Australian firms lag on AI cyber risk understanding
Thu, 24th Sep 2026 (Today)
Only 20% of Australian organisations have a detailed understanding of AI cyber risks, according to Herbert Smith Freehills Kramer's latest survey of legal leaders across corporate Australia.
AI-related cyber security risks are now among the top three areas of cyber investment for Australian organisations, even though only a small minority of respondents reported a detailed grasp of the threat landscape.
Now in its fourth year, the Cyber Risk Survey draws on responses from General Counsel and equivalent legal leaders across sectors including consumer services, financial services, resources, health and energy. It examines how organisations perceive cyber threats, prepare for them and respond when incidents occur.
Cameron Whittfield, Partner at Herbert Smith Freehills Kramer, said the gap between awareness and preparedness is becoming more pronounced as organisations adopt AI tools more widely.
"As AI adoption accelerates, including with the rapid advancement of frontier AI models, legal leaders are increasingly being asked to navigate a new generation of cyber threats. The challenge is no longer awareness, it is ensuring organisations have the governance, controls and response capabilities needed to keep pace with a rapidly evolving threat environment," Whittfield said.
People risk
The survey identified people-related risk as the third most-cited cyber concern among respondents. That category includes insider threats, key person dependencies and broader cultural factors within organisations.
Yet it did not appear in the top three investment priorities or the top three pain points in cyber resilience programs. This suggests many organisations recognise the exposure but have not matched that concern with spending or operational attention.
Legal leaders are confronting that issue as AI makes phishing attempts and impersonation attacks harder to detect. The survey pointed to growing concern over social engineering, including deepfake-enabled impersonation.
"As AI lowers the barrier to realistic phishing and deepfake-enabled impersonation, the human element is becoming more, not less, critical to organisational resilience," Whittfield said.
"Organisations that treat people risk as a standing investment priority, including through effective training, and understand that the drivers of this risk are distributed across the organisation, will be materially better positioned to withstand the threats that are already at their door. The most mature organisations will also factor the human element into their board cyber risk reporting," he said.
Board oversight
The findings also showed a rise in reported board-level cyber maturity. Almost 70% of respondents rated their board's cyber maturity as high or very high, up from 55% a year earlier.
At the same time, 90% said their board had a clear understanding of cyber risk, compared with 68% in the previous survey. Boards have been reviewing their cyber governance arrangements in the wake of the Star Decision and testing whether current oversight frameworks meet changing expectations for directors.
That increase in awareness has not fully translated into practical readiness. According to the survey, only half of respondent boards took part in a cyber simulation during the previous 12 months.
Carolyn Pugsley, Partner at Herbert Smith Freehills Kramer, said stronger board understanding still needs to be matched by more structured preparation.
"Equally, as the complexity and velocity of cyber incidents increase, there is a growing need for structured decision-making frameworks at a board level to enable directors to make informed, timely decisions during a crisis rather than relying on ad hoc processes under pressure," Pugsley said.
Supply chain
Supply chain risk remained the most frequently cited concern in the survey. Nearly two-thirds of respondents, or 62%, said their organisation had been affected by a third-party cyber incident during the previous 12 months.
The biggest obstacle in managing that exposure was limited visibility beyond direct suppliers. Seven in 10 respondents identified fourth-party risk, meaning a lack of insight into suppliers' own supply chains, as their main challenge in managing third-party risk.
Another 62% pointed to a lack of transparency and over-reliance on supplier questionnaires. Almost 40% said they struggled to secure suitable contractual rights, while 30% cited resourcing constraints that limited the use of existing rights.
A further 26% said they had difficulty moving away from suppliers, indicating that operational dependence remains a barrier even where risks are known. These findings suggest many organisations still face practical and governance limits in reshaping supplier relationships after an incident or when warning signs emerge.
Whittfield said the underlying issue extends beyond technical controls.
"These challenges reinforce a structural problem: organisations remain heavily dependent on counterparties whose cooperation cannot be guaranteed in a crisis, and whose own supply chains remain largely opaque," he said.
"Until that information asymmetry is addressed, third-party risk will remain as much a governance challenge as a technical one."