September 2026 in Retrospect

News from HSF Kramer 

Cyber Risk Survey 2026

Now in its fourth year, the HSF Kramer Cyber Risk Survey draws on the views of general counsel and senior legal counsel across Australia's leading organisations to examine how legal leaders perceive, prepare for and respond to cyber risk.

The defining story of 2026 is AI. 97% of respondents are aware of how AI is changing the threat landscape, yet only 20% report a detailed understanding of those risks. Third-party risk remains the leading concern, with 62% experiencing a supply chain cyber incident in the past 12 months.

A reactive posture persists, with many organisations waiting for a catalyst before prioritising cyber governance. 59% of respondents believe it would take a cyber incident to meaningfully drive greater focus on data risk management. 

Download our survey report, or our executive summary here.

Quarterly update

Our latest quarterly update has landed, which explores the key developments shaping the cyber, privacy and AI landscape.

We are delighted to invite our network to our annual Cyber Risk Survey briefing, where we unpack this update. Briefings are taking place throughout October (in person in Brisbane, Sydney, Melbourne and Perth).

If you’re interested in participating, follow the link here to submit your interest in one of our briefings.

Cross examining cyber: The Director series 

Join us for the next chapter in our conversation with Catherine Brenner and John Mullen, covering everything from cyber incident response and communications to AI, governance and board simulations.

Listen here.

AFR Cyber Summit 2026

We were proud to once again be a Platinum Sponsor of The Australian Financial Review Cyber Summit held in Sydney. It was a fantastic opportunity to connect with many new and familiar faces and exchange ideas on the challenges shaping Australia’s cyber future.
 
A highlight was the timely panel discussion on boards, cyber risk and the rise of personal liability, featuring partner Cameron Whittfield. 

Our team also authored an AFR op-ed looking at frontier AI, the "biggest cyber risk 'trend' of 2026", which argues that while frontier AI is reshaping cyber risk, organisations shouldn't lose sight of the fundamentals. Read our op-ed here.


The HSF Kramer Cyber “Essential Eight”: 

The cyber landscape continues to evolve at pace. It can be challenging to keep up, so we have collated our “Essential Eight” cyber stories from the last month, so you don’t have to. 

A little too agentic

AI agents are meant to take care of the repetitive tasks. One OpenAI-powered agent reportedly decided to expand its remit, infiltrating the Government’s Medicare / Services Australia website after acting beyond its intended instructions. OpenAI has since apologised, acknowledging that the activity was more extensive than first understood and describing it as a "new kind of cyber incident" (although not a hack or attack). As organisations embrace agentic AI, the incident is a reminder that autonomy without guardrails can produce some very creative interpretations of the brief.

Read more here and here.

The AI arms race gets diplomatic

World leaders gathered at the UN General Assembly this month to call for greater oversight of frontier AI systems, citing concerns about national security, cyber risk and the speed of AI development. However, despite high hopes for progress following the closely watched Trump-Xi meeting, no major agreements on AI governance or international standards emerged. Everyone seems to agree that AI is powerful. Agreeing on who gets to regulate it is proving slightly more difficult.

Read more here and here.

Qinlin's back. Again. 

Qilin has reportedly claimed two additional Australian victims this month, continuing a run that has made the ransomware group one of the most active threat actors globally. This adds to a growing list of Australian organisations caught in the crosshairs of ransomware and extortion campaigns. It seems Qilin's Australian tour is showing no signs of slowing down.

Your supply chain called

Stake and Revolut have become the latest organisations to experience the joys of third-party cyber risk after a supplier compromise reportedly exposed certain customer information. This aligns with a recurring and familiar theme that your cyber security posture is only as strong as your supply chain.

Read more here.

The old and the new for the OAIC

It was a tale of two privacy stories from the OAIC this month. On the one hand, the regulator provided a further update on its ongoing investigation and representative complaint arising from the 2023 Latitude data breach. A reminder that the “long tail” of cyber incidents can last long after they've left the headlines.

On the other, the OAIC looked to the future, suggesting that trusted government data could play an important role in improving the reliability of AI systems and helping counter AI-generated misinformation. With concerns growing about inaccurate content being generated at scale, the regulator's message is refreshingly simple: better data tends to produce better outcomes.

Read more here and here.

We'll be in touch

The ACSC has warned that North Korean-linked threat actors are impersonating recruiters and targeting IT professionals with fake job opportunities. While some operators reportedly pose as recruiters, US authorities have also warned that North Korean-linked individuals have infiltrated organisations by obtaining remote IT roles under false identities.

Read more here and here.

Not so shiny anymore

ShinyHunters recently claimed responsibility for a breach of FBI systems that allegedly exposed data relating to bureau employees. However, the spotlight turned back on the hackers themselves, with Dutch police arresting a suspected member of the group. 

Read more here and here.

Have you tried turning it off?

Kiteworks issued the kind of advisory customers rarely see, urging organisations to shut down internet-facing systems while it investigated a potential security issue. The advisory was later lifted, making it a rather expensive demonstration that "have you tried turning it off and on again?" may remain surprisingly effective.

Read more here.


Peter Jones photo

Peter Jones

Partner, Head of TMT, Asia, Singapore

Merryn Quayle photo

Merryn Quayle

Managing Partner, Melbourne Office, Melbourne

Kaman Tsoi photo

Kaman Tsoi

Special Counsel, Melbourne

Heather Kelly photo

Heather Kelly

Senior Associate, Melbourne

Key contacts

Peter Jones photo

Peter Jones

Partner, Head of TMT, Asia, Singapore

Merryn Quayle photo

Merryn Quayle

Managing Partner, Melbourne Office, Melbourne

Kaman Tsoi photo

Kaman Tsoi

Special Counsel, Melbourne

Heather Kelly photo

Heather Kelly

Senior Associate, Melbourne

Rebecca Gill photo

Rebecca Gill

Senior Associate, Melbourne

Caitlyn Bellis photo

Caitlyn Bellis

Senior Associate, Sydney

Cameron Whittfield Peter Jones Christine Wong Merryn Quayle Emily Coghlan Magdalena Blanch-de Wilt Kaman Tsoi Heather Kelly Rebecca Gill Caitlyn Bellis Brooke Crenfeldt Annabelle L’Estrange