Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

The Industry Speaks: Cyber Security Awareness Month, 2026, pt2

“The threat landscape we are defending against today bears little resemblance to 12 months ago.” - Andrew Kay, Illumio

• Tue, 06 Oct 2026 •
The Industry Speaks: Cyber Security Awareness Month, 2026, pt2

Jack Cherkas
Global Chief Information Security Officer at Syntax

Cyber Security Awareness Month is usually a reminder to get the fundamentals right and that is still absolutely critical. This year, however, the National Cybersecurity Alliance has adopted the theme, “Don’t Make It Easy for Them,” and that message should also prompt organisations to look at a growing source of risk: artificial intelligence.

As organisations and individuals adopt AI, we need to remember that AI is not just another technology. It has the potential to be transformational. It can hold accounts and permissions, see whatever you give it access to and take actions on your behalf. Many organisations and individuals have never considered the implications of these actions.

 
 

So, as the world embraces AI, we must determine three things before access is granted: what it can see, what it can do and who is responsible for it. And we also must remember that, in many cases, AI appears even when we never chose it. It’s in the tool approved three years ago that quietly shipped an AI-infused update, the browser extension or the application add-in. Some AI adoption arrives without a decision, and the things nobody decided on are the things nobody is watching.

“Don’t Make It Easy for Them” is the right tagline for this year. For organisations, that means adopting AI in a pragmatic, secure and responsible manner. For individuals, it means ten minutes in your settings. Neither is hard. Both are overdue for many.


Rob Gregory
CISO at Optiv

I believe Cyber Awareness Month is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity risk management program. However, it cannot be the strategy. If companies use it as another training module, then it’s just another compliance exercise.

Security awareness is a 24/7, 365-day-a-year operation. The goal for a CISO should be behaviour change and reinforcement, not training completion. CISOs should use this month as an opportunity to reinforce the behaviours that employees should be practising throughout all 12 months of the year.

They can do this by creating visibility and encouraging engagement as well as ensuring employees understand they are the front lines in cybersecurity. The strongest cyber cultures exist when employees see themselves as part of the security team. This month should reinforce that culture, not be a substitute for it.


James Greenwood
Area Vice President, Solution Engineering APAC, at Tanium

This year, the ASD is calling for an inaugural year of action, and for good reason. Many businesses are already using AI to unveil insights around market opportunities, growth prospects, and of course, cyber threats. But few organisations are actually leveraging AI to turn those insights, dashboards and data into tangible action. This gap will separate the AI experimenters from the AI adopters, with the latter best equipped to turn noise into action plans specific to their roles.

We’re now in a world where skilled and less-skilled operators can enter a prompt for an IT or security issue and be directed on how to address that issue in real-time, lowering the need for highly skilled resources and democratising access to tools. Management has never had greater access to real-time reporting and visibility, as well as comprehensive guidance on how to investigate, mitigate and remediate issues as they happen.

Taking effective control of these new capabilities requires companies to marry their AI adoption with a “human above the loop”, not just a “human in the loop”. We can’t afford to assume that equipping our teams with AI will lead to good governance. Businesses need to ensure that, alongside controlled AI adoption, there is a proactive approach to ensuring humans are in control of how AI is used, designed, and evolved over time. This means not being afraid to change, stop, or update AI tools and approaches as needed, and investing the time and resources to ensure they are operating in ways that support and strengthen cyber hygiene without introducing new business or governance risks.


Lindsay Keating
EVP & GM, APAC at Pax8

Midsize companies to SMBs are often seen as the easier target for cyber criminals. While enterprises are investing the funds and resources into preventative measures, organisation-wide training, and the latest technologies, midsize companies and SMB owners are focused on simply keeping the business running against the backdrop of economic uncertainty and a cost-of-living crisis. AI presents an unprecedented opportunity for companies to compete, grow, and secure their organisations at the same pace and scale as enterprises, but many business owners across ANZ are hesitating to act, too concerned about potential backlash or a general fear of change.

This Cyber Security Awareness Month, which the Australian government is encouraging companies to treat as a year of action, couldn’t be more timely. Taking action doesn’t need to mean adopting every AI tool for the sake of it. In fact, for midsize to SMB owners, a savvier place to start is with education. Knowledge is power, and the more we can equip businesses with the information needed to make smart, effective, and strategic AI investments, the more resilient they will be against cyber threats.


Andrew Kay
Senior Director, Systems Engineering, APJ, at Illumio

The threat landscape we are defending against today bears little resemblance to 12 months ago. Then, organisations could still afford to think of cyber defence as a ‘race’ between attackers and defenders. Now, with Frontier AI, the contest is essentially won. Attackers can now move faster, adapt faster and scale attacks faster, leaving defenders well, defenceless.

Combine this frightening reality with the fact that – even if an attack is detected, doesn’t mean it is contained quickly. Illumio research found that while 95% of organisations say they can detect unauthorised movement in their IT environments, almost half struggle to stop it spreading. That is a dangerous gap. It exposes a critical window where attackers can move laterally, escalate privileges, and turn an initial foothold into a disaster - crippled operations, costly downtime and reputation damage.

The Australian government is right to shift the focus to action over awareness this year, and to urge the adoption of an ‘assumed breach’ mindset. Breach containment is the most critical part of this, and should be a core security strategy. Organisations need to know how attackers could move through their environments when an incident inevitably occurs, eliminate unnecessary pathways and be able to rapidly isolate compromised systems.


David Hayes
Regional Director, Australia and New Zealand at Arctic Wolf

Cyber Security Awareness Month comes at a point when even the companies building frontier AI are asking hard questions about speed, autonomy and control. That debate matters, but businesses cannot wait for it to be resolved. AI is already embedded in organisations and being used by defenders and attackers alike. The question for business leaders is no longer ‘how do we slow this down?’ but ‘how do we operate safely while it keeps speeding up?

At Arctic Wolf, we analyse more than ten trillion security events on our platform every week, which gives you a sense of the sheer volume and speed organisations are up against. A second is a long time in cyber security. The challenge is not simply seeing more activity but being able to separate the signal from the noise and act quickly when something genuinely matters.

That requires a different level of preparedness. Machines can take on routine security work at machine speed, but people still need to hold judgement over the decisions that carry the greatest impact.


James Eageleton
Managing Director, ANZ, at Cohesity

Cyber Security Awareness Month reminds us that awareness of cyber risks is growing, but preparedness remains a challenge for many organisations.

Recent cyber incidents have shown that no sector is immune from attack, and almost every organisation now has its own recovery and resilience plan. That said, many organisations still rely on unproven assumptions in these plans about how they would respond and recover during a real-world incident. Our latest research found that 93% of Australian organisations that experienced a material attack in the last year had relied on recovery plans built on unproven assumptions, such as assuming recovery will proceed in a linear, step-by-step sequence without significant backtracking, or that they will have adequate information.

This highlights a significant gap between understanding cyber risk and being prepared to navigate it realistically under pressure. We also found that only two per cent of organisations believe their current recovery plans are adequately equipped to withstand frontier AI-powered threats.

These findings show that while cyber threat awareness is at an all-time high, many organisations remain unsure how well they could recover from a live incident. Cyber Security Awareness Month is a timely reminder to challenge assumptions, validate resilience strategies and regularly test critical recovery processes. Awareness is the necessary first step, but true resilience comes from confidence that plans will work when they are needed most.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: