ITSPmagazine

Bridging the Cybersecurity Divide Between the Haves and Have-Nots: Lessons from Australia’s CISO Community | A Conversation with Andrew Morgan | Redefining CyberSecurity with Sean Martin

Nov 5, 2025
Andrew Morgan, a seasoned cybersecurity leader and former detective, shares insights on the pressing issue of the cybersecurity divide between well-resourced and underfunded organizations. He emphasizes the critical need for basic security hygiene and resilient planning for smaller entities. Morgan discusses Australia's cyber maturity, effective peer collaboration, and how AI can enhance awareness and training. He argues for the importance of building meaningful partnerships and champions a culture-first approach to risk management, highlighting the real-world impact of cyber failures.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

From Detective To CISO

  • Andrew Morgan described his career path from detective in Victoria police to DFIR and then CISO roles across NBN and universities.
  • He used that journey to explain how hands-on forensics and SOC experience shaped his risk-focused leadership style.
INSIGHT

Cyber Needs Risk-Centered Culture

  • Morgan argued cyber should be driven by culture and informed by risk, not treated as an IT subset.
  • He said governance, risk, and compliance must be the centerpiece of security programs.
INSIGHT

Tool Sprawl Masks Real Risk

  • Overbuying tools without strategy creates overlap, noise, and false confidence for smaller orgs.
  • He recommended threat-modeling assets and quantifying risk in business terms before buying tech.
Get the Snipd Podcast app to discover more snips from this episode
Get the app