Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Security Leaders Discuss OpenAI’s Call for Collaboration on Cyber Defense

By Jordyn Alger, Managing Editor
AI computer chip
Immo Wegmann via Unsplash
August 28, 2026

100 technology firms (including OpenAI, Google, Microsoft and Anthropic) released an open letter calling for “collective action” for cyber defense. 

“We have a limited window to strengthen cyber defenses,” the letter reads. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable. The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk.” 

The letter outlines how organizations can band together to bolster security before AI threats become too overwhelming. 

Below, security leaders share their thoughts on the letter. 

Security Leaders Weigh In

Aviv Nahum, Co-founder and CEO at Above Security:

The companies building the most capable AI systems are effectively saying that these capabilities will become broadly available, very quickly, and that model-level safeguards alone are not going to protect the rest of the internet.

I don’t take from this that we should slow down AI. I take almost the opposite view: defenders have to assume the attacker will have access to extremely capable AI and design around that reality. Trying to preserve security by keeping offensive capability out of attackers’ hands is unlikely to be a durable strategy once comparable models are widely available.

What changes is the speed of the game. An AI attacker can continuously investigate an environment, test hypotheses, adapt when something fails and pursue multiple paths without waiting for a human operator. Human-led security operations built around static rules, queues of alerts and periodic remediation simply cannot operate at that tempo.

The real takeaway from the letter is not ‘be afraid of AI.’ It is that security itself must become AI-native. Defenders need systems that continuously investigate identities, humans and agents, reason about behavior in context, and respond at machine speed. If AI is going to dramatically increase the capability of attackers, the answer is to give defenders the same leverage.

Diana Kelley, Chief Information Security Officer at Noma Security:

I read this letter as an acknowledgment that AI is changing the economics of cyberattack faster than many organizations are reducing their security debt or strengthening governance over their own agents. And one of the most powerful ways to respond is collectively.

AI doesn’t have to invent fundamentally new exploit techniques to create a serious problem. And agents don’t have to be “evil” to behave in ways their operators didn’t intend. When AI-driven agents can find vulnerabilities humans missed, automate reconnaissance, chain known attack paths, and operate at machine speed, longstanding weaknesses become more dangerous.

The practical response is to address the debt we already know exists: patch systems, eliminate unnecessary privileges, strengthen identity and access controls, continuously test defenses, and use AI to help defenders find weaknesses before attackers do.

At the same time, organizations need to recognize that their own agent deployments are becoming part of both the security architecture and the attack surface. They need to know what an agent can access, what tools it can invoke, what actions it can take, where it can communicate, and whether they can detect and stop it at runtime when its behavior violates policy.

As the letter highlights, we need to take collective defense seriously. Attackers have shared tools, techniques, infrastructure, and intelligence for decades; defenders need to collaborate just as effectively. As AI pushes attacks toward machine speed, collective defense can’t rely on human-speed reports and static indicators. We need shared signals, automated warning systems, and mechanisms for rapidly propagating what one defender learns so others can act on it at machine speed too.

Randolph Barr, Chief Information Security Officer at Cequence Security:

Before we get to AI-specific risks, we must get the basics correct. In the rush to bring AI to market quickly, engineering and product teams often cut corners to meet aggressive launch timelines. When that happens, basic security controls get skipped, and those shortcuts make their way into production. Therefore, while organizations are undeniably starting to think about model protections, prompt injection, data leakage, and anomaly detection, those efforts mean little if you haven’t locked down identity, access, and configuration at a foundational level. 

Organizations should catalogue where AI agents operate in their environment, restrict permissions before scaling usage, vet third-party skills with the same thoroughness applied to open-source dependencies, and ensure behavioral visibility across web, API, bot, and AI-driven traffic. AI agents extend the existing application attack surface; they do not replace it and should be governed with that reality in mind. The goal is not to slow innovation but to secure it intentionally. 

The bottom line is that visibility, behavior-based detection, and least privilege for agents are working. Legacy tooling, unverified isolation, and an ungoverned agent supply chain are the gaps.

John Gallagher, Vice President at Viakoo:

The technical premise of the open letter is sound; the window where human-driven remediation can keep pace with AI-driven threats has closed. Discovering a vulnerability is no good if patching it takes weeks or months. Where this will have the most impact is in operational technology (OT) and critical infrastructure where there has been historically a lack of focus on cyber hygiene. 

Where the open letter misses reality is in the idea that defenders hold an advantage because they can find and fix vulnerabilities that have accumulated for years. In OT and critical infrastructure, the current pace of remediation is glacial, for several reasons. Maintenance and downtime must be carefully managed, coordinate between devices and applications can be tedious, and the cost of device not coming back online can be enormous.  

Without more concrete and focused plans, and budget to implement them, it is hard to imagine up-levelling OT and critical infrastructure teams within the next few months to address the velocity and volume of AI-driven threats. 

The only viable countermeasure to the AI-driven threats highlighted here is automated, scalable cyber hygiene and remediation across all types of connected assets. Funding and training should urgently be focused in this area.  

The purpose of the letter does seem to be for self-serving PR and perhaps to pre-emptively shift liability from the frontier AI developer to the organizations about to be attacked. Having a frontier AI company aggressively release more capable models and simultaneously issue an urgent warning that we’ve only got months to prevent disaster can easily to be taken cynically. Kind of like an arsonist selling fire extinguishers. Yet the core point remains; urgent action is needed to mount autonomous and rapid remediation solutions.  

Ram Varadarajan, CEO at Acalvio:

AI-powered cyberattacks have moved from theory to reality. The larger concern for enterprises is what today’s AI systems can do. Modern models no longer just scan code for technical mistakes. They can infer what developers intended the software to do and spot contradictions humans missed. That makes a new category of vulnerabilities far easier to find: hidden business-logic flaws, broken trust assumptions, and authorization errors that appear perfectly valid to conventional security tools but can still be exploited.

Shadow AI has become nearly ubiquitous across the corporate landscape.  Industry studies are consistently showing that most knowledge workers regularly use unsanctioned AI tools.  This creates a profound and unplanned-for organizational blind spot.  Employees are routinely bypassing traditional corporate networks through personal devices, browser extensions, and web-based applications.

Employees predominantly resort to unauthorized tools out of a usability and productivity impulse, driven by the belief that enterprise-approved platforms are overly restrictive, cumbersome, or too slow to keep pace with personal-grade consumer tools.  Convenience is a great motivator, even when we should be more circumspect.

We’re facing an “assume compromise” future within cybersecurity. Our best defense will be to engage these attacks bot-on-bot inside the perimeter, with active defense keyed by AI itself.

Dana Simberkoff, Chief Risk, Privacy and Information Security Officer at AvePoint:

AI does not need rest, it does not lose focus, and it can turn small openings into chained activity very quickly. Point-in-time assessments and manual escalation alone are not enough when autonomous systems can act faster than traditional response processes. What organizations need is continuous visibility into identity, access, configuration, data movement, and agent behavior before an incident occurs. Recent research found that nearly 9 in 10 organizations delayed both agentic and generative AI deployments by an average of almost six months because of unresolved data security and data management concerns. You cannot secure what you cannot see, and confidence is different from control. 

Advanced defensive capabilities matter, however, access to powerful tools is different from readiness to use them safely. Before testing systems like this against real-world infrastructure, I would want independent pre-test review, documented scope, technical controls that prevent boundary crossing, continuous monitoring by a separate team, mandatory reporting, and a liability model that does not leave the affected third party carrying the risk. Good governance does not slow innovation. 

Chris Hughes, Vice President of Security Strategy at Noma Security:

There’s a bit of “help me from myself” aspect here and leaning into the FUD around AI-enabled attacks. It’s complicated because we are going to see widespread AI-enabled attacks by cyber capable models.

But many of the signatories are cloud providers, frontier labs and cybersecurity vendors who are of course incentivized to see cyber become a business priority because that means more cyber spending, and thus revenue opportunities for those selling cyber products and services.

We unfortunately can’t call to action or will our way to better security, there needs to be sufficient market and regulatory incentives to change the behavior of business and get them to prioritize security on par with or ahead of competing priorities such as speed to market and revenue in some cases.

All that said, we already saw AI industrialize vulnerability discovery, and soon, we will see widespread AI-enabled attacks, especially as open source helps commoditize the capability into the hands of not just nation states but those without elevated cyber skills and makes hacking with AI available to nearly all.

It could be the forthcoming AI-enabled cyber incidents which end up driving that prioritization of cyber from businesses, but we will see.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security security leaders

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Blurry photo of people moving through the mall

Violence Remains Top Concern for Retailers

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Events

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Laptop in a dark room with coding on screen

    Security leaders discuss ONCD's call for memory-safe software

    See More
  • American flag

    Security Leaders Discuss Trump’s Cyber Strategy for America

    See More
  • American Airlines

    Security Leaders Discuss Cyberattack on American Airlines Subsidiary

    See More

Related Products

See More Products
  • 9780367339456.jpg.jpg.jpg

    Cyber Strategy: Risk-Driven Security and Resiliency

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing