Your Risk Framework Is Lying to You
Most board risk registers describe the cyber threat landscape as it stood five years ago: static, with the main variable being how fast your IT team can move. The Five Eyes have now said publicly that this model no longer holds.
Their cyber security agencies issued a joint call-to-action last week warning that AI is accelerating “the speed, scale, and sophistication of cyber threats.” Read plainly, that means the assumptions inside your risk appetite statement — particularly any that treat time-to-patch as a real buffer — describe an environment your organisation no longer operates in. That is a board problem, not an IT one.
The Window Boards Were Counting On No Longer Exists
Australian risk frameworks have long treated vulnerability management as a timing exercise. A critical CVE lands, the team has days or weeks to assess, prioritise and patch before exploitation becomes likely, and the board approves a process with a comfortable runway attached to it.
AI has taken the runway away. Open-weight models are now capable enough to be genuinely useful in orchestrating offensive work — vulnerability discovery, exploitation scripting, reconnaissance — tasks that used to require both skilled operators and lead time and now require neither. The gap between public disclosure and a working exploit landing on real targets has collapsed, and there is no reason to expect it to stop collapsing.
Five governments whose intelligence agencies have built careers on not overstating things have now said the genie is out of the bottle. Treat that as a change to your operating environment rather than a communications event.
The Governance Exposure Is Specific
For Australian organisations operating under APRA CPS 234 or the SOCI Act, this creates a precise and defensible liability exposure — not a hypothetical one.
CPS 234 requires information security capability commensurate with the size and extent of threats to information assets, and requires boards to satisfy themselves that it is sufficient. A framework assuming weeks of runway, in an environment measured in hours, fails that test on the facts rather than on interpretation.
SOCI Act obligations around critical infrastructure risk management programs carry similar logic. A risk management program is only as good as the threat model it’s built on. If that threat model is outdated — and a framework that ignores AI-accelerated exploitation timelines is outdated — then the program does not satisfy the obligation in substance, even if it satisfies it on paper.
The practical consequence: if your organisation experiences a breach involving a recently disclosed vulnerability, and the board-approved risk framework assumed a mitigation window that no longer exists, that is a governance failure with a paper trail. Regulators will ask whether the risk framework reflected the known threat environment. The Five Eyes just made “known” very hard to argue around.
This Is Not an IT Resourcing Request
The instinct, when this kind of risk is raised, is to treat it as an ask for more budget — more staff, faster patching cycles, better tooling. That framing lets boards off the hook too easily.
What matters is whether your risk appetite statement is accurate. Appetite is a board instrument describing the level of risk the organisation accepts and the assumptions underneath that acceptance. Get the assumptions wrong and you have not written a governance document; you have written evidence.
The question to put to the CISO or risk function is specific: does our framework account for AI-accelerated exploitation timelines? “Are we aware of AI as a threat” is the question that gets a comfortable yes. The harder version asks whether the rated likelihood and velocity of individual risks have been revised now that exploitation regularly outruns the patch cycle. If not, that revision belongs before the next risk committee sign-off, not on the list of things scheduled for review.
What Defensible Looks Like From Here
Three things distinguish defensible governance here. The first is a current threat model, which means risk ratings for technology-dependent exposures get reviewed against the real exploitation environment rather than on an annual cycle. Material shifts should trigger the review; this statement is one.
The second is honesty about what the controls can do. Compensating controls that depend on response time need reassessment, and where detection and containment carry the load, the board should know how far detection lag has actually come down and what residual risk sits behind that number.
The third is an appetite statement that matches the organisation. If you cannot close critical vulnerabilities in hours, that is a risk acceptance, and it belongs in writing, owned at board level, rather than living unspoken in a backlog.
The Takeaway
This is a formal acknowledgement from the world’s leading signals intelligence community that the threat model has changed in a specific and measurable way. A board that keeps approving frameworks built on pre-AI timelines is not exercising prudence; it is signing something it has been told is wrong.
Take the risk appetite statement out and read it against one question: does it describe an exploitation environment where the window your controls assume has effectively closed? Fix it while the question is still yours to answer, rather than a regulator’s.