IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Cybersecurity finds problems. AI can accelerate remediation

Cybersecurity finds problems. AI can accelerate remediation

Thu, 24th Sep 2026 (Today)
Scott Magill
SCOTT MAGILL

AI can help organisations prioritise vulnerabilities, accelerate remediation and close the gap between finding cyber exposures and fixing them.

Cybersecurity has become very good at finding problems. There are more than 300,000 known vulnerabilities on record today, and the industry logged over 45,000 new ones in just the first seven months of this year, already on pace to more than double last year's record total. Most large Australian organisations have no shortage of security data either. Their teams can identify vulnerabilities, misconfigurations, excessive permissions, exposed assets and weaknesses across cloud environments, identities, applications and operational technology. Finding issues is no longer the constraint.

Being able to take that insight and determine which vulnerabilities could hurt the business is the real challenge. With so many active cyber threats facing organisations today, which ones deserve attention first? Who needs to fix them, and how quickly can that happen? Those are the questions I hear from security leaders in Australia far more often than anything about coverage or detection, and the numbers explain why: the gap between a vulnerability becoming known and someone exploiting it has gone from roughly 771 days in 2021 to under two days now, while the average organisation still takes somewhere between 30 and 40 days to patch. 

This "decision gap" - the time it takes to make an informed decision, prioritise with business-critical context and remediate - is what matters, not the length of the vulnerability list. Visibility offers little value to an organisation that cannot translate insights into actionable decisions. As the above numbers show, most security teams are already past that threshold.

How can AI become a partner in cyber response and remediation? 

In a very short period of time, AI has metamorphosed from a perceived threat to job security into a potential solution to the problem of insufficient reaction time and resource depth. That matters because a vulnerability almost never exists in isolation. A flaw on an obscure system with limited access and little connection to anything important carries a different level of risk than a less severe flaw sitting on an internet-facing system, tied to an identity with excessive permissions and a viable path to sensitive data. A long list of vulnerabilities tells you both exist, but only the path between them tells you which one to fix today.

With exposures now being surfaced at machine speed, organisations will also have to remediate as quickly, while budgets and resources remain constrained. In fact, most organisations are expected to do more with less. This is not a cybersecurity or IT problem alone, but one to be addressed collectively as an organisation. Efficiency becomes an imperative, not an option – and AI has a key role to play in helping organisations achieve it. This doesn't mean replacing security teams.  

Security teams understand their organisations in ways no model can automatically infer: which systems keep the business running, where the sensitive information actually sits, what a customer-facing outage would cost. AI becomes genuinely useful once that organisational knowledge is combined with the technical detail security teams already collect. It becomes even more useful once it starts closing the gap between finding a problem and fixing it - recommending a response and helping coordinate the parts of remediation that currently eat up the most time for IT teams.

Australia is a reasonable place to make this argument. Seventy-one per cent of Australian organisations reported a cyber incident in the past year, and cybercrime reports now reveal that roughly one cyberattack occurs on local organisations every six minutes, so the operating environment isn't short of urgency. What's changed is the policy response. The Australian Signals Directorate is retiring the Essential Eight, the checklist organisations have used to benchmark security maturity for over a decade, and replacing it with a new Essentials series built around outcomes rather than fixed controls. 

The Prime Minister has also flagged a mandatory national AI framework, with legislation expected in Parliament early next year, building on the National AI Plan's goal of capturing AI's benefits without losing track of the risk. Australian policy is already asking the same question exposure management is built to answer: do you actually know where you're exposed, right now?

However, we should be cautious, of anyone claiming AI on its own fixes an under-resourced security function. If anything, when done well, it should free experienced people to spend more time on the judgement calls that actually need a person, instead of working through another queue of alerts that could be triaged automatically.

Security teams already know how to find problems. Give IT, OT and cloud teams the context behind the prioritisation or – better yet, pair machine-speed exposure discovery with machine-speed remediation – and you reclaim the advantage.