Cyber Risk

What Anthropic's Mythos Reveals About Cyber Risk and Cyber Mythology

• 8 min read

Mind your CVEs, but remember: resilience still determines risk. AI may uncover vulnerabilities faster than ever, but resilience determines whether those vulnerabilities become material incidents.

What Does Anthropic’s Mythos Mean for Cyber Risk Management?

Cybersecurity practitioners have always worried about the next major technical leap that could tilt the balance in favor of attackers. Recently, that conversation has focused on Anthropic’s Mythos, an advanced AI model reportedly capable of identifying and exploiting previously unknown software vulnerabilities at a significantly increased rate and scale. Anthropic itself characterized Mythos as a potential “watershed moment” in cybersecurity and restricted access to a limited set of vetted organizations because of concerns about misuse.

For boards, executives, investors, insurers, and cyber risk professionals, Mythos raises an obvious question:

If AI can find vulnerabilities faster than humans can fix them, how should organizations measure and manage cyber risk?

The answer is as it has been all along, and that is to avoid fixating on vulnerabilities alone. Risk is more reliably measured by the broader factors that determine whether exploited vulnerabilities become material cyber incidents. That is where cyber resilience is increasingly important.

Why Mythos Matters for Cybersecurity and Cyber Risk

According to Anthropic, as well as many other independent observers and commentators, Mythos demonstrates a significant advancement in AI-assisted vulnerability discovery, exploit development, and automated attack techniques. The concern is not only that Mythos can discover vulnerabilities; security researchers have been using automation for years. Rather, the concern is that frontier AI systems may dramatically accelerate the discovery of previously unknown “zero-day” vulnerabilities while simultaneously lowering the cost of exploitation. This has the potential to create both technical and economic advantages for bad actors.

If these capabilities become widely available, organizations could face:

    • Faster discovery of exploitable weaknesses
    • Increasing volumes of vulnerabilities requiring remediation
    • Reduced attacker costs and increased attack automation
    • Greater pressure on already-stretched security teams
    • A widening gap between vulnerability discovery and remediation capabilities

Mythos represents a future in which attackers may achieve unprecedented efficiency in identifying and exploiting technical weaknesses and thereby overwhelm the defenders. However, this does not automatically translate into equivalent increases in successful cyber incidents.

The Mythology of Managing Cyber Vulnerabilities

One of the most important lessons emerging from the Mythos discussion is that cyber incidents are rarely caused by vulnerabilities alone. In fact, most of the Common Vulnerabilities and Exposures (CVEs) are never exploited, and Common Vulnerability Scoring System (CVSS) scores are generated in advance of any data about successful exploits. While frontier AI may mean that more of them are in the future, or that they are combined in unique and destructive ways, the degree to which an exploited vulnerability impacts an organization has more to do with organizational resilience than the characteristics of the vulnerability itself.

It is undoubtedly true that nearly every organization operates with vulnerabilities. Even before Mythos, security teams were already unable to remediate every discovered weakness. The challenge is not simply finding vulnerabilities; it’s managing exposure and maintaining resilience in the face of inevitable weaknesses.

Consider two firms facing a newly discovered zero-day vulnerability. Both organizations may be exposed. Yet one company may:

    • Maintain strong security governance
    • Minimize asset exposure
    • Operate with disciplined patch management processes
    • Monitor external attack surfaces continuously
    • Detect suspicious activity quickly
    • Contain incidents effectively
    • Maintain control of the incident narrative

The other organization may lack these capabilities.

When attackers exploit the same vulnerability, the outcomes can be dramatically different. This distinction is critical because Mythos may increase the number of vulnerabilities discovered, but resilience determines whether those vulnerabilities lead to significant operational, financial, regulatory, or reputational consequences. In short, if vulnerabilities are becoming more exploitable, companies need to ensure their assets are becoming less susceptible and that incident impacts are becoming more manageable.

Why CVE Metrics Are Poor Indicators of Cyber Risk

In response to concerns about AI-driven vulnerability discovery, many organizations instinctively focus on CVEs. Even prior to the buzz about Mythos, companies have already allowed CVE metrics (e.g., discovery rate, closure rate, etc.) to dominate management and board level reporting, and to distract them from higher-order efforts to improve resilience. CVE metrics might be a convenient way to articulate progress to non-technical stakeholders, but what do they really convey?

A count of vulnerabilities tells us relatively little about an organization’s overall cyber risk. The proof: thousands of companies undoubtedly have similar vulnerabilities, yet only a small number experience material breaches.

Executive stakeholders need answers to broader questions:

    • Is the company reducing attack surface exposure?
    • How are the most critical assets protected?
    • Are systems configured according to secure practices?
    • Does the organization demonstrate characteristics associated with lower breach likelihood?
    • Are we ready for the next incident when it happens?
    • How are we managing our liability exposure?
    • How are we doing compared with peer organizations?

These questions focus on resilience rather than vulnerability inventory. As AI accelerates vulnerability discovery, understanding resilience becomes even more valuable. This does not mean that organizations should stop caring about CVEs. Obviously, this is the wrong strategy; but it does mean that companies cannot afford to become obsessed with CVE metrics at the expense of efforts to measure and enhance their cyber resilience.

How the ISS Cyber Risk Score Measures Cyber Resilience

The ISS Cyber Risk Score was designed specifically to provide a broader, statistically-based view of forward-looking incident risk through the lens of cyber resilience.

Unlike approaches that focus primarily on enumerating vulnerabilities, the ISS Cyber Risk Score evaluates a wide range of observable indicators associated with asset exposure, adherence to best practice, situational awareness and responsiveness, and cyber resilience. The model is trained using historical cyber incident data and machine-learning techniques designed to identify patterns associated with future cyber events.

The methodology looks beyond CVE metrics because CVEs themselves are simply not good indicators of forward-looking risk.

Data-Driven and Predictive

The score is derived from large-scale cyber data collection, historical incident information, and machine-learning models that have been trained on organizations that have experienced cyber incidents, and those that have not. The objective is to calculate the likelihood of a material cyber incident rather than simply catalog technical findings.

Evaluation of Security Posture Indicators

The model incorporates signals associated with organizational security posture across endpoints, software services, infrastructure, and observable technology assets. It examines indicators such as overall exposure, software misconfigurations, infrastructure exposure, website security issues, botnet-related activity, and other risk signals that collectively reflect cybersecurity maturity.

Resilience Matters More Than CVE Counts

Importantly, the ISS Cyber Risk Score is not a CVE counting system. The model does not seek to measure risk solely by the number of (or implied severity of) identified vulnerabilities. Rather, it evaluates broader indicators that reveal how effectively an organization manages cybersecurity risk and maintains cyber resilience.

This distinction is especially relevant in a Mythos-driven threat environment. If advanced AI makes vulnerabilities easier to discover, organizations will need better ways to identify the characteristics that make firms less susceptible to the consequences of those vulnerabilities.

How Organizations Should Manage Cyber Risk in the Age of AI

The arrival of Mythos should not be viewed as a reason for panic.

Rather, it should be viewed as evidence that cybersecurity is entering an era in which vulnerability discovery may become increasingly automated and scalable. Rather than a single-minded focus on reducing vulnerabilities, organizations need to pivot to reducing the potential impact of vulnerabilities that are actually exploited. This is not a one-or-the-other choice, but a deliberate reset of the balance between avoiding vulnerabilities and surviving their impact. The organizations that perform best in this environment will not necessarily be those with the fewest vulnerabilities. They will be those with the best plan for dealing with those that become real for their company.

For boards and executive teams, this means moving beyond the vulnerability management metrics that comprise too large a share of the oversight reporting regime that has characterized the recent past. Instead, management teams need a new, additional focus on measurable indicators of security posture, governance, operational discipline, and organizational preparedness.

The ISS Cyber Risk Score provides exactly this perspective. By evaluating the observable characteristics associated with cyber resilience—and not merely the existence of CVEs—it offers a forward-looking view of cyber risk that is particularly relevant in a world shaped by AI-enabled security threats.

Additionally, oversight requires context, which implies relevant, comparative information. Peer benchmarking capabilities provide a means for risk to be considered in market-relevant terms. Perfect security is not possible; but reasonable, deliberate, and risk-informed security is possible. This is best attained through statistically-sound metrics and market-relevant comparison data points.

Mythos may change how vulnerabilities are discovered, and perhaps even how they are exploited, but resilience will continue to determine how much risk those vulnerabilities ultimately create.

Assess cyber resilience and benchmark risk against peers with ISS-Corporate’s Cyber Risk Score »

Authors:

  • Douglas Clare

    Head of Cyber Risk Services