
Five Eyes Cyber Security Agencies Statement: AI will find its way in. The only question left is how prepared your infrastructure was.
The leaders of the Five Eyes cyber security agencies just told all boards the same thing: AI is collapsing the time between vulnerability discovery and exploitation, so stop chasing tools and get the foundations right. We walk through their five practical action items and show how Act handles each one, by shrinking what any attacker or agent can actually reach before the moment it matters.
On June 22, the heads of the Five Eyes cyber agencies put their names on a single statement. That’s CISA and the NSA in the US, the NCSC in the UK, the Canadian Centre for Cyber Security, the Australian Cyber Security Centre, and New Zealand’s National Cyber Security Centre, all signing the same page. They didn’t issue it because of a single breach. They issued it because of a trajectory. AI is accelerating the speed, scale, and sophistication of attacks, and it’s shrinking the gap between a vulnerability being found and being exploited.
It all comes back to timing. You don’t get to shrink your blast radius after the breach is underway:
“We must act before and be prepared to adapt and withstand evolving threats.”
The statement is a call to action aimed at security leaders. It treats cyber risk as a core business risk and a board-level responsibility, and it urges executives to:
Here’s the point: get the foundations right, and to do it now.
The core principles, and the bottom line under them
Before the to-do list, the agencies lay down three key principles that frame everything else.
First, secure-by-design and secure-by-default must become standard practice, “not an aspiration.” Second, resilience can’t lean on one product, so defense in depth is critical. And lastly, as AI systems evolve, new and previously unknown vulnerabilities, including zero-days, will keep emerging. You’re not going to out-patch that curve.
Which leads to the line that really sets the tone for the whole document:
“Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.”
Put plainly, in our words: AI will find its way in. That’s no longer the important variable. The important variable is how prepared your infrastructure was for the moment it does, because that’s what decides whether an intrusion stays a contained event or becomes a complete disaster. Preparedness here isn’t a bigger wall. It’s knowing, before anything goes wrong, exactly what a compromised identity or workload would be able to reach. That number is your blast radius, and it’s the thing you can actually shrink ahead of time.
The five practical actions, and how Act answers each
The agencies are upfront that these actions “are not new, but are now urgent.” Here’s their list, in their words, with where Act fits each one.
1. Reduce your attack surface.
“Limit unnecessary system access and external connectivity. Challenge whether systems need to be exposed at all and isolate those that do not.”
This is the center of what Act does. We pull identity and network into a single Access Map, so you can pin down which systems are genuinely exposed, and which access paths exist that no one actually needs. We then remove those unnecessary paths through your own native cloud controls and isolate your critical systems and data. The attack surface shrinks to what the business truly relies on, and the systems that don’t need exposure get isolated by actual policy.
2. Review and strengthen identity and access controls.
“Limit who can access critical systems. Enforce strong authentication and regularly review permissions.”
“Regularly review permissions” is the line everyone nods at and nobody does something about, because the set is way too large to be feasible. 96% of the cloud permissions organizations grant are never used. Act does the reviewing for you by computing everything each identity can reach versus what it has actually used. We then generate the exact policy changes needed to strip away that unused access, letting you enforce the new rules directly through your native controls. You don’t get another report, you get the unneeded permission actually gone.
3. Accelerate patching processes.
“AI is shortening the time between vulnerability discovery and exploitation. Delays in patching increase risk, especially for operational systems with long update cycles.”
Patching faster is the right instinct, but it’s a hard battle to win. The backlog grows every single day, and exploits now land in minutes, so speed alone can never really catch up. Act works the layer underneath it. A vulnerability only causes real damage if an attacker can use it as a stepping stone to your crown jewels, and that access is exactly what Act removes. Solve that root cause and the list of vulnerabilities gets dramatically shorter. A vulnerability that no one can reach anymore stops being a fire to fight, so the only flaws that stay relevant are the ones still sitting on an open path. Remediating them still matters. You just have far fewer that actually demand it.
4. Address legacy systems.
“Unsupported systems are easy targets. They are not just technical debt, they are strategic liabilities.”
You usually can’t rip a legacy system out tomorrow, so the near-term move is containment, and containment is an access question. Act maps everything that can currently reach a legacy system and everything that system can reach onward, then hands you a guided plan to box it in: the exact policy changes, on the security groups, SCPs, and resource controls you already own. A standing liability becomes a contained one, on a plan you can actually execute.
5. Prepare for incidents before they happen.
“Test response plans, train and prepare teams, and assume breaches will occur. Focus on fast containment and recovery.”
This is where the whole statement lands, and where preparedness becomes concrete. Containment under pressure is just your access map read in an emergency. If you already know what a given identity or workload can reach, you know the blast radius before the incident rather than discovering it at 2 a.m., and you’ve already cut the paths that would let one compromise become ten. Act lets you decide the answer to “what could this spread to” in advance, which is the difference between a contained event and a front page headline on the news.
The bottom line: get secure from the core
“Success will not come from having the most tools. It will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy.”
That’s the whole argument. The answer to AI-accelerated risk isn’t another detection product stacked on the pile. It’s going back to the foundation and making sure you’re secure from the core, the identities, the permissions, and the network reach that every workload and every agent inherits. Secure that once and most of the list the Five Eyes just handed your board is already handled.
Before the next agent ships or the next attacker breaks in, you need to set the right boundaries around your cloud. That’s where Act comes in.