SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
AI shifts Cybersecurity Awareness Month focus to visibility

AI shifts Cybersecurity Awareness Month focus to visibility

Tue, 6th Oct 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Cybersecurity suppliers and advisers are using Cybersecurity Awareness Month to warn that artificial intelligence is reshaping security risks for companies and public bodies. Their comments suggest a shift in focus from employee behaviour to visibility across infrastructure, identities and automated systems.

Several executives said awareness campaigns have traditionally centred on phishing, passwords and software updates. Organisations now face a broader challenge as AI tools, models and agents gain access to data, applications and workflows.

"Cybersecurity Awareness Month has traditionally focused on making people more aware of threats. But as AI becomes embedded across public cloud, private infrastructure and SaaS, organizations also need to ask whether their security systems are aware of what is actually happening across their business. Enterprise AI is rapidly evolving toward Hybrid AI, with different models and agents communicating with applications, data and each other across increasingly complex infrastructure. Yet 76% of CISOs say limited visibility into AI-driven traffic is already a major barrier to securing AI adoption. That makes AI security more than a user-awareness challenge. Organisations need trusted context about data in motion to understand how AI systems are interacting with the business and where those interactions create risk. As AI compresses the time between action and consequence, cyber awareness has to extend from the employee to the infrastructure carrying AI," said Shane Buckley, Chief Executive Officer, Gigamon.

Buckley's comments reflect a wider concern that AI adoption is moving faster than governance and monitoring. Security specialists say businesses often approve some uses of AI while remaining unaware of other tools introduced by employees, developers or business units.

"This year's Cybersecurity Awareness Month theme, 'Don't Make It Easy for Them', needs to start with closing the gap between what organizations think is happening and what is actually happening across their infrastructure. AI is making that harder. Employees are adopting their own tools, developers are embedding models into applications, and agents are creating new interactions with data and systems that security teams may never see. It's no surprise that 80% of CISOs (https://www.gigamon.com/campaigns/hybrid-cloud-security-survey.html) cite inadequate governance around unsanctioned AI as a top security challenge. Policies alone cannot govern activity that organizations cannot see. As AI adoption accelerates, security teams need continuous visibility into how sanctioned and unsanctioned AI interacts with applications, infrastructure and sensitive data. That context allows teams to validate whether controls are working and identify activity that falls outside policy. Cybersecurity fundamentals still matter, but AI is compressing the time attackers need to exploit weaknesses. The harder organizations make it for attackers to find and exploit gaps in policy and controls, the less advantage their speed provides," said Grant Yacomeni, Chief Information Security Officer, Gigamon.

Identity risks

Identity providers are also framing AI as a trust issue in consumer markets. They argue that shoppers may accept AI in low-risk interactions but draw the line when tools act on their behalf in financial or purchasing decisions.

"Securing the next 250 years means thinking about how trust needs to evolve as technology becomes a bigger part of consumers' lives. AI is helping people make decisions and take actions online, but consumer trust isn't all or nothing. Consumers might be comfortable having an AI agent recommend a product, for example, but hesitate to let it make a purchase or access sensitive financial information on their behalf. For retailers, identity is as much a business issue as it is a security one. AI creates more convenient digital experiences while also giving fraudsters new ways to impersonate legitimate consumers and make scams more convincing. Businesses need to embrace technologies like biometric authentication and verifiable credentials that allow consumers to securely prove who they are while helping retailers establish trust at every interaction. Putting identity at the centre of digital commerce can help reduce fraud without sacrificing the seamless experiences consumers expect. Cybersecurity Awareness Month is a reminder that building trust isn't just an October priority. It's fundamental to creating a safer digital economy for the years and generations ahead," said Darryl Jones, Vice President of Consumer Segment Strategy, Ping Identity.

Shadow AI

Other industry voices said AI changes the risk profile after authentication, not just before it. The issue becomes more acute when agents keep acting with access rights originally granted by an employee.

"Cybersecurity Awareness Month has traditionally focused attention on passwords, phishing, software updates and access to company systems. Those are now considered the basics, and they are still important, but AI changes what can happen after somebody has authenticated. An employee can give an AI assistant access to email, files, source code or a business application, and an agent can continue using that access without the employee being present for every action. That makes shadow AI a security problem that goes well beyond whether somebody has installed an unapproved tool. Organisations need comprehensive visibility into the AI activity taking place across their environment, and controls based on what they can actually see. Security teams need to know which credentials an AI system is using, which systems it can reach, what data it is accessing and what actions it is taking. An inventory of approved AI applications will only tell you part of that story. Cybersecurity Awareness Month should also prompt organizations to look at what AI is actually doing inside their environment, including activity they may never have formally approved in the first place," said Lawrence Spracklen, Co-Founder and Chief Science Officer, Classie.

Some executives also linked the debate to the need for AI literacy in technical teams. They said companies should understand what data and permissions an AI system receives before inserting it into core security or IT processes.

"Most people understand how AI works about as well as they understand how their refrigerator works (very little), and until recently, that was probably fine. But when you start deploying AI inside an enterprise and giving it access to sensitive data, security tools and operational workflows, that lack of understanding becomes a risk. For years, cybersecurity awareness has focused on people: what they click, how they handle credentials and how they interact with systems. As AI agents become active participants in security and IT operations, AI literacy must become part of the definition. That means deploying AI intentionally, with appropriate context, defined permissions, clear guardrails and visibility into what it's actually doing. Environment-aware AI can be far more useful than a generic model because it understands the systems and data it's working with, but that context must come with transparency and control. Security teams should be able to see what an agent can access, understand the tools and permissions it has, and follow the steps it takes. The future of AI in cybersecurity should give defenders greater context and visibility while keeping humans firmly in control of the boundaries," said Mike Wade, Vice President of Customer Success, Gravwell.

Public-sector security teams face a related but longer-term challenge in post-quantum cryptography, according to Gigamon engineering executive Shawn Dappen. He said, "Cybersecurity Awareness Month tends to focus attention on the risks organizations face today, but public-sector leaders also need to prepare for threats whose consequences may emerge years from now. The quantum threat goes beyond 'harvest now, decrypt later.' Agencies also need to prepare for 'trust now, forge later,' where future quantum capabilities could undermine the digital signatures that establish trust in identities, software and transactions. That makes PQC migration as much a discovery and validation challenge as a cryptography challenge. With 86% of CISOs saying visibility into encrypted traffic is critical for PQC readiness, agencies cannot migrate cryptography they cannot discover, manage dependencies they cannot see, or prove migration success without independent validation. The priority now is to assess PQC posture, identify cryptography in use, surface systems requiring review, establish migration priorities and continuously validate progress as PQC and hybrid protocols are introduced."