Session
This frames the practical takeaway: cyber leaders must simplify the environment without creating blind spots, protect the basic controls that prevent common attacks, and use automation to lift people into higher-value work. Simplifying the estate generally reduces complexity, which is good for cyber. The risk appears when more workloads move into major SaaS and cloud platforms and teams keep monitoring the network as if nothing changed.
The visibility problem becomes sharper as organisations consolidate into major SaaS and cloud platforms. Security teams may still have a SIEM, a SOC and people watching the network, but the activity that matters increasingly happens inside platforms where their historical controls and skills do not reach as cleanly. Leadership implication: simplification is still valuable, but visibility has to move with the architecture.
The visibility problem becomes sharper as organisations consolidate into major SaaS and cloud platforms.
The team needs platform-specific telemetry and skills, not only more centralised monitoring. Under budget pressure, the easiest cuts often land in the wrong place. Patching, provisioning, deprovisioning and privileged access control are the disciplines most likely to prevent common attacks.
At the same time, automation is changing how cyber teams operate. Lautenbach was direct that the most damaging cuts are often not in specialist security tools, but in the unglamorous IT foundations that stop simple compromise: patching, deprovisioning, privileged access management and keeping systems current. The strategic shift is clear: the security team cannot simply watch more data.
It has to engineer a response system that handles repeatable events and reserves human judgment for the work that genuinely requires it. Traditional SIEM-first models are under pressure. New specialised tools are improving visibility across SaaS platforms, while automated response is becoming increasingly practical.
At the same time, governments are moving toward more prescriptive cyber requirements. The final signal is regulatory. Lautenbach noted that Australian critical infrastructure policy is moving from a mode where organisations are expected to manage risk into a more directive model.
That matters because regulation carries cost into the IT environment and may travel through supplier ecosystems. Cyber resilience under constraint is now a leadership discipline. The organisations that win will not be the ones with the largest tool estates; they will be the ones that know where visibility is thinning, which hygiene processes cannot be touched, where automation can absorb response load, and how quickly regulatory obligations may move through the supply chain.
CISO UK Webinar | February 2025
Navigating Evolving Threats: Strengthening Data Privacy & Compliance in 2025
CMO UK Webinar | April 2025
Consent Management in Marketing: Balancing Compliance and Customer Trust
CMO UK Webinar | March 2025
Privacy-First Marketing: Strategies for Data Collection and Compliance
From Conviction To Execution
Four Leadership Signals for Australia's Next Reform Cycle
From Risk-Exposed to Recovery-Ready
James Eagleton's discussion reframes cyber resilience as a leadership and operating model challenge, not a narrow technology problem.
Modern CIO
How to be Successful in a Rapidly Changing Environment
Observability Imperative
How To Build Resilient, Data-Driven Enterprises.
Technology Leader's Webinar | Digital Resilience
Resilience in Action: from Digital to Operational
Technology Leaders' Webinar | Navigating the Build vs. Buy Decision for Customer Identity
Navigating the Build vs. Buy Decision for Customer Identity: Key Considerations for Modern Digital Experiences with Kast and Auth0
Technology Leader's Webinar | The Future of Digital Identity in an AI-Driven World
The Future of Digital Identity in an AI-Driven World
Establishing Cybersecurity Governance: Building Strong Foundations
Best practices for defining cybersecurity roles and responsibilities.
Exploring Cybersecurity Careers: Building Pathways Beyond Technical Roles
Broadening Career Horizons in Cybersecurity: Exploring non-technical roles
Fireside chat: Ensure the most secure Identity posture across your organisation
Ensure the most secure Identity posture across your organisation
Managing the Ever-Evolving Cyber Threat Landscape
Identifying emerging cyber threats and vulnerabilities.
Start Strong: Strategies for Building a Successful Team from the Ground Up
Best practices for defining cybersecurity roles and responsibilities.
Strategies for Mitigating Cybersecurity Risks
Conducting thorough cybersecurity assessments of systems integration.
Australian Enterprise and Global Shifts
Three Disruptions Redefining the Operating Environment
