Questions
1. AI is different, but not in the way many people think
2. AI amplifies existing weaknesses
3. Open models are not autonomous hackers
4. Supply chain security has become much more complex
5. The security perimeter is disappearing
6. Annual cyber planning is no longer enough
7. Recovery readiness matters as much as prevention
Discover more

Separating fact from fiction: realities of AI cyber risks

A man typing on a laptop with a lock hologram coming out of the screen. Mythos1TechnicalBlog_ArticleCoverImage_1920x600px@2x
  • AI increases the speed and scale of cyber risks, making strong security fundamentals more important than ever.

  • Organisations need to adapt their security approach by strengthening visibility, governance and continuous risk management across increasingly complex AI environments.

  • Building resilience through regular testing, preparedness and effective recovery is essential to staying ahead of evolving AI-driven cyber threats.

AI is reshaping cybersecurity, but not always in the ways headlines suggest. Datacom's recent executive briefing “The mythos of open AI models” with Group CISO, Collin Penman, and Director Cybersecurity Consulting, Adam Kirkpatrick, looked at the realities behind the hype, the risks organisations should be paying attention to and the security fundamentals that matter more than ever. 

AI has quickly become one of the most discussed topics in cybersecurity. Alongside genuine innovation has come a growing wave of claims about autonomous hacking systems, unstoppable attacks and entirely new categories of risk.  
  
Earlier this year when Anthropic’s Mythos model demonstrated the ability to discover and exploit software vulnerabilities at a scale and speed – beyond human capability – it sparked a flurry of discussion about the fundamental reshaping of cybersecurity and operational risk management. 

In a recent Datacom executive briefing session, The mythos of open AI models, Datacom Chief Information Security Officer, Collin Penman, and Director Cybersecurity Consulting, Adam Kirkpatrick, explored what is real, what is exaggerated and where organisations should focus their attention. The discussion cut through much of the hype surrounding AI and cyber risk, offering a practical perspective on how security leaders can prepare for what comes next.  

Here are seven key lessons from that session: 

1--ai-is-different--but-not-in-the-way-many-people-think

1. AI is different, but not in the way many people think

There is a tendency to compare AI with previous technology shifts such as cloud, mobility or social media. Penman argues that AI does represent something fundamentally different, but not because it introduces entirely new security challenges. 

Traditional software behaves predictably. Given the same inputs, it is designed to produce the same results. AI systems are different. 

“Traditional software behaves predictably: the same input results in the same output. What we're seeing with AI is that it is producing outputs that are somewhat ‘unknown’ as they can’t be fully tested for accuracy or relevance every single time, so there’s no real guarantee of consistency,” says Penman. 

That shift has significant implications for testing, assurance and governance. Organisations are no longer securing a deterministic application. They are increasingly managing systems that learn, adapt and behave in less predictable ways.

In this webinar, Datacom’s Adam Kirkpatrick is joined by Group CISO Collin Penman to explore the security and governance implications of open AI models, the evolving role of the software supply chain, and why identity, data, detection and resilience are becoming central to modern cyber strategy. The discussion also covers practical considerations for security leaders, from managing AI assurance and emerging machine identities to adapting investment planning in a fast-moving threat landscape.
2--ai-amplifies-existing-weaknesses

2. AI amplifies existing weaknesses

While AI changes the operating environment, it does not eliminate the need for cybersecurity fundamentals. 

According to Penman, many of the controls that mattered before AI still matter now. Identity management, access controls, patching, monitoring and API security remain critical. 

The difference is that AI accelerates both opportunity and risk. AI makes it easier to analyse code, discover vulnerabilities, generate phishing attacks and automate tasks that previously required specialist expertise. Weaknesses that might once have taken days or weeks to exploit can now be discovered and acted upon much more quickly. 

"AI doesn't change what breaks. It changes how quickly and how widely it breaks," says Penman. 

3--open-models-are-not-autonomous-hackers

3. Open models are not autonomous hackers

Few topics generate more debate than open AI models and so-called frontier models. 

Penman acknowledges that these systems can carry out increasingly sophisticated task chaining, analyse large volumes of information and automate complex workflows. However, he cautions against overstating their capabilities. 

"I think what's really misunderstood is it's not an autonomous hacker. It's really still requiring human direction. It's just requiring less context and a lot less access to individuals," says Penman.  

The real issue is not whether a particular model is open or closed. Security outcomes are shaped by how models are deployed, governed, monitored and integrated into broader systems. 

As Kirkpatrick noted during the discussion, security depends less on the model itself and more on "how it's deployed and how it's accessed and how it's governed"

4--supply-chain-security-has-become-much-more-complex

4. Supply chain security has become much more complex 

For years, security leaders have focused on software supply chain risks and Software Bills of Materials (SBOMs). AI is expanding that challenge dramatically. 

Models, APIs, training data, agents, plug-ins and external services can all become dependencies within a modern AI system. To describe this complexity, Penman introduced the concept of a "Mega SBOM". 

Rather than focusing solely on software libraries and application code, organisations need visibility across the entire chain of dependencies, including infrastructure, access paths, external services and AI components. 

"The SBOM is not just the application now," says Penman. "The Mega SBOM is really that complete entire inventory."  

This broader view becomes increasingly important as organisations adopt more AI-enabled services and third-party platforms. 

Collin Penman
Datacom Chief Information Security Officer, Collin Penman says "AI doesn't change what breaks. It changes how quickly and how widely it breaks."
5--the-security-perimeter-is-disappearing

5. The security perimeter is disappearing 

For decades, cybersecurity strategies centred on protecting networks and defending the organisational perimeter. 

That model is becoming less relevant. 

Data moves constantly between services. AI systems interact with multiple platforms. Machine identities are proliferating. Users, agents and applications increasingly operate outside traditional boundaries. 

"The perimeter, like the castle walls, has gone," says Penman.  

Instead, organisations need to focus on identity, behaviour, context and data access. Penman notes that Datacom now manages more non-human identities than human identities internally, reflecting a trend many organisations will soon face as AI agents become more common.  

6--annual-cyber-planning-is-no-longer-enough

6. Annual cyber planning is no longer enough

Many organisations still plan cybersecurity investments around annual budgeting cycles. The pace of AI-driven change is making that increasingly difficult. 

According to Penman, security leaders can no longer assume a stable threat landscape or predictable rate of change. 

"The biggest shift is around that planning now is really gone from a static planning to a continuous adaptation." 

Rather than relying solely on fixed annual roadmaps, organisations need flexibility to reassess priorities, reallocate resources and respond to rapidly emerging risks. Security programmes must become more adaptive, with greater emphasis on ongoing risk evaluation and continuous improvement. 

7--recovery-readiness-matters-as-much-as-prevention

7. Recovery readiness matters as much as prevention

Perhaps the strongest message from both leaders was the need to move beyond prevention-only thinking. 

Detection remains important. So does protection. But resilience is increasingly becoming the defining measure of cybersecurity maturity. 

Penman frequently returns to the importance of preparedness, testing and recovery. As he explained in Datacom's recent Cybersecurity Index research, many organisations remain overly optimistic about how quickly they could recover from a major cyber incident.  

"A plan that's never been tested isn't a plan – it's a document," says Penman. "Resilience is built through realistic practice that creates muscle memory, so response becomes automatic, coordinated and fast."  

As AI increases the speed and scale of cyber threats, recovery capability may become one of the most important differentiators between organisations that can withstand disruption and those that cannot. 

AI is undoubtedly changing cybersecurity, but perhaps not in the way headlines often suggest. The fundamentals of security remain largely unchanged.   

"AI doesn't fundamentally change what we defend."  

Organisations still need strong controls, clear governance, disciplined risk management and resilient recovery plans. What AI changes is the pace, complexity and scale of the environment in which those fundamentals must operate.   

The challenge for security leaders is ensuring they can evolve quickly enough to keep pace with it.   

Learn how digital resilience can help your organisation anticipate disruption, adapt with confidence and recover faster

discover-more

Strengthen your cybersecurity resilience

As AI increases the speed, scale and complexity of cyber threats, organisations need to look beyond the hype and focus on strong security fundamentals, adaptive risk management and resilience. Explore how Datacom’s cybersecurity solutions can help strengthen your security posture, protect critical systems and data and prepare your organisation to respond and recover as the threat landscape evolves.

Cybersecurity-Alternate-Hero-Image-1920x560px@2x.jpg