Cyber Security Awareness Month 2025 Skip to content

Cyber Security Awareness Month 2025

David Rajkovic

David Rajkovic, Regional Vice President A/NZ, Rubrik

“Cyber Security Awareness Month is an ideal time for leaders to review their current strategies in light of evolving attacks. The traditional approach to security has been to build the highest digital ‘walls’, but new strategies are seeing attackers routinely undermine these defences.   

Chief among these new methods are identity-based attacks. Recent research from Rubrik Zero Labs found almost 80 per cent of all cyberattacks in the past 12 months were identity-driven. These attacks involve exploiting a critical vulnerability in those digital walls – weaponising compromised user credentials to gain unauthorised access to critical systems.

As targeted attacks involving compromised credentials increase, zero trust principles can help to minimise the risk of these attacks. Least privilege, where users have access only to resources they need to work effectively, and just-in-time access, where privileges are granted only for pre-determined durations, are two such principles. 

Additionally, AI-powered anomaly detection systems can monitor user behaviour, detect unusual access patterns, and identify potential identity-based threats in real-time to provide critical early warning signals. It’s no longer enough to know an identity is compromised; we must understand what that identity has access to. Modern data security platforms now continuously map the relationship between every identity – human and machine – and the sensitive data they can access. Platforms allow organisations to proactively identify high-risk permissions and understand the potential ‘blast radius’ of a compromised account before an attack even happens. Digital walls might have worked when cyber attackers were breaking in, but a new approach is needed because increasingly they’re simply logging in.”

 Shain Singh

Shain Singh Principal Security Architect at F5

“For too many years, application security was considered to be an issue for the IT team. That is no longer the case. The theme for this year’s Cyber Security Awareness Month is ‘Building our cyber safe culture’ and it’s never been clearer that application security, like all elements of cyber security, is a whole-of-business concern. Every line of code, every integration, and every business process carries potential risk. Cybersecurity Awareness Month is a timely reminder that developers, executives, and employees all have a role to play in safeguarding digital trust. That means building trust at every layer. From applications and infrastructure to data. By embedding security into every part of the organisation, businesses can improve their resilience and stay ahead of emerging threats.

“As digital transformation accelerates, so do the risks that come with it. Security breaches are becoming a regular feature in the news, and many of them share a common thread, and that thread is gaps in application security. Cybersecurity Awareness Month serves as a useful prompt to re-examine how we approach security so it is viewed not just as a technical issue, but as a shared responsibility across teams. Strong defences rely on more than just tools. They depend on collaboration, a resilient mindset, and making security an integral part of how we build and run systems.”

Scott Morris

Scott Morris, Managing Director of Infoblox for Australia and New Zealand, Infoblox 

“This year’s theme, ‘Building our cyber safe culture’, reminds us of the need for Australians to view cybersecurity as a collective effort. There’s a misconception that cybersecurity can be achieved through one product, organisation or platform. But when it comes to cybersecurity, good enough isn’t actually good enough. Cyberthreats are now a constant in our lives, and every Australian should be taking steps towards becoming more cyber secure every day.”

“In April, our government, alongside the United States, Canada and New Zealand, released a joint cybersecurity advisory of the threat of ‘fast flux’ tactics. In this type of attack, threat actors rapidly change Domain Name Systems (DNS), which allows them to bypass traditional security safeguards.”

“Threat actors obfuscate their tactics by constructing intricate architectures with thousands of domains, making coordinated communications appear random and unconnected. Monitoring and analysing DNS threat intelligence data, including domain registration details, can unveil details about threat actor campaigns like fast flux.”

“For years, organisations have only used DNS security as a last line of defence – its role reduced to post-incident investigations. But DNS and IP addresses are the entry-gate to the internet, so in order to build a cyber safe culture, we need to position DNS security as the front line of defence.”

“This is becoming a common theme for governments around the world — who are rapidly incorporating DNS in regulatory requirements, as well as using it as a security control to protect government, public sector and critical national infrastructure. By elevating their DNS security posture, an organisation can fortify its entire cybersecurity strategy.”

“Cybersecurity Awareness Month is an important reminder for Australians to implement cybersecurity best practices. It might feel overwhelming, but the reality is that small, intentional steps every day can make a difference. Strong passwords, multi-factor authentication (MFA) and software updates — while considering advanced solutions like DNS security — are critical to stay ahead of emerging cyber threats.”

Roz Gregory

Roz Gregory, Regional Vice President A/NZ, Datadog

“Cybersecurity Awareness Month provides us with the opportunity to recognise just how different the world is from a year ago. However, it also reminds organisations and individuals of the necessity for safety and resilience in digital environments. Like every year there will be a focus on the usual cybersecurity tropes, but the spotlight should certainly be shining further.

“Cybersecurity cannot be allowed to deteriorate into a blame game between developers and operators when incidents arise. A cultural shift must occur, where responsibility for building secure systems from the ground up is shared between developers, operators, and leaders. This accountability guarantees security is built into design, development, and operations from the outset, rather than only being considered at the last minute.

“The urgency of this shift is non-negotiable with regulatory frameworks, like the Security of Critical Infrastructure (SOCI) Act, which place sovereignty and resilience at the forefront. Organisations must realise compliance extends beyond meeting bare-minimum requirements and avoiding penalties. Rather it’s about building operational resilience at a national level across people, processes, and technology.

“Integrating security and observability across all roles demonstrates strength and adaptability, satisfies regulatory expectations, and builds confidence in digital systems. When organisations adopt a culture of operational resilience through observability, they shift the focus from reactive compliance reporting to proactive resilience management. This brings traditionally disparate teams – like operations, engineering, security and risk – together to understand and collaborate on overlapping responsibilities in preventing breaches, outages, and vulnerabilities across the entire digital landscape, from soup to nuts.”

Kevin Gritsch

Kevin Gritsch, Vice President of Partner Services, APAC at Pax8 

“With every major cyber incident, regulators scrutinise businesses that much more, taking a lens to processes, people, and the tech under the hood. In a relatively short period of time, we now have frameworks like the Essential Eight maturity model, Privacy Act reforms, and ransomware payment reporting obligations, all raising the security bar for every organisation. This might be fine for the larger players, but for small and medium-sized businesses, that bar can sometimes seem a bit out of reach.

“It’s well known that a third of Australia’s GDP can be attributed to SMBs, yet they face the same compliance expectations as larger enterprises and often without the same internal resources. It’s for this reason I’ve seen an increase reliance on managed service providers now not only deploying technology, but guiding SMBs through frameworks, audits, and cultural change needed to meet rising standards. And it’s also because what we’re seeing is a convergence of pressures.

“Regulators, insurers, and customers are all demanding greater transparency and demonstrable uplift in security maturity. Cyber resilience is becoming less about if you are attacked, and more how you prepare, respond, and recover in a way that withstands inevitable scrutiny. For SMBs, the message hasn’t changed. Align to recognised frameworks like the Essential Eight, CIS v8, or SMB1001. What has changed are the consequences. What was once a technical headache is now a compliance fault line, one that can cripple a business even if it survives the attack itself.”

Vinayak Sreedhar ManageEngine

Vinayak Sreedhar, Country Head A/NZ at ManageEngine

 “October is Cybersecurity Awareness Month and it’s a chance to reflect on how much the digital landscape has shifted over the past year. It is also a timely reminder for both organisations and individuals to place digital safety and resilience at the forefront. Today, cybersecurity is not just about passwords and patches. With the rise of AI-driven tools and the risks that come with them, from deepfakes to automated attacks, the conversation has moved beyond basic awareness, underscoring that cybersecurity is a moving target that requires constant vigilance.

“This year, Cybersecurity Awareness Month comes at a time when AI adoption is accelerating across every sector. From healthcare to finance to education, organisations large and small are racing to implement AI solutions, while simultaneously working to set guardrails on responsible use. With uncertainty around how these technologies will reshape work, security, and trust, the focus has expanded beyond cybersecurity to the broader challenge of ensuring AI is deployed safely, ethically, and transparently.

“The rise of AI brings both opportunity and anxiety. For many organisations, the anxiety stems from uncertainty: where do the risks lie, and how can they prepare? The answer is clear. AI innovation cannot outpace security. Responsible governance, clear policies, and proactive defences must anchor adoption so that businesses can embrace AI confidently, without exposing themselves to new classes of cyber threats.”

Rob Dooley 002

Rob Dooley, Vice President, Asia Pacific and Japan, Rapid7

Cybersecurity Awareness Month presents an opportunity for security leaders to revisit their SecOps strategies, especially in the current environment as AI-driven phishing, ransomware, and social engineering are reshaping the threat landscape.  

AI is becoming a powerful tool for both defenders and adversaries. While security teams increasingly use AI to detect anomalies and accelerate incident response, attackers are harnessing generative models to craft highly convincing phishing campaigns, deepfake voice messages, and synthetic identities that evade traditional red flags.  

Ransomware campaigns have grown more adaptive too: automated reconnaissance, dynamic exploitation of vulnerabilities, and targeted strikes based on real-time intelligence are becoming the norm. Threat actors exploit weak MFA enforcement, exposed remote access points, and credential-based attacks to gain a foothold.  

In this environment, our security awareness must evolve beyond checking emails and texts for spelling mistakes. Every individual, from board executives to frontline staff and family members, has a role in maintaining cyber hygiene. Taking a moment’s pause before clicking, using multi-factor authentication, verifying unusual requests, and promptly reporting anomalies can disrupt attacker playbooks.  

October’s awareness campaign is a reminder that cybersecurity demands a mindset of foresight, collaboration, and continuous vigilance. As threats evolve, so must our defences.

Erich Kron

Erich Kron, CISO Advisor, KnowBe4

If we want to strengthen security, we need to start with the people who keep the organisation running. Security tools continue to improve, but so do the threats that rely on manipulating human behaviour. Attackers count on stress, distraction and misplaced trust, and those tactics are working. 

Recent data shows that between 70% and 90% of breaches involve human involvement. Human risk shows up when people are expected to spot threats but have not been set up to succeed. That is where Human Risk Management (HRM) makes a difference. 

HRM is not about ticking a box. It is about understanding how people think and work, what gets in their way, and how to build habits that lead to better decisions. Breaches linked to human behaviour are a sign that security culture is not keeping pace with the threat landscape. 

The work is not just about raising awareness. It is about making sure people feel supported, know what to watch for and have the confidence to act when it matters. The goal is not perfection. It is resilience, and that comes from people who are prepared to recognise risks and respond with good judgement.

Adjo Badat

Adhil Badat, Managing Director APJ at Rackspace Technology

The truth is that cyberattacks are inevitable. Ransomware and data breaches are designed to cause maximum disruption, and many businesses still treat recovery as a secondary concern.

Traditional backup and disaster recovery solutions were built for a time when organisations could absorb days or even weeks of downtime. In today’s business climate, even short periods of downtime can carry serious consequences. Research in Australia shows the average customer-facing incident takes about 2.5 hours to resolve and costs over a million dollars, confirming that even an hour of disruption is enough to erode revenue, customer trust and brand reputation. 

That shift demands a new mindset. Cyber readiness goes beyond storing a copy of your data. It means identifying mission-critical workloads, conducting readiness assessments, mapping dependencies and testing realistic scenarios. It also involves creating clean and isolated environments where recovery can be executed securely, allowing operations to resume in hours rather than weeks.

Resilience should be treated as an ongoing discipline. It requires consistent investment in people, processes and testing so that organisations are able to adapt as threats evolve. By building recovery into the very centre of a cyber strategy, businesses can transform resilience into a competitive strength. This ensures they protect not only their data but also their ability to operate and the trust they hold with customers and partners.

Lincoln Goldsmith

Lincoln Goldsmith, Director of Enterprise Channels & Alliances, APAC at Semperis

The weakest link in an organisation’s cybersecurity ecosystem is almost always human error. Threat actors routinely weaponise the very traits that make us human—trust, curiosity, and urgency. In fact, 69% of Australian organisations targeted by ransomware in the last 12 months were hit on a weekend or holiday. Cyber criminals know exactly when employees are distracted and their defences are low, so it’s no coincidence that attacks are timed around this.

Overall, human error accounts for roughly 30% of the data breaches in Australia, according to data from the OAIC. Regardless of how secure an organisation’s systems are, individuals contribute either intentionally or inadvertently to data breaches. For example, we’ve seen a significant increase in attackers exploiting Active Directory (AD) weaknesses caused by human error through phishing, weak or stolen credentials, insecure configurations, and excessive privileges. These errors (often enabled by poor security awareness and hygiene) allow attackers to gain network access and escalate privileges.

While large-scale cyberattacks make the headlines, Cyber Security Awareness Month serves as an annual reminder for the little things we can habitualise in our daily lives to help build a cyber-safe culture for all Australians. Most of us don’t think twice about taking a few minutes each day to brush our teeth to protect our dental health for the long term. The same applies to building a cyber safe culture. By implementing security behaviours into our daily routines, we can build good cyber hygiene to safeguard our digital lives – from our home to our place of work. The simplest cyber practices are often the most effective at preventing breaches and data loss before they happen. Measures like password protection, multi-factor authentication (MFA) and regular patching don’t require technical skills, just consistency, like brushing and flossing.

The everyday habits we build in our personal lives carry over into how resilient organisations are against cyberattacks, especially those with complex identity infrastructure and large networks. While the stakes may differ between personal and organisational cybersecurity, our culture-forming habits remain the same.

Dan McLean

Dan McLean, Country Manager, ANZ at Barracuda Networks

For Cyber Security Awareness Month 2025, the Australian Government has highlighted the continued reliance on legacy technology as a pressing issue to resolve. Legacy doesn’t have to mean something that’s been around for years, it covers anything that hasn’t been updated in line with evolving threats. With the current pace of change, the window to update and maintain systems is shrinking fast. 

Older or unpatched technologies may contain known and unaddressed security flaws, lack compatibility with modern security tools, and the vendor may have stopped supporting them. 

This can leave organisations exposed without updates or assistance, and prime targets for cyber criminals. Reports show that up to 70% of IT teams are spending more than 6 hours a week on security patching alone. Older systems also tend to be harder to manage securely, increasing the likelihood of human error and misconfigurations that can compromise sensitive data.  

When systems aren’t kept up to date, it isn’t just inefficient – it’s dangerous. Building a cyber safe culture means recognising that security is not just about reacting to threats but about proactively strengthening the foundations of our digital environments.  

http://itwire.com/enterprise-staff/cyber-security-awareness-month-2025.html