Back to Resources

Beyond Awareness Training: What Cyber Action Year Actually Asks of Australian Organisations

Key Takeaways

  • ASD has retired the “cyber awareness month” framing for 2026. Cyber Action Year is a year-long, ASD-led program built on an assumed breach mindset: planning for if, not when, a compromise occurs.
  • Assumed breach is an architectural standard, not a training outcome. The question it puts to security leaders is whether a single human error can still cascade into a network-wide event.
  • Post-quantum cryptography preparation is one of ASD’s own named critical actions under Cyber Action Year, driven by harvest-now, decrypt-later risk to data with a long confidentiality life.
  • The practical starting point this month is a Shadow IT Discovery audit: finding and securing the unauthorised tools staff already use, ahead of the Q4 change freeze rather than after it.

From Awareness to Action

Most Australian organisations still treat October as a season. A phishing simulation goes out, a few training modules get assigned, some posters appear in the break room, and by November the topic recedes until next year. ASD has moved past that framing for 2026. Cyber Security Awareness Month has not disappeared, but it now sits inside something larger: Cyber Action Year (ASD, Cyber Action Year 2026, 2026), an ASD-led program that for the first time brings government, industry and critical infrastructure together around a shared, year-round mandate. Awareness, ASD says plainly, is not enough on its own.

The shift matters more than its naming suggests. Cyber Action Year asks organisations to adopt an assumed breach mindset (ASD, Cyber Action Year 2026, 2026), a planning posture built around if, not when, a compromise occurs. That is a different brief than “train your staff to spot phishing.” It is a statement about architecture, detection and the assumptions built into a network, and it lands squarely on the desks of security leaders rather than compliance or communications teams.

ASD has named a specific set of critical actions (ASD, Cyber Action Year 2026, 2026) under this program: replace or mitigate legacy technology, implement best practice event logging, choose secure by design products and services, prepare for post-quantum cryptography, and prepare for AI-enabled threats. None of these are training initiatives. They are structural.

What Assumed Breach Actually Requires

Human error is often described as the leading cause of cyber incidents, and the industry’s response has typically been more training. Orro sees this pattern differently. Human error is frequently a symptom of poor system design, not a training failure. If one click on one link can still trigger a network-wide event, the technical controls have failed, not the person who clicked.

This is the premise behind what Orro calls Guardrail Security: building a network and control environment that makes it structurally difficult to do the wrong thing, so that awareness training becomes a second layer of defence rather than the only one. In practice, this looks like automated URL filtering and sandboxing that intercepts malicious links before a user ever has the chance to click through, detection capability that does not depend on a human noticing an anomaly in real time, and network segmentation that contains a compromised endpoint rather than allowing it to become a foothold for lateral movement.

Assumed breach reframes the question security leaders should be asking their teams. It is no longer only “how do we stop a compromise from happening.” It is also “when a compromise happens, and it will, how much of the network is exposed, how quickly is it detected, and how far can it travel before something stops it.”

Evidence Snapshot

  • ASD is running Cyber Action Year in 2026 for the first time, bringing government, industry and critical infrastructure into a coordinated, year-round program rather than a single-month campaign (ASD, Cyber Action Year 2026, 2026)
  • ASD has named five critical actions under the program: legacy technology replacement, event logging, secure by design procurement, post-quantum cryptography preparation and AI-enabled threat readiness (ASD, Cyber Action Year 2026, 2026)
  • ASD’s ACSC responded to more than 1,200 cyber security incidents in FY2024–25, an 11 per cent increase year on year, with some organisations taking over 520 days to detect an intrusion (ACSC, Annual Cyber Threat Report 2024–25, 2025)

The PQC Flag

Among ASD’s named critical actions for Cyber Action Year is preparation for post-quantum cryptography, and it is worth pausing on why a cryptographic transition sits alongside detection and legacy technology on a list otherwise focused on this year’s operational priorities.

The concern is harvest-now, decrypt-later. Adversaries can capture and store encrypted data today with no ability to read it, on the expectation that a future cryptographically relevant quantum computer will be able to decrypt it. ASD’s guidance is explicit that data protected by classical encryption today may be exposed later (ASD, Planning for Post-Quantum Cryptography, 2025), and it recommends that organisations cease using traditional asymmetric cryptography, including RSA, Diffie-Hellman and elliptic curve variants, by the end of 2030. For any organisation holding data with a long confidentiality life, health records, financial data, intellectual property or long-term contracts, that transition needs to start now rather than in 2029.

This is a signal-flag rather than a full treatment. Orro has covered the PQC transition and the harvest-now-decrypt-later mechanics in more depth elsewhere. Readers planning their own PQC roadmap should start there.

What Leaders Should Do This Month

The most useful action available to security leaders this month is not another round of training. It is a Shadow IT Discovery audit.

Staff adopt unauthorised AI tools and cloud applications for a predictable reason: the officially sanctioned process is slower or more cumbersome than the alternative sitting in a browser tab. Every one of those unauthorised tools is an unmanaged endpoint for company data, sitting outside the organisation’s logging, access controls and incident response coverage. Left unaddressed, this is exactly the kind of exposure that turns a single compromised credential into a network-wide event, the scenario assumed breach planning is designed to contain.

October is the wrong time to discover this gap. Running a Shadow IT Discovery audit now, ahead of the Q4 and Christmas change freeze, means unauthorised tools can be identified, assessed and either secured or retired while change windows are still open. Waiting until the traditional awareness campaign in October means competing for staff attention during the busiest period of the year, and running into the freeze before remediation work can be scheduled.

The audit itself does not need to be elaborate. It requires visibility into what applications staff are actually using, cross-referenced against what has been formally approved, followed by a decision on each unauthorised tool: secure it, replace it with a supported alternative, or block it. What matters is doing this in September, not fighting a culture war about it in October.

Cyber Action Year gives Australian organisations a structured list of what ASD considers critical this year. Orro’s Cyber Action Year Readiness Checklist maps directly to those actions, giving security leaders a practical way to work through legacy technology, logging, secure by design procurement and PQC transition planning before the year moves on without them.

Sources & Further Reading