To make sense of AI, first make sense of your data


Suzanne Prescott
Contributor

There’s a moment in every technology cycle where the conversation shifts from possibility to execution. According to Mandy Andress, chief information security officer at Elastic, that moment has arrived for AI – particularly in the public sector, where ambition is now colliding with the realities of legacy systems, cyber risk and operational delivery. 

Speaking on Commercial Disco(very) from Parliament House in Canberra, Ms Andress describes a global environment where governments and organisations alike are grappling with the same core challenge: how to unlock value from AI while maintaining trust, control and resilience. 

“The conversations are remarkably consistent wherever I go,” she says. “Organisations are trying to understand how to take advantage of AI, while also managing the cybersecurity and data challenges that come with it.” 

That tension, between innovation and control, is increasingly defining how public sector leaders approach modernisation. Agencies are under pressure to deliver digital transformation outcomes while managing complex, often poorly understood legacy environments and rising expectations around security and sovereignty. 

At the centre of this challenge is data. 

AI may dominate the headlines, but Ms Andress is clear that its effectiveness ultimately depends on how well organisations can access, understand and operationalise their data – particularly the vast volumes of unstructured information that have historically been difficult to analyse. 

“Think of all the large amounts of data that we all have today and need to take advantage of,” she explains. “Elastic enables second and sub-second analytics on very large amounts of data.” 

For government agencies, this has direct implications. The ability to bring together structured and unstructured data from across departments, systems and services enables a more complete view of operations, risks and opportunities. It also underpins more informed, data-driven decision-making, which is increasingly expected at both policy and service delivery levels. 

But as AI adoption accelerates across government, so too do the risks. 

Elastic chief information security officer Mandy Andress

One of the most immediate concerns is the reliability of AI outputs. Large language models, while powerful, can generate inaccurate or misleading responses if they are not properly contextualised. Ms Andress points to ‘grounding’ as a critical step in moving from experimentation to real-world deployment. 

“It’s not relying on broad public information,” she says. “It’s combining that with your organisational data, which reduces the potential for hallucinations.” 

This reflects a broader shift in how organisations are thinking about secure AI deployment – not as a standalone capability, but as something deeply connected to data governance, visibility and control. The conversation is increasingly focused on what ‘secure AI’ actually looks like in practice, rather than abstract potential. 

For many public sector organisations, however, the path to that outcome is far from straightforward. 

Legacy systems remain a significant barrier to modernisation, both operationally and from a security perspective. In many cases, agencies lack full visibility of how these systems function, creating blind spots that complicate both integration and risk management. 

“Often, organisations don’t even have full visibility of how their legacy systems operate,” Ms Andress notes. “Documentation is gone, the people who built them have moved on.” 

This is where the conversation begins to shift from technology to execution. Rather than attempting wholesale system replacement, many organisations are looking for ways to bridge old and new, bringing data from across environments into a unified view that can support both modern applications and existing infrastructure. 

At the same time, there is a growing recognition that security can no longer be treated as a separate, defensive function. 

As Ms Andress explains, the traditional divide between observability (understanding how systems are performing) and cybersecurity is beginning to collapse. Both rely on the same underlying data, and both are ultimately concerned with identifying and responding to anomalies. 

“Observability tells you what your systems are doing; whether they’re performing as expected,” she says. “Security is looking at that same data and asking whether something malicious is happening.” 

This convergence is being accelerated by AI, which is shifting organisations toward behaviour-based models – identifying what ‘normal’ looks like and flagging deviations, rather than relying solely on predefined rules. The implication is that security is becoming more embedded in operations, rather than sitting alongside them. 

For public sector leaders, this reframes cybersecurity from a cost centre to an operational enabler – one that supports resilience, performance and trust. 

From a global perspective, Ms Andress sees Australia as increasingly well positioned to navigate this shift. 

“Two years ago, I would have said Australia was slightly behind in how it approached technology and security,” she says. “Now, I’m seeing it catch up – and in some areas, lead.” 

National policy settings, including a stronger focus on AI and digital capability, are beginning to translate into practice. But the broader lesson from international markets is that success depends less on any single technology decision, and more on how organisations align data, security and operational strategy. 

For Ms Andress, the opportunity and the challenge are clear. 

While there is ongoing concern about the impact of AI on jobs and skills, she sees its primary role as amplifying human capability rather than replacing it. 

“There will be some roles that change,” she says. “But the greater power is in amplification; helping organisations do more with the resources they already have.” 

This amplification is already evident in areas like cybersecurity, where access to broader data sets and shared intelligence is enabling more effective responses to increasingly complex threats. 

The shift underway is not just about adopting AI, but about building the foundations that allow it to be used safely and effectively. For public sector organisations, this means focusing on visibility, governance and the ability to operate across complex, hybrid environments. 

If the past two years have been defined by exploration, the next phase will be defined by execution. 

And as Ms Andress makes clear, the organisations that succeed will be those that can turn data – from across systems, environments and formats – into something actionable, trustworthy and secure. 

This article and accompanying Commercial Disco(very) episode were produced by InnovationAus.com in partnership with Elastic. 

Do you know more? Contact James Riley via Email.

Leave a Comment

Related stories