Security
FIVE EYES BRINGS CYBER RESILIENCE INTO SHARP FOCUS
AI driven attacks are outpacing corporate defences, and the latest Five Eyes alert shows just how quickly the threat landscape is shifting. Boards can no longer treat cyber protection as a bolt on — integrated security is now a strategic necessity, according to Santiago Pontiroli, Lead Security Researcher at Acronis Threat Research Unit.
T
he Five Eyes warning should serve as a wake-up call for every board. AI is accelerating cyber threats faster than most organisations are adapting.
In a statement published in June, the high-level intelligence-
sharing alliance – made up of the US, the UK, Canada, Australia, and New Zealand – warned that while AI will help improve cyber defence over time, it “also accelerates the speed, scale, and sophistication of cyber threats”. In a stark warning, it claimed that frontier AI models are
‘anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities’. “Te timeline is not years, it is months,” it said.
Cybersecurity linked to national security and economic stability Te intervention by Five Eyes follows a ministerial letter published last year in which senior government figures called for cybersecurity to be made a ‘board responsibility’ because the UK’s economic and national security require an ‘urgent collective response’. “Strengthening our nation’s cyber resilience requires close
collaboration between government and industry,” they wrote. Both interventions reinforce a reality the security industry has
recognised for years – that cyber risk can no longer be treated purely as an IT department issue. Cybersecurity is now a core business risk and needs to be top of
the agenda for business leaders. As the Five Eyes communiqué makes clear: “It is not enough to
have controls. Leaders must be confident those controls will perform during a real incident. Tis requires reassessing long-standing trade-offs and using AI deliberately to strengthen defence – not just improve efficiency.” But meeting this new challenge requires a change in mindset.
Aſter all, for decades, cybersecurity strategies have been built around prevention. Te objective was straightforward. Build strong enough defences, and that should be enough to keep all but the most persistent attackers out.
20 | July/August 2026 Tis “ring of steel” approach included preventative measures
such as firewalls, endpoint protection, email security, identity management and access controls. Together, they were designed to stop malicious actors from gaining a foothold within an organisation’s networks and systems.
Why prevention-focused security is no longer sufficient But as numerous high-profile incidents have shown, determined attackers do sometimes get through. Te 2024 cyberattack on Transport for London (TFL) – which reportedly cost £29 million in losses and recovery costs – is a case in point. According to the National Crime Agency (NCA), the two
perpetrators – who admitted their involvement in June 2026 – were members of the online criminal collective known as Scattered Spider. As a result of the attack, all 28,000 TFL employees were forced
to attend a TfL office for an in-person password reset. Te breach exposed data from TfL’s Oyster refunds system and delayed customer refunds, leaving some passengers out of pocket for weeks longer than expected. It also closed down the application system for Oyster photocards
for children and young people. Te lesson from this case is stark. While prevention is key, it’s also
essential to have systems and processes in place in the event that something does happen. Instead of assuming, “Tis will never happen to us”, organisations
need to accept that, however strong their defences, there is always a chance an attacker will get through.
The case for integrated cyber protection One of the problems currently facing organisations is the emergence of tool sprawl. Over the years, organisations have layered new security products on top of existing ones, oſten ending up with separate tools for backup, disaster recovery, endpoint protection, patch management and monitoring.
www.pcr-online.biz
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40 |
Page 41 |
Page 42 |
Page 43 |
Page 44 |
Page 45 |
Page 46 |
Page 47 |
Page 48 |
Page 49 |
Page 50 |
Page 51 |
Page 52