Cybersecurity has spent years being treated as something organizations could largely handle on their own.
Buy the right technology. Patch the systems. Train the employees. Protect the network.
Those things still matter.
But the environment around us is changing quickly, particularly as artificial intelligence increases what both attackers and defenders can do.
That is why MTS Consulting Group has signed an open letter calling for greater collective action on cyber defense.
The letter, published by OpenAI and supported by organizations across technology, cybersecurity, financial services, government, and other sectors, begins with a straightforward warning:
“We have a limited window to strengthen cyber defenses.”
OpenAI argues that increasingly capable AI systems are likely to make AI-enabled cyberattacks more widespread and sophisticated. At the same time, those same advances can give defenders new ways to identify vulnerabilities, improve security tools, test defenses, and fix weaknesses faster.
That creates an important question for every business and nonprofit leader:
Are we using this moment to become better prepared, or are we simply waiting to see what happens next?
The Problem Is Bigger Than AI
It would be easy to read this letter and conclude that it is primarily about artificial intelligence.
We believe there is a larger lesson.
Many of the vulnerabilities organizations face today are not new.
The letter specifically points to longstanding problems such as:
- Excessive permissions
- Misconfigurations
- Unpatched or insecure software
- Weak authentication
- Legacy systems
- Accumulated technical debt
AI did not create these weaknesses.
What AI can change is the speed and scale at which weaknesses can potentially be discovered and exploited.
That distinction matters.
The question is no longer simply, “Do we have cybersecurity?”
A more useful question is:
“Do we actually understand where our greatest risks are today, and have we verified that the protections we depend on are working?”
That is a very different conversation.
Cybersecurity Must Become a Leadership Conversation
One of the strongest recommendations in the open letter is directed not at cybersecurity companies or IT departments, but at every organization.
The letter calls on organizations to make cyber defense an immediate leadership priority, address the highest-risk weaknesses, verify that fixes actually work, strengthen access controls, and raise security expectations for the technology they purchase and deploy.
That does not mean every executive needs to become a cybersecurity expert.
They should not have to.
But leaders do need enough clarity to make responsible decisions.
They should understand:
What information does our organization depend on?
What would happen if we lost access to our systems?
Who has access to sensitive information?
Where are our largest vulnerabilities?
Which risks could create the greatest operational, financial, legal, regulatory, or reputational consequences?
Are the controls we believe are protecting us actually working?
Those questions are part of understanding cyber liability, not simply buying cybersecurity technology.
Cyber liability is the broader exposure an organization carries because of its responsibilities for systems, data, employees, clients, donors, customers, vendors, and other stakeholders.
Technology is part of the answer.
Understanding the risk has to come first.
Why Collective Defense Matters
There is another important idea in this letter that deserves more attention.
No organization sees the entire threat landscape.
One security company may discover a new attack pattern.
Another may identify a vulnerability.
A technology provider may develop a fix.
An organization may learn something important during an incident.
A researcher may discover that a commonly accepted defense is no longer sufficient.
If those lessons remain isolated, everyone else has to learn them again.
Collective defense changes that equation.
OpenAI's proposal calls for organizations, cybersecurity providers, governments, technology companies, and AI companies to share threat intelligence, tested approaches, defensive tools, and verified fixes so that what one defender learns can help others become better protected.
That does not eliminate cyber risk.
It improves our ability to understand and respond to it.
And that is one reason MTS chose to sign the letter.
Why MTS Signed
Our decision was not based on the idea that one company, technology, AI model, or security provider can solve cybersecurity.
We signed because we believe good security starts with something more fundamental:
Clarity.
Before an organization can make good decisions, leaders need an honest picture of where they stand.
Then they need to understand the risks.
Then they can prioritize.
Then they can act.
And after action is taken, the results should be verified.
That philosophy is also why we believe independent assessment matters. Organizations should have access to evidence that helps them understand what vulnerabilities exist today, including whether the security solutions already in place are accomplishing what everyone expects them to accomplish.
Security should not begin with:
“What should we buy?”
It should begin with:
“What do we need to understand?”
AI Changes Both Sides of the Equation
There is an understandable amount of concern about how cybercriminals may use artificial intelligence.
That concern is legitimate.
But AI is not exclusively an offensive technology.
The same capabilities can help defenders analyze information, investigate suspicious activity, identify weaknesses, test systems, automate repetitive security work, and potentially respond to threats more quickly.
The OpenAI letter specifically calls for putting cyber-capable AI into the hands of defenders and expanding access to defensive capabilities, particularly for organizations protecting critical services or operating with limited security resources.
For smaller organizations, this may become especially important.
A 25-person nonprofit cannot build the same internal security organization as a global corporation.
A 20-person accounting firm cannot employ dozens of specialized security analysts.
But smaller organizations still handle sensitive information.
They still depend on technology.
They still have responsibilities to employees, clients, donors, customers, and their communities.
AI could help narrow some of that capability gap.
But only if it is implemented securely, intentionally, and with appropriate oversight.
Five Questions Leaders Should Be Asking Right Now
You do not need to wait for the next major cyber incident or the next generation of AI threats to begin improving your organization's position.
Start with five questions:
1. Do we have an objective picture of our current cyber risk?
Not what we believe is protected. What does the evidence show?
2. Which weaknesses could create the greatest business impact?
Every vulnerability is not equally important.
3. Have our most important security controls been independently tested or verified?
Installing a control and confirming its effectiveness are two different things.
4. Do we know how AI is already being used inside our organization?
Employees may be adopting AI faster than leadership realizes.
5. If the threat environment changes quickly, who helps us understand what has changed?
Cybersecurity cannot be a once-a-year conversation.
Preparation and Knowledge Matter
There is a simple principle we return to often at MTS:
Preparation and knowledge are key.
You do not want to discover your largest vulnerabilities during an attack.
You do not want to create an incident response plan while an incident is already underway.
And you do not want the first meaningful conversation about cyber liability to happen after something has gone wrong.
The opportunity in front of organizations today is to create clarity before the crisis.
That is ultimately what we believe this call for collective cyber defense is about.
Not fear.
Not another product.
Not the idea that every organization must become a cybersecurity company.
It is about recognizing that the environment is changing, sharing what defenders are learning, understanding the risks we already carry, strengthening the weaknesses we already know about, and using new technology responsibly to improve our defenses.
Start the Conversation
We encourage business and nonprofit leaders to read OpenAI's Call for Collective Action on Cyber Defense and discuss it with their leadership and technology teams.
Ask:
What would this mean for our organization?
What risks are we already carrying that we may not fully understand?
What are we assuming is protected that we have never actually verified?
Those are worthwhile conversations whether you work with MTS or not.
If the letter accomplishes one thing, we hope it encourages more organizations to have those conversations before the crisis hits.
MTS Consulting Group is proud to add our voice to that effort.
Your Beacon in the Cyber Storm.
Learn More
Read OpenAI's full Call for Collective Action on Cyber Defense and the principles behind the initiative. Read the OpenAI open letter
If your leadership team would like greater clarity about the risks that may already exist within your environment, you can also learn about the Independent Cyber Risk Assessment available through MTS.
The assessment is performed by the independent security company that helps evaluate and monitor MTS's own security. That company is not affiliated with MTS and, as a courtesy, makes a limited number of independent assessments available to MTS clients and prospective clients each month.
Its purpose is simple: provide evidence that helps leaders understand what vulnerabilities exist today, including an independent look at whether existing protections are working as intended.


