When Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves.
Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers examined technical benchmarks. Industry observers questioned how quickly these capabilities might fall into attackers’ hands.
Those conversations are important. They also point to a larger question that predominates my discussions with CISOs: How much time do we have?
Over the past year, conversations about AI in cybersecurity have changed noticeably. Twelve months ago, security leaders wanted to understand whether AI could meaningfully improve security operations. They wanted to know whether it could accurately investigate alerts, reduce analyst workload and operate reliably in production environments.
Today, security leaders are asking about timelines, implementation, how quickly AI is changing the threat landscape and what that means for how security teams operate.
Anthropic’s Mythos and Glasswing, OpenAI’s Daybreak and advances in DeepSeek accelerate those conversations. Each development provides another glimpse into the pace at which AI capabilities are advancing.
AI now reasons through security problems that historically required highly specialized expertise. The implications span vulnerability discovery, attack-path analysis, reconnaissance, social engineering and security operations.
The shift reflects a broader reality: cybersecurity is entering a period where the pace of adaptation may matter as much as the quality of defenses themselves. AI is accelerating both offense and defense simultaneously. Organizations are quickly redesigning security operations around that reality.
One consequence is becoming increasingly visible. For years, cybersecurity teams invested enormous effort in discovering threats, identifying vulnerabilities, gathering telemetry and collecting intelligence. AI is accelerating many of those activities simultaneously. Visibility is improving. Discovery is accelerating. Investigations are becoming faster and more comprehensive.
The bottleneck is beginning to move. The challenge increasingly centers on how quickly organizations can act on what they know. The organizations that gain an advantage may not be the ones with the most information. They will be the ones who can operationalize that information the fastest.
The timeline is compressing
Cybersecurity has experienced many major technology transitions. Cloud computing changed infrastructure. Mobile devices expanded the attack surface. Digital transformation connected systems that were previously isolated.
AI introduces a different dynamic.
Most technology transitions unfolded over years. Organizations had time to evaluate, pilot, deploy and gradually adapt operating models.
The current AI cycle moves at a different pace.
Capabilities improve continuously. New models arrive every few months. New research emerges every few weeks. Security teams absorb developments at the same time attackers do.
Vulnerability discovery provides a useful example. Security teams have long operated around a familiar cycle of discovery, validation, remediation and protection. AI systems accelerate every stage of that process. Similar patterns exist in phishing, reconnaissance, social engineering and attack planning.
A vulnerability that once moved through that cycle over weeks increasingly now moves through those stages in days or, in some cases, hours.
Attackers are already operating at the speed of AI. Defenders are now focused on reaching the same level of operational speed.
This shift is changing the questions CISOs ask.
Early discussions focused on capability. Could AI investigate alerts accurately? Could it operate reliably in production environments? Could it be trusted with meaningful security work?
As organizations gained experience with AI, the discussion shifted toward implementation. Security teams began evaluating where AI could create operational leverage and how quickly they could deploy it into existing workflows.
Today, many CISOs are focused on timing.
The pace of advancement is influencing planning horizons, budget decisions and operating-model discussions. Security leaders are evaluating how quickly they can introduce AI into investigations, threat hunting, detection engineering and response workflows. Boards are asking questions. Executive teams are paying attention.
Security programs that once viewed AI as a future initiative increasingly view it as a current operational priority.
The industry is moving from evaluating AI as a technology to incorporating AI as a security capability.
The timeline compression creates pressure on the traditional security operations model. Investigation speed, response speed and defensive coverage increasingly determine whether organizations can keep pace with adversaries operating with AI assistance.
Security operations are entering a new phase
The impact of AI is becoming particularly visible inside the SOC.
Many security operations centers were built around a straightforward assumption: alerts flow to human analysts who conduct investigations. Operational capacity scales primarily through hiring.
The volume of security data, the number of alerts and the complexity of modern environments have steadily increased. Security teams have responded by building processes, adding tools and creating specialized analyst roles.
AI introduces a new source of operational capacity.
Investigations that require analysts to examine dozens or hundreds of artifacts across endpoint, identity, cloud, network and email systems can now be performed in minutes. Analysts gain access to investigative depth and consistency that would be difficult to achieve manually at scale.
Many security leaders now view this capability through the lens of operating model design. They are examining how investigations are performed, how work is distributed and where human expertise creates the greatest value.
The evolution of the analyst role
One of the most important developments emerging from early production deployments is the evolution of analyst responsibilities.
Security analysts remain central to security operations. Their expertise becomes even more valuable as AI systems take on larger portions of investigative work.
Threat hunting, detection engineering, response strategy, governance and oversight are receiving increased attention. Analysts spend more time shaping how investigations are conducted, evaluating outcomes and improving overall security operations.
Many organizations are already beginning this shift.
Teams are investing more heavily in proactive security activities. Detection engineering programs are expanding. Threat hunting is becoming more accessible. Analysts are spending more time improving systems and less time repeating investigative tasks.
These changes create what I think of as an analyst-amplified SOC: an environment where AI expands the reach of security professionals and enables deeper security work across the organization.
Trust is critical and it doesn’t have to compromise speed
Faced with a compressing timeline, the instinct is to treat speed and trust as a trade-off, i.e., move faster, verify less. That trade-off feels inevitable. It isn’t.
You don’t trust AI in the abstract. You trust that a system understands your tools, your telemetry and the edge cases that only exist in your network. The problem was never speed. It’s speed without context. The faster a context-blind system runs, the more decisions you’re left unable to verify.
The tension eases when the system is quick to deploy and tunes to your environment once it’s there, rather than treating every network the same. Speed stops being the thing you trade against trust. The more it learns about your environment, the sharper and more trustworthy it becomes, so the two compound rather than compete. Trust still develops through operational evidence such as measurable outcomes, visibility into decisions and consistent performance. But where that evidence accrues matters.
The organizations making the fastest real progress understand this. They don’t compromise quality and trust for speed. They invest in AI that earns trust inside their own environment, so they don’t have to choose.
Leadership during a period of rapid change
The conversations surrounding Mythos and Glasswing reflect a broader reality facing security leaders.
AI is becoming part of both offense and defense. Security teams are incorporating it into investigations, detection engineering, response workflows and threat hunting. Attackers are incorporating it into their own operations.
Security leaders have an opportunity to modernize operating models, expand defensive capacity and build organizational experience while these capabilities continue to evolve.
The organizations making progress today are investing in readiness. They are building experience, adapting workflows and preparing teams for a new model of security operations.
The next phase of cybersecurity will be defined by how effectively organizations combine human judgment with machine-scale execution.
The question facing security leaders is increasingly clear: How quickly can their organizations adapt to a continuously changing threat environment?
This article is published as part of the Foundry Expert Contributor Network.
Want to join?