The leaders of Five Eyes are warning of artificial intelligence's (AI) rapidly transforming cyber risk, urging leaders to act swiftly to minimise the brunt of attacks.
Head of New Zealand’s National Cyber Security Centre (NCSC) Catriona Robinson said AI was "not a future consideration, it is already here."
"It lowers barriers for malicious actors and increases the speed and complexity of attacks, shrinking the window between vulnerability discovery and exploitation ever more quickly. At the same time, AI offers powerful tools to strengthen defence."
The call from the leaders of the Five Eyes security agencies was spurred by Frontier AI’s "ability to identify and exploit vulnerabilities at unprecedented speed and scale". Frontier AI models are the most advanced types of software available.
"As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead," Robinson said.
"Breaches will occur but preparedness helps you contain them quickly and prevent escalation into major operational and financial crises."
The NCSC was assessing frontier AI models to inform its response to security risks.
The Five Eyes' statement on the AI security risk describes cyber risks as no longer a purely technical issue - "This is a core business risk and leadership responsibility."
"It is not enough to have controls. Leaders must be confident those controls will perform during a real incident. This requires reassessing long-standing trade-offs and using AI deliberately to strengthen defence - not just improve efficiency."
It states standard practice now must be secure-by-design and secure-by-default and there must be multiple layers of defence.
"As AI systems evolve, new and previously unknown vulnerabilities will emerge, including zero‑day vulnerabilities," the statement read.
"The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats.
"Success will not come from having the most tools. It will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy."
Five Eyes' 'practical actions'
The statement says whilst the following actions may not be new, they are now urgent to reduce technical risk, and also operational, financial and reputational exposure.
1. Reduce your attack surface: Limit unnecessary system access and external connectivity. Challenge whether systems need to be exposed at all and isolate those that do not.
2. Accelerate patching processes: AI is shortening the time between vulnerability discovery and exploitation. Delays in patching increase risk, especially for operational systems with long update cycles. Prioritise security updates accordingly to manage risks.
3. Address legacy systems: Unsupported systems are easy targets. They are not just technical debt, they are strategic liabilities.
4. Review and strengthen identity and access controls: Limit who can access critical systems. Enforce strong authentication and regularly review permissions.
5. Prepare for incidents before they happen: Test response plans, train and prepare teams, and assume breaches will occur. Focus on fast containment and recovery.
7 Comments
This tells us what we already presumed - that the cat is out of the bag.
And it wasn't a very useful cat.
Doesn't list protect your source code, once you have source code you can often just walk into any system.
Totally agree with the list and the gist of decreasing time to protect after vulnerability identified.
3. Address legacy systems: Unsupported systems are easy targets. They are not just technical debt, they are strategic liabilities.
Our govt has many liabilities in this regard then. The legacy passport system is a DOS looking blue screen window operating with keyboard only.
Maybe it just runs a terminal to a 3270 back end....
oh god I have just shown how old I am...
Oh look! An AI squirrel! The draconian National led government is about to hand to "malicious actors" a trove of personal data.
"This government is presiding over the greatest expansion of State surveillance capacity in NZ in recent memory. Done without fanfare, or even being minimised by govt Ministers. Three Bills, two before Parliament and one that is coming, are making these changes.
The first bill is the Telecommunications and Other Matters Bill. …As a result of those changes, the government can now insist that overseas providers of end-to-end encrypted (E2E) communications provide it with an interception capability, a ‘backdoor’, into those communications. …A backdoor open to a government is open to everyone with the requisite skill to exploit it.
The second bill amends the Policing Act. …Historically, Police surveillance has been legally permitted only for people suspected of crimes …Under the new Act, surveillance will be allowed for ‘an intelligence purpose connected with a function, or an activity, of the Police, or any other lawful purpose connected with a function, or an activity, of the Police.’ In other words, the Police can conduct surveillance of the NZ public for any reason they can come up with. There is no limit. Further, the Police will now have the authority to conduct surveillance against any private property, so long as they do it from a public space. The Police could, for example, legally set up a surveillance site in a hillside park that could easily look into private property, 24 hours a day. No warrant required; no suspicion of wrongdoing needed, even. They just need to “consider that the information will or may support the Police in performing a function, or carrying out an activity, of the Police”.
Then there is the third piece of legislation, the so-called under-16 social media ban. Which hasn’t even been introduced yet, but for which the Dept. of Internal Affairs has already been given $30 million to implement. …You will have to show your age and, almost certainly, your identity, before you can use it. …To comply with laws designed to satisfy regulators, social media platforms, or the security firms they use to ensure their customers are over the age of 16, have to store some form of data. Unfortunately, that makes them an irresistible target for hackers. Even government systems in places like Estonia and India have been targeted and breached. More recently, Discord was breached, leading to the identification of a huge amount of its users' private data.
But this policy is doomed to failure. The Australian implementation has shown that it is easily circumvented, not only by using a VPN, but also by children themselves, who find simple workarounds."
https://x.com/darkwaterjack/status/2068836186999963953
https://singularity.kiwi/nz-government-surveillance-expansion-encryptio…
Have you seen the sentences imposed on the anti ICE protesters in Texas? Shooting a cop does deserve punishment. But 100 years? The UK has called the pro Palestine group there terrorists. I am not seeing that in the MS media reports I have read. Here, we stopped that fella who cut down one tree hill from legal action. So he should take up his chainsaw again? Then we use our moral superiority to pretend that our system of justice is better than say Singapore! As the corruption in concealing of the Immigration software failure shows, we are really really stupid to trust the State.
Yes, AI and automation based attacks are here now and will get worse. Recommended actions are good foundation basics but this area is only going to get more complex and the speed of the bad guys will be enhanced. Will be interesting to see the difference in response between closed source software and opensource software. AI based exploitation has the potential to kill one or the other based on their speed to patch and update ...or not.
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.