We have met the enemy and he is us

We are finding ourselves in a place where we are using technology but basically lack the expertise to use it safely.

Effective use of IT has been on the wane for many years, with many IT projects not meeting their budgets, schedule or quality objectives. 

We are struggling keeping the cyber crims outside the door and now there is AI.

AI is being used to attack and defend IT systems and data. It is being embraced without the adequate governance, discipline or oversight needed for such a powerful tool. And it will become immensely more powerful. 

Organisations need to take stock of how staff are using AI and management must implement policies that set the guardrails for its use. The IT management, operational risk, cybersecurity and business continuity functions must quickly improve their knowledge and skills to address the opportunities and risks presented by AI.  

Below are a few very recent examples where IT management and governance have spectacularly failed.

Ineffective identity management

The latest IBM Cost of Data Breach report found that 92% of organisations that experienced an AI-related breach, lacked proper access controls for their AI systems, with only 40% of organisations reporting using access controls on models. 

See page 7 - https://www.ibm.com/forms/mkt-whitepaper-90d12

Effective identity management has been a fundamental requirement for many years, yet AI-enabled cyberattacks are now exploiting this longstanding IT weakness.

Ineffective IT Management

On 8 July 2026, Telstra’s national mobile network collapsed after a faulty software update reset a GPS‑based Network Time Protocol server back to 2006. That single failure corrupted the clock that synchronises signalling, authentication and routing across the entire Telstra mobile network in Australia. Telstra had been warned of this vulnerability a number of times but failed to act.

As bad timestamps rippled through the system, network nodes fell out of sync, triggering a nationwide shutdown of voice, data and signalling. In addition, Victorian V/Line train services were disrupted for days afterwards. 

Another IT Management failure

At the end of July, two major AI companies, OpenAI and Anthropic, encountered problems while testing their most advanced AI systems. These systems were meant to be tested safely in a sandbox, but they ended up reaching the live internet and impacting real companies. There was no air gap! 

OpenAI’s agents spent days in Huggins Face’s infrastructure (Huggins is the open repository at the centre of the global model AI economy). It took the FBI to detect the intruders!

As Cyber News concludes in its excellent article (see below): 

“AI safety is no longer confined to speculative debates about what models might do in the future. The systems are already interacting with real networks, real credentials and real companies during the process meant to prove they are safe.”

https://www.cybernewscentre.com/ai-cyber-update-the-month-the-sandboxes-cracked/

We need to get better at managing IT! The hype and speed of the AI boom should cause us to be much more cautious about its use. Let’s act now so we really don’t end up being the enemy.

Next
Next

Crisis Indecision