Conference Description
Key Takeaways
- Single-day conference dedicated to operational technology security and cyber-physical resilience in Australian critical infrastructure
- Explores sovereignty, geopolitical risk and the convergence of IT and OT systems across energy, water, healthcare, defence and transport sectors
- Designed for in-house security practitioners, CISOs, OT engineers, government personnel and critical infrastructure operators
- Addresses AI risk, supply chain vulnerabilities, regulatory pressures and human factors in security culture
- Features keynote from former Prime Minister Malcolm Turnbull on national agency and emerging technology implications
Introduction
The Realms of Cyber Conference 2026 (ROCC26) convenes security practitioners and decision-makers responsible for protecting Australia’s critical infrastructure and operational technology environments. Taking place at Brisbane Powerhouse on 27 August 2026, the conference addresses the growing complexity of securing cyber-physical systems at a time when geopolitical tensions, supply chain vulnerabilities and rapid technological change are reshaping the threat landscape for essential services.
The 2026 theme, “Sovereignty in a Connected World: Where Reality Meets Resilience,” reflects mounting concerns about foreign influence, technological dependence and the operational challenges facing organisations that manage physical infrastructure through networked systems. These issues have gained urgency as Australian regulators strengthen requirements around critical infrastructure protection and as adversaries demonstrate increasingly sophisticated capabilities against industrial control systems.
About This Event
ROCC26 is structured as a single-day, in-person conference featuring multiple presentation streams, live technology demonstrations and hands-on exhibits. The programme balances technical depth with strategic perspectives, accommodating both practitioners working directly with SCADA systems and PLCs and executives responsible for organisational security posture.
Former Prime Minister Malcolm Turnbull delivers the keynote address, examining national agency, resilience and the security implications of emerging technologies within an environment of increasing global interdependence. The conference positions itself as practitioner-led, prioritising operational insight and peer collaboration over commercial messaging.
Operational Technology and Cyber-Physical Security Challenges
The convergence of information technology and operational technology has created security challenges that traditional IT frameworks struggle to address. Industrial control systems were historically isolated from corporate networks and the internet, but modern operational requirements have driven integration that exposes these systems to threats they were never designed to withstand.
ROCC26 examines security across physical domains including land, sea, air, space, biological and cognitive environments. This framing acknowledges that cyber-physical threats extend beyond conventional network security into areas where digital compromise can produce kinetic consequences—disrupting power generation, water treatment, transport systems or healthcare delivery.
Discussion topics span incident response in OT environments, the particular difficulties of patching and updating legacy industrial systems, and the cultural and organisational barriers that often separate IT security teams from operational engineering staff. Building effective security requires bridging these divides while respecting the availability and safety requirements that govern industrial operations.
Artificial Intelligence, Supply Chain Risk and Regulatory Pressures
Artificial intelligence features prominently in the programme, both as an emerging capability for defenders and as a source of new risk. The integration of AI into operational environments raises questions about system integrity, decision-making transparency and the potential for adversarial manipulation of machine learning models that influence physical processes.
Supply chain security represents another significant theme. Critical infrastructure operators depend on hardware, software and services sourced globally, creating exposure to compromise at multiple points before equipment reaches operational deployment. Managing these risks requires visibility into supplier practices and careful consideration of sovereign capability where strategic systems are concerned.
Australian regulatory frameworks continue to evolve, with strengthened obligations under critical infrastructure legislation placing new demands on operators across designated sectors. The conference addresses legal and compliance dimensions alongside technical controls, recognising that security programmes must satisfy both operational effectiveness and regulatory requirements.
Human Factors and Resilience Against Disinformation
Technical controls alone cannot secure complex organisations. ROCC26 dedicates attention to human factors in security, including the development of resilient security cultures, effective training approaches and the cognitive dimensions of threat response. Adversaries increasingly target personnel through social engineering and disinformation, making human resilience as important as system hardening.
The cognitive domain receives specific focus, acknowledging that influence operations and information warfare can undermine organisational decision-making and public trust in critical services even without direct technical compromise.
Who Should Attend
The conference serves security professionals working within organisations rather than those primarily engaged in selling security products or services. Target attendees include CISOs, security managers, OT and IT engineers, solution architects, and executives with responsibility for risk and resilience. Government and defence personnel, critical infrastructure operators in energy, water, aviation, mining and healthcare, and consultants advising these sectors will find relevant content across the programme.
The mix of technical and strategic sessions accommodates practitioners seeking operational guidance alongside senior leaders concerned with governance, investment priorities and organisational capability development.
Industry Context
Australia’s critical infrastructure sectors face a threat environment that has intensified considerably in recent years. State-sponsored actors have demonstrated persistent interest in pre-positioning within infrastructure networks, while ransomware operators have shown willingness to target operational systems with potentially dangerous consequences. The strategic importance of OT security has elevated from a specialist concern to a board-level priority across affected industries.
ROCC26 provides a forum for practitioners navigating these pressures to share experience, examine emerging approaches and build the professional networks that support effective response when incidents occur.

