In June, the Five Eyes intelligence alliance issued a rare joint statement. Frontier AI models, they warned, are “anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities.”This isn’t theoretical; attackers have proven their ability to bypass safeguards. The skill bar for unsophisticated attackers to execute increasingly sophisticated attacks will continue to drop.“In this environment, defending attack surfaces won’t cut it. We need to go on the offense.”For defenders, Five Eyes’ warning signals that existing security approaches do not match our adversaries’ exponential gains in speed and scale. In this environment, defending attack surfaces won’t cut it. We need to go on the offense.The best defense is a good offenseSecurity professionals have a reflexive instinct to treat the release of powerful models as strictly bad news. But hand-wringing about the pace of AI capability gains won’t do anything for a security program. Nearly all security defenses started as tools built to exploit environments, and security teams repurposed them for defense. The logic that built most commercial security tools in use today applies here too, and defenders hold the same claim to advanced technology.If attackers can now use AI to canvass an organization’s assets and generate attacks against every gap, defenders need a mindset that drives them to canvass their own environment first, using the same technology. This instinct naturally comes from a professional background rather than a deliberate choice or method. Different paths, different approachesCISOs gain their seat through several different paths. Some came from governance, risk, and compliance functions that already owned risk. Some came from IT, inheriting security along with the rest of the technology estate. Some came from security architecture, understanding how systems were actually built. More recently, a growing number came from engineering. Each path shaped a different worldview. “Engineering backgrounds tend to produce an attacker mindset, one that proactively searches for holes across the entire program the way an adversary would.”Compliance and IT backgrounds tend to produce a defender mindset: wait for logging, monitoring, or an incident to show you where to invest. Engineering backgrounds, especially at software companies, tend to produce an attacker mindset, one that proactively searches for holes across the entire program the way an adversary would. That’s the one we need right now.How to think like an attackerTeams with an attacker mindset see themselves as building scalable solutions that automate outcomes for the business, while continuously discovering potential shortcomings in the program, the threat landscape, and the infrastructure and asset catalog.That takes real curiosity. Understand how things are set up, why they’re set up that way, and what could go wrong. That’s the foundation of security research generally: an abundance of curiosity about how things work, how they’re supposed to behave, and how you can produce outcomes outside their intended use case.The changes I have made with my own teams move us toward outcome-based, engineering-led functions. Each team supports automated agents that identify risk, triage it, remediate it, and report on it, aligned to a specific business outcome. Application security focuses on engineering enablement, building agents that handle tasks end-to-end across the software development lifecycle. Governance and risk become trust and business resilience, oriented around continuously proving the organization is secure.Building the right AI advantageTo make this work, focus on two practical steps. First, model neutrality. Build workflows that are not tied to one model or vendor, since the best models and AI tools today may not be right in six months. Model neutrality also means deployment neutrality, giving security teams the option to run models in air-gapped or self-hosted environments when data residency or IP protection demands it, not just the option to swap vendors. Second, scope. Keep agentic tasks narrow and well-defined. Give an agent a large, vague problem, and it performs well briefly, then loses the plot and starts generating whatever it thinks will satisfy the prompt. Give it a specific task and prioritize delivering the right context up front for it to succeed more consistently. That is how you orchestrate intelligent outcomes without sacrificing accuracy.“Waiting for an incident or a vendor patch is a luxury we can no longer afford.”Not every program is ready to restructure around agents on day one, and that is fine. For a program earlier in this journey, the starting point does not need to be complicated: look at each area of focus, define the deterministic outcome you want from it, and work backward using the tools you already have, rather than assuming you need an entirely new stack. It’s time to rethink thingsThe biggest risk at this stage is analysis paralysis. The bar attackers must clear keeps dropping as the bar defenders must clear rises. Waiting for an incident or a vendor patch is a luxury we can no longer afford. Our security programs must meet the moment if we want to avoid becoming victims of our adversaries’ reinvention.The post In AI security, there’s no room for a defender’s mindset appeared first on The New Stack.