Elastic surveyed over 850 IT and cybersecurity professionals across Australia and New Zealand and found that frontier AI has accelerated cyberattacks to machine speed while defenses remain largely manual. Only 14% of organisations say they could respond to an AI-automated attack at machine speed, and just 9% of Australian and 15% of New Zealand organisations would detect a compromise within five minutes after hours. Monitoring blind spots persist (60% in Australia, 67% in NZ), and only around one in five respondents say their security data is ready for reliable AI agent use, despite most organisations already adopting or planning to adopt AI for cybersecurity. Policy reforms like Australia's Essential Eight replacement and New Zealand's Cyber Security Strategy 2026–2030 are underway, but survey respondents report a persistent gap between compliance and real protection, and rising leadership accountability and frontline stress.
Table of contents
Governments are rewriting the rules, but reality is outpacing policyMachine-speed attacks with human-speed defencesThe gaps in visibility are significantAI tools are being deployed, but data foundations are not readyThe pressure is mounting on leadersHow to navigate this momentShareQuestions this post answers
What percentage of organisations in Australia and New Zealand can respond to an AI-automated cyberattack at machine speed?
Only 14% of organisations in both Australia and New Zealand say they could respond to an AI-automated attack at machine speed. Most still rely on mixed or manual alert triage processes, even though attackers have already automated theirs, creating a significant gap between attack speed and defensive response capability. Security teams weighing AI-driven defense investments can track this readiness gap on daily.dev.
How many organisations say their security data is actually ready for an AI agent to use reliably?
Only around one in five respondents in Australia (20%) and New Zealand (19%) say their security data is ready for an AI agent to use reliably, despite 77% and 81% respectively already using or planning to deploy AI for cybersecurity within 12 months. Fragmented data across cloud, on-premises, and SaaS systems undermines effective AI-driven threat detection. Teams planning AI-driven security tooling can follow data-readiness research like this on daily.dev.
How common are unmonitored visibility gaps in cybersecurity environments in Australia and New Zealand?
60% of organisations in Australia and 67% in New Zealand have knowingly identified at least one unmonitored area in their security environment, with 33% and 26% respectively reporting multiple blind spots. Causes include legacy systems that are hard to monitor, skills shortages, and security data fragmented across cloud, on-premises, and SaaS environments. Anyone auditing monitoring coverage can track findings like these on daily.dev.