Cyber security is a subject where the same forty minutes cannot serve every audience. A board wants to know what it is accountable for. A general staff audience wants to know what to do differently with their own inbox. A practitioner audience wants substance and will disengage fast from anything that feels like an awareness video.
Brief the wrong room and a strong Speaker looks flat. So the six below are grouped by the audience they suit rather than by topic, and most of them work well across more than one.
If you want to look more broadly first, the Cyber Security and Asia Speakers collections are the place to start.
David Gee spent his executive career running security at the scale most boards are only now grappling with. He was Chief Information Security Officer for HSBC Asia Pacific, leading cyber across nineteen markets, then Global Head of Technology, Cyber and Data Risk at Macquarie Group, with earlier Chief Information Officer roles at MetLife Japan and Eli Lilly. He is the author of The Aspiring CIO and CISO and A Day in the Life of a CISO, and in 2025 was appointed an Ambassador for CI-ISAC Australia. For a board that needs to understand its own exposure rather than admire someone else's, he is the most direct fit on this list, and his Asia career means the examples land in the region rather than being translated into it.
Shamane Tan works on the part most boards actually struggle with, which is the conversation between the security function and the people above it. Based in Singapore, she is the author of Cyber Risk Leaders and co-author of the bestselling Cyber Mayday and the Day After, both built from interviews with executives who have lived through a crisis. She founded Cyber Risk Meetup, a community spanning Sydney, Melbourne, Singapore, the Philippines and Tokyo, and she has been named among IFSEC Global's top influencers in cyber security. Strong choice for a leadership offsite or a risk committee session where the goal is better questions rather than more information.
Confidence Stavely removes the jargon without removing the substance, which is harder than it sounds and rarer than it should be. Founder and Executive Director of the CyberSafe Foundation, a Forbes Technology Council member and the 2023 Cybersecurity Woman of the World, she is best known for explaining API security through cooking metaphors on her series API Kitchen. Her session on artificial intelligence in the hands of attackers works particularly well for a mixed audience where technical fluency varies widely across the room.
John Sileo has the story that makes the risk real. A trusted insider used his identity to embezzle from his clients, which destroyed his business and cost him two years fighting to stay out of jail. He now speaks on the human side of security for audiences including the Pentagon and Amazon, using live phone hacking and humour rather than fear. He is a National Speakers Hall of Fame inductee and has appeared on 60 Minutes. Best suited to an all staff session where the goal is behaviour change rather than policy comprehension.
Dr Toby Feakin served six years as Australia's inaugural Ambassador for Cyber Affairs and Critical Technology, advising multiple Prime Ministers and Foreign Ministers on where cyber security, technology and geopolitics intersect. He previously helped establish the International Cyber Policy Centre at the Australian Strategic Policy Institute. For government audiences, critical infrastructure operators and any organisation whose risk picture includes state actors across the Indo Pacific, he speaks from inside the rooms where those positions were formed.
Dr Mahsa McCauley brings the research and education perspective. She is an Associate Professor and Head of Computer and Information Sciences at Auckland University of Technology, Chair of AI Forum New Zealand, a Fulbright Scholar and a Communication and Information Commissioner for the New Zealand National Commission for UNESCO. She has authored more than eighty publications across artificial intelligence, machine learning and cyber security, and founded She Sharp to support women and non binary people in technology. Suited to universities, government bodies and any programme pairing security with a technology equity or workforce theme.
Who in the room can actually act on this? If the session is aimed at behaviour nobody present controls, it will be well received and change nothing.
What has this audience already sat through? Many organisations run annual awareness training. A Keynote that repeats it wastes the slot. Tell the Speaker what has already been covered.
Is this the opening or the closing session? Security content in the final slot after lunch needs a different energy from security content that sets up a day. The Speakers above differ sharply on this, and it is worth asking.
Security Speakers with regional credibility book early, particularly around October. If you are shaping a programme for an Asia Pacific audience, our team can talk through which of these suits your room before you commit to a name.