It People News / Enterprise Staff
October – Cyber Security Awareness Month
October is Cyber Security Awareness Month, an opportunity for all Australians to strengthen their cyber security knowledge and take practical steps to protect their devices, accounts, and personal information.
John Cannava, CIO, Ping Identity
Cybersecurity Awareness Month is an important reminder to make security a priority, but it shouldn’t begin and end in October. As technology evolves, so does the definition of who, or what, organizations need to secure. AI agents are increasingly accessing applications, data, and critical business systems while taking actions at machine speed, creating a new layer of risk that businesses need to manage every day.
The same security principles we’ve long applied to human access now need to extend to AI. At the end of the day, the nonhuman identity problem is still a human problem. Organizations need to know who authorized an agent, what authority it has, and what it should be allowed to do. That means giving AI agents verifiable identities, clear ownership, and least-privilege access, with continuous authorization and accountability for their actions. Businesses should extend proven identity principles to machines acting on behalf of people and build those principles into controls that can actually be enforced.
Looking ahead to secure the next 250 years, security cannot be in the spotlight for only one month. Leaders must build a culture of security and maintain visibility and control over every kind of identity year-round.”
David Rajkovic, Regional Vice President A/NZ, Rubrik
“The recent Medicare breach highlights the new risks organisations need to contend with. AI agents will continue to go rogue. Open AI’s incident, along with the Hugging Face breach earlier this year, demonstrate that frontier models can sustain complex cyber operations, discover novel attack paths, and move across real-world systems in pursuit of a narrow objective.
During Cyber Security Awareness month, I would urge organisations to review their resilience posture and ability to protect against agentic threats. The truth is, Australia is not prepared to deal with the risk agents pose. Our readiness posture is lagging. Far too many organisations are relying on prevention strategies and legacy data protection systems that are inadequate for the speed of AI attacks.”
Dayle Wilson, Head of Cyber Security at Macquarie Cloud Services:
“Risk cannot be outsourced. Cybersecurity awareness means little unless organisations accept they remain accountable for the security they still control. Too many Australian organisations assume a managed cloud solution transfers the risk to the MSP. It does not. Even when the provider handles defined cyber-defence actions, accountability stays with the customer. A shared responsibility model must be tightly defined, measured, capture evidence and shown ongoing with near real-time executive and operational dashboards. These should align with who owns which controls, and what residual risk remains.
A trusted MSP can feel like complete outsourcing. That is an assumption, not a certainty. Recent breaches at household names show how quickly an incident costs trust, regulatory scrutiny and questions of leadership.
In 2024-25, 39 per cent of the 138 ransomware incidents handled by the ACSC came to light because the government contacted the victim first. With SOCI reforms and Privacy Act changes raising expectations of providers, customers, and their boards, every leadership team should use this Cybersecurity Awareness Month to ask: if something were happening in our environment right now, would we know? If the answer isn’t a confident yes, the risk hasn’t gone away, it’s just gone unseen.”
Jason Garland, Director, Secure Access IT and GTIA ANZ Executive Council Member
“Cybersecurity Awareness Month is a good time to look at who carries the most risk. In Australia, small businesses reported an average loss of $56,000 per cybercrime in 2024-25, up 14 per cent on the previous year. In New Zealand, 53 per cent of SMEs faced a cyber threat or attack in the past six months, rising to 76 per cent among businesses with 20 to 49 staff.
“This year’s theme: ‘take a second, stay secure’ sounds simple, but small businesses don’t have the time, budget, or expertise to address staying secure on their own. As such, they rely on their IT service provider (ITSP) to spot the risks they miss, which puts ITSPs squarely on the front line.
“Many ITSPs serving small and mid-sized businesses (SMBs) are small businesses themselves. They face the same skills shortages and cost pressures as their customers, while managing security for dozens of clients at once. Vendors, distributors, and industry bodies need to make it easier for these providers to access training, share threat intel, and build services that fit SMB budgets.
“Better support for ITSPs and better protection for SMBs depends on the entire IT ecosystem working together. When knowledge is shared and peers are connected, threats are identified sooner, gaps are closed faster, and good practice spreads further. No business – big or small – should face these risks alone, so I would encourage every organisation to use this month to review their own security, talk to their clients, customers, partners, and peers, and make sure no business is left without support.”
Daryush Ashjari, CTO and Vice President Solution Engineering APJ, Nutanix
“As we recognise Cybersecurity Awareness Month, organisations should acknowledge that cybersecurity blind spots are no longer limited to external threats. As businesses accelerate their adoption of hybrid multicloud architectures, AI platforms, edge computing, and distributed applications, maintaining visibility across what needs to be secured is becoming increasingly challenging.
The challenge today is not simply keeping bad actors out. It is understanding where critical data resides, how it moves across cloud and on-premises environments, and who or what has access to it. Every new cloud service, AI deployment, or edge workload expands the attack surface and creates new opportunities for security gaps to emerge. Without a comprehensive view of the environment, risk becomes harder to identify, manage, and mitigate.
Visibility is the foundation of cyber resilience in the hybrid multicloud era. Organisations cannot effectively protect, govern, or recover assets they cannot see. Security leaders need a unified view across infrastructure, applications, identities, and data, regardless of where they reside. This visibility enables faster threat detection, stronger governance, and more effective response when incidents occur.
To strengthen resilience, organisations should focus on a few key priorities. First, simplify security operations by establishing consistent policies and controls across environments. Second, adopt a data-centric approach to security by understanding where sensitive information lives and ensuring it is protected throughout its lifecycle. Third, implement Zero Trust principles that continuously verify users, devices, and workloads rather than assuming trust based on network location. Finally, ensure cyber recovery capabilities are regularly tested so critical services and data can be restored quickly in the event of disruption.
The organisations that will be best positioned to navigate the evolving threat landscape are those that can reduce complexity, maintain end-to-end visibility, and build resilience into every layer of their hybrid multicloud strategy. In an environment where threats continue to evolve and technology estates continue to expand, visibility is no longer just a security requirement. It is a business imperative.”
Yadi Narayana, Field CTO APJ, Datadog
“Every October, Cybersecurity Awareness Month prompts familiar conversations about passwords and training. It’s good advice, but it misses the reality of modern resilience.
The threat has fundamentally changed. The ASD’s latest Annual Cyber Threat Report notes Australia now records a cybercrime report every six minutes, and AI has compressed attacks that once took days into seconds. These modern attacks cross applications, infrastructure, and APIs instantly. A performance blip, a strange login, and a traffic spike are no longer separate incidents – they are the same attack moving through a system.
Yet, many organisations fight this with disconnected tools and an endless volume of alerts. But the alert is not the attack. Security teams are drowning in clues when they need the story. By the time they manually stitch together an attack’s path, the damage is done. In fact, our State of DevSecOps 2026 report found that when runtime context is applied, only 18 per cent of ‘critical’ vulnerabilities actually remain critical. Teams are simply wading through noise.
You cannot stop a system-wide attack without seeing the whole system. The traditional disconnect – where security detects and engineering fixes using completely separate data – is an exploitable gap. Traditional tools watch isolated moments; today, we need to watch how entire systems behave in production.
Cybersecurity is no longer just a security problem, it’s an operational one. Security and engineering must look at the exact same real-time picture of how their systems behave. AI can help defenders connect security signals with operational context to investigate faster, but findings must be evidence-backed and actions on critical services appropriately approved. When attacks move at machine speed, runtime context, not alert volume, is the decisive advantage.”
Anthony Daniel, Managing Director, Australia, New Zealand and the Pacific Islands, WatchGuard Technologies
“This Cyber Security Awareness Month, the theme “Take a second. Stay secure.” is a timely reminder that a brief pause can interrupt an attack, but with threats evolving at unprecedented speeds, awareness alone is no longer enough.
For years, cyber security advice focused on familiar warning signs such as poorly written emails or suspicious links. Today, generative AI is helping attackers craft convincing messages, while stolen credentials can allow unauthorised entry through seemingly legitimate logins. At the same time, malware is becoming increasingly tailored to individual victims.
WatchGuard’s latest Internet Security Report found that 95.72% of Q2 endpoint threats appeared on just one machine, while novel endpoint malware rose 2,065% year-on-year. APAC also accounted for 50.33% of network malware detections per Firebox in the first half of 2026, roughly double the share recorded in either EMEA or the Americas.
For organisations across ANZ and the Pacific Islands the message is clear: security teams need to look beyond whether an email, link or login appears legitimate and focus on whether activity is behaving abnormally. Evolving attack methods must be treated as a local business priority.
Security must make the safe choice the easiest choice. Combine regular employee education with practical safeguards such as multi-factor authentication, strong identity controls, encrypted traffic inspection, layered network and endpoint protection, and continuous monitoring.
Cyber Security Awareness Month is a good opportunity to test where the gaps are. Use it to test one assumption your business has been making, whether that’s assuming MFA is enforced everywhere it should be, or that unusual account activity would be caught quickly, and fix what the test reveals.”
Daniel Churches, Director Cybersecurity, Asia Pacific and Japan, DXC Technology
“Across the region, organisations are moving fast to become AI-native, deploying tools and agents to drive efficiency and competitive advantage. But as AI transforms how your business operates, security must evolve too.
Our recent research shows that only 47% of organisations have fully integrated governance for agentic AI, despite many rapidly deploying autonomous AI capabilities across the business. AI systems are now touching identities, data and decision-making at a scale and speed that traditional, human-paced security simply wasn’t built for. If governance and identity aren’t embedded from the outset of an AI transformation, organisations are effectively scaling risk as fast as they’re scaling capability.
This Cybersecurity Awareness Month, take a second to assess whether your security strategy is keeping pace with how your business is adopting AI. Organisations need to move beyond reactive defence towards intelligent, proactive and increasingly autonomous security, with governance, identity and trust embedded into AI initiatives from the start. This will enable organisations to scale AI adoption without compromising resilience or control.”
Pat Breen, Head of ANZ, Cloudflare
“The conversation many customers are having right now is around mitigating the scaling cyber threat with the increased capabilities of AI models such as Astra and Fable being available. It’s a fair question, and the uplift in capability is real.
The fear of attackers finding flaws that nobody knew existed is not what is getting most Australian organisations breached right now.
We block an average 1.7 billion cyber threats per day targeting Australia, and that’s increased 16.7% in three months. The majority of those threats are automated attacks pointed at weaknesses we’ve known for years – reused passwords, unpatched systems, access that nobody has reviewed since the person left.
It’s important to understand: AI hasn’t changed the attack. It’s made it cheap enough to run the same attacks against everyone.
The assumption worth retiring is that you need a sophisticated defence for a sophisticated threat. Most attackers aren’t spending a breakthrough capability on you. They’re trying the front door with a password someone reused, and 63% of the logins we see use credentials that are known to have been compromised. It works often enough to be worth it.”
That’s why this year’s theme, ‘Don’t Make It Easy for Them’, is the right one. If I were advising a customer, I’d tell them the foundations still decide the outcome: know what you’re running, know where your data sits, know who has access to what. Strong, unique passwords. Multi-factor authentication wherever it’s available. Compromised credentials rotated quickly. Systems patched.
None of that is new advice. That’s the point.
Better tools just mean everyone gets tried. An attacker is working out whether you’re worth the effort, and the basics are what change the answer.
Cynthia Lee, Vice President APAC at Delinea
This year’s Cybersecurity Awareness Month theme, ‘Don’t Make It Easy for Them’, is a reminder that attackers don’t always need to outsmart security controls. More often, they’re looking for gaps in oversight, particularly when it comes to access to sensitive systems and data.
As organisations adopt AI, automation and other productivity tools, they’re creating more ways to access information across the business. The challenge is to ensure security controls are in place to maintain accountability for access over time, and ensuring it remains appropriate as roles, technologies and business needs evolve.
Delinea’s latest Identity Security Report highlights why this matters. Only 42% of Australian IT leaders can always trace a sensitive AI access event back to a named human authoriser, while just 56% automatically revoke or expire access when a session ends. When organisations can’t confidently answer who approved access, who is using it, or whether it’s still needed, risk begins to accumulate.
Making it harder for attackers starts with closing those gaps. Organisations need a clear understanding of who, or what, can access critical resources, alongside the ability to continuously review, govern and remove access when it’s no longer required. The organisations best positioned to reduce risk will be those that treat access as something that must be actively managed, not simply granted and forgotten.”
Jason Pearce, Field CTO, APJ at Claroty
Cyber Awareness Month: Awareness is Not the Same as Resilience
In 2026, Australia’s ASD has itself been pushing the conversation beyond awareness, calling for organisations to adopt an assumed-breach mindset and turn cyber awareness into practical, measurable action. For critical infrastructure, that includes being prepared for circumstances where systems and networks may need to operate differently – or even be isolated – for extended periods.
We rely on OT and cyber-physical systems constantly in everyday life, often without seeing them; from the electricity, water and transport we depend on to the hospitals, food supply chains, data centres and manufacturing systems behind essential services. That means the impact of disruption rarely stops at the affected organisation; it can cascade across customers, suppliers, communities and the broader ecosystem.
Cyber security remains important. But in environments where digital systems control physical processes, the outcome that ultimately matters is not simply whether an attack was detected or prevented. It is whether the organisation can continue to operate. That may be the most important cyber-awareness conversation organisations have this October.
Sarah Cecchetti, Director of Product Management at Semperis
What should we do about AI? Speed it up. Lock it down
There is a serious debate about whether we should slow down AI development. Builders understand the trade-off: progress creates risk, but refusing to make progress does not remove it; it often gives the advantage to someone else.
AI can help Australian organisations build security and identity infrastructure that is more capable and resilient. It can analyse identity telemetry, surface suspicious privilege changes, generate detection logic, test recovery plans, and trace complex attack paths. It can help small teams operate environments that have grown beyond what manual processes can safely manage.
Australia’s inaugural Cyber Action Year, led by the ASD, urges industry to adopt an ‘assumed breach’ mindset. In today’s AI-driven threat landscape, it is no longer a question of if you’ll experience a cyber compromise; but when.
We should expect breaches, accidental deletions, misconfigurations, and attackers using AI to find weaknesses faster than defenders can close them. Organisations should prepare now: back up critical identity systems, reduce standing privilege, secure administrative paths, monitor changes to identity infrastructure, and test whether they can detect, contain, and recover from an attack when the primary environment cannot be trusted.
The responsible choice is to build guardrails while AI advances: test models against adversarial prompts, limit access and execution, require approval for high-impact actions, log tool calls, detect unusual behaviour, and design for rollback.
These actions will support organisations to take meaningful, actionable steps toward building a cyber resilient Australia.
Mick McCluney, Field CTO, ANZ at TrendAI™
Cyber Security Awareness Month/ Cyber Action Year 2026
This week marks the start of the inaugural Cyber Action Year, led by the Australian Signals Directorate (ASD). The shift in name matters. Australian organisations don’t have an awareness problem: ASD and its Five Eyes partners have already published clear, practical advisories on what needs to be done. The task now is to do it. Security isn’t a point-in-time campaign – it’s ongoing action.
Cyber Action Year calls for year-round action across government, industry and critical infrastructure, with ASD setting out priority actions each month. Organisations should use it to focus on what matters most: reducing their exposure. That starts with vulnerabilities. AI-powered tools can now discover vulnerabilities at a pace no human team can match. Australian organisations are dealing with an overwhelming volume of common vulnerabilities and exposures (CVEs) – but volume doesn’t always translate into business risk.
The bigger problem is speed. The real risk is the widening gap between a vulnerability becoming public and an organisation being able to safely apply a permanent fix. Attackers can move within hours. Vendor patches can often take weeks or months. That exposure window is where organisations are most vulnerable. Security teams won’t be able to react to every disclosure; however, they can prioritise vulnerabilities that attackers can genuinely reach and weaponise within their environment.
Virtual patching can help close the gap, providing protection while permanent fixes are tested and deployed. This is particularly important for legacy technology that cannot be patched quickly. As AI accelerates exploitation, reducing that window of exposure is increasingly important.
In the year ahead, the organisations best positioned to reduce cyber risk will be those that can cut through the noise, identify the small number of flaws most likely to cause operational harm and protect business-critical systems. The guidance is already there. Cyber Action Year is the moment to act on it – and keep acting on it.
