SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
AI speeds up cyber attacks on ageing systems, experts warn

AI speeds up cyber attacks on ageing systems, experts warn

Thu, 17th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

The Australian Signals Directorate Chief has warned that artificial intelligence is reshaping the cyber threat landscape. Senior security executives say the biggest risk is how quickly attacks can now hit ageing and exposed systems.

The warning, delivered at the Australian Strategic Policy Institute's Sydney Dialogueue AI Masterclass, prompted rapid responses from security leaders who say many organisations still rely on legacy technology and fragmented defences. In their view, AI-driven attacks are compressing response times and magnifying long-standing weaknesses in basic cyber hygiene.

Fortinet executives say AI intensifies existing risk rather than creating an entirely new category of threat. They point to familiar weaknesses such as unpatched systems, weak access controls and unsecured network segments as the main entry points AI-assisted attackers can exploit at machine speed.

"AI is compressing the time organisations have to deal with existing cyber risk. AI-assisted attackers can exploit known vulnerabilities, weak access controls, insecure configurations and exposed legacy systems at far greater speed and scale. Organisations with a strong, proactive security posture should remain best placed to manage these threats, provided they can apply established security fundamentals quickly and consistently.

"There is no single technology that solves this challenge. The response remains defence in depth: maintaining visibility of assets and exposures, patching where possible, rigorously managing identities and access, segmenting networks, monitoring continuously, and putting compensating controls around systems that cannot be immediately remediated. This is particularly important for critical infrastructure, where taking ageing or unsupported technology offline may not be operationally viable," said Glenn Maiden, Chief Security Officer and Director of Threat Intelligence, Australia and New Zealand, Fortinet.

"What changes in an AI-enabled threat environment is the speed at which these controls need to work together. Integrated security platforms can help organisations coordinate protection across the environment rather than relying on disconnected tools and manual processes. Orchestration, automation and AI-driven defensive capabilities can augment established controls by helping security teams identify risk, investigate activity and contain threats at a machine speed that would be impossible to achieve manually. The priority is not replacing proven cybersecurity fundamentals for the AI era. It is executing them faster, more consistently and with greater coordination," Maiden said.

Kinetic IT consultants echoed the focus on speed and complexity, particularly for agencies and providers running critical services across mixed estates of modern and legacy technology. They said the ASD chief's remarks align with what they are seeing across government and essential infrastructure.

"The ASD's warning reflects what we're seeing across government and critical infrastructure: AI is accelerating the speed, scale and sophistication of cyber threats, while Australia's ageing technology estate remains an important part of that risk equation.

"For organisations responsible for critical services, the priority is understanding their risk profile, which does not necessarily mean replacing every legacy system. It means identifying which systems and dependencies would carry the greatest consequence if compromised or disrupted, strengthening controls around them, and sequencing modernisation so security and resilience improve while essential services remain available.

"This becomes even more important as organisations introduce agentic AI. AI is increasingly becoming part of an organisation's operational fabric, creating new dependencies across data, workflows, identity, platforms and controls. The ASD's new guidance on agentic AI harnesses is important because it sets practical guardrails around those dependencies, from least-privilege access and secure design to auditability, human oversight and clear accountability. Those harnesses should be engineered from the ground up to ensure humans are not just in the loop; human oversight should remain in control so accountability is never delegated.

"The organisations that will make the greatest progress are those that can modernise and adopt AI while maintaining operational control and continuity as these dependencies evolve. For government and critical infrastructure, the ability to keep essential services running and trusted is ultimately what matters most," said Kishore Jayaram, Chief Transformation Officer, Kinetic IT.

Aon risk advisers framed the issue as a structural exposure on corporate balance sheets. They said boards need a clearer view of how ageing systems contribute to cyber and business resilience risk in an AI-driven threat environment.

"The ASD's warning highlights a growing challenge for organisations that rely on ageing technology to support operations. As AI increases the speed and scale of cyber threats, older and end-of-life systems can become a source of cyber debt that is difficult to manage and increasingly costly to ignore.

"Ageing technology should be viewed as a business resilience exposure, not simply an IT maintenance issue. Boards need visibility of these exposures and a clear plan to manage and reduce them over time.

"The choice is often between investing in modernisation today or accepting greater cyber risk in the future," said Quinton Kotze, Head of Cyber Solutions, Australia, Aon.