AI in Cyber Security: What Australian Organisations Need to Know
Five Eyes has issued a blunt, stark warning to Australian organisations: integrate AI into your cyber security controls, or be a sitting duck for attackers already using it. This isn’t more of the “use AI or fall behind” performative urgency you see on LinkedIn. It’s a rare joint statement from a coalition of national intelligence agencies – Australia, UK, USA, Canada and New Zealand.
So, why now? After all, the use of AI in cyber security goes back to the 1980s. Dorothy Denning’s “An Intrusion Detection Model“, published in 1987, is often cited as the first application of AI in cyber defence.
But AI in cyber security has evolved with the technology around it. And now, we’re at a dangerous inflection point. The rapid advancement of AI tools since 2019 has already compressed the window between vulnerability discovery and exploitation. According to the SANS Institute, mean time-to-exploit has fallen from 2.3 years in 2019 to less than one day in 2026. With the emergence of 2026 frontier AI tools (like Anthropic’s Mythos), that window will shut completely – as discovery and exploitation become the same event.
That’s what’s at stake. It’s a structural shift in cyber risk that no organisation can ignore. But how should you take action?
This article will unpack what the Five Eyes expect of Australian organisations, and what a strong cyber security posture looks like in the AI era.
Cyber security’s AI-first future is now
"AI is not a future consideration – it is already here."
Five Eyes, in "The AI shift in cyber risk: why leaders must act now"
The Five Eyes statement says what cyber security teams already know: AI is already making a massive impact on adversarial capability.
Cyber criminals have been using AI to scale their efforts. From personalised phishing campaigns that are harder to discern from legitimate communications to automation handling more parts of the attack lifecycle. Cyber security researchers have already identified attacks that were handled end-to-end by agentic AI.
Finally, AI is also having an impact on the raw volume of threats. According to IDC and Fortinet’s 2025 State of Cybersecurity in Asia-Pacific report, nearly 51% of organisations across Australia say they have encountered AI-powered cyber threats in the past year. Of those, 76% reported a 2x increase and 16% reported a 3x increase in threat volume. Fortinet’s global 2026 threat report shows a significant increase in known exploitation attempts, up 25% from 97 billion in 2024 to nearly 122 billion in 2025.
That’s the background, now for the million-token question: What does Five Eyes expect from your organisation’s cyber security controls?
What the Five Eyes call to action on AI in cyber security means for Australian organisations
The Five Eyes statement offers practical guidance for Australian organisations to ensure their defences are prepared for the AI threats. They are:
Reduce your attack surface. The smaller the building, the fewer ways in there are. That rings true for your attack surface. Audit your systems, their public-facing exposure and who has access to them, and limit the unnecessary instances. Your aim here should be to strike an effective balance between exposure and organisational efficiency. Even the most secure organisations find a reduction here. When every exposure point is another way into your organisation’s systems, and AI rolls out the red carpet, that reduction is critical.
Faster patch management. With AI closing the discovery-to-exploitation window, unpatched systems pose a greater risk than ever. To manage your AI-enhanced cyber risk, you need to rapidly increase your patching cadence.
Address legacy systems. Old, unsupported systems are easy targets. Don’t let inertia (or plain old ignorance) multiply your risk. Review your legacy systems to ensure they meet the security standards of a system you’d approve of today. If a legacy system can’t be patched like new systems can, limit its access points.
Review and strengthen Identity and access controls. Apply the principle of least privilege by limiting who can access your systems. At the same time, strengthen the authentication requirements for that access. Combine this with identity governance that keeps those controls current by mandating regular reviews of access permissions across your organisation.
Prepare for incidents before they happen. This is the “assume compromise” approach that the ASD has been encouraging for some time now. In simple terms, it means preparing your security controls with the goal of minimising the damage should a cyber incident occur, over and above the preventative controls that form the cornerstone of traditional security postures.
None of these recommendations should shock you. If they do, cyber criminals won’t need AI to breach your organisation.
These the fundamentals you should be doing already – just optimised for a new threat landscape.
Work smarter, not faster
When confronted with the speed of AI threats, your instinct will probably be “we need to move faster”. That’s important, yes. Faster patching, faster detection and faster response all move the needle before adversaries can find it. But chasing speed alone is a race toward zero that no organisation can ever win. What does work when a control fails is your depth of defence. That means layering your security controls that ensure one failure doesn’t lead to a full-scale breach. For example, layering network segmentation across your environment means it can take over when patching fails – so that a missed patch window becomes a contained incident, not a network-wide breach. No longer a luxury for organisations with bigger security budgets, layering is essential to cyber resilience in an AI-era threat landscape.
Depth also shows up in resourcing. If your security team’s already under the pump, augmenting their efforts with AI isn’t enough. Neither is adding AI to security controls that otherwise haven’t been looked at in the context of an AI-first threat landscape. Without the fundamentals in place, any cost or speed gains AI brings will be offset by genuine risk.
In summary: AI in cyber security only adds value if it augments a fit-for-purpose foundation. Get the fundamentals right and increase your depth of defence, then layer AI on top of those controls. That’s your playbook for implementing a cyber security posture that can defend against today’s AI-first adversaries.
But what does an AI-ready security posture look like? What should your increased “depth of controls” cover? These are the key strategic and operational shifts you need to make to ensure security posture is AI-ready.
From vulnerability management to exposure management
Vulnerability management is a time-tested approach to maintaining your cyber security at scale. And it’s one the Five Eyes specifically called out as a core defence against the AI threat. But vulnerability management alone isn’t enough anymore. Well, it never really was, but AI efficiencies are turning complex attack vectors from mathematical possibilities into low-hanging fruits.
Traditional vulnerability management, which aims to identify and close Common Vulnerabilities and Exposures (CVEs) is reactive and patch-centric. That’s still important, especially in today’s landscape where attackers can instantly exploit an unpatched vulnerability. But when AI makes exploitation cheap, it can’t be the entire job. AI-assisted attackers aren’t just waiting to find CVEs. They’re probing for whatever exposure they can find. A misconfigured cloud storage, an internet-facing admin panel nobody remembered was live, an identity with more access than its role needs, a forgotten subdomain. These are all ways an attacker can gain unauthorised access to your environment. They’re also things that probably won’t show up in a vulnerability scan that runs monthly and only checks against known CVEs.
This is why cyber security teams should expand their vulnerability management programs towards exposure management. Exposure management is continuous, asset-aware and covers your entire environment. When done right, it allows your organisation to truly understand where you’re exposed in the detail today’s threat landscape demands.
Is exposure management just vulnerability management rebranded? In a way, yes. They have the same aim – identify and close gaps before attackers exploit them. But exposure management takes vulnerability management to the modern era. Traditional vulnerability management asks “what vulnerabilities are out there that we need to patch?”. Exposure management also asks “What could an attacker reach?” Until recently, that question was mostly theoretical. But now, when the average cyber criminal has capabilities that would have seemed like science fiction only a few years ago, it’s a fundamental question. Boards and execs alike need to understand that it’s about exposure, not just a numbers game you can solve with patching.
Data labelling and classification: knowing what AI (and attackers) can actually reach
Your AI-enhanced cyber security exposure isn’t only external. The moment you deploy an AI tool internally, such as a copilot-style assistant, an internal chatbot or an automation agent, it inherits whatever access the underlying data has.
Most organisations don’t actually know where their sensitive data lives or how it’s labelled, which means they don’t know what their own AI tools can see either.
Trusted employees with a little more access than they need are functionally harmless. An adversary that’s got their hands on that access, and actively seeks out sensitive data through AI-assisted reconnaissance, makes it a serious problem.
Building an AI-era cyber security stack
The fundamentals, implemented with more rigour and managed with more discipline, are what stops AI-enabled cyber threats.
That said, Five Eyes makes it clear that if cyber criminals are using AI as an offensive weapon, your cyber defences need to respond in kind.
AI brings a great many benefits to cyber security teams, from sharper threat intelligence and more accurate exposure prioritisation to speeding up alert triage, threat detection and remediation. No human team can match AI’s efficiency and scale.
"Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents – reducing both the cost and impact of incidents."
Five Eyes
Five Eyes made that statement they did because most enterprise cyber security postures are ill-equipped to stop contemporary AI-enhanced adversaries. This is true even when you add AI to the mix. Like any discipline, AI’s impact is constrained by the capabilities and controls it’s working with. Put simply, AI can help you narrow the goalposts, and perhaps even move them. But the only way to stop an adversary from eventually getting through is to add more lines of defence between them and the goals.
So, before you integrate AI tools into the way your cyber security team works, ensure the capabilities those tools will augment are the right ones – and all of them.
Use AI to strengthen your cyber defence
Integrating AI into your cyber security controls isn’t something you have to do alone.
AI is built into the core of how we operate. Developed in-house, our AI-enhanced cyber defence boosts our MDR and Active Defence services – without compromising trust or control. This enables enabling faster, more informed decisions – meaning a more secure organisation that can withstand AI-era cyber threats.
Where you want an independent view of your exposure, identity posture, or data classification baseline, we can run that assessment for you, benchmarked against the concentric-controls you need to withstand AI-era threats. You’ll get a concrete list of the controls to implement or uplift, and a prioritisation roadmap to help you confidently sequence and maximise the value of your security investments.
To find out more about how we’re keeping pace with AI threats across our Managed Cyber Security and Cyber Risk Consulting services, get in touch with our team.
Frequently Asked Questions
What is AI in cyber security?
AI in cyber security is the use of AI tools (such as generative AI, automation, machine learning and related technologies) to detect, prevent and respond to cyber threats. It is also a response to attackers using AI to augment their efforts in gaining, and exploiting, unauthorised access to systems.
What are the benefits of using AI in cyber security?
Used well, AI has several cyber security benefits. Firstly, it can analyse large volumes of data that no human could realistically review – which allows for faster threat detection and anomaly monitoring. AI also enables quicker alert triage sharper threat intelligence correlation across a wider set of sources. These efficiencies mean cyber security teams aren’t dealing with false positives and information overwhelm. Overall, the automation and augmentation made possible by defensive AI allows cyber security to quickly and easily assess threats and take the appropriate action.
How is AI changing cyber security?
AI has created many efficiencies for cyber security teams. At the same time, attackers are using these same efficiencies to their advantage. With attackers using AI to move faster, cyber security teams have an imperative to keep up. That’s why Five Eyes’ 2026 call to action pushed for AI adoption alongside stronger fundamentals, not instead of them.
How do you incorporate AI into cyber security?
Start with the fundamentals Five Eyes identified. Reduce your attack surface, tighten patch management, retire legacy systems, strengthen identity and access controls and prepare incident response plans before you need them. Once you’ve done the necessary security uplift, you can then layer AI on top your cyber security controls to maximise their impact. Remember: AI can only amplify what already exists – it’s not a replacement for weak controls.
What is exposure management?
Exposure management is continuous process of monitoring your organisation’s environment to identify, and address, areas where you’re exposed. The goal of exposure management is to identify everything an attacker could potentially reach across your organisation. It involves monitoring for misconfigurations, exposed or forgotten assets and identities with more access than they need, alongside traditional CVE patching.
How is exposure management different from vulnerability management?
Exposure management expands on vulnerability management. Vulnerability management focuses on patching known vulnerabilities (CVEs), and is reactive and patch-centric by nature, built around scanning for documented flaws on a schedule. Exposure management is a broader, proactive approach to managing security vulnerabilities across your entire environment, and every asset in it.
More Insights