The Five Eyes just issued one of the most urgent cybersecurity warnings in recent memory. Here’s what it actually means for your team and where to start.
On June 22, the cybersecurity agencies of Australia, Canada, New Zealand, the United Kingdom, and the United States issued a rare joint warning that most organizations are not going to want to hear: AI-powered cyber threats are not something you need to prepare for down the road, they are already here, and the window to get ahead of them is measured in months not years.
If you run security for a large enterprise with a fully staffed SOC and a budget to match, that warning is serious but probably manageable. If you are running security for a mid-market organization with a small team and about fifteen other things competing for your attention, it might feel like just another alarm going off in a room full of them. It should not, because the teams that come out of this in the best shape are not going to be the ones with the most resources, they are going to be the ones that stopped overthinking it and started moving.
Here is a realistic 90-day framework to do exactly that.
Days 1 to 30: Get an Honest Picture of What You Are Actually Defending
Before you can fix anything, you need to know what you are working with, and most organizations are surprised by how much they are missing when they actually look. AI is expanding the attack surface faster than traditional security tools are built to track, and the blind spots it creates are not small ones.
The three questions worth asking right now are:
- Do you actually know every AI tool being used across your organization including the unsanctioned ones?
- Do you know which users, devices, and applications have access to your most sensitive data?
- Do you have any real visibility into where that data could be going once it leaves your environment.
If you cannot answer those confidently, that is where your first 30 days go.
This is not a theoretical risk either. IBM’s 2025 Cost of a Data Breach Report found that Shadow AI was a factor in 20% of breaches studied, added an average of $670,000 to breach costs, and exposed customer PII at a significantly higher rate than other types of incidents. On top of that, 63% of the breached organizations they looked at had no AI governance policies in place at all. The Five Eyes report specifically calls out how fast the window is shrinking between vulnerability discovery and active exploitation, which means visibility is not a nice-to-have right now, it is the starting point for everything else.
Days 31 to 60: Start Closing the Gaps That Actually Matter
Once you have a clear picture of your environment, the next move is prioritization because not every risk carries the same weight and lean security teams cannot afford to treat them like they do.
The three areas the Five Eyes flagged as most critical are worth taking seriously.
- Patching: AI is compressing the time between a vulnerability being discovered, and it being actively exploited, and the numbers back that up. CISA recently cut the deadline for government agencies to patch serious vulnerabilities down to three days specifically, because of AI-driven threats, which tells you something about the pace of change. If your patch cycles are still measured in weeks, you are operating on borrowed time.
- Identity and access: Compromised credentials are still one of the most common ways attackers get in, and the IBM report found that 97% of organizations that experienced an AI-related breach lacked proper access controls. Multi-factor authentication, least-privilege access, and regular access reviews are not exciting but they are the kinds of controls that consistently determine whether an incident stays small or becomes a crisis.
- Legacy systems: A security expert quoted in CSO Online made a point that is worth repeating here, which is that virtually every large organization has enough misconfigured assets and shadow IT that attackers do not even need zero-days anymore. They can just walk in. Outdated infrastructure is not just a technical debt problem, it is an active liability in an environment where AI is helping attackers find those weaknesses faster than ever.
Days 61 to 90: Stop Treating a Breach Like a Hypothetical
This is the part most organizations drag their feet on, and it is also the part that tends to determine how bad things get when something actually happens.
The Five Eyes agencies were blunt about it: “Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.” So, the question is not really whether your organization is going to face an AI-enhanced attack at some point, the question is whether your team will be ready to contain it when it happens. Run a tabletop exercise, stress test your incident response plan against a realistic scenario that includes AI-generated phishing and deepfake social engineering, and find out where your plan breaks before an attacker does.
What the Report Does Not Tell You
The Five Eyes warning covers a lot of ground, but it was largely written with governments and large enterprises in mind. The reality for most mid-market security teams looks pretty different. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 94% of global security leaders identify AI as the most significant driver of cybersecurity change right now, and that small organizations are 2.5 times more likely to report insufficient cyber resilience compared to large ones. That gap is exactly where mid-market organizations are most exposed, and being handed a list of best practices without any context for how to actually execute them with a lean team is not particularly useful.
The organizations that come out ahead are not going to be the ones that waited for a perfect plan or a bigger budget. They are going to be the ones that picked a starting point, moved on it, and built from there.
Ninety days is enough time to meaningfully change your risk profile if you use it correctly.