Perth’s Cybersecurity Leaders to Watch

Related

Share

Perth sits closer to Jakarta than to Sydney, and its security community has grown up largely on its own terms. Much of it runs through the Western Australian public sector: a whole-of-government security office, the state police, a state insurer, a water utility that serves the entire state, and a major public hospital. The five leaders below cover that ground, along with an international education group operating in 24 countries. Several have held security leadership at more than one of the state’s institutions.

Peter Bouhlas – WA CISO, Office of Digital Government

Peter Bouhlas has served as Western Australia’s Chief Information Security Officer since July 2018, leading cyber security across the whole of state government. In that role he established the state’s Cyber Security Operations Centre and built its threat intelligence and incident response capabilities. He came to the job from the Office of the Auditor General, where as Senior Director of Information Systems and Performance Audit he set the approach for auditing information systems across the WA public sector, with a heavy focus on cyber security, risk, and continuity planning. Earlier he managed more than 20 large software implementations for agricultural, mining, and oil and gas clients in Australia and overseas. He also consulted for the World Bank and the Asian Development Bank on ICT strategy and audit work across more than 15 countries. Bouhlas sits on the board of the Security Research Institute at Edith Cowan University.

Robbie Whittome – Cyber Security Manager, Serco

Robbie Whittome spent nearly a decade at Curtin University, rising from manager of IT security and risk to Chief Information Security Officer and Head of Digital Identity. As CISO from 2020 to 2025 he led a $20 million-plus digital identity transformation, including IAM consolidation and MFA, delivered on time and within budget. He also ran a $5 million cyber maturity programme that improved detection, response, and restoration times by up to 90%, and established Curtin as a reference partner for the university sector under the Security of Critical Infrastructure regime. His security career began at WA Police, where he worked up from systems support to acting manager of information security, running the agency’s 24/7 security operations and incident response. After a stint consulting on business continuity at MaltIQ, Whittome joined Serco in February 2026 to lead cyber security for the Fiona Stanley Hospital contract. There he works with South Metropolitan Health Service to reduce disruption to clinical services.

Karen Owens – Head of Security and Risk (CISO), Insurance Commission of Western Australia

Fraud investigation was where Karen Owens started. She spent more than 11 years at HBOS in the United Kingdom investigating staff fraud across the branch network and managing physical security. Six years as Information Security Manager at Intelligent Finance followed before she moved to Perth and joined Bankwest. There she built the bank’s security design and consulting practice, managing up to 70 concurrent projects and holding 100% team retention over three years. Owens spent more than five years leading information security, risk, and governance at Edith Cowan University, then became CISO of the WA Police Force in 2020. She later served as its Chief Technology Officer, periodically acting as Assistant Commissioner. After a period in cyber coordination at the Australian Energy Market Operator, she became Head of Security and Risk and CISO at the Insurance Commission of Western Australia in October 2024. She has chaired the Perth branch of the Australian Information Security Association and holds CISSP and SABSA qualifications.

Gavin Ryan – Global Head of Information Security, Navitas

Gavin Ryan spent 13 years at Ernst & Young leading cyber security and IT advisory work, running programme management offices for enterprise security uplifts and helping clients build ISO 27001-certified management systems. Navitas recruited him in 2017 to build a cyber security function from scratch for an education group of more than 6,000 staff across 24 countries and 120 locations. He has since delivered a board-endorsed three-year cyber security strategy grounded in the NIST framework, co-authored a five-year enterprise IT strategy, and taken the organisation to ISO 27001 certification. He briefs the board every six months. Ryan was named a CSO30 winner in 2022 and received CrowdStrike’s Falconer Award the same year. He sits on customer advisory boards for CrowdStrike and Bugcrowd, and holds CISSP, CISM, and CISA certifications.

Chad Madaffari – Cyber Security Manager, The Kids Research Institute Australia

Chad Madaffari began in technical customer service at Getronics and worked his way through desktop and network support roles in rail infrastructure. He spent more than nine years at Wesfarmers Chemicals, Energy & Fertilisers, moving from network engineer to security engineer to Cyber Security Lead. In that last role he designed a three-year security strategy covering 36 initiatives and 80 projects, introduced board-level reporting of cyber risk, and established the business’s first formal information security management system. In 2020 he joined Water Corporation as Manager of Cyber Security for the state-wide water and wastewater provider. There he governed an $83 million, five-year modernisation programme, led readiness under the Security of Critical Infrastructure reforms, and cut incident containment time by 60%. He joined The Kids Research Institute Australia as Cyber Security Manager in September 2026.

Security Built for Isolation

Distance has shaped how Perth builds its security leaders. Bouhlas audited the state’s information systems before taking charge of defending them. Owens and Whittome both held security leadership at WA Police and then carried that experience into a state insurer and a major hospital. Madaffari brought an industrial operator’s discipline to a water utility serving the whole state, and Ryan built a global programme for an education group from an office in Perth. With the nearest large security market a four-hour flight away, the state’s institutions have tended to grow their own expertise and then keep it circulating. The result is a bench that knows Western Australia’s public infrastructure from several angles at once.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.