- TL;DR: Key takeaways for security and business leaders
- How AI adoption is accelerating cyber risk now
- Why the Five Eyes AI warning matters now
- The challenge boards often miss: Identity is both a target and a dependency
- Why AI makes the identity recovery question more urgent
- The gap between backup and true identity resilience
- What boards should ask management now
- What practical readiness looks like
- Reduce identity attack paths
- Improve visibility into identity-specific behavior
- Test recovery the way the business would experience it
- Treat crisis management and identity recovery as inseparable
- Where Semperis fits as a trusted advisor
- Boards must validate identity recovery now
- Related resources
In June 2026, the Australian Signals Directorate posted an announcement of a Joint Statement from the Five Eyes cyber security agencies. The post, linking directly to the full statement, summarizes the urgency of the Australian Government’s position on cyber resilience:
AI is accelerating the speed, scale, and sophistication of cyber threats–faster than most organisations are prepared for. With the potential this raises not only for operational disruption, but financial loss and reputational damage as well, the message is clear: cyber resilience is now a core business risk, not just an IT issue. Organisational leaders are urged to act now.
Source: Australian Signals Directorate via LinkedIn
These messages provide a focal point, distilling and validating the intense stressors on enterprise leaders and security practitioners I work with every day across Australia and New Zealand.
Behind the urgent message is a real and present risk that’s growing exponentially. For years, global cybersecurity leaders have emphasized embracing the “assume breach” mindset for cyber defense. Now, it’s clear that defensive measures, while still critical, aren’t enough. Organizations must be poised to respond and recover from attacks faster—even those that they can’t fully anticipate.
AI has changed the face of the attack surface. It has changed how attackers advance and how we defend our systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and incident response and recovery.
TL;DR: Key takeaways for security and business leaders
- AI is compressing cyber timelines and making stale assumptions dangerous.
- The Five Eyes agencies have made cyber resilience a Board-level leadership issue, not just an IT issue.
- For most enterprises, identity resilience is central to cyber resilience because Active Directory and hybrid identity underpin business operations and recovery.
- Backup alone is not enough. Organizations must prove they can recover AD to a known-clean state within a realistic business RTO.
- The strongest programs treat identity protection, clean recovery, and crisis management as one discipline rather than separate projects.
How AI adoption is accelerating cyber risk now
Enterprise organizations across Australia (like their counterparts around the world) tell me they are squeezed between the opportunities and the threats of AI. According to Semperis research, their experience is all too common—and it means that organizations are giving AI agents direct access to critical systems faster than they can erect adequate guardrails.
In the study The State of Identity Security in the AI Era, I discovered that respondents from Australian organizations confirmed:
- 37% of their workforce has AI installed on local machines where it can access SSH and encryption keys.
- 24% of organizations already use AI agents to handle security-related help desk tickets, including password resets and VPN access.
At the same time that they are accelerating adoption of AI agents, those study respondents recognize that adding agent identities vastly increases the identity attack surface.
- 80% of Australian respondents expect that AI will make identity attacks more frequent.
- 65% expect that attackers will use AI to target their identity infrastructure.
The regional statistics I found in the Semperis study closely mirror the reports from all global regions. This is a worldwide problem.
When Boards ask whether the organization is ready for an AI-accelerated cyberattack, many teams answer with a list of controls: multifactor authentication (MFA), endpoint detection and response (EDR), backup, patching, monitoring, tabletop exercises. Those all matter.
But the reality is that only 21% of Australian organizations—and just 32% of organizations worldwide—believe they could regain control if an AI agent exposed admin credentials.
The Five Eyes cyber security agencies statement raises the bar. The message is not simply that organizations should strengthen defense. It is that leaders must assume cyber risk assumptions can become outdated in months or even weeks—and that resilience must hold up under pressure during a real incident.
That’s an uncomfortable standard. Many enterprises have never truly validated whether they can recover identity systems quickly and cleanly after a compromise.
And because identity is the business control plane, that gap is not a technical footnote. It is a business risk with operational, financial, and reputational consequences.
Why the Five Eyes AI warning matters now
The Five Eyes agencies were brief and direct in their warning statement. AI is already lowering barriers for malicious actors, increasing the speed and complexity of attacks, and shrinking the window between vulnerability discovery and exploitation specific to identity.
At the same time, they argue that cyber resilience is no longer a purely technical concern. It is a leadership responsibility tied to operational continuity, market confidence, and long-term value.
That framing and specification should matter to every CISO, IAM leader, Active Directory and hybrid identity administrator, SecOps leader, and enterprise architect. It changes the question from “Do we have controls?” to “Can we prove those controls will perform during a real incident when identity is under attack?”
For most enterprises, the proof of resilience lies with identity recovery. As Semperis notes, the identity system is involved in most cyber incidents, and in most organizations that identity system is a hybrid environment anchored by Active Directory and Entra ID.
The challenge Boards often miss: Identity is both a target and a dependency
Security leaders have spent years explaining that Active Directory is critical infrastructure. But the Five Eyes statement gives that argument new urgency because AI compresses the time available to detect, decide, and respond.
The problem is not only that attackers target identity. It’s that the rest of the organization depends on identity to function. When identity is down, email, conferencing, file access, SaaS access, operational workflows, and even crisis coordination can fail with it.
That creates a compound risk:
- Identity is a high-value attack surface.
- Identity enables lateral movement and privilege escalation.
- Identity is also the system the business needs to recover everything else.
This is why Boards should not treat Active Directory recovery as just another backup exercise. AD is a multi-master, replicated database with strict recovery requirements, and recovering it incorrectly can extend downtime, reintroduce attacker persistence, or force teams to start over.
Why AI makes the identity recovery question more urgent
The Five Eyes guidance does not say AI changes every cyber principle. In fact, much of the advice is foundational: reduce exposure, accelerate patching, retire legacy systems, strengthen identity, and access controls, assume breaches will occur, and test response plans in advance.
What AI changes is the pace and scale at which vulnerabilities can be found and exploited. That means longstanding assumptions such as “we will have time to investigate,” “we can clean it up manually,” or “our backup is probably enough” become harder to defend.
For identity teams, the key implication is this: recovery readiness must be treated as a living capability, not a static document. If attackers can move faster, organizations need to know in advance:
- How long it takes to recover AD to a known-good state
- Whether backups are clean
- Whether privileged access paths have been understood and reduced
- Whether crisis communications and decision-making can continue if identity-dependent tools fail
Those are Board-level questions because they determine whether a cyber incident becomes a contained disruption or a prolonged business crisis.
The gap between backup and true identity resilience
One of the most important distinctions in identity resilience is the difference between having a backup and being able to recover to a trusted state.
Semperis makes this point clearly: recovery is the outcome that matters, not backup alone.
Anyone can claim to have backed up Active Directory. The harder question is whether the organization can recover it in a way that restores enough trusted identity capacity to support minimum viable company (MVC) operations within the required timeframe.
That distinction matters because compromised identity systems are not compromised in only one way. Attackers may compromise the operating systems hosting AD, but they may also create persistence inside the AD database itself through privileged accounts, permissions changes, rogue memberships, or other backdoors. Restoring the wrong backup too quickly can simply reintroduce the attacker’s foothold.
This is where many resilience programs are still immature. They have backup policies. They may even have recovery runbooks. But they have not proven that identity can be restored cleanly, within a realistic recovery time objective (RTO), under the stress and confusion of an actual cyber crisis.
What Boards should ask management now
If the Five Eyes statement is a call to leadership, Boards need concrete questions to ask. Good ones include:
- Can we recover Active Directory to a known-clean state? Fast recovery is important, but clean recovery is more important. Leaders should ask how the organization verifies that the recovery point is trusted and that identity-layer persistence will not survive the restore.
- Have we tested recovery against our actual business RTO? An AD recovery target is only meaningful if it restores enough identity services to support the organization’s critical applications and business processes. Recovering one domain controller is not the same as restoring business operations.
- Do we know which identity exposures matter most? The Five Eyes guidance emphasizes foundational controls and reduced exposure. In practice, that includes understanding privileged paths, stale admin access, misconfigurations, delegation risk, and weak identity controls that attackers can chain together.
- Can the response team coordinate if identity-dependent systems are unavailable? A recovery plan that assumes email, file shares, and normal communications will still work during an identity outage is incomplete. Crisis management must function independently of the systems being recovered, with an out-of-band communication and coordination capability (such as Semperis Ready1) ensuring response teams can continue to collaborate throughout the incident.
- Have we validated this recently enough? If cyber risk assumptions can become outdated in months, then resilience validation can’t be a once-a-year checkbox. It needs to be rehearsed often enough to reflect current architecture, current dependencies, and current attack paths.
What practical readiness looks like
The good news in the Five Eyes statement is that the answer is not “buy more tools.”
The agencies explicitly point leaders back to fundamentals, disciplined execution, and deliberate use of AI to improve defense where it adds value.
For hybrid identity environments, practical readiness usually includes several actions.
Reduce identity attack paths
Strengthen privileged access, remove unnecessary exposure, review permissions regularly, and identify high-risk attack paths to Tier 0 assets before an adversary does.
Improve visibility into identity-specific behavior
General logging matters, but identity attacks often require AD-specific context to spot dangerous changes such as DCSync activity, Golden Ticket behavior, privileged group manipulation, or abuse of AdminSDHolder.
Test recovery the way the business would experience it
A meaningful recovery test validates whether identity services come back in the right order, with the right dependencies, at sufficient scale for critical operations. It also tests whether teams can execute under pressure and communicate effectively throughout the incident.
Treat crisis management and identity recovery as inseparable
Identity recovery is not just a technical restoration event. It is also an orchestration problem involving executives, legal teams, infrastructure teams, application owners, responders, and often external stakeholders. The organizations that manage both well recover faster and with less chaos.
Where Semperis fits as a trusted advisor
Semperis is most valuable in this conversation when the goal is not simply to sell a product but to help organizations close the gap between identity security plans and demonstrated identity resilience.
That can start with understanding exposure. Semperis has free and practical ways to baseline identity posture, including Purple Knight for assessing common weaknesses across AD, Entra ID, and Okta, and Forest Druid for identifying Tier 0 attack paths.
Semperis’ expertise also extends to response and recovery. Their Identity Forensics and Incident Response (IFIR) teams emphasize that recovery that restores AD to a malware-free, trusted state rather than simply bringing services back online. Recovery planning is paired with crisis coordination that remains available even when identity-dependent systems are not.
That positioning matters because it aligns with the Five Eyes guidance. The strategic need is not more fear. It is more proof—that foundational controls are effective, that identity can recover cleanly, and that the organization can operate through the incident rather than improvising in the middle of it.
Boards must validate identity recovery now
The most important challenge raised by the Five Eyes statement is not determining whether AI will change cyber risk. It already has.
Now leadership teams must validate the one capability that will matter most when identity is compromised: the ability to recover AD quickly, cleanly, and with enough control to keep the business moving.
Boards don’t need another abstract assurance that “we have controls in place.” They need evidence that identity resilience works under pressure. Organizations that can provide that evidence will be better prepared not just to survive AI-accelerated threats, but to maintain trust when the test comes.
Related resources
Five Eyes cyber security agencies statement | Cyber.gov.au
The State of Identity Security in the AI Era
Introducing AI Agents to your Identity Fabric
Identity Recovery & Crisis Management: Inseparable for Incident Response
Rethinking Cyber Crisis Management: Why Plans Fail
Top Manual AD Forest Recovery Pitfalls
Minimum Viable Company: True Cyber Resilience Starts with Identity
Checklist: Prepare Your Identity Fabric for the Agentic Era
