affairs, and ASD as the lead technical authority. New Zealand has the National Cyber Security Centre under the GCSB following the CERT NZ integration, distinct privacy legislation, and a much smaller but more concentrated industry structure. Treating the two as a single market produces predictable mistakes.
How is AI changing the work of these cybersecurity thought leaders? AI is reshaping cybersecurity at every level, from automated reconnaissance and tailored phishing on the offensive side to AI-assisted SOC triage and compliance mapping on the defensive side. The thinkers on this list have varying perspectives on the value of these developments, with some including Cole Cornford pushing back hard against AI hype in the security tooling market, and others including Madhuri Nandi and Hilary Walton focused on the human-in-the-loop controls that make AI deployment safe. Following the debate among these voices is the fastest way to develop a balanced view.
Final Thoughts
The thirty-five people on this list represent the breadth and depth of the cybersecurity conversation across Australia and New Zealand in 2026. They are the policy architects, the operating practitioners, the working researchers, the teaching academics, the practising lawyers, the building entrepreneurs, the advocating community leaders, and the country-specific voices who shape how the trans-Tasman cyber profession actually thinks. Following their work is not a substitute for building cybersecurity capability inside your own organisation, but it is the most efficient way for any senior leader to develop the cyber literacy that the next decade of regulation, geopolitics, and technological change will demand.
If you are a cybersecurity professional, pick five to ten people across the categories and make their work part of your weekly reading. If you are a board member, a CEO, or an executive whose technical understanding does not match the seriousness of the cyber risks you are now accountable for, the same advice applies, with extra weight on the policy and academic voices who translate technical reality into the language you will need in front of regulators and the press. If you are a small business owner, start with Susie Jones at Cynch Security and the practical guidance she has spent years building.
The hardest work in cybersecurity is rarely the technical work. It is the executive conversation that has not happened, the cultural change that has not landed, the cross-functional relationship that has broken down, and the difficult feedback that has not been delivered. Jonno White's book Step Up or Step Out, available at https://www.amazon.com.au/Step-Up-Out-Difficult-Conflict/dp/B097X7B5LD, is the foundation text for that harder work, and his keynote speaking, workshop facilitation, and executive offsite work bring the book's frameworks into practical application. To engage Jonno for a leadership session that translates the public cyber conversation into the private executive decisions your organisation needs to make, email jonno@consultclarity.org.
For more on the leadership behind high-performing cybersecurity teams, check out my blog post '35 Best Thought Leaders in Banking in Australia and New Zealand (2026)' at https://www.consultclarity.org/post/thought-leaders-banking-australia-nz. For a deeper look at the AI ethics dimensions that increasingly shape cybersecurity decisions, see '35 Best Thought Leaders on AI Ethics in ANZ' at https://www.consultclarity.org/post/thought-leaders-ai-ethics-anz. And for the broader leadership conversation on building team cultures that translate technical capability into business outcomes, see '25 Best Thought Leaders for Events Australia NZ (2026)' at https://www.consultclarity.org/post/thought-leaders-events-australia-nz.
About the Author
Jonno White is a Certified Working Genius Facilitator, bestselling author, and leadership consultant who has worked with schools, corporates, and nonprofits across the UK, India, Australia, Canada, Mongolia, New Zealand, Romania, Singapore, South Africa, USA, Finland, Namibia, and more. His book Step Up or Step Out has sold over 10,000 copies globally, and his podcast The Leadership Conversations has featured 230 plus episodes reaching listeners in 150 plus countries. Jonno founded The 7 Questions Movement with 6,000 plus participating leaders and achieved a 93.75 per cent satisfaction rating for his Working Genius masterclass at the ASBA 2025 National Conference. Based in Brisbane, Australia, Jonno works globally and regularly travels for speaking and facilitation engagements. Organisations consistently find that international travel is far more affordable than expected.
To book Jonno for your next keynote, workshop, or facilitation session, email jonno@consultclarity.org.
Next Read
35 Best Thought Leaders in Banking in Australia and New Zealand (2026)
Finding the thought leaders who are genuinely shaping banking in Australia and New Zealand is one of the most consequential research tasks facing anyone working in financial services in 2026. Whether you are organising a banking conference, recruiting a board advisor, curating a leadership development programme, or simply trying to understand who is driving the conversation, you need a guide that separates the true industry shapers from people who merely hold impressive titles.
The Australian banking sector remains one of the most concentrated in the developed world, with the Big Four banks holding approximately 75 per cent of total banking assets. Across the Tasman, five major institutions control nearly 85 per cent of the New Zealand market. Yet beyond the headlines about these giants, a vibrant ecosystem of fintech founders, specialist journalists, regulators, economists, academics, and payments innovators are reshaping how both countries think about money, risk, technology, and customer experience.
This directory profiles 35 of the most influential thought leaders actively shaping banking and financial services across Australia and New Zealand in 2026. We identified these individuals by analysing the top ranking content on banking thought leadership and verifying that each person actively contributes to public discourse through publishing, speaking, or policy work.