CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
AI gives criminals speed boost, but basic security failures persist

AI gives criminals speed boost, but basic security failures persist

Tue, 1st Sep 2026 (Today)
David Shilovsky
DAVID SHILOVSKY Interview Editor

While artificial intelligence may be reshaping the cyber threat landscape, Australian companies still face many of the same fundamental security problems that have existed for years.

AI is giving bad actors new tools to improve phishing campaigns and reconnaissance, and potentially automate elements of intrusion.

However, it is simultaneously imperative for businesses to not lose sight of longstanding weaknesses such as poor security hygiene, inadequate asset management and governance, and compromised credentials, said Regional Director APAC at LevelBlue, Nigel Hardy.

"The same, familiar challenges are still there," Hardy said.

"Typical threats still apply to businesses from one-two or five years ago. Basic hygiene, housekeeping and understanding the technologies you've got are all still important."

The rapid adoption of newer technologies, particularly artificial intelligence, is nevertheless creating an expanded and evolving attack surface for organisations.

Businesses are increasingly deploying AI capabilities into their existing networks and software environments, sometimes without fully considering the security implications. 

Companies need to find ways of adopting those technologies in a more risk-managed manner.

"The adoption of newer technologies and artificial intelligence being deployed into networks is creating a revised attack surface," Hardy said.

Supply chain attacks have also become a growing concern since late 2025. LevelBlue is seeing a significant number of incidents involving compromises further down the technology supply chain.

Compromised email still a significant threat

Despite the emergence of more sophisticated AI-enabled attacks, business email compromise remains one of the most significant sources of cyber incidents.

Hardy cited LevelBlue's global incident response data, which draws on activity across the Americas, Europe, the Middle East and APAC.

Business email compromise accounted for approximately 45 per cent of incidents in the organisation's second-quarter threat tactics, techniques and procedures briefing for 2026.

One statistic was particularly significant: multi-factor authentication was bypassed in every business email compromise case where MFA had been deployed.

The finding highlights the limitations of treating individual security technologies as a complete solution to cyber risk. While MFA remains an important control, attackers are increasingly finding ways to circumvent or exploit weaknesses around authentication processes.

At the same time, the time attackers spend inside compromised environments is changing.

Dwell times - the period between an attacker gaining access to an organisation and being detected or removed - are becoming shorter as security monitoring and incident response improved.

Response time is also shifting. Cases that may previously have taken a month or more to resolve can now often be dealt with in between three and 10 days.

However, that improvement is also influencing attacker behaviour.

Rather than spending extended periods inside a network building persistence and developing a detailed understanding of the environment, some attackers are moving directly towards valuable data.

"We're seeing attackers skipping encryption and going straight to exfiltration and extortion," Hardy said.

"They're going straight to the target rather than spending more time building a profile and persistence."

AI gives attackers speed advantage

Artificial intelligence is accelerating that trend, particularly by allowing attackers to improve and automate activities that were previously more labour-intensive.

Attackers are currently utilising a 'tempo advantage' regarding AI adoption.

Threat intelligence and predictive reporting had initially identified AI being used largely in the preparation phase of attacks, including reconnaissance and the development of phishing campaigns.

The impact is already visible in phishing emails.

Traditional warning signs such as spelling mistakes, poor grammar and awkward wording are becoming less useful as AI improves the quality of malicious communications.

AI is also improving attackers' ability to create convincing phishing messages in multiple languages, Hardy explained.

"Those classic tells that made emails easy to spot aren't there anymore," he said.

AI is now moving closer to operational use by attackers, with the potential for autonomous intrusion agents and AI-generated malware capable of modifying or mutating its own signature to make detection more difficult.

Automation could also allow cybercriminals to develop and deploy campaigns far more quickly than would be possible through traditional manual processes.

But Hardy insists that AI is not creating an insurmountable capability gap between attack and defence.

Security providers and managed services organisations have an advantage in the scale of their visibility, allowing them to aggregate information from thousands of attempted intrusions across large customer environments.

LevelBlue can identify patterns emerging in one industry or geography and rapidly apply that intelligence to detection capabilities for customers elsewhere.

"If something is emerging in one industry or geography, we can very quickly roll that detection and pattern recognition across other clients," Hardy said.

That broader perspective gives defenders an advantage that individual attackers do not have.

"The ability to see patterns, aggregate and turn around and respond is easier for defenders once it's deployed," Hardy said.

The challenge for security teams is often not technological capability but the speed at which organisations can safely adopt new tools.

Attackers can move quickly, having no regard for the governance and guardrails that large businesses need to implement.

More intelligence doesn't necessarily equate to better security

Hardy also warned organisations against responding to the changing threat landscape simply by purchasing more threat intelligence feeds.

The volume of available cyber intelligence can be overwhelming and may create a false sense of security if organisations are unable to apply it effectively.

"It's like drinking from a fire hose at times," Hardy said.

The answer is not necessarily a bigger budget or access to more information, but better context and discipline.

Every organisation has a different attack surface, operating model, technology environment and set of critical assets. As a result, the intelligence that matters most will also vary.

"Don't measure how much intelligence you consume," Hardy said. "Measure how well it's shaping decision-making."

Organisations should start by understanding their own environments, including what assets they have, where those assets are located and what information they contain.

Businesses should also make better use of internal sources such as configuration management databases, security logs, incident histories and vulnerability scans before attempting to consume every available external threat intelligence feed.

"Start internally," Hardy said.

"Look at your own environment, your logs, your incident history and the outputs from vulnerability scans. All of that is absolutely relevant."

From there, organisations can identify gaps and use external threat intelligence to better understand how an attacker might view their environment.

The goal should be to trim away the noise and focus on intelligence that can meaningfully improve security decisions.

Cyber risks tied to global conflicts

Businesses, particularly those operating critical infrastructure, should also pay closer attention to geopolitical developments and the growing overlap between kinetic and cyber warfare.

The Russia-Ukraine conflict demonstrated how cyber operations could occur alongside conventional military activity, while recent tensions involving the US, Israel and Iran had further highlighted the potential for cyberattacks to accompany geopolitical conflict.

Critical infrastructure was a particular concern, with recent attacks targeting systems such as municipal water and wastewater services.

Organisations should consider not only threats affecting their own region, but developments affecting their industry sector globally.

Attackers may also test malware or techniques against smaller and less well-defended organisations before deploying them against higher-value targets.

"Before testing and deploying malware against official targets, they want to check that it's working," Hardy said.

"They may be looking for other soft targets."