IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Why cyber resilience is an identity challenge

Why cyber resilience is an identity challenge

Wed, 12th Aug 2026 (Today)
Mathew Graham
MATHEW GRAHAM Chief Security Officer Okta

Over the past few months, cyber security authorities have delivered a consistent message.

The Five Eyes agencies have called on leaders to prepare for the changing cyber risk landscape created by artificial intelligence. The Australian Signals Directorate (ASD) has strengthened its guidance around secure software development and AI-enabled systems through updates to the Information Security Manual (ISM). The Australian Cyber Security Centre (ACSC) has released guidance on the careful adoption of agentic AI services.

Most recently, ASD announced plans to transition beyond the Essential Eight framework towards a broader "Essentials" series covering enterprise IT, cloud, operational technology and potentially agentic AI.

While each initiative addresses a different aspect of cyber security, they all point to the same underlying challenge:

Who, or what, is authorised to do what inside an organisation?

Cyber resilience previously focused on protecting systems from compromise. There is no doubt that remains critical, but the environments organisations are securing today look very different from those of even a few years ago.

Applications communicate directly with other applications. Machine identities authenticate and exchange information across systems. Automated processes execute business workflows without human intervention. AI-powered systems are increasingly interacting with sensitive information and making decisions that influence business outcomes.

The number of identities operating inside organisations is growing rapidly, and many of them are no longer human. Okta's Businesses at Work research found that in some enterprise environments, non-human identities already outnumber human identities by as much as 45 to 1.

This shift changes how organisations need to think about cyber resilience.

Historically, security teams focused on users, devices and networks. Increasingly, they also need visibility into a growing ecosystem of applications, services, machine identities and AI-powered systems operating across their environment.

That raises a new set of governance questions.

  • Do we know what identities exist in our environment?
  • What systems, applications and data can they access?
  • Why was that access granted?
  • Who is accountable for it?
  • And can it be modified or removed when circumstances change?

These are no longer purely technical questions.

They are governance questions.

The recent Five Eyes guidance highlights the importance of strengthening identity and access controls as AI increases the speed and sophistication of cyber threats. The ACSC's guidance on agentic AI emphasises ownership, accountability and oversight before autonomous systems are deployed at scale. The ASD's latest ISM updates reinforce the importance of building security into systems from the outset rather than attempting to address risk later.

Together, they reflect a broader shift underway across the industry. Cyber resilience is now less about managing individual technologies and more about governing access across increasingly complex environments.

Identity sits at the centre of that challenge.

Identity provides the context organisations need to understand who, or what, is operating within their environment, what resources they can access and what actions they are authorised to perform. It creates accountability across both human and non-human identities and provides a foundation for governance as environments continue to evolve.

This isn't about slowing innovation. AI, automation and machine-driven processes will continue to create significant opportunities for organisations. The challenge is ensuring governance evolves alongside the technology.

As organisations adopt more AI-powered systems, applications and automation, cyber resilience will increasingly be measured by their ability to maintain visibility, accountability and control across a growing mix of human and non-human identities.

That's the common thread running through the latest guidance from the Five Eyes agencies, ASD and ACSC and I expect it to become one of the defining cyber security challenges for the years ahead.