
There are plenty of predictions being made about what AI will mean for cybersecurity.
But one published recently caught my attention.
OpenAI issued an open letter calling for a global push to strengthen cyber defenses. It has since attracted signatories from across technology, cybersecurity, financial services, telecommunications and other industries, including Microsoft, Google, Cisco, IBM, Visa, Mastercard, CrowdStrike and many others.
The warning is straightforward.
As AI models become more capable, OpenAI expects AI-enabled cyberattacks to become more widespread and sophisticated in the coming months.
But what I found most interesting wasn't the warning about AI.
It was the weaknesses they said attackers will have to work with.
Unpatched software.
Weak authentication.
Excessive permissions.
Misconfigurations.
Old systems.
Technical debt.
I've been working in IT and cybersecurity for more than 25 years.
None of those problems are new.
What's changing is how quickly and efficiently attackers may be able to take advantage of them.
AI Doesn't Need to Invent a New Way into Your Business
When people hear "AI-powered cyberattack," it's easy to imagine something we've never seen before.
An entirely new kind of malware.
An incredibly sophisticated hacking technique.
An attack no security team could possibly anticipate.
Those things may eventually be part of the story.
But an attacker doesn't need to invent a revolutionary way into your environment if an old one still works.
A forgotten administrator account can still be useful.
A firewall that hasn't been updated can still be useful.
A password without multifactor authentication can still be useful.
An internet-facing vulnerability that hasn't been patched can still be useful.
An employee who can be convinced to hand over credentials can still be useful.
AI can potentially make it easier to find, test, exploit or scale some of those opportunities.
The weakness itself may have been sitting there for years.
The Speed Is What Changes the Equation
This is the part I think businesses should pay attention to.
Cybersecurity has always involved a race.
A vulnerability becomes known.
A patch becomes available.
IT teams need to identify affected systems, test the fix and deploy it.
Attackers look for organizations that haven't done so yet.
AI has the potential to compress parts of that timeline.
Tasks that once required more manual effort can increasingly be automated or accelerated.
Research can happen faster.
Reconnaissance can happen faster.
Phishing can be personalized at greater scale.
Code can be analyzed faster.
And vulnerabilities can potentially be identified and exploited more efficiently.
OpenAI's letter describes the current moment as a limited window for defenders and argues that organizations should address their highest-risk weaknesses now rather than wait for AI-enabled attacks to become more capable.
I think that's the message business leaders should take seriously.
Not panic.
Time.
That Security Project You've Been Putting Off Matters More Now
Every IT professional has a list.
The old server everyone knows needs to be replaced.
The firewall that's approaching end of life.
The application that can't easily be patched because someone is afraid an update will break it.
The administrator accounts that have accumulated over the years.
The employees who have access to far more information than their current roles require.
The security project that keeps getting moved to next quarter.
The incident response plan that exists somewhere but hasn't been tested.
Individually, it's easy to postpone these things.
The business is busy.
Replacing technology costs money.
Nobody wants downtime.
And when nothing bad has happened, another six months can feel harmless.
But technical debt doesn't disappear because nothing happened last year.
It accumulates.
And if attackers are becoming faster at identifying and exploiting weaknesses, the cost of leaving those weaknesses unresolved changes too.
Start With What Would Hurt the Most
The answer isn't to suddenly try to fix everything.
Most businesses couldn't do that even if they wanted to.
I'd start with a different question:
If someone attacked us tomorrow, which weakness would we most regret not fixing today?
Maybe it's an exposed system.
Maybe it's an account with too much access.
Maybe it's missing multifactor authentication.
Maybe it's a critical application running unsupported software.
Maybe backups exist, but nobody has tested whether they can actually restore the business.
Maybe the company has an incident response document, but nobody knows who makes the first phone call.
Those are the issues I'd want at the top of the list.
OpenAI's recommendations follow a similar principle: prioritize the highest-risk weaknesses, verify that remediation actually worked, and use compensating controls when something can't immediately be patched or replaced.
That word matters: verify.
Installing a security tool isn't the same as confirming you're protected.
Applying a patch isn't the same as confirming the vulnerability is gone.
Having backups isn't the same as successfully restoring from them.
Having MFA "everywhere" isn't the same as checking whether every critical account is actually covered.
Security isn't finished when someone checks a box.
Your Incident Response Plan Has to Work at Attack Speed
There's another area I think deserves more attention as attacks accelerate.
What happens after someone gets in?
Who has authority to declare an incident?
Who gets called first?
Who contacts your insurance carrier?
Who preserves logs and evidence?
Who communicates with employees?
Who contacts customers or regulators if notification is required?
Can you reach those people at 9:00 on a Sunday night?
And has anyone actually practiced this?
A document isn't necessarily a plan.
A plan is something people can execute when they're under pressure.
If AI reduces the amount of time defenders have to recognize and contain an attack, organizations can't afford to spend the first few hours figuring out who's responsible for what.
Preparation becomes part of the defense.
AI Isn't Only an Advantage for the Attacker
There's another side to this that I don't want businesses to miss.
The same technology changing the offensive side of cybersecurity is also giving defenders new capabilities.
That's a major part of OpenAI's argument.
AI can help security teams analyze information, identify weaknesses, investigate alerts, test systems and respond more efficiently. OpenAI is calling for broader access to these capabilities, particularly for organizations protecting critical infrastructure that may not have large security teams.
So, I don't see this as a story about attackers getting AI and defenders being left behind.
It's a race in which both sides are getting better tools.
The question is which organizations actually use this period to improve their defenses.
The Basics Aren't Becoming Less Important
Whenever technology takes a major leap forward, there's a tendency to assume everything that came before it has suddenly become obsolete.
Cybersecurity doesn't work that way.
AI doesn't make patching less important.
It doesn't make multifactor authentication less important.
It doesn't make least privilege less important.
It doesn't make backups, monitoring, employee awareness or incident response less important.
If anything, it can make getting those fundamentals right more urgent.
OpenAI's letter says the current security status quo will not be enough and calls on organizations to treat cyber defense as an immediate leadership priority.
I think there's a very practical way for business leaders to interpret that.
You don't need to predict exactly what an AI-powered cyberattack will look like a year from now.
You don't need to understand every new model.
And you don't need to chase every new cybersecurity product that has "AI" in the name.
You need to understand where your business is vulnerable today.
Then start closing those gaps.
Because the biggest cybersecurity problem AI creates for many businesses may not be some futuristic attack we've never seen before.
It may simply give attackers a faster way to find the weaknesses we've been meaning to fix all along.
If this has you wondering where your own business may be vulnerable, we can help you assess your environment and identify the areas that deserve attention first.

310-553-3055
213-463-2100
