← All posts

The World's Top Spy Agencies Just Told You to Fix Your Cybersecurity. Are You Listening?

On June 22, the intelligence agencies of the United States, United Kingdom, Canada, Australia, and New Zealand — the Five Eyes alliance — released a joint statement with a title that should have landed on every board agenda this week: "The AI shift in cyber risk: why leaders must act now."

The message was blunt. Frontier AI models will "fundamentally transform both offensive and defensive cyber capabilities," and the timeline is "months, not years."

This is not a vendor selling you something. This is the NSA, CISA, and their allied counterparts telling you that the threat model your organization built last year may already be obsolete.

What Changed — and Why It Matters Now

In April, Anthropic's Mythos Preview model autonomously discovered approximately 2,000 previously unknown software vulnerabilities in seven weeks. Some of those flaws had survived decades of human-led security review. One was a 27-year-old vulnerability in OpenBSD. Another was a 16-year-old flaw in FFmpeg, a video processing component embedded in countless applications you probably use every day.

No security researcher found these. No red team exercise surfaced them. An AI model, given essentially the instruction "find a security vulnerability in this program," found and exploited them without human involvement.

That was the restricted model. The Five Eyes warning is about what happens when those capabilities — or something close — become broadly available. And according to CyberScoop's reporting, open-source AI models have historically run just six to eight months behind frontier commercial models. The clock is ticking.

The Three Questions Your Board Should Be Asking

In Cyber Risk Is Business Risk, I outline three questions every executive and board member should be able to answer about their organization's cybersecurity posture. The Five Eyes statement makes those questions more urgent than ever.

First: What are we protecting? If your organization uses AI tools — and most do now, whether they've formally approved them or not — you have a new category of assets to defend. The recent exploitation of CVE-2026-42271 in LiteLLM, an open-source AI gateway, demonstrated exactly this. Attackers chained two vulnerabilities together to achieve unauthenticated remote code execution on AI proxy servers, gaining access to every API key and model credential the system managed. CISA added it to their Known Exploited Vulnerabilities catalog on June 9. If your team can't tell you what AI infrastructure you're running and who has access to it, that's your first problem.

Second: How would we know if something went wrong? The Five Eyes agencies specifically flagged "weak identity and access controls" and "a lack of pre-incident planning" as weaknesses that AI will excel at exploiting. AI-driven attacks move faster than human response teams. If your incident detection and response playbooks haven't been updated to account for machine-speed attacks, you're bringing a clipboard to a gunfight.

Third: What's the plan when — not if — it happens? The joint statement put it plainly: "Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises." That's not pessimism. That's risk management. And it's exactly the shift in mindset I've been urging executives to make — from "how do we prevent everything" to "how do we survive the inevitable."

Stop Treating Cybersecurity Like a Compliance Checkbox

Here's what struck me most about the Five Eyes statement. After all the warnings about frontier AI capabilities and the urgency of the threat, their guidance landed somewhere familiar: get the basics right.

Patch your systems. Retire legacy technology. Limit unnecessary internet connectivity. Control who has access to what. Plan for incidents before they happen.

In my experience, the organizations that suffer catastrophic breaches aren't the ones facing the most sophisticated adversaries. They're the ones that never got around to replacing the Windows Server 2012 box in the corner, or the ones where the CEO's password is still "Company2024!" because nobody wanted to have that conversation.

The Five Eyes statement says it directly: "Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy." Not buying another tool. Not hiring another consultant. Integrating security into how you run the business.

What to Ask Your CISO This Week

If this Five Eyes warning doesn't prompt a conversation with your security leadership, I'm not sure what will. Here's where to start:

Ask them to inventory your AI-connected infrastructure — every API gateway, every model endpoint, every tool your teams have plugged into an LLM. If they can't produce that inventory within a week, you have a governance gap that attackers will find before you do.

Ask whether your incident response plan accounts for machine-speed attacks. Traditional playbooks assume human adversaries working on human timescales. AI changes that math.

Ask what your patching cadence looks like for AI-adjacent tools, not just your core enterprise stack. The LiteLLM vulnerability sat in production environments for months before CISA flagged it. How many similar tools are running in your environment right now, unpatched and unmonitored?

And ask yourself the hardest question: is cybersecurity a standing agenda item at your board meetings, or does it only come up after something goes wrong?

The Five Eyes agencies don't issue joint public warnings lightly. When the intelligence services of five nations tell you to act now, that's not marketing. That's a signal.

The question is whether you'll hear it before or after the breach.