{"id":8559,"date":"2026-06-23T01:08:41","date_gmt":"2026-06-23T01:08:41","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8559"},"modified":"2026-06-23T01:08:41","modified_gmt":"2026-06-23T01:08:41","slug":"change-your-cyber-risk-strategy-to-meet-ai-threats-five-eyes-countries-warn-csos","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8559","title":{"rendered":"Change your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOs"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>CSOs must re-write their cyber risk strategies because threat actors are increasing using AI to evade defenses, says a group of national cybersecurity agencies \u2013 a call that one expert immediately complained is too vague to be of use.<\/p>\n<p>In its <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/five-eyes-cyber-security-agencies-statement\" target=\"_blank\" rel=\"noopener\">call to action on Monday<\/a>, the group warned that \u201cfrontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.\u201d<\/p>\n<p>Because of this, cyber resilience is integral to advancing business continuity, market confidence, and long-term value, the statement says.<\/p>\n<p>The statement comes from the US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cybersecurity Centre, the Canadian Centre for Cyber Security (CCCS), the Australian Cyber Security Centre, and the New Zealand Cyber Security Directorate, collectively known as Five Eyes.<\/p>\n<p>It urges business and infosec leaders to understand and assess cyber risk, readiness to face an attack, and accountability; prioritize foundational cyber security practices and controls; empower cyber leaders with authority and resources; and stay actively engaged as threats and guidance evolve.<\/p>\n<p>\u00a0The Canadian Centre for Cyber Security told\u00a0<em>CSO<\/em>\u00a0that the Five Eyes statement was issued now \u201cbecause we are seeing real, recent shifts in how AI tools are being used, including to speed up the discovery and exploitation of vulnerabilities. As these capabilities become more accessible, the risk is no longer theoretical.\u201d <\/p>\n<p>The statement clearly signals that the pace of change has reached a point where organizations need to act, CCCS added, noting, \u201cwaiting will only narrow the window to respond. Our shared purpose was to be direct and accessible to senior leaders: AI is already affecting cyber risk, and it needs to be addressed as part of core business risk management.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Get the basics right<\/h2>\n<p>In the statement, the agencies warn, \u201cSuccess will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy. Those that do not will face growing operational and strategic disadvantage.\u201d<\/p>\n<p><a href=\"https:\/\/www.csoonline.com\/article\/573879\/why-a-risk-based-cybersecurity-strategy-is-the-way-to-go.html\" target=\"_blank\" rel=\"noopener\">Cyber risk<\/a> can no longer be treated as a purely technical issue, they point out. \u201cThis is a core business risk and leadership responsibility. Boards and executives should ensure cyber resilience is in place and works under pressure. It is not enough to have controls. Leaders must be confident those controls will perform during a real incident. This requires reassessing long-standing trade-offs and using AI deliberately to strengthen defense, not just improve efficiency.\u201d<\/p>\n<p>For leaders, the statement offers three core principles to act on, including making sure secure-by-design and secure-by-default are standard IT practice and not aspirations, implementing defense in depth, and being prepared to face new zero-day vulnerabilities.<\/p>\n<p>It also recommends five practical actions, including reducing attack surface, accelerating patching, addressing legacy systems, strengthening identity and access controls, and preparing for breaches of security controls through testing response plans and focusing on containing a breach.<\/p>\n<p>\u201cThese actions are not new,\u201d the agencies admit, \u201cbut are now urgent to reduce not only technical risk, but also operational, financial and reputational exposure.\u201d<\/p>\n<p>The agencies also urge infosec defenders to use AI to strengthen enterprise defenses.<\/p>\n<p><strong>[Related content: <a href=\"https:\/\/www.csoonline.com\/article\/4186877\/breaking-the-soc-triangle-how-ai-reshapes-security-operations-trade-offs.html\" target=\"_blank\" rel=\"noopener\">How SOCs can leverage AI<\/a>]<\/strong><\/p>\n<h2 class=\"wp-block-heading\">Experts unimpressed<\/h2>\n<p>However, the advice doesn\u2019t impress some experts.<\/p>\n<p>It \u201cseems to be a generic statement that states the obvious, and, quite frankly, does not provide meaningful guidance about addressing AI risks,\u201d complained <a href=\"https:\/\/josephsteinberg.com\/cybersecurityexpertjosephsteinberg\/\" target=\"_blank\" rel=\"noopener\">Joseph Steinberg<\/a>, a US-based cybersecurity and AI advisor to businesses and governments.<\/p>\n<p>\u00a0\u201cNot only does the statement not discuss many aspects of risk that AI creates, and for which businesses should already be planning and implementing countermeasures, but four out of the five recommended Practical Actions contained within the statement do not even mention AI, and have applied well before the dawn of the AI era.\u201d<\/p>\n<p>The statement should have discussed AI\u2019s total transformation of social engineering and its ability to perform greater reconnaissance, he said, and recommended techniques for social engineering-specific targets. It should have also have explained that generative AI can leak data about a company\u2019s internal work, and that if an AI is fed poisoned data it may \u201clearn\u201d incorrect things; that training issue is hard to undo.<\/p>\n<p>Asked for comment on complaints that the Five Eyes statement is too generic, a CISA spokesperson\u00a0pointed to <a href=\"https:\/\/www.cisa.gov\/ai\" target=\"_blank\" rel=\"noopener\">the agency\u2019s artificial intelligence guidance website<\/a>, which contains articles on AI data security, how AI must be secure by design, and other resources.<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/rob-enderle-03729\" target=\"_blank\" rel=\"noopener\">Rob Enderle<\/a>, head of the Enderle Group, said that the Five Eyes warning is \u201cincredibly late.\u201d<\/p>\n<p>\u201cAI-driven threats and deepfakes have been heavily impacting corporate landscapes for some time now,\u201d he said in an email. \u201cHowever, while late, the guidance is completely consistent with the severity and scale of the threat we are actively facing, providing a needed baseline for agencies trying to catch up to the current environment.\u201d<\/p>\n<p>The advice itself is solid, he acknowledged, \u201cbut acts more as a critical wake-up call than a prescient roadmap. It successfully emphasizes that AI is fundamentally altering the threat vector, and organizations can no longer afford to treat cybersecurity as a siloed technical problem. Rather than being overly generic, it accurately underscores the immediate operational vulnerabilities that corporations need to address.\u201d<\/p>\n<p><strong>[Related content: <a href=\"https:\/\/www.csoonline.com\/article\/3497163\/how-to-ensure-cybersecurity-strategies-align-with-the-companys-risk-tolerance.html\" target=\"_blank\" rel=\"noopener\">Risk tolerance vs risk appetite<\/a>]<\/strong><\/p>\n<p>\u201cCrucially,\u201d Endele added, \u201cthis is no longer just a discussion for CSOs. To manage this risk effectively, CSOs, CIOs, and CEOs all must be aligned and actively involved. Because AI impacts everything from operational infrastructure to brand trust and corporate governance, cyber risk strategy must be treated as a core business continuity issue driven straight from the top.\u201d<\/p>\n<p><a href=\"https:\/\/www.immuniweb.com\/company\/leadership\/ilia-kolochenko\/\" target=\"_blank\" rel=\"noopener\">Ilia Kolochenko<\/a>, CEO of ImmuniWeb and adjunct professor of cybersecurity practice and cyber law at US-based Capitol Technology University, said the Five Eyes statement \u201cmakes perfect sense. However, it should have been sent in late 2023. Today, careless implementation and imprudent use of legitimate AI systems is a much bigger threat than any misuse of AI.\u201d<\/p>\n<p>He added that while the practical recommendations, such as the reduction of organization\u2019s external attack surface, are relevant, they have little direct relationship with the modern AI risks. AI accelerates and amplifies the detection of misconfigured, obsolete, or vulnerable systems exposed to the internet, he agreed, but such issues have been around for more than a decade. \u201cThere are thousands of freely available non-AI tools that can quickly find the low-hanging fruit, which are oftentimes even better and much cheaper than LLMs, so AI is not even relevant here,\u201d he said.<\/p>\n<p>The biggest risk, Kolochenko said, stems from within organizations. Driven by the fear of missing out, corporate leadership frequently decides to precipitately deploy various AI systems across their organizations without even informing their CSO, let alone conducting a comprehensive risk assessment. Eventually, he said, AI introduces countless new attack vectors and vulnerabilities, becoming a much bigger risk than cybercriminals with AI.<\/p>\n<p>He added that, in 2026, threat actors really don\u2019t need more zero-days, because virtually every large company has so much shadow IT and so many misconfigured assets that cybercriminals can simply download all of the organization\u2019s crown jewels in one click. \u201cNo zero-days or faster exploitation cycle with AI are needed to get everything any more,\u201d he said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>CSOs must re-write their cyber risk strategies because threat actors are increasing using AI to evade defenses, says a group of national cybersecurity agencies \u2013 a call that one expert immediately complained is too vague to be of use. In its call to action on Monday, the group warned that \u201cfrontier Al models are anticipated [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8560,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8559","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8559"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8559"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8559\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8560"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}