SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Collective cyber defence will be won or lost in how we act together

Collective cyber defence will be won or lost in how we act together

Wed, 2nd Sep 2026 (Today)
Nicole Henry
NICOLE HENRY Head of Government Affair - Australia and New Zealand Fortinet

OpenAI has issued a global call for collective action on cyber defence (1), and Fortinet is proud to be a signatory. The Australian Prudential Regulation Authority (APRA) and the Australian Securities & Investments Commission (ASIC) has also urged Australia's financial sector to move from awareness to decisive action (2), reinforcing guidance from the Australian Signals Directorate (ASD) and the Australian Institute of Company Directors (AICD). (3)

Taken together, they send a clear message: frontier AI is increasing risk and exposure now, and defenders have a limited window before advanced offensive capability becomes more widely available. The significance is not simply faster threats, it is less time for organisations to recognise what has changed, decide what matters and act. This means reducing exposure now.

Organisations already face cyber risks amplified by frontier AI, whether or not they use the technology themselves. Attackers use it to find, combine and exploit weaknesses faster. Meanwhile, organisations are putting AI to work across their operations, expanding its access to data and systems and, increasingly, its authority to act. One force increases pressure on the digital environment; the other changes the environment being defended.

Frontier AI is more than another entry on the risk register. It changes the assumptions behind accepted risk: weaknesses once considered difficult to exploit may no longer be. The same challenge surfaces in discussions with industry, government and tertiary leaders. Organisations have less time to reduce exposure and respond when a weakness is exploited.

Frontier AI raises the cost of getting the fundamentals wrong. ASD is evolving the Essential Eight into a broader Essential Series so baseline cyber practices keep pace with changing technology and threats. (4) Defensive AI can help organisations identify and remediate exposure faster; however, it cannot replace a clear understanding of which services must keep running, what they depend on and where exposure lies.

In today's threat environment, the cyber front line runs from the family-run deli to the largest critical infrastructure operator. Any digitally connected organisation must be able to contain compromise and keep delivering its products or services. Its exposure extends through providers, suppliers and infrastructure beyond its control, letting a weakness in one place become disruption elsewhere.

This connected exposure is why the OpenAI letter calls for collective defence. No organisation controls all the dependencies shaping its risk or holds all the intelligence and capability needed to respond. Collective defence must work at two levels: within organisations and across the economy.

Across the economy, capability and authority remain distributed. Businesses understand the operational consequences, technology providers see threats across many environments, and government holds the intelligence and authority that industry lacks. Collaboration brings those perspectives together before pressure arrives; coordination turns them into timely action.

COVID showed that government and industry can build effective relationships under pressure. It also showed why we should not wait for a crisis. Collective defence requires trusted relationships and clear authority before an incident, including who can interrupt a critical service to contain a threat.

Within organisations, AI now sits where business, cyber security, data and privacy meet. A decision in one function can change what others must manage and defend. Organisations cannot embrace AI as a business transformation while treating its exploitation as a cyber team problem. Accountability must sit with the people who have authority to change and manage the resulting risk.

Frontier AI is accelerating threats, yet organisational decision-making is not keeping pace. It leaves less time for process and deliberation before action is required. Tools and automation should handle routine, repeatable work at speed, preserving time for decisions where context and consequence matter. Governance must bring the right information, operational context and authority together quickly. The pathways for consequential decisions across organisational boundaries should be established and tested before an incident.

Assurance is changing. Government is looking beyond whether an organisation has met its obligations to whether it can show its resilience will hold under pressure. Proposed Security of Critical Infrastructure Act 2018 (SOCI) reforms reflect this shift through more independent assurance and closer scrutiny of major suppliers and critical components. (5) This is not simply another layer of compliance. Resilience depends on how systems, controls and suppliers perform when they are needed most.

Frontier AI makes that shift more urgent. ASD and the AICD ask boards to verify that mitigations are effective (6); APRA and ASIC emphasise implementation, practical testing and measurable resilience (7); and OpenAI calls for continuous testing and verified fixes. (8) This means demonstrating operational resilience, with evidence that controls work as intended and recovery arrangements hold under pressure. As frontier AI changes the speed and scale of attack, evidence from the last review is no longer enough.

The warnings are converging, and awareness is no longer enough. Government and industry need to reduce known exposure, settle who can decide and act when time is short, and test whether the services people rely on will hold under pressure. The defenders' window is limited, yet still open. The time to act is now.