ai · security · skills

Perspective · for the CISO

Mythos changed the tempo, not the rules.

In 2026, Anthropic reported that Claude Mythos identified thousands of zero-days across major operating systems and browsers and chained them into exploit paths; the UK AI Security Institute found it could autonomously attack weakly defended systems. The vulnerabilities were always there. What changed is speed, volume, and autonomy.

Drowning in findings
volume & speed — weeks of work now takes hours
Machine-tempo attacks
autonomous pressure on weakly defended systems
Fundamentals exposed
legacy & OT: decades-old flaws surface fastest
Response under strain
the human tempo can’t keep up alone
Public reporting: CSO Online · UK AISI · Bain · Computer Weekly · TechTarget · GovTech · ArmorCode. No numbers of our own.

None of the four is new in kind. The rupture is that they all arrived at machine speed at once.

The tension

You must adopt the same frontier capability defensively — before adversaries weaponise it — while governing that adoption. Too slow, you’re outpaced; ungoverned, you’ve imported the risk yourself.

“Never mind how scary it is — what concretely changes in my program on Monday?”

The answer

Each challenge already maps to something the framework measures and moves.

Not a coincidence — Mythos is the rupture this practice was built for. Four challenges, four answers already in the app.

Drowning in findings

volume & speed — weeks of work now takes hours

The vulnerability-prioritization play

KPI: critical-backlog age; AI ranking + deterministic routing, measured before/after.

Machine-tempo attacks

autonomous pressure on weakly defended systems

The adopt axis, gated

Triage & detection plays raise autonomy — the gate blocks any that outruns its controls.

Fundamentals exposed

legacy & OT: decades-old flaws surface fastest

The Inheritance Stack

AI capability graded as a net addition, bounded by the ISMS/cloud/privacy foundation beneath it.

Response under strain

the human tempo can’t keep up alone

The People dimension

Capability = weakest of People/Process/Technology. Tooling-only reads as L1.

The mappings are our editorial judgment, labelled as such — any maturity reading stays self-assessed until evidenced on your own work.

The lesson, in one line

“Adoption stopped being optional and governance stopped being deferrable — on the same day.”

That’s the whole board conversation: move fast on AI defence, and prove the gate holds while you do it. The scorecard reads both at once.

See the board scorecard →The threats, in plain English
← Back to Insights

Subscribe for the next essay.