WEBINAR SERIES: Three cyber security questions every business owner has to answer.

Danet Website Banner

30 SEPT, 28 OCT, 25 NOV | 1:00PM - 1:40PM AEDT

Online Format | Join us via Microsoft Teams

Three questions every business has to answer

Who is trying to access your business? What are they able to reach once they are in? And are they using a safe device to do it? Strong cyber security is not one thing. It is these three critical elements working together, and cyber security lives where they overlap.

Why attend all three
Identity, Data and Endpoint answer who, what and do we have safe devices. Ensure you watch all three to understand your cyber security position.

One sign up registers you for the three sessions
Register once and we take care of the rest, we’ll sign you up to all three. Turn up over lunch and we will send everything else to you.

The full picture
Each session stands on its own, together they give you a complete, map of where your business is strong and where it is needs some work.

What you'll walk away with

blank
blank
blank

September 30th: Identity Protection

Who is trying to access your business?  We cover changes coming to multifactor authentication through the use of Passkeys. We explain how your systems are able to verify that you are the person you’re claiming to be, what is single-sign-on and what are the security benefits.

You will leave with: a short identity checklist you can run against your own firm this week.

October 28th: Data Protection

What is encryption? We cover knowing where your information lives, deciding who should see it, keeping secure backups, and preventing information being accidentally shared or lost.

You will leave with: a simple map of the data lifecycle and what you should be concerned with at each stage.

November 25th: Endpoint Protection

Are they using a safe device? What is the meaning of having a compliant device and how does the mobile device management assist with this.

You will leave with: a device readiness checklist for laptops, phones and servers, plus the full three pillar picture.

Webinar Format will be a 40 minute lunch and learn

Forty minutes, designed to fit a lunch break. Daniel opens talking on the topic and why it matters to your business.

He is then joined by a guest expert for a relaxed conversation on real business risks and what good looks like. The last ten minutes are yours, for live questions.

blank

Can’t make it live?
Register anyway. Every session is recorded and sent to you, along with its takeaway checklist, so you never miss out.

Who it is for
The series is open to Danet clients, prospective clients and new guests. Whether you are reviewing your current setup or starting from scratch, you will leave with something practical.

Save your seat
Register once for all three sessions. We will send the calendar invitations, reminders and replays.

SAVE YOUR SEAT AT THIS WEBINAR SERIES

30 SEPT, 28 OCT, 25 NOV | 1:00PM – 1:40PM AEDT

What APRA’s AI Letter Signals for Every Regulated Business

blank

What APRA's AI Letter Signals for Every Regulated Business

blank

In April 2026, APRA wrote to industry with a message that was hard to misread. It called for a step-change in how banks, insurers and superannuation trustees manage the risks that come with artificial intelligence, warning that governance, risk management, assurance and operational resilience are not keeping pace with how quickly AI is being adopted.

The letter followed a targeted review of some of the country’s largest financial institutions. While it is directed at APRA-regulated entities, the observations read like a checklist for any organisation now weaving AI into everyday work. The themes are familiar to anyone who has watched a new technology move faster than the structures built to govern it.

Here is what the letter actually says, and why it matters well beyond the entities it was addressed to.

Adoption is racing ahead of governance

APRA found that every entity it engaged with is actively adopting AI, and many are moving beyond internal productivity experiments into customer facing uses such as claims triage, loan processing, fraud detection and customer interaction.

Governance has not matured at the same speed. APRA noted a tendency to treat AI risk as just another technology, which misses what makes AI different. Models can adapt over time, produce unpredictable outputs and carry considerations such as bias and data handling that traditional systems do not. The result is gaps across the AI lifecycle, particularly in monitoring how models behave once they are deployed.

At board level, APRA observed strong enthusiasm for the benefits of AI, but also that many boards are still building the technical literacy needed to challenge and oversee AI decisions. In some cases there was an overreliance on vendor presentations rather than independent examination of the risks.

AI is changing the cyber threat landscape

The letter is clear that AI is not only a productivity story. It is also reshaping how organisations are attacked.

APRA pointed to new attack pathways, including prompt injection, data leakage through AI tools, insecure integrations and the misuse of autonomous AI agents. AI can shorten the attack cycle, allowing incidents to move with more speed and coordination than before.

One observation deserves particular attention as adoption grows. Identity and access controls in many organisations have not yet adjusted to non-human actors, such as AI agents that can act inside systems on a user’s behalf. At the same time, staff use of AI tools outside approved control frameworks remains a concern, with many organisations relying on policy rather than enforceable technical controls.

Supplier concentration and opacity are real risks

APRA observed some entities heavily dependent on a single provider for multiple AI use cases, often without tested exit or substitution plans. Because AI capability is increasingly embedded inside software and platforms, the upstream dependencies, such as foundation models and the data behind them, can be opaque. That makes it harder for an organisation to independently assess how a model performs, where its data goes and how resilient it is.

blank
blank

Assurance built for static systems is not enough

Traditional change management and point-in-time assurance were built for systems that behave the same way each time. APRA noted these methods are ill-suited to probabilistic models that learn, adapt and degrade over time, and that few entities had continuous monitoring in place to detect issues such as model drift. Internal audit and risk functions were often found to lack the specialist skills and tooling to assess AI systems.

What APRA expects

Underneath the observations, APRA set out clear expectations. At a minimum, entities should

  • Maintain board and executive literacy sufficient to set strategic direction and provide genuine challenge on AI risk.
  • Run an AI strategy aligned to the organisation’s risk appetite, supported by monitoring and reporting.
  • Keep an inventory of AI tooling and AI use cases.
  • Assign ownership and accountability across the AI lifecycle, from design through to decommissioning.
  • Keep people involved in high-risk decisions.
  • Train staff on AI use, misuse, limitations and secure practices.
  • Map the full AI supply chain, including third and fourth-party dependencies.
  • Apply continuous, integrated assurance across security, data governance, model performance and privacy.

APRA also signaled that where entities fail to manage AI risks proportionately, it will take stronger supervisory action and, where appropriate, pursue enforcement.

Why this matters beyond APRA-regulated entities

APRA regulates banks, insurers and superannuation trustees. Financial advice licensees sit under ASIC, which delivered a strikingly similar message in its own May 2026 letter describing cyber resilience as being at a minute to midnight and stressing that boards must be able to evidence that controls are actually working, not just designed.

Two regulators, weeks apart, landed on the same point. AI adoption is moving faster than governance, and the expectation is shifting from intent to evidence.

Where to start

For most organisations, the honest starting point is simpler than a strategy document. It is visibility.

Many businesses cannot yet answer a basic question: where is AI already being used across the organisation, including the AI features quietly switched on inside the software we already run? Building that inventory is where responsible adoption begins. From there, the familiar disciplines apply. Align access to what each person, and each agent, genuinely needs. Keep people accountable for high-risk decisions. Make sure the information AI can reach is well organised and governed underneath.

That last point is where much of the real work sits. Tools like Microsoft Copilot operate on the information users already have access to, which means the value they deliver, and the risk they carry, is shaped by how well that environment is structured. For many organisations, AI is not creating new governance questions so much as bringing existing ones into sharper focus.

At Danet, this is the conversation we are having with clients across regulated industries. Not whether to adopt AI, but how to build the visibility, identity controls and information governance that let an organisation adopt it with confidence.

If your organisation is working through what responsible AI adoption looks like in practice, get in touch.

Sources

APRA, Letter to Industry on Artificial Intelligence (published 30 April 2026): https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai

ASIC, open letter on cyber resilience and AI (May 2026), as summarised by Clayton Utz, “The clock is at a minute to midnight”: “The clock is at a minute to midnight”: ASIC’s ope… | Clayton Utz

ASIC, Cyber resilience regulatory resources: Cyber resilience | ASIC

Australian Signals Directorate (ASD), Annual Cyber Threat Report 2024-25 (context on the evolving threat environment): https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

AI & Actionable Insights in 2026 Guide for AFSL Holders

AI & Actionable Insights in 2026 Guide for AFSL Holders

blank

Download the guide

AI & Actionable Insights in 2026

A 5 minute read for Australian financial services executives. Covers Danet’s survey of financial services firms, the account type rule, four risk areas, and three executive moves for the next month.

Your team is using artificial intelligence today, in tools you may or may not have approved. Inside a regulated financial services firm, that creates new questions about client privacy, supplier risk, and the version of every Microsoft, Google or OpenAI product your staff are actually logged into.

Written for executives, read in five minutes, designed to be forwarded to your information technology partner or compliance lead.

Whats Inside

  • Headline findings from the Danet Artificial Intelligence Experience & Insights Survey
  • The 5 AI tools your team is most likely already using
  • The account type difference: personal, enterprise and tenant bound Microsoft 365 Copilot Chat
  • The 4 risk areas specific to a regulated financial services firm
  • The 3 executive moves for the next 30 days

Cyber & RG104 Guide for AFSL Holders

Cyber & RG104 Guide for AFSL Holders

blank

Download the guide

Meeting Your RG 104 Obligations.

A 5 minute read for Australian financial services executives. Covers the four RG 104 obligation areas, the five foundational controls, a 90 day plan, and nine questions for your IT partner.

Written for executives, read in five minutes, designed to be forwarded to your information technology partner or compliance lead.

Whats Inside

  • The 4 RG 104 obligation areas and the section 912A duty behind them
  • The 5 foundational cyber controls mapped to RG 104.100’s 10 review criteria
  • 30 / 30 / 30 day plan: assess, remediate and evidence
  • The 9 questions to put to your information technology partner
  • Recent ASIC enforcement: RI Advice, FIIG Securities, ASIC supervisory posture

How AI hallucinations could land for AFSL holders

blank

How AI hallucinations could land for AFSL holders

blank

With 90% of industry leaders believing AI will improve service and efficiency in their firms,attention is now turning to how this technology is integrated into everyday workflows, and how its behaviour shapes outcomes.

A specific pattern emerging is AI hallucinations, where AI recognises objects or patterns that don’t exist or that humans are unable to see.

The problem with this? Inaccurate, invented responses, with no supporting evidence or insight, and errors hard to detect due to the confidence AI responds with.

AI is going to be part of every Australian financial services organisation, the right approach is choosing the version that protects your client data.

AI hallucinations in the real world

In 2023, AI hallucinations appeared in the legal case of Mata v. Avianca. An attorney was representing an injury claim for a client, using ChatGPT this produced references that did not exist in the legal research.

It also falsely claimed the references came from a reputable legal database, revealing how far AI can go in producing inaccurate outputs.

The knowledge base AI utilises continued to be undermined. From 2023-2025, cases like these kept emerging, with judges worldwide issuing hundreds of filings, 90% of them in 2025 alone.

For AFSL holders, in a Statement of Advice, this can land as AI-generated errors appearing as verified content, which risks consumers being misled by incorrect facts and insights.

Why this matters to AFSL holders

AFSL holders need to ensure that consumers aren’t unethically treated through vulnerability exploitation and potential AI bias.

The accuracy of insights and facts produced to consumers must also oblige ensuring AI information isn’t misleading, unexplained, or inaccurate.

Under directors’ duties, responsibilities must be undertaken carefully and diligently when considering reliance on information from AI and the risk that it holds.

Without upholding these obligations, an uncaught hallucination in a Statement of Advice, client email or compliance file note becomes an AFCA complaint, a breach report, and a remediation bill the licensee carries.

A confident approach to AI

For AFSL holders to ensure they can meet these obligations, Microsoft 365, specifically Microsoft Copilot, is a safe way to implement AI. Designed specifically for enterprise, Copilot operates within an organisation’s tenant.

The benefits of Microsoft 365 involve:

Data protection and strict permissions: Adheres to an organisation’s existing data permissions and information, no exposure of organisational data to train the public AI model.

Automated compliance:Finds regulatory changes and prepares for audits, allowing adherence to compliance standards.

Microsoft purview:Prevents unauthorised data sharing, monitors AI prompts, and classifies sensitive data.

Many organisations already have these capabilities within their environments, they just haven’t been optimised yet. For financial services organisations, accuracy can be enhanced through role-specific AI agents, allowing for automated data reconciliation.

Reliable and permitted outputs can also be achieved through a strong SharePoint architecture and governed data access, allowing Copilot to search through categories.

The next 3 steps

There are a series of steps AFSL holders can take to ensure continued confidence within their environments.

  1. Embed Copilot through existing applications and actively update databases
  2. Ensure data governance through implementing restrictions and Microsoft Purview
  3. Updating policies around AI that mandate human review

These measures ensure Copilot can function optimally in your environment while maintaining data and access governance supported by updated AI policies.

Why Danet

With AI being part of how financial services will operate in 2026 and beyond, hallucinations will progressively surface.

Those who move first with the right version of AI will benefit from the productivity without the privacy risk.

Danet works with organisations to align Microsoft 365 and Copilot to their environments to ensure confidence and compliance with the use of AI, through designing and continuing to update the structures of databases and workflows.

These themes are further explored in Danet’s AI Guide for AFSL Leaders, determining how AI capabilities can be implemented into Microsoft 365 environments and how governance oversight shapes this.

A new phishing pattern in Microsoft 365

blank

A new phishing pattern in Microsoft 365

blank

 As work becomes more connected within Microsoft 365, attackers are adapting their methods to reflect that connectivity.

A pattern now emerging involves compromised Microsoft accounts and legitimate Microsoft SharePoint file sharing. Rather than relying on suspicious links or external impersonation, the technique operates within trusted channels that employees use every day.

Understanding how this works supports both technical response and user awareness.

How the method works

This technique follows a structured sequence:

  1. A legitimate Microsoft account is compromised. Access may have been obtained through credential reuse, earlier phishing, or password exposure.
  2. The attacker uses Microsoft SharePoint to share a genuine file from that real account. The recipient receives a standard SharePoint notification from a recognised contact.
  3. When the file is opened, a Microsoft sign-in prompt appears. The prompt mirrors the usual Microsoft authentication experience.
  4. If credentials are entered, access extends further.

At that point, the attacker is operating inside the organisation’s Microsoft 365 environment as a legitimate user. Collaboration patterns continue as normal, which allows exposure to expand through routine sharing.

This pattern is often described as a secondary attack. Even when most employees act carefully, a single compromised identity can create a downstream impact through everyday workflows.

Why this spreads quickly

Microsoft 365 is intentionally designed to support connected work. Within that environment, Microsoft SharePoint governs how information is shared, Microsoft Teams structures collaboration in shared digital spaces, and Microsoft Outlook sustains communication across the organisation.

These capabilities are central to productivity. When an attacker operates from a legitimate account, the same collaborative design that supports productivity also supports internal movement. Within that environment:

  • File shares appear consistent with normal collaboration
  • Authentication prompts align with expected workflows
  • Access extends through established trust relationships

The compromised identity carries organisational credibility, allowing activity to continue without immediate suspicion.

Where AI changes the equation

The introduction of AI capabilities such as Microsoft Copilot adds another dimension to this pattern.

Microsoft Copilot surfaces insight based on existing permissions across Microsoft 365, reflecting the structure and governance already in place. When identity controls align with role accountability and information architecture is clearly defined, AI supports productivity within those boundaries. Visibility within the environment is shaped directly by how access has been configured.

AI also influences how phishing techniques continue to develop. Generative tools allow attackers to produce communication that reflects organisational language and context. Messages can align closely with current projects or recent activity, which reduces obvious inconsistencies in tone or workflow.

Once access is established, AI-driven tools can assist with navigating large volumes of information or identifying high-value content more efficiently. This places greater emphasis on maintaining well-defined access boundaries and regularly reviewing how permissions are assigned within Microsoft Modern Workplace.

As organisations expand their use of AI, the relationship between Microsoft Modern Workplace design and responsible AI adoption becomes increasingly interconnected.

What to watch for

User awareness remains one of the most effective safeguards.

Pause when you notice:

  • A Microsoft SharePoint file share arriving without prior context
  • An authentication prompt appearing outside your usual workflow
  • A request from a known contact that feels inconsistent with recent activity

Verification through an alternate communication channel is a simple and effective control. Taking a moment before entering credentials can interrupt the progression of secondary compromise.

Strengthening the structural response

Key areas for review include:

  • Conditional access configuration within Microsoft Entra ID
  • Multi-factor authentication coverage
  • Microsoft SharePoint external sharing settings
  • Monitoring for unusual sign-in behaviour

These measures are not about limiting collaboration. They ensure that identity, access, and sharing controls remain aligned as Microsoft 365 usage expands and new technologies are introduced.

Cyber awareness training should also evolve to reflect that phishing techniques now operate within trusted platforms, instead of solely through external email campaigns.

A connected environment requires connected awareness

As work becomes more integrated within Microsoft 365, phishing techniques increasingly reflect that integration. Effective defence combines disciplined identity governance with users who recognise how trust can be leveraged within connected environments.

Designing and maintaining that structure requires a deep understanding of identity architecture, Microsoft SharePoint governance, access control design, and information protection within Microsoft 365.

Danet works with organisations to align Microsoft Modern Workplace environments to operational requirements and security standards, ensuring collaboration remains seamless while governance remains embedded.

Connected work brings opportunity. With considered design and ongoing oversight, organisations can support secure collaboration, responsible AI adoption, and sustained growth.

Microsoft Modern Workplace

blank
blank

Secure collaboration designed for growth

Microsoft Modern Workplace is often described as a productivity solution.  In addition,  Microsoft Modern Workplace is a governance and security framework that defines how your organisation controls identity, manages information and enables collaboration.   Many businesses operate within Microsoft 365, yet few have intentionally designed the underlying structure that  determines how securely documents are shared, how permissions are assigned and how sensitive data is protected. 

blank

Modern workplace starts with identity

At its core, Microsoft Modern Workplace is built on identity.

Every login, every device, every document access request begins with verifying who the user is and what they are authorised to do. When identity is structured, access aligns with role and responsibility. Conditional access policies assess device health and location and multifactor authentication strengthens verification to create an environment that is secure by design. Without strong identity architecture, collaboration tools may function, but governance is fragile.

Thedocumentjourneyinside Microsoft 365

Every organisation relies on shared documentation. Throughout that journey, multiple edits occur and multiple opinions are incorporated.

A proposal is drafted -> stakeholders provide input -> revisions are made -> approvals are granted -> the final version is archived.

If the environment lacks structure, that process quickly creates risk.

  • Versions circulate in inboxes
  • Sensitive information may be copied into new documents
  • Access permissions expand informally
  • Ownership becomes unclear.

In a properly designed Microsoft Modern Workplace, that same document journey unfolds within a governed structure.

  • SharePoint libraries are organised around business functions.
  • Version history is automatic
  • Co-authoring happens in real time without duplicating files
  • Access is role based rather than manually granted
  • Sensitive content can be labelled and restricted at the document level.

The result is collaboration that remains fluid while control remains intact. A structured SharePoint environment establishes logical site architecture aligned to departments, projects or client groups. It defines document ownership, controls internal and external sharing and maintains audit trails and retention policies.

Protecting sensitive information through labels and access controls

Microsoft 365 includes powerful information protection capabilities that are often underutilised. Sensitivity labels, data loss prevention policies and role based access controls allow governance to operate automatically in the background.

These controls can:

  • Restrict confidential documents from being forwarded externally
  • Encrypt files based on classification
  • Limit access to financial or executive materials
  • Prevent unauthorised downloads and printing on unmanaged devices

Importantly, these protections are applied to the document itself, not just the folder it sits in. This ensures that even if a file is moved or shared, its security posture travels with it. Governance becomes embedded in the lifecycle of information rather than dependent on manual discipline.

blank
blank

AI and the importance of structure

As organisations introduce Microsoft Copilot and other AI capabilities, the importance of structure increases. AI tools surface information based on existing permissions, they do not distinguish between what should be accessible and what technically is accessible. If permissions are overly broad or documents are poorly structured, AI simply amplifies that exposure.

A well architected Modern Workplace ensures that:

  • Permissions reflect true role accountability
  • Sensitive data is clearly classified
  • Access controls are continuously reviewed

Designing modern workplace intentionally

A mature Modern Workplace includes:

  • Structured identity architecture
  • Role aligned access controls
  • Governed SharePoint site design
  • Embedded sensitivity labels
  • Controlled external sharing
  • Continuous review of permissions and policies

When these elements work together, collaboration becomes secure by default. Information moves efficiently, sensitive data is protected, so your organisation is positioned to scale confidently and adopt AI responsibly.

blank
blank

Modern workplace requires ongoing oversight

Microsoft environments are dynamic, as teams evolve, projects expand, staff change roles and compliance requirements shift, permissions accumulate and sharing settings drift unless actively managed.

Ongoing oversight ensures that identity policies remain aligned, access remains appropriate and governance evolves alongside the organisation. This is not about restricting collaboration. It is about preserving control as complexity increases.

Why Danet Technology

Designing a secure Microsoft Modern Workplace requires deep expertise in identity architecture, SharePoint governance, information protection and access control design. Danet Technology specialises in structuring Microsoft 365 environments so that collaboration remains seamless while security and compliance remain embedded. The result is a Microsoft environment that supports secure growth, protects sensitive information and provides a strong foundation for AI adoption.