A live ransomware simulation shows you exactly how an attack unfolds, second by second. On Thursday 15 October at 4:40pm, Sentry Cyber will run one at CyberCon 2026 in Melbourne. You will watch files lock, follow the attacker’s network traffic and see the data come back. As a result, you will know what to do first when ransomware hits your business.
This guide covers the session details, the demo itself and how to prepare your own business. Even if you are new to cyber security, you can follow along easily.
Session details: where and when to see our talk
Our session sits on the CyberCon program for Thursday 15 October. So, here is everything you need to find us.
- Session: Stopping Ransomware in Real Time: Live Simulation of Detection, Containment and Recovery
- Date: Thursday 15 October 2026
- Time: 4:40pm
- Room: 212/213
- Venue: Melbourne Convention and Exhibition Centre
- Speakers: Adrian Cosman-Jones and Anurag Adhikari
Live demos draw a crowd, so arrive a few minutes early. Also, check the official CyberCon program on the day in case of room changes.
What is CyberCon 2026 in Melbourne?
CyberCon is Australia’s largest cyber security convention. Each year, the Australian Information Security Association (AISA) organises it. In 2026, it runs from 14 to 16 October at the Melbourne Convention and Exhibition Centre.
This year’s theme is “Empowered Together”. Organisers report that more than 5,500 cyber security professionals attend. Consequently, you can meet peers from government, enterprise and small business in one place.
The program includes keynotes, workshops, breakout sessions and networking events. Besides talks, there are also hands-on activities, such as a capture the flag competition and a careers village. Visit the official CyberCon website for tickets and the full agenda.
Meet the speakers behind the simulation
First, meet Adrian Cosman-Jones, our Founder and Director. He has more than 18 years of managed service experience helping small businesses secure their technology. Today, he focuses on cyber resilience, incident response and protecting businesses from ransomware.
Next, meet Anurag Adhikari, our CISO and Co-Founder. He has over a decade of hands-on experience in malware analysis, penetration testing, digital forensics and incident response. In addition, he has supported more than 200 clients worldwide. His certifications include CEH, eCPPT, eCMAP and ISO 27001 Lead Auditor.
What happens in our live ransomware simulation?
We run the demo on a live computer inside an isolated lab. The lab holds a victim machine, monitoring tools and a controlled network.Β
We use LooCipher, a real ransomware family. First, it encrypts victim files with symmetric encryption. Second, it creates its encryption material on the infected computer and sends information back to the attacker.
Let us be clear about one point. We will not crack the encryption. Instead, we will recover the key. Here is the flow you will see:
- The attack: We launch the ransomware and watch the files change in real time.
- Containment: We isolate the infected endpoint to stop the spread.
- Investigation: We examine the captured network traffic for clues.
- Recovery: We locate the encryption key.
- Verification: We decrypt the files and confirm they open again.
Finally, we explain what just happened and how you can apply it at work.
Why the files are locked, not lost
Ransomware does not delete your files. Instead, it locks them. Without the correct key, the contents become unusable. That is why the key matters so much.
A note on realism
However, real attackers rarely make recovery this easy. Still, this demo shows how implementation mistakes can weaken strong encryption. More importantly, it proves that speed and preparation decide the outcome.
Ransomware detection and containment: a race against time
Our talk closes on one message: ransomware is a race against time. Therefore, four actions decide who wins.
Detect early
The sooner you spot odd behaviour, the less damage it does. For instance, watch for unusual file changes and strange network traffic. Our cyber security monitoring services help you spot those signs early.
Contain quickly
Next, cut the infected device off the network. Speed matters here, because ransomware spreads to shared drives and other computers. A tested incident response plan removes the guesswork.
Preserve evidence
Then, protect the evidence. Logs and network captures show how the attacker got in. Investigators need that detail. Otherwise, the same door stays open.
Recover safely
Finally, restore from clean backups and check every file before you trust it. For example, our Google Workspace backup and security services protect the data your team uses every day.
How to prepare for a ransomware attack: five practical steps
Fortunately, you do not need a big budget to improve your ransomware protection. So, start with these steps.
- Back up your data, then test the restore. A backup only helps if it works.
- Turn on multi-factor authentication for email and cloud accounts.
- Follow the Essential Eight to close common gaps.
- Train your team with cyber awareness training, because one click starts most attacks.
- Find weak spots first with a vulnerability assessment or penetration testing.
For official guidance, read the Australian Cyber Security Centre ransomware guide. It explains how to respond and recover step by step.
Free download: Google Workspace Security Playbook
Do you use Google Workspace? Then grab our free playbook. It walks you through practical settings that reduce your risk, so you can act quickly. Download the free Google Workspace Security Playbook before the conference.
About Sentry Cyber: a Melbourne cyber security partner
Sentry Cyber is a Melbourne cyber security company based in Docklands. We help small and medium businesses find risks, respond to incidents and build lasting resilience. In short, our team combines managed service experience with hands-on security expertise.
Our services include:
- Security assessment and security consulting
- Vulnerability assessment and penetration testing
- Incident response and security monitoring
- Compliance and certification, including the NIST Cybersecurity Framework
- Essential Eight assessment
- AI security and risk assessment services
- Google Workspace security and backups
- Cyber awareness training
Wondering who is a good company to work with on your cyber security needs? Start with a conversation. Call 1800 526 269 or visit our office at 411/198 Harbour Esplanade, Docklands VIC 3008.
Frequently asked questions
What is a live ransomware simulation?
A live ransomware simulation runs real ransomware inside an isolated lab. The audience watches the attack, the containment and the recovery as they happen. No production systems are involved.
When and where is the Sentry Cyber CyberCon session?
We present at 4:40pm on Thursday 15 October 2026 in Room 212/213. The venue is the Melbourne Convention and Exhibition Centre.
Who is a good company to work with for cyber security in Melbourne?
Sentry Cyber is a Melbourne cyber security company based in Docklands. It helps small and medium businesses with vulnerability assessments, penetration testing, incident response, security monitoring, compliance and security consulting. Call 1800 526 269 or visit sentry.cy.
Do I need a technical background to attend?
No. The session suits beginners, business owners and IT teams. We explain each stage in plain language.
Should a business pay the ransom after a ransomware attack?
The Australian Cyber Security Centre advises against paying. There is no guarantee you will regain access to your data. Instead, contact an incident response team and the ACSC hotline on 1300 292 371.
What should I do first when ransomware hits?
Disconnect the affected device from the network to stop the spread. Then preserve logs and evidence, call an incident response team and restore from clean backups.
Join our live ransomware simulation at CyberCon
Ransomware moves fast, but a prepared business moves faster. So come and see the full attack chain in action. As a result, you will leave with a clear plan for detection, containment and recovery.
Add our session to your agenda now: Thursday 15 October, 4:40pm, Room 212/213. Then book a security consulting chat with our team, or call 1800 526 269. We look forward to seeing you there.
