2026-06-06 08:58 UTC
Talkin' Bout A Revolution 🎵🤖
We spent some time this week speaking with customer CISOs - knowledgeable and experienced professionals at the top of their game – under Chatham House Rule. I always love these experienced – the opportunity to spend focused time in a dedicated setting discussing and debating the pressing security issues of the day – directly with the people that are actively trying to manage those issues.
A prominent topic was of course “AI” and naturally the “Mythos Moment” came up. Unsurprising. And we’ve had a strong, albeit balanced, position on the question for some time. But at this point I felt I started to lose control of the room, because my assessment of the impact of AI on security is much more moderate than some of our customers.
Hey – I’m on the vendor side – aren’t I supposed to be the one with exaggerated and alarmist FUD messages on everything?
The way one customer put it: “You think this is an evolution, but it’s a really a revolution”.
The contrast between “Evolution” and “Revolution” quite neatly captures the divergent positions we see emerging across the domain, including here on LinkedIn. If LLM and Agentic capabilities like Mythos (and others) represent an “Evolution”, then our response can be to focus on doing the basic right consistently, and perhaps use AI to help us work faster and make fewer mistakes. Different, but the same.
If we’re dealing with a “Revolution”, then cyber-attacks will eventually become fully autonomous, planned, coordinated and executed by AI agents at wire speed. LLMs will discover vulnerabilities, write exploits, navigate the killchain end to end without human intervention and do it all before your SOC analyst has finished reading the SIEM email alert. Data exfiltrated, wiper deployed, game over.
An AI security “revolution” renders existing approaches obsolete, goes the argument, and so the only the only thing defenders can do is to develop their own army of autonomous agents that can similarly operate at wire speed – a practical application of the old notion of self-healing systems. Security skillsets, products and services, KPIs, players, leaders and workforces all get fundamentally transformed in this process.
As much as this all sounds like Gibsonesque Sci-Fi – AI fighting AI in cyberspace – some CISOs anticipate rolling out autonomous AI agents to perform security functions on their networks by the end of this year!
Which brings me to my question, and the purpose of this post: Is it “evolution”, or “revolution”? Does Mythos symbolize an inflection point in security where everything that was, is now obsolete? Or do ancient security truths, practices and tropes still hold true, ready to root our response to the AI “evolution” in the gospel of NIST & CISSP and the grand priests of Zero Trust and CTEM?
Please let me know your thoughts! Or complete my simpleLinkedIn survey below so that I too can understand wtf is actually going on!!!
https://www.linkedin.com/posts/charl-van-der-walt_talkin-bout-a-revolution-we-spent-activity-7468581310131752960-StMd
Replies (0)
No replies.