Frenchelephant
Essay · Security Strategy & Planning

Six
Years.

Brisbane is hosting the Olympics in 2032. Your security programme has less time than you think.

Author Dan Boucaut
Published June 2026
Reading time 7 min
Topic Planning & Identity
Days
Weeks
Months
Years

Six years feels like a long time until you start counting backwards.

The Brisbane 2032 Olympic and Paralympic Games will run from the 23rd of July. That's roughly 2,200 days from now. It sounds like an abundance of time — enough to plan properly, to get the board aligned, to finally address the identity debt that has been accumulating since the last major platform refresh.

Here is what those 2,200 days actually contain.

A typical hardware refresh cycle for a mid-sized Australian enterprise runs three to four years from business case to full deployment. If you haven't started that conversation, you are already inside the window. Major IAM platform programmes — the kind that replace legacy directories, rationalise service accounts, and bring non-human identity under governance — routinely take eighteen months from vendor selection to stabilisation, and that assumes a procurement process that doesn't stall, an integration environment that behaves, and a programme sponsor who doesn't change roles halfway through. None of those things are guaranteed.

You will not be the target. You may be the path.

Compress that against the operational reality of an Olympic host city and the picture sharpens. Brisbane's infrastructure — transport, utilities, communications, health, financial services — will be under scrutiny and under load simultaneously. The attack surface won't be your organisation's alone. It will include every supplier, every venue system, every digital touchpoint that intersects with an event drawing five billion viewers and the concentrated attention of every nation-state threat actor that finds large, visible, time-pressured targets interesting.

You will not be the target. You may be the path.

· · ·

The 1% doctrine is usually applied to athletic performance. Marginal gains, consistently applied, compound into structural advantage. The same principle applies to security programmes, with one important difference: in sport, you know your current performance level. In security, most organisations are running on a measurement system that tells them how many alerts they closed, not how exposed they actually are.

So before you can get 1% better, you need an honest baseline.

That means asking questions that most security programmes avoid because the answers are uncomfortable. How many privileged accounts exist in your environment right now, across every system? How many of them are assigned to humans who are still employed in the role that warranted the access? How many are service accounts with standing access and no expiry, no owner, and no audit trail? How many identities were created for a project or a contractor engagement and never deprovisioned?

The answer to all of those questions, in almost every organisation, is: more than you think, and fewer of them are monitored than you'd want to admit.

That is your baseline. Not a maturity score on a framework. The actual count of the things that could be used against you.

· · ·

From that baseline, the roadmap writes itself — not as a compliance exercise, but as a series of compounding improvements with measurable outcomes.

2026
— 27

Visibility & hygiene

Identity discovery, access certification, and removal of standing privilege where it isn't operationally justified. Unglamorous work — and the foundation everything else depends on. You cannot govern what you cannot see, and you cannot automate what you haven't cleaned up.

2027
— 28

Automation & enforcement

Provisioning workflows that don't require a helpdesk ticket and a three-day wait. Access reviews that surface anomalies rather than requiring manual inspection of a spreadsheet. Policy enforcement that doesn't depend on someone remembering to check. Hardware refresh programmes completed or in final stages. The secure path becomes the easy path.

2028
— 32

Compounding returns

Your security team is no longer spending the majority of its time on access requests and audit preparation. Your identity estate is smaller, better understood, and more tightly governed. When a new threat emerges — and in an Olympic year, new threats will emerge — you are responding from a position of clarity rather than scrambling to understand what you're protecting.

The organisations that will be genuinely prepared in July 2032 are not the ones that start a security uplift programme in 2030. They are the ones that started the visibility work now, when the urgency wasn't obvious, and built compounding improvements into the rhythm of how they operate.

The Olympics is a useful deadline precisely because it is fixed and public. The games will happen whether your identity estate is ready or not. The question is whether you used the time, or just watched it pass.

2,200 days. Start counting.

Not sure where your baseline sits?
A focused conversation usually surfaces the gaps faster than a formal assessment. Initial discussions are confidential and without obligation.

Start a conversation →

New writing, when it's ready.
One email when the next piece is published. Nothing else.