For years, network and security teams have operated separately, often at odds. One prioritised keeping things open, while the other focussed on locking them down. That gap is disappearing fast elsewhere across the Asia Pacific and Japan (APJ region, where the network is now largely treated as part of security from the outset.
It’s that gap where Australia is falling behind. 2026 figures published by the Australian Government’s Office of the Australian Information Commissioner (OAIC) show Australia recorded 1,205 notifiable data breaches in 2025, the highest annual total since mandatory reporting began and an 8% increase on the year prior. At the same time, the Australin Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) issued an advisory on threat actors targeting internet-facing network devices, specifically citing exposed management services, weak configurations and known vulnerabilities as being used to steal network information and credentials.
The good news is that the path forward is already mapped elsewhere in the region. Australian organisations do not have to work out whether this merging of operations works, only how to get there quickly.
Part of the urgency is that threats aren't standing still. Initiatives such as Project Glasswing, powered by Anthropic's Claude Mythos Preview model, show just how quickly AI is changing the speed and scale at which vulnerabilities can be identified. The Hugging Face incident in July 2026 made the risk more tangible, with autonomous AI agents recovering exposed credentials and exploiting vulnerabilities to expand their access across internal systems.
That speed makes delayed security controls increasingly untenable, because every new connection or outdated policy can create a period in which access is not fully understood or controlled.
Here is how it can look in practice: a device connects from a new location, a policy hasn't been updated to cover it, and a window opens, sometimes for hours, sometimes longer, where nobody in the business can say with confidence who or what has access to the network. Those are exactly the kinds of gaps attackers have shown they can exploit.
There's a structural problem underneath this too. Network teams and security teams have traditionally worked to different priorities, and much of the infrastructure built during that split reflects it. Remote access is one example. Recent exploits in Australia have shown attackers successfully using compromised third-party credentials to access enterprise networks as a pathway into a wider environment.
It's a reminder that the network can't be treated simply as the transport layer underneath security; the network itself is part of the security ecosystem.
This structural split shows up organisationally as well. In parts of APJ, it's common for network and security teams to report into the same function, share tooling, and work from a single view of who and what is connected. In Australia, that's still the exception rather than the norm.
The consequences are often procedural rather than technical. A device may be approved without the security team having full visibility, or a connectivity change may be implemented without its broader security implications being assessed. When network and security teams operate with different information and timelines, routine decisions can introduce risks that neither team identifies early enough.
The pace of this shift elsewhere in the region also means Australian organisations are increasingly competing against (and being targeted alongside) businesses that have already closed this gap. Unfortunately, a slower-moving target is a more attractive one.
Closing that gap starts with treating the network as a sensor that actively helps defend the business and moves with it rather than a passive layer everything else sits on top of. Ultimately, the network and the security posture must merge to become the same conversation.
Most organisations don't have the luxury of ripping out their existing network and starting again. The more realistic path is building on infrastructure that's already proven at scale, and then extending it to do more, rather than layering a new security product on top and hoping the two systems talk to each other properly.
Most of the infrastructure needed to strengthen this position is already sitting inside these organisations. We need to be treating network and security as one foundation, rather than patching problems after they have materialised.
Security and the network are not two separate problems to be solved by two separate teams, they're one and the same.




