Summary
- Machine-speed attacks enabled by frontier AI are outpacing current defensive capabilities across Australia and New Zealand.
- Policy frameworks in the region are evolving, yet data reveals a persistent gap between regulatory intent and real-world operational security outcomes.
- Visibility gaps and fragmented data environments remain critical challenges that hinder organisations from achieving rapid, automated threat detection.
- Data architecture preparation is essential for reliable AI deployment as current infrastructures often lack the complete, searchable context required for effective defence.
Frontier AI has handed attackers something they have never had before: the ability to move at machine speed. Attacks that once took days to craft now take minutes. Threats have not just evolved to be automated, adaptive, and operational around the clock. They have also changed category.
We surveyed more than 850 IT and cybersecurity professionals across Australia and New Zealand to understand how organisations are keeping up. What the data reveals is not a capability problem. It is a pace problem. And most organisations are losing the race.
Governments are rewriting the rules, but reality is outpacing policy #
Both Australia and New Zealand have acknowledged the problem at the policy level. In June 2026, the Five Eyes intelligence partnership issued a direct warning: Frontier AI could transform cyber risk within months, not years. Both countries have responded with framework reform.
In Australia, the Australian Signals Directorate (ASD) is consulting on a replacement for the Essential Eight, a framework built for a different era and one that the research confirms has become too rigid for AI-enabled attacks. In New Zealand, the Cyber Security Strategy 2026–2030 is now live, representing the most significant national cyber framework update in years. Both efforts are welcome. The data reveals a significant gap between intent and impact.
In Australia, only 18% say the previous Essential Eight primarily supported real protection over compliance, and 82% want its replacement to be clearer, simpler, and more prescriptive to drive real outcomes. In New Zealand, 83% see the new strategy as delivering genuine security value, but 15% already say compliance burdens outweigh protection.
Machine-speed attacks with human-speed defences #
Awareness of the risk is not the problem: 90% of Australian respondents and 87% in New Zealand say their organisation understands how frontier AI could be weaponised against them. The issue is that awareness isn’t driving action.
Only 14% of organisations in both countries say they could respond to an AI-automated attack at machine speed. The majority are still relying on mixed or manual processes to respond to attacks. Alert triage remains a human activity. Attackers have already automated theirs.
Detection speed outside business hours is another critical gap. Only 9% of Australian organisations would detect a compromise within five minutes after hours. More than a third in each country expect detection to take at least an hour. These are the windows attackers are built to exploit.
The gaps in visibility are significant #
Monitoring blind spots is not a hidden problem: 60% of organisations in Australia have knowingly identified at least one unmonitored area in their environment, including 33% with several gaps. In New Zealand, that figure rises to 67% with 26% reporting multiple gaps.
The causes are consistent across both countries: legacy systems that are difficult to monitor, skills shortages, and security data fragmented across cloud, on-premises, and SaaS environments. The environment has expanded faster than the visibility tools built to cover it.
Unmonitored gaps are not just a visibility problem. They are an AI readiness problem. An AI agent can only act on the context it can reach. If that context is incomplete, the agent is blind in exactly the places attackers are trained to exploit.
Operational readiness | Australia | New Zealand | | Human intervention required for 40%+ of alert decisions | 84% | 87% | | Would detect a compromise within five minutes outside business hours | 9% | 15% | | Expect detection to take at least an hour outside business hours | 41% | 35% | | Have knowingly identified at least one unmonitored area | 60% | 67% | | Have multiple monitoring blind spots | 33% | 26% |
AI tools are being deployed, but data foundations are not ready #
Organisations across both countries are moving fast on AI adoption. New Zealand leads with 62% already using AI for cybersecurity compared with 52% in Australia. However, both countries are in the same position on readiness.
Only around one in five respondents in each country say their security data is actually ready for an AI agent to use reliably. An AI agent needs complete, searchable, real-time context to function. Scattered data across disconnected systems does not provide that. Deploying AI on a fragmented foundation does not close the readiness gap. It hides it.
AI deployment and data readiness | Australia | New Zealand | | Already using AI for cybersecurity | 52% | 62% | | Using or planning to deploy AI within 12 months | 77% | 81% | | Security data ready for an AI agent to use reliably | 20% | 19% | | Updated incident response playbook in past 12 months | 78% | 77% | | Remain unconfident in defences despite updated playbook | 54% | 49% |
The pressure is mounting on leaders #
Cyber accountability is no longer abstract. Under Australian law, directors can face personal fines and removal following a breach. In Australia, 57% believe their CEO would resign or be removed within 12 months of a major incident. In New Zealand, 50% say the same.
But accountability has not yet translated into operational change at the pace the threat demands. In Australia, 28% say their organisation's response has been mostly paperwork. In New Zealand, 52% say stronger enforcement has not meaningfully changed their leadership team's behaviour.
The pressure is not only falling on leaders. For example, in New Zealand, 56% of security professionals say the growing role of AI in cyber threats has increased their work-related stress over the past 12 months. People on the front line are feeling it.
About the research
Elastic's 2026 cybersecurity research was conducted by Pureprofile in August 2026. It surveyed over 850 IT and cybersecurity professionals across Australia and New Zealand with primary, shared, or advisory responsibility for their organisation's information or cybersecurity decisions. Australian findings are drawn from 602 respondents; New Zealand findings are from 249 respondents.
The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.