Australian tech leaders urge cyber recovery planning
Mon, 24th Aug 2026 (Today)
Australian technology executives are urging organisations to prepare cyber recovery plans before suffering a security breach. Their comments reflect a broader shift in incident response planning as companies face more automated attacks and increasing use of artificial intelligence tools.
Three senior figures from Rubrik, Datadog and Nintex said businesses should treat recovery planning as a continuous discipline, not a document left untouched until a crisis. They pointed to rehearsed response plans, better visibility across systems and clearer ownership of recovery tasks as essential steps before an incident.
The remarks come as companies reassess cyber resilience in an environment where attacks can spread more quickly across networks and cloud systems. Recovery, they argue, no longer begins once systems are compromised. It starts earlier, with testing, governance and operational preparation.
David Rajkovic, Vice President A/NZ, Rubrik, said many organisations still rely on outdated plans that are not updated as risks change.
"Too many businesses treat incident response plans as 'set and forget'. These need to be regularly rehearsed, updated and refined as new risks emerge. Everyone's roles should be clearly defined, from critical decision-makers to those updating regulators and stakeholders to staff keeping operations running. Nothing should be worked out live under pressure. When an incident hits, businesses don't have days to react. Decisions must happen in minutes. The difference between a manageable disruption and a complete crisis is preparation. Businesses must know their recovery points in advance, understand which systems and data sets are critical, and verify they can restore systems from a clean and verified source. Many businesses have begun implementing AI, but how many have updated their response plans accordingly? Recent research from Rubrik Zero Labs found 86% of organisations expect AI agents to surpass their security guardrails within the next year. Only 23% reported having full visibility into their agents. In 2026, response plans need to account for AI agents going rogue. Businesses need observability, governance and the ability to roll back agentic actions without disruption. Whether it's an attacker or an AI agent destroying your data, incident response plans must be ready for anything," Rajkovic said.
That focus on preparation extends beyond backups and restoration. It also includes who makes decisions, who communicates with regulators and customers, and how quickly a company can isolate affected systems without disrupting essential operations.
Visibility gap
Merlin Luck, Regional Director - Commercial, ANZ, Datadog, said many security teams still respond too narrowly, chasing separate alerts instead of understanding how an attack moves through connected systems.
"Incident response should be viewed as a discipline you build before anything can go wrong. Too many businesses treat incident response as something to figure out in the moment. The security industry has spent years watching the scoreboard while attackers learned to play the whole game. That's precisely when things fall apart. With AI-driven attacks now moving across entire systems in seconds, the old model of chasing individual threats no longer holds. Teams need a clear and live story of what's unfolding - a unified, real-time view across logs, metrics and traces. That single pane of glass is the difference between identifying a threat in minutes and discovering it days later, long after the damage is done. Threats rarely announce themselves loudly. Subtle anomalies like unusual authentication patterns, unexpected network behaviour and incremental changes in system performance are often the earliest signals. Without dynamic baselines that show how systems normally behave, those signals get lost in the noise until it's too late. Visibility built before an incident provides the context to act decisively in the moment. For SMEs operating with lean teams and limited resources, understanding system behaviour, not just faster alerts or more detection rules, could be the difference between a contained incident and a catastrophic one," Luck said.
His comments point to a practical problem for many smaller businesses in Australia and New Zealand. Lean information technology and security teams may not have the staff to investigate every anomaly manually, increasing the need for a clear picture of normal system activity before anything goes wrong.
Executives say this kind of visibility matters because attacks often first appear through small signs rather than a single obvious failure. Unusual sign-in activity, unexplained changes in network traffic and shifts in application performance can all indicate a problem before a breach becomes fully visible.
Process discipline
Chris Ellis, Director, Solution Engineering, Nintex, said response efforts often break down because organisations have not mapped the sequence of actions needed once an incident begins.
"A breach is rarely what destroys a business. It's chaos during response and recovery that truly cripples a business. Without a well-defined process, the natural human reaction immediately after an attack can be to scramble, to rush or to panic. None of these reactions are helpful. Each incident response stage - evidence preservation, internal escalation, stakeholder communication, regulatory notification, recovery - needs to be a robust, owned process with clear tasks and timelines. Processes need to be followed to ensure a cyber event doesn't become catastrophe. Communicating with stakeholders and notifying regulators are among the most critical steps. Whether it is customers, partners or employees, each stakeholder requires clear and concise information to assure them you're taking the appropriate steps to keep their information safe. Regulators will require timely and consistent notifications. The last thing a business needs after a breach is to run afoul of compliance obligations. Before a breach occurs, organisations should map out their incident response processes, clearly define ownership of each step and automate key processes to ensure the necessary rules and governance procedures are followed. After such a devastating event, the organisation cannot afford chaos. Process mapping and workflow automation can help ensure cool heads prevail," Ellis said.
Taken together, the executives' comments suggest cyber recovery planning is broadening from a technical issue into an operational one. Businesses are being pushed to test not only whether data can be restored, but also whether management teams can make decisions quickly, whether system behaviour is understood well enough to spot trouble early, and whether communications and compliance processes will hold up under pressure.
Rubrik's cited research finding that 86% of organisations expect AI agents to surpass security guardrails within the next year, while only 23% report full visibility into those agents, underlines concerns that recovery plans may not yet reflect how artificial intelligence is changing cyber risk.