Trending Topics

Five Eyes, the NCSC and the AI reality check: Why cyber security fundamentals matter more than ever
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
In this article, Richard Holland, Field CISO at Quorum Cyber, explores why strong cyber security fundamentals are becoming even more critical as artificial intelligence reshapes the threat landscape.
A Field CISOโs Perspective

Over recent weeks, two significant messages have emerged from the cyber security community that deserve the attention of every board, CEO, CIO and CISO. The first came from the National Cyber Security Centre (NCSC), which revealed that the UK experienced over two hundred significant cyber incidents affecting critical national infrastructure during the past year, the majority linked to hostile nation-state activity.
The second came from the Five Eyes intelligence alliance, whose leaders issued an unusually direct warning that artificial intelligence (AI) is accelerating cyber threats at a pace measured in months rather than years.
These announcements paint a clear picture of the environment organisations now operate within. The threat landscape is becoming faster, more automated and increasingly influenced by geopolitical tensions. Yet despite the headlines focusing on AI, nation-state actors and sophisticated cyber capabilities, the core message is surprisingly simple: organisations that consistently execute the fundamentals of cyber security remain in the strongest position to defend themselves.
Thereโs a temptation to believe that AI changes everything. In reality, AI isnโt creating entirely new categories of cyber-attack; itโs amplifying existing ones. Attackers continue to pursue familiar objectives such as stealing credentials, exploiting vulnerabilities, gaining access to systems, moving laterally through networks and disrupting operations. Whatโs changing is the speed and scale at which these activities can now be performed. Tasks that once required specialist skills and considerable time can increasingly be supported by AI systems capable of analysing vulnerabilities, generating code, conducting reconnaissance and identifying attack paths in a matter of minutes.
This acceleration concerns the intelligence community. The Five Eyes warning is not simply about more attacks. Itโs about reducing the time defenders have available to identify, understand and respond. As offensive capability becomes more automated, organisations must increase their own operational tempo if theyโre to remain resilient.
Perhaps the most important lesson from both the NCSC and Five Eyes is that the majority of successful attacks still exploit familiar weaknesses. Compromised identities, poor credential management, inadequate multi-factor authentication, unpatched vulnerabilities, weak visibility and insufficient monitoring continue to feature in many major incidents. AI makes these weaknesses more dangerous.
An attacker who previously required weeks to identify a pathway into an organisation may soon need only hours. An organisation that struggles with basic cyber hygiene today is likely to face even greater challenges against AI-assisted adversaries tomorrow.
This is why the cyber security conversation must move beyond technology acquisition and focus instead on cyber health. Good cyber health is built upon strong identity management, effective vulnerability management, robust monitoring, secure data practices and a culture that understands cyber risk. These capabilities remain the foundation upon which resilience is built. The organisations that perform these activities consistently and well are typically the organisations that recover fastest when incidents occur.
AI must become part of the defence
However, AI isnโt solely a threat. Itโs rapidly becoming an essential component of modern cyber defence. Security operations teams across every sector face the same challenge: increasing volumes of alerts, growing complexity, expanding attack surfaces and an industry-wide shortage of experienced cyber professionals. Human analysts alone cannot keep pace with the volume of activity generated by modern environments. AI therefore becomes a force multiplier, helping analysts identify patterns, correlate events, prioritise investigations and respond more quickly to emerging threats.
The future of cyber defence is unlikely to be fully autonomous, nor should it be. AI systems remain probabilistic by nature. They are designed to generate likely outcomes rather than guaranteed truths. They can make mistakes, draw incorrect conclusions and occasionally act with a confidence that exceeds their actual understanding. For this reason, human judgement remains critical. The most effective security operations centres of the future will combine the speed and scale of AI with the experience, context and critical thinking provided by human analysts. This model of augmentation, rather than replacement, is where the greatest defensive advantage will be found.
One of the most important developments over the next few years will be the emergence of AI agents within cyber security operations. These agents will assist with triage, investigation, enrichment, threat hunting and response activities. Theyโll dramatically reduce the time required to process vast quantities of telemetry and allow analysts to focus on the decisions that require human judgement.
Organisations should already be considering how AI agents can be safely integrated into their security operations, because the attackers they face will almost certainly be doing the same.
The conversation should therefore not be about whether AI should be used in cyber security, but how quickly organisations can responsibly integrate AI into their defensive capabilities. Every modern SOC, MDR provider and cyber security team should be developing a roadmap for AI-assisted operations. The future defender will be an analyst supported by AI, just as the future attacker will increasingly be supported by AI.
MDR must evolve
The implications for MDR services are profound. Traditional MDR capabilities built around signatures, rules and manual investigation remain important, but theyโre no longer sufficient on their own. The next generation of cyber defence will increasingly rely upon AI agents operating alongside threat intelligence, detection engineering and experienced analysts.
Future MDR services must combine visibility across identities, endpoints, cloud services, networks and data with AI-driven investigation and automation. The objective isnโt simply to generate alerts; itโs to identify genuine threats, understand their potential impact and accelerate meaningful defensive action before business operations are affected.
This evolution also reinforces the growing importance of detection engineering and threat intelligence. Understanding attacker techniques, procedures and behaviours is becoming increasingly important in an AI-driven threat landscape. Intelligence-led security operations, supported by AI and experienced analysts, will become one of the defining characteristics of high-performing cyber defence teams.
Equally important is the ability to understand whether detections are working. The future of MDR is about continuously validating that controls, detections and response processes remain effective against evolving attacker techniques. This is where threat simulation and continuous exposure validation become essential.
Threat simulation must become part of the basics
One area where many organisations still have significant room for improvement is the continuous validation of security controls. Historically, penetration testing and red teaming have often been viewed as specialist exercises conducted annually or to satisfy compliance requirements. In a world where threats evolve daily, this approach is no longer sufficient.
Organisations should routinely test whether their security controls can detect and respond to realistic attack scenarios. Threat simulation platforms, breach and attack simulation tools and adversary emulation capabilities provide an opportunity to validate assumptions before a real attacker does. They help organisations understand whether controls are functioning correctly, whether detection coverage is sufficient and whether response teams can act quickly enough to contain threats.
In many respects, threat simulation should now be considered part of the cyber security fundamentals. We would never deploy backups without testing them. We would never assume a disaster recovery plan works without exercising it. The same principle should apply to cyber defence. Continuous validation provides confidence that controls are effective and highlights weaknesses before they become incidents.
Importantly, threat simulation shouldnโt be viewed as separate from MDR. The most mature organisations are increasingly integrating continuous attack simulation, continuous threat exposure management and detection validation directly into their security operations. Understanding whether controls are working is every bit as important as having controls in the first place. In the age of AI, assumptions become dangerous. Validation becomes essential.
Cyber health must become the board conversation
As the threat landscape evolves, organisations must rethink how they measure success. Too often, cyber security discussions focus on projects completed, technologies deployed or compliance frameworks achieved. While these remain important, they donโt necessarily answer the question that matters most to boards and executives.
Can the organisation continue operating when a cyber incident occurs?
Cyber health provides a more meaningful measure of preparedness. It considers identity security, vulnerability management, detection coverage, data protection, third-party risk, resilience and recovery capability as interconnected components of organisational strength. It provides a broader understanding of whether the organisation can withstand disruption and recover effectively.
This shift is particularly important because cyber security is increasingly becoming a business resilience discipline rather than a purely technical one. Boards are now concerned with operational continuity, customer trust, regulatory expectations and reputational impact. The ability to measure, improve and communicate cyber health is therefore becoming a critical leadership responsibility.
The most effective organisations are increasingly measuring cyber health through security scores, attack surface visibility, threat exposure, resilience testing and recovery readiness. These measures provide a far more accurate representation of organisational preparedness than compliance reports or project milestones alone.
The Field CISOโs conclusion: the future belongs to adaptive defenders
The recent warnings from the NCSC and Five Eyes make one thing clear: cyber security is entering a period of rapid change. The convergence of AI, geopolitical instability, increasingly capable threat actors and growing digital dependence is creating what NCSC CEO Richard Horne described at CyberUK 2026 as a โperfect stormโ for organisations.
The challenge is that attackers are becoming more sophisticated โ and theyโre becoming significantly faster. AI is reducing the time needed to identify vulnerabilities, map attack paths, develop malicious code and launch campaigns at scale. The emergence of advanced AI models shows that this is no longer a future concern but an operational reality for both attackers and defenders.
Success wonโt belong to those organisations that consistently demonstrate strong cyber health. Identity security, vulnerability management, asset visibility, data protection, effective monitoring and tested recovery capabilities remain the foundations of resilience โ and their importance only increases as AI accelerates the threat landscape.
Traditional approaches alone wonโt be enough. The speed and scale of future attacks will increasingly outpace purely human-led operations. AI must therefore become part of every defensive strategy. Security teams should be exploring how AI can enhance detection engineering, threat hunting, investigations, response and threat intelligence. Human expertise remains essential, but AI-augmented defenders will increasingly set the standard.
Continuous threat simulation and control validation should become routine. Organisations that identify and address weaknesses before adversaries do will always be in a stronger position.
My advice is simple: focus relentlessly on cyber health and master the fundamentals. Measure security outcomes rather than technology deployments, validate controls through regular testing, and build resilience through exercises and recovery planning. Most importantly, begin integrating AI into your security operations today.
The organisations that thrive over the next decade will be those that successfully combine human expertise, operational discipline, threat intelligence, continuous validation and AI-enabled defence to create adaptive security capabilities capable of responding to an increasingly uncertain world.
The future of cyber security will be defined by how effectively organisations combine people, process, technology and intelligence to protect what matters most.
Related articles
- Peter Gaffney, Chief Information and Security Officer at Sovos: โThe role of CISOs has changed significantly over the past decadeโ
- Microsoftโs record-breaking Patch Tuesday is a vulnerability itself
- Marco Eggerling, International CISO at UiPath: โThe single highest return investment most organisations can make right now is achieving identity hygieneโ
