• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity Software
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises & Simulations
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Resilience as a Service
          • Business Continuity as a Service (BCaaS)
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • Book – From Panic to Poise: Crisis Management in the Modern World
          • Book – The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity Software
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises & Simulations
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Resilience as a Service
      • Business Continuity as a Service (BCaaS)
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • Book – From Panic to Poise: Crisis Management in the Modern World
      • Book – The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

The AI Labs Just Warned You About AI-Enabled Cyber Attacks. Here Is What They Left Out.

You are here: Home / Business Continuity / The AI Labs Just Warned You About AI-Enabled Cyber Attacks. Here Is What They Left Out.

September 2, 2026 By //  by Bryan Strawser

Last week, OpenAI and Anthropic signed the same letter. So did Microsoft, Google, AWS, CrowdStrike, Palo Alto Networks, Mastercard, Visa, AT&T, and more than a hundred other organizations.

The letter, A Call for Collective Action on Cyber Defense, says AI-enabled cyber attacks “will become far more widespread and sophisticated” in the coming months, and that defenders have “a limited window” to get ready.

Competitors who agree on almost nothing agreed on this.

Treat that the way you would treat a hurricane forecast that every model converges on. Not as a vendor pitch. As a signal.

What the letter actually says

The threat is speed and access. AI models are cutting the time and skill an attacker needs to find a vulnerability, build a working exploit, and use it. Axios reported that an AI-generated exploitation script has already been used against U.S. water systems.

The letter’s diagnosis is blunt: “Status quo security won’t be enough.” It names the exposure most organizations already know they carry: “Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems.”

The asks are familiar. Treat cyber defense as a leadership priority with “incident-response intensity.” Fix the highest-risk vulnerabilities first and verify the fixes. Raise the security bar on everything you buy, build, or deploy, including AI-generated code. Apply compensating controls where you cannot patch.

None of this is new advice. What is new is who is saying it, how loudly, and how short they say the window is.

What the letter leaves out

This is a prevention letter, written by security and AI companies for security teams. Nearly every recommendation is about keeping attackers out. Response and recovery get a passing mention.

Nobody signed on behalf of your crisis management team.

That matters because the letter’s own premise undercuts a prevention-only strategy. If AI collapses exploitation timelines from weeks to hours, some attacks will land before your patch cycle catches up. The signatories say as much. When that happens, the binding constraint is no longer your security tooling. It is how fast your organization can decide, communicate, and recover under pressure.

Speed of response becomes the control.

Old View New View
AI-enabled cyber attacks are a security team problem They are a leadership decision problem that the security team surfaces
The patch cycle is the clock The attacker’s exploitation timeline is the clock
Incident response is measured in days Decisions must be made in hours, and sustained for weeks

 

We have already run this scenario

In August, we facilitated the first commercial AI-accelerated vulnerability storm exercise for a healthcare technology company.

The scenario: a fictional AI model discovers concurrent zero-day vulnerabilities, and exploitation begins within four hours of disclosure. Three moves across ten simulated days. Twenty-seven participants from technical, security, business, and support functions.

What broke was not the security stack.

Standard patching windows could not keep pace with exploitation. No one held clear authority to take production-impacting emergency action. Escalation processes had never been tested at that tempo.

The full AI Storm case study walks through what we found and what the client did about it.

Going in, the CISO’s biggest concern was not the tooling. It was whether the people could sustain the pace over an extended period. That concern was right, and the open letter does not address it anywhere.

Five moves to make while the window is open

  1. Fix the boring stuff, and make it a leadership item. The letter’s list is your list: unpatched software, excessive permissions, weak authentication, legacy systems nobody wants to touch. Ask your CISO for the inventory of high-risk vulnerabilities and the systems that cannot be patched. Put compensating controls and a date next to each one. Ask the same question of your cloud provider, your MSSP, and every critical SaaS vendor. The letter tells them to raise their standards too. Hold them to it.
  2. Pre-decide authority. Who can take a customer-facing system offline at 2 a.m. without convening a meeting? Who authorizes an emergency change that skips the normal approval path? Who calls the regulator, the board, the top ten customers? At AI speed there is no time to work this out live. Write it down now, get it signed, and make sure the people holding the authority know they hold it.
  3. Exercise at AI speed. Most cyber tabletops run on a timeline of days. Run one where exploitation starts four hours after disclosure and the second vulnerability drops before you have contained the first. That is the exercise that shows you whether your escalation criteria, activation thresholds, and decision rights work under compression. Our AI crisis exercises are built for exactly this.
  4. Plan for a marathon, not a sprint. A vulnerability storm is not a single incident. It is a sustained campaign that can run for weeks. Your incident commanders, engineers, and communicators will burn out on day three if you have not planned shifts, rest, backfill, and surge support. The people problem is the one every technical plan skips.
  5. Validate recovery, do not assume it. In more than one exercise this year, the honest post-exercise answer to “how fast can we recover, and in what order?” was “we do not know.” Test your restores. Map your dependencies. Know which systems you can patch without a reboot and which you cannot. And establish out-of-band communications now, because during a real event you should assume your primary environment is compromised or unavailable.

The window is the point

Months of warning is a gift most crises never give you. The companies that signed this letter are spending theirs hardening the systems they build and sell.

Spend yours making sure your organization can lead through the attack that gets past them.

Keep Going

A few ways to go deeper if this was useful.

  • Read more. Resilience, crisis management, and continuity writing at Bryghtpath Insights, or the structured Ultimate Guide to Crisis Management.
  • Run the AI Storm exercise. Our AI Crisis Exercises test your leadership team against vulnerability storms, deepfakes, AI system failures, and AI vendor incidents at machine speed.
  • Get a maturity score. Our Resiliency Diagnosis® is a standards-based review that produces a maturity score and a prioritized roadmap.
  • Talk to us. Set up a call to think through your program with us.

Category: Business Continuity, Crisis Management

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Previous Post: « A Return-to-Office Mandate Is a Tell About Your Leadership, Not Your Strategy

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Exercises & Simulations
  • Crisis Management
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Resilience as a Service
    • Business Continuity as a Service (BCaaS)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.