Cybersecurity is an ongoing challenge for many organisations. In recent years, large-scale cybersecurity attacks have impacted the reputation and trust that many place in well-known companies, including Qantas, Medibank and Optus.
It’s clear cybersecurity is a pivotal part of contemporary workplaces, but beyond data breaches, what does the landscape look like in the current economy? What do leaders need to be focusing on now to be prepared for the next wave of cybersecurity threats to their Microsoft 365 tenant?
Here’s an overview of some of the biggest cybersecurity trends to watch as we head into 2027.
In this article
Australian organisations are heading into 2027 facing a cybersecurity landscape that is changing faster than most defences. AI has collapsed the time it takes attackers to compromise a Microsoft 365 tenant, reported breach numbers understate the true scale of the problem, and government regulation is set to tighten. This blog will look at the trends shaping the next wave of threats, from AI-assisted attacks to stricter mandatory reporting, and explain why the root cause so often traces back to poor governance of complex platforms like Microsoft 365.
When it comes to AI and cybersecurity, we’re already in the thick of a technological turning point. Anthropic held back the release of its Claude Mythos due to significant security vulnerability-testing capabilities and concerns that this could be used for the wrong reasons.
AI cybersecurity threats aren’t hypothetical, and they’re only becoming more advanced. What used to take hackers days or weeks to achieve in a Microsoft 365 tenant can now be executed in seconds with a single prompt to AI agents. AI doesn’t fatigue, and it works exponentially faster than any human actor.
Signalling back to Claude Mythos, the question everyone is asking is what more advanced AI systems might eventually be capable of. I tend to describe this quite plainly: a beast lurking just under the covers, with the potential to disrupt organisations and entire cloud ecosystems in ways that nobody can yet fully predict.
The majority of companies now subscribe to some form of AI tool for workplace productivity, with many reaping significant benefits. The challenge ahead is where AI-powered productivity and AI-powered threats collide on what I refer to as the ‘digital battlefield’.
From a Microsoft perspective, CoPilot is already strongly intertwined in many business practices. As people invest more in AI and outsource to agents, the challenges we’re seeing from a Microsoft 365 and digital footprint standpoint will only increase.
Between January and October 2025, Australia publicly reported 71 data breaches involving businesses. Compared to the 48 reported breaches in the same period in 2024, that's a 48% increase, and this is likely just the tip of the iceberg.
While Australia has made progress on breach notification legislation, requiring public companies and government agencies to report incidents that meet certain thresholds, I believe this only captures a fraction of what’s actually occurring - and this is only going to get more complicated as we head into 2027. It’s highly likely there will be a significant surge in breach activity, driven largely by AI-assisted attacks, suggesting that reported figures are already vastly understated.
While 71 breaches might appear in a dataset, the actual number could be exponentially higher depending on how breaches are defined at both a governmental and individual organisational level.
The root cause traces back through a clear chain: breaches stem from security incidents, which stem from poor governance, which stems from administrators being overwhelmed by complex platforms, like Microsoft 365, without adequate tooling to manage them effectively.
Addressing future cybersecurity trends requires a coordinated response at both the state and federal levels, with meaningful government investment in stronger controls. As things stand, we see the problem worsening before it improves, especially in the Microsoft 365 environment. As governments attempt to keep up, we’ll likely see stricter mandatory reporting requirements, with audits, fines, and legal consequences for those who don’t meet them.
None of this is exactly a new paradigm for cybersecurity, but there will be gaps between governmental policies and approaches to acknowledging, addressing and reporting breaches versus what is practical and feasible for businesses. In over 15 years of experience in the sector, I’ve consistently seen the ways every organisation has to assume a degree of risk to operate its business. It’s a constant balance between security and convenience.
What’s changing now and into the near future is the inherent understanding of the degree of risk that businesses are basing their decisions on.
Based on my experience and what we’ve seen occur historically, I believe the government’s primary role, beyond legislation on reporting, should be to raise awareness of contemporary and emerging cybersecurity risks and offer clear guidance on how to address them, rather than defaulting to punitive measures. The real consequences for businesses that fail to act won’t come from fines or audits: they’ll come from the threats themselves rendering organisations ineffective or obsolete.
With that existential stake in mind, we need to advocate for a shift from a carrot-and-stick approach to one rooted in education and proactive support that fully addresses current and emerging risks.
For IT leaders making the case for greater Microsoft 365 cyber resilience investment, my advice is to start with what’s already true: the decision to adopt M365 has already been made.
With around 78% of organisations worldwide running on the platform, it’s become the digital backbone of modern business. The real question is whether the tools and processes protecting that backbone have kept pace.
Organisations are still relying on legacy approaches to administer, secure, and govern a Microsoft 365 tenant, which is anything but legacy. This isn’t a failure of intent but a product of assumptions and misconceptions about what Microsoft 365 actually requires to remain secure. The platform is unique in its complexity and central to how businesses operate. We’re dealing with more advanced risks, which demand an entirely new way of thinking about governance and protection.
That awareness is at the heart of what CoreView set out to do in helping organisations understand the scope of the challenge within their M365 tenant. It’s an approach I’m hopeful will take hold more broadly, both at the organisational level and across the industry at large.
If this conversation has prompted you to take a closer look at how your M365 tenant is governed and protected, then CoreView can help you turn that closer look into action. Start with the Microsoft 365 tenant resilience assessment and see where your governance stands.