SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
AI pushes cyber awareness campaigns beyond passwords

AI pushes cyber awareness campaigns beyond passwords

Tue, 29th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Australian and New Zealand security leaders warn that traditional awareness campaigns are falling behind as artificial intelligence reshapes cyber risk during this year's Cyber Security Action Month. Executives from Barracuda, Arctic Wolf and HCLTech say organisations must treat AI-driven threats and identity protection as core operational issues.

The federal government's decision to rebadge the program as Cyber Security Action Month has drawn support from security vendors, which argue that awareness alone no longer matches the pace of attacks. Incidents such as the recent Medicare AI agent intrusion and the Origin Energy breach have highlighted how quickly automation can turn small control gaps into large-scale data exposures.

Dan McLean, Country Manager for Australia and New Zealand at Barracuda, said advice focused on passwords and generic phishing drills no longer reflects how attackers operate.

"The government has renamed Cyber Security Action Month this year, and that word change earns its keep. Awareness usually lands on passwords and phishing. Useful, but no longer enough. Identity is the new perimeter, and AI is pushing it to breaking point. Adversaries rarely force their way in anymore. They sign in, using credentials belonging to someone, or something, we already trust. Our own Red Team showed how fast that unfolds. One AI-written phishing email chained through a ClickFix lure and an MFA bypass to full endpoint compromise and attacker persistence in five minutes. Five minutes. Quarterly access reviews and Monday morning alert queues don't meet that. Monitoring has to be continuous, response measured in minutes, and somebody has to be tracking how these techniques shift week to week.

From there, a single identity becomes the launch pad for everything else. Our research finds one in seven compromised accounts is now used to launch further attacks, and we expect that to climb as adversaries automate. Machine identities compound the problem. The API keys, service accounts and automation tokens quietly running our businesses outnumber our staff, and most have never been reviewed, rotated or retired.

Here's the gap that frustrates me. Large enterprises fold identity into a broader cyber resilience platform. Smaller Australian organisations, and the MSPs supporting them, are stuck stitching together standalone tools that are complex, costly and painful to run at scale. So my ask this October is a call to action, not a takeaway. Count your non-human identities, then work out how fast you would spot one being used against you. In the agentic AI era, protecting both human and machine identities isn't optional. It's resilience," said McLean.

McLean's comments reflect a broader shift in local boardroom discussions, where identity systems, API keys and automation tokens now sit alongside endpoints and networks as frontline assets. Smaller security teams face particular strain as they try to manage these issues across multiple point tools with limited staff.

At Arctic Wolf, the focus has turned to the volume of machine-generated data security operations teams must interpret as AI increases the speed of both attacks and defences.

"Cybersecurity Awareness Month comes at a point when even the companies building frontier AI are asking hard questions about speed, autonomy and control. That debate matters, but businesses cannot wait for it to be resolved. AI is already embedded in organisations and being used by defenders and attackers alike. The question for business leaders is no longer 'how do we slow this down?' but 'how do we operate safely while it keeps speeding up?'

At Arctic Wolf, we analyse more than 10 trillion security events on our platform every week, which gives a sense of the sheer volume and speed organisations are up against. A second is a long time in cybersecurity. The challenge is not simply seeing more activity, but separating the signal from the noise and acting quickly when something genuinely matters.

That requires a different level of preparedness. Machines can take on routine security work at machine speed, but people still need to exercise judgment over decisions with the greatest impact. Arctic Wolf helps organisations understand where AI is operating, what it can access, put clear guardrails around those permissions, and detect, contain and respond quickly when something goes wrong.

Cybersecurity is ultimately a team sport. While technology plays a critical role, people remain one of the most important lines of defence. That's why, as part of Cybersecurity Awareness Month, Arctic Wolf is providing free security awareness training resources to help organisations strengthen their human layer of defence, recognise cyber risks and build safer online habits.

AI has its foot on the accelerator. Cybersecurity is what keeps the car on the road. At Arctic Wolf, our focus is helping organisations navigate that reality with confidence. We cannot predict every AI-related risk, but we can reduce exposure, catch problems earlier and make sure one failure does not become a lasting business problem," said David Hayes, Regional Director, Australia and New Zealand, Arctic Wolf.

The role of non-technical staff in risk management is also front of mind for large employers. Sonia Eland, Executive Vice President and Country Manager, Australia and New Zealand, HCLTech, said new tools and models have changed how organisations must think about everyday behaviour.

"Cybersecurity awareness has been a priority for organisations for many years, and most businesses now understand it's not just the responsibility of IT teams. What has changed recently is the speed and complexity of the risk environment, particularly as generative AI and frontier language models become part of everyday work and everyday life.

The act of typing a prompt can now create new and sometimes unforeseen vulnerabilities. A poorly framed instruction, a vague request, or the use of sensitive company or customer information in the wrong environment can expose organisations to risks that traditional cyber training was not designed to address. This is not just a technology issue. It is a people, process and governance issue as well.

Employees are already using generative AI at home and in their personal lives, often in very open and experimental ways. At work, that same behaviour needs much clearer boundaries. People need to understand what information can be shared, what should never be entered into external tools, and how to use AI safely without putting company, customer or partner data at risk.

At the same time, established cyber threats have not gone away. Phishing, impersonation and social engineering remain major entry points into corporate systems, but generative AI is making these attacks more convincing, more personalised and harder to detect. That makes the human in the loop one of the most important parts of an organisation's security posture.

Cybersecurity Awareness Month is a timely opportunity for organisations to reinforce that message. The goal is to make sure their people are properly supported with the right awareness, guardrails, processes and technology. As AI becomes more deeply embedded in the way we work, uplifting cyber safety across the workforce is more critical than ever," said Eland.