-
08:20
Registration and breakfast
-
09:00
Welcome remarks by Corinium & Chair’s opening remarks
Manmeet Mahinderjit Singh - Associate Professor - Universiti Sains Malaysia
-
09:10
Speed Networking – Making new connections at CISO Malaysia!
During this 5-minute networking session, the aim of the game is to go and meet three people you don't already know. Have fun!
-
09:15
International Keynote
Securing an AI-Native Organisation at Scale: Mercari, Japan’s Largest C2C MarketplaceJason Fernandes - VP of Security, Privacy, and AI Governance - Mercari, Inc.
As organisations race to adopt Generative AI, transitioning to an "AI Native" business model introduces unprecedented cyber security challenges. In this international keynote, discover how Mercari, Japan's largest C2C marketplace and one of Japan's first tech unicorns, is safely navigating the LLM revolution. We will explore the current state of agentic AI, common challenges, and essential frameworks, strategies and guardrails to govern and secure the modern agentic enterprise. By examining real-world security models through this case study, attendees will learn practical and actionable strategies to safely accelerate AI integration while ensuring effective controls are in place.
-
09:40
Unified Cyber Resilience for AI
- Senior representative - Commvault
The AI revolution demands a resilience revolution. As organizations race to adopt AI, traditional security approaches struggle with exponential complexity, scale, and risk. This session explores current landscape challenges and demonstrates how a dual approach—resilience with AI and resilience for AI—enables truly scalable, sustainable operations.
-
10:05
CISO Panel
Achieving Meaningful Outcomes from Cyber InitiativesClosing the gap between vision and execution remains one of the biggest hurdles for today’s cyber leaders. From aligning stakeholders to building realistic delivery pathways and identifying the indicators that truly matter, this session focuses on making cyber programs tangible, achievable, and outcome-driven.
- What typically derails the journey from cyber strategy to delivery, and how can leaders navigate around these barriers?
- How can you secure organisation-wide commitment so programs move beyond intention and into action?
- When cyber uplift actually takes hold, what are the critical enablers that create meaningful, long-term impact?
Panellists
Mohamed Nabil Zolkefly CISO Takaful Malaysia
Aishah Farha Mohd Raih CISO Permodalan Nasional Berhad
Wan Roshaimi Wan Abdullah CTO CyberSecurity Malaysia
Raja Azrina Raja Othman CISO Telekom Malaysia
-
10:40
Coffee & Connect
-
11:10
AI Panel
The AI-Accelerated Security Organisation: Redefining Capability, Capacity, and Cyber Resilience- How is AI reshaping the capability and structure of modern security teams?
- Where does AI meaningfully increase SOC capacity, and how should humans and machines collaborate?
- What new risks emerge from agentic AI, and how can CISOs ensure trust and decision assurance?
- How should CISOs redesign processes, talent, and governance to build an AI accelerated, resilient security organisation?
Panellists
Goh Ser Yoong CISO Ryt Bank
Amir Abdul Samad Head, Cyber Security (CISO) PETRONAS
Eddie Hau CISO Sunway Group
Dr. Ismamuradi Abdul Kadir CISO Bank Muamalat
-
11:45
Resilience Planning: From Incident Response to Cyber Insurance
- Building effective incident response plans tailored to today’s threat landscape
- Using tabletop exercises to validate readiness and improve cross-functional coordination
- Exploring the role of cyber insurance as part of a broader resilience strategy
-
12:10
Secure by Design: Building Resilient, Digital-Native Security Architectures
Sina Manavi - Global Head of Cloud Security & Compliance - DHL IT Services
- Key principles for architecting secure, scalable environments across cloud, hybrid, and edge
- How to embed resilience and agility without compromising speed or user experience
- Real-world approaches to modernising legacy infrastructure while preparing for future threats
-
12:35
Data Termination: The Final Defense in a Robust Cybersecurity Strategy
There's a key defense that organizations often overlook: eradicating data permanently and decisively—and as soon as it's no longer needed.
Drawing on industry research, best practices, and case studies, we'll explore why enterprises must address end-of-life data more efficiently and precisely than ever before. We'll also look at how to target regulated data within traditional endpoints (including remote workplaces), live environments (onsite or in the cloud) and decommissioned IT assets (loose drives and devices).
Session takeaways include:
- How to securely remove sensitive remotely home and on-prem
- The drawbacks of physical destruction for end-of-life assets
- Why reformatting, data deletion, and other data destruction methods are unacceptable approaches
- Best practices for automation and integration, whether to target live data or protect decommissioned assets against unauthorized data access
-
13:00
Lunch & Networking
-
TRACK A: CYBER SECURITY UPLIFT
Chaired by Dr Manmeet Mahinderjit Singh - Associate Professor - Universiti Sains Malaysia
-
14:00
AI Adoption Is Accelerating. Is Security Keeping Up?
Devika Rani Krishnan - Director Risk Transformation & Governance - Standard Chartered
- Understanding where AI adoption is creating new security gaps, particularly across data, identity, third-party platforms, shadow AI and increasingly autonomous systems
- Putting guardrails around AI without slowing innovation, balancing experimentation and speed with security, accountability and regulatory expectations
- Preparing for AI-enabled attacks and AI-enabled defence, from automated threat detection and response to deepfakes, fraud and AI-assisted cybercrime
- Bringing security into the AI governance conversation, ensuring CISOs have a voice in how AI is deployed, governed and managed across the enterprise
-
14:25
The Art of the Socially Engineered Attack
- Senior representative - Abnormal Security
It's hard to believe that invoice fraud is even possible in this era of online payment, sophisticated accounts-payable systems and our heightened awareness of cybercrime. Yet, Australian businesses lost $152m to payment redirection scams last year - a 67% increase on 2023.
In this talk, I'll explore real world examples of cleverly crafted socially engineered attacks - taken directly from the emails sent by threat actors to Australian businesses. Some were acted upon and the unbelievable conversation with threat-actors will be revealed. We'll also take a look through the security analyst's lens and uncover ways you can identify these amazingly real-looking emails, as fraudulent.
Generative AI and GPTs feature heavily in the threat actor's toolkit to create very real and convincing attack emails, so we'll review examples of how ChatGPT is being so easily used to not only create the socially engineered email but also perform extensive profiling on the target to ensure the attack is contextually relevant, personal and believable.
How do you transform to evolve your defences against this type of attack, especially when your supplier accounts could be compromised or look-alike domains are used? Is it worth pursuing a takedown? I'll cover the reality of these techniques along with other methods such as EFT payment verification and behavioural AI.
-
14:50
Fireside Chat
Zero Trust in Action: From Strategy to Real-World Implementation- How leading organisations are implementing Zero Trust across hybrid and multi-cloud environments
- Breaking down real-world playbooks: identity, segmentation, continuous verification
- Overcoming resistance, complexity, and legacy system limitations on the path to Zero Trust
Speakers
Anthony Jonathan Luistro Head of Cyber Security Malaysia Aviation Group
Sivanathan Subramaniam GM of Cyber Security & Resilience CTOS Digital Berhad
-
15:15
Cyber Leadership: What Should We Be Preparing For?
- AI-driven threats, deepfakes, and cyber-enabled misinformation are forcing organisations to rethink governance, trust, and human oversight in security operations
- As critical infrastructure and digital ecosystems become more connected, cyber leaders must strengthen resilience across cloud, OT, third-party, and legacy environments
- The role of the CISO is evolving from technical operator to strategic business leader responsible for resilience, workforce readiness, and navigating constant disruption
-
TRACK B: EMERGING RISKS
Chaired by Abdul Hakim Razip - Cyber Security Leader -
-
14:00
Are We Secure, or Just Compliant? Rethinking Security Architecture in a Changing Regulatory Landscape
Goh Hong Yao - Cloud Security & Compliance Lead - Friesland Campina
- Examining the gap between compliance and actual security, and where organisations may still be exposed despite meeting regulatory requirements
- Translating regulatory requirements into architecture decisions, particularly across legacy infrastructure, cloud, IT/OT and increasingly connected environments
- Preparing for evolving expectations around cyber incidents and accountability, including the implications of Malaysia’s Cybercrimes Bill 2026 and NCII obligations
- Building security architectures that support resilience, giving organisations the ability to detect, contain and recover when preventive controls fail
-
14:25
Cloud Security in the Age of Digital Warfare
Exploring how cyberwarfare-style threats are reshaping cloud security, and what CISOs must do to build resilient, threat-informed cloud environments using CSA-aligned frameworks.
-
14:50
Fireside Chat
When Downtime Becomes a Cyber Weapon: Securing Critical Infrastructure in a Connected Era- Understanding the unique cyber risk profile of critical infrastructure – why IT/OT convergence, legacy systems, and national dependency make these environments high-impact targets
- Building operational resilience where safety, uptime, and security intersect – rethinking incident response, recovery, and decision-making when cyber incidents can disrupt essential services
- Strengthening ecosystem collaboration – how operators, regulators, and technology partners can work together to uplift resilience across Philippines’s critical infrastructure landscape
Speakers
Dr. Faisha Shahriman Head, Risk & Resilience PLUS
Abdul Hakim Razip Cyber Security Leader
-
15:15
You Can’t Ban Your Way Out of Shadow AI
Shadow AI is not just a governance problem or a technology problem. It is a secure behaviour problem. Employees turn to unsanctioned AI when approved paths feel slower, harder, or less useful. This session explores what that reveals about security culture, when people hide risk versus surface it, and how leaders can make secure AI use the easier choice in the flow of work.
-
15:40
Teh Tarik & Networking
-
16:10
Fireside Chat
From NCII Compliance to Operational Resilience- Moving beyond compliance checklists to embed NCII requirements into everyday security, risk, and business continuity strategies
- Strengthening resilience across critical systems, third-party ecosystems, and IT-OT environments to contain disruption and maintain essential services
- Testing whether organisations can detect, respond to, and recover from a major cyber incident while maintaining operational continuity and stakeholder trust
Speakers
Mohd Rizal Mohd Ramly Head Digital & Data TNB Genco
Naveen Chantiran Head of Cyber Security Air Liquide
-
16:35
Closing Panel
Humans vs Machines: Rethinking Cybersecurity in the Age of AIAI is reshaping cybersecurity on both sides of the battlefield. It is powering more sophisticated attacks while enabling smarter defences. But where do humans fit in? This session unpacks how organisations are redefining the “human-in-the-loop” to stay resilient in an AI-driven threat landscape.
What you’ll gain:
- How AI is transforming threat detection, response, and fraud prevention
- Insights into AI-enabled attacks (deepfakes, automation, advanced phishing)
- Where human expertise still outperforms AI in cyber defence
- Strategies to upskill cyber teams for an AI-augmented future
- How to address talent anxiety and job displacement concerns
Panellists
Haji Aizuddin Mohd Ghazali Director, Cyber Security Department Bank Negara Malaysia
Dr. Faisha Shahriman Head, Risk & Resilience PLUS
-
17:10
Closing Remarks by the Chair
Manmeet Mahinderjit Singh - Associate Professor - Universiti Sains Malaysia
-
17:15
CISO Malaysia Networking & Drinks Reception
-
18:00
Close of CISO Malaysia 2027
Not Found