Sign in to view Tony’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Tony’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
AI, Cybersecurity and IT Risk | Lawyer | Managing Partner | Teaching Fellow | Independent Expert
Greater Sydney Area
Sign in to view Tony’s full profile
Tony can introduce you to 4 people at Novera
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
14K followers
500+ connections
Sign in to view Tony’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Tony
Tony can introduce you to 4 people at Novera
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Tony
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Tony’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
My purpose is to help people and organisations protect themselves from risks and harm. Using my knowledge, skills, abilities and experience, I do this by working towards a safer and more secure digital world.
With over 25 years of experience in the information security, IT, and privacy domains, I am a recognised leader and advocate in cybersecurity, business, and risk management. I have board level and senior management experience and am also an admitted lawyer.
I have an undergraduate degree in computer science and a postgraduate Executive MBA degree. I have worked and studied across North America, Europe and Asia. I have completed a Juris Doctor with honours and a Graduate Diploma in Legal Professional Practice.
My core competencies include IT security programs, regulatory compliance, data privacy, and cyber law. I have also earned multiple certifications, such as CISSP, CISM, CRISC, CIPP/E, CCSP and ISO27001, that demonstrate my professional expertise and credibility. I am also a Fellow of the Governance Institute of Australia and a Senior Member of the Australian Computer Society (ACS).
Additionally, I have contributed to numerous publications and events that showcase my thought leadership and advocacy in the cybersecurity, privacy and IT fields. I am driven by the mission to digitally protect and empower organisations and individuals and enable them to achieve their goals and potential.
I continue to work across multiple initiatives with government, industry and academia stakeholders to improve the overall level of cyber security, privacy and resilience to digital risks across broader society.
Services
Articles by Tony
-
The ASD and the AICD have written your AI cyber to-do list. We've translated it into actionable steps.
The ASD and the AICD have written your AI cyber to-do list. We've translated it into actionable steps.
After last edition’s edition of Tony's Phish and Chips, where we took apart breathless AI headlines from published…
32
3 Comments -
No, OpenAI's model did not 'go rogue' - and the real story is more useful than the headlinesJul 23, 2026
No, OpenAI's model did not 'go rogue' - and the real story is more useful than the headlines
Working in the realm of AI and cybersecurity really can be insufferable at times. Last week's disclosure that OpenAI…
84
16 Comments -
The report card is in: five uncomfortable digital risk truths from FY25–26, and what they mean for the year aheadJul 16, 2026
The report card is in: five uncomfortable digital risk truths from FY25–26, and what they mean for the year ahead
Something a little bit different this month. Rather than dissecting a single cyber threat vector or control, I wanted…
16
2 Comments -
AI-Generated Phone Scams and 'Vishing' have become Mainstream. Here are ways you can Protect Yourself.May 25, 2026
AI-Generated Phone Scams and 'Vishing' have become Mainstream. Here are ways you can Protect Yourself.
Yesterday was not a great day. Two separate reports landed on my desk from people who had been taken, not for hundreds…
37
2 Comments -
The Time for Professional Standards for the Australian Cyber Security Workforce is NowMar 21, 2026
The Time for Professional Standards for the Australian Cyber Security Workforce is Now
Adopting a Government-endorsed set of Professional Standards for the Australian Cyber Security workforce will help to…
65
9 Comments -
Staying Safe this Black Friday and Cyber MondayNov 21, 2025
Staying Safe this Black Friday and Cyber Monday
A Dodgey Start to the Day This edition of Tony's Phish and Chips comes to you from a state of daze, confusion and…
27
-
Cyber in 2025 and BeyondAug 14, 2025
Cyber in 2025 and Beyond
By Tony Vizza, Managing Partner, Novera Cybercriminals are escalating recruitment of insiders to assist in fraud…
41
5 Comments -
Don't Be A Bunny: Easter Reflections on AI Safety During Election CampaignsApr 16, 2025
Don't Be A Bunny: Easter Reflections on AI Safety During Election Campaigns
This special AI edition of Tony's Phish and Chips takes a step away from the pungent and heavy deep fryer smells of the…
16
2 Comments -
Digital Risk Management EssentialsMar 3, 2025
Digital Risk Management Essentials
Part 1: Cybersecurity Introduction Its been some time since my last Tony's Phish and Chips newsletter. Truth is, I've…
21
-
How the Y2K 'Millennium Bug' Taught Me to Speak Up, and why History Repeats in the Cyber Security Professionalisation Debate.Jan 28, 2025
How the Y2K 'Millennium Bug' Taught Me to Speak Up, and why History Repeats in the Cyber Security Professionalisation Debate.
I read a meme recently that said that the year 2050 is closer to us than the year 2000 was. This gave me pause to think…
47
18 Comments
Activity
14K followers
-
Tony Vizza shared thisThe Attorney-General's Department has released its #Privacy Reform Consultation Paper, together with a draft Privacy Amendment (Personal Data Protection) Bill 2026. Now, I was one of the many voices that decried the 2024 tranche of privacy reform as 'tinkering on the edges'. The second tranche is anything but. Tranche 2 has 41 proposals or measures, some of which will fundamentally change how organisations handle and protect personal information. These include: ➣ The "fair and reasonable" test: APPs 3, 4 and 6 are replaced with a single principle: you may only handle personal information where it is fair and reasonable in the circumstances, assessed holistically against legislated factors including reasonable expectations, proportionality and risk of harm. No single factor is determinative. The question shifts from "did we obtain consent?" to "can we justify this?" ➣ Expansion of Scope: Personal information moves from information "about" an individual to information that "relates to" them, with a new definition of "reasonably identifiable". A person can be identified without their name being known - being singled out is enough. Inferences generated by data analysis or AI are expressly a collection. Precise geolocation tracking and genomic information becomes sensitive information. ➣ 72 hour notification period for eligible data breaches. Notification to the Information Commissioner within 72 hours of reasonable grounds to believe an eligible data breach has occurred, aligned with the SOCI Act and the Cyber Security Act, plus positive obligations to contain a breach and mitigate harm that apply even where the serious harm threshold is not met. ➣ APP 11 grows teeth. You must be able to identify what personal information you hold, consider whether it should be destroyed, and regularly evaluate whether your controls actually work. Data minimisation now becomes an auditable obligation. There is also a right to erasure — but only against large digital platforms ($500m revenue or 2.5m monthly users), a controller/processor split that will genuinely simplify life for service providers, and five open questions on smart glasses, wearables and connected vehicles. ➣ Practical Operation: The part that really matters - the Department has said this consultation is focused primarily on practical operation, implementation and compliance impact. That makes it a request for evidence from people who have to make this work, and if you have ever tried to run a data inventory across a real business, you have something to contribute that a policy team does not. Its not the EU GDPR but many of the proposed concepts parallel them. Sadly, the political and small business exemptions remain. Submissions close 18th September (less than 3 weeks). More details at ag.gov.au. I encourage responses especially from privacy supporters and advocates.
-
Tony Vizza shared thisOver the course of the past week, I’ve had more than several conversations with people who have ended up on the corporate scrap heap of redundancy and have now had their lives thrown upside down. These are individuals who are exceptionally talented, highly ethical and are good operators who have always done what was asked of them by their organisations and are now paying the price for the failed decisions of those at the top - in many cases decisions that are playing out in the media. If there is one lesson that has branded itself into my consciousness about my time in the corporate world is that shit flows downhill. There is no other polite way to say it, and no getting around it. And that is an unavoidable fact of life where corporate culture is centred on unending growth, beating everyone else at all costs, self-preservation and dog-eat-dog. As I say…show me the incentive and I’ll show you the outcome. All of this is small consolation to those who now end up without a job. You’re going to go through a rough ride. Between blaming the organisation you were at, blaming yourself, blaming the world and everything in between, you’re going to be angry, sad, nervous, upset, happy, glad and an infinite other number of emotions in between. Im not one to give advice often, but in this case I will. Let yourself be angry for a few days. Get a workplace lawyer. Fight for the best outcome you can get. And then take time off. Spend time with your kids if you have them, or spend time with your friends and people who unconditionally care for you if you don’t. Go for regular walks (like I am doing this moment at beautiful Cape Banks in Sydney). Work out. Stay connected with people in your industry. Make time with them for coffee. And if you’re independently-minded, build your own thing with your own vision. You’ll end up being ok, I promise you. And eventually, you’ll prove to yourself that someone else’s poor decision was the best thing that happened to you. If you need to talk, to vent, or as a shoulder to cry on, ping me.
-
Tony Vizza shared thisThe request was reasonable enough. While assisting a valued client with remediating a cyber-related policy, I was asked, ‘Hey Tony, can you take a look at our social media policy to see if it needs updating as well?' My answer - ‘Sure thing, send me what you have, and I'll add it to the list of things to do'. What happened next was an exercise in reliving the horrors of some rather poor decisions I made in my mid-to-late 20s, which have thankfully managed to escape the hyperconnected world we find ourselves in. 😅 In all seriousness, though, if you have policies, procedures and frameworks that have not been reviewed since Kevin Rudd was PM, George W. Bush was President, and a full-head-of-hair Tony was frequenting almost every music festival from Marion Bay in Tassie to Caboolture in Queensland, the Novera team and I specialise in getting you up to speed on this sort of thing. (Permission to post this excerpt in question was granted by the client - who managed to see the humour in the situation).
-
Tony Vizza shared thisWhen I was a young undergrad studying computer science at University of Technology Sydney, we learned how to manage networks using equipment that was donated by one of the world’s largest networking vendors. It was generous. It gave students access to technology we might otherwise never have seen. But there was also an obvious commercial benefit: teach students your technology while they are learning, and there is a pretty good chance they will keep using, recommending and buying it when they enter the workforce. Fast forward a couple of decades, and, according to this article, that playbook appears to have become vastly more sophisticated. Google, Microsoft and others are deeply embedded in the education ecosystem, providing technology, training teachers and increasingly helping shape how students learn about AI and computing. There is nothing inherently wrong with industry supporting education. But we should be very clear-eyed about the influence that comes with it. And I think the same question needs to be asked in the public policy arena. It is perhaps little coincidence that Google, Microsoft and Cisco, companies with enormous commercial interests in how governments approach technology and cybersecurity, also have seats on the Australian Government’s Executive Cyber Council. Of course, industry should have a seat at the table. But a seat at the table should never become ownership of the table. And whether we are educating students or developing national technology policy, diversity of thought, genuine independence and representation beyond the largest technology vendors matters enormously. What are your thoughts? https://lnkd.in/g5pKZivz
-
Tony Vizza shared thisThere can come a point in any relationship where walking away is stronger than staying at the table. That applies to relationships between people. It applies to businesses. And, as Canada has just demonstrated, it applies to relationships between nations. When any relationship becomes horribly lopsided, it eventually ceases to be a relationship. When negotiations become all show and no substance, they cease to be negotiations. And when good faith is replaced by shifting goalposts, deceit, coercion or a closed-minded insistence that everything must be on one party’s terms, sometimes the strongest thing you can do is simply say: ‘No thanks’ and then walk away. That should not mean that you stop talking forever. In fact, letting the dust settle and reflecting on mistakes will make relationships stronger. It doesn’t mean you don’t compromise. And it certainly doesn’t mean that there aren’t consequences at least in the short and perhaps even long term. Walking away can be enormously costly, as the Canadian economy is about to learn. But there is an important difference between compromise and capitulation. Whether we are talking about friendships, commercial relationships or international diplomacy, accepting a bad deal simply because a deal feels preferable to uncertainty can mean that the next negotiation begins from an even weaker position. Canada has decided that there is a line beyond which it will not go. And I respect that. International relationships, particularly between friends, neighbours and long-standing allies, should be built upon mutual respect, trust and an understanding that both sides need to walk away with something. They cannot sustainably operate on the basis that one side must continually bend to the will of the other. My full respect to Canada for taking a principled stance. Hopefully, in time, the United States can see the error of its ways and extend an olive branch. The best relationships aren’t built on who can exert the most leverage. They are and should be built on mutual respect, kindness and a willingness to see the bigger picture and work towards a shared goal - whatever that may be. https://lnkd.in/gpT67DPGCarney Stands Up to Trump in Trade War Despite the RisksCarney Stands Up to Trump in Trade War Despite the Risks
-
Tony Vizza shared thisThis fascinating article on the topic of free speech and on the freedom to disagree respectfully brought back a memory of a conversation I had with someone over dinner more than 10 years ago. The conversation was between an IT professional from IBM who was visiting from the US, and myself as a born-and-bred Aussie, over dinner at one of my favourite restaurants in Sydney, INDU. The topic of gun control came up. Being younger, and far more willing to shoot my mouth off (no pun indended) than I am these days, I told him exactly what I thought - American gun laws "are nuts". The US "should have brought in gun control decades ago". My dinner friend, responds with his take, which was that he believed that Australians "are nuts" for allowing the government to take and control firearms. Naturally, my dinner guests willingness to challenge me intrigued me. And at that point, the conversation should have gone either way - it could have been a battle to the death over the entrees, or, as it turned out, we made our respective cases calmly and politely. By the end of that conversation, I can say that my guest had a compelling and strong argument. He explained to me how the history of the formation of the US meant that Americans relationships with firearms were (for better or worse) very different to ours, where our history took a different path. While I respectfully disagreed that the US could do more on that front, I left that dinner not feeling as absolute in my opinion as I entered it. That, to me, is what a good disagreement does. It rarely converts you. It just loosens your grip. What bothers me these days is how much rarer that sort of dinner is. It has become far easier for people to cut ties and go "no contact" with someone you disagree with than to sit with the discomfort of unpacking why the other side thinks the way it does. I've been very fortunate, particularly in the second half of my life, to hold onto longstanding friendships with people who are both similar to me and nothing like me at all. The ones who see the world differently are, almost without exception, the ones who have taught me the most. You don't have to agree with someone to learn something from them. You just have to stay at the table. What are your thoughts? https://lnkd.in/gca5Gx3KPrestigious law schools aren’t Legally Blonde. Free speech is in troublePrestigious law schools aren’t Legally Blonde. Free speech is in trouble
-
Tony Vizza shared thisComputer science lecturer Greg Baker made some big headlines earlier in the week when he ran a successful case against real lawyers regarding a case in the Fair Work Commission only using #AI. In describing the win, he predicts 'carnage for the legal profession, much fewer jobs, terrible time for graduates and much lower pay'. The piece turns to the jobs that are much harder to hand over - physical, relational, or licensed work. Baker's survivor list includes funeral director, counsellor, nurse, aged care worker, childcare worker, nanny, primary school teacher. Every single one of these involves a person having a crap day who needs another person to be in the room. After all, you can't prompt your way through a grieving family, or settle a four-year-old with well-structured AI slop. 'Law is a gate-kept profession', I hear you say. But the gate won't save every job. So, I contend that disruption will look less like an extinction and more like restructuring: the commodity end of the work collapses, while the accountable, judgment-bearing and disputes nature of work holds. This will be cold comfort for the 20-something year old graduates and recent lawyers who read this and will want to proverbially shoot me. The commodity end is exactly where the trade is learned - and its going to disappear. Harvey and Legora are already all over it. In fact, the skills that will keep you employed are the ones nobody ever examined you on, such as: (1) Emotional intelligence. Reading a room. Knowing when the client's real problem is not a legal one - but rather a misunderstanding, miscommunication or misperception. (2) Negotiation. Holding a position, exploring options with the other party, conceding gracefully, and finding the middle ground between interests. (3) The deeply unglamorous ability to work with people you don't like. The ability to handle the difficult opponent; the client who won't take advice; the colleague you'd never choose. In my view, these three criteria, professional skills in fact, are essential in getting a good career outcome. And they are rarer than you'd think - especially for a generation who have embraced disposable everything, including relationships and friendships. AI is going to draft your advice, and it will do it faster and probably better than you. However, it will not sit across the table from someone who is furious, exhausted, distraught, out of money and make them feel heard. It will not catch the flicker on an opponent's face when they are bluffing. And therein lies your opportunity. What are your thoughts? https://lnkd.in/gu-uKjCVOnly one type of lawyer will survive the AI wipeoutOnly one type of lawyer will survive the AI wipeout
-
Tony Vizza shared thisAnyone who has ever been on a video call with me has seen this beautiful thing sitting in the background above me: a 1:200-scale die-cast Qantas A380, which my family gave me on a landmark birthday a few years back, weighing about five kilos. Having eagerly watched the first A380 arrive in Australia about 20 years ago, having fond memories of a similar Emirates A380 model sitting on Ben F.on Ben F.'s desk when we were both working at Westcon-Comstor, there are very few modes of transport that fanboy me as much as flying in one of these things. If you have never been on one, let me paint you a picture. As you board, one of the first things you realise is just how spacious they are. It really does feel less like you are in a plane and more like you are in a building. Next, as the plane starts to hurtle down the runway, two thoughts come to mind... (1) this is a really quiet plane for one that has four engines and (2) I don't think this massive beast will get off the ground. As you look out the window, you become pleasantly surprised when it does, in fact, lift, then fly, and then provide one of the most exceptional and special experiences in the air that you can get. Altogether, I've flown what would probably be a thousand times. A few times, I've even had the thrill of flying an aircraft myself. Yet, one of the most memorable flights I have ever had was a QF from Dallas to Sydney on an A380 where I slept for what would have been 12 hours straight (thanks melatonin!) in a lie-flat that was as good as, if not better than, my bed at home. The preceding connecting flight, from Tampa to Dallas, featured a 12-hour delay, remnants of a hurricane, the jet stream over the Gulf of Mexico, a much smaller aircraft, and an American Airlines pilot who must have been flying F-35A's in the United States Air Force the week prior — all in and of themselves memorable experiences. As we were waiting for the weather to clear, when I queried whether the pilot would be airborne any time soon, his reply, with a thick Southern drawl, was a phrase that has lived with me ever since... 'Sir, I can tell you that you would rather be on the ground wishing that you were in the air, than being in the air and wishing you were on the ground'. Recently, Qantas has said that it plans to retire these wonderful modern marvels. While that news saddens me, I secretly hope that the joys of aviation can keep flying for as long as possible. After all, if there are Convairs in service that are still carrying passengers 80+ years after they were made, hopefully the A380's can find similar longevity. And of course, I have to mention Richard de Crespigny AM in any post that talks about Qantas and the A380's. I dont have many role models - but he is certainly one of them. Aircraft feature prominently in many of my #cybersecurity discussions — precisely for the reasons I have highlighted above: people, process, and technology above all else.
-
Tony Vizza shared thisThe EU's watermarking rules for #AI went live on 2 August. Article 50 of the EU AI Act now requires providers of generative AI to mark their outputs in a machine-readable format so the content is detectable as artificially generated. The European Commission's Code of Practice on Transparency of AI-generated Content, published in June, sets out how. Technically, watermarking of even plain text is achievable. After all, an AI answer is not 'knowledge' per se. It is a mathematical, probabilistic output. A model calculates which token is most likely to come next, over and over, until it has assembled something that reads like a person wrote it. And because that selection is based on statistics, it can also be nudged. Watermarking of AI text can work by biasing those probabilities in a mathematical pattern which detector can later recognise. In effect, it is a formula, similiar in ways to a traditional checksum, tuned to leave a signature in the output. So, yes, it is possible to watermark AI text. And its likely that regulators will get their compliance. However, here is the more nuanced problem thats going to emerge going to become a smorgasbord for lawyers in the not too distant future. Generative AI is intrinsically designed to mimic human expression. National Institute of Standards and Technology (NIST)'s guidance on synthetic content, AI 100-4, is candid about this. And we know text watermark detection will degrade as content gets shorter and more predictable. As an example, paraphrasing can cut detection rates dramatically. And in principle, any text watermarking scheme can be defeated. This means that the next question is not 'can we watermark it', but rather, what happens when the formula says AI was used, and the person says that it wasn't? We are already seeing it. Stories that won this years Commonwealth Short Story Prize were accused of containing AI-generated content. The Foundation reviewed the drafts and found no evidence. Stanford research has shown detection tools falsely flag non-native English writers at markedly higher rates. And an accusation alone can end a career, or result in tragic outcomes, as we have seen in Prof. Jason Arday's case in the UK. Watermarking helps to answer a narrow question: was a machine involved. However, it does not answer the question organisations will actually face - such as whose account do we believe, and on what evidence? In my opinion, boards should be considering more than just the compliance requirements to laws where they operate. The issue of how to handle AI output is a governance one, more than a technology one. For example: - Should the organisation consider a disclosure policy, and methods to establish provenance, version recording and change control? - Does an evidentiary threshold need to be established for alleged AI use? - What about a right of reply for an individual or company accused of using AI? What are your thoughts?
-
Tony Vizza liked thisThis is big! While these reforms are still in consultation and may evolve before becoming law, they offer a clear indication of the direction of travel. The proposed changes tackle some of the most controversial privacy issues that have been debated for years, while also addressing newer challenges arising from AI, digital platforms and evolving data practices. The centrepiece is the proposed "fair and reasonable" test, which echoes the direction the Office of the Australian Information Commissioner has been championing for some time. From my perspective, the proposed 72-hour breach notification requirement is the reform I'll be watching most closely. Moving from the current 30-day assessment period to a 72-hour notification window would represent a significant shift in approach. This will place significant pressure on organisations already dealing with a crisis and is likely to drive precautionary over-reporting. That risks overwhelming the regulator with notifications of limited value, while taking time and resources away from what affected organisations should be focused on most: containment, investigation and recovery. The good news is that you have an opportunity to help shape the outcome. Submissions close on 18 September 2026, and the Government has specifically invited engagement through the consultation process. Have your say here: https://lnkd.in/gKsy2ugMTony Vizza liked thisYesterday, the Australian Government released the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, marking the next major step in its efforts to modernise and strengthen Australia’s privacy laws for the digital age. The proposed reforms would significantly reshape Australia’s privacy framework, introducing new requirements for handling personal information, consent, data security and breach response. An accompanying Consultation Paper also examines privacy challenges associated with emerging technologies, including wearable devices and smart glasses. Consultation closes on 18 September 2026. Our team has prepared an overview of the key proposals and the practical steps organisations should consider when assessing the potential impact on their privacy, data governance and AI initiatives. View our update: https://lnkd.in/gQWwVWAg Have questions? Get in touch with Leah Mooney: https://lnkd.in/gcMZ8HuQ Kieran Doyle Nicole Gabryk
-
Tony Vizza liked thisTony Vizza liked thisToday, on International Women in Cyber Day, I want to celebrate the incredible women helping to shape and strengthen Australia’s cyber security ecosystem. As our world becomes increasingly connected, Australia must grow its cyber capability. From responding to increasingly sophisticated cyber threats to advancing our ambition of becoming one of the most cyber secure nations in the world, strengthening our cyber resilience will depend on our ability to harness the full talent, skills and perspectives of our nation. This means we need to encourage more women to join our cyber security workforce. Meeting the cyber challenges of today and tomorrow requires a workforce with diverse capabilities, experiences and perspectives. Cyber security is a field built on collaboration, critical thinking, analysis, risk management and innovation. We need more women across every part of the cyber workforce. We need their expertise, insights and leadership to strengthen Australia’s cyber resilience. Across our nation, outstanding women are already making a significant contribution to protecting our communities, strengthening our economy and shaping the future of cyber security in Australia. Looking ahead, we must continue to create pathways and foster environments that enable more women to join, thrive and lead in cyber security. By doing so, we will strengthen not only our workforce, but our national resilience. #WomenInCyber #WomenInTech
-
Tony Vizza reacted on thisTony Vizza reacted on thisWhen a 9 years old Ryan empathy and action will put most adult to shame. When 9-year-old Ryan Kyote saw a news story about a young girl having her school lunch taken away because of unpaid meal fees, it bothered him. The third grader from Napa, California, couldn't understand why a child should have to worry about money while simply trying to eat lunch at school. Ryan started asking his mother, Kylie Kirkpatrick, how things worked at his own school. She contacted the Napa Valley school district and learned that students there would still receive a hot meal even when their accounts had negative balances. But those unpaid charges could accumulate as debt for their families. Ryan then wanted to know something else: how much did the students in his entire third grade owe? The answer was $74.50. Ryan had been saving his allowance, money he would normally use to buy sports gear. When his mother asked what he wanted to do after hearing the total, his response was simple. He wanted to pay it. Ryan brought his savings to West Park Elementary and cleared the outstanding lunch balances for the entire third grade. He originally wanted the donation to remain anonymous because, according to his mother, he wasn't interested in bragging about what he had done. His small act eventually became part of a much larger conversation about school meal debt. Later that year, California Gov. Gavin Newsom publicly thanked Ryan when signing legislation designed to prevent students with unpaid meal fees from being singled out or given a different meal. One third grader's $74.50 decision had traveled much further than he ever expected. . // Robin // #MemeLord // .
Experience
-
Founder and Managing Partner
Novera
- Present 1 year 8 months
Sydney, New South Wales, Australia
As the Founder and Managing Partner of Novera, I lead a team of digital risk management professionals with deep expertise in cybersecurity, AI and IT risk management to deliver tangible value and outcomes to our clients.
I have been successfully helping clients with their information technology, cyber and now AI risk challenges and problems for over 25 years and am excited to lead a fantastic team of professionals that offers a comprehensive suite of services to help businesses identify,…As the Founder and Managing Partner of Novera, I lead a team of digital risk management professionals with deep expertise in cybersecurity, AI and IT risk management to deliver tangible value and outcomes to our clients.
I have been successfully helping clients with their information technology, cyber and now AI risk challenges and problems for over 25 years and am excited to lead a fantastic team of professionals that offers a comprehensive suite of services to help businesses identify, assess and mitigate digital risks to ensure robust and resilient protection of their digital assets. -
Teaching Fellow - Faculty of Law and Justice
UNSW
- Present 1 year 5 months
Sydney, New South Wales, Australia
Teaching Fellow appointment at the University of New South Wales Faculty of Law and Justice.
I will be teaching LAWS8398/LAWS9812 Introduction to Law and Policy for Cyber Security.
The course will offer an introduction to law and policy issues in cyber security for postgraduate students who do not have a primary degree in Law. It introduces relevant core concepts (including regulation, common law and statute) and doctrines (including tort and contract), with a specific focus on the…Teaching Fellow appointment at the University of New South Wales Faculty of Law and Justice.
I will be teaching LAWS8398/LAWS9812 Introduction to Law and Policy for Cyber Security.
The course will offer an introduction to law and policy issues in cyber security for postgraduate students who do not have a primary degree in Law. It introduces relevant core concepts (including regulation, common law and statute) and doctrines (including tort and contract), with a specific focus on the cyber context. Relevant legislation in areas such as privacy, telecommunications, critical infrastructure, criminal law, national security and law enforcement will be analysed to understand how they might affect the behaviour of both attackers and defenders. The focus is on Australian law, but comparative material is included where relevant, particularly where it impacts Australian industry. Topical matters in international law are also explored. -
Cybersecurity Committee Member
The Australian Bar Association
- Present 1 year 11 months
Sydney, New South Wales, Australia
As a Cybersecurity Committee Member at the Australian Bar Association, I play a pivotal role in strengthening cyber resilience within the legal community. By leveraging my expertise in cybersecurity and digital risk management, I assist in developing strategies to protect barristers and legal professionals from cyber threats. My contributions help enhance the overall security posture of the Australian legal sector.
-
Executive Committee Member, Cybersecurity Committee - ASFA
ASFA | The Voice of Super
- Present 9 months
Sydney, New South Wales, Australia
Serving on the Executive Committee of ASFA’s Cybersecurity Committee, with a focus on advancing practical, risk-based cybersecurity outcomes for the Australian superannuation industry. Contributing to discussion on cyber resilience, governance, regulatory expectations, and emerging threats impacting funds, service providers, and member trust.
View Tony’s full profile
-
See who you know in common
-
Get introduced
-
Contact Tony directly
Other similar profiles
Explore more posts
-
James Orr
Cyber Wyze • 2K followers
These 5 key strategic items should be on every Australian businesses radar in 2026. 1. Privacy enforcement is no longer complaint driven The law moved in 2024. The behaviour change is happening now. OAIC has the power to issue fines, compliance notices, run sweeps, and force remediation without waiting for a breach. If your privacy policy, data handling, suppliers, or AI use don’t reflect reality, you don’t just have a gap, you have a regulatory trigger. 2. Cyber assurance is becoming a commercial gate, not a safeguard Cyber is now being used to decide who gets awarded contracts, insured, onboarded, or procured, especially in Defence, government supply chains, finance, and critical services. “We’re working on it” is no longer a neutral position. It will actively exclude you from opportunities in 2026 and beyond. 3. Supply chain risk is being pushed downstream Large organisations are shifting liability and assurance obligations onto suppliers. Questionnaires, attestations, audits, contract clauses, insurance exclusions. If you can’t evidence security controls, you could fail to meet emerging requirements, including your ability to supply. 4. AI use is moving from experimentation to accountability It doesn’t matter if you built it, bought it, or “just turned it on”. If AI influences pricing, hiring, customer decisions, or data processing, you own the outcome. Businesses need to think about whats in use, where the data comes from, goes to, and who is accountable when it goes wrong. 5. Businesses are being judged on timing, not intent Waiting for certainty is now seen as a governance failure. Regulators and insurers are looking at whether action was taken when risk was known, not whether it was eventually addressed. Late compliance costs more, commercially and reputationally.
10
-
Dynamic Standards International (DSI)
3K followers
Australian SMBs complete an average of 35 cybersecurity questionnaires annually. Each one takes weeks. Each one asks different questions. None provides legal assurance. This is why Dynamic Standards International (DSI) created SCAP, the Supplier Cyber Assurance Program. Instead of endless assessments, one certification provides the proof they need. With the launch of SMB1001:2026, MSPs who adopt SCAP can empower their clients to replace questionnaires with legally binding attestations. This not only gives your clients real proof but frees up weeks of productive time for both of you. SCAP shifts the market from promises to proof. From assessments to assurance. 👉 The 2026 standard is now live. Download it today on the link below. 🔗 https://lnkd.in/giyvBTD5
3
-
Cyber Daily
4K followers
#PODCAST: Daniel Croft and David Hollingworth touch on the latest in AI news, concerning developments in the world of cyber crime, and recommendations by the Law Council of Australia regarding the next phase of the nation’s Cyber Security Strategy. Tune in: https://bit.ly/467yWHC
-
Privacy108 Consulting
723 followers
Australians care deeply about privacy and have clear ideas of when personal information handling is fair. The latest Australian Community Attitudes to Privacy Survey revealed that Australians expect safeguards to be in place for AI use. Community expectations around transparency of AI usage is likely to inform the implementation of the forthcoming automated decision-making (ADM) transparency obligation, which will require regulated entities to provide details regarding their use of ADM in their privacy policies from December 2026. Keen to learn more about what Australians expect from organisations when it comes to privacy? Check out our post: https://lnkd.in/e5H636cN
4
-
Independent Voice
66 followers
Hackers don’t discriminate — are YOU their next target?” Think cyber-attacks are only for big corporations? Wrong. NDIS small businesses are increasingly in the crosshairs — and most don’t even know they’re exposed. One click. One weak password. That’s all it takes to lose trust, data, and clients. But here’s the good news: A practical, no-nonsense Cybersecurity Checklist has just dropped — designed specifically for NDIS, Regional SMEs, local government and end users. It’s FREE. It’s simple. And it could be the smartest move you make all year. Get the checklist here and lock the digital door before someone breaks in: https://lnkd.in/gdJTT5nr #NDIS #CyberSecurity #SmallBusinessSafety #SME #RiskManagement #ClientTrust #DataProtection #BusinessContinuity #ChecklistReady
1
-
Debbie Reynolds
Debbie Reynolds Consulting… • 41K followers
🎙️LISTEN NEW DATA DIVA TALKS PRIVACY PODCAST EPISODE🎙️ Introducing 🎙️ The Data Diva Talks Privacy Podcast – Episode 274 Liz MacPherson Deputy Privacy Commissioner, Office of the Privacy Commissioner, New Zealand In this episode, Liz and I explore why privacy is not an obstacle to innovation, but one of its most important enablers. We dive into how New Zealand approaches biometric governance, facial recognition, and data protection through purpose, context, and proportionality rather than consent theater. We discuss: 🔐 Why privacy guardrails allow innovation to move faster and safer 🧠 The risks of facial recognition and why it is not a plug-and-play technology 🏪 A real-world supermarket case study involving biometric trials and independent evaluation ⚖️ How purpose, necessity, and proportionality shape lawful data use in New Zealand 📊 Why effectiveness testing matters before deploying high-risk technologies 👁️ The dangers of inference, misidentification, and bias in biometric systems 🗑️ Why data retention is the sleeping giant of cybersecurity risk 🌱 How putting people at the center of data decisions builds long-term trust 🎧 Listen to the full episode here: https://lnkd.in/gJRyY-4G About The Data Diva Talks Privacy Podcast: This award-winning podcast has been downloaded over 1 million times and reaches listeners in 158 countries. Each week, I speak with global leaders on data privacy, cybersecurity, AI, and emerging technology, sharing insights businesses need to retain value, reduce risk, and increase revenue. Become an insider. Join Data Diva Confidential for data strategy and data privacy insights delivered to your inbox. 💡 Expert briefings, practical guidance, and exclusive resources you will not find anywhere else. 👉 Join here: http://bit.ly/3Jb8S5p Debbie Reynolds Debbie Reynolds Consulting, LLC #DataPrivacy #Biometrics #FacialRecognition #Trust #AI #Governance #PrivacyLeadership #DataDiva
39
3 Comments -
Savira
68 followers
The APPs are changing - and so should your approach to privacy compliance. Australia's privacy reforms are bringing stricter requirements and much higher penalties. The 13 Australian Privacy Principles that govern how you handle personal information are about to get teeth. Don't wait for reforms to pass. Understanding your current obligations and preparing for changes now will save headaches (and potentially millions) later. Need help navigating the APPs? That's what we're here for. #MakingComplianceEasy #PrivacyAct #AustralianBusiness
5
-
InPlace Software
2K followers
Are you confident in your institution’s privacy compliance? With tightening privacy laws across Australia, the UK, and the US, education providers face greater scrutiny, higher penalties, and growing expectations from regulators and insurers. It’s no longer a question of if you’ll need to prove compliance, but how quickly you can. Manual processes aren’t keeping up. Privacy requests, data retention, and audit preparation can take days, with limited visibility and no defensible tracking. That’s why we launched InPlace Privacy Management, turning privacy from a reactive burden into a built-in capability: → Automated, policy-aligned retention → Privacy requests processed in minutes → Protected records for investigations → Complete audit trails for regulators and insurers Less risk. Less manual effort. More confidence. Learn more: https://lnkd.in/gcnxrh66 #HigherEducation #VocationalEducation #PrivacyCompliance #RiskManagement #EdTech
8
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More