ASD Cyber Action Year 2026
What It Means for You

This October is Cyber Security Action Month, and ASD has made 2026 its first Cyber Action Year. Its first recommendation is to replace or mitigate legacy technology. Here’s how to act on it.

Pixelbird client
Pixelbird client
Pixelbird client

Over a decade of website security expertise

From Awareness to Action

October has long been Cyber Security Awareness Month in Australia. In 2026 it is Cyber Security Action Month, with the theme “Take a second. Stay secure.”, and the Australian Signals Directorate has launched its first Cyber Action Year, urging organisations to adopt an ‘assumed breach’ mindset: plan for when, not if.

ASD’s critical actions for organisational resilience are to replace or mitigate legacy technologies, implement best-practice event logging, choose secure-by-design products and services, and prepare for post-quantum cryptography and AI-enabled threats.

ASD’s 2024–25 Annual Cyber Threat Report recorded more than 84,700 cybercrime reports, one every six minutes, and more than 1,200 incidents it responded to, up 11%.

Businessman Wearing Headset Talking To Caller In Busy Customer Services Centre

Turning ASD’s

Advice Into

Real

Action

Turning ASD’s Advice

Into Real Action

Turning ASD’s Advice

Into Real Action

Replace or mitigate legacy technology. End-of-life Drupal, Joomla, Magento and PHP sites are exactly what ASD means. We take them over, harden them and move them onto supported platforms.

Best-practice event logging. If you can’t see who logged in, what changed and what was accessed, you can’t assess a breach. We put logging and monitoring in place on your websites and servers.

Secure by design. New platforms and custom software are built with security from the first line of code, not bolted on later. Assumed breach. We help you plan the response before you need it, and handle it when it happens.

Smiling mature confident professional executive manager at office.

Where to

Start This

October

Where to Start

This October

Where to Start

This October

Find Your Legacy Tech

An audit identifies every end-of-life platform, abandoned plugin and unsupported server version across your web estate.

Switch On the Basics

Updates, multi-factor authentication and tested backups on every website, portal and admin account.

Plan for the Day It Happens

Logging, a response plan and a team to call, so a breach is a bad day rather than a crisis.

0 +

Cybercrime Reports to ASD in 2024–25

0

Minutes Between Reports, on Average

0 +

Incidents ASD Responded To in 2024–25

$ 0

Average Cost per Report for a Small Business

How It Works

Tell us what you’re running. We’ll point out the legacy and logging gaps worth fixing first.

Young African businessman looking at data on computer screen

Step 2: Audit Your

Web Estate

We find end-of-life platforms, missing logging, weak admin access and untested backups.

Group of young happy business people looking at laptop screen, communocating and discussing work

Step 3: Act on

the Findings

You get a prioritised plan for your board, and we can replace, harden or migrate what needs it.

Brands We Have Helped

What People Say

Makes the Magic Happen

“Love the professional finishes . Dustin and the team know how to make the magic happen.”

Sam Hunter

Sam Hunter

Corporate Headshot Photographer

Always Shows Up

“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”

Kym Bolger

Kym Bolger

Social Media Marketing

Responsive Professionalism

“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”

Ivan Huang

Ivan Huang

CPA

What You Can Expect

ASD Recommendation

What We Do

Common Gap

Replace Legacy Technology

With Us

Migrate end-of-life platforms to supported ones

With Them

Unsupported CMS still live

Mitigate Legacy Technology

With Us

Harden and monitor what can’t move yet

With Them

Left exposed until a rebuild

Event Logging

With Us

Admin, file and access events logged and kept

With Them

No logs to investigate with

Secure by Design

With Us

Security built into new platforms from day one

With Them

Security added after launch

Assumed Breach

With Us

Response plan and incident support ready

With Them

Working it out on the day

Patching

With Us

CMS, plugins and servers kept current

With Them

Updates months behind

Multi-Factor Authentication

With Us

MFA on every admin and hosting account

With Them

Password-only logins

Backups

With Us

Off-site and restore-tested

With Them

Never actually restored

AI-Enabled Threats

With Us

Faster patching and monitoring for automated attacks

With Them

Assuming attackers are slow

Board Reporting

With Us

Plain-English progress for directors

With Them

Technical jargon

Frequently Asked Questions

In 2026, October’s national cyber security campaign became Cyber Security Action Month, shifting the focus from awareness to practical action. The theme is “Take a second. Stay secure.”

An ASD-led, industry-driven program launched in 2026 that brings government, industry and critical infrastructure together to deliver practical, measurable cyber security outcomes, built around an assumed breach mindset.

If your site runs on an end-of-life CMS, unsupported PHP or abandoned plugins, it can’t be fully patched. Replace means migrating to a supported platform; mitigate means hardening and monitoring it until you can.

Planning on the basis that a compromise will happen at some point: limiting what attackers can reach, logging what happens, and having a tested plan to detect, contain and recover.

With an audit of your web estate. It shows which legacy technology, logging gaps and access weaknesses matter most, so you can act on ASD’s advice in priority order.

Turn This October Into Action