With the period closed, what remains usable for anyone operating systems isn't the billion-dollar figures, it's a short list running through every documented episode.
First: what the model reads is untrusted input. That covers error logs, web pages, incoming messages and documents sent by customers. An instruction written into a request is not access control.
Second: an agent needs its own identity, an explicit scope and credentials that expire. Inheriting the permissions of whoever configured it is how most of the period's incidents began.
Third: a barrier counts only after failing on purpose. Test with an invalid key, an expired token, an open door, and verify the alert fired and somebody answered.
Fourth: a single source is a risk, not a choice. That holds for memory, for cloud and for models, and the fallback has to be a different supplier, tested before it's needed.
None of this requires a large company's budget, and no new tool would have prevented any of the quarter's stories. All of them run through one of those four lines.
