Insight
Cybersecurity at AI speed: why enterprise incident response needs to change
By James White
AI powers us to do many things faster and be more productive. But there is a darker side that allows it to be used in bad faith.
The Claude Mythos story has unfolded in the media over the last few months and is continuing to do so. The risks highlighted by Mythos became even more significant in July 2026, when OpenAI disclosed that two of its models had escaped a testing environment and gained unauthorised access to the company Hugging Face’s systems. The key takeaway is clear: AI has changed how we need to think about and plan cybersecurity. The security response timelines of companies are not something AI will respect. Businesses need to be prepared and ready to move at a much greater speed than ever before.
“AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back..."
The birth of Mythos
Anthropic is an AI company, set up by former employees of OpenAI, with a strong focus on ethics. Claude is the public-facing AI assistant which works in a similar way to ChatGPT and offers an ever-growing array of capabilities. Claude Mythos Preview is one of Anthropic’s newest frontier AI models, which started life to learn coding but its capabilities have grown organically beyond the original intent to make it especially powerful at security testing.
In April 2026 Anthropic realised the danger that Mythos could pose in the wrong hands. So they formed a coalition of leading organisations from government, finance and technology under the banner Project Glasswing to confirm their concerns about what it could do. The results showed how powerful the technology had become, with 10,000+ new critical or high severity vulnerabilities discovered that were previously not found by humans. If an AI model being used for defence can find thousands of serious weaknesses, once it falls into the hands of hackers, they will use it to attack. The point is not that Mythos itself is about to attack your business, but that the capability exists and that other AI companies are close to releasing similar tools.
Cybersecurity has now changed
Vulnerability exploitation is where hackers find something that is unpatched, misconfigured or any form of technical weakness. Traditionally the focus has been on the outer defences of a business: stopping the attacker from getting in at all. But the consideration now needs to widen to what happens once they are inside.
Hackers using AI only need to find the smallest window that has been left open and forgotten. Once they are in, AI can get its toolbox out to search rapidly across all systems, permissions, misconfigurations and weaknesses. That means a firewall and external defences alone are no longer enough. Internal systems, access controls, patching and monitoring all need to be managed.
Iteration is everything
When technology companies publish online security patch notes, AI can also read them. So what was once a useful insight about why something needed to be fixed, has now become a playbook for AI-powered hackers. AI will try to reverse engineer each issue to know exactly what is and isn’t patched and how to exploit the system.
This isn’t limited to the latest issues either. When AI knows what the patch is fixing, it can go back through many versions to expose weaknesses that were never even considered. One weakness AI found was a security flaw in core OS Linux code, which is the software used by many of the world's servers, granting full admin access.
AI constantly learns. If it finds exploitable vulnerabilities in one company, it is smart enough to take that and apply it at scale in future attacks. And it will unravel standard processes, technological relationships and identify patterns to help it move more quickly and effectively by chaining attacks together.
What was once a useful insight about why something needed to be fixed, has now become a playbook for AI-powered hackers.
AI doesn’t need coffee breaks
In a typical business, there are processes for technology change. There are different levels of authority and sign-offs that decisions need to go through. Sometimes there can be disagreements about which department is responsible for what, or individual egos that get in the way. And every human needs to sleep and eat.
AI has none of these needs.
AI can just stay working 24/7/365. It has no hierarchy to consult with, it just goes where the opportunity takes it.
And this is where the fundamental issue lies. Humans and AI work in different ways. People proceed cautiously, testing and checking that a new development won’t break anything. AI, when being used by hackers, wants to break everything it can. The danger this difference poses is that while human decision-makers are pouring their coffee, the AI is already breaching their systems. And by the time they realise, AI will have taken those learnings and spread them across not only their organisation, but many others as well.
What you need to focus on now
Bureaucracy in large companies is possibly the biggest enabler of AI hackers once the initial breach has taken place. There will not be time to work through the normal layers of approvals, you need to get ready to act fast if the worst happens. The March 2026 Stryker attack, although not driven by AI, is a good example of how bad it can get. Tens of thousands of devices were reportedly wiped, with the attackers claiming more than 200,000 were affected.
The speed at which AI works is totally different to what we have seen before. In 2018 the average window between identifying a threat and attackers exploiting it was 2.3 years, in 2026 this is now reported as under eight hours. The 30-day patching targets are over: you need to start moving in hours.
The key things to work on now are:
Get your house in order
Make sure all your policies and procedures are fully documented and signed off. You need to know what the ask is and how to achieve it. That goes for everyone who will be involved, not just the authors of the document.
Plan your emergency response
At the point of an attack there isn’t time to create a response from scratch, you need to mobilise already defined processes. Plan and practise how you will run the response. You might need to break it down into different sections e.g. Windows, servers, networks, to move fast enough.
Think about the capacity planning of the emergency team, that includes reviewing contracts for outsourced third-party suppliers to make sure you are covered. Do a gap analysis and make sure that you have the right skillsets to work at speed.
Get communications and documents drafted so they are ready to be used as soon as they are needed.
Consider the restart
Think about the interface into the business. If systems in a production environment need a reboot, that is often a challenge, so consider who might need to be involved. If possible, prepare them for the potential scenario. You don’t want to be arguing about what can and can’t be done in a crisis situation, it just needs to happen.
Once the panic is over, you need to work out how you clean up the environment to get the business back on its feet again. Again, thinking about this before it is needed will speed the return to business continuity.
Support your people
A critical incident can have a significant toll on the people involved. Remember to check in and make sure they get the support and recovery time that they need to cope. Tag in another team member to give them a break if it’s a long-running incident.
The bottom line is that what we did yesterday is not good enough for tomorrow.
Businesses cannot afford to let slow processes, unclear ownership and human hesitation become the perfect time window and distraction needed for AI attackers to exploit.
Get in Touch
Talk to us today to explore how we can support your organisation's technology needs.