AI is already changing how we work. It is also changing how we are attacked.
That is why OpenAI’s open letter “A call for collective action on cyber defense” is worth reading carefully. It is signed by Google, Microsoft, Amazon, Anthropic, CrowdStrike, Cisco and more than a hundred other companies — banks, telecoms, and security vendors among them.
The argument is simple and uncomfortable. We have a limited window to strengthen defenses. In the coming months, AI-enabled attacks will become more widespread and more sophisticated as models around the world get more capable. At risk are the companies and public services communities depend on: hospitals, water systems, the infrastructure of the internet.
The same AI advances already give defenders new ways to close weaknesses that have accumulated for years. If we act now, that window can still belong to defense rather than offense.
What the letter actually says
The authors are not announcing a brand-new threat. They are naming a change of scale.
Status-quo security is no longer enough. Longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication, and technical debt in legacy systems have left too much exposed. Security teams — especially in critical infrastructure — have been under-resourced for years.
Second: put cyber-capable AI in the hands of more defenders. Models can make core security work faster, cheaper, and better — finding weaknesses, verifying fixes, and raising the floor where there is no large SOC.
Third: no single company should control the future of cyber defense. A collective response is required — sharing tools, verified fixes, threat intelligence, and playbooks that actually work.
Fourth: this is no longer an “IT ticket.” The letter tells every organization’s leaders to treat cyber defense as a leadership priority, with the urgency of an incident that outranks everything except keeping essential operations running.
Why this is not theoretical for Ukraine
For much of the world, the letter is a warning about the near future. For Ukraine, it describes an escalation of what is already happening.
Our companies and public institutions already live under sustained cyber pressure. Add a war, a shortage of people, legacy systems, improvised infrastructure, and the fast adoption of AI at work without matching controls. AI-generated code is already landing in production. Phishing is more personal. Supply-chain attacks are cheaper.
If global players say the defenders’ window is measured in months, Ukrainian companies cannot wait for “when we have a cybersecurity budget.” The budget may never arrive. The window will still close.
I see this in the businesses I run and in the ones around them: security is still too often treated as a request to IT, not as a condition of survival. That mistake will cost more, under AI-enabled attacks, than any transformation project.
How Ukrainian companies should prepare
Not a three-year program. The next moves you can make without waiting for a large integrator.
1. Make cyber defense a leadership decision, not an IT ticket
Name one owner with real authority. Put security on the agenda of owners and boards. Measure whether the highest-risk holes are closed and whether you can recover after a hit — not how many policies you have written.
2. See what you actually have
You cannot defend what you cannot see. Inventory systems, access, cloud, email, VPNs, backups, and the things that “have been running since 2018.” For energy, municipalities, and industry, that includes OT and field equipment. A blind network is no longer a metaphor.
3. Fix the highest risk first, not everything at once
Multi-factor authentication everywhere people log in. No shared admin passwords. Least privilege. Network segmentation. Backups someone has actually restored, not merely “we have them.” Patches on critical systems. Where a system cannot be patched without stopping a service, apply compensating controls — and verify them, instead of putting them in a slide deck.
4. Raise the bar for what you buy, write, and deploy — including AI-generated code
The letter is explicit: AI-generated code cannot go to production as a black box. Review it as strictly as a junior engineer’s work. The same applies to new SaaS, integrations, and “quick automations.” Speed of execution is an advantage. Speed without access control is a gift to the attacker.
5. Give AI to defenders, not only to sales and marketing
If the team already uses models to write emails and code, those same tools should help find vulnerabilities, read logs, check configs, and rehearse incident response. For small and mid-size companies this is often the only way to get expertise they cannot hire. Use capable lower-cost models for broad coverage, and frontier capabilities for the hardest problems.
6. Prepare collectively
A Ukrainian SMB will not win a race against sponsored attackers alone. Share indicators with CERT-UA, industry groups, IT clusters, and business councils. Ask vendors for patches and guidance, not NDA silence. Measure progress by how many organizations are protected and how fast an attack is contained — not by how many meetings you held.
7. Rehearse recovery, not only the perimeter
The question is not whether an incident will happen. It is how many hours it takes to bring critical services back, who decides at 3 a.m., and whether you have an offline plan for the moment email and messengers are no longer yours.
The window will not wait until we “mature”
The OpenAI letter is not a cybersecurity marketing campaign. It is an admission that attack is getting cheaper faster than conventional defense can get smarter and better staffed.
Ukrainian companies do not need a Silicon Valley gold standard. They need clarity, speed, and systems instead of heroic night-shift admins. See the assets. Close the most dangerous gaps. Verify the fix. Share what worked.
The original call is here: openai.com/collective-cyberdefense.