AI is changing the economics of cyber crime. Most businesses have not realised it yet.

Over the past few months, there has been significant attention on the emergence of increasingly capable AI models for cyber security and vulnerability discovery.

Much of the recent discussion has centred around Anthropic’s newly publicised Mythos model, which reportedly demonstrated an ability to identify vulnerabilities in software and systems at a level that has attracted the attention of governments, regulators and major technology firms.

As with any new AI breakthrough, it is important to separate reality from hype. The full implications of these tools remain uncertain, and some independent experts have rightly questioned how transformational they really are in practice.

However, I believe businesses would be making a mistake if they dismissed this as another overblown AI story.

Because whether it is Mythos specifically or the next generation of models that inevitably follow, the direction of travel is becoming increasingly clear.

The economics of cyber attack are changing.

Attackers no longer need to work as hard to find targets

Historically, identifying vulnerable organisations took time, effort and expertise.

Attackers needed to manually research businesses, scan websites, look for weaknesses, test configurations and decide whether a target looked worth the effort.

That process naturally created friction. In simple terms, cyber criminals had to work for their opportunities. AI has the potential to change that.

Increasingly capable reasoning models are making it easier to automate vulnerability discovery, assess environments at scale and prioritise organisations that appear easier to compromise.

This matters because most cyber attacks are not particularly sophisticated.

More often than not, attackers get in through weaknesses that should have been spotted and fixed: outdated software, exposed services, weak passwords, poor configurations or vulnerabilities that have simply been left unpatched.

In many cases, it is not advanced hacking that causes the problem. It is the accumulation of small gaps over time. In other words, attackers are often looking for the lowest hanging fruit. And AI may make finding that fruit significantly easier.

The real risk for businesses

For many organisations, the biggest misconception about cyber security is believing they are unlikely to be targeted. The reality is that most businesses are not individually selected. They are discovered.

Attackers increasingly operate opportunistically. Rather than choosing a specific organisation from day one, they scan broadly, identify weaknesses and pursue the easiest routes to access. That means the question businesses should be asking is not:

“Would somebody target us?”

But:

“If someone looked at our environment today, would we appear easy to target?”

That is an uncomfortable question because many organisations simply do not know the answer. They may have inherited websites, outdated software, forgotten subdomains, legacy configurations or third-party integrations that nobody has reviewed for years. On paper, everything may appear secure. From the outside, things can look very different.

Good cyber security may become even more important

There is an important nuance here. The same developments making attackers more capable may also strengthen cyber defence.

AI tools are increasingly being used to identify vulnerabilities faster, support remediation, prioritise patching and strengthen resilience. In practical terms, this means cyber hygiene matters more than ever.

Strong patching practices. Good access controls. Multi-factor authentication. Regular reviews of exposed systems. Sensible penetration testing. Clear visibility of external risk. The fundamentals are unlikely to change. But the consequences of neglecting them may increase.

So what should businesses do?

The answer is not panic. And it is certainly not rushing to buy every new AI security tool on the market. Instead, organisations should start by asking some fairly practical questions:

  • Do we know what our external attack surface actually looks like?
  • Are there visible vulnerabilities we are unaware of?
  • Have our websites, systems and environments changed since they were last reviewed?
  • Would we know if we had become an easy target?

For many organisations, the biggest risk is simply visibility. You cannot fix weaknesses you do not know exist.

The conversation around AI in cyber security is only just beginning. Some of the headlines may prove exaggerated. Others may ultimately prove understated. But one thing feels increasingly likely: the speed and scale at which attackers can identify vulnerable organisations is unlikely to move backwards.

That means understanding your visible cyber exposure is critical.

New: Threat Exposure Review service

If reading this has made you wonder whether your organisation might currently look like an easy target from the outside, that is exactly why we recently launched Threat Exposure Review.

It is designed to help organisations identify the kinds of visible vulnerabilities attackers increasingly use to select targets, particularly where a full penetration test may not yet be proportionate.

In short: before investing in a full pentest, it helps answer a fairly practical question:

“Are there obvious weaknesses we should know about?”

You can find out more about our new Threat Exposure Review service by clicking here.