Why the Five Eyes AI warning should change the Board's cyber agenda


By Nick Lowther*
Friday, 11 September, 2026


Why the Five Eyes AI warning should change the Board's cyber agenda

In June 2026, the Australian Signals Directorate and Five Eyes Alliance warned that frontier AI is accelerating the speed, scale and sophistication of cyber threats faster than most organisations are prepared for. With the potential for operational disruption, as well as financial loss and reputational damage, the message is clear: cyber resilience is now a core business risk, not just an IT issue — and organisational leaders are being urged to act now.

At the centre of this changing risk is identity — the credentials which determine who (and what) should be able to access an organisation's systems. Unfortunately, AI has introduced a new dimension to this problem.

As enterprises introduce a wave of generative AI tools and AI agents, each one comes with its own non-human identity (NHI). NHIs already vastly outnumber human users 10:1, according to Microsoft, with that ratio trending towards 100:1 in the future.

As a result, AI is changing how attackers advance and how organisations defend their systems: and it must change the way that boards think about the intersection of AI adoption, identity security, and incident response and recovery.

How AI adoption is accelerating cyber risk now

Leadership at Australian organisations tell me they are squeezed between the opportunities and the threats of AI. Often, this means they are giving AI agents direct access to critical systems faster than they can erect adequate guardrails.

In Semperis' recent State of Identity Security in the AI Era report, Australian respondents said that:

  • 37% of their workforce has AI installed on local machines where it can access important passwords and security keys.
  • 24% of organisations already use AI agents to handle security-related help desk tickets, including password resets and VPN access.
     

At the same time, those respondents also believe AI is vastly increasing their identity attack surface. For example:

  • 80% of Australian respondents expect AI will make identity attacks more frequent.
  • Only 21% of Australian organisations believe they could regain control if an AI agent exposed their admin credentials.
     

With AI evolving at such a rapid pace, the Five Eyes statement stresses that cyber risk assumptions can become outdated in months or even weeks — and that resilience must hold up under pressure in the event of a real incident.

That's an uncomfortable standard, given many enterprises have never actually battle-tested whether they can recover their identity systems after a compromise.

The key challenge is that identity is both a target and a dependency. Not only do attackers routinely target identity systems — the rest of the organisation also depends on identity systems to function. When identity is down, email, conferencing, file access, SaaS access, operational workflows and even crisis coordination can fail with it.

That creates a compound risk, where:

  • identity is a high-value attack surface
  • identity enables lateral movement and privilege escalation
  • identity is also the system the business needs to recover everything else.
     

This is why boards should not treat Active Directory recovery as just another backup exercise.

The gap between backup and true identity resilience

One of the most important distinctions in identity resilience is the difference between having a backup and being able to recover to a trusted state. Recovery is the outcome that matters, not backup alone.

Anyone can claim to have backed up Active Directory: the harder question is whether it works. Organisations need to ensure the restored AD functions correctly enough to enable minimum viable company (MVC) operations — the absolute smallest set of people, processes, technology and systems an organisation needs to stay operational during a severe crisis.

This is where many resilience programs are still immature. They have backup policies and maybe even recovery runbooks, but they have not proven that identity can be restored cleanly, within a reasonable timeframe, under the stress and confusion of an actual crisis.

If the Five Eyes statement is a call to leadership, boards need concrete questions to ask, for example:

  1. Can we recover AD to a known-clean state? It’s critical to ensure your backup is totally free of hackers before you restore it (so they can't simply break in again).
  2. Have we tested recovery within the expected timeframe? AD recovery is only meaningful if it functions correctly, within a reasonable timeframe.
  3. Do we know which identity exposures matter most? For example, it could be old admin logins, misconfigurations or weak identity controls that attackers can chain together.
  4. Can the crisis response team coordinate if communication systems are down? If email, file shares and normal communications are not functioning correctly, crisis response teams will require an out-of-band communication system.
  5. Have we validated this recently? If cyber risk assumptions can become outdated in months, then resilience validation can't be a once-a-year checkbox. It must be rehearsed regularly.

What practical readiness looks like

For hybrid identity environments, practical readiness usually includes several actions:

  1. Reduce identity attack paths: Strengthen privileged access, remove unnecessary exposure, and identify high-risk attack paths before an adversary does.
  2. Improve visibility into identity-specific behaviour: General logging matters, but identity attacks often require AD-specific context to spot dangerous changes.
  3. Test recovery in a real-life scenario: Ensure identity services, dependencies, and critical operations can be restored effectively under pressure.
  4. Treat crisis management and identity recovery as inseparable: Identity recovery is not just a technical restoration event — it involves executives, legal teams, infrastructure teams, external stakeholders and more. The organisations that manage both simultaneously will recover faster and with less chaos.

Boards must validate identity recovery now

Boards don't need another abstract assurance that "we have controls in place". They need evidence that identity resilience works under pressure.

This means leadership teams must validate the one capability that will matter most when their identity systems are compromised: the ability to recover AD quickly and reliably. Organisations that can provide that evidence will be better prepared not just to survive AI-accelerated threats, but to maintain trust when the test comes.

*Nick Lowther is Enterprise Sales Director, ANZ at Semperis.

Image credit: iStock.com/Just_Super

Related Articles

The next cyber threat has arrived and identity security is key for survival

Frontier AI is poised to reshape cybercrime by making sophisticated attacks faster, cheaper and...

Faking a trusted brand is easier than ever, defending against impersonation isn’t

Organisations need to defend their brands with renewed vigour as AI‍-‍driven...

How Mythos changes the assumptions underpinning Australia's banking regulations

The advent of frontier AI models invalidates many of the cybersecurity assumptions implicit in...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd