CISO Roundtable

Shadow AI: What 70,000 Security Assessments Reveal

Adopted. Unsanctioned. Exposed. Accountable.

A closed-door conversation for CISOs on what the largest dataset of its kind reveals about the AI tools already running inside their business, and what's quietly leaving through them.

Sydney Thurs 24th Sept 12:00 to 2:00pm Venue TBC

Overview

More than 70,000 security assessments turned up the same pattern. AI gets adopted by whoever finds it useful, long before anyone signs off on it. It stays unsanctioned because approving it properly feels slower than the work it's replacing. Then something gets exposed: a contract, some source code, a customer record, pasted into a tool nobody vetted. Whatever happens next lands on the CISO, whether or not they knew the tool existed.

This session is hosted by CyberCX, Accenture and Microsoft, putting that research in front of senior security leaders in Sydney for a closed-door conversation about where that cycle is already running inside their own organisation, and what a defensible response looks like that doesn't just ban the tools people have already decided they need.

It runs under Chatham House rules, small and invitation-only.

Talking points

Adopted. Unsanctioned. Exposed. Accountable.

01

Adopted

What the data actually shows about how AI tools spread inside organisations before anyone approves them.

02

Unsanctioned

Giving people an approved option good enough that they stop reaching for the one you didn't sign off on.

03

Exposed

What's already left the building through a tool nobody approved, and how you'd actually know.

04

Accountable

What a defensible AI governance policy looks like in practice, not just on paper.

"Organisations are adopting AI systems faster than they can secure them."
Liam O'Shannessy, Executive Director, Security Testing & Assurance, CyberCX

Hosted by

CyberCX, part of Accenture

One of the largest cybersecurity providers in Asia Pacific, with deep experience across ANZ government and critical infrastructure.

Brings global security and applied AI expertise to the partnership, following its acquisition of CyberCX earlier this year.

Its security platform, spanning Azure, Defender, Sentinel, Purview and M365, underpins much of the environment this conversation is about.

Register your interest

Seats are limited and held by invitation. Complete the form and the team will be in touch to confirm your place.

CitySydney
DateThurs 24th Sept
Time12:00 to 2:00pm
VenueTBC