Boards know their organisations will get breached. The question is how long it takes them to notice.
FOI data from the OAIC shows an Australian mining and manufacturing companies went 520 days before detecting an intrusion last year, then another 84 days before reporting it.
Cyber espionage cost Australia $12.5 billion in FY23-24. PwC’s 2026 survey shows geopolitical volatility is now directly shaping cyber risk investment decisions, and early indicators suggest pressure is continuing into 2026.
1. Cloud security is still the biggest gap
PwC’s 2026 Global Digital Trust Insights continues to rank cloud-related threats among the most concerning cyber risks, with earlier PwC survey data showing 42% of executives flagging cloud as a top concern and an area they feel least prepared to handle.
Most companies spread their data across AWS, Azure, Google Cloud and other SaaS platforms. Yet only 6% of organisations say they are confident across all vulnerabilities surveyed, according to PwC’s 2026 Global Digital Trust Insights.
2. Third-party vendors remain the easiest way in
Third-party access continues to sit at the centre of serious incidents because it accumulates quietly and changes faster than most organisations can track.
What makes this harder in 2026 is that in practice, no one has a complete view of which suppliers can reach what or how that access is being used. For attackers, this makes suppliers an obvious entry point. Rather than pushing directly at large organisations, they focus on vendors that already sit inside trusted pathways.
Third-party data breaches remain one of the most concerning cyber threats for executives, sitting alongside cloud and ransomware risks in PwC’s global findings.
3. Generative AI creating data leaks
67% of security leaders believe that GenAI has increased their attack surface over the last year. That change has carried into 2026 as AI tools become more embedded in daily workflows.
Many organisations are experimenting in parallel across teams, without consistent guardrails or visibility.
Limiting AI use can affect productivity, while open use could spread sensitive information across systems that sit outside existing controls. In 2026, most organisations are still working through where these practical boundaries can work for them.
4. Legacy systems & response speed
Legacy systems are one of the main reasons detection and response take so long. These systems sit underneath core operations and tend to be the hardest to change. They run ERP platforms, production environments, and control systems that the business depends on daily.
Most were built before modern authentication and monitoring were expected. As a result, visibility into what’s happening inside these systems is thin compared to newer environments.
The Australian Signals Directorate has continued to flag legacy IT as a long-term risk in its 2025-26 board guidance. In Gridware’s experience, even organisations that invest heavily elsewhere still find that response speed is shaped by the oldest parts of their environment.
5. Ransomware moved from encryption to data theft
In 2024-25, the Australian Signals Directorate responded to 138 ransomware incidents. 2026 is unfortunately tracking worse.
Ransomware incidents in 2026 often centre on data long before systems are disrupted. Attackers focus on copying information early in the intrusion and holding it as leverage. Whether encryption follows usually depends on how much pressure they think is needed.
PwC’s 2026 survey shows only 24% of organisations are investing significantly more in proactive measures than reactive response, a gap that leaves many organisations exposed when data theft becomes the primary leverage.
Recent incidents have only made it more apparent. In several cases, the most serious impact came after systems were back online, once stolen data began circulating or disclosure obligations kicked in. In 2026, ransomware victims are experiencing less downtime, but more regulatory scrutiny, reputational damage, and downstream commercial impact.
6. Regulatory scrutiny starts before answers exist
Regulatory scrutiny usually starts while an incident is still unfolding. Boards are asked to explain what was known, when it was known, and how decisions were made with limited visibility.
Because Australian cyber regulation is principles based, those explanations are judged against how controls were operating in practice, not how they were documented.
This is where many organisations struggle. When regulators ask how quickly an intrusion was detected or why issues were not escalated sooner, answers seem hard to explain alone.
What prepared boards tend to have in common
Boards that cope better with cyber incidents in 2026 tend to have a clearer view of how risk shows up day to day. That usually comes from regular engagement with security teams, defined oversight responsibilities, and direct discussion of detection and response capability.
Research from PwC shows high-resilience organisations report stronger board involvement in cybersecurity. In practice, that involvement shows up through questions about visibility, response timelines, and areas where confidence is low, rather than broad assurances.
For many ASX100 organisations, clarity comes from testing before an incident happens. Cyber War Gaming puts boards and executives into realistic cyber scenarios, showing how decisions play out and where assumptions don’t hold. It gives teams a clearer sense of readiness without blame or pressure.




