loader from loading.io

Special Episode - From the Server Room to the Boardroom: AI, Identity and the Cyber Risks Directors Can’t Ignore

Boardroom Confidential

Release Date: 12/03/2025

S3E9 – Former Mirvac CEO Susan Lloyd-Hurwitz on Australia’s housing challengers, gender diversity and transitioning to the boardroom show art S3E9 – Former Mirvac CEO Susan Lloyd-Hurwitz on Australia’s housing challengers, gender diversity and transitioning to the boardroom

Boardroom Confidential

Susan Lloyd-Hurwitz reflects on a career shaped by unexpected turns, major leadership challenges and a decade transforming Mirvac as CEO - and how those experiences now inform her work in the boardroom. In this conversation, Susan discusses the mindset shift from executive to non-executive roles, the discipline of governing without managing, and what effective boards get right in uncertain times. She explores the balance between being supportive and challenging, the central role of the chair, and why CEO succession is the most important decision a board makes. Susan also shares insights from...

info_outline
S3E8 - Nothing About Us Without Us: Alastair McEwin on Disability, Leadership and the Boardroom show art S3E8 - Nothing About Us Without Us: Alastair McEwin on Disability, Leadership and the Boardroom

Boardroom Confidential

Alastair McEwin has spent his career pushing for a more inclusive Australia — as a lawyer, board director, Disability Discrimination Commissioner and a commissioner on the Disability Royal Commission. In this conversation, he reflects on what drew him to disability advocacy, what he learned starting out on boards in his twenties, and why great governance is a team sport. Alastair unpacks why representation at the top still lags, how boards can move beyond tokenism, and the practical changes that make boardrooms genuinely accessible. He also shares the Royal Commission’s central message:...

info_outline
S3E7 – Polycrisis and Boards: Merriden Varrall on the geopolitical risk directors can’t ignore show art S3E7 – Polycrisis and Boards: Merriden Varrall on the geopolitical risk directors can’t ignore

Boardroom Confidential

Geopolitics is no longer just background noise — it’s now central to how organisations plan, invest and manage risk. In this episode, foreign affairs expert Merriden Varrall, joins Boardroom Confidential to unpack what today’s “polycrisis” world really means for directors. Drawing on her experience at KPMG, the Lowy Institute and the UN in China, Merriden explains why boards must look beyond daily headlines to the deeper megatrends: converging climate, energy and food risks; the erosion of trust in institutions and the rise of populism; and a fragmenting global economy shaped by...

info_outline
S3E6 – Brad Welsh: Career re-invention, curiosity in the boardroom, and unlocking First Nations talent show art S3E6 – Brad Welsh: Career re-invention, curiosity in the boardroom, and unlocking First Nations talent

Boardroom Confidential

Brad Welsh has built a career defined by reinvention — from child protection officer to political adviser, CEO of Energy Resources of Australia, board member at nib, and now founder of Mawal. In this conversation, Brad reflects on the choices, opportunities and turning points that shaped his path, and how curiosity and ambition have guided every reinvention. Brad discusses the lessons learned leading ERA through the complex rehabilitation of a major uranium mine, what long-term projects teach leaders about managing risk, and how to balance the expectations of diverse stakeholders. He also...

info_outline
Holiday Archive - Audette Exel on social entrepreneurship in action, learning from mistakes, and the board’s role in promoting philanthropy show art Holiday Archive - Audette Exel on social entrepreneurship in action, learning from mistakes, and the board’s role in promoting philanthropy

Boardroom Confidential

Over the holidays, we’ll be bringing you some earlier episodes of our Boardroom Confidential podcast. This time it’s Audette Exel, the founder and chair of Adara Group. She’s also a former director with Suncorp and Westpac and previously served as Chair of the Bermuda Stock Exchange. Audette shares the story behind Adara’s unique model, which channels profits from corporate advisory work directly into life-saving development programs in some of the world’s most remote communities. She reflects candidly on the mistakes she’s made along the way, what they taught her, and why boards...

info_outline
Holiday Archive - David Kirk on investing in Australia’s tech start-ups, what big companies can learn from small ones, and how to prepare for board meetings show art Holiday Archive - David Kirk on investing in Australia’s tech start-ups, what big companies can learn from small ones, and how to prepare for board meetings

Boardroom Confidential

Over the holidays, we’ll be bringing you some earlier episodes of our Boardroom Confidential podcast. This time it’s David Kirk, the co-founder of listed venture capital fund Bailador and chair at a range of organisations including KMD Brands, Forsyth Barr and KiwiHarvest.  David was also the CEO of Fairfax Limited and had an extremely successful career on the sporting field, captaining the mighty All Blacks to victory in the first Rugby World Cup in 1987. David shares what he’s learned moving from executive leadership into chair and portfolio roles, including how to stay...

info_outline
Holiday Archive - Marina Go on how to be an effective chair, tips for starting your director career, and why diversity is critical for boards show art Holiday Archive - Marina Go on how to be an effective chair, tips for starting your director career, and why diversity is critical for boards

Boardroom Confidential

Over the holidays, we’ll be bringing you some earlier episodes of our Boardroom Confidential podcast. This time it’s Marina Go, a board member with Metcash, Southern Cross Media and the AICD itself. She’s also been a chair or director with several other organisations including Adore Beauty, Energy Australia, the West Tigers NRL club and Netball Australia. On top of that, Marina was also the GM of magazine company Bauer Media Australia and Private Media. She tells us how her media career prepared her for the boardroom. Plus: advice on being an effective chair, tips for finding your...

info_outline
Holiday Archive - Andy Penn on preparing for cyber attacks, effective Chair-CEO relationships and governance at the National Gallery of Victoria show art Holiday Archive - Andy Penn on preparing for cyber attacks, effective Chair-CEO relationships and governance at the National Gallery of Victoria

Boardroom Confidential

Over the holidays, we’ll be bringing you some earlier episodes of our Boardroom Confidential podcast. This time, it’s Andy Penn, a director with Coles and Trustee for the National Gallery of Victoria. He also spent seven years as the CEO of Telstra and previously served as the chair of the federal government’s Cyber Security Strategy Expert Advisory Board.  We talk about: lesson for boards on cyber security, advice on effective Chair-CEO relationships, and governance at the National Gallery of Victoria.

info_outline
S3E5 – Penny Bingham-Hall: Planning for cyber-attacks, climate governance in action, and building a boardroom portfolio show art S3E5 – Penny Bingham-Hall: Planning for cyber-attacks, climate governance in action, and building a boardroom portfolio

Boardroom Confidential

Co-chair of Supply Nation and Fortescue director Penny Bingham-Hall joins Boardroom Confidential to unpack some of the major issues facing today’s boards: harnessing AI’s predictive power, overseeing cyber risk in a “when, not if” world, and lifting climate governance from compliance to capability.   We also explore the craft of a high-performing board (diverse, collegiate, agenda-sharp), how to build a deliberate portfolio career, and why First Nations procurement is a powerful, practical lever for impact.   Key Themes:   AI readiness starts with data — know what...

info_outline
Special Episode - From the Server Room to the Boardroom: AI, Identity and the Cyber Risks Directors Can’t Ignore show art Special Episode - From the Server Room to the Boardroom: AI, Identity and the Cyber Risks Directors Can’t Ignore

Boardroom Confidential

Presented by Okta   Cyber security has become a core governance issue, not just an IT problem. In this episode, Mathew Graham, Chief Security Officer for Asia–Pac at Okta, explains why identity is now the front line of security — and what that means for directors. He outlines how cyber risk has shifted from firewalls to cloud systems, remote work and interconnected supply chains, where most breaches now begin with compromised credentials.   Mathew clarifies the board’s role in setting risk appetite, shaping a culture of security, and holding management accountable through...

info_outline
 
More Episodes

Presented by Okta

 

Cyber security has become a core governance issue, not just an IT problem. In this episode, Mathew Graham, Chief Security Officer for Asia–Pac at Okta, explains why identity is now the front line of security — and what that means for directors. He outlines how cyber risk has shifted from firewalls to cloud systems, remote work and interconnected supply chains, where most breaches now begin with compromised credentials.

 

Mathew clarifies the board’s role in setting risk appetite, shaping a culture of security, and holding management accountable through clear, risk‑focused reporting. He challenges common misconceptions (“compliant = secure”) and highlights the danger of relying on a single tech provider.

 

He also explores AI’s dual edge — accelerating attacks and strengthening defence — and why non‑human identities like bots and AI agents must be secured. Finally, Mathew shares practical steps: stronger MFA, regular simulations and one big question every board should ask — who has access to our most critical data?

 

Key Takeaways:

 

·       From tech issue to business risk — why cyber has moved from the server room to the boardroom, with identity now the critical perimeter.

·       Board vs management roles — the board sets the “what” and “why” (risk appetite, culture of security); management owns the “how”.

·       Good cyber reporting — concise, risk-focused dashboards over jargon-heavy reports; red flags when leaders can’t answer “who has access to what?”.

·       SMEs and NFPs — how resource-constrained organisations can use ACSC guidance, baseline controls and targeted investment to lift their posture.

·       AI as accelerator — attackers using AI for better phishing, faster vulnerability discovery and malware, while defenders use AI for anomaly detection.

·       Non-human identities & supply chain risk — bots and AI agents as new identities to secure, and why many major breaches now start with a third party.