Security Café
About this episode In this special edition of SecurityCafe, Quint Ketting and Koen Maris join host Menno van der Horst for an open, no-nonsense conversation about Mythos — Anthropic's frontier AI model expected to become more widely available around mid-August. No panic, no hype — just an honest look at what will actually change, and what your organization should already have been doing. ---------------------------------------- What we cover Mythos: revolution or evolution? Koen opens with a sharp reality check: if it takes five days to build an exploit today and Mythos brings that down to twenty hours — how much really changes? The hype around Mythos risks drawing attention away from what's already happening. Claude Opus 4.7 is already live, carrying many of the same capabilities, with barely anyone noticing. The real shift: accessibility The barrier to sophisticated attacks is dropping fast. It's not that experts are becoming more dangerous — it's the new wave of attackers without deep technical skills that warrants concern. Quint illustrates the point with his own experience using Claude: from building custom tools to recovering audio from a faulty recording. What this means for your organization * Cyber hygiene first. If your foundations aren't in order, you already have a problem — Mythos just makes it more visible and more urgent. * Third-party contracts. Patch response clauses of 90 days or more are no longer viable. Time to renegotiate. * Asset management. If you don't know what you have, you don't know what to protect. A scan often reveals 40% more assets than organizations think they manage. * Exposure management. Unmanaged assets are exactly where attackers will strike first. * Patch cycles. Microsoft recently released 250 patches in a single Patch Tuesday — normally 10 to 20. That pattern is not a coincidence. Prepare, Respond, Adapt Koen introduces the PRA framework: we are currently in a fragile peace. Use this window well. Organizations that prepare thoroughly will weather the storm quickly. Those that don't may find themselves in a prolonged and costly recovery. Frontier AI: the next buzzword — and what it actually means Mythos is part of a broader phenomenon. Vendors like Palo Alto are already embedding the same AI engines into their defensive toolsets. The question isn't whether this will affect you — it's whether you'll be ready. Project Glasswing & responsible disclosure Anthropic has given early access to a select group of major technology companies, resulting in both an explosion of patches and new AI-powered defenses. Responsible management of this capability is exactly the right approach — and a model the industry should follow. ---------------------------------------- Key takeaways * Start an internal working group now. Structure it with proper governance, board-level reporting, and weekly progress reviews. * Review your third-party agreements: do your SLAs still hold in a world of 24/7 patching? * Don't wait for Mythos to get your basics right. A low security maturity level cannot be fixed in two months. * Frontier AI is the bigger frame. Follow developments across Anthropic, Google, and others — not just the Mythos headlines. ---------------------------------------- Guests * linkedin.com/in/menno-van-der-horst-74710794 [http://linkedin.com/in/menno-van-der-horst-74710794] * linkedin.com/in/koen-maris [http://linkedin.com/in/koen-maris] * linkedin.com/in/quintketting [http://linkedin.com/in/quintketting]
25 Episoder
Kommentarer
0Vær den første til å kommentere
Registrer deg nå og bli medlem av Security Café sitt community!