Navigating the Next Wave of Cybersecurity: Insights from Compnow and Fortinet.

Cybersecurity remains one of the most critical priorities for organisations of every size, driven by rapid digital transformation, hybrid work models and increasingly industrialised threat activity. In a recent webinar, Compnow’s Chief Technology Officer, Julian Critchlow, sat down with Glenn Maiden, Chief Security Officer and Director of Threat Intelligence at Fortinet Australia, to explore the current threat landscape and the practical steps organisations can take to strengthen their posture.

With more than two decades in government intelligence and security, including roles supporting critical national systems and services, Glenn brings a unique perspective on how threats evolve and how defences must adapt.

Talk to an expert

The shifting threat landscape

Despite the continued prominence of cyber incidents in the media, Glenn suggests that some narratives around attacker sophistication are overstated. While credential theft, commodity ransomware and initial access tooling continue to innovate, the tactics used after that point are widely understood. The tools, processes and people required to counter them already exist.

However, threat actors are becoming more industrialised. Weaponisation timelines for new vulnerabilities have compressed from months to days or weeks. Attackers are also experimenting with AI for reverse engineering, targeting automation and social engineering at scale. As defenders adopt AI to accelerate detection and containment, adversaries are doing the same.

Deepfakes and digital identity risk

A growing area of concern is the convergence of deepfake technology with real-time conversational AI, enabling attackers to impersonate executives or trusted individuals convincingly. Glenn expects this capability to emerge more widely within the next 12 to 18 months, creating new challenges for identity verification and fraud prevention.

The pressure on small and medium business

Large enterprises often have dedicated security teams, governance frameworks and rapid patch deployment processes. In contrast, most organisations in Australia and New Zealand are small businesses with fewer than twenty employees, and many lack specialist resources. This leaves them disproportionately exposed to industrialised attack campaigns. Sympathy and realism are required. Complexity is challenging even for well funded teams.

Post-Covid transformation and the hybrid perimeter

Hybrid work has fundamentally changed how IT environments are secured. Users can connect from anywhere, on almost any device, to data hosted in SaaS platforms or multi-cloud environments. Traditional perimeter controls no longer apply. Surprisingly, unforced errors during the rush to remote work were fewer than expected. Many organisations deployed effective platforms under pressure, and now have an opportunity to refresh and refine those environments without the urgency of crisis.

This second cycle is where strategic improvements can be made.

Zero Trust, SASE and platform consolidation

As networking and security converge, architectures such as Zero Trust and Secure Access Service Edge (SASE) provide a structured way to manage modern risk. Organisations may already have some of the core components in place, including multifactor authentication, identity management or SD-WAN. The focus now is on unifying policies, reducing tool sprawl and aligning governance with business outcomes.

Limiting blast radius through visibility and automation

Breaches are no longer a question of if, but when. The objective is to restrict attacker movement so that impacts remain negligible. Converged security architectures allow organisations to:

  • baseline normal behaviour
  • identify anomalous activity early
  • enforce least privilege across users and devices
  • automate response at machine speed

Stopping attackers before they reach their objective phase can be the difference between minor disruption and catastrophic loss.

The importance of exercising incident response

Many organisations have policies and playbooks, but few have tested them. Glenn emphasises that rehearsing incident scenarios is essential. Testing uncovers gaps in context, communication and decision-making. Boards are now more accountable than ever, and regulatory expectations continue to rise. Preparedness cannot be theoretical.

Planning the next cycle of investment

Ransomware payouts are trending down. Endpoint controls continue to improve. Security maturity is making an impact. However, waiting to invest until after an incident is costly. Glenn recommends reviewing existing platforms, refining processes and building on what already works rather than starting from scratch.

Sound investments made now, while not under stress, can materially reduce risk.

How Compnow can help

Compnow works with leading partners such as Fortinet to deliver architectural guidance, platform consolidation, security tooling, incident preparedness and lifecycle support tailored to the needs of each organisation. Whether you are modernising hybrid work environments, uplifting governance or planning a Zero Trust strategy, our teams can help chart a practical and staged path forward.

Talk to an expert

I am looking to
Check warranty and insurance status

How to find your serial number?

  • Send us a message

    Want to know more about how we can help with your requirements?

    Send us a message and one of our experts will be in touch to answer your questions.