Back to Basics (For Now)
9-14-2026 (Monday)
Hello, and welcome to The Intentional Brief - your weekly video update on the one big thing in cybersecurity for middle market companies, their investors, and executive teams.
I’m your host, Shay Colson, Managing Partner at Intentional Cybersecurity, and you can find us online at intentionalcyber.com.
Today is Monday, September 14, 2026, and the Strait of Hormuz is still closed.
There’s been a ton of hand-wringing the past week about the existential threat that AI may or may not pose, depending on which article you’re reading.
There was also a good bit of activity - including this bulletin from CISA, a Threat Intelligence Report from Google, and Reuters coverage accusing Chinese AI companies of “malicious copying” of American AI models in a mechanic called distillation.
Not to be confused with this bit from Anthropic’s September threat report where Chinese company Moonshot AI was literally just forwarding user input to Claude, but presenting it as if they were using a Kimi model.
I’m going to let all of that settle for a week and focus on a few of the more tactical things that I think you should be worrying about in the meantime.
Back to Basics (For Now)
Last week, there was reporting about the FBI’s new cyber strategy, which is centered around a “focus on cyber basics” - and I couldn’t agree more.
The strategy itself has been published, and you should give it a read if you’re curious, but the focus on basics is encouraging.
We saw last week a rash of news items about how attackers are leveraging AI tools to accelerate the rate at which they can deploy relatively basic attacks, mostly targeting your users, including:
Hackers Send 1 Million AI-Assisted CEO Impersonation Emails in Invoice Fraud Campaign;
The return of the Shai-Hulud campaign targeting supply chain vulnerabilities.
None of these attacks are particularly sophisticated, and all of them can be carried out without the use of artificial intelligence, but what AI gives these attackers is speed and scale.
Are you getting speed and scale on our defenses? Have you deployed the controls and architecture that help reduce your attack surface, role out least-privilege and roll-based access across the enterprise, and have robust audit logs widely deployed so that you can see what is or isn’t happening in your environment?
If not, please go focus on those things in the days and weeks ahead, instead of new AI tools or worries that may or may not even come to pass, much less add value to your business.
Microsoft has a great write-up on how you can protect your organization and what to look out for that’s specific to some of these attacks, but gives you coverage against many other types, as well.
If your goal is to protect your company in an AI age, these are the sorts of things you should be spending your very limited time, energy, and resources on.
Fundraising
From a fundraising perspective, we’re still humming along, with nearly $33B in newly committed capital announced last week, led by:
ICG raised €12b for its ninth structured capital fund; and
Permira raised €9.4b in a first close for its ninth flagship fund, which is targeting €17b, per the WSJ.
Anthropic seems on track to IPO this year, but we’ll see how all this slow down talk, especially as we head into the midterm election season here in the US comes together. It feels like we’re in for quite a bumpy ride to the end of the year from here, folks.
A reminder that you can find links to all the articles we covered below, find back issues of these videos and the written transcripts at intentionalcyber.com.
We’ll see you next week for another edition of the Intentional Brief.
Links
https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
https://www.anthropic.com/threat-intelligence-report-september-2026
https://hormuzstraitmonitor.com
https://www.fbi.gov/investigate/cyber/cyber-strategy
https://cyberpress.org/ai-ceo-invoice-fraud/
https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign