SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Australian firms urged to act on cyber resilience now

Australian firms urged to act on cyber resilience now

Thu, 1st Oct 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Australian security leaders are urging organisations to use Cyber Security Awareness Month as a trigger for concrete resilience measures, not just another awareness exercise.

Vendors and practitioners warn that the rising use of artificial intelligence in attacks, combined with the growing impact of data breaches, leaves little room for complacency.

Andrew Kay, Senior Director, Systems Engineering, APJ, Illumio, said the threat environment has shifted markedly in a short time, with so-called frontier AI giving attackers new speed and reach across victim networks.

Many defenders still rely on detection-centric strategies that assume they can respond fast enough once an intrusion begins, he said. In his view, that mindset no longer matches the reality of machine-driven attacks that probe weaknesses and pivot between systems in seconds.

Illumio research points to a wide gap between detection and containment. The company found that 95% of organisations say they can detect unauthorised movement in their IT environments, yet almost half struggle to stop it from spreading.

Practitioners increasingly describe this divergence as a "lateral movement window", when attackers escalate privileges, compromise additional systems, and move closer to sensitive data and operational technology.

"The threat landscape we are defending against today bears little resemblance to 12 months ago. Then, organisations could still afford to think of cyber defence as a race between attackers and defenders. Now, with frontier AI, the contest is essentially won. Attackers can move faster, adapt faster, and scale attacks faster, leaving defenders, well, defenceless. Combine this frightening reality with the fact that even if an attack is detected, it does not mean it is contained quickly. Illumio research found that while 95% of organisations say they can detect unauthorised movement in their IT environments, almost half struggle to stop it spreading. That is a dangerous gap. It exposes a critical window where attackers can move laterally, escalate privileges, and turn an initial foothold into a disaster: crippled operations, costly downtime, and reputational damage. The Australian government is right to shift the focus to action over awareness this year, and to urge the adoption of an assumed-breach mindset. Breach containment is the most critical part of this and should be a core security strategy. Organisations need to know how attackers could move through their environments when an incident inevitably occurs, eliminate unnecessary pathways, and be able to rapidly isolate compromised systems," said Andrew Kay, Senior Director, Systems Engineering, APJ, Illumio.

Preparedness for recovery is also under scrutiny. New figures from Cohesity indicate that almost all large organisations in Australia claim to have a cyber resilience strategy, yet most uncover gaps when an incident unfolds.

Cohesity's Global Cyber Resilience Report found that four in five Australian organisations suffered a material cyberattack in the past year, a higher rate than the global sample. Among those attacked, 92% expected their recovery plan would require workarounds or improvisation. Most also took longer to recover than expected and found more affected systems than first assessed.

James Eageleton, Managing Director, ANZ, Cohesity, said many plans still assume a linear incident sequence and a well-understood environment. In practice, organisations often discover during a crisis that system dependencies are unclear, clean infrastructure is not readily available, or decision-making authority is ambiguous.

The rapid rollout of AI agents, copilots, and automated workflows adds further complexity, he said. Nearly half of Australian respondents in the research lacked a centralised inventory or clear view of their AI usage, and only 2% believed their current recovery approaches could withstand frontier AI-enabled threats.

He said a more realistic approach draws on the "Minimum Viable Company" concept. Organisations identify the minimum people, processes, technology, and data needed to keep core services operating through a major disruption, then test recovery around that set.

Data protection specialists are pushing a similar message about the resilience of backups and archives. Josh Langley, Chief Information Officer, Iron Mountain, said recent incidents in the health sector showed how quickly attackers can turn an initial breach into large-scale data loss and operational disruption.

"'Don't make it easy for them' means thinking beyond the moment an attacker gets through the front door. The recent Medicare attack is just another high-profile example of why damage limitation is paramount in 2026. An assume-breach mindset asks a harder question: if a cybercriminal makes it into your environment, how much data can they steal, encrypt, or destroy? Data resilience has a critical role to play here. Backups and recovery systems cannot be treated as an afterthought. If they remain connected to the same environment as production data, they can become another target for ransomware and data destruction. Critical data needs layers of protection, including isolation and immutable copies that attackers cannot alter or encrypt. Just as importantly, organisations need to regularly test whether those copies can actually be used to recover. Keeping attackers out will always matter. But true cyber resilience means planning for what happens when they get in, and making sure your most important data is still there when you need it."