Skip to content

Cybersecurity

The Five Eyes just wrote to your board. Here's the map we already hold every client to.

Six Five Eyes cyber agency heads wrote to business leaders, not IT teams. They asked for five things. Every CCP client already has to meet all five.

6 min read
Jump to section
  1. 01 The five things they asked for
  2. 02 We already require all five
  3. 03 Fundamentals beat budget
  4. 04 What to ask your IT provider this week

A statement like this usually goes to the technical team and stops there. This one went straight to the people who sign off the budget.

On 22 June 2026 the heads of six cyber agencies across five countries put their names to a single page. Those five countries are the Five Eyes: Australia, Canada, New Zealand, the United Kingdom and the United States. Stephanie Crowe signed for the Australian Signals Directorate. Her counterparts signed for Canada’s Communications Security Establishment, New Zealand’s Government Communications Security Bureau, and the United Kingdom’s National Cyber Security Centre. Two American agencies signed as well: the National Security Agency and the Cybersecurity and Infrastructure Security Agency. All six signed the same message.

They warned that attacks are getting faster and cheaper to run, and that most organisations still have not locked down the basics.

Boards delegate cyber resilience to IT and treat it as a technical chore. That is exactly where it fails, and it is why the agencies wrote to leaders this time. They put cyber resilience alongside cash flow and insurance: a core business risk for the people running the business. And the clock has changed. AI lowers the barrier for attackers and shrinks the gap between someone finding a flaw and someone using it against you at scale.

“The timeline is not years, it is months.”

That line is the agencies’ own. You can read the full statement on cyber.gov.au.

The five things they asked for

The statement is short and practical. Stripped to the actions, the agencies asked every organisation to do five things.

  1. Reduce your attack surface. Your attack surface is everything an intruder can reach: every login, every system left switched on, every connection open to the internet. Challenge whether each one needs to be exposed at all, and wall off the parts that don’t.
  2. Accelerate patching. A patch is the fix a vendor ships when a hole is found in their software. AI is shortening the time between that hole becoming public and someone using it. So a slow update cycle is no longer background housekeeping. It is now your biggest exposure.
  3. Address legacy systems. Unsupported software that no longer gets security fixes is an easy target. The agencies were blunt about it: “They are not just technical debt, they are strategic liabilities.”
  4. Review and strengthen identity and access. Know who can reach your critical systems, give each person only what their role needs, and protect the front door with strong authentication. The clearest example is multi-factor authentication, or MFA: the second step, a code or a tap on your phone, after the password.
  5. Prepare for incidents before they happen. Assume something will get through. Write the response plan, rehearse it, back up your data, and practise the recovery before the day you need it.

We already require all five

None of this is new to us. Every business we manage agrees to a set of security controls written into the contract. It predates this statement by years, and it already covers all five asks. Each ask maps to a control in the Essential Eight. That is the Australian government’s set of eight baseline security measures, and insurers, brokers and regulators now treat it as the minimum.

What the Five Eyes asked forWhat we already require of every client
Reduce the attack surfaceApplication control, locked-down admin rights, and a standing review that asks why a system is exposed at all. (Essential Eight: application control, restrict admin privileges, application hardening.)
Accelerate patchingKnown vulnerabilities fixed inside 30 days or better, tracked rather than left to a quarterly cycle. (Essential Eight: patch applications, patch operating systems.)
Address legacy systemsWe flag end-of-life software at the same review and get it retired or replaced. (Essential Eight: removing unsupported software.)
Strengthen identity and accessPhishing-resistant MFA on critical systems. A password manager, so staff never hold the password themselves. Offboarding wired into HR, so access dies the day someone leaves. (Essential Eight: multi-factor authentication, restrict admin privileges.)
Prepare for incidentsA written incident response plan and tested backups, so you have rehearsed recovery before you need it. (Essential Eight: regular backups.)

The baseline is not a poster on the wall, so we check it at the operational reviews. If a control has been switched off, or was never put in, we say so in writing. The client then has thirty days to fix it. The contract goes further:

Where a client won’t meet the baseline, we’d rather decline the work than accept the risk of an incident they chose to ignore.

The reason is commercial as much as it is principled. We can’t afford to insure a business against the one control it refuses to put in. And if an incident hits a system the client left exposed against our advice, we both pay for it. So we set the minimum at the start, in writing, and we hold to it. That is the same position the Five Eyes agencies have now put in front of every board in the country.

Fundamentals beat budget

The sharpest line in the statement is not about AI at all. It is about spending. “Success will not come from having the most tools,” the agencies wrote. “It will come from getting the basics right.”

For a business owner, read that as permission to stop buying. A well-run Microsoft 365 Business Premium setup, with the fundamentals on, will beat a six-figure pile of security products that nobody finished configuring.

The reflex when a board gets nervous is to approve another tool with another dashboard. More dashboards are not more defence. You already hold a licence for most of the controls the agencies listed. The work is switching them on and keeping them there. Secure-by-default, meaning the protections are on before you ask for them, is the baseline the agencies now expect. Today rather than eventually.

What to ask your IT provider this week

If you take one action from the statement, make it this one. Ask whoever runs your IT to walk you through the five points for your own setup. Your systems, your logins, your backups, your plan for the morning after a breach.

  • Ask your IT provider to map your environment against the Five Eyes five: attack surface, patching, legacy systems, identity, and incident readiness.
  • For each one, ask to see evidence, not reassurance. A patch report, a list of who holds admin rights, the date your backups were last test-restored.
  • If the answer is vague on any of the five, you have found the gap. Fix it first.

If your provider can’t show you that map, that is the conversation to have this week. We’ll run the same five-point map across any Australian business’s setup, client or not, and tell you where you stand. Every one of our plans includes the baseline by default. It is how we work with every client. If you’d like us to run the map over your business, get in touch.

Tags five-eyesai-cyber-riskessential-eightclient-security-baselineasd-acscincident-response
Share LinkedIn Email
See if we're a fit