IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
ANZ SMEs back AI in cyber security, but trust lags

ANZ SMEs back AI in cyber security, but trust lags

Wed, 29th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Arctic Wolf has released research showing a gap between AI adoption and trust among small and midsize businesses in Australia and New Zealand, where AI use is now almost universal.

Its 2026 AI & Cybersecurity Trends Report found that 95% of ANZ SMEs already use AI or large language models, while 98% have adopted or plan to adopt the technology. Another 69% expect AI to shape their cybersecurity strategy over the next 12 months.

That uptake has not translated into confidence in handing security decisions to software. While 80% of respondents said AI would improve the detection of new or sophisticated threats, 60% did not expect it to reduce alert volumes.

Concerns remain centred on privacy, accuracy and oversight. Almost a third of ANZ SMEs, 31%, identified AI and agentic models as a leading cybersecurity concern because of worries about sensitive data, the lack of human judgment and the reliability of automated outputs.

The report also pointed to a heavy operational burden. More than 70% of SMEs in Australia and New Zealand said they had experienced a significant cybersecurity incident, with many reporting productivity losses of up to three weeks.

According to the survey, those figures place the region second globally for significant cyber incidents. At the same time, only 23% of ANZ SMEs said they use an external partner for round-the-clock security monitoring and response.

That leaves many businesses managing rising cyber risk largely on their own. The findings suggest that many smaller firms are introducing AI into security operations while teams remain stretched and incidents continue to disrupt day-to-day work.

Trust questions

Based on responses from 1,350 security and IT decision-makers globally, the survey presents ANZ as a market where compliance maturity sits alongside operational strain. Australia ranked first globally for cybersecurity compliance and regulatory alignment, yet businesses in the region still reported high levels of disruption from cyber attacks and other incidents.

That contrast adds to the debate over what AI can realistically solve inside security teams. Many respondents appear to see value in using AI to improve threat visibility, but fewer believe it will ease alert volumes or remove the need for human review.

David Hayes, Regional Director, ANZ, Arctic Wolf, said the market conversation had shifted from basic adoption to questions of practical use and control.

"For SMEs across ANZ, the AI conversation has moved quickly from whether to adopt it to which capabilities they need, what they can afford and how they can deploy them securely. As frontier models become more accessible and AI is embedded across business and security platforms, organisations are having to balance the potential benefits against rising technology costs, data risks and legitimate questions about accuracy and autonomous decision-making. The findings show that SMEs see real value in AI as a defensive tool, but they are not treating it as a silver bullet and nor should they. In a region already experiencing high levels of cyber disruption, the answer cannot be choosing between human-led and AI-led security. ANZ SMEs need AI to give stretched teams greater speed and visibility, while people continue to provide the judgment, context and accountability needed to use that capability safely," said Hayes.

Global picture

Beyond Australia and New Zealand, the report found similar tensions in other markets. Globally, 35% of leaders surveyed said AI was their top cybersecurity risk, ahead of ransomware and malware for the second year in a row.

Confidence was also high, even as incidents remained widespread. The report found that 96% of leaders were confident in their team's ability to manage modern threats, yet 63% said they had still experienced a significant cybersecurity incident in the past year.

Most respondents also expected AI to improve security outcomes. The survey found that 85% believed AI would improve their ability to detect new or elusive threats, and 72% said it was more capable than humans at identifying threats.

Even so, security work continues to consume large amounts of staff time. Respondents reported spending about 13 to 15 hours each week on major security functions such as reducing false positives, managing tools and meeting compliance requirements.

Arctic Wolf said that workload reflects the pressure on modern security teams and the demand for more automation. The findings indicate, however, that many businesses are not yet prepared to rely on AI without clear human involvement in decision-making and accountability.

Adam Marrè, Chief Information Security Officer, Arctic Wolf, said: "Organisations have already decided that AI will play a central role in cybersecurity. The challenge now is trust. Security leaders want the speed, scale, and efficiency AI can deliver, but they also need confidence that the outcomes are trustworthy, explainable, and aligned to their business. The future of security operations will belong to organisations that combine trusted AI with human expertise to move faster, make better decisions, and build greater resilience."