Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Cyber Action Year 2026

Cyber Action Year 2026: What Australian Organisations Should Do

October 2026 is Cyber Security Action Month, not Cyber Security Awareness Month. The campaign has a new name, and this year it sits inside Cyber Action Year 2026, the Australian Signals Directorate's first year-long program to move Australian organisations from awareness to action. Whether you run a ten-person practice, a multi-venue hospitality group or a regulated financial services business, the ask is the same: pick the actions that fit your environment, start them in October and keep going for the rest of the year.

Below: what changed, what ASD's critical actions mean at different sizes, and the everyday habits for staff this month.

"Awareness alone is not enough."

Australian Signals Directorate, Cyber Action Year 2026

What Is Cyber Action Year 2026?

Cyber Action Year is an ASD-led, industry-driven program running through 2026. For the first time, government, industry and critical infrastructure are working to a shared list of practical, measurable security outcomes rather than a single month of messaging. Cyber Security Action Month, run by the Department of Home Affairs every October, is the public-facing part of that effort, with the 2026 theme "Take a second. Stay secure."

Underneath both is an assumed breach mindset. Instead of only asking how to stop an attack, you also plan for what happens when one gets through: how quickly you would notice, how far it could spread, and how fast you could get back to operating. For a smaller business, that means knowing your answers before you need them. For a larger organisation, it means testing whether one compromised account can still reach the rest of the network.

ASD's Critical Actions, Scaled to Your Organisation

ASD's Cyber Action Year page lists six critical actions. Here is what each looks like in practice:

  • Replace or mitigate legacy technology. Smaller teams should list out-of-support devices, such as PCs still on Windows 10 (end of support October 2025), old routers and POS terminals. Larger environments need a register of unsupported servers and line-of-business applications, with a replace or mitigate decision for each.
  • Implement best practice event logging. At minimum, Microsoft 365 audit logging should be on and retained long enough to investigate a suspicious login. Larger organisations should centralise logs across endpoints, cloud and network so incidents are detected in hours, not months.
  • Choose secure by design products and services. Ask vendors about multi-factor authentication and patching before buying. At scale, build this into procurement and third-party risk reviews.
  • Prepare for AI-enabled cyber threats. AI makes phishing and voice impersonation more convincing. Every organisation needs a call-back rule for payment and bank detail changes. Larger organisations should also govern which AI tools staff can use with company data.
  • Prepare for post-quantum cryptography. ASD recommends moving away from traditional asymmetric cryptography by the end of 2030. Larger organisations holding long-life sensitive data should start a cryptographic inventory now. Smaller ones should keep systems updatable and ask key vendors about their plans.
  • Plan for isolation. Critical infrastructure entities should be ready to isolate systems and networks for up to three months. If you supply services to critical infrastructure, expect your clients to ask how you would support that.

For regulated organisations, these actions map directly to existing obligations: APRA CPS 234 and CPS 230 for financial services, and PCI DSS 4.0 for venues taking card payments. The ACSC Essential Eight remains the practical baseline to measure against while ASD consults on its successor, the Essentials series.

All IT's cybersecurity services: patching schedules, event logging, secure procurement and AI-use policies that map directly to the six critical actions above.

Five Everyday Actions for Cyber Security Action Month

The October campaign is aimed at people, not systems, so these apply to every staff member, from a sole bookkeeper to a 500-person workforce:

  • Apply updates. Keep computers, phones and apps patched. Attackers scan for known, unpatched weaknesses automatically.
  • Set long, unique passphrases. One reused password can unlock email, finance systems and remote access at once. A password manager makes this practical.
  • Turn on multi-factor authentication. Start with email, banking and anything with admin access.
  • Back up and test the restore. A backup nobody has restored is a guess. Test that files and systems actually come back.
  • Pause on unexpected requests. Urgent payment changes and updated bank details are where many losses start. Confirm by phone using a number you already have.

Where to Get Free Help

The government's free Cyber Health Check at cyber.gov.au gives any organisation a plain-language starting point, and Scamwatch and ReportCyber are where to report a scam or incident. Smaller businesses can use the Cyber Wardens program for free staff training. The Parliamentary Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations is also running a preparedness survey until 29 January 2027.

Turning One Month Into a Year of Action

The point of Cyber Action Year is that none of this belongs to October alone. A workable rhythm is to run the everyday actions with staff this month, review legacy systems and logging before the end-of-year change freeze, and test backups and incident contacts every quarter.

Assumed breach planning scales with the organisation. For a small business it can fit on one page: which systems matter most, who you call first and who can approve shutting something down. For a larger organisation, run a tabletop exercise against a realistic scenario, such as a compromised executive mailbox, and fix the gaps it exposes.

How All IT Handles This

All IT works through these actions with clients all year, from small offices to multi-site groups: patching schedules, multi-factor authentication and passphrase hygiene, logging, legacy system planning, and the vendor coordination that comes with POS, TAB, gaming, payment gateway and compliance systems.

Support runs on monthly contracts with no lock-in, and chat response is under three minutes.

A cybersecurity audit: the fastest way to find out where your organisation stands against ASD's critical actions.

All IT is a Sydney-based managed IT provider supporting SMB, mid-market and enterprise organisations across Sydney, Melbourne, Brisbane, the Gold Coast and Orange/Central West NSW.


Frequently Asked Questions

It is the Australian Government's national cyber security campaign held every October, previously called Cyber Security Awareness Month. The 2026 theme is "Take a second. Stay secure." and it focuses on everyday habits such as updates, passphrases, multi-factor authentication, backups and spotting scams.
It is the Australian Signals Directorate's first year-long cyber security program, bringing government, industry and critical infrastructure together around practical, measurable actions. It is built on an assumed breach mindset and lists critical actions including replacing legacy technology, event logging and preparing for AI-enabled threats.
The October campaign is still running, but in 2026 it is called Cyber Security Action Month. The new name reflects the shift from raising awareness to taking practical steps, in line with ASD's Cyber Action Year.
It applies to both. ASD's critical actions are written with larger organisations and critical infrastructure in mind, but every one of them has a practical version for a small or mid-sized business, and the October everyday actions apply to every staff member regardless of organisation size.

Take a Second This October

We will help you check your organisation against ASD's Cyber Action Year critical actions during Cyber Security Action Month.