SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Businesses urged to add stronger controls beyond vigilance

Businesses urged to add stronger controls beyond vigilance

Fri, 21st Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Australian cyber security and payments experts are urging businesses to shift their focus from employee vigilance to stronger technical controls, as Scam Awareness Week highlights the growing financial and regulatory risks of fraud.

The push comes as regulators tighten expectations around scam prevention and losses from online fraud continue to rise.

Industry concern has sharpened over whether traditional awareness campaigns can keep pace with increasingly sophisticated criminal tactics. Recent Australian Competition and Consumer Commission figures show Australians reported more than AUD $2 billion in scam losses in 2025, with online scams involving financial loss up almost one-third and phishing the most commonly reported category.

Security vendors are seeing similar patterns. WatchGuard Technologies has observed a marked shift towards more evasive malware, including attempts to blend malicious activity into legitimate web and application traffic.

Beyond vigilance

Anthony Daniel, Managing Director for Australia, New Zealand and the Pacific Islands at WatchGuard Technologies, said the familiar advice to "stay vigilant" no longer reflects the reality of modern attacks, which often mimic authentic digital experiences and target trusted platforms.

"Every year, Scam Awareness Week is framed as a reminder to 'stay vigilant'. But vigilance alone is not enough when scam tactics are becoming increasingly difficult to distinguish from legitimate digital interactions. Attackers are hyper-personalising their approaches, using spoofed platforms, online advertisements and fake websites to exploit trust, harvest credentials and quietly establish access."

Attackers are increasingly trying to bypass the first line of defence by compromising credentials and then moving laterally inside networks. That has increased the importance of tools that track behaviour after a user logs in, not just at the point of login.

Daniel said multi-factor authentication should be a baseline, supported by continuous monitoring, behavioural analysis and Zero Trust principles. These measures can flag anomalies when legitimate usernames and passwords are being used but the activity departs from normal patterns.

Regulatory pressure

Financial services and payments businesses also face fresh regulatory pressure. From 1 September 2026, the core rules of the Scam Prevention Framework will impose strict duties on banks, telecommunications providers and digital platforms, with enforcement focused on how organisations detect, disrupt and respond to scams at the moment money moves.

Payment redirection scams remain a particular concern. Government data shows they were the second-largest source of scam losses in 2025, costing Australians more than AUD $166 million.

Payments controls

Payments fintechs argue that stronger controls at the point of transaction can block a significant share of fraudulent transfers before funds leave a customer account. Confirmation of Payee has emerged as a central part of that push in Australia.

Confirmation of Payee is an industry-wide name-checking tool that compares the account name and details entered by a payer with those held by the recipient's bank. It warns the payer when there is a mismatch or ambiguity.

Zepto, which provides digital payment services to merchants, said uptake has been rapid since the service launched in mid-2025.

"From 1 September 2026, the core rules of the Scam Prevention Framework take effect, imposing strict duties on banks, telecommunications providers and digital platforms to detect, disrupt and respond to scams. With payment redirection the second-largest scam loss category in 2025, costing Australians more than AUD $166 million, the message is clear: the controls in place at the moment money moves will determine whether businesses protect customers or face regulatory consequences.
"Fortunately, the industry has responded with the rollout of Confirmation of Payee, an industry-wide security service that matches the account details a business enters with those held by the recipient's bank. Since launching in July 2025, Confirmation of Payee has surpassed 150 million checks and become a frontline defence against payments fraud and scams. Zepto's platform data shows that one in three payments checked by Confirmation of Payee in the first half of 2026 was flagged for closer inspection, demonstrating the importance of verifying before money moves.
"While scam awareness efforts rightly focus on educating businesses and consumers about social engineering tactics, businesses cannot neglect the point at which money moves and the deception succeeds. Those that embed stronger security controls into their payment flows will not just meet incoming compliance expectations, they will directly address the critical vulnerability where Australians are losing the most."

Daniel said Scam Awareness Week should now extend well beyond awareness campaigns to measures that limit the damage when users inevitably make mistakes or fall for deceptive messages.

"According to the ACCC, Australians reported more than AUD $2 billion in scam losses in 2025. Online scams involving financial loss increased by 31.8 per cent, and phishing remained the most commonly reported scam type. WatchGuard's Threat Report points to the same broader trend towards more evasive activity, with new malware increasing every quarter and surging 1,548 per cent between Q3 and Q4 alone as attackers became increasingly effective at concealing malicious behaviour within seemingly legitimate traffic.
"For Australian businesses, particularly those with limited security resources, the answer is not simply more reminders for employees to be careful before they click. Organisations need to accept that some highly convincing scams will succeed and build their security strategy around what happens next. Multi-factor authentication remains essential, but it should be reinforced by continuous monitoring, behavioural analysis and Zero Trust principles that can identify when legitimate credentials are being misused.
"These controls give organisations greater visibility into what happens after a user logs in, helping security teams detect unusual behaviour and contain suspicious activity before it escalates. Employee awareness remains important, but it cannot be the sole line of defence against increasingly sophisticated attacks. In 2026, the real test is how quickly an organisation can detect abnormal activity after the click, contain it and prevent one compromised account from becoming a broader business-wide incident."