"share threat intelligence and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work," the Collective Cyber Defense letter instructs.
Who signed — and how many have since joined
Last week more than 100 companies and organizations published an open letter calling for a rapid acceleration of cyber defense capabilities to counter AI-enabled attacks. The signatory list reads like a procurement catalog: Microsoft, Google, AWS, Cisco, IBM, CrowdStrike, Cloudflare, Anthropic, Okta and Fortinet appear alongside buyers such as Mastercard, Visa and Capital One. The public signatory page has since passed 200 companies and organizations, and firms including 1Password, Sophos and Prophet Security have published posts detailing their own commitments to defenders.
The shrinking window for remediation — CrowdStrike’s data and React2Shell
The letter opens with a clear diagnosis: there is a limited window to strengthen defenses before AI-enabled attacks become widespread. It cites CrowdStrike’s 2026 Threat Hunting Report, covering January through June 2026, which “found that 88 percent of the exploitation it observed against vulnerabilities with a public proof of concept occurred within 48 hours of that proof of concept being published.” The same CrowdStrike team logged more than 800 hunting leads across over 80 victim organizations in the four days after the React2Shell disclosure. Forty-eight hours, the letter argues, is shorter than most change windows and shorter than many patch cycles.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat the letter demands from vendors — three measurable metrics
Buried in the section addressed to cybersecurity companies is the single sentence that behaves like a standard. The letter asks companies to “share threat intelligence and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work.” Those three metrics — coverage, containment speed, and verified remediation — were publicly endorsed by every security vendor on the signatory list, under each company’s logo, in a document they chose to promote.
Five questions to bring to your next vendor renewal
- What share of your installed base is actually running the AI-enabled defenses described here, and what does that capability cost above the current contract?
- What is your median and 95th percentile time to contain, measured by your own telemetry, this year versus last?
- What is your retest rate, and how many remediations failed verification on the first attempt?
- The letter commits signatories to making AI-powered defense deployable for critical infrastructure operators with hands-on help — what does that program cost a 200-bed rural hospital, and how many are enrolled today?
- What proportion of your own product is model-generated code, and who reviews it before it reaches my environment?
Those five questions are lifted directly from the letter’s logic: ask vendors to produce evidence against their own asks. Coverage claimed in a letter and coverage sold in a SKU are rarely the same number; the gap is where upsells live.
How technologists, procurement leaders, and critical infrastructure operators should respond
Technologists and security teams should demand telemetry-backed answers to the three metrics the letter endorsed: coverage, containment speed, and whether fixes are verified. Procurement leaders should put the five renewal questions on the table to translate public commitments into contract terms and cost projections. Critical infrastructure operators should press signatories for the hands-on deployment programs the letter promises — specifically, the cost and enrollment numbers for a 200-bed rural hospital — before accepting assurances of deployability.
The letter’s diagnosis is candid and its timing urgent; signing it cost nothing as of Aug. 27. But commitment on a webpage becomes concrete only when buyers make it so. Two hundred companies agreed to measure progress. Put the question in your next renewal and one meeting will tell you which of them meant it.




