Jason Pearce
Field chief technology officer, APJ, at Claroty
In 2026, Australia’s ASD has itself been pushing the conversation beyond awareness, calling for organisations to adopt an assumed-breach mindset and turn cyber awareness into practical, measurable action. For critical infrastructure, that includes being prepared for circumstances where systems and networks may need to operate differently – or even be isolated – for extended periods.
We rely on OT and cyber-physical systems constantly in everyday life, often without seeing them; from the electricity, water, and transport we depend on to the hospitals, food supply chains, data centres, and manufacturing systems behind essential services. That means the impact of disruption rarely stops at the affected organisation; it can cascade across customers, suppliers, communities, and the broader ecosystem.
Cyber security remains important. But in environments where digital systems control physical processes, the outcome that ultimately matters is not simply whether an attack was detected or prevented. It is whether the organisation can continue to operate. That may be the most important cyber-awareness conversation organisations have this October.
Sarah Cecchetti
Director of product management at Semperis
There is a serious debate about whether we should slow down AI development. Builders understand the trade-off: progress creates risk, but refusing to make progress does not remove it; it often gives the advantage to someone else.
AI can help Australian organisations build security and identity infrastructure that is more capable and resilient. It can analyse identity telemetry, surface suspicious privilege changes, generate detection logic, test recovery plans, and trace complex attack paths. It can help small teams operate environments that have grown beyond what manual processes can safely manage.
Australia’s inaugural Cyber Action Year, led by the ASD, urges industry to adopt an ‘assumed breach’ mindset. In today’s AI-driven threat landscape, it is no longer a question of if you’ll experience a cyber compromise, but when.
We should expect breaches, accidental deletions, misconfigurations, and attackers using AI to find weaknesses faster than defenders can close them. Organisations should prepare now: back up critical identity systems, reduce standing privilege, secure administrative paths, monitor changes to identity infrastructure, and test whether they can detect, contain, and recover from an attack when the primary environment cannot be trusted.
The responsible choice is to build guardrails while AI advances: test models against adversarial prompts, limit access and execution, require approval for high-impact actions, log tool calls, detect unusual behaviour, and design for rollback.
These actions will support organisations to take meaningful, actionable steps toward building a cyber resilient Australia.
Andrew Philp
Field CISO, ANZ, at TrendAI
This week marks the start of the inaugural Cyber Action Year, led by the Australian Signals Directorate (ASD). The shift in name matters. Australian organisations don’t have an awareness problem: ASD and its Five Eyes partners have already published clear, practical advisories on what needs to be done. The task now is to do it. Security isn’t a point-in-time campaign – it’s ongoing action.
Cyber Action Year calls for year-round action across government, industry, and critical infrastructure, with ASD setting out priority actions each month. Organisations should use it to focus on what matters most: reducing their exposure. That starts with vulnerabilities. AI-powered tools can now discover vulnerabilities at a pace no human team can match. Australian organisations are dealing with an overwhelming volume of common vulnerabilities and exposures (CVEs) – but volume doesn’t always translate into business risk.
The bigger problem is speed. The real risk is the widening gap between a vulnerability becoming public and an organisation being able to safely apply a permanent fix. Attackers can move within hours. Vendor patches can often take weeks or months. That exposure window is where organisations are most vulnerable. Security teams won’t be able to react to every disclosure; however, they can prioritise vulnerabilities that attackers can genuinely reach and weaponise within their environment.
Virtual patching can help close the gap, providing protection while permanent fixes are tested and deployed. This is particularly important for legacy technology that cannot be patched quickly. As AI accelerates exploitation, reducing that window of exposure is increasingly important.
In the year ahead, the organisations best positioned to reduce cyber risk will be those that can cut through the noise, identify the small number of flaws most likely to cause operational harm, and protect business-critical systems. The guidance is already there. Cyber Action Year is the moment to act on it – and keep acting on it.
Ravi Soin
CIO and CISO at Smartsheet
If a manager gave a new hire standing access to your customer database, financial systems, and half your internal tools – and never reviewed their judgment once – you’d fire that manager. Yet that’s exactly how most organisations are managing AI agents right now, and no one’s being held accountable for it.
AI agents make thousands of judgement calls a day: what data to pull, what to send where, almost none of it reviewed. The gap isn’t that adoption is moving fast. It’s that we deploy agents like software and expect them to behave like employees, without the system that catches them when they don’t.
Three failure modes hide in plain sight: scope creep (an agent quietly picks up access nobody approved, one integration at a time), drift (outputs stay technically fine while diverging from intent, unnoticed without a regular check-in), and dead weight (agents outliving the project that justified them, because retiring one isn’t anyone’s job).
The fix isn’t new tooling. It’s the same discipline security frameworks have championed for decades: defined scope, an auditable record, a scheduled review, and a named owner. When something’s off, agents deserve the same process employees get: a formal performance improvement plan (PIP), which would mean a narrowed scope, a remediation window, and a decision point before an all-or-nothing shutdown. Termination should be just as procedural: access revoked, credentials killed, the shutdown logged and confirmed.
None of this is exotic. It’s the same discipline we already apply to people, aimed at a newer kind of worker. The organisations that get ahead of AI risk this year won’t be the ones that adopted the most tools. They’ll be the ones who can name, for every agent running in their environment, exactly who’s managing its performance, and what happens when it isn’t good enough.
Mathi Gurusamy
Chief product and strategy officer at Lantronix
Having fallback infrastructure is critical: you need it to maintain operations and ensure security in the event of an outage or a cyber attack. During Cyber Security Awareness Month, we can further reflect on the importance of systems that support business continuity before they’re needed. Out-of-band management is core security infrastructure. It separates routine administration from the production network. It’s not a luxury, but an independent, trusted access path when primary controls are unsafe.
Carolyn Duby
Field CTO and cyber security lead at Cloudera
Bringing AI closer to the data can reduce exposure to public cloud endpoints and strengthen sovereign control over proprietary data. However, infrastructure control does not automatically equate to complete security. Insider threats, misconfigurations, compromised credentials, and unexpected agent behaviour still remain. Bringing compute closer to sensitive enterprise data places greater responsibility on organisations to secure, monitor, and govern that environment. Private AI changes that equation, but it does not erase it. The foundational principles of cyber security remain unchanged, but the entity interacting with enterprise data has fundamentally evolved.
As enterprises give AI agents greater autonomy and responsibility, cyber resilience will increasingly depend not on assuming those agents will remain within their guardrails, but on having the visibility and controls to monitor, contain, and audit what happens when they do not.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.