Operational Security Best Practices: How to Stay Protected in the Age of AI Attacks

Sign reads 'Trail not maintained beyond this point' against a blue, circuit-pattern background (warning that the trail ends).

There’s an old saying that it’s better to be lucky than good. When it comes to protecting your business from cyber threats, that’s a gamble worth retiring.

We prefer a different version: the harder you work, the luckier you get. In cybersecurity, the organisations that look lucky when a major threat makes the news are almost always the ones that invested in operational security best practices long before the headline appeared; unglamorous, consistent work that quietly removes risk before any alert is published.

How AI Has Changed the Cybersecurity Threat Landscape

AI has fundamentally changed the economics of a cyberattack. For years, the raw materials for a breach – old leaked credentials, previously disclosed vulnerabilities, forgotten accounts, unpatched devices – have been sitting in the open. What’s changed is that attackers can now use AI to comb through years of those exposures and test them against live networks at a speed and scale that simply wasn’t practical before.

The FortiBleed activity is a recent example. It wasn’t a single, novel zero-day. It was a systematic recycling of vulnerabilities and credential leaks that were already known and already disclosed – assembled by AI into a working attack against internet-accessible firewalls and VPN gateways. The materials were old. The method was new.

That pattern isn’t unique to one vendor or one product. It’s the shape of the modern threat landscape: the cost of patience has dropped to near zero for attackers, which means the margin for “we’ll get to it eventually” has narrowed considerably for everyone else.

Lucky or Prepared? The Real Difference in Cybersecurity

Here’s the encouraging part. For organisations that had been practising sound operational security, an event like FortiBleed wasn’t an emergency; it was a normal course of business. Review the controls, confirm everything was in order, and move on.

That isn’t luck. It’s the compounding return on consistent work. The teams that hadn’t done the work spent that same week in a fire drill. Same threat, very different week.

The difference comes down to a handful of disciplines that, done routinely, quietly remove most of the risk before any alert is published.

Operational Security Best Practices: The Fundamentals That Work

Operational security isn’t a product you buy. It’s a set of habits you keep. The ones that matter most:

Routine firmware updates.

The devices that run your network – firewalls, switches, access points – need firmware maintained on a schedule, not whenever someone remembers. Outdated firmware is one of the most common ways old vulnerabilities stay exploitable long after a fix exists. If your team discovered FortiBleed through the news rather than through a patch notification, that’s a gap worth closing.

Managed software patching.

Patching should run on a defined cadence and be verified, not assumed. “The update was available” and “the update is installed and the system rebooted” are very different things, and only one of them protects you.

Strong credential management.

Most modern attacks don’t break in, they log in. A business-wide password manager, enforced multifactor authentication (MFA) on every account that matters, and the elimination of generic or default logins close off the easiest path an attacker has. Credentials are the new perimeter; treat them that way.

A minimised attack surface.

Management interfaces shouldn’t be reachable from the public internet. Unnecessary accounts and services should be turned off. Every door you don’t need is one you don’t have to defend.

Routine review of controls.

Security configurations drift over time as people change roles, projects launch, and systems are added. A regular review – confirming that the controls you put in place are still in place and still working – is what keeps a strong posture from quietly eroding.

None of these are exotic. That’s precisely the point. They reward consistency, not cleverness.

Why Operational Security Is Your Best Defence Against AI-Powered Attacks

In an environment where attackers move at machine speed, disciplined operational security may be your single most effective defence – paired with AI-assisted detection and response that can spot and contain trouble at the same pace threats are moving. One side reduces how much can go wrong; the other shortens how long it takes to catch what does.

But tools and tactics only go so far without one more ingredient: treating IT security as a core business competency, with genuine leadership support behind it. Threats like FortiBleed don’t reward the organisations that bought the most software. They reward the ones that operate well, every day – and that takes leadership deciding security is worth doing properly.

Strengthening Your Operational Security With Go West IT

Insisting that security be a core competency doesn’t mean building all of it in-house. The execution and the guidance can be entrusted to a partner who does this work every day – keeping firmware and software current, managing credentials and access, hardening your platforms, and reviewing your controls so nothing drifts.

That’s where Go West IT comes in: helping you put the right fundamentals in place, keep them running, and turn the next industry-wide scramble into a routine exercise.

The harder you work on the fundamentals, the luckier you’ll look when the next threat comes around. We’d be glad to help you do that work.

If you’d like to review where your organisation stands on operational security, we’re here.

Further reading: CISA, “CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure” (June 2026)

Frequently Asked Questions About Operational Security

What is operational security in IT?

Operational security (OpSec) in an IT context refers to the ongoing discipline of maintaining controls that protect a business’s systems, data, and network. This includes routine practices such as firmware and software patching, credential management, MFA enforcement, minimising the attack surface, and regularly auditing that existing controls are still working. Unlike a one-time security audit, operational security is a set of continuous habits – the consistent work that reduces risk before a threat materialises.

What does the FortiBleed vulnerability mean for my business?

FortiBleed refers to a wave of attacks exploiting previously disclosed vulnerabilities in Fortinet devices – particularly firewalls and VPN gateways – combined with leaked credentials. Attackers used AI to systematically test known exposures against live networks. If your business uses Fortinet or similar edge devices and has not applied recent firmware updates or rotated credentials following prior disclosures, it is worth reviewing your posture. CISA published guidance in June 2026 specifically urging organisations to harden Fortinet devices and review credential exposure.

What is the single most important step I can take to improve my business’s cybersecurity right now?

If you’re starting from scratch, enforcing multifactor authentication (MFA) across all key accounts – email, remote access, admin portals – delivers the most immediate reduction in risk. Most successful breaches involve compromised credentials; MFA closes off that path even when a password is known. From there, a structured firmware and patching schedule, combined with a regular review of who has access to what, will address the majority of the remaining exposure.

The owner of this website has made a commitment to accessibility and inclusion, please report any problems that you encounter using the contact form on this website. This site uses the WP ADA Compliance Check plugin to enhance accessibility.