James Henderson

When threats accelerate, budgets tighten and risk appetite shifts

Whether small, medium or large, businesses are facing an increasingly uncomfortable reality – attackers are moving faster, AI is accelerating vulnerability discovery and ransomware groups continue to evolve.

Yet many Australian organisations are entering FY27 under pressure to control costs, extend solution lifecycles and extract more value from existing technology investments.

According to Cisco Talos – the threat intelligence arm of Cisco – the gap between attacker capability and organisational readiness continues to widen.

The challenge is not simply security, however. It is economics.

Cisco Talos analyses almost 900 billion security events every day from approximately 46 million devices across 193 countries and 46 languages, providing one of the industry’s broadest views of attacker behaviour.

That breadth of visibility means Cisco Talos is not simply observing isolated attacks, rather tracking how attacker behaviour is changing across industries, regions and attack techniques at global scale.

Carl Solder (Cisco), Amy Henderson (Cisco Talos) and Matt Olney (Cisco Talos)

The latest research points to a threat landscape increasingly shaped by technical debt, ageing infrastructure, identity attacks and AI-driven acceleration. For many organisations, however, the problem is not recognising those risks, rather finding the financial and operational capacity to respond.

“Three major themes emerged in 2025 that have continued into 2026,” shared Amy Henderson, Senior Director of Strategy and Operations at Cisco Talos.

“Firstly, attackers are moving faster than ever. Secondly, threat actors are increasingly targeting identity infrastructure rather than simply stealing passwords. Thirdly, state-sponsored actors and cyber criminals are increasingly targeting network infrastructure and centralised management platforms.”

Attackers moving faster than businesses can respond


If there is one theme that defines the current threat landscape, it is speed. One of the clearest examples of accelerated malicious activity was the widespread exploitation of the Log4Shell vulnerability, first uncovered more than four years ago.

“One of the things that has absolutely changed is the speed and persistence at which attackers mobilise,” Henderson added.

That acceleration is evident across almost every aspect of modern cyber crime, from ransomware operations through to vulnerability exploitation.

“The proof of concept for Log4Shell was available around 30 hours after disclosure,” said Matt Olney, Senior Director of Threat Intelligence and Interdiction at Cisco Talos. “Our data currently shows that the mean time for vulnerabilities that are weaponised is 10 hours.”

10 hours.

That is now the average time between a vulnerability becoming publicly known and attackers developing the capability to exploit it.

For defenders, the challenge is obvious.

“One important point is the mismatch between attacker speed and defender speed,” cautioned Carl Solder, CTO of Australia and New Zealand (A/NZ) at Cisco.

“Because the reality is that most organisations take weeks, sometimes months, quarters to patch systems. That creates a significant exposure window meaning boards and risk committees are now having serious conversations about risk appetite.”

That widening gap between attacker speed and organisational response is becoming one of the defining security challenges for technology and security leaders.

But the speed of exploitation is only one part of the problem.

Increasingly, attackers are targeting software supply chains, compromising trusted software before malicious code is distributed downstream to hundreds – or even thousands – of customers.

Olney pointed to Log4Shell as an example.

“It continues to be used,” he said. “It is a popular initial access vector for supply chain attacks to get into repositories, subsequently infect those repositories and then push those changes downstream to all the customers of that company.”

For security teams already struggling to keep pace with patching cycles, supply-chain compromise introduces another layer of complexity because the attack may originate inside software they already trust.

At the same time, AI is dramatically reducing the effort required to build sophisticated offensive capabilities. Olney highlighted one example analysed by Cisco Talos.

“We came across a piece of malware that we call VoidLink,” he explained.

“It was developed through an AI-enabled development platform. Looking at what they’d done, they began coding in late November 2025 and by the end of 2025 there were 88,000 lines of code. We estimate this development would have taken a team about 30 weeks to build.”

The implication is clear.

AI is no longer simply helping organisations defend themselves more efficiently. It is helping attackers develop tools, automate processes and compress development timelines at unprecedented speed.

Growing burden of technical debt


While speed alone presents a severe hurdle for organisations to mount – combined with ageing infrastructure, the task of protecting the enterprise has become considerably more challenging.

According to Cisco Talos, the top 10 most targeted vulnerabilities of 2025 revealed a threat landscape driven by speed, scale and the continued exploitation of long-standing weaknesses.

The list blended newly discovered, rapidly weaponised flaws – such as the React2Shell and ToolShell vulnerabilities – with older, deeply embedded vulnerabilities like PHPUnit and Log4j that attackers continue to exploit at high volume.

Together, these CVEs illustrate how adversaries combine opportunistic scanning, automated exploitation and supply-chain fragility to consistently compromise exposed systems.

Carl Solder (Cisco)

According to Cisco Talos, 40% of the top 100 targeted vulnerabilities during 2025 affected end-of-life systems while 32% of vulnerabilities are at least 10 years old. These are not systems approaching retirement, rather systems that can no longer receive security patches.

Olney believes that figure is unlikely to improve.

“I would absolutely expect that number to rise,” he predicted.

“We’ve seen a substantial increase in vulnerability discovery, particularly as AI is increasingly used to identify weaknesses. Attackers prefer end-of-life systems because they typically have weaker protections, are less likely to run modern security controls and are well understood from an exploitation perspective.”

For Olney, the end-of-life challenge extends well beyond a narrow technology stack.

“There are software vulnerabilities – such as in Microsoft Office – that are more than a decade old that remain actively exploited today,” he continued.

“We also continue to see ageing routers, switches, servers, firewalls and load balancers operating in production environments. Many sit on network perimeters and remain in service because replacing them is difficult and disruptive.”

For many organisations, replacing those systems is neither simple nor inexpensive.

“As an engineer, you think that’s awesome – my product is still doing its thing after all these years,” Solder said. “But now that represents a severe risk exposure for organisations.”

The result is that infrastructure refresh programs are becoming strategic business decisions rather than purely technical exercises.

“Organisations are now having to think about their risk appetite of leaving those devices as is, or do they have to make changes?” Solder said. “Those conversations are happening at the board level across many companies right now.”

For Solder, attitudes are already changing across Australia.

“In the past maybe it wasn’t a higher focus item, but in this post-Mythos world, absolutely, the lens is now being applied on that,” he assessed.

Ultimately, organisations are being forced to choose between three options.

“The reaction from organisations from a risk standpoint is: do we just leave it in place and wear the risk? The second is to upgrade. The third is what could you do to provide isolation for that thing.”

Each option carries financial, operational and security consequences. The challenge is determining which compromise carries the least risk.

“Our recommendation is that organisations upgrade,” Solder confirmed.

“However, budget constraints and risk tolerance ultimately determine the path they take. Many organisations are now reassessing whether maintaining those risks is acceptable.”

Why manufacturing is now a primary target


The impact of technical debt is perhaps most visible within manufacturing. Cisco Talos identified this as the most targeted industry for ransomware activity during 2025, overtaking healthcare after several years at the top of the list.

Unsurprisingly, the reasons are largely operational.

Manufacturing remains a persistently vulnerable industry vertical for ransomware attacks as organisations have very low downtime tolerance and operate hybrid environments that incorporate both IT and OT systems – thereby expanding the attack surface.

Also, businesses within this sector often have “less robust cyber security budgets” compared to other industries such as financial services, and rely on insecure legacy equipment and/or software.

“Manufacturing’s reliance on OT and its limited tolerance for downtime make it an attractive target for ransomware operators,” Henderson observed.

Unlike many office-based environments, manufacturing organisations often rely on OT that cannot simply be rebooted, patched or replaced without affecting production.

For Solder, that reality fundamentally changes the security equation.

“The reality is that in a manufacturing world there’s a heavy reliance on OT,” he expanded.

“OT is an area that attackers focus on because that OT typically is using solutions which are old or they’re very difficult to patch or they’re very difficult to upgrade.”

While modern IT environments have largely adopted mature patching and lifecycle management practices, OT often remains constrained by production requirements, compatibility concerns and long replacement cycles.

“Defending an organisation is already challenging,” Solder outlined.

“Defending OT environments is even harder because those systems don’t always support traditional IT security practices.

“Threat actors know this and specifically target those environments. That’s why manufacturing and other critical infrastructure sectors continue to attract significant attention from attackers because it only takes one oversight, one small crack in your defence.”

Amy Henderson (Cisco Talos)

That observation reinforces an important point – the challenge facing manufacturers is no longer simply cyber security but operational resilience. Keeping production running has become inseparable from protecting the systems that enable it.

“Many critical infrastructure regulations historically focused on physical safety,” Olney added.

“Cyber security requirements have often been introduced later. As a result, regulatory maturity differs substantially between sectors and jurisdictions.”

Identity becomes cyber security’s new battleground


Ransomware remained a dominant threat to enterprises globally in 2025, driven by operators continuously evolving their tactics, techniques, and procedures (TTPs) to enhance ransomware-as-a-service (RaaS) capabilities and intensify pressure on victims.

“Ransomware remains a major concern,” Henderson cautioned. “While threat actors are increasingly using AI to accelerate activity, one of the most notable developments in 2025 was a change in the dominant ransomware groups.”

LockBit, which led activity in 2024, declined significantly following law enforcement action and internal disruption. The most active ransomware group tracked was Qilin, which averaged more than 40 victims per month posted to its leak site.

“One interesting trend is seasonality,” Henderson highlighted.

“January consistently records the lowest ransomware activity levels. We also see notable spikes around back-to-school periods and tax seasons.

“We can also observe the impact of law enforcement activity. When infrastructure associated with major ransomware groups is disrupted, activity temporarily declines before operators regroup and resume operations.”

While ransomware continues to dominate headlines, Cisco Talos cited identity infrastructure as one of the most valuable targets for sophisticated threat actors.

“Threat actors are increasingly targeting identity systems,” Henderson expanded.

“They’re no longer focused solely on usernames and passwords. They’re targeting the underlying trust infrastructure, including SSH tokens, Kerberos tokens and identity and access management platforms.”

According to Cisco Talos, 30% of multi-factor authentication attacks targeted identity and access management applications themselves rather than the users they support. That reflects a broader evolution in attacker behaviour.

“The infrastructure that is managing trust across your network really is going to be a target,” Henderson added.

“As AI agents become more common, identity will extend beyond humans to include machine and agent identities. The same trust systems we use for people will increasingly be used for AI agents, creating new opportunities for attackers.”

Identity now sits at the centre of modern enterprise trust.

Rather than attacking individual devices, threat actors are increasingly targeting the systems responsible for authenticating users, applications and services across entire organisations.

For Olney, this reflects a deliberate change in strategy.

“As exploit development becomes more difficult, attackers increasingly target identity instead,” he said. “State-sponsored actors have specifically targeted routers and network infrastructure because they often use separate identity systems.

“By compromising those systems, attackers can monitor traffic, redirect communications, manipulate DNS services and conduct espionage activities. Identity has become one of the most important battlegrounds in cyber security.”

AI creates new attack surface


In 2025, Cisco Talos’ observations show that AI was more commonly used to automate or augment discrete parts of traditional attacks.

This is especially true for social engineering. AI lowers the barrier of entry for novice attackers to employ more convincing social engineering techniques, such as easily generating phishing sites at the click of a button.

At the same time, it also raises the ceiling for the operations of more advanced actors, such as APTs leveraging deepfake technology to secure employment at a target organisation.

“Agentic AI introduces entirely new attack vectors,” Olney explained.

“Examples include prompt injection, goal hijacking, agent runtime abuse, tool manipulation, memory poisoning and host environment compromise. These are fundamentally different from traditional security challenges.

“Organisations need to understand not only how AI agents function but also how they can be manipulated. The principle remains the same: limit permissions, control access and minimise blast radius if a compromise occurs.”

In parallel, identity is also changing and extending beyond people.

“Identity doesn’t just mean human anymore,” Henderson continued.

“It is going to mean agentic identity as well. How we’re protecting those agents using the same infrastructure that we protect human agents right now is the same concept.”

Matt Olney (Cisco Talos)

That evolution introduces an entirely new category of cyber security challenges given that Cisco Talos researchers have identified the emerging attack techniques likely to shape the next-generation of AI security.

The concern is not simply protecting AI systems themselves but ensuring those systems cannot be manipulated into making decisions they were never intended to make.

“Threat actors are already attacking human identity,” Henderson noted. “It’s going to be interesting to see how they use this to attack agentic identity.”

Meanwhile, Solder views the challenge from two equally important directions.

“There are two angles to the security conversation around agents,” he said. “Protecting the world from agents and protecting agents from the world.”

In other words, organisations must protect AI systems from compromise while also ensuring compromised AI systems cannot create broader business risk.

“You don’t want somebody to be able to compromise an agent and then have it go off and start doing things it’s not supposed to do,” Solder added. “AI is now the new attack surface.”

Security becomes an exercise in prioritisation


The most significant finding from Cisco Talos is not that cyber threats are increasing – security leaders already understand that.

Perhaps the bigger challenge is that threats are accelerating at exactly the same time organisations are facing increasing pressure to justify investment, manage ageing infrastructure and make difficult decisions about technology refresh.

Attackers can weaponise vulnerabilities within hours.

AI is helping identify vulnerabilities and accelerate malware development – 40% of the most exploited vulnerabilities affect systems that can no longer be patched.

Manufacturing environments continue to rely on OT that was never designed for today’s threat landscape. Identity infrastructure has become a primary target.

And AI is creating entirely new attack surfaces before many organisations have fully secured existing ones.

Against that backdrop, Olney believes organisations should resist chasing every new security trend before addressing the foundational requirements.

“Ultimately, organisations need strong security fundamentals,” he noted.

“You need to understand what you’re protecting, assess risk properly and make informed investment decisions. The answer isn’t always consolidation. The answer is making thoughtful decisions based on your organisation’s risk profile. You have to identify your core treasure that you’re trying to protect and build out from there.”

That may be the most important lesson from the latest Cisco Talos research. Cyber security is no longer a question of simply deploying more technology. Nor is it a question of eliminating every possible risk.

As threats accelerate, budgets tighten and attack surfaces continue to expand, security leaders are increasingly being asked to make business decisions rather than technology decisions – understanding which assets matter most, where risk can realistically be accepted and how to allocate finite investment where it will have the greatest impact.

In an environment where organisations can no longer protect everything equally, prioritisation has become one of the most important security capabilities of all.

SIGN UP FOR INSIGHTS VIA MOXIE MAIL

Inform your opinion with executive guidance, in-depth analysis and business commentary.