By Manveer Perhar, Vice President, ECA Online
If your firewall had a personality, it’d ask you to stop shipping shadow AI to prod. This FREE University Short Course turns Artificial Intelligence from “clever but chaotic” into “secure, compliant, and actually helpful” for security teams. Presented by IT Masters with Charles Sturt University (CSU) and led by Dr Georg Thomas, the program shows you how to build guardrails engineers respect and auditors adore—while keeping adversaries bored. Learn how to pivot with Artificial Intelligence.
Why now: attackers sprint, so your governance can’t crawl
CrowdStrike’s 2025 Global Threat Report logged the fastest eCrime breakout at 51 seconds, with an average of 48 minutes (down from 62), and 79% malware-free detections. These numbers demand AI-aware controls that move at incident speed.

Figure 1: eCrime breakout times (fastest vs average; prior-year). Source: CrowdStrike 2025 Executive Summary.

Figure 2: Malware-free detections surged to 79% in 2024. Source: CrowdStrike 2025 Executive Summary.
AI helps defenders—if your processes don’t trip them first
Atlassian’s State of Developer Experience 2025 shows 68% of developers save 10+ hours/week with GenAI, 70% of managers see similar gains—yet 50% still lose 10+ hours to organisational drag. This course replaces drag with disciplined delivery.

Figure 3: GenAI time savings vs. persistent inefficiencies. Source: Atlassian, State of Developer Experience 2025.
Where the Australian jobs and use-cases are lighting up
NAIC (CSIRO/DISR) maps a 2025 sample of 1,533 Artificial Intelligence companies (1,121 private; 412 public). Public-company clusters are strongest in energy/raw materials/utilities (82) and healthcare (77). Build skills where hiring is hot—and standards matter.

Figure 4: Public AI company clusters in AU (sample). Source: NAIC/CSIRO, June 2025.

Figure 5: AU AI company mix (private vs public) in the 2025 sample. Source: NAIC/CSIRO.
Role radar: hire for impact
- Engineering & Technology: AI pipeline security engineers, data-governance leads, prompt-injection red teamers, and AIMS owners to wire ISO/IEC 42001 into the SDLC.
- Healthcare: Clinical AI safety officers; PHI privacy engineers; model validation & audit aligning ISO/IEC 42001 with ISO 27001 and health data controls.
- Mining (Energy & Resources): OT/ICS cyber architects for AI autonomy and predictive maintenance; identity and remote-access hardening.
- Finance: Model risk management, AI transparency, fraud analytics using privacy-preserving ML, third-party and sovereign risk reviews.
- Public Sector: Responsible AI leads, policy engineers, assurance teams; foundation-model supply-chain risk.
What you’ll learn (and how it lands in prod)
- Foundations of Responsible AI: Bias/harms, transparency, LLM threat models, and ethical use in the AU context.
- GRC in AI: Risk → control mapping, identity-first security, privacy-by-design, audit artefacts.
- ISO/IEC 42001 & AIMS: Design an AIMS that snaps into ISO 27001/27701 and incident response.
- Implementation & Future Trends: Hands-on templates, vendor-risk checklists, and a capstone that turns policy into shipping code.
Outcome: Replace shadow AI with governed AI—faster releases, tighter controls, cleaner audits. Backed by IT Masters and CSU, this short course blends academic rigor with battle-tested security practice.
Ready to make AI safe and useful? Join the free course and bring responsible AI to production without slowing your teams.