SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
System administrators face growing security burden

System administrators face growing security burden

Fri, 31st Jul 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Cybersecurity firms have highlighted the growing security burden on system administrators as organisations expand their use of cloud, AI and hybrid work models. The comments coincide with industry recognition of SysAdmin Day across the global technology sector.

Vendors and security leaders say the role has shifted from infrastructure maintenance to frontline risk management. System administrators now sit at the intersection of identity, access and network control across widely distributed environments.

Santanu Dutt, Vice President and Head of Technology, AsiaPacific-Japan, at Zscaler, said the combination of cloud services, AI adoption and hybrid work has reshaped expectations of IT teams.

"As organisations continue to embrace cloud services, AI and hybrid work, the role of the system administrator has expanded far beyond maintaining IT infrastructure. Today's IT teams are responsible for managing increasingly complex environments while ensuring employees can securely access the applications and data they need for their jobs.

Dutt said security now sits at the centre of that expanded remit as threat actors increasingly target users, identities and encrypted traffic.

Australia remains a key target. Research cited by Dutt places the country among the 10 most targeted globally for phishing activity, with most attempts now concealed in encrypted channels.

"With this growing responsibility, security has become an increasingly important part of their role. Australia remains among the top 10 most targeted countries globally for phishing activity, while Zscaler research found that 95.2% of phishing attempts are now hidden within encrypted traffic, making threats harder to detect through traditional approaches.

Dutt said supporting system administrators with greater visibility, automation and security controls will be essential as organisations continue to evolve.

"System administrators made the shift a few years ago from maintaining infrastructure manually to automation via cloud and infrastructure as code. Today that shifts even further in the cybersecurity space, where system administrators are not looking for additional security products or more capabilities. Rather, they are seeking a significant reduction in attack surface and footprint, leading to reduced complexity and a stronger security posture. This means IT teams can focus less on manual processes and more on enabling business resilience and innovation," he said.

Dmitry Volkov, Chief Executive Officer of Group-IB, said system administrators now occupy a dual role as both defenders and attractive targets for attackers.

"System administrators are often the people keeping the business running, while also managing the access points attackers look for. That makes them high-value targets for cybercriminals in their own right," Volkov said.

He described administrators as the first to spot subtle warning signs that only become significant when combined across systems and services.

"They are in a unique position: they're usually the first to notice the small signals that, on their own, look routine, such as a leaked credential, an exposed service, or an unpatched vulnerability. Individually, each is manageable. Together, they can be early evidence of an attack taking shape," Volkov said.

Volkov linked that perspective to Group-IB's emphasis on adversary-focused intelligence that combines technical indicators with information about threat actors.

"We study who is behind an attack, their infrastructure, their patterns, their intent. Because that context is what turns a random signal into a warning worth acting on. It's the same instinct a good system administrator already has, just applied at scale," Volkov said.

He said many teams lack the time to manually connect disparate alerts across identity, network and application layers.

"Administrators on the front line don't have time to manually piece together a leaked credential, an exposed service, and an odd login pattern. The goal is automation that does that correlation for them, so the signals surface as one clear picture instead of three separate alerts to chase down," Volkov said.

Volkov framed AI as a tool that augments professionals rather than displaces them.

"Its value is in connecting those signals faster and cutting down repetitive analysis, so experienced people can focus on the decisions that keep services available and stop incidents from escalating. The technology should make the administrator's instinct faster to act on, not substitute for it," Volkov said.

Darren Guccione, Chief Executive Officer and Co-Founder of Keeper Security, said the traditional view of system administrators as backroom operators understates their influence on breach outcomes.

"System administrators don't just keep the lights on; they enforce the access policies that determine whether a breach becomes a headline. That distinction matters more today than it ever has.

The work is foundational and often invisible: managing access, enforcing policy, patching systems before a vulnerability becomes an incident. What has changed, faster than most organisations have adjusted to, is the scale of what they are now responsible for governing. AI agents, cloud workloads and non-human identities have multiplied the attack surface these teams must secure.

The question of who has access to what has always been critical. It is now exponentially harder to answer, with higher stakes when the answer is wrong. Credentials are proliferating faster than most organisations can track.

System administrators are the operational layer through which zero-trust principles either get executed or ignored. Privileged access management, least-privilege controls and credential hygiene are not optional layers added on top of a security program. They are the foundation. When that foundation is weak, every other layer of the security stack is compensating for a problem it was not designed to solve.

Security leadership owes these professionals two things: the tools to do the job properly, and the organisational support to act on what those tools surface. The risk of not providing both shows up in incident reports, and organisations learn that the hard way.

Recognising that work today is the easy part. The harder, more important part is making sure the professionals doing it have what they need to succeed and the organisational standing to act on what they find. Security does not hold at the perimeter anymore. It happens at the access layer, where these professionals work every day," Guccione said.