Research commissioned by AI observability firm Elastic and conducted by Pureprofile found 57 per cent of Australian respondents expect such a leadership change following a major incident.
However, 28 per cent said their organisation’s response to the prospect of rising cyber risk has been mostly paperwork rather than genuine operational change.
The findings are particularly significant as frontier AI enables attackers to increase the speed, scale, and automation of their operations.
While 90 per cent of respondents said their organisation has at least some understanding of how frontier AI models could be weaponised, just 14 per cent said their organisation would respond to an AI-automated attack with mostly automated processes capable of operating at machine speed.
Instead, 83 per cent said they continue to rely on a combination of manual and automated processes.
“The Australian government has made clear that cyber resilience is a leadership responsibility. But AI agents don’t carry accountability; people do,” Jeremy Pell, country manager ANZ at Elastic, said in an August 26 statement.
“AI adoption and risk appetite are often set from the top down, but security teams can be left carrying the operational consequences when fragmented data, manual processes and untested controls fail.”
The research comes as the Australian Signals Directorate prepares to evolve the Essential Eight cybersecurity framework. Just 18 per cent of Australian respondents said the current framework primarily supports real protection rather than compliance, while 82% want its replacement to be either simpler and prescriptive, or combine clear rules with organisational judgement.
Meanwhile, 64 per cent of Australian organisations have experienced cybercriminals impersonating their organisation, brand, or staff to target customers or business partners.
Operational visibility is also a concern, with 60 per cent of organisations knowingly identifying at least one unmonitored area of their environment. Legacy systems, skills shortages and fragmented data across cloud, on-premises, and SaaS environments were among the leading causes.
More than half of respondents said their organisations are already using AI for cyber security, while another 25 per cent expect to deploy it within 12 months. Yet only 20 per cent considered their security data “very ready” for reliable use by an AI agent.
“Deploying an AI security agent is not the same as being ready for one,” Pell said.
“Agents need complete, searchable context and the freedom to use the model best suited to the task.”
The research surveyed 602 Australian IT and cybersecurity professionals as part of a wider study of more than 850 respondents across Australia and New Zealand, with fieldwork conducted in August 2026.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.