Hi Members,
Please join us via Zoom for the July 2026 ISACA Brisbane Professional Development session. Details are as follows:
---
Speaker Biography
Christian Kissane is the ICT Operations & Cybersecurity Manager at Hypersonix Launch Systems, a Brisbane-based aerospace and defence company developing hypersonic scramjet technology. He holds the CISM certification and is responsible for cybersecurity governance, IT operations, and compliance in a defence contractor environment, working across NIST 800-171 and ASD frameworks. Before joining Hypersonix, Christian was the IT Infrastructure Manager at Pareto Phone, where he was on the ground during the 2023 LockBit ransomware attack and the data breach that followed, which affected more than 70 Australian charities. His background covers incident response, third-party data governance, and building out security capability in growing organisations. Christian is currently working towards CISSP certification and studying a Master of Information Technology at QUT.
Session Desciption
In April 2023, Brisbane telemarketer Pareto Phone was hit by a LockBit ransomware attack. Over the following months, the personal data of tens of thousands of charity donors was exposed on the dark web, the OAIC opened an investigation, and the company eventually collapsed. I was Pareto Phone's IT Infrastructure Manager the night the breach was discovered, and I stayed through the response effort in the months that followed.
This session is a straight account of what actually happens inside an organisation during and after a serious cyber incident. I'll walk through the timeline, the decisions we made under pressure, and the operational problems that don't show up in frameworks or tabletop exercises. That includes coordinating communications across dozens of affected charities, dealing with legacy data retention issues that should have been addressed years earlier, responding to regulatory scrutiny, and managing the workload on a small team that was already stretched.
This is not a theoretical review. It's based on what I saw and did. The session will cover practical lessons in incident response, third-party data governance, organisational resilience, and why data minimisation matters more than most organisations realise. Attendees will come away with things they can actually apply to their own incident preparedness, vendor risk management, and breach response planning. I'll leave time at the end for open Q&A so we can have a proper discussion about how to handle these situations better.
Key Audience Takeaways
1. What incident response actually looks like when you're under-resourced and under pressure, and where common frameworks fall short.
2. Why data retention and minimisation are not just governance checkboxes. In this case, holding data for years beyond its use was a direct contributor to the scale of the breach.
3. Third-party risk from the other side of the table. Most people in this room audit vendors. This talk is from the vendor's perspective.
4. Concrete improvements for vendor management and breach response playbooks that come from real mistakes, not theory.
Joining Details:
Online only via Zoom: https://us02web.zoom.us/j/84463992476?pwd=zl3mk21ipnekcIIv7YUaDEUwm5evRu.1
Meeting ID: 844 6399 2476
Passcode: 964403