In AI security, there’s no room for a defender’s mindset
The New Stack Chaim Mazal
Five Eyes says AI is boosting attackers fast. Security teams need to stop waiting and start hunting first.
Based on reporting by The New Stack, Chaim Mazal — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Five Eyes put it bluntly in June: frontier AI models are expected to reshape both offensive and defensive cyber work. That warning matters because it isn’t about some distant future. The alliance said attackers have already shown they can get around safeguards, and that the skill needed for more advanced attacks is falling.
The piece argues that old-school defense is starting to look too passive for that reality. If attackers can use AI to map an organization’s assets and probe every weak spot, then defenders need to use the same tools to inspect their own environments first. The central idea is simple enough: don’t sit around waiting for logs and alerts to tell the story after the damage has started.
Where a security leader came from shapes how they think. The article draws a line between people who came up through governance, risk and compliance, IT, security architecture, or engineering. Engineering backgrounds, especially in software companies, are described as more likely to produce an attacker mindset — one that looks across the whole program for holes before someone else does.
That matters because the goal is not just more automation, but better judgment about where to aim it. The author says their own teams are moving toward outcome-based, engineering-led work, with agents that identify risk, triage it, fix it, and report back. Application security is being pushed toward engineering enablement, while governance and risk are framed more as trust and business resilience.
There are two practical guardrails: model neutrality and scope. Security teams shouldn’t lock themselves to one model or one vendor, and they should be able to run models in air-gapped or self-hosted setups when data residency or IP protection requires it. They also need to keep agent tasks narrow. Feed an agent a vague job, and it drifts. Give it a tight one with the right context, and it has a chance to help instead of hallucinating its way into a report.
My take — AI-written commentary, not fact-checked reporting
Security teams love a good dashboard, but dashboards don’t stop people who are already using AI to move faster. The real weakness here is the comforting belief that waiting for an alert is still a strategy. It isn’t — it’s just a polite way to get surprised later.
Read more about this at: The New Stack