Visualização de leitura

Cyber Risk Assumptions Are Becoming Obsolete Due to AI, Warn Five Eyes

AI Cyber Risk

AI Cyber Risk is evolving faster than many organizations can adapt, prompting a joint warning from the Five Eyes cyber security agencies. The agencies have called on business leaders, executives, and boards to act now, warning that advances in artificial intelligence are rapidly transforming the cyber threat landscape and shortening the time available to respond to emerging risks. In a coordinated statement, the leaders of the Five Eyes cyber security partnership said that while AI has the potential to improve defensive capabilities, it is also accelerating the speed, scale, and sophistication of cyber attacks. They cautioned that developments in Frontier AI are expected to exceed current industry expectations and could fundamentally change both offensive and defensive cyber operations within months rather than years.

AI Cyber Risk Demands Immediate Attention

The agencies stressed that AI is no longer a future consideration. According to the statement, AI is already lowering barriers for malicious actors and increasing the complexity of attacks. At the same time, it is reducing the gap between the discovery of vulnerabilities and their exploitation. As a result, organizations are being urged to assess their readiness, understand accountability structures, and strengthen foundational Cyber Security practices. The agencies emphasized that cyber resilience should be viewed as a critical component of business continuity, market confidence, and long-term organizational value. Leaders were encouraged to remain actively engaged as threats continue to evolve and new guidance emerges.

Frontier AI Is Accelerating Cyber Risk

The Five Eyes agencies warned that Frontier AI models are advancing faster than many organizations anticipate and could fundamentally reshape both cyber attacks and cyber defence within months. As these systems evolve, long-standing assumptions about cyber risk, threat detection, and vulnerability management may quickly become outdated.

The agencies cautioned that organizations that fail to adapt could face growing operational and strategic disadvantages. They emphasized that leaders should not view AI-driven cyber risk as a future challenge but as an immediate business concern requiring proactive planning, continuous assessment, and investment in cyber resilience. As AI capabilities expand, the agencies said organizations must remain prepared for rapidly changing threats and emerging vulnerabilities that may challenge traditional security approaches.

Cyber Resilience Is a Leadership Responsibility

The Five Eyes agencies stated that Cyber Resilience can no longer be treated solely as a technical issue. Instead, it should be considered a core Business Risk and a leadership responsibility. According to the statement, boards and executives must ensure that cyber resilience measures are not only implemented but are capable of functioning effectively during real-world incidents. The agencies noted that having security controls in place is not enough. Organizations must be confident those controls will perform under pressure. They also called on leaders to reassess long-standing trade-offs and adopt AI deliberately to strengthen defensive capabilities rather than focusing exclusively on operational efficiency.

Key Cyber Security Principles Highlighted

The agencies identified several principles organizations should adopt to address evolving AI Threats. They stated that Secure-by-Design and secure-by-default approaches should become standard practice rather than long-term goals. They also warned against relying on a single security solution, emphasizing that layered security remains essential. The statement further noted that as AI systems continue to evolve, organizations should expect new and previously unknown vulnerabilities to emerge, including Zero-Day Vulnerabilities. The agencies acknowledged that breaches are likely to occur and emphasized that preparedness is essential for containing incidents quickly and preventing them from escalating into larger operational and financial crises.

Practical Actions for Organizations

To reduce technical, operational, financial, and reputational exposure, the Five Eyes agencies outlined several practical actions. Organizations were advised to reduce their attack surface by limiting unnecessary system access and external connectivity. They were also encouraged to accelerate patching processes, warning that AI is shortening the time available between vulnerability disclosure and exploitation. The agencies highlighted unsupported legacy systems as strategic liabilities that can become easy targets for attackers. They also urged organizations to review and strengthen Identity and Access Controls, limit access to critical systems, enforce strong authentication, and regularly assess permissions. In addition, they recommended testing Incident Response plans, training teams, and preparing for breaches before they occur, with a focus on rapid containment and recovery.

Using AI to Strengthen Defense

The agencies noted that threat actors are already using AI to improve their capabilities and increase operational speed. As a result, defenders must also embrace AI-driven security tools. According to the statement, organizations that integrate AI into security operations can improve vulnerability detection, enhance software quality, identify unusual activity, and accelerate response efforts. The agencies emphasized that success will not depend on having the largest number of security tools. Instead, it will come from strong fundamentals, rapid action, and integrating cyber security into core business strategy.

Five Eyes Call for Collective Action

The Five Eyes leaders concluded that assumptions about cyber threats can become outdated within months due to the rapid pace of AI development. They urged organizations, including technology vendors, to act now, strengthen resilience, and remain prepared to adapt to changing threats. The agencies said leaders who move quickly can reduce exposure, strengthen resilience, and build trust among customers, partners, and investors. Those who delay, they warned, face growing and avoidable risk.

Taiwan Flags Five Major Cyber Risks After 726 Security Incidents in 2025

Taiwan cyber risk

Taiwan’s digital security authorities have identified five major areas of concern following hundreds of reported cybersecurity incidents involving government agencies in 2025. According to Taiwan’s Ministry of Digital Affairs, the country recorded 726 cybersecurity incidents this year, highlighting ongoing Taiwan cyber risk challenges tied to ransomware, fake software, supply chain weaknesses, and social engineering attacks. The Administration for Cyber Security said the total number of reported cases declined slightly compared to 2024, with 29 fewer incidents recorded year over year. However, officials warned that attack methods continue to expose weaknesses across government systems and digital infrastructure.

Cybersecurity Incidents in Taiwan 

As reported by CNA and cited by UDN, most cybersecurity incidents were categorized as low-level threats under Taiwan’s classification system. However, authorities stressed that even minor breaches can create broader operational and national security concerns if left unresolved.  Under Taiwan’s cybersecurity framework, incidents are divided into four levels based on their impact on confidentiality, integrity, and system availability. Level 1 incidents accounted for 87.33% of all reports in 2025, while Level 2 incidents represented 9.78%. Level 3 incidents made up 2.89% of the total. No Level 4 incidents — the most severe category — were reported during the year.  Unauthorized access remained the most common issue among reported cybersecurity incidents, accounting for 68.6% of all cases. Equipment-related failures represented 15.43% of incidents, while denial-of-service attacks accounted for 4.96%. Website attacks made up another 2.48% of reported cases.  Following a review of cyber threat patterns and incident reports from government agencies, Taiwan’s Administration for Cyber Security identified five major Taiwan cyber risk trends that officials believe require immediate attention. 

Fake Messaging Apps Raise Taiwan Cyber Risk

One of the biggest cybersecurity risks highlighted by the administration involved fake communication software distributed through unofficial websites. According to UDN, some users unknowingly downloaded counterfeit messaging applications after replacing old devices or setting up new computers. Authorities said these downloads allowed attackers to install backdoor malware capable of compromising systems and sensitive information. The administration urged government agencies to implement stricter procedures for system modifications and software installations. Officials recommended that all software, hardware, and application installations receive prior approval before being used within agency systems. The administration warned that unofficial downloads continue to create major Taiwan cyber risk exposure across public sector networks.

Ransomware Tactics Become More Sophisticated

The second major concern centered on ransomware groups using customized software drivers to infiltrate systems and evade security detection tools. Authorities noted that attackers are becoming more advanced in bypassing conventional endpoint security measures. To reduce the likelihood of future cybersecurity incidents, the administration advised agencies to regularly scan websites for vulnerabilities, apply timely fixes, deploy web application firewalls, and ensure endpoint protection software remains updated. The ministry emphasized that outdated security tools and delayed patch management continue to increase Taiwan's cyber risk across both government and critical infrastructure networks.

Weak Supply Chain Security Creates Additional Exposure 

Supply chain vulnerabilities were identified as the third major cybersecurity threat. Officials cited one case in which a maintenance contractor installed remote desktop software on a website server. Hackers later gained access to the system after successfully guessing the password linked to the remote access tool.  The incident highlighted growing concerns about third-party vendors and contractor oversight. According to the administration, external maintenance work can create hidden entry points for cybercriminals if agencies fail to maintain strict security controls. The administration said agencies should strengthen supervision of vendors, improve password management practices, and enforce tighter restrictions on remote access systems to reduce Taiwan's cyber risk tied to supply chain operations. 

CISO vs. CEO: Making a case for cybersecurity investments

Ask CISOs why they think there is a cyber skills shortage in their organization, what keeps them up at night or what the most important issue facing the industry is — at some point, even if not the first response, they will bring up budgets.

For example, at RSA Conference 2024, a roundtable discussion about issues facing the cybersecurity industry, one CISO stated bluntly that budgets — or lack thereof — are the biggest problem. At a time when everything is getting more expensive, the CISO said, security budgets are being slashed.

As for the cybersecurity talent shortage, the 2024 ISC2 Cybersecurity Workforce Study noted that “39% said a lack of budget was the top reason for cyber shortages, replacing a shortage of talent as the previous top reason for staff shortages.” According to Forrester’s 2024 Cybersecurity Benchmarks Global Report, the cybersecurity budget is just 5.7% of the entire IT budget, making it very difficult for CISOs to bring in the right personnel or upgrade tools and solutions.

However, it might not be the dollar amount that is the problem as much as where the budget is coming from. CEOs think about cybersecurity differently when it is tied to IT and when the CISO reports directly to the CIO versus when the CISO can present cybersecurity as a vital cog in overall business operations and tie it directly to business risk, the Forrester report found.

“CISOs who can articulate the business value of cybersecurity, demonstrating how it can drive revenue and support strategic goals, are more likely to secure the necessary funding. This shift also reflects a growing recognition of cybersecurity’s strategic importance beyond mere IT operations,” Louis Columbus wrote.

Key issues in cybersecurity funding

Once cybersecurity is approached as a key factor in business operations rather than as a function of IT, CEOs and CISOs are more likely to be on the same page when it comes to budget.

“Security funding and oversight is a top priority for both the management team and the Board of Directors,” said Dave Gerry, CEO of Bugcrowd.

“Cybersecurity investment uplift is prioritized against the cyber threats we face as a business; the IT risks that we have identified and need to remediate or the customer and compliance obligations that we need to ensure,” Gerry added. “Thematically, however, it all points back to ensuring that the confidentiality, integrity and availability of our data we reside over is protected — whether it’s that of customers, employees or critical business partners, whilst enabling our business in-turn.”

Risk prioritization and business continuity are two key areas that George Jones, CISO at Critical Start, focuses on. Along with emerging threats and vulnerability management, Jones says these four items are the pillars of security for the enterprise as they are aligned with overall business goals and objectives.

One of the drivers behind realigning cybersecurity investments is the Security and Exchange Commission’s (SEC) new rules around the disclosure of cybersecurity incidents. Organizations are now also required to share details about their cybersecurity risk management programs, particularly around any financial information.

“After recent SEC guidelines were announced, Boards are more focused than ever on cyber risk reduction and ensuring adequate funding is critical, especially as organization’s attack surfaces continue to rapidly expand,” said Gerry.

Explore AI cybersecurity solutions

Collaboration between CISOs and CEOs

While CISOs and CEOs (and, in many cases, in conjunction with the CFO) have to build an ongoing dialogue about cybersecurity investments, they are coming to the table with two different interests.

“The CEO lens will be focused on obtaining satisfaction that the security initiatives deliver value with tolerable impacts on productivity, but more importantly looking for the potential of competitive advantage,” said Gareth Lindahl-Wise, CISO at Ontinue. The CISO’s approach, on the other hand, focuses on risk prevention, mitigation and solutions to meet all of the organization’s legal, regulatory and contractual obligations.

The overall goal should be to create a security posture advantageous in gaining or retaining customers or attracting investment. Ultimately, said Lindahl-Wise, these decisions lie with the CEO and board.

“When it comes to funding and risk acceptance, CISO is, largely, an expert advisor — if an informed and conscious decision has been made by a CEO, then one should argue the CISO has discharged their responsibilities,” Lindahl-Wise added.

CEO Gerry, however, said the final decision on funding allocation is made by the Board of Directors, and it is up to both the CEO and the CISO to get their buy-in on where and what security investments should be made.

“This is a key reason that the CISO should report to the CEO and have direct access to the Board of Directors,” said Gerry. “While oftentimes security can be viewed as a cost center, the new reality is that a robust security program should be a competitive differentiator and a revenue enabler, in addition to simply being the cost of doing business in an ever-expanding threat environment.”

The Future is AI

CISOs have long understood the role AI plays in cybersecurity, particularly handling some of the most mundane tasks that free up time for overworked security teams to handle issues that require hands-on management. As generative AI becomes ubiquitous in the workplace, CEOs have become increasingly aware of AI’s impact on business and security risks. Some companies are turning to adding Chief AI Officers to their IT and security teams, but even when they aren’t CEOs still recognize the need to include AI in future security budgets.

“As threats become more sophisticated, leveraging AI tools enables us to enhance our threat detection, automate responses and improve incident management,” said Darren Guccione, CEO at Keeper Security. “Skilled professionals are needed to navigate the rapidly evolving threat landscape and ensure that our AI-driven strategies remain effective and secure and must be a budget consideration.”

How it is defined within the cybersecurity budget will depend on how it is used. Will it be a fringe use of AI in commercial tools for productivity gains or an embedded use of AI in the organization’s core offerings?

“If it is the latter, the CEO must satisfy themselves that the organization has the right experience to manage the opportunities and risks,” Lindahl-Wise said. As for the security side of things, “My hunch is we will see AI responsibilities feature heavily in CIO/CTO roles before standalone CAIOs become the norm.”

AI might be the most current technology and security disrupter, but it won’t be the last. Where it is similar is that it creates risk, both to the business and to cybersecurity, and risk is where CEOs and CISOs will focus on investments as a team.

The post CISO vs. CEO: Making a case for cybersecurity investments appeared first on Security Intelligence.

❌