
OpenAI’s cyber defense letter gets the diagnosis right and the prescription wrong
On August 27, 2026, OpenAI published an open letter titled “A call for collective action on cyber defense.” More than 100 organizations signed it (CNBC counted 116) including Anthropic, Microsoft, Google, Amazon, CrowdS…
以下正文同步自 InfoWorld,版权归原站所有,已转换为易读排版。
On August 27, 2026, OpenAI published an open letter titled “A call for collective action on cyber defense.” More than 100 organizations signed it (CNBC counted 116) including Anthropic, Microsoft, Google, Amazon, CrowdStrike, Palo Alto Networks, Mastercard, and Visa. The central message is blunt:
In the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable.
They’re right, and the letter is more honest than most industry documents of its kind. It concedes that current security practices are not sufficient. It names hospitals, water treatment plants, and power systems instead of hiding behind the word critical. It admits that the technical debt is real and that the teams are under-resourced.
Then it reaches the recommendations, and the urgency drains out of the room.
The asks describe a world where you still get to react
The letter’s four calls to action come down to threat intelligence sharing, coordination across levels of government, funding for under-resourced essential services, patching high-risk vulnerabilities, and giving defenders access to capable models during an incident. All of it is worth doing. All of it also happens either long before an attack, on a timeline you control, or after an attack has already started.
Intelligence sharing assumes somebody saw it first. Coordination assumes there’s time to convene. Funding assumes a budget cycle. Patching assumes a published CVE and a maintenance window you can actually get approved.
That is a defense architecture built for an adversary who works business hours.
Run the arithmetic on GTG-1002
On November 14, 2025, Anthropic disclosed what it called the first reported AI-orchestrated cyber espionage campaign. A Chinese state-linked group it tracks as GTG-1002 hit roughly 30 organizations and used Claude Code to execute 80% to 90% of the operation independently. Human operators contributed a maximum of about 20 minutes of work at the key decision points.
Twenty minutes. Across a campaign against thirty targets.
Set that against your own numbers. Triage time on a single alert. The lag between an EDR (endpoint detection and response) system firing and a person deciding the threat is real. If the honest answer runs to hours, you aren’t in the race. You’re watching it.
The letter says we have a limited window to respond and measures that window in months. The window that decides the outcome is the gap between the instant that malicious code executes on an endpoint and the instant that anything in your stack reacts. That gap runs in milliseconds, and an autonomous adversary now owns both ends of it.
Detection was a rational bet when attacks moved at human speed
Detect and respond was never a bad idea. It was an economic one. When an attacker needed weeks of manual reconnaissance, a human tester, and a hand-built payload, buying time to notice and contain was the highest return per dollar in security. That math held for fifteen years.
It doesn’t hold against a process that never sleeps, never gets paged, and never hands off at shift change.
Keep the telemetry. Keep the hunting, the playbooks, and the tabletop exercises. That work is what makes an incident survivable, and it isn’t going anywhere. But it’s a second line of defense, and this industry has spent a decade funding it like a first one. The OpenAI letter, for all its candor, mostly proposes that we fund the second line harder.
The one recommendation the letter almost makes
Tucked into the ask aimed at cybersecurity companies is a line about layered defense and least privilege access. That is the closest the document gets to prevention, and it’s the part that deserves expanding, because layers only pay off when at least one of them is deterministic.
Deterministic means the control doesn’t need to recognize the threat to stop it. No classification, no confidence score, no waiting for a verdict. It removes the conditions the payload needs to run at all. Anything that depends on recognition inherits every blind spot of whatever is doing the recognizing, and machine-generated malware is now produced faster than any corpus can be labeled.
That distinction is the whole argument. A probabilistic control degrades as novelty rises. A deterministic one doesn’t care how novel the sample is, because it never gets a working environment to execute in.
Stop measuring response. Start measuring what never ran
Change the metric. Mean time to detect and mean time to respond describe how gracefully you lose. The number that belongs on the slide for the board of directors is the share of attempted executions stopped at run time, before anything downstream needed cleaning up.
Three questions are worth asking this quarter. What percentage of malicious executions in our environment were blocked outright rather than caught afterward? Which of our controls work with zero prior knowledge of the threat? If the SOC went dark for twelve hours tonight, what still holds the line?
Most teams can’t answer the first one. That’s the finding.
Months is the wrong unit
The signatories did the industry a real service by putting their names on the diagnosis. Competitors rarely co-sign a document that says their customers’ current practices are insufficient, and that alone should register.
But the window they’re describing and the window that matters are not the same window. One closes over months. The other closed years ago, quietly, every time an attacker automated a step a human used to perform.
Stop the code from executing. Then share, coordinate, and fund everything else with the time you just bought.
—
New Tech Forum provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all inquiries to doug_dineley@foundryco.com.
正文由 FLUX 从来源站点 RSS 同步,内容未经改写;遇到排版缺失或需要图片、视频时请以原文为准。