AI cyberattacks outpace Australian firms' defences

Fifty-seven per cent of Australian IT professionals expect a CEO would resign or be removed after a major breach. Three regulators have moved this year to make board accountability the formal governance expectation. Cyber and D&O underwriters are watching both

AI cyberattacks outpace Australian firms' defences

Cyber

By Jonalyn Cueto

Fewer than one in seven Australian organisations believe they could respond to an AI-automated cyberattack at machine speed, according to research from Elastic. The finding lands as Australian regulators move to tie AI-driven cyber risk directly to board and executive accountability, a shift with growing relevance for cyber and directors and officers (D&O) underwriters.

The Elastic survey drew on responses from 602 Australian IT and cybersecurity professionals, finding a gap between awareness of AI-driven threats and confidence in operational response: 90% said their organisation had at least some understanding of how frontier AI models could be used against them, but 83% said their response to attacks still relied on mixed or manual processes.

Independent data points to a similar trend. A separate survey by QBE found that cyber incidents are widespread among Australian businesses, with 50% reporting a cyber event in the past 12 months and 26% saying the incident was believed to involve AI, while 85% of organisations reported already using AI in their operations, with a further 12% actively exploring its use.

Regulators tighten the screws

The Australian Prudential Regulation Authority issued its first published AI-specific expectations for boards and accountable executives in April, covering cyber and information security, governance, supplier risk, and change management. APRA stated that AI adoption is materially changing the cyber threat landscape for regulated entities, increasing the pathways attackers can use and leading to more frequent attacks.

The Australian Securities and Investments Commission followed in May, issuing an open letter to every AFS licensee declaring that the rise of frontier AI has fundamentally and permanently altered the cyber threat environment, with the directive that boards must table and discuss the letter at their highest governance committees. ASIC commissioner Simone Constant said, "Cyber risk has entered a new era."

The Australian Signals Directorate and the Australian Institute of Company Directors released Frontier AI Cyber Threat Considerations for Boards of Directors in early August, warning that frontier AI models are compressing attack timelines and lowering the skill barrier for malicious actors.

Under Australian law, directors can already face personal penalties or removal if a company is compromised because of weak cybersecurity, a backdrop that helps explain why more than half of the Elastic respondents expect executive accountability to follow a serious breach. Yet 28% of respondents said stronger accountability had mainly produced more paperwork rather than operational change, and 11% said nothing had changed at all, per Elastic's findings.

Detection gaps persist

The Elastic survey also found that half of respondents still require human intervention for 60% to 100% of security decisions when handling alerts, and 84% said a person must read an alert and decide what to do for at least 40% of decisions. Confidence in overnight detection was limited: only 9% believed a compromise would be noticed within five minutes, while 41% expected detection to take at least an hour. Almost two-thirds of organisations, 64%, said criminals had impersonated their brand or staff to target customers or partners.

Jeremy Pell, Elastic's country manager for Australia and New Zealand, said accountability increasingly falls on leaders even when security teams manage fragile systems. "AI agents don't carry accountability; people do," Pell said.

Adoption of AI security tools is accelerating regardless of readiness gaps, according to Elastic: 52% of organisations already use AI for cybersecurity and a further 25% plan to within a year, even though only 20% described their security data as very ready for reliable AI use. Some 78% said they had revised their incident response playbook in the past year to address AI-accelerated attacks, though 54% of those who did remained unconfident in their defences.

For cyber and D&O insurers, the combination of rising AI-enabled incident frequency, tightening regulatory expectation and persistent operational gaps points toward continued underwriting scrutiny of both technical controls and board-level governance processes.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!