threat_intelligence2411 wordsRead on Arc Codex

Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk

Every AI security vendor right now wants you to believe the answer to faster attackers is a faster AI defender. That's backward. Speed without judgment simply generates more telemetry and alerting, much of which may not require human triage or consideration, taxing already stretched cybersecurity resources. For an Australian board, the more useful question is whether the organisation can see what is happening, make a sound decision quickly and recover when prevention fails. In July 2026, Hugging Face disclosed a security incident involving an autonomous-agent system that reached production infrastructure, executed code, harvested credentials and moved laterally. OpenAI later described the incident as connected to models operating in an internal cyber-capability evaluation. The reported impact was limited; the case is useful because it shows how quickly access, credentials and automation can combine when an evaluation environment crosses its intended boundaries. The incident is not evidence that AI routinely breaches organisations, nor that every AI system acts independently. It is a practical illustration of why boards need clear controls around privileged access, testing environments, provider risk and incident response. What ASD Is Actually Asking Boards to Do Australia Signals Directorate (ASD) and the Australian Institute of Company Directors have published two relevant pieces of guidance for boards: Cyber security priorities for boards of directors 2025-26 and Frontier AI cyber threat considerations for boards of directors. Together, they make two points: the fundamentals still matter, and emerging AI capabilities may compress the time available to detect and contain an attack. The cost of inaction. The board guidance states that espionage enabled by technology advancements cost Australia $12.5 billion in FY23–24. A separate measure in ASD's Annual Cyber Threat Report 2024–25 puts the average self-reported cost of cybercrime for Australian businesses at $80,850 per report, with averages of $56,600 for businesses of any size, $97,200 for medium businesses and $202,700 for large businesses. These figures are not interchangeable: the first is a national estimate for espionage, while the second is a self-reported average for business cybercrime reports. The AI risk multiplier. The frontier-AI guidance describes the potential for advanced models to identify vulnerabilities, chain lower-severity weaknesses and conduct malicious activity with limited human oversight. That is a capability assessment, not a claim that every attacker is already using autonomous systems or that every attack will move from days to hours. Boards should treat the change as an opportunity to test assumptions about response and detection times, not as grounds to abandon the fundamentals. A shift in timelines: AI has reduced the timeline of a cyberattack from days to hours, lowering the barrier to entry for unskilled attackers. Staggered priorities for defence: Start with the attack surface. Secure-by-design technology, timely patching and a managed view of exposed services reduce the opportunities an attacker can find first. Secure identity. Strengthen identity, credential and access management, including phishing-resistant MFA for higher-risk access. Deal with legacy exposure. Replace or isolate unsupported systems and edge devices. Track exceptions, assign an owner and set a date for removal. Make logs useful. Collect and review event logs so suspicious activity can be correlated across systems rather than assessed one alert at a time. Understand dependencies. Know which suppliers, MSPs, SaaS providers and AI providers can access systems or data, and what would happen if one of them were compromised. Prepare for the longer horizon. Set controls around AI agents and human oversight, while beginning the longer-term planning required for post-quantum cryptography. The ASD's Overall Stance: "Assume Compromise" The ASD's language is deliberate: boards should stop assuming a breach will take days to unfold, and stop assuming their organisation is "too small to be a target." Agentic AI can automate the discovery and exploitation of exposed systems, which means the old comfort of obscurity (nobody's coming for a 40-person business in regional Queensland) no longer holds. The ASD's overall stance can be summarised in two words: Assume Compromise. We see what "assume compromise" looks like in practice every day. In one Huntress SOC investigation, an attacker logged into a company's VPN using stolen but valid credentials. Huntress SIEM dashboard showing successful authentication events from threat actor's IP. Read more about the incident here. The login itself looked routine. What gave the attacker away was something else: a failed login attempt on a different system, one minute earlier, from an account that had no business being there. On its own, that failed attempt meant little. Because the company's logs were being collected and reviewed together, the SOC could connect the two events, recognise an intrusion in progress and help contain it before the attacker got further. The same principle applies once an attack is underway. In one anonymised ransomware investigation, Huntress analysts used newly created file extensions, ransom-note files and timestamps to distinguish active encryption from older artefacts. When the evidence indicated a credible, active threat across multiple hosts, the response process supported containment at both the host and identity levels. This stopped the spread while analysts validated the evidence and determined the next action. The Huntress SOC may need to contain an entire organisation when a misconfigured VPN or firewall, or a threat actor using valid credentials, creates an active path into the environment. In some incidents, compromised remote monitoring and management (RMM) software has required isolation at the account level to protect every business supported by the affected service. These actions are not a substitute for human judgement. They create the time and control needed for analysts to validate the threat, confirm its scope, remediate the third-party service and decide when containment can safely be relaxed, without waiting for a complete forensic picture. Consequently, the ASD is urging boards to shift their focus from mere prevention to resilience and rapid response. It's no longer just about having a firewall; it's about having deep visibility, continuous event logging and 24/7 threat detection to catch an attacker the moment they slip through the cracks. Questions Directors Should Be Asking Here's the part of the ASD guidance that gets lost in most of the commentary around it: the agency isn't telling boards to fight AI with more AI. It's telling boards their AI defences need to be human-supervised. That distinction matters. As an executive or board member, the ASD wants you to be asking your IT and security teams hard, threshold governance questions: Is our risk assessment current? If an AI-assisted attack can reduce the time between discovery and exploitation, do our detection, escalation and containment objectives still reflect the risk? What exercise or incident evidence supports that answer? Who is watching the logs? The ASD has highlighted the requirement. Do we have an enterprise-wide approach to event logging, with defined coverage, retention and ownership? Who reviews the signals, and what happens when an anomaly is not resolved promptly? Where are our supply-chain blind spots? Do we understand the security posture and access of critical suppliers, MSPs, SaaS providers and AI providers? Which dependencies would matter most during an incident? Your reliance on a given AI provider is a cyber supply chain risk in the same category as any other vendor, and it deserves the same scrutiny. Are our identities secure? Are privileged and high-risk accounts protected with phishing-resistant MFA where appropriate? Are suspicious logins, mailbox rules, token use and privilege changes monitored and investigated? Can we identify an AI-accelerated social engineering before fraudulent transactions occur? What is our actual legacy-IT exposure? Which unsupported systems, edge devices or inherited exceptions remain connected? Who owns each risk, what compensating control exists and when will the exposure be removed? None of these questions requires a seven-figure security operation to answer. They do require reliable visibility, clear ownership and someone qualified to review what is happening in the environment. They are also a test of whether the organisation has done enough to reduce the likelihood and impact of compromise, manage the remaining risk and protect its ability to operate. That is the governance gap many organisations are trying to close with limited resources. "Assume compromise" does not mean accepting failure as inevitable. It means being able to answer what happens when prevention fails. If an incident began tomorrow, how confident are we that we could detect it, contain it, make sound decisions and communicate openly with the people affected? That confidence should come from exercises, incident evidence, control testing and supplier assurance, not from the existence of policies or the purchase of tools. The objective is not to predict exactly when an incident will occur. It is to be prepared for when it does, and to know that the organisation can manage the incident professionally, transparently and with clear accountability. A Word from SOC Leadership The SOC is seeing two pressures at once. Attackers can move through an environment quickly, while the volume of telemetry and alerting grows beyond what a human team can inspect one event at a time. The practical question is not whether every signal needs a human decision. It is whether the organisation can identify the signals that matter, resolve routine activity safely and keep experienced analysts available for active intrusions. Scale matters. Across endpoint, identity and SIEM investigations, the Huntress SOC handles a volume of signals that cannot be reviewed manually one event at a time. Automation absorbs repeatable investigation work, while analysts focus on ambiguity, novel tradecraft and active threats. This is how the SOC does more with less without removing human judgement from consequential decisions. The division of labour is explicit. AI and automation begin the investigation, gather relevant context and follow established investigative paths. Analysts review the results, resolve uncertainty and take responsibility for decisions that affect containment, customers and operations. The value is not that automation replaces analysts. It is that analysts can spend more time where judgement changes the outcome. Hands-on-keyboard activity is where that judgement matters most. Attackers can move through an environment quickly, so the SOC must recognise behaviour across hosts, identities and logs before the next stage of the attack. From the time the SOC identifies a key detection or is made aware of a relevant signal, analysts can assess the situation and, where warranted, isolate a host or mass-isolate affected systems in less than 60 seconds. That response includes a human-in-the-loop assessment. The objective is not to promise a universal response time. It is to show that machine-speed action can remain subject to informed human judgement. Containment also has to scale. Huntress response guidance identifies active ransomware, pre-ransomware behaviour, persistent threat-actor access across multiple hosts and VPN or network-appliance access as situations that may justify mass isolation when there is a credible hypothesis. In practice, the SOC may need to isolate a large number of hosts or accounts to interrupt an active attack and protect connected businesses. Those decisions are proportionate to the evidence available and remain subject to analyst review. Containment cannot be designed only for a single laptop. That is what the SOC is using AI for. Athena and other automation gather relevant telemetry, correlate activity, follow established investigative paths and surface the cases that need expert attention. Analysts provide the judgement layer: they validate the evidence, identify tradecraft the workflow does not fully support, decide whether containment is proportionate and feed the result back into detections and AI workflows. The machine can move at machine speed. The human remains responsible for the calls that carry operational, customer or reputational consequences. The ASD is right to call out "frontier AI," but we need to cut through the hype. AI can make attackers faster by automating vulnerability discovery and producing highly tailored phishing at scale. The post-compromise behaviours, establishing persistence, stealing credentials and moving laterally still require defenders to understand context and intent and haven't fundamentally changed. The ASD mentions that organisations should adopt AI for cyber defence, but importantly notes it must be "human-supervised." We see this every day in the SOC. AI and automation are great for correlating logs and bubbling up anomalies, but it takes a human threat hunter to understand the context, confirm the malicious intent and isolate the endpoint before the ransomware detonates in evolving threat chains. If you rely solely on AI to fight AI, you will miss the contextual indicators for complex attacks. The combination of high-fidelity telemetry and human intuition is the only way to effectively counter the speed of modern threats. Most people would hesitate to board a commercial aircraft without a pilot, even when its autopilot is fully capable of flying it. Yet organisations are often more willing to rely on automated systems to protect their operations, people and customers without equivalent human oversight. The Bottom Line for Australian Boards The 2025-26 ASD guidance is a wake-up call for the APAC region. The barriers for threat actors have never been lower, but the standard for boardroom governance has never been higher. ASD is right that the timeline has changed. Where the broader industry reaction risks going wrong is treating that as a reason to buy a faster automated defence and call the problem solved. The new standard is achievable for organisations of any size, provided visibility and human judgement, not just tooling, are treated as the priority. That is the model Huntress describes through its agentic security platform: unifying visibility across endpoints, identities and logs so nothing sits in a blind spot waiting to be found, backed by a 24/7 AI-centric SOC where AI accelerates investigation but a person still makes the call. Huntress describes AI as a force multiplier for gathering telemetry, correlating activity, summarising evidence and building investigation timelines, while human analysts interpret context, make risk-aware decisions and handle novel attacker tradecraft. The Huntress SOC applies the same principle operationally. When a key detection or signal is received, analysts can move from assessment to host isolation or mass isolation in under 60 seconds when the evidence supports that action. The speed comes from prepared workflows and automation. The decision remains human-led. That combination gives organisations a way to manage an active incident before a complete forensic picture is available, while preserving accountability for why containment was applied and when it can be relaxed. For boards, the question is not whether to choose humans or automation. It is whether management can show that both are working together: that the organisation can see what matters, act quickly enough to limit harm, and explain its decisions professionally and openly when prevention fails. If your board is asking these questions of its own environment, that is a conversation worth having sooner rather than later.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.