Cybersecurity has alwaysbeen a community-driven discipline. Threat actors collaborateopenly, sharing tools, techniques and infrastructure, while defenderstraditionally responded by sharing intelligence, vulnerabilities and lessonslearned. That collective knowledge has always been one of our greateststrengths.London'strading industry is coming home!That is why the recent callfor collective action on cyber defence, led by OpenAI and supported by morethan 100 organisations across technology, cybersecurity, financial services andcritical infrastructure, is so significant. Not because of the companiesinvolved, but because it signals a growing recognition that the traditionalmodel of organisational self-defence may no longer be sufficient.If AI is becoming the forcemultiplier for attackers, then collaborative, intelligence-driven defence hasto become the force multiplier for everyone else. That is the thesis I want tounpack here, and why I think this could be an open-source moment for ourindustry.From Best Practice to CollectivePerformanceCybersecurity has never hadmore technology available than it does today. Security leaders are inundatedwith new products and promises. Every year, the market produces anothergeneration of tools claiming to solve emerging threats. Yet despite this investment,organisations continue to experiencebreaches, ransomware events, fraud losses and operational disruption.The problem is rarely a lackof technology, but understanding whether controls perform under real-worldconditions. Too often, organisations measure security through inputs ratherthan outcomes. They track the number of controls implemented, policies written,vulnerabilities patched or frameworks adopted. These activities are important,but they do not necessarily reveal whether risk is being meaningfully reduced.A firewall can be perfectlyconfigured and still be bypassed. An incident response plan can exist on paperand fail during a crisis. A security awareness program can achieve highcompletion rates while employees continue to fall victim to phishing attacks.This is where I thinksecurity experts need to get out of textbook thinking. A security gap does notautomatically mean the answer is another tool; it means a control needs to betested against how it actually behaves under pressure.What matters most isperformance. How quickly can an attack be detected? How effectively can it becontained? How quickly can an organisation recover? And can they demonstratethat a security investment has reduced risk in a measurable way?This is precisely the kindof question that gets easier to answer collectively than alone. Australia hassometimes played catch-up in cybersecurity, but there are areas whereAustralian organisations have been genuinely industry-leading, and one of ourstrengths has been the willingness to learn from each other.If one organisation hasfound an effective way to counter a particular threat, a playbook that actuallyheld up during a live ransomware event or a detection rule that caughtsomething others missed, others shouldn't have to rediscover it from scratch. That'sthe whole premise behind initiatives like the open call to action on cyberdefence, turning isolated lessons into shared ones.The AI Shift Changes the EquationThis becomes particularlyimportant in an AI-driven threat environment, where the technology is beingused to accelerate scams and fraud, with increasingly sophisticated attacks.The 4 stages of Artificial Intelligence:0. Systemic AI responds to prompts based on probabilities established during training: i.e. current state-of-the-art AI.1. Sentient AI is quintessentially curious and uses experience to refine beliefs about the world. 2. Sophisticated…— World of Statistics (@stats_feed) April 8, 2024The foundations ofcybersecurity remain essential, but the industry needs to better understandwhether they can withstand an adversary that is increasingly AI-enabled andpersistent. That is why organisations need to move beyond simply securing AIand start becoming AI-native in the way they operate security.AI should help organisationsidentify exposure faster, analyse risk more effectively, test performancecontinuously and improve response capabilities. It should enable security teamsto focus on higher-value work while increasing both speed and accuracy acrosssecurity operations.This is not about stoppinginnovation but instead creating an environment where peoplecan adopt AI confidently and securely, and where the industry’s collectiveresponses change at the same pace as the threats.None of this meansone-size-fits-all. One of the challenges for global organisations is that thereis no single threat environment. The threat environment facing a financialservices business in Australia may differ significantly from the risksencountered in Europe, the United Kingdom or the Middle East.That's not an argumentagainst collective defence, but it is a reason to be precise about what we'resharing. The value of collaboration isn't a single global policy that assumesevery market faces the same threats. There needs to be common foundations andprinciples with enough flexibility to manage local threat profilesappropriately.So instead of asking whetherevery part of the organisation follows the same process, security teams shouldbe asking whether the controls are performing effectively against thereal-world threats that matter in each location, informed by what the widerindustry has already learned.AI May Change the Role of the CISOThere is a temptation torespond to every new cyber threat with another tool, process or additionallayer of security. But the old playbook of more people and tools to combat morethreats may no longer be the answer.The future belongs to organisationsthat cancontinuously measure effectiveness, leverage automation intelligently anduse AI to improve decision-making at scale.A verified YouTube account was impersonating SpaceX and livestreaming an Elon Musk deepfake crypto scam.The number of scams on YouTube has skyrocketed. YouTube should just change its name to ScamTube. pic.twitter.com/5z6c0w0jft— DogeDesigner (@cb_doge) April 9, 2024That requires ChiefInformation Security Officers (CISOs) to lean further into collaboration thanwe have before. The new collective action model gives us a way to acceleratethat learning by turning individual incident response into shared institutionalmemory across the industry.The breadth of organisationssupporting the collective cyber defence call is a powerful signal that theindustry at large is prepared to recognise cybersecurity as a shared challenge.Much like the open-sourcemovement did for engineering, cybersecurity now has an opportunity to build aculture where organisations share what works, learn from what doesn’t, andbuild on each other’s progress rather than solving the same problems independently.AI is making the cost ofplaying alone much greater, but it’s also giving the industry much better toolsto play as a team.This article was written by Manasseh Paradesi at www.financemagnates.com.