When a regulator tells you to table a letter at the board, the question isn’t whether your cybersecurity exists — it’s whether you can prove it actually works.
Imagine it is a Friday morning anywhere in Australia. An executive at your average organisation pours their first coffee, settles into the chair, and opens their email. Somewhere beneath their quarterly earnings report and the average drudgery of correspondence is a three-page letter from the Australian Securities and Investments Commission (ASIC).
The letter does not ask, nor does it suggest but rather it instructs with an unmistakable tone of government regulation that has grown tired of watching the same preventable cyber breaches repeat themselves. The setup highlights how artificial intelligence is impacting the world of cybersecurity and what every organisation should be doing to ensure they are not the next victim. The recommendations are nothing new but an affirmation that the basics must be done, and they need to be done well.
That letter, dated May 8, signed by the ASIC commissioner follows APRA’s call to arms for a step-change in how banks, insurers and superannuation trustees manage AI-related risks as the technology continues to rapidly evolve. It deserves more than a forward to the CISO and leadership team. It deserves a conversation in the boardroom as you’re not just putting your customers at risk, you might well be putting the economy at risk.
What ASIC is describing is not an Australian problem but rather a global issue and the companies that understand that distinction will be far better positioned than those that treat it as a compliance burden. Unfortunately, the devil is in the details. The threat to organisations has not changed, but rather it has been multiplied by AI for severity and impact.
ASIC’s framing is precise and worth repeating: AI models and solutions do not introduce entirely new categories of risk but what they do is amplify the pressure on every cybersecurity control you already have in place.
The barrier to sophisticated cyber activity is now much lower enabling even the old concept of script kiddies to conduct even more attacks at machine speed and precision. A threat actor who previously lacked the technical skill to craft a convincing spear-phishing campaign or chain together multiple vulnerabilities into a coherent intrusion now has access to AI engines that can link multiple attack vectors together and conduct nefarious missions simply based on plain English commands. In other words, the threat actor’s capability to inflict damage has been raised significantly while your organisation’s attack surface has not changed nor has your defenses been leveled up either.
ASIC’s call to action is to treat cybersecurity fundamentals as mission-critical disciplines, and in my opinion, is absolutely the right response for organisations to follow. The open letter enumerates expectations that any seasoned security practitioner will recognise.
This includes minimising the attack surface, putting governance frameworks in place, regularly reviewing user access and reassessing privileges, patching systems promptly, and implementing layered defense-in-depth architectures that assume breach and restrict lateral movement. This will ensure that you have the appropriate incident response plans in case of a worst-case scenario, and actively manage third-party risks.
These are not new recommendations. They have appeared in NIST guidance, in the Australian Signals Directorate’s (ASD) Essential Eight, and in virtually every post-incident review of a significant breach in the past decade. And yet, as ASIC observed in multiple cases, organisations continue to fail on precisely these controls, not because they lack awareness, but because they lack discipline and potentially budget which warrants a board room discussion. Governance without actionable enforcement is simply assurance without evidence.
The letter makes this point with admirable directness: governance should not rely on assurances alone. It should be supported by test results, audit findings, lessons from incidents, and independent validation. Too often, boards receive activity reports without tested proof that cybersecurity is actually working. That distinction matters enormously. A firewall that has not been tested under realistic conditions is not a control point; it is a hypothesis waiting to be stress tested.
With this in mind, one line in ASIC’s letter deserves to be pulled from the list and placed in bold on everyone’s next agenda: “regularly review user access and reassess privileges”. If you can control the privilege, you can control risk and in my opinion, this is one of the most effective strategies for mitigating AI based attack vectors. This reinforces the principle of least privilege and granting only the access necessary to perform a defined function. In the world of AI, this control is critical.
Overprivileged accounts are not just a lateral movement risk for an external attacker; they are a force multiplier for an AI-assisted attacker who can enumerate, correlate, and exploit access gaps at machine speed. Reducing the blast radius of any single compromised identity is no longer a best practice but rather a necessity when privileges are potentially overprovisioned and not properly accounted for.
Finally, ASIC’s closing instruction is unambiguous: ensure this letter is tabled and discussed at your board and risk governance committees. That is not a boilerplate recommendation but rather a regulatory expectation with legal weight and a firm call to action for everyone.
For boards and senior executives, the questions to ask are not technical. They are governance questions:
- Is our cyber capability proportionate to the threat environment we actually face today, not the one from our last review? This is especially true in light of the new capabilities threat actors possess.
- Are we receiving meaningful reporting on whether our controls are working and not just that they exist? Have we ever stress tested them?
- Do we have evidence, not just assurance, that our incident response plans have been tested against realistic scenarios?
ASIC is not asking organisations to reinvent their approach. It is asking them to put strict controls and governance in place to execute the approach they already have, with the rigour and resourcing the current threat environment demands. It is not a matter of if your controls will be tested. It is a matter of when and whether they will hold. Are you doing them well enough and can you prove it?
By Morey J. Haber, chief security officer, BeyondTrust






