Our website uses cookies to improve user experience, analyse website traffic and assist in our marketing efforts. By clicking “Accept”, you agree to the storing of cookies on your device. View our Privacy policy for more information. You can change your preferences at any time.
Orange cross to indicate close page icon.
graphic depicting an automated Malware alert

Why Mythos demands a new operating model for your infrastructure

Frontier AI is rewriting the rules of network security. Here's how UK manufacturers can move to a faster, more resilient infrastructure operating model.

A recent conversation between two Cisco security leaders made one thing clear: frontier AI has permanently changed the pace of cyber security. The old habit of hardening infrastructure once and leaving it untouched no longer holds. Here is what that means for your network — and where to begin.

There is a moment in every technology cycle where the ground shifts beneath everyone at once. Listening to Cisco's Tom Gillis and Russell Smoak discuss how frontier AI models are reshaping cyber security, it is hard not to conclude that we are living through one of those moments now. Their message was direct: the tools that defenders and attackers alike now have access to represent a genuine step-change, and the way we build, test and — most importantly — operate infrastructure has to change with them.

As a Cisco Preferred Networking Partner of more than 25 years, we have sat through a great many predictions about what will transform the industry. Most arrive with more noise than consequence. This one is different, and it is worth explaining why, and what it means in practical terms for the manufacturers and warehouse operators we work with every day.

What has actually changed

For several years, AI has been a useful assistant in security work. What Cisco's team described is a qualitative leap rather than an incremental one. The latest frontier models can now hold an entire multi-million-line codebase — the kind that sits inside a Catalyst switch or a firewall — in their view all at once. Because they understand a system in its entirety, they can trace the long, subtle chains of events that lead to a vulnerability: the kind of flaws that skilled human reviewers have missed after a decade of looking. In Cisco's own offensive security work, a team of fewer than a hundred people is now producing the output of more than five hundred senior engineers, complete with proof-of-concept exploits and suggested patches.

The uncomfortable corollary is that adversaries have the same capability. Vulnerabilities that once took months to surface will be found in days, and exploits written in hours. As Russell Smoak put it, defenders now have to move at machine speed. Tellingly, these models can find exploitable weaknesses in a live system simply by exercising its APIs — no source code required.

The "summer of turbulence"

Cisco's leaders were candid that the near term will be bumpy. Every piece of software, from data-centre infrastructure to the thermostat on the wall, contains vulnerabilities that will now be discovered and disclosed at a pace the industry has never seen. They called it a summer of turbulence: a high-volume wave of patching that the whole sector must work through together. Even once that wave passes, the baseline rate of disclosure will settle at a permanently higher level than before.

For organisations still operating on the traditional rhythm — harden the network, prove it works, then leave it alone for eighteen months — this is a genuinely difficult adjustment. The mindset that has kept infrastructure stable for decades, a bias toward mitigating and working around problems to avoid downtime, is precisely the mindset that now needs to invert. The direction of travel is toward an upgrade culture, where change is frequent, small and routine rather than rare, large and nerve-wracking.

A new operating model, not a single product

It would be easy to reduce this to a shopping list of features, but the more useful way to think about it is as a change in operating model. Cisco described a layered approach, and it is a sensible frame for any conversation about resilience.

The foundation is segmentation. On the assumption that a compromise will eventually happen somewhere, the goal is to contain the blast radius so that a single breach cannot spread across the estate. This has always been good practice; it now matters more than ever, and the granularity available has improved dramatically, down to stateful inspection at the level of an individual switch port.

Above that sit compensating controls — the ability to apply a precise, temporary shield to a running system between maintenance windows, without rebooting it or altering the software itself. Cisco's LiveProtect capability, embedded in its data-centre switching operating system, does this for infrastructure, and the same philosophy extends to customer applications, including the third-party and legacy software that can take months to patch. These are explicitly emergency measures for critical, actively targeted vulnerabilities, and they never remove the need to patch properly. But as a way to plug a hole while a proper fix is prepared, they are a meaningful advance.

Finally, AI-powered detection in the security operations centre watches for the anomalies that indicate a compromise has slipped through, so that it can be found and remediated quickly.

Where to begin

Much of Cisco's practical advice is refreshingly unglamorous, and all the stronger for it. The no-regret moves are the ones we would encourage any client to make regardless of how the AI story unfolds: segment the network wherever you can, apply multi-factor authentication everywhere, and get a genuinely accurate inventory of your assets so you can judge the risk each one carries. Sharpen the processes around software qualification and configuration management, and be prepared to migrate end-of-life equipment out of the network before it becomes a liability.

The harder shift is cultural. Adopting more frequent, smaller updates means expanding your tolerance for change a little, because the alternative — moving slowly while adversaries move at machine speed — is the greater risk. None of this compromises the availability that a manufacturing line or a busy warehouse depends on; a well-designed, resilient network can be upgraded in stages without ever going dark.

How we can help

This is the kind of change that benefits enormously from a partner who can move quickly and tailor the response to your environment rather than push a fixed template. Our size is an advantage here: we can get close to your operation, understand the specific constraints of your sites, and make decisions without waiting on bureaucracy. What matters most in the months ahead is not adopting any single technology but building an operating model that lets you upgrade with confidence and stay ahead of a faster adversary.

If the summer of turbulence has you wondering where your own infrastructure stands, that is exactly the conversation we are here to have. We would start not with a product, but with a clear-eyed look at your current posture and the outcomes you need — and take it from there.

If our blog post interests you and you’d like to find out more, please get in touch!
CONTACT US
Orange arrow icon for back to top link.