Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity & Business Resilience

Schrödinger's Vulnerabilities: What Mythos Actually Broke in Cyber Insurance

By Joshua Brown
Vertical green code on black screen
Markus Spiske via Unsplash
June 4, 2026

There’s a quote making the rounds in the post-Mythos cyber insurance discourse: “With AI, the gap between vulnerability, discovery or and exploitation has collapsed from months to minutes. What happens to historical frequency data as a predictor of forward-looking events? This becomes insufficient. It's not working.” That quote is attributed to Tracey-Lee Kus, chief executive at Aon’s Global Broking Centre, when she spoke in April at a cyber risk conference.

The critique of historical frequency data is correct. The framing around it misses the actual mechanism.

The vulnerabilities Anthropic surfaced through Mythos didn’t appear in April 2026. Some had been sitting in production code for decades. The bugs existed last year, the year before, and the year before that. What changed isn’t the population of vulnerabilities. What changed is who can see them, how fast, and at what cost.

Underwriters tend to read this as a frequency problem. It looks more like an observability problem dressed up as one.

The Schrödinger Framing

Here’s where the right metaphor lands: a large class of latent vulnerabilities now sits in a kind of Schrödinger's cat state. They exist. We know they exist. We have strong indirect evidence — Anthropic’s technical preview, the Project Glasswing coordinated disclosure pipeline, twelve of the largest infrastructure companies on the planet quietly patching things. For the rest of the market, the specific bugs remain confirmed-to-exist and unspecified-in-detail.

Call it what it is: information asymmetry. A privileged set of organizations holds the catalog. Everyone else holds the inference. Until the patches ship and the advisories drop, no defender outside the coalition can act on any specific bug, because no defender outside the Glasswing coalition knows what the specific bug is.

The defender’s epistemic state is genuinely bifurcated. That’s the actual disruption. AI didn’t create new vulnerabilities. AI collapsed the discovery half of the vulnerability lifecycle from a slow, distributed, semi-public process into a fast, concentrated, partially-private one.

Cost moves, Doesn’t Disappear

When detection stops being the bottleneck, the cost migrates rather than vanishes.

Remediation was always the expensive half of vulnerability management. Patch testing, regression risk, downtime windows, configuration drift, the long tail of unpatchable systems running someone’s grandma’s accounts payable software — that’s where security budgets actually go. AI made none of that easier. It just moved more work into that bucket, faster than most organizations can absorb.

For insurers, this matters because severity is governed by remediation lag, not discovery speed. The question isn’t “how fast did the attacker find the bug?” The question is how long the window was between disclosure and patch deployment in your insured's environment, and what was reachable from that window.

That’s measurable. It’s also exactly the data that annual questionnaires don’t capture, because they were designed for a world where the attacker side moved at human speed.

Where I’d Push Back on Myself

Two things I want to be honest about.

First, the one-time-glut theory. I think Mythos represents a step function, and that the catch-up period reaches a new equilibrium once defensive AI tooling and coordinated disclosure pipelines absorb the backlog. I think that. I can’t prove it. If frontier capability keeps compounding faster than defensive deployment can keep up, the glut isn’t a one-time event; it’s the new baseline. The honest position is that this is a directional bet, not a settled point.

Second, the “we can’t do anything about them en masse” line overstates the defender’s predicament. What breaks is CVE-driven vulnerability management. Patch-the-known stops working against bugs you can’t see. Defense-in-depth doesn’t require knowing the specific vulnerability. Network segmentation, behavioral endpoint detection and response (EDR), identity hygiene and blast radius reduction — these work against unknown exploits. Traditional vulnerability management breaks down. Defense doesn’t.

That distinction matters when underwriters start asking insureds what they’re doing about Mythos-class risk, because the right answer isn't a list of CVEs patched. The right answer is a posture that holds up against an exploit you’ve never seen before.

What This Means for the Underwriting Model

The frequency-data critique is right that historical loss data is a poor predictor of forward risk in this regime. The deeper issue is that the entire model of pricing cyber risk based on a once-a-year snapshot of self-attested controls was already breaking before Mythos. Mythos just made the failure mode obvious.

The replacement isn’t more questionnaires. It’s continuous, verifiable evidence of control efficacy, measured against the things that actually drive severity. Patch latency. Identity hygiene. Segmentation depth. Incident response time. The boring operational signals that determine whether a known vulnerability becomes an uneventful Tuesday or a board-level incident.

The vulnerabilities are in the box. The cat is in the box. We don’t get to open the box on our schedule anymore. The underwriting model that survives this transition is the one that prices the box, not the cat.

KEYWORDS: cyberattack cybersecurity threat actor vulnerability management

Share This Story

Joshua Brown is the Chief Information Security Officer of Spektrum. 

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Photograph of apartment complex patios

Enhancing Residential Building Security

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Open filing cabinet

The Inside Job: Corporate Espionage Never Went Away

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Events

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing