Why “having controls in place” is no longer enough – and what intelligence agencies are now asking of IT leaders.
When the intelligence and cyber security agencies of five nations issue a joint public statement, it is worth paying close attention. On 22 June 2026, the heads of the Australian Cyber Security Centre, the UK’s NCSC, CISA, the NSA, Canada’s Centre for Cyber Security, and New Zealand’s NCSC did exactly that.
The statement, titled “The AI shift in cyber risk: why leaders must act now,” is not a policy document or a framework update. It is a direct call to action addressed to boards and executives across industry. And buried within it is a line that should land with particular weight for every IT and risk leader managing security controls in a mid-market environment:
“It is not enough to have controls. Leaders must be confident those controls will perform during a real incident.”
That sentence is the operational challenge this piece unpacks.
Why This Statement Is Different
Joint statements from the Five Eyes are rare. When they occur, they signal that the agencies have reached a shared assessment serious enough to warrant public disclosure. This one carries the signatures of six agency heads and makes a specific, urgent claim: frontier AI models are transforming cyber risk faster than most organisations are prepared for, and the timeline is months, not years.
For Australian mid-market organisations, the significance isn’t just the AI warning. It’s the explicit shift in what the world’s leading intelligence agencies now consider the minimum standard for cyber security. The statement moves the benchmark from having controls to being confident those controls will perform. That is a meaningful and consequential distinction.
What the Five Eyes Actually Recommend
The statement outlines four concrete actions. Each one has direct operational implications for IT and risk leaders.
- Accelerate patch management
AI is compressing the time between vulnerability discovery and exploitation. What previously gave organisations weeks to respond may now give them days. The statement is explicit: delays in patching increase risk, especially for operational systems with long update cycles. For IT teams managing Essential Eight obligations, this raises a direct question – not whether patching processes exist, but whether they are fast enough and comprehensive enough to keep pace with an AI-accelerated threat environment.
- Address legacy systems
The Five Eyes agencies describe unsupported systems not as technical debt but as strategic liabilities – high-value targets that provide persistent entry points for attackers. For mid-market organisations, legacy systems often sit at the edges of environments: off-network endpoints, decommissioned applications still running in the background, infrastructure that fell out of the patch cycle years ago. The statement’s instruction is clear: review, remediate, or replace.
- Review and strengthen identity and access controls
The recommendation is to limit who can access critical systems, enforce strong authentication, and regularly review permissions. This maps directly to two of the Essential Eight controls – restricting administrative privileges and enforcing multi-factor authentication. The operative word in the statement is “regularly.” A review conducted twelve months ago does not reflect an environment that has changed since then.
- Prepare for incidents before they happen
The statement acknowledges that breaches will occur. Preparedness, it argues, is what determines whether an incident becomes a contained disruption or an operational crisis. This means tested response plans, trained teams, and the assumption that existing defences will eventually be tested under real conditions.
The Gap the Statement Identifies
The most operationally significant insight in the Five Eyes statement is about timing. AI is not just enabling more sophisticated attacks – it is shrinking the window between when a vulnerability exists and when it is exploited.
This has a direct consequence for how organisations maintain their security controls. A patch management process that was adequate six months ago may no longer be fast enough. A legacy system that carried low risk last year is now a higher-value target. An access review conducted at the last assessment may not reflect who has access today.
The statement captures this dynamic precisely: “The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years.”
For IT and risk leaders, this is not an abstract warning. It is a practical challenge. The controls that were validated at the last assessment are operating in an environment that has continued to change. The gap between that validation and the current state of the environment is where exposure accumulates – quietly, without triggering alerts.
This is the same gap that point-in-time security assessments struggle to address. An assessment completed last quarter was accurate then. Whether it reflects today’s environment is a different question entirely.
Will My Essential Eight Compliance Still Be Valid?
The Five Eyes standard – confidence that controls will perform during a real incident – is higher than most organisations currently meet. And it is higher than most reporting currently measures.
Security reporting tells you what controls are in place. It does not tell you whether those controls are performing as expected right now, in a live environment that has changed since the last review. The gap between the two is where unquantified risk tends to sit – and where the Five Eyes statement is now directing attention.
Closing that gap requires moving beyond periodic validation toward a continuously current understanding of what is actually in the environment and how controls are performing. For IT and risk leaders, that means three things in practice:
Patch currency needs to be verified across every endpoint – including remote, legacy, and off-network devices – not assumed based on scheduled processes. Access privileges need to reflect the current team and current roles, not a configuration that was accurate at the last review. And monitoring needs to be tuned to surface genuine threats efficiently, not generate noise that buries real signals.
This is what a structured security posture assessment is designed to establish – a verified, current picture of how controls are actually performing, not an assumed one. It is also what cyber insurers are increasingly requiring before they will write or renew coverage.
The Five Eyes statement has effectively raised the bar. The organisations that meet it will not be the ones with the most controls. They will be the ones who can demonstrate those controls are working.
What This Means for Australian Mid-Market Organisations
The Five Eyes statement is directed at boards and executives. But the operational responsibility for meeting its standard sits with IT and risk leaders. Most mid-market organisations do not have a dedicated CISO. The people accountable for security posture are also accountable for infrastructure, operations, and service delivery. The Five Eyes standard is now their standard too.
The good news is that the foundational controls the statement recommends – patch management, access integrity, legacy remediation, incident preparedness – are the same controls that Essential Eight compliance in 2026 already addresses. Organisations that have invested in Essential Eight maturity are not starting from scratch. They are starting from a foundation.
The question is whether that foundation is verified or assumed.
The Bottom Line
The Five Eyes agencies have set a clear standard: having controls is not enough. Confidence that those controls will perform under pressure is the new baseline.
For Australian IT and risk leaders, this is not a distant concern. It is a question worth answering now – before an incident answers it for you.
If you’d like to understand where your current security controls stand against this standard, the Evolution Systems team is ready to help.
FAQs
What is the Five Eyes cyber security statement?
On 22 June 2026, the intelligence and cyber security agencies of Australia, the United Kingdom, the United States, Canada, and New Zealand issued a joint statement titled "The AI shift in cyber risk: why leaders must act now." It calls on boards and executives across industry to strengthen foundational cyber security practices, integrate cyber risk into business strategy, and ensure that security controls will perform under real incident conditions - not just on paper.
What does the Five Eyes statement recommend organisations do?
The statement outlines four concrete actions: accelerate patch management, address legacy systems, review and strengthen identity and access controls, and prepare for incidents before they happen. It emphasises that cyber risk is a core business risk and leadership responsibility, not a purely technical issue.
How does AI change cyber security risk for mid-market organisations?
AI is compressing the time between vulnerability discovery and exploitation. Controls and risk assumptions that were valid months ago may already be outdated. For mid-market IT teams, this means patch management, access reviews, and control validation need to happen more frequently and more comprehensively than periodic assessments alone can support.
What does it mean to be "confident your controls will perform"?
The Five Eyes standard goes beyond having controls in place. It requires that leaders can demonstrate those controls are performing as expected in a live environment - not just at the point of the last assessment. This means verified patch currency, current access privileges, tuned monitoring, and tested incident response capability.
How does the Essential Eight relate to the Five Eyes statement?
The foundational controls the Five Eyes recommend - patch management, access integrity, application hardening, and backup resilience - map directly to the Essential Eight. Organisations that have invested in Essential Eight maturity have the right foundation. The Five Eyes statement raises the question of whether that foundation is verified or assumed.
What should Australian IT leaders do now?
Start by understanding whether your current controls are performing as expected - not as they were configured at the last assessment. A structured security posture assessment provides a verified, current picture of control performance across your environment. From there, the Five Eyes recommendations provide a clear framework for prioritisation.