Financial services now have the most expensive breaches in Australia: what the 2026 numbers mean

blank

Financial services now have the most expensive breaches in Australia: what the 2026 numbers mean

blank

Every year, IBM’s Cost of a Data Breach Report gives Australian businesses a clear benchmark for what a security incident costs. It’s one of the few studies of its kind that lets organisations compare their own exposure against a large, consistent global dataset year after year.

The 2026 edition, published on 31 July 2026, examined breaches experienced by 602 organisations globally between March 2025 and February 2026. As in previous years, the report breaks these findings down by industry and region, giving a picture of how different sectors are faring against the same threats. Buried in the Australian results are several findings financial services leaders can’t afford to overlook.

The numbers

The average cost of a data breach in Australia has risen toAUD $4.22 million, up 38 per cent since 2019.

Financial services recorded the highest average breach cost of any sector in the country, at AUD $6.31 million per incident (IBM, 2026). It is now the most expensive sector in Australia to experience a breach, ahead of every other industry IBM measured this year.

It helps to understand what that figure represents, because it is easy to read it as a single dramatic event and move on, however, it isn’t one. It is an average, built up from incident response, forensic investigation, regulatory notification, lost business and the time it takes a Financial Services firm to identify and contain an issue once it has started.

For a sector that holds sensitive client information and moves money for a living, each of those components tends to run longer and cost more, and the total adds up quickly.

A trend, not a spike

The cost figure lines up with what’s happening on the reporting side too. The Office of the Australian Information Commissioner received1,205 data breach notifications in 2025, the highest number since the Notifiable Data Breaches scheme began in 2018, and an 8 per cent increase on the 1,112 notifications recorded in 2024 (OAIC, 2026). A consistent picture can be seen when you read the two data points together.

Breaches are being reported more often across the board, and when they land in financial services, they cost more to resolve than anywhere else.

None of this means Financial Services firms are doing something wrong, it reflects the nature of the work being completed. Businesses in this sector hold information and manage transactions, so a breach is not just costly to put right, it also comes with strict reporting obligations to regulators.

blank

Where the value sits

What the figure highlights is the value of preparation before an incident, not after one. The businesses that survive a breach with less damage rarely do so by chance. They usually have a plan that was written and tested well before it was needed, so the first hour of an incident is spent executing it rather than working out where to start.”

Picture two businesses hit by a similar incident on the same day. One already knows who gets notified, in what order, and what the client message says, before anyone’s written a word of it. The other is figuring all of that out for the first time, with the clock already running. That gap, in cost and in client trust, is most of what this report is measuring.

Closing that gap doesn’t call for a finished plan overnight, and it doesn’t need to be perfect on the first attempt, it just needs to exist before it’s tested for real.

How can we help you?

Join us for a Cyber Webinar Series where we unpack practically how you can learn and discover how to not only protect your environment, but who has access to it and what information they have access to. 
 
More information is found here: 
https://danet.com.au/webinar-series-three-cyber-security-questions-every-business-owner-has-to-answer/

If you’d like to talk through what this means for your business, contact us.

danet.com.au

Sources

OAIC, Data breach notifications increase to all-time high in 2025, new NDB stats show (published 6 July 2026): https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show

IBM, Cost of a Data Breach Report 2026: https://www.ibm.com/reports/data-breach

What APRA’s AI Letter Signals for Every Regulated Business

blank

What APRA's AI Letter Signals for Every Regulated Business

blank

In April 2026, APRA wrote to industry with a message that was hard to misread. It called for a step-change in how banks, insurers and superannuation trustees manage the risks that come with artificial intelligence, warning that governance, risk management, assurance and operational resilience are not keeping pace with how quickly AI is being adopted.

The letter followed a targeted review of some of the country’s largest financial institutions. While it is directed at APRA-regulated entities, the observations read like a checklist for any organisation now weaving AI into everyday work. The themes are familiar to anyone who has watched a new technology move faster than the structures built to govern it.

Here is what the letter actually says, and why it matters well beyond the entities it was addressed to.

Adoption is racing ahead of governance

APRA found that every entity it engaged with is actively adopting AI, and many are moving beyond internal productivity experiments into customer facing uses such as claims triage, loan processing, fraud detection and customer interaction.

Governance has not matured at the same speed. APRA noted a tendency to treat AI risk as just another technology, which misses what makes AI different. Models can adapt over time, produce unpredictable outputs and carry considerations such as bias and data handling that traditional systems do not. The result is gaps across the AI lifecycle, particularly in monitoring how models behave once they are deployed.

At board level, APRA observed strong enthusiasm for the benefits of AI, but also that many boards are still building the technical literacy needed to challenge and oversee AI decisions. In some cases there was an overreliance on vendor presentations rather than independent examination of the risks.

AI is changing the cyber threat landscape

The letter is clear that AI is not only a productivity story. It is also reshaping how organisations are attacked.

APRA pointed to new attack pathways, including prompt injection, data leakage through AI tools, insecure integrations and the misuse of autonomous AI agents. AI can shorten the attack cycle, allowing incidents to move with more speed and coordination than before.

One observation deserves particular attention as adoption grows. Identity and access controls in many organisations have not yet adjusted to non-human actors, such as AI agents that can act inside systems on a user’s behalf. At the same time, staff use of AI tools outside approved control frameworks remains a concern, with many organisations relying on policy rather than enforceable technical controls.

Supplier concentration and opacity are real risks

APRA observed some entities heavily dependent on a single provider for multiple AI use cases, often without tested exit or substitution plans. Because AI capability is increasingly embedded inside software and platforms, the upstream dependencies, such as foundation models and the data behind them, can be opaque. That makes it harder for an organisation to independently assess how a model performs, where its data goes and how resilient it is.

blank
blank

Assurance built for static systems is not enough

Traditional change management and point-in-time assurance were built for systems that behave the same way each time. APRA noted these methods are ill-suited to probabilistic models that learn, adapt and degrade over time, and that few entities had continuous monitoring in place to detect issues such as model drift. Internal audit and risk functions were often found to lack the specialist skills and tooling to assess AI systems.

What APRA expects

Underneath the observations, APRA set out clear expectations. At a minimum, entities should

  • Maintain board and executive literacy sufficient to set strategic direction and provide genuine challenge on AI risk.
  • Run an AI strategy aligned to the organisation’s risk appetite, supported by monitoring and reporting.
  • Keep an inventory of AI tooling and AI use cases.
  • Assign ownership and accountability across the AI lifecycle, from design through to decommissioning.
  • Keep people involved in high-risk decisions.
  • Train staff on AI use, misuse, limitations and secure practices.
  • Map the full AI supply chain, including third and fourth-party dependencies.
  • Apply continuous, integrated assurance across security, data governance, model performance and privacy.

APRA also signaled that where entities fail to manage AI risks proportionately, it will take stronger supervisory action and, where appropriate, pursue enforcement.

Why this matters beyond APRA-regulated entities

APRA regulates banks, insurers and superannuation trustees. Financial advice licensees sit under ASIC, which delivered a strikingly similar message in its own May 2026 letter describing cyber resilience as being at a minute to midnight and stressing that boards must be able to evidence that controls are actually working, not just designed.

Two regulators, weeks apart, landed on the same point. AI adoption is moving faster than governance, and the expectation is shifting from intent to evidence.

Where to start

For most organisations, the honest starting point is simpler than a strategy document. It is visibility.

Many businesses cannot yet answer a basic question: where is AI already being used across the organisation, including the AI features quietly switched on inside the software we already run? Building that inventory is where responsible adoption begins. From there, the familiar disciplines apply. Align access to what each person, and each agent, genuinely needs. Keep people accountable for high-risk decisions. Make sure the information AI can reach is well organised and governed underneath.

That last point is where much of the real work sits. Tools like Microsoft Copilot operate on the information users already have access to, which means the value they deliver, and the risk they carry, is shaped by how well that environment is structured. For many organisations, AI is not creating new governance questions so much as bringing existing ones into sharper focus.

At Danet, this is the conversation we are having with clients across regulated industries. Not whether to adopt AI, but how to build the visibility, identity controls and information governance that let an organisation adopt it with confidence.

If your organisation is working through what responsible AI adoption looks like in practice, get in touch.

Sources

APRA, Letter to Industry on Artificial Intelligence (published 30 April 2026): https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai

ASIC, open letter on cyber resilience and AI (May 2026), as summarised by Clayton Utz, “The clock is at a minute to midnight”: “The clock is at a minute to midnight”: ASIC’s ope… | Clayton Utz

ASIC, Cyber resilience regulatory resources: Cyber resilience | ASIC

Australian Signals Directorate (ASD), Annual Cyber Threat Report 2024-25 (context on the evolving threat environment): https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

How AI hallucinations could land for AFSL holders

blank

How AI hallucinations could land for AFSL holders

blank

With 90% of industry leaders believing AI will improve service and efficiency in their firms,attention is now turning to how this technology is integrated into everyday workflows, and how its behaviour shapes outcomes.

A specific pattern emerging is AI hallucinations, where AI recognises objects or patterns that don’t exist or that humans are unable to see.

The problem with this? Inaccurate, invented responses, with no supporting evidence or insight, and errors hard to detect due to the confidence AI responds with.

AI is going to be part of every Australian financial services organisation, the right approach is choosing the version that protects your client data.

AI hallucinations in the real world

In 2023, AI hallucinations appeared in the legal case of Mata v. Avianca. An attorney was representing an injury claim for a client, using ChatGPT this produced references that did not exist in the legal research.

It also falsely claimed the references came from a reputable legal database, revealing how far AI can go in producing inaccurate outputs.

The knowledge base AI utilises continued to be undermined. From 2023-2025, cases like these kept emerging, with judges worldwide issuing hundreds of filings, 90% of them in 2025 alone.

For AFSL holders, in a Statement of Advice, this can land as AI-generated errors appearing as verified content, which risks consumers being misled by incorrect facts and insights.

Why this matters to AFSL holders

AFSL holders need to ensure that consumers aren’t unethically treated through vulnerability exploitation and potential AI bias.

The accuracy of insights and facts produced to consumers must also oblige ensuring AI information isn’t misleading, unexplained, or inaccurate.

Under directors’ duties, responsibilities must be undertaken carefully and diligently when considering reliance on information from AI and the risk that it holds.

Without upholding these obligations, an uncaught hallucination in a Statement of Advice, client email or compliance file note becomes an AFCA complaint, a breach report, and a remediation bill the licensee carries.

A confident approach to AI

For AFSL holders to ensure they can meet these obligations, Microsoft 365, specifically Microsoft Copilot, is a safe way to implement AI. Designed specifically for enterprise, Copilot operates within an organisation’s tenant.

The benefits of Microsoft 365 involve:

Data protection and strict permissions: Adheres to an organisation’s existing data permissions and information, no exposure of organisational data to train the public AI model.

Automated compliance:Finds regulatory changes and prepares for audits, allowing adherence to compliance standards.

Microsoft purview:Prevents unauthorised data sharing, monitors AI prompts, and classifies sensitive data.

Many organisations already have these capabilities within their environments, they just haven’t been optimised yet. For financial services organisations, accuracy can be enhanced through role-specific AI agents, allowing for automated data reconciliation.

Reliable and permitted outputs can also be achieved through a strong SharePoint architecture and governed data access, allowing Copilot to search through categories.

The next 3 steps

There are a series of steps AFSL holders can take to ensure continued confidence within their environments.

  1. Embed Copilot through existing applications and actively update databases
  2. Ensure data governance through implementing restrictions and Microsoft Purview
  3. Updating policies around AI that mandate human review

These measures ensure Copilot can function optimally in your environment while maintaining data and access governance supported by updated AI policies.

Why Danet

With AI being part of how financial services will operate in 2026 and beyond, hallucinations will progressively surface.

Those who move first with the right version of AI will benefit from the productivity without the privacy risk.

Danet works with organisations to align Microsoft 365 and Copilot to their environments to ensure confidence and compliance with the use of AI, through designing and continuing to update the structures of databases and workflows.

These themes are further explored in Danet’s AI Guide for AFSL Leaders, determining how AI capabilities can be implemented into Microsoft 365 environments and how governance oversight shapes this.

AI is already in your environment: understanding how different tools interact with your data

AI in your environment

AI is already in your environment: understanding how different tools interact with your data

blank

This is changing how every business operates and how day to day processes are completed. Confidential information, client accounts and internal documents are most likely being passed through or viewed by AI multiples time a day. In many businesses, AI is in contact with this information without clear oversight on how these systems are being used or where organisational data is being retained.

Do know how AI is being used in your workplace? Have you tested access to internal documentation?

The type of AI platform makes a difference

Copilot operates within Microsoft 365 through Entra ID and existing Microsoft permissions. The information it surfaces reflects the same access structures already governing collaboration inside SharePoint, Outlook and Teams. This keeps AI activity connected to the identity and access controls already established across the environment.

External AI platforms operate differently. ChatGPT, Claude and Gemini are commonly accessed through browser sessions or personal accounts operating outside Microsoft 365 governance oversight. Staff may paste client information or internal notes into these tools during routine work. Once information enters those platforms, the organisation may have limited oversight around retention model usage or where that information is processed.

AI capability is also becoming embedded into software already used across financial services environments. Meeting intelligence tools can generate summaries from conversations while CRM platforms surface AI-driven prompts during workflow activity. Research platforms now return AI-generated responses inside the application itself.

Over time, organisational data begins moving through multiple AI environments operating under different data handling conditions.

Identity and access can change AI behaviour

Identity governance plays a larger role in how organisational data is surfaced across the organisation.

Microsoft 365, Entra ID defines the identity boundary through which Copilot interacts with information. Existing permissions determine which content available through your Microsoft Modern Workplace can appear through AI-driven search and summarisation. Records and internal knowledge continuously move between collaboration spaces during normal work. AI systems now interact with that same information structure, which places greater importance on maintaining access aligned to operational responsibility.

As AI capability expands identity governance further shapes how confidently organisations can maintain control over the information AI systems can access throughout the environment.

blank
blank

AI increases visibility into operational maturity

AI systems are interacting broadly with organisational data, this means the maturity of the environment becomes easier to observe.

Information ownership remains clearer when access responsibilities continue reflecting how teams currently operate across the organisation. Permissions also remain easier to govern when environments are reviewed as collaboration patterns evolve over time.

This is shifting AI governance discussions toward the condition of the environment itself. Organisations with clear ownership and structured access practices are often better positioned to introduce AI capability into connected workflow activity.

AI capability reflects the maturity of the environment it operates within.

Financial services environments carry additional governance expectations

Questions around governance oversight are important in financial services firms as AI systems begin interacting with client information.

For many AFSL holders here are some practical questions you should be asking.

  • Which AI platforms are staff already using during client-related work?
  • Are staff entering regulated information into personal AI accounts?
  • Which AI tools retain prompts or uploaded material outside the organisation?
  • Does the business have oversight around where AI-generated outputs are stored or shared?
blank

Why Danet

Danet works with organisations to structure Microsoft 365 environments where governance oversight remains aligned with the way AI capability evolves across connected platforms and the information within them.

Within financial services environments, this includes maintaining oversight around how AI systems interact with information moving through regulated workflow activity.

For financial services organisations, these themes are explored further in Danet’s AI Guide for AFSL Leaders, which examines how governance oversight shapes the way AI capability is introduced across connected Microsoft 365 environments.

Strong security, identity and governance in practice

Strong security, identity and governance

Security & identity control is one of the strongest indicators of how effectively a technology environment operates.

As cloud platforms, Microsoft 365, and AI tools become part of everyday business operations, organisations need to focus on how their environments are structured, governed, and maintained over time.

As collaboration expands across Teams, SharePoint, OneDrive, email, mobile devices, and third-party platforms,maintaining strong governance supports secure growth, operational maturity, and AI readiness.

What control looks like in practice

Control creates visibility across people, information, and access. In mature Microsoft 365 environments, teams understand where information belongs, who is responsible for it, and how collaboration should operate across the organisation.

Leadership teams also require visibility over how governance is maintained as the environment evolves. This includes ensuring access permissions remain aligned with operational responsibilities, sensitive information is protected appropriately, and governance controls continue to support the organisation as teams, projects, and systems change over time.

Strong operational control is typically supported through:

  • Clear ownership of information and collaboration spaces
  • Access permissions aligned with business responsibilities
  • Structured governance across Microsoft 365 environments
blank

Identity is the operational foundation

Every interaction across Microsoft 365 begins with identity.

Microsoft Entra ID provides the foundation that determines who a user is, what they can access, and under what conditions access is granted. When identity architecture reflects operational responsibilities, organisations are better positioned to manage collaboration securely while maintaining accountability across the environment.

Conditional access policies help organisations apply security controls dynamically by evaluating device health, authentication strength, user location, and sign-in behaviour before access is approved.

As organisations grow, access requirements naturally evolve alongside them. Teams restructure, projects conclude, and external collaboration increases. Regular review processes help ensure permissions continue to align with how the organisation currently operates.

blank

Governance is an operational practice

Governance delivers the strongest outcomes when it is maintained consistently across the environment.

This often includes:

  • Regular access reviews and lifecycle management
  • Sensitivity labels and Microsoft Purview policies
  • Structured SharePoint architecture with defined ownership

These controls support operational oversight while helping organisations demonstrate governance maturity to boards, auditors, insurers, and regulators.

What AI makes visible

Microsoft Copilot is probably already integrated into your daily operations. Copilot interacts with the information users already have access to throughout Microsoft 365 environments, including SharePoint, Teams, Outlook, and OneDrive. This places greater focus on how permissions, classifications, and ownership structures are managed across the business.

Organisations with mature governance structures are positioned to adopt AI with greater confidence because identity, access, and information management are already aligned across the environment.

Why Danet

Danet helps organisations design Microsoft 365 environments where identity, governance, and operational accountability work together as a connected system.

Our approach helps organisations:

  • Strengthen visibility across users, access, and collaboration
  • Support governance and compliance obligations
  • Align Microsoft 365 structures with operational responsibilities

For organisations operating within regulated environments, operational control supports secure growth, governance maturity, and long-term business resilience.

A new phishing pattern in Microsoft 365

blank

A new phishing pattern in Microsoft 365

blank

 As work becomes more connected within Microsoft 365, attackers are adapting their methods to reflect that connectivity.

A pattern now emerging involves compromised Microsoft accounts and legitimate Microsoft SharePoint file sharing. Rather than relying on suspicious links or external impersonation, the technique operates within trusted channels that employees use every day.

Understanding how this works supports both technical response and user awareness.

How the method works

This technique follows a structured sequence:

  1. A legitimate Microsoft account is compromised. Access may have been obtained through credential reuse, earlier phishing, or password exposure.
  2. The attacker uses Microsoft SharePoint to share a genuine file from that real account. The recipient receives a standard SharePoint notification from a recognised contact.
  3. When the file is opened, a Microsoft sign-in prompt appears. The prompt mirrors the usual Microsoft authentication experience.
  4. If credentials are entered, access extends further.

At that point, the attacker is operating inside the organisation’s Microsoft 365 environment as a legitimate user. Collaboration patterns continue as normal, which allows exposure to expand through routine sharing.

This pattern is often described as a secondary attack. Even when most employees act carefully, a single compromised identity can create a downstream impact through everyday workflows.

Why this spreads quickly

Microsoft 365 is intentionally designed to support connected work. Within that environment, Microsoft SharePoint governs how information is shared, Microsoft Teams structures collaboration in shared digital spaces, and Microsoft Outlook sustains communication across the organisation.

These capabilities are central to productivity. When an attacker operates from a legitimate account, the same collaborative design that supports productivity also supports internal movement. Within that environment:

  • File shares appear consistent with normal collaboration
  • Authentication prompts align with expected workflows
  • Access extends through established trust relationships

The compromised identity carries organisational credibility, allowing activity to continue without immediate suspicion.

Where AI changes the equation

The introduction of AI capabilities such as Microsoft Copilot adds another dimension to this pattern.

Microsoft Copilot surfaces insight based on existing permissions across Microsoft 365, reflecting the structure and governance already in place. When identity controls align with role accountability and information architecture is clearly defined, AI supports productivity within those boundaries. Visibility within the environment is shaped directly by how access has been configured.

AI also influences how phishing techniques continue to develop. Generative tools allow attackers to produce communication that reflects organisational language and context. Messages can align closely with current projects or recent activity, which reduces obvious inconsistencies in tone or workflow.

Once access is established, AI-driven tools can assist with navigating large volumes of information or identifying high-value content more efficiently. This places greater emphasis on maintaining well-defined access boundaries and regularly reviewing how permissions are assigned within Microsoft Modern Workplace.

As organisations expand their use of AI, the relationship between Microsoft Modern Workplace design and responsible AI adoption becomes increasingly interconnected.

What to watch for

User awareness remains one of the most effective safeguards.

Pause when you notice:

  • A Microsoft SharePoint file share arriving without prior context
  • An authentication prompt appearing outside your usual workflow
  • A request from a known contact that feels inconsistent with recent activity

Verification through an alternate communication channel is a simple and effective control. Taking a moment before entering credentials can interrupt the progression of secondary compromise.

Strengthening the structural response

Key areas for review include:

  • Conditional access configuration within Microsoft Entra ID
  • Multi-factor authentication coverage
  • Microsoft SharePoint external sharing settings
  • Monitoring for unusual sign-in behaviour

These measures are not about limiting collaboration. They ensure that identity, access, and sharing controls remain aligned as Microsoft 365 usage expands and new technologies are introduced.

Cyber awareness training should also evolve to reflect that phishing techniques now operate within trusted platforms, instead of solely through external email campaigns.

A connected environment requires connected awareness

As work becomes more integrated within Microsoft 365, phishing techniques increasingly reflect that integration. Effective defence combines disciplined identity governance with users who recognise how trust can be leveraged within connected environments.

Designing and maintaining that structure requires a deep understanding of identity architecture, Microsoft SharePoint governance, access control design, and information protection within Microsoft 365.

Danet works with organisations to align Microsoft Modern Workplace environments to operational requirements and security standards, ensuring collaboration remains seamless while governance remains embedded.

Connected work brings opportunity. With considered design and ongoing oversight, organisations can support secure collaboration, responsible AI adoption, and sustained growth.

Microsoft Modern Workplace

blank
blank

Secure collaboration designed for growth

Microsoft Modern Workplace is often described as a productivity solution.  In addition,  Microsoft Modern Workplace is a governance and security framework that defines how your organisation controls identity, manages information and enables collaboration.   Many businesses operate within Microsoft 365, yet few have intentionally designed the underlying structure that  determines how securely documents are shared, how permissions are assigned and how sensitive data is protected. 

blank

Modern workplace starts with identity

At its core, Microsoft Modern Workplace is built on identity.

Every login, every device, every document access request begins with verifying who the user is and what they are authorised to do. When identity is structured, access aligns with role and responsibility. Conditional access policies assess device health and location and multifactor authentication strengthens verification to create an environment that is secure by design. Without strong identity architecture, collaboration tools may function, but governance is fragile.

Thedocumentjourneyinside Microsoft 365

Every organisation relies on shared documentation. Throughout that journey, multiple edits occur and multiple opinions are incorporated.

A proposal is drafted -> stakeholders provide input -> revisions are made -> approvals are granted -> the final version is archived.

If the environment lacks structure, that process quickly creates risk.

  • Versions circulate in inboxes
  • Sensitive information may be copied into new documents
  • Access permissions expand informally
  • Ownership becomes unclear.

In a properly designed Microsoft Modern Workplace, that same document journey unfolds within a governed structure.

  • SharePoint libraries are organised around business functions.
  • Version history is automatic
  • Co-authoring happens in real time without duplicating files
  • Access is role based rather than manually granted
  • Sensitive content can be labelled and restricted at the document level.

The result is collaboration that remains fluid while control remains intact. A structured SharePoint environment establishes logical site architecture aligned to departments, projects or client groups. It defines document ownership, controls internal and external sharing and maintains audit trails and retention policies.

Protecting sensitive information through labels and access controls

Microsoft 365 includes powerful information protection capabilities that are often underutilised. Sensitivity labels, data loss prevention policies and role based access controls allow governance to operate automatically in the background.

These controls can:

  • Restrict confidential documents from being forwarded externally
  • Encrypt files based on classification
  • Limit access to financial or executive materials
  • Prevent unauthorised downloads and printing on unmanaged devices

Importantly, these protections are applied to the document itself, not just the folder it sits in. This ensures that even if a file is moved or shared, its security posture travels with it. Governance becomes embedded in the lifecycle of information rather than dependent on manual discipline.

blank
blank

AI and the importance of structure

As organisations introduce Microsoft Copilot and other AI capabilities, the importance of structure increases. AI tools surface information based on existing permissions, they do not distinguish between what should be accessible and what technically is accessible. If permissions are overly broad or documents are poorly structured, AI simply amplifies that exposure.

A well architected Modern Workplace ensures that:

  • Permissions reflect true role accountability
  • Sensitive data is clearly classified
  • Access controls are continuously reviewed

Designing modern workplace intentionally

A mature Modern Workplace includes:

  • Structured identity architecture
  • Role aligned access controls
  • Governed SharePoint site design
  • Embedded sensitivity labels
  • Controlled external sharing
  • Continuous review of permissions and policies

When these elements work together, collaboration becomes secure by default. Information moves efficiently, sensitive data is protected, so your organisation is positioned to scale confidently and adopt AI responsibly.

blank
blank

Modern workplace requires ongoing oversight

Microsoft environments are dynamic, as teams evolve, projects expand, staff change roles and compliance requirements shift, permissions accumulate and sharing settings drift unless actively managed.

Ongoing oversight ensures that identity policies remain aligned, access remains appropriate and governance evolves alongside the organisation. This is not about restricting collaboration. It is about preserving control as complexity increases.

Why Danet Technology

Designing a secure Microsoft Modern Workplace requires deep expertise in identity architecture, SharePoint governance, information protection and access control design. Danet Technology specialises in structuring Microsoft 365 environments so that collaboration remains seamless while security and compliance remain embedded. The result is a Microsoft environment that supports secure growth, protects sensitive information and provides a strong foundation for AI adoption.

The Opportunity and Risk of AI

blank

The opportunity & risk of AI:

Preparing for 2026 with secure data foundations

blank

The opportunities with AI in 2026 are transformative, built into how teams analyse data, manage compliance, and serve customers with greater efficiency, faster insights, and more informed decisions.

AI only delivers value when the data beneath it is clean, secure, and governed. Without that foundation, businesses risk exposing the very information they are trusted to protect.

This year Danet Technology is focusing on how AI is transforming businesses across Australia. We want to know what you have planned for AI and help you understand what AI has planned for you. AI only delivers value when the data beneath it is clean, secure, and governed.

Without that foundation, financial organisations risk exposing the very information they are trusted to protect.At Danet, we have been asking our clients, what they have planned for AI in 2026, but sharing what AI has planned for you is equally important. ​

The AI opportunity

AI is already reshaping the way financial organisations operate. Tools like Microsoft Copilot are helping teams produce reports, manage workloads, and interpret data more effectively. Across lending, compliance, and advisory functions, automation is removing manual steps and surfacing insights faster than ever before.

In 2026, AI will play an even deeper role, supporting strategic decisions, identifying anomalies in real time, and enhancing customer experience with personalised, data-driven service. 
For leaders, the potential is clear with higher productivity, more reliable insights, and faster innovation.

But opportunity and exposure grow in parallel. As AI systems become more capable, they also depend on and reveal more of an organisation’s data.

The risks of ungoverned AI

When AI has unrestricted visibility across an organisation, it does not distinguish between what can be accessed and what should be.

In early Copilot deployments, many organisations discovered how easily sensitive information surfaced in search results and summaries. Files stored in shared drives, test folders, or outdated repositories appeared in new contexts, sometimes exposing data that was never intended to be seen again.

This is a governance issue. 
 
Confidential client information, compliance reports, and internal assessments can all appear where they do not belong if permissions and classifications are not aligned.

AI does not create new weaknesses.
It highlights where existing ones have been ignored.

blank

Building secure data foundations for AI

Preparing for AI is about strengthening the environment that supports innovation.

A secure data foundation allows AI to operate safely, enhancing productivity while maintaining trust.

Your businesses practical steps for readiness include

  1. Data classificationClearly define what information is confidential, internal, or public. Without this baseline, AI models have no context for what should remain restricted.
  2. Access control Review and enforce permissions across shared and legacy storage. Outdated access lists are one of the most common causes of accidental exposure.
  3. Governance frameworks Update internal policies to reflect how AI tools interact with files, chats, and collaboration spaces.
  4. Audit and visibility Establish monitoring and reporting to understand how AI queries and surfaces data.
  5. User awareness Educate staff that AI summarisation and search functions depend on access, and that sharing or storing data incorrectly can have broader consequences.

These are not new concepts for organisations. They are familiar disciplines applied through a modern lens. Governance and compliance frameworks already exist. They now need to evolve to match how information flows through AI.

Readiness means building the right environment for AI to operate with control, clarity, and confidence, supported by policies that continue to evolve.

Looking ahead to 2026

The next 18 months will shape how businesses balance innovation and integrity. AI is here. However, how you shape what that means for you and your business is what matters first. At Danet Technology, we have seen how small improvements in structure, classification, and governance can transform readiness for AI. Keen to learn more about how we can help you through this process?

How to avoid the cost of a cybersecurity breach

blank

How to avoid
the cost of a
cybersecurity breach

blank

Why is ISO 27001 the right framework?

ISO 27001 is the internationally recognised standard for information security management, it outlines how to:

  1. Identify and treat information risks
  2. Establish clear governance policies
  3. Continuously monitor and improve
  4. Align people, processes and technology to protect information assets

While ISO 27001 is not mandatory under the ASIC RG104, it is often used as a benchmark of adequacy in risk and compliance audits.

What does best practice look like?

While many small to medium sized fin services firms outsource their technical support, they are still liable for establishing the right governance practices, all backed by external controls.

Here’s a typical 20–30-person firm that meets ASIC’s expectations:

  1. Live threat alerting via SIEM tools
  2. Incident response plan with clearly defined escalation
  3. Multi-factor authentication (MFA) for all remote and privileged access
  4. Annual backup testing, including offsite and immutable storage
  5. Ongoing staff cyber awareness training and policy sign-offs

Need Help?

If you need help in understanding how this will impact your
financial services business, join our Webinar Event.

Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.

Cybersecurity and AFSL compliance and what every financial services leader needs to know

blank

Cybersecurity and
AFSL compliance and
what every financial services leader needs to know

blank

In 2022, ASIC updated its guidance under Regulatory Guide 104 (RG 104), reinforcing the responsibility of Australian Financial Services License (AFSL) holders to maintain adequate technological resources.

For leaders in financial services, this means that cybersecurity is no longer an optional IT issue, it is now central to your compliance obligations, business continuity, and client trust.

But what does RG104 mean?

RG104 makes it really clear to all AFSL holders, they must maintain technology that is both stable and secure, aligned to the nature, scale and complexity of their financial services business. However, RG104 is well beyond the right infrastructure.

As an overview RG104 obligations highlight:

  • Cybersecurity and information security
  • Risk management systems
  • Outsourced IT Oversight
  • Incident Response
  • Employee Training & Supervision

So why is this important?

Over the last 18 months, multiple financial services firms in Australia have faced ASIC enforcement actions, not just because they were breached but because they couldn’t demonstrate adequate cyber risk management before a breach occurred.

In one high profile case in 2023, a boutique Advisory Firm received $1.2million penalty and temporary suspension of license operations due to failure to implement basic cybersecurity safeguards including:

  1. No formal incident response plan
  2. Inadequate endpoint protection
  3. No staff cybersecurity awareness training

What are regulators expecting?

ASIC has repeatedly highlighted the importance of the following requirements:

  1. Cyber risk registers as a part of your business risk
  2. Third party oversight including you working with MSPs and cloud vendors
  3. Business continuity plans and stress testing the plans
  4. User activity monitoring and transparency on privilege access controls
  5. ISO 27001 alignment especially where regulatory scrutiny is higher

Need Help?

If you need help in understanding how this will impact your
financial services business, join our Webinar Event.

Daniel Butt, CEO, Danet will be walking through Fin Services obligations and
the right controls – don't just meet these but exceed them when its Audit time.