IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Seven Cyber Controls Businesses Can No Longer Afford to Overlook

Seven Cyber Controls Businesses Can No Longer Afford to Overlook

Thu, 8th Oct 2026 (Today)
Matthew Lowe
MATTHEW LOWE Regional Director – Pacific Anomali

The latest wave of cyber breaches is exposing a gap between the security measures businesses buy and the protection they actually deliver. For Australian executives, the challenge is increasingly one of execution and ensuring controls work together, cover emerging risks, and support recovery when prevention fails.

Threat research recorded 799 confirmed ransomware attacks globally in July 2026, up 19% on June, with financial services experiencing a 71% increase. Incidents of infected software packages illustrate how weaknesses in infrastructure, supply chains and identity management can compound.

The speed mismatch is troublingly stark. Global median attacker dwell time reached 14 days in 2025, while intruders can move between systems within 30 minutes of gaining access. Businesses need to close that detection gap while strengthening a range of practical areas of defence.

The top seven controls that can be put in place are:

Control 1: Identity and recovery

The first control is authentication that resists phishing. Multi-factor authentication (MFA) is widely deployed, but its presence does not guarantee protection. Attackers can intercept codes or trick employees into authorising access through fraudulent websites and convincing telephone calls.

Separate industry research found 67% of organisations experienced a successful account takeover in 2025. Of the compromised accounts, 59% had multi-factor authentication enabled. Passkeys and FIDO2 hardware tokens offer businesses a stronger foundation than reliance on text messages or temporary codes.

Control 2: ITDR

The second priority is identity threat detection and response. Criminals increasingly operate with legitimate credentials, remote management software, and standard system utilities, reducing their dependence on malicious software that traditional antivirus products recognise.

With an increasing number of detections classified as malware-free, security teams need visibility into authentication behaviour. Unusual logins, stolen access tokens, and unexpected increases in user privileges can provide warning signs that signature-based controls miss.

Control 3: Ability to recover

Organisations must also protect their ability to recover as ransomware operators target backup systems and the infrastructure required to restore operations, increasing pressure on victims to pay.

Backups should be isolated from production environments and protected against alteration or deletion. Executives also need evidence that restoration works within acceptable business timeframes. A completed recovery exercise provides far more assurance than confirmation that backup jobs ran successfully.

Control 4: Addressing the AI challenge

This control addresses artificial intelligence applications. Employees are adopting tools outside formal approval processes, creating opportunities for sensitive information to leave corporate environments and for valuable AI credentials to be exposed.

An application inventory should establish which services are used, who uses them, and what information they receive. Data loss prevention controls and clear rules governing prompts can then restrict the transfer of confidential material. Policies must translate into controls employees can understand and security teams can enforce.

Control 5: Access governance

Another important control is maintaining continual oversight of supplier access. Shared platforms and external service providers can create exposure across multiple organisations, yet access reviews often concentrate on initial onboarding.

Businesses need to monitor vendor permissions throughout the relationship, specify breach notification obligations, and revoke accounts and tokens when engagements end. Outsourcing a service does not remove management responsibility for the resulting risk.

Control 6: Continuous vulnerability management

The sixth control is continuous vulnerability management, particularly for internet-facing and edge devices. These systems can become persistent footholds when they sit outside routine monitoring.

Research put median dwell time for cyber espionage actors at 122 days in 2025. That makes periodic patching an inadequate response where actively exploited weaknesses demand urgent action. Organisations should maintain an accurate asset inventory, scan continuously and set remediation deadlines according to exposure and known exploitation.

Control 7: Turning capability into protection

The seventh priority is AI-assisted detection engineering. Automated triage, rule development, and detection tuning can help security teams handle growing workloads, provided experienced staff validate the results.

Recruitment alone is unlikely to solve the capacity problem as workforce research found 55% of senior appointments took at least six months to fill. Meanwhile, only 38% of organisations provided comprehensive AI security training, although 54% reported having governance policies.

That disparity explains why controls can exist on paper without delivering operational protection. Multiple security products add further complexity when teams lack the expertise to integrate and tune them.

Responsibility must also be clear across technology, security and business teams. Each control needs an accountable owner, measurable performance expectations and regular review, so gaps are identified before they become potentially costly operational failures.

For management, sequencing matters. Stronger authentication and protected, tested backups provide practical starting points. Identity monitoring and continuous vulnerability management should follow, alongside tighter oversight of AI applications and supplier access.

Investment in effective automated detection requires sustained attention, training, and accountability. Boards should ask for evidence of coverage and recovery performance, rather than product inventories or policy counts.

The commercial objective is clear: reduce the likelihood of disruption and restore operations quickly when an attacker gets through.