The rules just changed
Updated: Aug 15
Over the weekend, I listened to an interesting cyber security podcast (Steve Gibson’s ‘Security Now!’), discussing Anthropic’s new AI model “Mythos” and its ability to identify previously unknown software vulnerabilities at a scale and speed we simply haven’t seen before.
What struck me wasn’t the usual “AI will change everything” narrative, which is probably a bit of a boring read for people here now. This was something that really needs everyone's attention.
For years, much of the technology industry, and their customers, has operated with a degree of accepted imperfection:
Software gets shipped quickly to meet demand
Humans are expected to uncover issues
Vulnerabilities get patched later
Now imagine what happens when AI becomes exceptionally good at reviewing software code, identifying weaknesses and developing exploits faster than humans can respond.
One example discussed in the podcast was a critical vulnerability that Mythos reportedly identified in a widely used encryption library called wolfSSL, which is said to protect BILLIONS of devices worldwide. The concern wasn’t just the vulnerability itself. It was that something quite fundamental, related to certificate validation checks, had remained undiscovered for so long.
I think many organisations may still be underestimating what’s coming.
The real issue is not simply that AI can help attackers. It’s that AI may expose just how much hidden technical debt, weak governance and operational fragility exists beneath the surface.
In many organisations today:
Legacy systems are often unsupported
Patch cycles are still fairly inconsistent
Supplier assurance remains weak
AI governance is still fairly immature (I’m personally trying to change that!)
Cyber security still competes with short term delivery pressures
One of the most sobering examples discussed was how rapidly the gap between vulnerability disclosure and active exploitation is collapsing. In 2018, organisations typically had an average of 2.3 YEARS before newly disclosed vulnerabilities were actively exploited. Today, that window has reportedly fallen to around 10 HOURS.
That fundamentally changes the operating model for those responsible for cyber security. Patching cycles, governance processes and risk management approaches haven’t been designed for a world where machine-speed attacks can emerge within hours of disclosure. That needs to change …. and fast.
Ironically, while this may ultimately improve security standards across the industry, the transition period could be uncomfortable for organisations that havent invested sufficiently in resilience, governance and operational discipline.
We are entering a world where the gap between vulnerability discovery and catastrophic business impact may be measured in hours, not months. That should trigger serious discussion and meaningful action to reduce the risk.


Comments