116 companies called for a defensive surge. Who in your business would answer?

116 companies called for a defensive surge. Who in your business would answer?
More than a hundred technology companies warned this week that AI-enabled attacks are about to get much worse, and told every organisation to fix its vulnerabilities. Most Canadian mid-market businesses cannot act on that advice, and the reason is governance, not tooling.

On Thursday, more than a hundred technology companies signed a joint letter warning that AI-enabled cyber attacks are about to become, in their words, far more widespread and sophisticated. The signatories include OpenAI, Anthropic, Google, Microsoft, Amazon and Oracle. Their argument is that there is a narrow window in which defenders can get frontier AI models working for them, before attackers have the same capability as a matter of course.

The letter sets out what it wants from four groups: governments, AI developers, cyber security firms, and everybody else. That last category is the one most Canadian businesses fall into, and the instruction to it is short. Fix your vulnerabilities. Modernise the systems you have been putting off. Put AI to work on your security problems.

It is good advice. Most Canadian mid-market businesses cannot act on it, and not for the reason people assume.

The gap is not tooling. It is who decides.

Ask a two-hundred-person Canadian company to "fix its vulnerabilities" and you have not given it a task. You have given it a question it has no process for answering. Which vulnerabilities? Ranked how? Against what view of which systems actually matter to the business? Signed off by whom, on what budget, at the expense of what else?

In organisations with a security function, those questions have owners. In the organisations we mostly meet, they do not. There is an IT manager who is already fully occupied, a finance lead who signs things, and a board that has never been given the information it would need to prioritise anything. The advice arrives and nothing moves, not because anyone disagrees with it, but because it is nobody's job to convert it into a decision.

That is a governance problem wearing a technical costume. And it is the reason a warning with a short fuse is harder to act on than a warning with a long one. A twelve-month risk can wait for the next planning cycle. A risk measured in months cannot, and a business that needs three months just to work out who owns the question has already spent the window.

Three questions worth answering this quarter

None of these require a security team. They require somebody senior to sit down for an afternoon and write the answers down.

What would actually hurt us? Not a list of every system. A short, honest list of the handful of things whose loss or exposure would genuinely damage the business: the customer data, the one application everything depends on, the person whose credentials open the most doors. Most organisations have never written this down, which is why every risk looks the same size.

Who decides, and how fast can they? If something needs patching this week and it will break a process the business relies on, who makes that call? If the answer is "it would go to the next management meeting", that is your real exposure.

What could we show? If a customer, an insurer or the Privacy Commissioner asked what you did about this in the six months after the warning, what document would you hand them? Under PIPEDA you are already required to keep a record of every privacy breach for two years, including the ones you judged harmless. Most businesses discover they have no such record at the worst possible moment.

One thing worth noticing about the letter

A hundred and sixteen organisations signed it, and a great many of them sell AI, cyber security, or both. That does not make the warning wrong. The technical case that AI systems are getting better at finding and exploiting software flaws is well evidenced and does not depend on who is making it. But it is worth being clear-eyed that the recommended response, buy more AI-powered security, happens to be what the signatories sell.

Which is the argument for governance rather than procurement. The businesses that come out of the next two years well will not be the ones that bought the most. They will be the ones that decided what mattered, wrote it down, and can show their work.

Where we sit

We are not a security vendor and we do not sell tooling, so we have nothing to gain from telling you to buy any of it. What we do is help Canadian boards and executives answer the three questions above and produce the evidence that they did. If the letter has landed on your desk and you are not sure what it means for your organisation specifically, that is a conversation worth having, and the first one costs nothing.

Leave a Reply

Your email address will not be published. Required fields are marked *

French Version »