RiskNZ

Summit 2026 · The Goodie Bag

Global perspectives on managing cyber security and AI risks.

Thanks for joining the session. This is the companion page to Chris Hawksworth's talk - a smorgasbord of managing the risks that come with AI in the face of growing cyber security challenges. Everything we referenced is in one download below.

Chris Hawksworth · Founder & CEO, Speculo

One ZIP · ~40 MB · no sign-up, none of it is gated.

What we covered

AI attacks are already live - this is a risk conversation, not a future one.

From the $25M Arup deepfake heist to a Claude-assisted extortion spree and a 64-million-record breach behind the password “123456”, every headline traces back to the same four gaps. AI adoption has reached critical mass; governance has not.

88%

of organisations are actively using AI across business functions

8%

have a comprehensive AI governance framework in place

97%

of breached organisations lacked proper AI access controls

56%

don't know how long it would take to halt an AI system mid-incident

Four gaps between AI adoption and AI governance.

The spine of the talk. Each gap maps to a real incident - and to the metrics and frameworks that close it.

Gap 1 · Governance

The governance gap

No AI inventory, no vendor AI oversight, no baseline controls on the AI already embedded in your SaaS. You can't govern what you can't see - visibility comes before policy.

Gap 2 · Measurement

No true measurement

Annual audits can't keep pace with AI-speed attacks. Inventory coverage, shadow-AI ratios, incident-response readiness - the metrics that actually complement your cyber framework.

Gap 3 · Language

One risk, four languages

The same AI risk needs a different lexicon for the board, for risk & compliance, for engineering, and for the frontline. Translation is a governance skill, not a soft one.

Gap 4 · Expertise

Expertise catching up

The professionals best placed to close the AI governance gap aren't in security - they're in risk. This is the opportunity, and the skillset most organisations don't have yet.

Start with visibility, not policy. Translate risk into board language. Build capability before the regulation arrives.

Before you go

What's in the goodie bag.

The compact deck plus the fuller version, the companion deep-dives, and the standards kits and reference material we pointed to. Pick one metric to start with, inventory one system, and go from there.

The talk

  • RiskNZ Summit - full presentation (PPTX)
  • RiskNZ Summit - compact final deck (PPTX)

Speculo resources

  • Speculo AI Security Framework
  • Speculo AI controls (CSV, HTML & PDF)
  • What CISOs Must Ask AI Security Vendors

Standards & policy kits

  • ISO/IEC 42001 Audit-Ready AIMS Manual
  • ISO/IEC 42001 Scope & Evidence Intake Kit
  • EU AI Act-Ready AI Governance Policy Suite

Reference & research

  • Gartner Magic Quadrant for AI Governance Platforms
  • US Executive Order 14409
  • Top 10 Framework URLs for Risk Practitioners
  • Wiz GenAI Security best-practices bundle (3 guides)
One download, everything included
Download the goodie bag (ZIP)

~40 MB · no sign-up required

Or scan to open this page

QR code linking to speculo.co.nz/risknz-summit

speculo.co.nz/risknz-summit

Frameworks are free. Knowing where to start isn't.

Speculo helps NZ risk and security teams turn AI governance from a policy document into an evidenced, board-ready position. If the talk landed, let's carry on the conversation.