Anthony Daniel
Managing Director, Australia, New Zealand and the Pacific Islands, at WatchGuard Technologies
This Cyber Security Awareness Month, the theme ‘Take a second. Stay secure’ is a timely reminder that a brief pause can interrupt an attack, but with threats evolving at unprecedented speeds, awareness alone is no longer enough.
For years, cyber security advice focused on familiar warning signs such as poorly written emails or suspicious links. Today, generative AI is helping attackers craft convincing messages, while stolen credentials can allow unauthorised entry through seemingly legitimate logins. At the same time, malware is becoming increasingly tailored to individual victims.
WatchGuard’s latest Internet Security Report found that 95.72 per cent of Q2 endpoint threats appeared on just one machine, while novel endpoint malware rose 2,065 per cent year-on-year. APAC also accounted for 50.33 per cent of network malware detections per Firebox in the first half of 2026, roughly double the share recorded in either EMEA or the Americas.
For organisations across ANZ and the Pacific Islands, the message is clear: security teams need to look beyond whether an email, link or login appears legitimate and focus on whether activity is behaving abnormally. Evolving attack methods must be treated as a local business priority.
Security must make the safe choice the easiest choice. Combine regular employee education with practical safeguards such as multi-factor authentication, strong identity controls, encrypted traffic inspection, layered network and endpoint protection, and continuous monitoring.
Cyber Security Awareness Month is a good opportunity to test where the gaps are. Use it to test one assumption your business has been making, whether that's assuming MFA is enforced everywhere it should be, or that unusual account activity would be caught quickly, and fix what the test reveals.
Daniel Churches
Director Cybersecurity, Asia Pacific and Japan, at DXC Technology
Across the region, organisations are moving fast to become AI-native, deploying tools and agents to drive efficiency and competitive advantage. But as AI transforms how your business operates, security must evolve too.
Our recent research shows that only 47 per cent of organisations have fully integrated governance for agentic AI, despite many rapidly deploying autonomous AI capabilities across the business. AI systems are now touching identities, data and decision-making at a scale and speed that traditional, human-paced security simply wasn't built for. If governance and identity aren't embedded from the outset of an AI transformation, organisations are effectively scaling risk as fast as they're scaling capability.
This Cyber Security Awareness Month, take a second to assess whether your security strategy is keeping pace with how your business is adopting AI. Organisations need to move beyond reactive defence towards intelligent, proactive and increasingly autonomous security, with governance, identity and trust embedded into AI initiatives from the start. This will enable organisations to scale AI adoption without compromising resilience or control.
Pat Breen
Head of ANZ at Cloudflare
The conversation many customers are having right now is around mitigating the scaling cyber threat with the increased capabilities of AI models such as Astra and Fable being available. It's a fair question, and the uplift in capability is real.
The fear of attackers finding flaws that nobody knew existed is not what is getting most Australian organisations breached right now.
We block an average 1.7 billion cyber threats per day targeting Australia, and that's increased 16.7 per cent in three months. The majority of those threats are automated attacks pointed at weaknesses we've known for years – reused passwords, unpatched systems, access that nobody has reviewed since the person left.
It's important to understand: AI hasn't changed the attack. It's made it cheap enough to run the same attacks against everyone.
The assumption worth retiring is that you need a sophisticated defence for a sophisticated threat. Most attackers aren't spending a breakthrough capability on you. They're trying the front door with a password someone reused, and 63 per cent of the logins we see use credentials that are known to have been compromised. It works often enough to be worth it.
That's why this year's theme, 'Don't Make It Easy for Them’, is the right one. If I were advising a customer, I'd tell them the foundations still decide the outcome: know what you're running, know where your data sits, know who has access to what. Strong, unique passwords. Multi-factor authentication wherever it's available. Compromised credentials rotated quickly. Systems patched.
None of that is new advice. That's the point.
Better tools just mean everyone gets tried. An attacker is working out whether you're worth the effort, and the basics are what change the answer.
Cynthia Lee
Vice President APAC at Delinea
This year's Cyber Security Awareness Month theme, 'Don't Make It Easy for Them', is a reminder that attackers don't always need to outsmart security controls. More often, they're looking for gaps in oversight, particularly when it comes to access to sensitive systems and data.
As organisations adopt AI, automation and other productivity tools, they're creating more ways to access information across the business. The challenge is to ensure security controls are in place to maintain accountability for access over time, and ensuring it remains appropriate as roles, technologies and business needs evolve.
Delinea’s latest Identity Security Report highlights why this matters. Only 42 per cent of Australian IT leaders can always trace a sensitive AI access event back to a named human authoriser, while just 56 per cent automatically revoke or expire access when a session ends. When organisations can't confidently answer who approved access, who is using it, or whether it's still needed, risk begins to accumulate.
Making it harder for attackers starts with closing those gaps. Organisations need a clear understanding of who, or what, can access critical resources, alongside the ability to continuously review, govern and remove access when it's no longer required. The organisations best positioned to reduce risk will be those that treat access as something that must be actively managed, not simply granted and forgotten.
David Rajkovic
Regional Vice President A/NZ, at Rubrik
The recent Medicare breach highlights the new risks organisations need to contend with. AI agents will continue to go rogue. OpenAI’s incident, along with the Hugging Face breach earlier this year, demonstrates that frontier models can sustain complex cyber operations, discover novel attack paths, and move across real-world systems in pursuit of a narrow objective.
During Cyber Security Awareness month, I would urge organisations to review their resilience posture and ability to protect against agentic threats. The truth is, Australia is not prepared to deal with the risk agents pose. Our readiness posture is lagging. Far too many organisations are relying on prevention strategies and legacy data protection systems that are inadequate for the speed of AI attacks.
Dayle Wilson
Head of Cyber Security at Macquarie Cloud Services
Risk cannot be outsourced. Cyber security awareness means little unless organisations accept they remain accountable for the security they still control. Too many Australian organisations assume a managed cloud solution transfers the risk to the MSP. It does not. Even when the provider handles defined cyber-defence actions, accountability stays with the customer. A shared responsibility model must be tightly defined, measured, capture evidence and shown ongoing with near real-time executive and operational dashboards. These should align with who owns which controls, and what residual risk remains.
A trusted MSP can feel like complete outsourcing. That is an assumption, not a certainty. Recent breaches at household names show how quickly an incident costs trust, regulatory scrutiny, and questions of leadership.
In 2024-25, 39 per cent of the 138 ransomware incidents handled by the ACSC came to light because the government contacted the victim first. With SOCI reforms and Privacy Act changes raising expectations of providers, customers, and their boards, every leadership team should use this Cyber Security Awareness Month to ask: if something were happening in our environment right now, would we know? If the answer isn't a confident yes, the risk hasn't gone away, it’s just gone unseen.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.