Post

ASD's frontier AI guidance for boards — it's not just for ASX 200 directors

The Australian Signals Directorate published something yesterday worth ten minutes of a board meeting’s time: Frontier AI cyber threat considerations for boards of directors, developed with the Australian Institute of Company Directors.

It reads like it was written for a listed company’s audit and risk committee, and in one sense it was. But strip out the ASX-200 framing and what’s left is a set of governance questions that apply just as directly to a school council, a small charity board, or a business owner who is the board because there isn’t one to delegate to.

What’s actually new here

The guidance isn’t really about AI chatbots being clever. It’s about what happens to attack timelines once frontier AI models get involved. ASD’s framing is specific: these models can identify vulnerabilities and weaponise them quickly, chain together several minor weaknesses into a serious compromise, and in some cases act with little to no human oversight on the attacker’s side.

The practical effect is that the gap between a vulnerability existing and someone exploiting it is shrinking — from what used to be days, toward hours. That matters most to organisations that were already slow to notice something was wrong, and under-resourced schools, charities and small businesses tend to sit exactly there.

The vulnerability isn’t new. What’s new is how little time you now have between someone finding it and someone using it.

Questions worth taking to your own board (or your own reflection, if you are the board)

ASD frames its guidance as threshold questions for directors to put to management. A few translate directly, whatever size organisation you’re running:

  • How vulnerable are we, realistically, to an AI-enabled attack against our most important systems — enrolment, finance, donor or client records?
  • What legacy technology are we still carrying, and do we have an actual plan to retire it, or are we just hoping it lasts another year?
  • Do we understand who our key vendors depend on — not just our IT provider, but the vendors they rely on?
  • If one of our core systems were compromised tonight, could we keep operating tomorrow?
  • Are we assuming a low likelihood of attack because we’re small, when the whole point of this guidance is that AI removes the “not worth the effort” calculation attackers used to make about smaller targets?

That last one is the one I’d push hardest on. “We’re too small to be a target” was already a weak assumption before AI made broad, individually-tailored attacks cheap to run at scale.

The part I keep coming back to: nobody’s actually testing this

Boards asking good questions is progress, but it’s not the same as knowing the answers hold up. ASD’s own priority list — secure configurations, patch known vulnerabilities, retire legacy systems, enforce least privilege, keep incident response plans current — reads as fairly standard cyber hygiene, and that’s deliberate. Frontier AI doesn’t require a new playbook so much as it raises the cost of not having the old one properly in place.

The gap I see most often, working with schools, charities and small businesses around Townsville and North Queensland, isn’t a missing policy document. It’s that the incident response plan was written once, filed, and never actually rehearsed against a scenario that looks like “our finance system is down and families or customers need to hear from us today.” A plan nobody has tested is a plan nobody actually trusts under pressure — and that’s true with or without AI in the threat model.

A short list, if you want to act on this before your next board cycle

  1. Put cyber on the agenda as its own item, separate from general IT or budget reporting.
  2. Ask who — a director, or an outside adviser — is actually equipped to challenge management’s answers, rather than accept reassurance at face value.
  3. Get an honest inventory of what you’re carrying: which systems are current, which are legacy, and who actually depends on which vendor.
  4. Pull out the incident response plan and check whether anyone could execute it from memory, under pressure, this week.
  5. Read the ASD guidance itself — it’s short, plainly written, and not gated behind anything.

I’ve written before about how Aon’s 2026 Independent Schools Risk Report found cyber risk sitting at the top of school boards’ concerns two surveys running, and outsourcing IT doesn’t outsource the risk that comes with it. This ASD guidance is the same message from a different angle: the board owns this, AI is compressing how much runway you have to get it right, and the fix starts with questions, not a technology purchase.

If your board, council or committee wants an outside view on any of this, it’s exactly the conversation Suburban Secure’s Leadership Technology Review is built around — including for organisations around Townsville and North Queensland.

This post is independent commentary on ASD and AICD’s published guidance. No affiliation or endorsement by ASD or the AICD is implied.

This post is licensed under CC BY-NC-ND 4.0 by the author.