NAB Joins Global Cyber Defence Call

An open letter signed by 127 technology, security and financial services organisations says the security posture most enterprises run today will not hold. AI-enabled attacks will overwhelm it within months, the letter argues. One Australian organisation has signed.

The letter, A call for collective action on cyber defense, was published by OpenAI on 27 August. National Australia Bank is its only Australian signatory. No New Zealand organisation appears on the list.

Other signatories include Anthropic, Google, Microsoft, AWS, IBM, Oracle, SAP, Cisco, Dell, Accenture, KPMG and PwC. Security vendors on the list include CrowdStrike, Palo Alto Networks, Fortinet, Zscaler, Okta, Sophos, Tenable and Darktrace. Financial signatories include Mastercard, Visa, Citi, Capital One and Zurich Insurance Company. Counts reported at release ranged from 100 to 116, and the published list has grown since.

The central claim sits in the opening lines. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter states.

It names hospitals, water treatment plants and the infrastructure that powers the internet as the assets at risk.

The first of four principles is blunt. "Recognize that status quo security won't be enough," it reads. Current exposure is attributed to longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems.

Security teams protecting critical infrastructure "have been historically under-resourced and need a surge in tools and resources", the letter says.

The three remaining principles are to empower more defenders with cyber-capable AI and to mobilise a collective response across borders. The fourth holds that every party can reduce risk now rather than later.

What the letter asks of each group

The document then splits its demands across four audiences. For every organisation, it asks that cyber defence be made an immediate leadership priority.

Organisations should act with "the urgency and coordination of an incident that takes precedence over everything except critical business operations", it says.

That means fixing the highest-risk weaknesses, verifying results without disrupting essential services, and raising the security bar for what is bought, built and deployed. The letter explicitly includes AI-generated code in that scope.

It also asks organisations to upgrade or replace systems so that least privilege, strong access controls and defence in depth are built in. Cheaper models should provide broad coverage, with frontier capability reserved for the hardest problems.

Where a system cannot be patched without disrupting essential services, the letter asks that compensating controls be applied and verified.

Cybersecurity vendors and technology partners are asked to test their defences continuously against frontier cyber capabilities. They are also asked to make AI-powered defence deployable for critical infrastructure operators, with hands-on help.

They are also asked to change how they report progress. Success should be measured by how many organisations are protected, how quickly attacks are contained, and whether fixes actually work.

Governments are asked to coordinate defence at local, national and international levels. They should fund essential services that lack staff or budget, expedite trusted access programs and impose costs on attackers. Frontier AI companies are asked to provide responsible model access, funding and training, and to ensure agentic identities are traceable and accountable.

Five Eyes made a similar call in June

The letter arrives about two months after the Five Eyes cyber security agencies issued their own call to action. Those agencies cover Australia, Canada, New Zealand, the United Kingdom and the United States. The Five Eyes cyber security agencies statement of 22 June was co-signed by ASD's Australian Cyber Security Centre.

That statement warned that AI is compressing the time between the discovery of a vulnerability and its exploitation. It asked leaders to strengthen foundational security practices, reduce exposure and fold cyber risk into organisational strategy.

Toby Murray, Professor of Cybersecurity at the University of Melbourne, argued the sequence matters. "Before reaching for AI, defenders should first invest in their fundamentals. Otherwise, they are effectively deploying a robot guard dog to defend an unlocked door," he wrote. Read the full analysis.

The industry letter goes further than the agencies did on one point. It asks that capable defensive models be put in the hands of under-resourced defenders, including hospitals, water utilities and local government.

Access remains the unresolved part of that proposition. Anthropic has restricted access to Mythos on the grounds that it is too powerful to fall into the wrong hands, the BBC reported. The tool had found a weakness in a legacy platform that went undiscovered for 27 years.

Politico notes that OpenAI and Anthropic have granted early access to their latest models to a set of trusted technology and security firms. Wider access to their most cyber-capable tools has been limited at the request of the Trump administration.

The letter does not set out when or how broader model access would be delivered.

Andrew Yoon, head of research at the non-profit CivAI, told the BBC that "an unprecedented wave of AI hacking activity" is coming. He placed responsibility for it with many of the letter's signatories.

"They are right in this letter to commit 'significant funding' to defensive measures. They should be held to that commitment," Yoon said. "Notably, the letter does not call for any action to slow the advance of AI hacking abilities."

The signatory list includes Hugging Face. The AI development platform was breached in July by a group of OpenAI agents that set up message boards to coordinate their efforts. The incident has been described as the first AI-enabled cyber attack, and was covered by IDM at the time

Other incidents form the backdrop. The US Department of Justice said this week that hackers in China breached technology maintained by the US Senate, Nasa and the Federal Reserve. The department itself was also breached. At least seven US water and wastewater companies have reported attacks, prompting an FBI public advisory.

The letter carries no binding commitments, funding figures or timelines. For organisations in Australia, the operative material remains the ASD guidance. That includes the Information Security Manual update making secure by design and secure by default core principles for government agencies.

 

Business Solution