CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
Australian firms unready for AI cyber attacks, Elastic

Australian firms unready for AI cyber attacks, Elastic

Wed, 26th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Elastic has published research showing that 14% of Australian organisations believe they could respond to an AI-automated cyber attack at machine speed. The survey also found that 57% of respondents expect a Chief Executive Officer would resign or be removed after a major breach.

Drawn from a survey of 602 Australian IT and cybersecurity professionals, the findings point to a gap between awareness of AI-driven threats and confidence in operational response. While 90% said their organisation had at least some understanding of how frontier AI models could be used against them, 83% said their response to attacks still relied on mixed or manual processes.

That gap sits alongside rising expectations of executive accountability. Australian law allows directors to face personal penalties or removal if a company is compromised because of weak cybersecurity, and the survey suggests many security professionals now expect that pressure to reach the top job after a serious incident.

Respondents did not, however, describe a broad shift in operational practice. More than a quarter, 28%, said stronger accountability had resulted mainly in more paperwork rather than real change, while 11% said nothing had changed at all.

Jeremy Pell, Country Manager, ANZ, at Elastic, said the burden of accountability may fall on leaders even when security teams are left managing fragile systems and fragmented data.

"The Australian Government has made clear that cyber resilience is a leadership responsibility. But AI agents don't carry accountability; people do," Pell said.

"AI adoption and risk appetite are often set from the top down, but security teams can be left carrying the operational consequences when fragmented data, manual processes and untested controls fail."

Framework pressure

The research comes as Australian cyber guidance is under review, with the Australian Signals Directorate preparing changes to the Essential Eight. Respondents offered a mixed assessment of the framework, with only 18% saying it primarily supported real protection rather than compliance.

A larger group wanted future guidance to be clearer. Some 82% said they wanted the next framework either to be simpler and more prescriptive or to strike a balance between firm rules and organisational judgement.

Resource constraints and ageing technology remain obstacles to implementation. Respondents cited insufficient budgets, staffing and skills, legacy systems, and competing business priorities as the main barriers to fully putting guidance into practice.

Beyond governance, the survey points to weaknesses in day-to-day monitoring and response. Sixty per cent said their organisation had identified at least one unmonitored area in its environment, while a third said they had several such gaps.

Legacy systems were the most common reason given for those blind spots, followed by shortages of people or specialist skills, data spread across cloud, on-premises and software-as-a-service systems, and tools that do not integrate effectively.

Manual bottlenecks

The survey found that half of respondents still require human intervention for 60% to 100% of security decisions when dealing with alerts. A larger share, 84%, said a person must read an alert and decide what to do for at least 40% of security decisions.

Outside business hours, confidence in early detection was limited. Only 9% believed someone would become aware of a compromise within five minutes, while 41% expected detection to take at least an hour.

The research also highlighted the spread of impersonation attacks. Almost two-thirds of Australian organisations, 64%, said cyber criminals had at some point impersonated their organisation, brand or a member of staff to target customers or business partners.

Pell said attackers have moved faster than most defenders.

"Attackers automate their moves, but most Australian defenders still need a person to read an alert before anything happens. Being aware that frontier AI models are changing the cybersecurity landscape, and actually having the systems in place to deal with the problem, are two different things.

"This imbalance between automated and manual methodologies is becoming unsustainable. It is made worse when the tools themselves are not built to support searchable, integrated, real-time agentic data and security tools that explain reasoning. The goal is not to remove human judgement from security operations. It is to ensure you have a strong agentic operations centre and can move humans to the top of the loop, where they are making decisions rather than manually tracking down background details."

AI uptake

More than half of respondents, 52%, said AI is already being used for cybersecurity in their organisation, and another 25% expect to deploy it within the next year. Even so, only 20% described their security data as very ready for an AI agent to use reliably.

That mismatch suggests many organisations are adopting tools before fixing the quality and accessibility of the underlying information those systems depend on. The survey found that 28% reported important data gaps or fragmentation, while 11% had either not assessed readiness or said they were not ready at all.

Many organisations have updated procedures to reflect faster-moving threats. Some 78% said they had revised their incident response playbook within the past year to address AI-accelerated attacks.

Those updates have not removed doubt. Among respondents whose organisations had refreshed their playbook, 54% still said they were not confident in their defences.

Pell said adopting AI tools should not be confused with operational readiness.

"Deploying an AI security agent is not the same as being ready for one," he said.

"Agents need complete, searchable context and the freedom to use the model best suited to the task. An open, model-agnostic security platform allows organisations to use commercial or on-premises open-source models without locking critical operations to one provider. As AI accelerates the threat, Australian organisations need defences that can move just as quickly."