“100 technology firms (including OpenAI, Google, Microsoft and Anthropic) released an open letter calling for ‘collective action’ for cyber defense.”
100 technology firms’ open letter: a collective call and the premise
The open letter from 100 technology firms frames AI-driven cyber risk as a collective problem that requires collective action. Security leaders quoted in the letter’s wake interpreted the message similarly: more capable models will be broadly available very quickly, and defenders cannot rely solely on model-level safeguards to protect the rest of the internet.
Aviv Nahum: defenders must become AI-native
Aviv Nahum, co‑founder and CEO at Above Security, distilled the change in tempo the letter describes: “An AI attacker can continuously investigate an environment, test hypotheses, adapt when something fails and pursue multiple paths without waiting for a human operator.” He argued that human-led security operations “built around static rules, queues of alerts and periodic remediation simply cannot operate at that tempo.” His prescription: security must “become AI-native” so defenders “continuously investigate identities, humans and agents, reason about behavior in context, and respond at machine speed.”

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildDiana Kelley: collective defense, agent governance, and shared signals
Diana Kelley, chief information security officer at Noma Security, read the letter as “an acknowledgment that AI is changing the economics of cyberattack faster than many organizations are reducing their security debt.” Kelley emphasized immediate, practical actions—patch systems, eliminate unnecessary privileges, strengthen identity and access controls, continuously test defenses—and warned that organizations must treat their own agent deployments as part of both the security architecture and the attack surface. She urged “shared signals, automated warning systems, and mechanisms for rapidly propagating what one defender learns so others can act on it at machine speed.”
Randolph Barr and Ram Varadarajan: fundamentals and new classes of flaws
Randolph Barr, chief information security officer at Cequence Security, pushed back to basics. He said that rapid product timelines can let teams “cut corners” and that “basic security controls get skipped,” which undermines more advanced model protections. Barr recommended cataloguing where agents operate, restricting permissions, vetting third‑party skills, and ensuring behavioral visibility across web, API, bot, and AI‑driven traffic. “The bottom line is that visibility, behavior‑based detection, and least privilege for agents are working,” he said.
Ram Varadarajan, CEO at Acalvio, warned the enterprise threat is not limited to technical bugs. He said modern models can “infer what developers intended the software to do and spot contradictions humans missed,” enabling discovery of “hidden business‑logic flaws, broken trust assumptions, and authorization errors.” Varadarajan added that “Shadow AI has become nearly ubiquitous,” with many knowledge workers using unsanctioned tools and bypassing corporate networks—creating “a profound and unplanned‑for organizational blind spot.” His summation: “We’re facing an ‘assume compromise’ future.”
John Gallagher and Dana Simberkoff: OT friction, remediation pace, and governance before testing
John Gallagher, vice president at Viakoo, agreed the letter’s technical premise is sound but cautioned that remediation pace makes the problem acute for operational technology (OT) and critical infrastructure. “Discovering a vulnerability is no good if patching it takes weeks or months,” he said, noting that maintenance windows, coordinated device updates, and the cost of downtime all slow response. Gallagher called for “automated, scalable cyber hygiene and remediation across all types of connected assets,” and warned that without funding and training, the OT gap will persist. He also observed a cynical reading: the letter could be seen as “an arsonist selling fire extinguishers.”
Dana Simberkoff, chief risk, privacy and information security officer at AvePoint, underscored the need for continuous visibility into “identity, access, configuration, data movement, and agent behavior.” She cited research finding that “nearly 9 in 10 organizations delayed both agentic and generative AI deployments by an average of almost six months because of unresolved data security and data management concerns.” Simberkoff added that before testing powerful systems against real infrastructure she would want “independent pre‑test review, documented scope, technical controls that prevent boundary crossing, continuous monitoring by a separate team, mandatory reporting, and a liability model” that does not leave affected third parties carrying the risk.
What this means for technologists, OT and critical infrastructure teams, and procurement leaders
- Technologists and security teams: Expect recommendations to move from advisory to operational—greater emphasis on continuous visibility, behavior‑based detection, and AI‑native defensive tooling, alongside stricter governance of agent permissions and third‑party skills.
- OT and critical infrastructure teams: Gallagher’s account signals urgency—current remediation processes are “glacial,” and the path forward requires automated hygiene, dedicated funding, and training to shorten mean time to remediate.
- Procurement and product teams: Barr and Kelley’s comments point to tighter vetting and lifecycle governance for AI agents and components—cataloguing where agents operate and treating skills and integrations with the same scrutiny applied to dependencies.
The signatories’ call for “collective action” has prompted a clear consensus among security leaders quoted here: the speed and capability of AI‑driven attacks demand structural changes—continuous monitoring, least‑privilege governance for agents, automated remediation, and mechanisms to share signals at machine speed—while debates remain about incentives, timelines, and who bears the liability for experiments on critical systems. The policy and operational choices made next will determine whether defenders can close the tempo gap the letter warns about.




