Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

The Industry Speaks: Cyber Security Awareness Month 2026, pt5

“When knowledge is shared and peers are connected, threats are identified sooner, gaps are closed faster, and good practice spreads further.” - Jason Garland, Secure Access IT

• Wed, 07 Oct 2026 •
The Industry Speaks: Cyber Security Awareness Month 2026, pt5

Yadi Narayana
Field CTO APJ, at Datadog

Every October, Cyber Security Awareness Month prompts familiar conversations about passwords and training. It’s good advice, but it misses the reality of modern resilience.

The threat has fundamentally changed. The ASD's latest Annual Cyber Threat Report notes Australia now records a cybercrime report every six minutes, and AI has compressed attacks that once took days into seconds. These modern attacks cross applications, infrastructure, and APIs instantly. A performance blip, a strange login, and a traffic spike are no longer separate incidents – they are the same attack moving through a system.

 
 

Yet, many organisations fight this with disconnected tools and an endless volume of alerts. But the alert is not the attack. Security teams are drowning in clues when they need the story. By the time they manually stitch together an attack's path, the damage is done. In fact, our State of DevSecOps 2026 report found that when runtime context is applied, only 18 per cent of ‘critical’ vulnerabilities actually remain critical. Teams are simply wading through noise.

You cannot stop a system-wide attack without seeing the whole system. The traditional disconnect – where security detects and engineering fixes using completely separate data – is an exploitable gap. Traditional tools watch isolated moments; today, we need to watch how entire systems behave in production.

Cyber security is no longer just a security problem, it’s an operational one. Security and engineering must look at the exact same real-time picture of how their systems behave. AI can help defenders connect security signals with operational context to investigate faster, but findings must be evidence-backed and actions on critical services appropriately approved. When attacks move at machine speed, runtime context, not alert volume, is the decisive advantage.


Jason Garland
Director at Secure Access IT and GTIA ANZ Executive Council Member

Cyber Security Awareness Month is a good time to look at who carries the most risk. In Australia, small businesses reported an average loss of $56,000 per cybercrime in 2024-25, up 14 per cent on the previous year. In New Zealand, 53 per cent of SMEs faced a cyber threat or attack in the past six months, rising to 76 per cent among businesses with 20 to 49 staff.

This year’s theme: ‘take a second, stay secure' sounds simple, but small businesses don’t have the time, budget, or expertise to address staying secure on their own. As such, they rely on their IT service provider (ITSP) to spot the risks they miss, which puts ITSPs squarely on the front line.

Many ITSPs serving small and mid-sized businesses (SMBs) are small businesses themselves. They face the same skills shortages and cost pressures as their customers, while managing security for dozens of clients at once. Vendors, distributors, and industry bodies need to make it easier for these providers to access training, share threat intel, and build services that fit SMB budgets.

Better support for ITSPs and better protection for SMBs depends on the entire IT ecosystem working together. When knowledge is shared and peers are connected, threats are identified sooner, gaps are closed faster, and good practice spreads further. No business – big or small – should face these risks alone, so I would encourage every organisation to use this month to review their own security, talk to their clients, customers, partners, and peers, and make sure no business is left without support.


Daryush Ashjari
CTO and Vice President Solution Engineering APJ, at Nutanix

As we recognise Cyber Security Awareness Month, organisations should acknowledge that cybersecurity blind spots are no longer limited to external threats. As businesses accelerate their adoption of hybrid multicloud architectures, AI platforms, edge computing, and distributed applications, maintaining visibility across what needs to be secured is becoming increasingly challenging.

The challenge today is not simply keeping bad actors out. It is understanding where critical data resides, how it moves across cloud and on-premises environments, and who or what has access to it. Every new cloud service, AI deployment, or edge workload expands the attack surface and creates new opportunities for security gaps to emerge. Without a comprehensive view of the environment, risk becomes harder to identify, manage, and mitigate.

Visibility is the foundation of cyber resilience in the hybrid multicloud era. Organisations cannot effectively protect, govern, or recover assets they cannot see. Security leaders need a unified view across infrastructure, applications, identities, and data, regardless of where they reside. This visibility enables faster threat detection, stronger governance, and more effective response when incidents occur.

To strengthen resilience, organisations should focus on a few key priorities. First, simplify security operations by establishing consistent policies and controls across environments. Second, adopt a data-centric approach to security by understanding where sensitive information lives and ensuring it is protected throughout its lifecycle. Third, implement Zero Trust principles that continuously verify users, devices, and workloads rather than assuming trust based on network location. Finally, ensure cyber recovery capabilities are regularly tested so critical services and data can be restored quickly in the event of disruption.

The organisations that will be best positioned to navigate the evolving threat landscape are those that can reduce complexity, maintain end-to-end visibility, and build resilience into every layer of their hybrid multicloud strategy. In an environment where threats continue to evolve and technology estates continue to expand, visibility is no longer just a security requirement. It is a business imperative.


Jennifer Cheng
Director, Cyber Security Strategy, APJ, at Proofpoint

Cyber Security Awareness Month needs to be more than an excuse to remind people to avoid scams or fake phishing email to test if people will click. Awareness alone won't keep us safe from online threats - but it's an important start, and we all play a part.

Powerful tools cut both ways, and AI is no exception. It's the hottest topic around, but the hype is outrunning the homework on how to use it safely. Organisations are playing catch-up, trying to harness AI's power while defending against it under pressure and with limited resources. Proofpoint's 2026 Voice of the CISO report found that nearly four in five Australian CISOs (79 per cent) are now expected to manage expanding AI risks without any extra resources. The cost of getting it wrong has escalated just as fast: direct financial losses from breaches nearly tripled between 2025 and 2026, from 18 per cent to 49 per cent, and regulatory sanctions rose from 29 per cent to 46 per cent.

People remain the biggest source of value and vulnerability our industry faces. That was true before AI, and it's still true now. Strong cyber hygiene, knowing how to report suspicious activity, and protecting sensitive data are fundamentals every organisation needs to get right, and increasingly, so is knowing how to work safely with AI.

Maintaining a well-trained, vigilant workforce is not optional nor a mere compliance exercise. Sharpen your team's instincts and make sure the AI you've deployed is working for you, not creating new gaps. Cybersecurity Awareness Month is ultimately about keeping people at the centre of our defences, even as the technology around them evolves.


Kevin Greene
Chief Cybersecurity Technologist – Public Sector, at BeyondTrust

Cyber Security Awareness Month is a reminder that threats move faster than the tools we have to contain them. AI compressed the gap between vulnerability disclosure and exploitation. Months became days, and in some instances, hours. And the same flaw sitting in a water treatment plant is sitting in a school district server and a county office.

Technical debt is not an IT problem. It is access. It is the leverage threat actors use to get inside our infrastructure and critical systems. Unsupported devices are the easiest way in. End-of-support doesn't mean broken. It means no more security patches to close attack vectors. Automated scanning finds a forgotten router or camera long before anyone thinks to replace it.

Volt Typhoon is a great example. The FBI dismantled a botnet built from end-of-life routers that Chinese state actors used to preposition inside U.S. water, energy, and transportation networks. Preparation has to go beyond patching. Recovery isn't restoring files. It's sustaining operations. Whether the water keeps running. Whether the school opens Monday. Whether the county makes payroll.

Resiliency is decided before the attack, not after – by how the systems were built, not by how fast anyone responds. And the harder question is who holds the keys, the leverage in our systems. Work and home now share the same networks and the same passwords. AI agents are acting on our behalf in ways most people have never examined.

It is important to retire what is no longer supported. Build for continuity. Know what has access to what is awareness. When we patch, it protects our devices, but knowing who holds the keys protects the mission capabilities.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: