Session 2.6d Update: Your Cyber Report is not a Decision: Translating Findings into Mission Impact and Executive Action
Tracks
ㅤ
| Wednesday, November 18, 2026 |
| 1:30 PM - 2:30 PM |
| Nicholls Theatre |
Presentation Outline
Defence organisations are producing more cyber evidence than ever: threat intelligence, vulnerability assessments, penetration tests, security monitoring, supply-chain assurance and AI risk assessments. Yet more reporting does not automatically create decision advantage. When findings remain expressed as technical severity ratings, control deficiencies or lengthy reports, senior leaders may lack a clear understanding of mission effect, operational consequence, urgency or residual risk.
This non-commercial update examines the gap between cyber evidence and Defence capability decisions. It presents a practical chain that converts technical findings into five elements: evidence, credible exposure, mission or capability effect, the decision required and residual risk. Using de-identified examples from Defence, government and critical infrastructure, the presentation will show where cyber reporting fails, how significant issues become obscured by volume, and how technical integrity and traceability can be maintained while communicating clearly at executive level.
The session will consider evidence across military information systems, software supply chains, cloud and on-premises environments, AI-enabled capability and allied interoperability. Attendees will leave with a vendor-neutral method for determining what leaders need to know, what supports the conclusion, what action is required and what may occur if no action is taken.
Intended audience:
Defence executives, capability managers, DDG, CASG and ICT leaders, cyber and assurance professionals, architects and industry partners assuring Defence capability.
Key takeaways:
Participants will be better able to distinguish technical severity from mission consequence, convert complex findings into decisions, maintain traceability between evidence and executive advice, identify when reporting volume conceals material risk, and communicate residual risk clearly.
Speaker
Ms Sam Maher
Head of Federal Government
NCC Group Australia
ㅤ
Biography
Sam Maher is NCC Group’s Australian Federal Government Lead, with nearly 30 years of experience across government, industry and highly regulated environments. She specialises in translating complex technical evidence, cyber risk and emerging technology into decisions senior leaders can understand and act on.
Her experience spans Defence capability, technical assurance, secure systems, cyber resilience, crisis management, incident response, rapid response, AI governance and cloud adoption. She has advised government executives, boards and delivery teams on the operational, commercial and policy implications of technology risk, including during periods of disruption, uncertainty and heightened threat. Sam’s Australian Government and Defence experience is supported by NCC Group’s work across UK Government, Defence, critical national infrastructure, AUKUS and FVEY environments.
Her experience spans Defence capability, technical assurance, secure systems, cyber resilience, crisis management, incident response, rapid response, AI governance and cloud adoption. She has advised government executives, boards and delivery teams on the operational, commercial and policy implications of technology risk, including during periods of disruption, uncertainty and heightened threat. Sam’s Australian Government and Defence experience is supported by NCC Group’s work across UK Government, Defence, critical national infrastructure, AUKUS and FVEY environments.