- Boards might be preparing for the wrong type of cyber threat as AI changes the assumptions behind their plans.
- MinterEllison’s research shows AI-enabled threats are challenging ransomware as the leading concern for senior decision markers.
- ASIC says boards must move beyond awareness to ensure their organisations have “well-tested response plans” and understand where they are vulnerable.
Boards risk preparing for a cyber threat that is changing faster than their response plans, AICD CEO Mark Rigotti has cautioned, as regulators call on companies to turn frontier AI risk awareness into action.
The warning comes as APRA and ASIC say frontier AI is increasing the speed, scale and sophistication of cyberthreats, putting pressure on boards to ensure they can make critical decisions and recover when incidents unfold at unprecedented speed.
Speaking at the launch of MinterEllison’s 11th annual Perspectives on Cyber Risk: The AI Edition report, Rigotti said boards were not ignoring cyber. But after years of dealing with familiar threats, they may be preparing for the wrong thing.
“I can’t think of any director who’s actually ignoring cyber,” he said. “To the contrary, it’s probably one of the things they’re actually asking about on their boards.”
Citing the AICD’s latest Director Sentiment Index, Rigotti said cyber had been among directors’ top five concerns four years ago, but had fallen outside the top five over the past 18 months, behind issues including geopolitical risk and productivity.
But his concern was not complacency so much as preparation.
For years, he explained, boards have focused on preparing for conventional cyber incidents, but AI is changing the assumptions behind those plans.
“Maybe it’s the wrong playbook. You have to play the puck where it’s going to be, not where it is,” suggested Rigotti, borrowing an analogy from Canadian ice hockey great Wayne Gretzky.
The MinterEllison research shows how quickly AI has moved into Australian organisations. The survey of 150 senior decision-makers found 98 per cent of organisations had introduced AI in the past 24 months, while 95 per cent reported having a formal AI governance framework.
At the same time, 71 per cent had experienced at least one cyber incident in the previous 12 months.
For the first time in the survey series, AI-enabled threats were challenging ransomware as the respondents’ leading concern.
The regulators’ latest warning underscores this shift. In a joint statement issued on 27 August, APRA and ASIC said threat actors are using frontier AI to exploit vulnerabilities that once took professionals months to find.
Releasing the findings of nine industry roundtables involving 600 financial sector leaders, ASIC Commissioner Simone Constant urged boards to prepare immediately.
“The urgency of this challenge cannot be overstated,” she said. “Now is the time to ensure you have a strong, tested plan to respond when the worst happens.
“Boards and executives must move beyond awareness to ensure their organisations have well-tested response plans and understand where they are vulnerable, so they can respond effectively under pressure.”
For Rigotti, some of the most important lessons are less technical.
He has participated in three cyber tabletop simulations over the past year as both CEO and director. The lessons, he said, were similar – too many people in a room can slow a response, while unclear delegations can leave management waiting for decisions.
The fix, he said: “Very clear delegations so management can get what it needs to do what it needs. Then on communications… Do you have communications specialists? An external person who will give you the news bluntly?”
The latter, he stressed, is key.
The threat itself is also becoming harder to fit into traditional incident-response planning.
The MinterEllison report highlights recent cases in which autonomous AI systems were able to identify vulnerabilities, access systems and operate at a speed difficult for a human team to match.
That raises a more fundamental question for boards: What happens when the attacker is not behaving like a conventional attacker or when there’s no single human actor making decisions?
It also complicates the job of working out what’s been compromised and what needs to be disclosed, particularly as AI systems increasingly hold sensitive corporate information and sit inside critical technology platforms.
Do boards need AI fluency?
The discussion also turned to whether boards need to change their composition as AI becomes more important.
Rigotti said there was no one answer. Boards, he noted, have more digital skills than they did four or five years ago, but that did not necessarily mean appointing a technology specialist.
“You need a level of AI fluency,” he said.
But for Rigotti, the more pressing issue was whether directors and executives could make decisions without having all the information.
“You need the capability to make decisions off the back of incomplete information,” he said. “And that’s both at the management and at the board level.”
His advice for organisations preparing for the next cyber incident is straightforward – prepare the relationships before the crisis.
“Build bridges before you need them,” Rigotti advised.
That means knowing who to call at the Australian Signals Directorate, having advisers lined up, and running tabletop exercises with the board and management together.
Three things boards should do before the end of the year
1. Build an AI inventory
MinterEllison’s Sam Burrett and Chelsea Gordon said boards should know what AI systems are being used across the organisation, what risks they create, what controls apply, what personal information they hold and where AI is embedded in existing systems or the supply chain.
2. Build relationships before they’re required
Rigotti captured this point best: “Build bridges before you need them.” That means knowing who you’ll call at the Australian Signals Directorate, having consultants lined up, and exercising board and management together so there are clear delegations and decision-making authority when something goes wrong.
3. Go back to basics: People, process, technology
Good cyber and AI governance still comes down to people, process and technology, said MinterEllison’s Paul Kallenback. It means ensuring those fundamentals are strong enough to withstand the faster, more complex threats AI is bringing into the cyber landscape.
Latest news
Already a member?
Login to view this content