Outsourcing reimagined for FSI in New Zealand: From operational support to strategic growth enabler

Get in touch

daniel dsouza
Head of Information Security Solutions, Canon Business Services ANZ

Daniel D'Souza is a highly accomplished Information Security professional with a wealth of experience spanning over a decade. His professional journey has covered multiple market sectors including finance, insurance, technology, education, and consulting. The latest of which led him to join the dynamic team at Satalyst, a Canon Business Services Australia company, as an Information Security Manager. In this role, Daniel was instrumental in helping customers safeguard their digital assets, protect their data, and mature their Information Security control environment. 

In recognition of his expertise Daniel was then transitioned into a pivotal secondment as the Manager of IT Governance, Risk & Compliance within Canon Business Services. Daniel's scrupulous oversight in ensuring key security audits and assessments were delivered has not only strengthened the implementation of CBS’ governance framework, but also substantiated a robust security infrastructure, both for CBS and its customers. 

Currently serving as the Head of Information Security Solutions at CBS, Daniel’s insightful approach to cybersecurity leadership plays a key role in ensuring CBS customers leverage the latest in Information Security technology and services. In this role he brings together strategic vision and a team of highly skilled cyber security professionals with vast real-world experience in reducing business risk through cyber resilience. 

Last updated Tuesday 29 September 2026
Summary:

Modern cybersecurity depends on bringing networking and security services together so organisations can protect users wherever they connect. SASE security services and security service edge (SSE) can support secure network access across cloud services, branch offices, remote environments, and the network edge, while reducing reliance on multiple point solutions. A cloud-native platform can also enable centralised, unified management, consistent data protection, advanced threat protection, and stronger control over web traffic. The goal isn't centralised management, but networking and security capabilities that apply consistent policies across a distributed organisation and strengthen resilience when threats get through.

Cybersecurity is traditionally framed around prevention: keep attackers out, protect the network perimeter, and stop incidents before they happen.

That objective still matters. But it’s no longer enough.

Australia’s threat environment makes the challenge clear. The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 recorded more than 1,200 cybersecurity incidents, up 11% from the previous year. The average self-reported cost of cybercrime to Australian businesses also rose 50%, to $80,850 per report.

At the same time, organisations are adopting cloud-delivered services, artificial intelligence, and distributed working models that make the traditional network perimeter increasingly difficult to define.

The future cybersecurity strategy therefore needs to address a harder question: not simply ‘how do we prevent an attack’ but ‘how do we protect critical operations when an attack succeeds’?

That means moving towards cyber resilience: reducing cyber risk, limiting the impact of compromise, maintaining critical services, and recovering quickly. Prevention remains essential, but resilience assumes no security stack, however sophisticated, can remove every vulnerability or stop every threat.

1. Future state: Making AI adoption secure by design

AI adoption presents security teams with a familiar tension at an unfamiliar speed.

Business leaders want the productivity, automation, and competitive advantages AI can deliver. Employees are already experimenting with generative AI and agents. Yet governance, security tools and controls, and data protection often develop more slowly than adoption itself.

Microsoft’s 2026 Data Security Index found only 47% of organisations were implementing controls specifically focused on generative AI workloads. It also found that generative AI use was involved in 32% of surveyed organisations’ data security incidents.

Chris Georgellis, CBS National Solutions Advisor – Security, sees the same tension emerging with customers.

“Technology adoption is moving much faster than security maturity,” he says. “Organisations are embracing AI, cloud platforms, and hybrid work models to drive productivity and innovation, but many are expanding their attack surface without fully understanding the associated risks.”

AI data exposure is a particular concern. Employees may use public or unsanctioned AI services to increase productivity without fully understanding what happens to the information they enter.

The risk isn’t necessarily the AI platform. It’s sensitive corporate, customer, or intellectual property data being disclosed through poorly governed use.

The answer isn’t to make security the gatekeeper that slows every AI initiative. Strong security can make responsible adoption possible.

That starts with visibility. Organisations need to understand which AI services are in use, what sensitive data they can access, which cloud applications they connect to, and what actions users can perform through them.

Governance then provides the boundaries. Roles, responsibilities, and risk tolerance should be explicit. Access controls should apply least-privilege principles. Data loss prevention and classification policies should follow sensitive data into AI-enabled workflows rather than stopping at traditional corporate network boundaries.

This is increasingly the role of the modern security team. More than simply protecting technology, your cybersecurity team should be creating the conditions under which the business can use emerging technology safely.

2. Future state: Governing autonomous AI agents

The next challenge is more complicated. AI is moving from providing information to taking action.

An autonomous agent may access systems, retrieve data, execute workflows, communicate with other services, or decide on a user’s behalf. That creates a fundamentally different cyber risk from a chatbot that simply generates an answer.

In February 2026, Microsoft reported that more than 80% of Fortune 500 companies were using active AI agents, while 29% of employees surveyed had used unsanctioned agents for work tasks.

The security implication is straightforward: an agent needs an identity, and that identity requires governance.

That matters because identity is already becoming one of the most important pathways into modern business environments. As Chris explains, attackers increasingly target “credentials, privileged accounts, and cloud-based identities”, rather than attempting to breach a traditional network perimeter directly.

A compromised identity can potentially provide access to cloud applications, collaboration services, data, and business systems without an attacker ever having to ‘break into’ the corporate network in the conventional sense.

AI agents should therefore be subject to many of the same Zero Trust principles applied to human users and service accounts:
  • Give agents only the access required to perform their function.
  • Explicitly verify identities and requests before granting access.
  • Limit permissions to specific cloud resources, applications, and data.
  • Continuously monitor agent activity and behaviour.
  • Maintain clear ownership and accountability.
  • Assume that an agent, credential, or connected system could become compromised.

Observability is crucially important. Security teams can’t control an agent they don’t know exists, and they can’t assess risk without understanding which systems, data, and network resources it can reach.

As agentic AI expands, the question increasingly isn’t who has access? It’s what non-human identities can act, what can they do, and who remains accountable for those actions?

3. Future state: Moving from vulnerability management to exposure management

Another fundamental change is happening in the way we think about vulnerabilities.

The number of potential exposures has grown beyond the ability of many security teams to remediate everything at once. ASD reported a 28% increase in publicly reported common vulnerabilities and exposures during FY2024–25 alone.

Treating every vulnerability as equally urgent is neither practical nor strategically useful.

Exposure management starts with risk assessment. Rather than simply counting vulnerabilities, organisations assess which weaknesses create plausible attack paths to critical systems, sensitive data, and business operations.

Identity is central to that analysis.

Modern attacks often move between endpoints, SaaS applications, cloud resources, and business systems using compromised credentials and excessive privileges. A relatively minor technical weakness can become a significant cyber risk when it connects to an over-privileged account or inadequately controlled access path.

Chris believes lateral movement remains particularly underestimated.

“Many invest heavily in prevention technologies but don't adequately consider what happens after an attacker gains initial access. Once inside, attackers can often move across systems, escalate privileges and access critical assets far more easily than they should,” he says.

Chris Georgellis, National Solutions Advisor-Security at Canon Business Services ANZ (CBS)


The stronger question therefore becomes: what could an attacker reach from here? That shifts security priorities towards:
  • Critical assets and business services
  • Privileged identities
  • Unnecessary access rights
  • Exposed cloud resources
  • Weak authentication
  • Third-party connectivity
  • Attack paths between systems
  • The likely business impact of compromise

Risk analysis can then help security teams prioritise security measures by asset criticality, likelihood, and potential impact.

This doesn’t mean patching becomes less important. It means patching and other security controls are applied with greater context, helping organisations direct limited resources towards the exposures most likely to cause material harm.

4. Future state: Operationalising Zero Trust and Assume Breach

The traditional network security model assumed a relatively clear boundary. Trusted users and systems sat inside the corporate network, while cyber threats were kept outside.

Cloud applications, branch offices, remote workers, mobile devices, and distributed environments have made that model increasingly difficult to sustain.

Daniel D'Souza, CBS Head of Information Security, sees this driving a broader change in how organisations think about trust.

“One of the biggest shifts is that organisations are starting to view Zero Trust less as a security initiative and more as an operating model. Traditional assumptions about trust based on network location are becoming less relevant, particularly as users, applications, and data sit across cloud services and distributed environments.”

Instead, access decisions increasingly need to consider:
  • Identity
  • Device posture
  • Behaviour
  • Context
  • Risk
ASD’s guidance on modern defensible architecture describes three foundations:
  1. Never trust automatically
  2. Explicitly verify access
  3. Assume an attacker may already be present
Assume Breach takes that thinking further. As Chris puts it:

“An ‘assume breach’ mindset starts with accepting a simple reality: at some point, an attacker will get in. Now the question isn’t, ‘How do we stop every attack?’ but, ‘How do we minimise the impact when an attack occurs?’”

In practice, that means designing security infrastructure around containment and prevention.

Strong identity security is one layer. Multi-factor authentication, privileged access management, conditional access, and continuous identity monitoring can reduce the opportunity for compromised credentials to be abused.

Segmentation is another. A compromised workstation shouldn’t give an attacker unrestricted movement through the environment. Network segmentation, micro-segmentation, and Zero Trust Network Access can limit lateral movement and reduce the potential blast radius.

Visibility is equally important. High-quality telemetry across endpoints, cloud services, identities, applications, and networks lets security teams identify suspicious activity and respond before a contained incident develops into a larger breach.

Automation can also improve response speed. Security platforms may isolate compromised devices, disable accounts, or contain malicious activity in seconds rather than waiting for manual intervention.

Where SASE fits

Secure Access Service Edge (SASE) can support this modern operating model from a technology perspective.

A SASE architecture combines networking and comprehensive security services through a cloud-delivered framework, helping organisations provide secure connectivity to users, whether they're accessing a data centre, branch office, cloud service, or business application.

A SASE solution typically combines network connectivity with security service edge capabilities such as Zero Trust Network Access (ZTNA), secure web gateway, cloud access security broker (CASB), and data loss prevention.

ZTNA can provide secure remote access to specific applications based on identity and context rather than granting broad access to the corporate network.

This consolidation addresses a practical problem many security teams face: multiple point security solutions creating fragmented policies, duplicated security functions, and limited visibility. Gartner forecasts the global SASE market will reach US$28.5 billion by 2028, reflecting growing demand to consolidate networking and security functions as organisations become more distributed.

But Daniel cautions against treating SASE as the strategy itself.

“SASE often supports this approach from a technology perspective, but the bigger change is how organisations think about trust,” he explains. “Zero Trust is often misunderstood as a technology initiative, when it’s actually a framework for reducing reliance on implicit trust.”

SASE is therefore an enabling cloud-delivered architecture rather than an end state. Its value comes from supporting consistent security policies, secure connectivity, and Zero Trust principles across remote users, branch offices, cloud apps, and distributed environments.

5. Future state: Building resilience when prevention fails

Assuming breach doesn’t mean accepting defeat. It means planning for reality.

Cyber resilience is the ability to contain an incident, maintain essential business operations, and restore affected services quickly. That requires preparation long before a breach occurs.

NIST’s current Cybersecurity Framework 2.0 captures this lifecycle through six functions:
  1. Govern
  2. Identify
  3. Protect
  4. Detect
  5. Respond
  6. Recover

The addition of ‘Govern’ reinforces an important point — cybersecurity is an enterprise risk issue, not just an IT responsibility.

This distinction appears clearly in the organisations furthest along their resilience journey, Daniel notes.

“The most resilient organisations have accepted that prevention alone isn’t enough. They understand not every vulnerability can be patched, not every threat can be predicted, and not every attack can be stopped. Rather than focusing solely on prevention, they invest equally in their ability to detect, respond, recover, and continue operating during a security event.”

Daniel D'Souza, Head of Information Security at Canon Business Services ANZ (CBS)

A resilient organisation therefore needs layers of protective and recovery capability

An incident response plan should define responsibilities, escalation processes, and procedures for containing, investigating, and recovering from incidents. But plans also need to be tested.

Chris points to executive tabletop exercises, recovery testing, and validated backups as essential components of operational readiness.

“During a cyber incident, organisations rarely rise to the level of their plans. They fall back to the level of their preparation,” he explains.

Backups remain critical. ASD recommends the 3-2-1 backup strategy: maintain three copies of important data across two different media, with one copy stored offsite. Backups also need regular restoration testing. A backup you can’t restore quickly isn’t a resilience strategy.

People remain another essential layer. Regular cybersecurity training should cover phishing, social engineering, secure data handling, and incident reporting, so your employees understand how attacks occur and what action to take when something looks wrong.

Third parties need the same scrutiny. ASD’s September 2026 procurement and outsourcing guidance recommends cyber supply-chain risk assessments and ongoing security assessments of managed service providers with access to organisational facilities, systems, or data.

Vendor security can no longer be a one-off questionnaire completed during procurement. Organisations need ongoing visibility into their suppliers’ security posture, access, data handling, and incident-response responsibilities.

Measuring what matters

A mature cyber resilience program should ultimately be measured in business terms.
cyber resilience
Daniel argues that this risk-based mindset is one of the clearest differences between resilient organisations and those still focused primarily on prevention.

“They understand which systems and services matter most, where security investment will have the greatest impact, and where risk needs to be actively managed rather than avoided,” he explains. “Security becomes part of enabling the business to operate with confidence, even when disruption occurs.”

Preventing an attack will always be the preferred outcome. But resilience determines what happens when prevention isn’t enough.

The future of cybersecurity is resilience

The future state of cybersecurity isn’t a world in which every breach is prevented. The attack surface is becoming larger, identities are multiplying, AI agents are gaining autonomy, and technology environments are more distributed.

Those best positioned for the future will combine strong prevention with the ability to withstand compromise.

That means:
  • Securing AI from the start
  • Governing autonomous identities
  • Reducing meaningful attack paths
  • Applying Zero Trust principles
  • Modernising network and security architecture

It also means investing in people, processes, and security capabilities that let teams to detect, contain, respond, and recover.

Most importantly, it means treating cyber resilience as a business capability.

Chris captures the shift succinctly:

“The future of cybersecurity isn’t about building higher walls. It’s about limiting trust, reducing your blast radius, detecting threats faster, and maintaining business resilience when prevention inevitably fails.”

A strong security posture shouldn’t prevent you from innovating, adopting cloud services, or enabling remote work. Done well, cybersecurity provides the confidence to do those things safely — while ensuring you can continue operating when the inevitable happens.

How Canon Business Services ANZ can help

CBS helps organisations strengthen cybersecurity strategy across identity, cloud, networks, data protection, and managed security services.

By bringing together security controls, modern technology and practical risk management, we help you reduce exposure, improve visibility, and build the resilience to respond and recover when incidents occur.

Get in touch to explore how Canon Business Services ANZ can help strengthen your security posture and build a more resilient foundation for what comes next.

Similar Articles

View all

APRA CPS 230 & the future of IT compliance

Ensure IT compliance with APRA CPS 230. Learn how AI and automation help enterprises build resilience in a changing regulatory landscape.

What is Security Automation?

Learn how automated security transforms cybersecurity, making it simpler and more efficient. Protect your business data with CBS New Zealand’s expert insights now!

What are the benefits of penetration testing?

Gain confidence in your digital security with the benefits of penetration testing. Enhance cybersecurity, identify vulnerabilities, and fortify your defences with CBS New Zealand's expert insights now!

Cybersecurity Threat Detection: Proactive strategies

Stay ahead in cybersecurity with our 2024 guide on threat detection. Learn advanced technologies & response plans to protect your business against threats with CBS New Zealand.

Cybersecurity risk assessment

Learn how to protect your business with a detailed cybersecurity risk assessment. Start now to identify threats and secure your digital assets!

Digital transformation in different industries

Discover how digital transformation is driving innovation across industries like healthcare, finance, and retail in New Zealand. Learn more.

Essential 8 maturity levels

Learn about Essential 8 Maturity Levels to protect your business from cyber threats. Discover strategies to enhance security for New Zealand organisations. Start improving today!

How do you prevent phishing attacks?

Prevent phishing attacks with MFA, anti-phishing tools, and employee training to safeguard sensitive information and stay secure with Cannon Business Services New Zealand!

Ultimate guide to internal penetration testing

This Internal Penetration Testing guide covers techniques, analysis, and best practices for identifying vulnerabilities & strengthening your cyber defense in New Zealand.

RMM Meaning and its significance in IT management

Evolving technology, key benefits, and its impact on efficiency and security. protect your business data with CBS New Zealand’s expert insights now!

How IT leaders are modernising for the future

Discover why IT leaders in New Zealand are modernising cloud, data, and infrastructure to unlock real GenAI value in the years ahead—beyond pilots and proof-of-concepts.

The role of AI in cyber security

Discover how AI enhances cybersecurity with faster threat detection and automated, real-time protection with Canon Business Services New Zealand.