Assumed Breach: An Operational Necessity for IT Leaders

Why “not if, but when” has stopped being a warning and started being an operating assumption for Australian IT and risk leaders.

“It’s not if, but when.” The line is very familiar to all in cyber security circles. What’s different now is that ASD’s own data turns it from a cautionary line into an operating assumption: something built into how an organisation runs, not just something repeated after an incident.

What Assumed Breach Mindset Actually Requires

Traditional security planning optimises almost entirely for keeping attackers out. An assumed breach posture adds equal weight to what happens the moment that doesn’t hold: noticing an intrusion quickly, limiting how far it can spread, and restoring normal operations before a small compromise turns into a prolonged outage.

ASD makes this explicit in its own Annual Cyber Threat Report 2024–25, recommending that businesses operate with a mindset of “assume compromise” and prioritise protecting the assets that matter most. This isn’t a slogan pulled from a headline. It’s formal guidance from the national technical authority on cyber security.

Why We're Raising This Now

That report, released in October 2025, recorded more than 1,200 cyber security incidents responded to by ASD’s Australian Cyber Security Centre, an 11 per cent increase on the year before, and more than 1,700 proactive notifications of potential malicious activity, an 83 per cent increase.

Months after that data was published, the intelligence and cyber security agencies of Australia, the UK, the US, Canada, and New Zealand issued a joint statement making a related point from a different angle: that having controls in place is no longer enough, and leaders need confidence those controls will perform during a real incident. ASD’s own numbers were already pointing this way before five national agencies said so publicly and together. That’s the same conclusion, reached independently, twice.

The Shift From Prevention-Only to Detect, Contain, Recover

The practical value of assumed breach thinking is in the questions it puts in front of an organisation that prevention-only planning never has to answer:

  • Not “can attackers get in,” but “how long would it take us to notice if they had”
  • Not “do we have a firewall,” but “what happens the moment something gets past it”
  • Not “is there an incident response plan,” but “when was it last tested against a real scenario, not just written and filed”

That last one is the gap most mid-market organisations haven’t closed. A plan that exists is not the same as a plan that’s been rehearsed. Attackers, increasingly assisted by AI tooling, are moving from initial access to impact faster than most detection and patch cycles are built to handle, which compresses the time an organisation has to notice something is wrong before it becomes material.

The Number That Actually Matters Isn't 83%

The 83 per cent increase in threat notifications is the figure that gets quoted, but it isn’t the one that should shape planning. A growing count of alerts confirms that activity is increasing. On its own, it says nothing about how many of those alerts were followed up properly, and how many simply accumulated without anyone getting to them.

Generating more alerts without the capacity to work through them doesn’t make an organisation safer. It mostly means there’s more of a paper trail afterwards, showing activity nobody acted on while it still mattered. The gap between what gets flagged and what gets actioned is exactly where an assumed breach posture is meant to close in.

It’s also worth being precise about what this figure does and doesn’t prove. Some of the year-on-year increase likely reflects improved detection and reporting requirements, not purely a matching rise in attacker activity. That doesn’t undercut the broader trend. Cybercrime in Australia is still increasing in frequency and cost year over year, on ASD’s own figures. But it’s a reason to treat the number as a signal worth acting on, not a statistic to repeat without context.

The Question Worth Asking Now

Assumed breach thinking doesn’t need a bigger budget before it starts. It needs an honest answer to one uncomfortable question: if someone got into your systems tonight, would tomorrow’s response follow a process your team has actually rehearsed, or would people be working it out as they went?

If that answer isn’t a confident one, that’s the gap worth closing before an actual incident closes it for you.

If you’d like an honest, independent picture of how your organisation would actually respond if an incident happened tomorrow, not just whether your controls exist on paper, our team is ready to walk you through what that looks like.

FAQs

What does "assumed breach" mean in cyber security?

Assumed breach is an operating posture that treats a security incident as inevitable rather than avoidable. Rather than focusing solely on keeping attackers out, it puts equal weight on how quickly an organisation notices an intrusion, limits its spread, and restores normal operations

Why is this relevant now?

ASD's Annual Cyber Threat Report 2024–25 recorded an 11 per cent rise in cyber security incidents and an 83 per cent rise in proactive threat notifications compared to the previous year. Combined with AI-assisted attacks shortening the gap between initial access and impact, relying on prevention alone is no longer sufficient.

Does assumed breach mean prevention doesn't matter?

No. Prevention remains essential. Assumed breach adds a second, equally important capability: a rehearsed way of noticing, containing, and recovering from the moments prevention doesn't hold. Organisations that invest only in prevention often have no tested plan for what comes after.

How does this relate to the Five Eyes statement on cyber risk?

The Five Eyes joint statement argued that having controls isn't enough, and that leaders need confidence those controls will perform during a real incident. ASD's own incident and notification data, published months earlier, shows the same pattern from a different angle: the assumption that controls are working needs to be tested, not taken on faith.

What should Australian IT and risk leaders do first?

Start by testing, not assuming, how the organisation would detect and respond to an incident today. A structured security posture assessment provides an independent, current view of detection and response capability, rather than relying on when the incident response plan was last reviewed on paper.

 

 

Let's see how we can personalise your cloud computing needs

Evolution Systems is ISO 27001 Certified