Cybersecurity has always
been a community-driven discipline. Threat actors collaborate
openly, sharing tools, techniques and infrastructure, while defenders
traditionally responded by sharing intelligence, vulnerabilities and lessons
learned. That collective knowledge has always been one of our greatest
strengths.
London’s
trading industry is coming home!
That is why the recent call
for collective action on cyber defence, led by OpenAI and supported by more
than 100 organisations across technology, cybersecurity, financial services and
critical infrastructure, is so significant. Not because of the companies
involved, but because it signals a growing recognition that the traditional
model of organisational self-defence may no longer be sufficient.
If AI is becoming the force
multiplier for attackers, then collaborative, intelligence-driven defence has
to become the force multiplier for everyone else. That is the thesis I want to
unpack here, and why I think this could be an open-source moment for our
industry.
Cybersecurity has never had
more technology available than it does today. Security leaders are inundated
with new products and promises. Every year, the market produces another
generation of tools claiming to solve emerging threats. Yet despite this investment,
organisations continue to experience
breaches, ransomware events, fraud losses and operational disruption.
The problem is rarely a lack
of technology, but understanding whether controls perform under real-world
conditions. Too often, organisations measure security through inputs rather
than outcomes. They track the number of controls implemented, policies written,
vulnerabilities patched or frameworks adopted. These activities are important,
but they do not necessarily reveal whether risk is being meaningfully reduced.
A firewall can be perfectly
configured and still be bypassed. An incident response plan can exist on paper
and fail during a crisis. A security awareness program can achieve high
completion rates while employees continue to fall victim to phishing attacks.
This is where I think
security experts need to get out of textbook thinking. A security gap does not
automatically mean the answer is another tool; it means a control needs to be
tested against how it actually behaves under pressure.
What matters most is
performance. How quickly can an attack be detected? How effectively can it be
contained? How quickly can an organisation recover? And can they demonstrate
that a security investment has reduced risk in a measurable way?
This is precisely the kind
of question that gets easier to answer collectively than alone. Australia has
sometimes played catch-up in cybersecurity , but there are areas where
Australian organisations have been genuinely industry-leading, and one of our
strengths has been the willingness to learn from each other.
If one organisation has
found an effective way to counter a particular threat, a playbook that actually
held up during a live ransomware event or a detection rule that caught
something others missed, others shouldn’t have to rediscover it from scratch. That’s
the whole premise behind initiatives like the open call to action on cyber
defence, turning isolated lessons into shared ones.
The AI Shift Changes the Equation
This becomes particularly
important in an AI-driven threat environment, where the technology is being
used to accelerate scams and fraud, with increasingly sophisticated attacks.
The 4 stages of Artificial Intelligence:
0. Systemic AI responds to prompts based on probabilities established during training: i.e. current state-of-the-art AI.
1. Sentient AI is quintessentially curious and uses experience to refine beliefs about the world.
2. Sophisticated…
— World of Statistics (@stats_feed) April 8, 2024
The foundations of
cybersecurity remain essential, but the industry needs to better understand
whether they can withstand an adversary that is increasingly AI-enabled and
persistent. That is why organisations need to move beyond simply securing AI
and start becoming AI-native in the way they operate security.
AI should help organisations
identify exposure faster, analyse risk more effectively, test performance
continuously and improve response capabilities. It should enable security teams
to focus on higher-value work while increasing both speed and accuracy across
security operations.
This is not about stopping
innovation but instead creating an environment where people
can adopt AI confidently and securely, and where the industry’s collective
responses change at the same pace as the threats.
None of this means
one-size-fits-all. One of the challenges for global organisations is that there
is no single threat environment. The threat environment facing a financial
services business in Australia may differ significantly from the risks
encountered in Europe, the United Kingdom or the Middle East.
That’s not an argument
against collective defence, but it is a reason to be precise about what we’re
sharing. The value of collaboration isn’t a single global policy that assumes
every market faces the same threats. There needs to be common foundations and
principles with enough flexibility to manage local threat profiles
appropriately.
So instead of asking whether
every part of the organisation follows the same process, security teams should
be asking whether the controls are performing effectively against the
real-world threats that matter in each location, informed by what the wider
industry has already learned.
AI May Change the Role of the CISO
There is a temptation to
respond to every new cyber threat with another tool, process or additional
layer of security. But the old playbook of more people and tools to combat more
threats may no longer be the answer.
The future belongs to organisations
that can
continuously measure effectiveness, leverage automation intelligently and
use AI to improve decision-making at scale.
A verified YouTube account was impersonating SpaceX and livestreaming an Elon Musk deepfake crypto scam.
The number of scams on YouTube has skyrocketed. YouTube should just change its name to ScamTube. pic.twitter.com/5z6c0w0jft
— DogeDesigner (@cb_doge) April 9, 2024
That requires Chief
Information Security Officers (CISOs) to lean further into collaboration than
we have before. The new collective action model gives us a way to accelerate
that learning by turning individual incident response into shared institutional
memory across the industry.
The breadth of organisations
supporting the collective cyber defence call is a powerful signal that the
industry at large is prepared to recognise cybersecurity as a shared challenge.
Much like the open-source
movement did for engineering, cybersecurity now has an opportunity to build a
culture where organisations share what works, learn from what doesn’t, and
build on each other’s progress rather than solving the same problems independently.
AI is making the cost of
playing alone much greater, but it’s also giving the industry much better tools
to play as a team.
Cybersecurity has always
been a community-driven discipline. Threat actors collaborate
openly, sharing tools, techniques and infrastructure, while defenders
traditionally responded by sharing intelligence, vulnerabilities and lessons
learned. That collective knowledge has always been one of our greatest
strengths.
London’s
trading industry is coming home!
That is why the recent call
for collective action on cyber defence, led by OpenAI and supported by more
than 100 organisations across technology, cybersecurity, financial services and
critical infrastructure, is so significant. Not because of the companies
involved, but because it signals a growing recognition that the traditional
model of organisational self-defence may no longer be sufficient.
If AI is becoming the force
multiplier for attackers, then collaborative, intelligence-driven defence has
to become the force multiplier for everyone else. That is the thesis I want to
unpack here, and why I think this could be an open-source moment for our
industry.
Cybersecurity has never had
more technology available than it does today. Security leaders are inundated
with new products and promises. Every year, the market produces another
generation of tools claiming to solve emerging threats. Yet despite this investment,
organisations continue to experience
breaches, ransomware events, fraud losses and operational disruption.
The problem is rarely a lack
of technology, but understanding whether controls perform under real-world
conditions. Too often, organisations measure security through inputs rather
than outcomes. They track the number of controls implemented, policies written,
vulnerabilities patched or frameworks adopted. These activities are important,
but they do not necessarily reveal whether risk is being meaningfully reduced.
A firewall can be perfectly
configured and still be bypassed. An incident response plan can exist on paper
and fail during a crisis. A security awareness program can achieve high
completion rates while employees continue to fall victim to phishing attacks.
This is where I think
security experts need to get out of textbook thinking. A security gap does not
automatically mean the answer is another tool; it means a control needs to be
tested against how it actually behaves under pressure.
What matters most is
performance. How quickly can an attack be detected? How effectively can it be
contained? How quickly can an organisation recover? And can they demonstrate
that a security investment has reduced risk in a measurable way?
This is precisely the kind
of question that gets easier to answer collectively than alone. Australia has
sometimes played catch-up in cybersecurity , but there are areas where
Australian organisations have been genuinely industry-leading, and one of our
strengths has been the willingness to learn from each other.
If one organisation has
found an effective way to counter a particular threat, a playbook that actually
held up during a live ransomware event or a detection rule that caught
something others missed, others shouldn’t have to rediscover it from scratch. That’s
the whole premise behind initiatives like the open call to action on cyber
defence, turning isolated lessons into shared ones.
The AI Shift Changes the Equation
This becomes particularly
important in an AI-driven threat environment, where the technology is being
used to accelerate scams and fraud, with increasingly sophisticated attacks.
The 4 stages of Artificial Intelligence:
0. Systemic AI responds to prompts based on probabilities established during training: i.e. current state-of-the-art AI.
1. Sentient AI is quintessentially curious and uses experience to refine beliefs about the world.
2. Sophisticated…
— World of Statistics (@stats_feed) April 8, 2024
The foundations of
cybersecurity remain essential, but the industry needs to better understand
whether they can withstand an adversary that is increasingly AI-enabled and
persistent. That is why organisations need to move beyond simply securing AI
and start becoming AI-native in the way they operate security.
AI should help organisations
identify exposure faster, analyse risk more effectively, test performance
continuously and improve response capabilities. It should enable security teams
to focus on higher-value work while increasing both speed and accuracy across
security operations.
This is not about stopping
innovation but instead creating an environment where people
can adopt AI confidently and securely, and where the industry’s collective
responses change at the same pace as the threats.
None of this means
one-size-fits-all. One of the challenges for global organisations is that there
is no single threat environment. The threat environment facing a financial
services business in Australia may differ significantly from the risks
encountered in Europe, the United Kingdom or the Middle East.
That’s not an argument
against collective defence, but it is a reason to be precise about what we’re
sharing. The value of collaboration isn’t a single global policy that assumes
every market faces the same threats. There needs to be common foundations and
principles with enough flexibility to manage local threat profiles
appropriately.
So instead of asking whether
every part of the organisation follows the same process, security teams should
be asking whether the controls are performing effectively against the
real-world threats that matter in each location, informed by what the wider
industry has already learned.
AI May Change the Role of the CISO
There is a temptation to
respond to every new cyber threat with another tool, process or additional
layer of security. But the old playbook of more people and tools to combat more
threats may no longer be the answer.
The future belongs to organisations
that can
continuously measure effectiveness, leverage automation intelligently and
use AI to improve decision-making at scale.
A verified YouTube account was impersonating SpaceX and livestreaming an Elon Musk deepfake crypto scam.
The number of scams on YouTube has skyrocketed. YouTube should just change its name to ScamTube. pic.twitter.com/5z6c0w0jft
— DogeDesigner (@cb_doge) April 9, 2024
That requires Chief
Information Security Officers (CISOs) to lean further into collaboration than
we have before. The new collective action model gives us a way to accelerate
that learning by turning individual incident response into shared institutional
memory across the industry.
The breadth of organisations
supporting the collective cyber defence call is a powerful signal that the
industry at large is prepared to recognise cybersecurity as a shared challenge.
Much like the open-source
movement did for engineering, cybersecurity now has an opportunity to build a
culture where organisations share what works, learn from what doesn’t, and
build on each other’s progress rather than solving the same problems independently.
AI is making the cost of
playing alone much greater, but it’s also giving the industry much better tools
to play as a team.
