
Summit 2026 · The Goodie Bag
Global perspectives on managing cyber security and AI risks.
Thanks for joining the session. This is the companion page to Chris Hawksworth's talk - a smorgasbord of managing the risks that come with AI in the face of growing cyber security challenges. Everything we referenced is in one download below.
Chris Hawksworth · Founder & CEO, Speculo
One ZIP · ~40 MB · no sign-up, none of it is gated.
What we covered
AI attacks are already live - this is a risk conversation, not a future one.
From the $25M Arup deepfake heist to a Claude-assisted extortion spree and a 64-million-record breach behind the password “123456”, every headline traces back to the same four gaps. AI adoption has reached critical mass; governance has not.
of organisations are actively using AI across business functions
have a comprehensive AI governance framework in place
of breached organisations lacked proper AI access controls
don't know how long it would take to halt an AI system mid-incident
Four gaps between AI adoption and AI governance.
The spine of the talk. Each gap maps to a real incident - and to the metrics and frameworks that close it.
The governance gap
No AI inventory, no vendor AI oversight, no baseline controls on the AI already embedded in your SaaS. You can't govern what you can't see - visibility comes before policy.
No true measurement
Annual audits can't keep pace with AI-speed attacks. Inventory coverage, shadow-AI ratios, incident-response readiness - the metrics that actually complement your cyber framework.
One risk, four languages
The same AI risk needs a different lexicon for the board, for risk & compliance, for engineering, and for the frontline. Translation is a governance skill, not a soft one.
Expertise catching up
The professionals best placed to close the AI governance gap aren't in security - they're in risk. This is the opportunity, and the skillset most organisations don't have yet.
Start with visibility, not policy. Translate risk into board language. Build capability before the regulation arrives.
Before you go
What's in the goodie bag.
The compact deck plus the fuller version, the companion deep-dives, and the standards kits and reference material we pointed to. Pick one metric to start with, inventory one system, and go from there.
The talk
- RiskNZ Summit - full presentation (PPTX)
- RiskNZ Summit - compact final deck (PPTX)
Speculo resources
- Speculo AI Security Framework
- Speculo AI controls (CSV, HTML & PDF)
- What CISOs Must Ask AI Security Vendors
Standards & policy kits
- ISO/IEC 42001 Audit-Ready AIMS Manual
- ISO/IEC 42001 Scope & Evidence Intake Kit
- EU AI Act-Ready AI Governance Policy Suite
Reference & research
- Gartner Magic Quadrant for AI Governance Platforms
- US Executive Order 14409
- Top 10 Framework URLs for Risk Practitioners
- Wiz GenAI Security best-practices bundle (3 guides)
~40 MB · no sign-up required
Or scan to open this page
speculo.co.nz/risknz-summit
Frameworks are free. Knowing where to start isn't.
Speculo helps NZ risk and security teams turn AI governance from a policy document into an evidenced, board-ready position. If the talk landed, let's carry on the conversation.