September 2026 in Retrospect
News from HSF Kramer
Cyber Risk Survey 2026
Now in its fourth year, the HSF Kramer Cyber Risk Survey draws on the views of general counsel and senior legal counsel across Australia's leading organisations to examine how legal leaders perceive, prepare for and respond to cyber risk.
The defining story of 2026 is AI. 97% of respondents are aware of how AI is changing the threat landscape, yet only 20% report a detailed understanding of those risks. Third-party risk remains the leading concern, with 62% experiencing a supply chain cyber incident in the past 12 months.
A reactive posture persists, with many organisations waiting for a catalyst before prioritising cyber governance. 59% of respondents believe it would take a cyber incident to meaningfully drive greater focus on data risk management.
Download our survey report, or our executive summary here.
Quarterly update
Our latest quarterly update has landed, which explores the key developments shaping the cyber, privacy and AI landscape.
We are delighted to invite our network to our annual Cyber Risk Survey briefing, where we unpack this update. Briefings are taking place throughout October (in person in Brisbane, Sydney, Melbourne and Perth).
If you’re interested in participating, follow the link here to submit your interest in one of our briefings.
Cross examining cyber: The Director series
Join us for the next chapter in our conversation with Catherine Brenner and John Mullen, covering everything from cyber incident response and communications to AI, governance and board simulations.
Listen here.
AFR Cyber Summit 2026
We were proud to once again be a Platinum Sponsor of The Australian Financial Review Cyber Summit held in Sydney. It was a fantastic opportunity to connect with many new and familiar faces and exchange ideas on the challenges shaping Australia’s cyber future.
A highlight was the timely panel discussion on boards, cyber risk and the rise of personal liability, featuring partner Cameron Whittfield.
Our team also authored an AFR op-ed looking at frontier AI, the "biggest cyber risk 'trend' of 2026", which argues that while frontier AI is reshaping cyber risk, organisations shouldn't lose sight of the fundamentals. Read our op-ed here.
The HSF Kramer Cyber “Essential Eight”:
The cyber landscape continues to evolve at pace. It can be challenging to keep up, so we have collated our “Essential Eight” cyber stories from the last month, so you don’t have to.
![]() | A little too agenticAI agents are meant to take care of the repetitive tasks. One OpenAI-powered agent reportedly decided to expand its remit, infiltrating the Government’s Medicare / Services Australia website after acting beyond its intended instructions. OpenAI has since apologised, acknowledging that the activity was more extensive than first understood and describing it as a "new kind of cyber incident" (although not a hack or attack). As organisations embrace agentic AI, the incident is a reminder that autonomy without guardrails can produce some very creative interpretations of the brief. |
![]() | The AI arms race gets diplomaticWorld leaders gathered at the UN General Assembly this month to call for greater oversight of frontier AI systems, citing concerns about national security, cyber risk and the speed of AI development. However, despite high hopes for progress following the closely watched Trump-Xi meeting, no major agreements on AI governance or international standards emerged. Everyone seems to agree that AI is powerful. Agreeing on who gets to regulate it is proving slightly more difficult. |
![]() | Qinlin's back. Again.Qilin has reportedly claimed two additional Australian victims this month, continuing a run that has made the ransomware group one of the most active threat actors globally. This adds to a growing list of Australian organisations caught in the crosshairs of ransomware and extortion campaigns. It seems Qilin's Australian tour is showing no signs of slowing down. |
![]() | Your supply chain calledStake and Revolut have become the latest organisations to experience the joys of third-party cyber risk after a supplier compromise reportedly exposed certain customer information. This aligns with a recurring and familiar theme that your cyber security posture is only as strong as your supply chain. Read more here. |
![]() | The old and the new for the OAICIt was a tale of two privacy stories from the OAIC this month. On the one hand, the regulator provided a further update on its ongoing investigation and representative complaint arising from the 2023 Latitude data breach. A reminder that the “long tail” of cyber incidents can last long after they've left the headlines. On the other, the OAIC looked to the future, suggesting that trusted government data could play an important role in improving the reliability of AI systems and helping counter AI-generated misinformation. With concerns growing about inaccurate content being generated at scale, the regulator's message is refreshingly simple: better data tends to produce better outcomes. |
![]() | We'll be in touchThe ACSC has warned that North Korean-linked threat actors are impersonating recruiters and targeting IT professionals with fake job opportunities. While some operators reportedly pose as recruiters, US authorities have also warned that North Korean-linked individuals have infiltrated organisations by obtaining remote IT roles under false identities. |
![]() | Not so shiny anymoreShinyHunters recently claimed responsibility for a breach of FBI systems that allegedly exposed data relating to bureau employees. However, the spotlight turned back on the hackers themselves, with Dutch police arresting a suspected member of the group. |
![]() | Have you tried turning it off?Kiteworks issued the kind of advisory customers rarely see, urging organisations to shut down internet-facing systems while it investigated a potential security issue. The advisory was later lifted, making it a rather expensive demonstration that "have you tried turning it off and on again?" may remain surprisingly effective. Read more here. |
Cameron Whittfield
Partner, Melbourne
Peter Jones
Partner, Head of TMT, Asia, Singapore
Christine Wong
Partner, Sydney
Merryn Quayle
Managing Partner, Melbourne Office, Melbourne
Emily Coghlan
Partner, Melbourne
Magdalena Blanch-de Wilt
Executive Counsel, Melbourne
Kaman Tsoi
Special Counsel, Melbourne
Heather Kelly
Senior Associate, Melbourne
Key contacts
Cameron Whittfield
Partner, Melbourne
Peter Jones
Partner, Head of TMT, Asia, Singapore
Christine Wong
Partner, Sydney
Merryn Quayle
Managing Partner, Melbourne Office, Melbourne
Emily Coghlan
Partner, Melbourne
Magdalena Blanch-de Wilt
Executive Counsel, Melbourne
Kaman Tsoi
Special Counsel, Melbourne
Heather Kelly
Senior Associate, Melbourne
Rebecca Gill
Senior Associate, Melbourne
Caitlyn Bellis
Senior Associate, Sydney
Brooke Crenfeldt
Solicitor, Sydney
Annabelle L’Estrange
Solicitor, Sydney
Disclaimer
The articles published on this website, current at the dates of publication set out above, are for reference purposes only. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action.







