This is the keynote given by Professor Attila Brungs at UNSW Cyber Security Summit on Tuesday, 26 May 2026

I acknowledge the Bedegal People, the traditional custodians of these lands – where we are privileged to create and share knowledge – just as knowledge has been shared on this land for tens of thousands of years.

I pay my respects to Elders, past and present, and I extend that respect to Aboriginal and Torres Strait Islander people who are here today.

Thank you to Derek Winter and the teams across cyber security, technology, research and operations who have brought this event together. And welcome to our colleagues and partners from government, industry and the university sector.

Giving the introduction to a room with this level of expertise is basically singing karaoke accompanied by the Sydney Symphony Orchestra. I can’t help feeling the real music begins when I leave.

One of the comforting things about university is that no matter how complicated the world becomes, there is always somebody nearby who understands it at a frightening level of detail. Looking through today’s program, I feel reassured by the depth of expertise we have here at UNSW and among our partners.

At the same time, I think there’s also a shared sense that the ground is moving quite quickly beneath all of us.

Cyber security – if it ever was - is no longer the cliché of a niche technical discipline sitting quietly in the basement beside a blinking server rack and a forgotten foosball table.

Cyber security now sits at the centre of:

  • Economic resilience
  • National security.
  • Research integrity.
  • Democracy.
  • Social trust.
  • And increasingly, human identity itself.

I was thinking about that recently when reading about the ransomware attack on Canvas, the online learning platform used by universities and schools around the world.

Now students think of Canvas as the place where lecture recordings live and deadlines appear unexpectedly. But suddenly this very familiar educational tool became part of a global cyber security story involving ShinyHunters, stolen data, ransom demands and concerns about the exposure of student and staff information across thousands of institutions.

And then came the surreal part: “Instructure reached an agreement with the unauthorised actor involved in this incident.”

That is issues management-speak for a global education platform paid a massive ransom to organised criminals.

Think about how strange that story would have sounded even ten years ago.

Educational institutions — places of libraries, lectures and learning — suddenly finding ourselves in a world of espionage thrillers and sabotage of critical infrastructure.

And I think stories like that land differently in universities than they might elsewhere.

Because universities are unusual organisations.

We are designed to be open, we collaborate internationally, we connect thousands upon thousands of people across research, teaching and public engagement.

That openness is one of our great strengths. But it also creates a very complicated operating environment when the threat landscape changes as rapidly as it now is.

Canvas is not even the most confronting story to drop into the cyber security space.

Last month Anthropic – possibly forced by a leak – announced Claude Mythos, a model that represented a step-change in capability so significant that it couldn’t be released publicly.

Mythos’ long-horizon reasoning and cyber vulnerability discovery was such an advance, Anthropic distributed it only to a small consortium of organisations, so they could use it to protect the systems operating global infrastructure before bad actors got access to a cyber doomsday device.

I’m sure many people in this room immediately started thinking about the implications of Mythos.

If the previous generation of AI could create Mythos, what sort of cyber tool would Mythos be able to design? And what will be the power and reach of the tool that that next generation AI creates?

I don’t say any of this in an alarmist way. One of the things I appreciate about the cyber security community is that people working in the field tend to be practical. You don’t delude yourself that the world is simpler than it is.

Technology evolves. Threats evolve. Systems evolve. Human behaviour evolves. It always will, but importantly we adapt and keep going.

The same AI systems capable of accelerating cyber attacks are also becoming extraordinary defensive tools.

AI can already identify anomalies in networks faster than human teams. We use it to detect suspicious behaviour patterns and accelerate incident response.

With AI we can model vulnerabilities and protect critical infrastructure.

UNSW startups and spinouts are using AI to strengthen medical systems and support disaster response.

Our mission at UNSW is to use AI to augment human capability rather than replace it.

That distinction matters enormously. There is a tendency in public debate to frame AI as a competition between humans and machines. I think that is the wrong frame.

The more interesting question is: How do humans and intelligent systems work together in ways that amplify human strengths?

Because empathy can be enhanced by intelligence. Human judgement improves with better data. Scientific creativity is empowered by computational capability.

In February, Daniela Amodei, co-Founder and President of Anthropic gave an interview in which she said: “In a world where AI is very smart and capable of doing so many things, the things that make us human will become much more important.”

She was talking about how advances in AI may actually increase the value of capabilities that are uniquely human — judgement, empathy, creativity, ethics, connection and, of course, trust.

I think we’re entering a period where what cyber security is no longer just about protecting servers or systems or passwords. It’s also about protecting trust:

  • Trust in institutions.
  • Trust in research.
  • Trust in communication.
  • Trust that people are who they say they are.
  • Trust that information is authentic.

Trust is intrinsically human. It can’t be outsourced to AI.

Cyber security problems are almost never purely technical. Quite often they’re ordinary human problems expressed through technology.

A phishing email works because somebody trusts something they shouldn’t. A scam works because somebody is frightened or distracted or under pressure. Disinformation works because human beings are social and emotional creatures, not perfectly rational machines.

Which means technical capability matters enormously — of course it does — but culture matters too.

And this is one of the reasons I’m pleased to see so much collaboration represented in today’s summit.

Cyber security has become one of those areas where cooperation is not optional.

The bad actors cooperate very effectively. Unfortunately, they often have excellent customer service as well, which is slightly depressing when you think about it.

But the broader point is serious. No university can manage these challenges entirely alone. No company can. No government agency can.

We need strong relationships between institutions, between disciplines and between sectors.

The students coming through universities now are entering a world where cyber security capability is becoming relevant across almost every field.

Some will become specialists, of course. Others will work in policy, research, healthcare, defence, finance, education or infrastructure where cyber resilience is simply part of professional life. And many of them will work in jobs that don’t even exist in dreams.

Which I know is a slightly unsettling thing for universities because we do like a well-structured curriculum. But it does mean we have to think carefully about what kinds of graduates we’re trying to develop.

We have an outstanding record of developing technical excellence. Will we be equally successful at continuing to develope adaptability and ethical judgement and the ability to collaborate across disciplines?

These capabilities are even more critical in an AI world. And here’s a challenge. The talent to explain complicated things clearly may be one of the most underrated professional skills in modern society.

I suspect many people here have had the experience of trying to explain a serious cyber risk issue to somebody outside the field and watching them slowly drift into a state of polite existential exhaustion.

Part of leadership in this area is helping broader communities understand why these issues matter without overwhelming them. And I think universities are well placed to help with that.

We are institutions built around knowledge-sharing and public engagement. Our purpose is to help society navigate complexity and not ignore it.

Today’s program has been deliberately designed to move us beyond awareness. You will hear about:

  • The AI accelerated threat landscape
  • The growing challenge of identity and trust
  • Risks emerging from our digital supply chains
  • The future of cyber in a post-quantum world.

You will also see these risks brought to life through demonstrations, including how convincingly AI can impersonate individuals in real time. Importantly, many of you will have the opportunity to engage, test and build capability through hands on activities and challenges.

This is not a passive event - it is an active step towards strengthening our collective resilience.

At UNSW we’ve made substantial investments in cyber resilience, systems, governance and capability over recent years, and that work will continue.

But I think we also recognise that there is no final state where an institution declares itself “done” with cyber security. The environment keeps changing. The challenge is ongoing.

Universities are among the few institutions built for long-term thinking. Politics operates in three-year cycles. Markets have quarterly cycles. Social media works in three-second cycles. Universities must think in decades.

That responsibility is becoming more important because the choices we make now around AI governance, cyber resilience and digital trust will shape society for generations.

So thank you all for being here today. Thank you for the work you do across research, operations, teaching, industry and government.

Thank you for helping ensure that as our systems become more powerful and more complex, they also remain trustworthy, collaborative and ultimately human. I hope you have a really productive and enjoyable summit.