top of page

Five cyber security trends shaping Australia's defence industry

Writer: De Stefano & Co
De Stefano & Co
Sep 1
3 min read

In today’s complex business landscape, Australian cyber security is so much more than an IT responsibility.


Cyber threats have continued to become more sophisticated, and as a result, Defence is strengthening its security expectations.


Businesses operating in the Defence supply chain not only need to understand the new threats, but also need to be clear on the latest requirements for defence industry cyber security compliance.


Here are the 5 latest cyber security trends to watch out for:


  1. AI-powered threats


IBM’s 2026 Cost of a Data Breach Report reports that AI-driven attacks have increased by 56%, at a global average cost of US$4.99 million.


As highlighted in MinterEllison’s 2026 Perspectives on Cyber Risk report, AI now affects security in three key ways:


  • It’s being used to make conventional attacks (e.g. phishing) more convincing

  • AI systems deployed by organisations are at an increased risk of becoming targets for cyberattacks, and

  • AI is acting as the ‘attacker’


With this in mind, investment in the right defensive tools, as well as employee training on both the use of AI-based platforms and the identification of AI-based threats, are essential to reducing the likelihood and severity of cyber security incidents.


  1. AI and machine learning security tools present new solutions


There are a growing number of AI and machine-learning-based tools available (e.g. malware detection, fraud prevention and phishing detection tools), which offer organisations a means to detect threats earlier and respond more quickly.


According to IBM’s 2026 Cost of a Data Breach Report, “security teams extensively using AI and automation shortened their breach times by 65 days and lowered their average costs by USD 1.93 million compared to those that didn’t use these solutions”.


  1. ‘Zero Trust’ architecture is the way to go


While company suppliers, partner networks and supply chains were once largely considered trusted and secure, the rapid and widespread adoption of SaaS applications and platforms, remote workforces, offshore IT providers, cloud services and mobile devices have fundamentally changed the cyber risk landscape. Organisations may now face threats originating from an increasingly complex IT ecosystem over which they have little or no direct control.


This has prompted a shift towards a ‘Zero Trust’ approach to cybersecurity, based on the principle of ‘never trust, always verify’. Rather than automatically trusting users, devices, applications or connections because they are within an organisation’s network or come from a known supplier, Zero Trust requires access to be explicitly verified and authorised based on factors such as identity, device security and the specific resource being accessed. It also operates on the assumption that a breach may already have occurred, limiting access to only what is necessary and continuously monitoring for signs of compromise.


  1. The Essential Eight is evolving


The Essential Eight is a set of eight prioritised cyber security mitigation strategies developed by the Australian Cyber Security Centre (ACSC) to help organisations protect their IT networks against cyber threats.


For Defence suppliers, the Essential Eight is no longer simply a cyber security best-practice recommendation. All Defence Industry Security Program (DISP) members are now required to achieve and maintain Essential Eight Maturity Level 2.


The eight strategies are:


  1. Application Control

  2. Patch Applications

  3. Restrict Administrative Privileges

  4. Patch Operating Systems

  5. User Application Hardening

  6. Multi-Factor Authentication

  7. Regular Backups

  8. Restrict Microsoft Office Macros


Need help with your Essential Eight program? With a comprehensive understanding of the framework and the Australian defence industry cyber security guidelines, our team can help you simply and cost-effectively apply the right strategies. Visit our Essential Eight page for more information.


BREAKING NEWS: In July 2026, the Australian Signals Directorate (AS) and the ACSC announced that the Essentials Eight framework will be phased out. It will be replaced with a new “Essentials” framework that will cater to the changes in the modern business landscape, especially the rapid adoption of new tech like AI and cloud computing.


The ASD has made it clear that there will be a transition period where the two frameworks will overlap, before the Essential Eight is retired. In the meanwhile, companies are encouraged to keep following their Essential Eight programs and await further updates.


  1. Employee-related risks are becoming a primary priority


Today, employees may be putting your company at risk accidentally. They may fall victim to AI-generated phishing campaigns, or perhaps they use AI tools to boost productivity and streamline their work and in so doing, share sensitive data with public AI models, bypassing proper protocols. (We explore the risks associated with AI-based note-taking tools here.)


With the Australian cyber security landscape shifting fast, it’s important for organisations to stay up to date with the latest trends and to understand what security requirements apply to Australian defence suppliers.


Need guidance on your Defence or cyber security strategies? Contact the De Stefano & Co team to discuss how we can support your organisation.

 
 
bottom of page