Skip to main content
Loading

A Facebook Cybersecurity Argument That Escalated Quickly: A Case Study

26 Nov 2026
Seminar Theatre 2

A business owner's Facebook post about a cyber incident sparked an unexpected debate that raises important questions about how organisations think about cyber security.

Following a malware attack that led to attempted BAS fraud through an ATO portal, the incident was attributed to ‘human error’ after an employee opened a malicious document. Yet the discussion revealed a broader issue facing many businesses today: Are we too quick to blame employees when cyber security controls fail?

In this engaging and thought-provoking session, Olga Burtseva draws on a real-world case study to challenge common assumptions about cyber security, risk, and responsibility. Rather than focusing on technical jargon or the latest security products, Olga will explore what effective cyber security looks like in practice and why having the right tools does not always lead to the desired outcomes.

Key Themes

  • Why ‘human error’ is rarely the full story behind a cyber incident.

  • The difference between purchasing security products and achieving security outcomes.

  • How attackers exploit everyday business processes and trusted workflows.

  • Why relying on employees as the primary line of defence is a risky strategy.

  • The importance of layered security controls, detection, response, and continuous improvement.

  • What business owners should ask after a cyber incident instead of simply asking, ‘Who clicked the link?’

What You'll Learn

Attendees will gain practical insights into how modern cyber attacks unfold and why cyber resilience depends on much more than antivirus software, firewalls, or multi-factor authentication. The session will help business leaders better understand where vulnerabilities commonly exist, how to evaluate the effectiveness of their current security measures, and what steps can be taken to reduce risk without creating unnecessary complexity.

Whether you lead a small business, manage operational risk, oversee compliance obligations, or simply want greater confidence in your organisation's cyber readiness, this session will provide actionable takeaways that can be applied immediately.

Because eventually someone will take the bait. Click.

The real question is: What happens next?

Speakers
Olga Burtseva, General Manager - IT First Responder