Companies Urged to "Assume You've Been Breached"
28 July 2026
The Australian Cyber Security Centre (CSC) - part of Australia’s top intelligence gathering agency – has urged organisations to adopt an “assumed breach mindset”.
Put simply it’s advising companies to approach their cyber security on the basis that a breach has either already occurred or is imminent.
Defeatist…?
That’s not defeatism. It’s a practical evidence‑based shift in mindset driven by the speed, scale, and sophistication of modern cyber threats.
ACSC’s rationale is straightforward. Attackers no longer rely on exotic zero‑days or elite skills. They exploit weak credentials, legacy systems, unpatched software, misconfigurations, and human behaviour - all common in organisations. Once they’ve gained access, they move quickly, quietly, and laterally.
By the time a traditional perimeter‑focused security model detects them, the damage may already be done.
Flipping the Traditional Mindset
An assumed‑breach mindset flips the traditional corporate IT approach. Instead of asking, “How do we keep attackers out?” the ACSC encourages organisations to ask, “How do we limit what an attacker can do once they’re in?”
This shift drives a different set of behaviours: continuous monitoring, rapid detection, containment, segmentation, least‑privilege access, and rigorous credential hygiene. It also forces leaders to confront uncomfortable truths about legacy technology, technical debt, and the fragility of critical business systems.
The ACSC is clear that this mindset isn’t just a technical posture, it’s a governance posture. Boards and executives must treat cyber risk as a business risk rather than an IT issue. That means investing in modern platforms, reducing reliance on end‑of‑life systems, enforcing Multi-Factor Authentication (MFA), uplifting logging and monitoring, and ensuring incident response plans assume internal compromise from day one.
The organisations that thrive in the current threat landscape aren’t the ones with perfect defences. They’re the ones that plan for failure, limit blast radius, and respond with speed and clarity.
The Mindset and MFT
Managed File Transfer (MFT) directly helps organisations adopt an assumed breach mindset by ensuring that even if an attacker infiltrates the network, data in transit and at rest remains heavily protected, tracked, and contained. Rather than relying on network perimeter security to keep data safe, MFT operates on the principle that the surrounding environment may be compromised, safeguarding the data itself.
This includes:
Data-Centric Encryption: MFT encrypts data while stored and while in transit. Even if an attacker has successfully breached the network and intercepts the files, the data remains unreadable and useless without the decryption keys.
Tamper-Evident Auditing: Comprehensive, automated logs trace exactly who accessed, sent, or received a file. In an assumed breach scenario, these pristine audit trails are vital for forensic teams to quickly pinpoint what data was exposed.
Micro-Segmentation of Data Flows: MFT removes files from vulnerable, shared network drives and places them in isolated, secure repositories. This restricts an attacker's ability to move laterally across the network to steal sensitive data.
Strict Access Control: MFT platforms enforce role-based access control and MFA. If an attacker compromises a basic user account, MFT prevents them from accessing high-value file transfer workflows.
Centralised Visibility: Instead of employees using unmonitored "Shadow IT" tools (such as personal cloud storage), MFT funnels all transfers through a single, monitored gateway. This enables security teams to easily spot anomalous data movements that indicate an active breach.
Local Help on Hand
At Generic Systems Australia, we’re Australia’s and New Zealand’s deep local experts in MFT. A top ten MFT partner for Fortra globally, we have many years of experience helping organisations from small to multinational install and leverage the world’s leading MFT, GoAnywhere.
Let us know if you’d like to learn more about how GoAnywhere MFT can help you follow the ACSC’s advice.
