MinterEllison Cyber Risk 2026: AI Is Changing How Organisations Face Attacks
MinterEllison's 2026 cyber risk report finds that AI is reshaping attacks, defence and governance, while supplier exposure and incident preparedness remain major concerns for organisations.
Xcademia Team
Xcademia Research Team

Introduction
Artificial intelligence is becoming a defining factor in the cybersecurity landscape, changing not only how organisations defend themselves but also how cyberattacks can be launched.
That is the central message of MinterEllison's Perspectives on Cyber Risk 2026: The AI Edition, the firm's 11th annual cyber risk report. The report examines how Australian senior decision-makers view cyber risk as organisations adopt AI while facing heightened legal and regulatory expectations.
The findings point to a cybersecurity environment where incidents are increasingly common, AI is becoming part of enterprise infrastructure, and traditional incident response plans may not always reflect the threats organisations are most likely to encounter.
AI is reshaping the cyber threat landscape
MinterEllison says AI is rapidly changing how attacks are launched and defended against.
According to the report, 64% of respondents experienced a direct cyber incident during the previous 12 months, while 57% were affected through a supplier or vendor. These findings underline the importance of looking beyond an organisation's own systems when assessing cyber exposure.
AI is also becoming increasingly embedded in organisations. 98% of respondents said their organisation had adopted AI within 24 months. This positions AI not simply as an emerging technology initiative, but increasingly as part of enterprise infrastructure.
At the same time, AI-enabled threats are becoming a major concern. The report identifies AI-enabled threats as the second-leading cyber concern, with 25% of respondents naming them as their leading concern. Ransomware ranked first at 30%.
AI is compressing the attack timeline
One of the report's central observations is that AI is changing the economics and speed of cyber activity.
MinterEllison says AI can compress attack timelines, lower barriers to entry and raise first-attempt success rates. The report also highlights the supply chain as a significant source of breach exposure.
For security teams, this creates a more demanding operating environment. Faster attacks can reduce the time available to identify suspicious activity, assess its impact and initiate an appropriate response.
The combination of AI-enabled attacks and supplier exposure also means that cyber risk increasingly extends beyond the traditional perimeter of an organisation.

AI adoption is moving faster than governance
The report's second major theme is the growing gap between AI adoption and governance.
MinterEllison states that having a written AI governance framework is now a minimum requirement. However, the report emphasises that the important question is whether that framework is actually operationalised, monitored and defensible.
This reflects a broader shift in how organisations need to think about AI risk.
AI governance cannot exist only as a policy document. Organisations increasingly need to understand how AI is being used, how those uses fit within existing risk structures, and whether governance controls are functioning in practice.
For boards and executives, this means AI governance becomes closely connected with broader cybersecurity, risk and accountability responsibilities.
Organisations may be preparing for the wrong incident
The third major theme concerns incident response.
MinterEllison notes that almost every organisation now has an incident response plan. The differentiator is whether that plan reflects the incidents an organisation is actually likely to experience and whether the legal aspects of response have been considered in advance.
This is particularly relevant in an AI-enabled environment.
A response plan designed around traditional scenarios may not adequately address incidents involving AI-enabled attacks, rapidly changing attack timelines or third-party exposure.
The report therefore points organisations towards stress-testing against AI-era scenarios rather than treating incident response as a document that only needs to exist.

What the findings mean for enterprise security
The findings point to several practical considerations for technology and security leaders.
First, organisations need to consider AI as part of their broader enterprise infrastructure rather than treating it solely as an experimental technology.
Second, third-party and supplier risk remains important. With 57% of respondents reporting that they had been hit through a supplier or vendor, organisations need to account for risks that can originate outside their direct environment.
Third, incident response needs to reflect the current threat environment. Having a response plan is not necessarily enough. Organisations need to consider whether the scenarios they rehearse correspond with the risks they now face.
Finally, governance needs to move from documentation towards operation. MinterEllison specifically highlights the importance of governance that is operationalised, monitored and defensible.

The broader shift toward AI-era cyber resilience
MinterEllison's findings reflect a broader industry shift toward treating AI as both a technology opportunity and a cybersecurity risk factor.
The report does not suggest that organisations can eliminate these risks through a single security control or policy. Instead, its themes point towards a combination of governance, preparedness, monitoring and scenario testing.
For enterprises, this could mean that cybersecurity programmes increasingly need to account for how quickly AI can change the threat environment, while boards and executives need sufficient visibility to challenge whether existing controls and response arrangements remain appropriate.
The report sets out eight characteristics of resilient organisations and identifies board and executive priorities for the year ahead, including stress-testing organisations against AI-era scenarios and considering legal privilege in incident response from the beginning.
Conclusion
MinterEllison's 2026 findings present AI as a fundamental part of the changing cyber risk environment.
With 98% of respondents reporting AI adoption within 24 months, organisations are moving rapidly towards AI-enabled operations. At the same time, direct cyber incidents, supplier exposure and AI-enabled threats remain significant concerns.
The key challenge is therefore not simply adopting AI securely. It is ensuring that governance, monitoring and incident response evolve at a pace that reflects how AI is changing the threat landscape.
For security leaders, boards and technology teams, the report's message is clear: cyber resilience in the AI era requires organisations to test whether their existing assumptions, controls and response plans are still fit for the incidents they may actually face.
About the Author