August 31, 2026

The ASD’s Frontier AI report is now on the board agenda. Is your security strategy ready?

Richard Dornhart
National Practice Manager - Security, Data#3

Most organisations are thinking about AI through the lens of opportunity, with the conversation largely focused on improving productivity, automating processes and creating new ways of working. The Australian Signals Directorate’s (ASD) latest guidance on the careful adoption of agentic AI services adds an important question: what does increasingly capable AI mean for cyber risk?

The report challenges organisations to look at some of the assumptions behind security strategies. What happens when vulnerabilities can be identified and exploited faster, or when attacks can be automated? The fundamentals of good cyber security haven’t changed, but what is changing is the speed at which security teams need to detect, respond and recover.

That raises some practical questions for security leaders. Where are we exposed? Which risks matter most? And if an attack moves faster than it does today, can we respond quickly enough?

The ASD report gives boards a framework for asking those questions. The job for security teams is to be ready with the answers.

What’s changing in the threat landscape

The report highlights three frontier AI capabilities:

  1. It can find vulnerabilities faster than a human analyst can.
  2. It can chain small, low severity weaknesses into a major compromise.
  3. It can run malicious activity with little to no human oversight.

As a result, exploitation timelines are compressing from days to hours, and the skill barrier for attackers is reducing significantly.

The report’s recommended response is to essentially improve the fundamentals now, strengthen resilience and modernise for an AI-enabled future. The ASD lays this out across immediate, short, medium and longer-term priorities:

  • Immediate: secure the attack surface and reduce software vulnerabilities.
  • Short term: replace legacy systems, reinforce identity and access, restrict unnecessary privileges and prepare incident response.
  • Medium term: adopt AI for defence, with human supervision and accountability.
  • Longer term: modernise using secure by design principles.

None of these are new ideas. What is new is the speed they happen and the pace at which security teams need to detect and respond. That puts greater pressure on the fundamentals of cyber resilience.

From technical risk to business risk

One challenge for security leaders is turning a complex technical picture into a clear view of business risk.

The board doesn’t need your vulnerability register, but they need to understand what it means for the organisation. Most importantly, they need confidence that the management team understands the risk and is taking appropriate action.

An executive will ask the same question differently. A CISO, a CIO or a GM will want the mechanics behind the answer: which systems are affected, where the gaps are, what remediation costs, how long will it take and who owns it. They’re testing whether the plan is achievable.

It’s the same underlying risks, but communicated at two different levels, and both versions need to be ready before the meeting starts.

  • Board version: “We’re exposed in these areas. Here’s what it could mean for the business, how we are managing them and where we need to accept or reduce risk.”
  • Exec version: “These are the systems and gaps driving the risk. Here is the remediation plan, the investment required, the timeline and who owns each action”.

Write the board answer first. It forces you to step back from the technical detail and be clear about what matters, what needs to happen and whether you have the evidence to support the answer.

The questions to prepare for

The report gives boards a framework and they will want to understand what the responses are based on. These are the questions to have evidence for:

  • How vulnerable are we to AI enabled attacks, and what assumptions in our current risk assessment might no longer hold?
  • Where could minor weaknesses combine into a major incident, including through our vendors and supply chain?
  • Do we have control over our fundamentals: a recognised framework, a legacy remediation plan, nothing parked because it seemed low severity?
  • Can we keep operating if a critical system is compromised, and have we tested our response against attacks that now take hours, not days?

Answering these questions requires a view of resilience that extends across people, processes, governance and technology. If you can’t answer these with evidence today, that’s what needs to be addressed first.

Building resilience before you’re tested

Fundamentals always come first. You need:

  • Configuration baselines that are deployed and actively monitored for drift, not just written down
  • A vulnerability management process that finds, validates, remediates and verifies fixes on a risk-based timeframe
  • A plan for legacy systems that can’t meet current requirements, with compensating controls until they’re replaced.

Identity and access is where many of the short-term priorities sit, and for good reason. This is the part of the environment attackers move through once they’re in, so it needs to hold. This means:

  • Disabling unused accounts on a regular cycle
  • Storing secrets and keys properly, with access controls
  • Using phishing resistant multi factor authentication everywhere, especially from untrusted locations
  • Switching off legacy authentication protocols that bypass modern controls
  • Reviewing privileges against what people, and AI agents, need to do the job.

That last point is especially important. An AI agent with excessive access is now a genuine attack path, not a hypothetical one. Incident response and continuity plans also need to be tested, not filed.

The report asks: if attacks move from days to hours, does your plan still hold up? Be ready when your board asks this.

AI has a role on your side of the fight too. Vulnerability scanning, security monitoring and event triage all move faster with AI in the loop, provided it stays human supervised and accountable. This is how you start closing the speed gap attackers are creating.

Where to start

Knowing you have gaps is the easy part. Knowing exactly where they are, how significant they are and what to prioritise first is what improves resilience. That’s not something you want to work out live in a board meeting.

The Data#3 Security Resilience Assessment provides an independent view of your current posture, identifies areas of exposure and delivers a prioritised roadmap for improvement.

Most importantly, it helps security and technology leaders support board discussions with evidence rather than assumptions.

If you’re preparing for that conversation, reach out to my team via the form below. We’d be happy to help you understand where your current security posture stands and where to focus next.

Contact us

Information provided within this form will be handled in accordance with our privacy statement.