Five Eyes Cyber Agencies Warn Business Leaders to Act Now on AI-Driven Cyber Risk
Artificial intelligence is already reshaping the cyber threat landscape, and the timeframe for organisations to respond is measured in months, not years.
In a rare joint statement, the heads of the Five Eyes cyber security agencies, including New Zealand’s National Cyber Security Centre, warned that advanced AI is expected to significantly increase both offensive and defensive cyber capability.
For New Zealand organisations, the message is clear: cyber attacks are likely to become faster, more scalable, and easier to execute, while the time available to detect, patch, and respond will continue to shrink.
AI is accelerating cyber risk
AI creates significant opportunities for cyber defenders. It can support faster threat detection, improve vulnerability analysis, and help security teams respond more efficiently.
However, the same capabilities are available to malicious actors.
AI can help attackers:
- Identify vulnerable systems more quickly
- Automate reconnaissance and attack preparation
- Create more convincing phishing and social engineering campaigns
- Analyse large volumes of technical information
- Reduce the time between vulnerability discovery and active exploitation
This means patching delays that were once considered manageable may become a significant business risk.
Organisations need clear visibility of their internet-facing systems, critical assets, remote access services, and identity platforms. They also need the ability to act quickly when serious vulnerabilities are identified.
Cyber resilience is a leadership responsibility
The Five Eyes statement is directed not only at technical teams, but also at boards and executives.
Cyber incidents can disrupt operations, affect revenue, expose sensitive information, damage customer confidence, and create regulatory or contractual consequences. Cyber resilience must therefore be treated as a core business risk rather than an isolated IT issue.
Business leaders should understand:
- Which systems and services are critical to operations
- What could happen if those systems became unavailable
- How quickly serious vulnerabilities can be remediated
- Who is responsible for making decisions during an incident
- Whether incident response and recovery plans have been tested
Having security technologies in place is important, but organisations also need clear responsibilities, effective processes, and the ability to respond under pressure.
The fundamentals still matter most
The agencies emphasise that resilience will not come from simply adding more security products.
The priority should be strengthening the fundamentals:
- Reducing unnecessary attack surfaces
- Accelerating critical patching
- Replacing or isolating unsupported systems
- Strengthening identity and access controls
- Applying multi-factor authentication
- Reviewing privileged and third-party access
- Improving network segmentation
- Testing incident response and recovery plans
These are established cyber security practices, but AI is making the consequences of weak controls and slow response times more severe.
Legacy and unsupported systems are a particular concern. Systems that no longer receive security updates can remain permanently exposed to known vulnerabilities and should be replaced, isolated, or protected through compensating controls.
What should New Zealand organisations do now?
New Zealand organisations should review their current cyber security posture and confirm whether existing controls are suitable for a faster-moving threat environment.
A practical review should include:
- External-facing systems and services
- Firewall policies and remote access configurations
- Multi-factor authentication coverage
- Privileged, administrator, and vendor access
- Critical vulnerability response times
- Unsupported hardware and software
- Network segmentation
- Security monitoring and alerting
- Backup integrity and recovery processes
- Incident response and escalation plans
The objective is not simply to confirm that a policy or product exists. Organisations need confidence that their controls are effective, responsibilities are understood, and critical decisions can be made quickly.
Preparing for an AI-Accelerated threat environment
At Nextro, these are the conversations we are having with customers across retail, hospitality, financial services, logistics, commercial environments, and critical infrastructure.
AI will help both attackers and defenders move faster. Organisations with strong foundational controls, clear leadership accountability, and tested response plans will be better positioned to adapt.
Those that delay may find that the time available to respond has reduced significantly.
Strengthen your cyber resilience with Nextro
Nextro can assess your network and cyber security environment, identify material risks, and recommend practical improvements aligned with your operational requirements.
Our services include security assessments, secure network and firewall design, identity and remote access protection, vulnerability risk reduction, managed monitoring, and incident response readiness.
Contact the Nextro team today to arrange a tailored cyber security and network assessment.
