Pierre Le Calvez

Pierre Le Calvez

Vice-President, Consulting Services, Canada

Across CGI’s client base, three distinct cybersecurity postures are emerging in response to frontier AI cyber capabilities such as Anthropic’s Claude Mythos and Fable, as well as OpenAI’s GPT-5.5 Cyber. Each is valid, but each requires a different course of action.

Before diving in, it’s helpful to establish some context. CGI’s Chief Security Officer Ray Daoud’s recent blog, Defending at the speed of frontier AI: The new test of operational discipline, explores the strategic implications of frontier AI for cybersecurity: what has changed, what remains the same, and where the primary bottleneck now lies.

In essence, Ray describes that the “battle-tested cybersecurity playbook” still applies, but the response window has narrowed. The U.S. government’s June 12 suspension of Fable 5 and Mythos 5 on national security grounds made that compression visible in real time. The models were shut down in less than two hours, and organizations that had built automated workflows on Fable 5 lost a critical engine the same afternoon it was withdrawn.

Three postures, one cybersecurity imperative

That’s the operational reality this blog addresses. As a practical companion to Ray’s analysis, the below outlines the actions organizations can take over the next 60 days.

Crisis response : “We need to act now.”

Some organizations, particularly those operating critical infrastructure, mobilized dedicated response teams, accelerated supplier reviews, and called for 30-day action plans within days.

One large North American energy company assembled a 50- to 60-person team across 7 parallel workstreams: attack surface reduction, identity management and the start of the Zero Trust journey, vulnerability and patch management, secure development pipelines, third-party risk, anomaly detection, and AI-driven risk scoring. The effort was intensive, but the value was clear: a coordinated response spanning people, technology and the broader ecosystem.

Analysis : “We need to understand the implications.”

These organizations are focused on separating signal from noise, testing assumptions, and establishing a roadmap before committing to action.

A structured diagnostic across people, processes, and technology can provide that clarity. By assessing risk posture, patch and remediation management, assets and attack surfaces, identity governance, and AI security readiness, organizations can gain a clear view of their preparedness and define a practical plan for closing the gaps that matter most.

Wait and see : “We will address it later.”

The risk may not be on the board’s agenda yet, but it’s already making its presence felt. The shutdown of Fable 5 landed in CISOs’ inboxes everywhere, whether frontier AI risk had already become an executive priority.

A one-hour leadership workshop and a one-page executive briefing remain the right starting points, but the context has changed. This is no longer a risk on the horizon; it’s already here.

Whatever the posture, the imperative is the same: respond with clarity and urgency, avoiding both panic and complacency.

Five actions to take in the next 60 days to strengthen your cybersecurity posture

work team around a table

The right starting point will vary by posture, but these 5 actions can strengthen cyber preparedness and resilience over the next 60 days.

  1. Reduce the attack surface. Remove, isolate, or segment outdated, exposed, or unnecessary systems. Prioritize internet-facing assets, legacy platforms, and critical dependencies.


  2. Stress-test patching under pressure. Run a tabletop exercise in which three to five critical vulnerabilities emerge in the same week. The constraint is rarely detection; it’s decision-making, prioritization, and coordination.

  3. Map exposure across the ecosystem. Identify where suppliers, open-source components, AI tools, agents, and data flows introduce risk. Prioritize access controls, accountability, and governance.

  4. Strengthen identity and fraud controls. Expand phishing-resistant multifactor authentication, eliminate persistent privileges, and prepare response playbooks for deepfakes, vishing, and synthetic identity abuse.

  5. Pilot defensive AI in controlled use cases. Apply AI to code review, CI/CD checks, vulnerability triage, and remediation support while retaining human oversight and clear accountability.

Four actions to avoid in your ongoing cybersecurity preparedness

Laptop på skrivbord visar kerativt uppsatt kod

The next 60 days are as much about avoiding costly missteps as they are about accelerating the right actions. Here are four actions to avoid:

  1. Don’t build critical workflows around a single frontier model without a documented fallback. The June 12 shutdown of Fable 5 disrupted every automated pipeline that depended on it—not gradually or with a migration window, but immediately. Design for continuity through alternative models, manual procedures, and tested failover plans.


  2. Don’t rush to purchase a new AI-native platform. The market is likely to evolve significantly over the next 12 months. Start by assessing where AI can add value within existing tools and workflows before introducing another platform.

  3. Don’t become overly dependent on one AI vendor or model. There’s no consistently dominant model for cybersecurity, and independent benchmarks change frequently. Flexible pipelines that route tasks to the most appropriate model are more resilient than those locked into a single option.

  4. Don’t create a new program when an existing one can be strengthened. Most organizations don’t need another initiative. They need to operate vulnerability management, identity, and incident response programs at greater speed, supported by surge capacity and pre-authorized playbooks.

A note on legacy systems and technical debt

Many enterprises have systems that are difficult to secure for legitimate business reasons: legacy applications, lightly maintained integrations, end-of-life platforms that still support revenue, and suppliers operating infrastructure they can’t readily replace. These have long been the most challenging elements of vulnerability management. Frontier AI is now changing the risk calculus around that technical debt by shortening the time in which organizations must identify, assess, and address exposure.

The UK Cyber Security Centre’s CTO Ollie Whitehouse has described the period ahead as a “tsunami of patches addressing decades of technical debt.” That characterization reflects what CGI is seeing across critical infrastructure, financial services, and government. The answer isn’t an immediate, enterprise-wide modernization effort. It’s to identify the legacy systems where high exposure, business criticality, and slow remediation converge, then apply targeted compensating controls, including segmentation, configuration changes, tighter access restrictions, enhanced monitoring, and documented risk acceptance, while defining a longer-term modernization path.

For many organizations, this is where executive sponsorship matters most. Technical debt decisions that may have been acceptable in 2024 are becoming increasingly difficult to justify in 2026.

Where to start

If you’d like to discuss where your organization sits across these three postures, or how to translate any of the actions above into a defined engagement, our cybersecurity practice helps clients across advisory, managed security services, AI governance, and secure delivery, please contact me to learn more. I also invite you to review the summary of how we help clients strengthen cyber resilience in the age of frontier AI: AI cybersecurity and cyber resilience in the age of frontier AI.

About this author

Pierre Le Calvez

Pierre Le Calvez

Vice-President, Consulting Services, Canada

Pierre Le Calvez is an accomplished cybersecurity executive with more than 20 years of experience in information technology, including more than 17 years focused on cybersecurity. As Vice-President, Consulting Services, he leads CGI’s national cybersecurity practice in Canada, overseeing a team of more than 85 ...