Months, not years. Five Eyes warns companies about the new pace of risk

AI is shortening the time between discovering a vulnerability and exploiting it. For companies, this means less room for delay, technical debt and false confidence.

Months, not years. Five Eyes warns companies about the new pace of risk

Table of contents

    TL;DR

    AI is not creating an entirely new world of cyber threats, but it is radically accelerating the pace at which known weaknesses inside companies can be found and exploited. The Five Eyes warning should be read as an operational signal: organizations no longer have years to clean up technical debt, patching processes, access controls and incident response plans. In many cases, they may only have months.

    For businesses, this means cybersecurity is no longer just an IT topic. Unpatched systems, old integrations, excessive permissions and untested recovery procedures can quickly turn into downtime, costs, customer delays and decision-making chaos. The key recommendation is straightforward: get back to the fundamentals, but move faster and treat cyber resilience as part of operational strategy, not as a technical project postponed to the next quarter.


    Introduction

    The most important shift in cybersecurity is not that companies are suddenly facing entirely new types of attacks. Organizations are still dealing with phishing, unpatched systems, misconfigured access rights, software vulnerabilities, technical debt and weak incident response. What has changed is the speed at which these weaknesses can be found, exploited and scaled.

    The Five Eyes warning matters because it does not sound like a distant prediction. It is more of an operational signal: organizations no longer have years to adapt to the impact of AI on cybersecurity. In many areas, they may have months.

    For companies, this changes the business context. Cybersecurity can no longer be treated as something that “IT has under control” until an incident happens. In an environment where AI accelerates the work of attackers, delays in patching, excessive permissions, legacy systems and untested response plans become more than technical problems. They become risks to business continuity, reputation, costs and customer trust.

    This is not an argument for buying another tool simply because it has AI in its name. In fact, the opposite is true. The highest value starts with the fundamentals: reducing the attack surface, patching faster, controlling identities and access, preparing for incidents and making cyber resilience part of business strategy. AI can help, but it does not replace leadership accountability.

    Example

    Leonie runs operations at a mid-sized manufacturing company serving customers across several countries. The company uses a modern ERP system, but several older applications still operate alongside it because they “still do the job”. One of them handles data exchange between the warehouse and an external logistics provider.

    For a long time, this application appeared in meetings as a typical piece of technical debt. Everyone knew the system was old, but replacing it would be expensive, require downtime and offer no obvious sales advantage. So the decision kept being pushed into the next quarter.

    The problem started when the software vendor stopped supporting one of the libraries used by that system. The information reached IT, but it was treated as something to plan, not as an urgent operational risk. Under older assumptions, the company would have expected to have several months to deal with the issue. In the new environment, that assumption was too optimistic.

    Attackers did not need a long, manual reconnaissance process. Automated tools helped them identify vulnerable configurations faster, match attack scenarios and test possible entry points. The incident did not begin with a dramatic breach. It started with a small weakness that had been considered an “acceptable compromise” for years.

    The consequences quickly moved beyond IT. The warehouse had to operate in emergency mode for several hours, some shipments required manual verification, customer support did not have full visibility into order statuses, and finance had to estimate the impact of delays on contractual penalties. The most expensive part was not the technical flaw itself. It was the fact that the company did not know how long it could operate without that system and who should make decisions during the first hours of the crisis.

    That is the practical meaning of the Five Eyes warning. AI does not mean every company will immediately become the target of a highly sophisticated attack. But it does mean that old weaknesses can move faster from being local technical issues to affecting operations, customers, costs and management decisions.


    Why the pace of risk is changing

    For years, many organizations built their security processes around the assumption that there was a reasonable buffer between the discovery of a vulnerability and its practical exploitation. That buffer allowed teams to plan updates, agree on maintenance windows, wait for budget decisions or move difficult topics to the next roadmap cycle.

    AI weakens that model because it accelerates several parts of the attacker workflow at the same time. The issue is not only that attackers can write more convincing phishing emails. More importantly, they can analyze information faster, automate reconnaissance, generate variants of attacks and scale activities that previously required more time or expertise.

    For a company, this shortens the reaction window in several places:

    • Vulnerabilities move faster from “to be monitored” to “ready to be exploited”. If an organization needs weeks to assess, test and deploy a fix, it may be moving slower than the risk it is trying to control.

    • Externally exposed systems become more visible to automated reconnaissance. Public-facing panels, misconfigured services, old integrations and unnecessary connections are no longer passive parts of the infrastructure. They can be discovered and tested at scale.

    • Configuration errors have a shorter life as “invisible problems”. In the past, an organization could live with poor permissions or outdated components for a long time without obvious consequences. Now these weaknesses are easier to combine into practical attack paths.

    • Attacks can be better adapted to the company’s context. AI makes it easier to analyze public information, organizational structures, communication patterns and business processes. This increases the effectiveness of impersonation, data theft and manipulation attempts.

    In practice, what changes is not only the technology of attack, but also the economics of attacking. If the cost of preparing an attack goes down and the speed of testing scenarios goes up, more companies become potential targets. Not because they are especially interesting. Because they are vulnerable enough.


    Cybersecurity as a business risk

    The biggest mistake would be to assume that the warning is mainly for security teams. Of course, those teams will implement tools, monitor incidents and analyze vulnerabilities. But the consequences of weak resilience are carried by the entire organization.

    Cybersecurity becomes a business risk because an incident rarely stays in the technical layer. An attack on a system can block sales, delay deliveries, damage customer trust, trigger legal costs, disrupt reporting and paralyze internal communication. In digital businesses, the difference between “the system is down” and “the company is down” is shrinking.

    The impact of the new pace of risk should be considered across several business areas.

    Operations and processes are usually the first place where the real effects of an incident become visible. If the company does not understand dependencies between systems, it does not know which processes will stop when one component fails. This creates decision chaos, manual work and improvised workarounds that can generate additional risks.

    Finance and costs include more than the direct expense of handling an incident. Costs can include downtime, delays, lost sales, contractual penalties, external consultants, crisis communication and later remediation projects carried out under pressure. The later a company reacts, the more expensive it becomes to regain control.

    Customer experience is particularly sensitive to poor communication and unreliable service. A customer does not need to understand the technical details. They see that an order has not arrived, an application is unavailable, data cannot be accessed or the company is communicating vaguely. Cyber resilience becomes part of trust, not just a back-office safeguard.

    People and HR also feel the consequences of the new pace of risk. Employees are more frequently targeted by social engineering, and during an incident they must operate under pressure, often without clear procedures. If an organization does not train for these situations, it puts responsibility on people who have not been prepared for it.

    Management and decision-making are critical because the first hours of an incident are not the time to define rules from scratch. Who can disconnect a system? Who informs customers? Who decides when to restore a service? Who contacts partners? A lack of answers to these questions can increase the damage more than the technical vulnerability itself.

    That is why cybersecurity should enter leadership discussions not as a presentation about the number of alerts, but as a question about the company’s ability to operate under pressure.


    The basics have become urgent

    One of the most important aspects of the Five Eyes message is that the recommendations are not exotic. They do not require a revolution in security architecture. They require companies to consistently execute the things they have known about for years. The difference is that neglected issues now have a shorter shelf life.

    The first area is reducing the attack surface. A company should regularly check which systems are exposed externally, which integrations are active, which services are unnecessarily public and which accounts have access to critical resources. Every unnecessary access point is a potential entry point.

    In practice, this means several concrete actions:

    • Limiting unnecessary system exposure should be a continuous process, not a one-time audit. If an application does not need to be publicly accessible, it should be isolated or placed behind additional layers of control.

    • Cleaning up integrations between systems matters because many companies still have connections created years ago for projects that no longer exist. These integrations often remain active even though nobody can explain their current business purpose.

    • Reviewing technical accounts and permissions regularly reduces the risk that compromising one account opens access to too much of the environment. Shared accounts, ownerless accounts and “temporary” permissions that have existed for months are especially dangerous.

    The second area is faster patching. Many companies have an update process, but it is designed around stability rather than the speed of modern risk. Of course, not every patch can be deployed immediately, especially in production, medical, industrial or financial environments. The problem appears when the organization has no clear prioritization mechanism.

    Patching should account not only for technical severity, but also for the business criticality of the system, external exposure, available workarounds and the potential impact of downtime. Otherwise, IT teams may spend time on less important updates while the riskiest component waits for the “next maintenance window”.

    The third area is legacy systems. Older solutions often remain in companies because they are deeply embedded in operations. The problem is that lack of support, lack of updates and dependence on a narrow group of specialists create risks that cannot be solved by procedure alone.

    A legacy system is not just an “old system”. It is often where three problems meet: difficulty of modernization, high operational importance and weaker security resilience. This turns technical debt into strategic debt.


    How AI can strengthen defense

    AI increases the capabilities of attackers, but it can also strengthen defense in practical ways. There is one condition: the organization must use it for specific tasks, not as decoration in a security strategy. The most valuable use cases are those that reduce detection time, improve decision quality and lower the burden on security teams.

    In cybersecurity, time matters enormously. If a company identifies unusual behavior faster, classifies an alert faster and decides to isolate a system faster, it limits the scale of the incident. AI can help precisely in the areas where people face too many signals, too little context or too much repetitive analysis.

    Practical defensive uses of AI include several areas:

    • Earlier vulnerability detection helps identify components, configurations and dependencies that need attention. In companies with many applications, simply understanding the risk landscape can be harder than fixing individual issues.

    • Analysis of unusual behavior can detect signals that do not look dangerous on their own, but together form a risk pattern. This may involve logins, data flows, technical account behavior or attempts to access specific resources.

    • Support for SOC teams can reduce the time required for initial alert classification. This matters because many security teams operate under overload and must separate real signals from operational noise.

    • Improving software quality makes it possible to detect some problems earlier, before deployment. AI does not replace secure software development, but it can support code reviews, testing and identification of common mistakes.

    • Faster incident handling can help organize information, build timelines, recommend next steps and support communication between teams. This is especially important when time pressure creates organizational mistakes.

    However, AI should not be confused with automatic security improvement. A tool can accelerate analysis, but it will not solve the absence of risk ownership, outdated systems, chaotic permissions or untested recovery plans. AI strengthens organizations that already have solid foundations. In chaotic organizations, it may simply reveal the scale of disorder faster.


    What leaders should do

    The main task for leaders is not to understand every technical detail of every control. Their role is to make sure cyber resilience has an owner, priority, budget, metrics and a place in business decisions. Without that, security remains a set of technical initiatives that lose against more urgent operational projects.

    The first step should be understanding the company’s real exposure. Executives should know which processes are critical, which systems they depend on, how quickly those systems can be restored and which incident scenarios are most likely. This does not require technical micromanagement. It requires asking the right questions.

    In practice, leaders should focus on several decisions:

    • Defining accountability for cyber risk is essential because distributed responsibility leads to delays. The company should know who decides whether to accept a risk, who approves exceptions and who owns remediation.

    • Giving security teams a real mandate enables faster action, especially when access must be limited, a service must be shut down or a business project must be changed. Without authority, security becomes an advisory function that can be ignored.

    • Testing incident response plans regularly reveals problems that are invisible in documents. Exercises should involve not only IT, but also operations, customer support, communications, legal, finance and leadership.

    • Reviewing trade-offs between business speed and security should be explicit. Many risks appear because a company wants to launch a product, integration or campaign faster, but does not document the security cost it is accepting.

    • Including cyber resilience in supplier strategy is increasingly important because companies operate in ecosystems. A weak technology partner, integrator or service provider can become a practical entry path into the organization.

    Leaders should also change how cybersecurity is reported. The number of blocked attacks or alerts is often less useful than answers to questions such as: which processes are most exposed, how long it takes to patch a critical vulnerability, how many accounts have excessive permissions, which systems are unsupported and when the last incident scenario exercise was run.

    In the new pace of risk, the advantage goes to organizations that can make decisions quickly. They will not always have perfect technology, but they will know what is critical, who decides and how to limit damage before a problem becomes a crisis.


    Summary

    The Five Eyes warning should not be read as another generic message about growing cyber threats. Its meaning is more specific: AI shortens the time companies can safely postpone difficult decisions. What once looked like a problem for “next year” can become an operational risk within months.

    The key conclusions for companies are simple but demanding. They need to reduce the attack surface, patch vulnerabilities faster, clean up identities and access, limit the risk of legacy systems, practice incident response and use AI to strengthen defense. Not as a fashionable add-on, but as a tool for shortening detection, analysis and response time.

    Cybersecurity in the age of AI is no longer only the domain of technical specialists. It is a topic for leadership, operations, finance, sales, HR and customer support because the consequences of an incident spread across the whole organization. Companies that treat cyber resilience as part of strategy will gain greater stability and trust. Companies that wait may discover that their old assumptions about response time no longer apply.

    The biggest risk today is not the lack of the newest tool. The biggest risk is believing that the old pace of action is still enough.

    Sebastian Kaczmarek

    About author

    Sebastian Kaczmarek

    CTO at MDBootstrap and CogniVis AI / Co-founder of MDBS - 10 years shipping hard tech, now building private AI that turns document chaos into structured data.

    Author of Learn Bosque Programming book / YouTube creator / ex StackOverflow contributor.