Anthropic's next frontier AI model is rolling out this summer, and if not Mythos, expect Kimi, DeepSeek, or others to follow. The CSA / SANS Mythos-Ready Security Program, developed with contributions from Jen Easterly, Bruce Schneier, Heather Adkins, Rob Joyce, Phil Venables, and others, and reviewed by hundreds of CISOs and security leaders, calls it the most significant offensive AI capability shift the industry has seen. Your security team gets it back to back with vacation season.
The window is real. NIS2's first compliance audit deadline is 30 June 2026. BSI is in active enforcement. Article 20 imposes personal liability on management bodies, extending to US companies with EU subsidiaries or operations in the Union. A material breach triggers disclosure obligations, notice requirements, and the legal clock, all at once.
Before you sign off on vacation, ask your CISO these five questions. Make them answer with evidence, not assumption. If they can answer all five succinctly and with live evidence, you are in good shape. If they cannot, that is the signal to get help, before the news cycle does it for you.
- Show me what's exposed to the internet this week. Not last quarter. This week. The next generation of frontier AI finds what you don't know exists. An aged inventory is worse than no inventory.
- When the next frontier AI drops, how many hours until we're patched? Tell me a number, not a process. Time-to-exploit is now hours. If your patch SLA is in weeks, you have already lost.
- If we get breached tonight, who knows first: us, our customers, or the press? Regulatory notice windows are tight and unforgiving. You can't meet them if you don't detect the incident first.
- Who has the keys to our crown jewels? Walk me through the list. If your CISO can't name privileged identities in three minutes, neither can the auditor.
- Prove to me the blast radius is bounded. With evidence, not assumption. "We have Zero Trust" is not evidence. A live posture screen is.
The rest of this article covers what good answers look like, what stopping the spread actually means as a managed strategy, and how one week on-site (SHERPA) tells you concretely where you stand.
For the CFO and general counsel: you've already bought the tools
US enterprises have spent the last decade investing in network, endpoint, identity, and cloud security. The tools work as advertised. What's missing is the corporate strategy that ties them to business risk, and the operational discipline to prove, on demand, that the strategy is holding when the SEC, the NIS2 competent authority, the board, or a customer asks.
Three questions worth asking alongside the CISO's five: are you extracting the strategy you already paid for from the stack you already own? When the board, an auditor, the SEC, or a NIS2 competent authority asks "are you in control right now?", can you answer with live evidence, not a slide? And if a breach lands tomorrow, will you be prepared, or scrambling lawyers, consultants, and insurers to get ahead of a news cycle?
The next breach is no longer a question of if. AI-driven adversaries collapsed the time from vulnerability to exploit from weeks to hours. NIS2 Article 20 puts personal liability on management bodies of in-scope EU entities, and on US parents providing services through EU subsidiaries. Buying more tools won't close the gap. Strategy and operational discipline will, applied to the tools you already own.
What stopping the spread actually looks like
Stopping the spread isn't a product. It's a strategy with three layers, embedded as a culture, operationalized through the controls you already own. The layers go in this order; each one is the foundation for the next.
Strategy
Kindervag's five-step methodology, written by a Forrester analyst in 2010. Define protect surfaces, map transaction flows, build Kipling-method policy (who, what, when, where, why, how), microsegment, monitor continuously. Vendor-agnostic by design.
Culture
The organizational discipline that keeps the strategy from drifting back into product configuration. SHERPA Onboarding Week installs it on-site. AUXO™ governs it across six management layers: Strategy, Policy, Architecture, Engineering, Operations, Assurance.
Operationalization
Your existing security investments, managed to one Zero Trust policy. MDR Prevent runs your network, endpoint, identity, and SASE controls to a single strategy, continuously hardened, continuously evidenced. No rip-and-replace.
11 Mythos-Ready actions. 8 delivered today. 3 honest answers.
In April 2026, the CSA / SANS Mythos-Ready Security Program, developed with contributions from Easterly, Schneier, Adkins, Joyce, Reavis, Venables, and others, published 11 priority actions for surviving AI-accelerated vulnerability discovery. The table below maps each one to how it's delivered as part of MDR Prevent today. Eight directly. Two with your engineering team. One through our partner ecosystem.
| # | Priority Action | Sev. | ON2IT Delivery | How |
|---|---|---|---|---|
| PA1 | Point Agents at code & pipelines | CRIT | Partial | LLM-driven code review via AUXO™ + partner ecosystem; full VulnOps is the roadmap (see PA11). |
| PA2 | Require AI agent adoption | CRIT | Advise | SHERPA Week sets the customer's adoption policy and security guardrails for coding agents. |
| PA3 | Defend your agents | CRIT | Delivers | Agents become a Protect Surface in ZT Step 1; Kipling policy in ZT Step 4 bounds tools, blast-radius, and escalation. |
| PA4 | Innovation & acceleration governance | CRIT | Delivers | SHERPA Week convenes security, legal, and engineering on-site with an ON2IT CISO + Enterprise Consultant. |
| PA5 | Prepare for continuous patching | CRIT | Delivers | 24×7 Global SOC triages disclosure waves; AUXO™ orchestrates change without breaking ZT policy. |
| PA6 | Update risk models & reporting | CRIT | Delivers | SHERPA Week reframes board metrics around containment + recovery; Global SOC produces the evidence stream. |
| PA7 | Inventory & reduce attack surface | HIGH | Delivers | ZT Step 1 (DAAS / Protect Surface) and Step 2 (Transaction Flows), the methodology was built for this. |
| PA8 | Harden your environment | HIGH | Delivers | MDR Prevent Configuration pillar + ZT Steps 3-4: segmentation, egress filtering, phishing-resistant MFA, Kipling policy. |
| PA9 | Build a deception capability | HIGH | Delivers | Behavioral monitoring + IOC enrichment in Global SOC; native canary / honey-token tooling not yet productized. |
| PA10 | Build an automated response capability | HIGH | Delivers | MDR Prevent Expert IR pillar + AUXO™ SOAR + pre-authorized Global SOC playbooks. Customer reference: <2 hrs MTTC. |
| PA11 | Stand up VulnOps | CRIT | Partner | Continuous AI-driven vulnerability discovery delivered through the ON2IT partner ecosystem; integrated into the customer's MDR Prevent posture. |
MDR Prevent: three pillars do the heavy lift
The Mythos-Ready briefing repeats one message: harden, contain, respond at machine speed. That is exactly how MDR Prevent is built. The three pillars below sit inside AUXO™'s six management layers, so the same Zero Trust language is spoken in the boardroom, the change ticket, and the Global SOC.
Configuration
Hardening the platform: segmentation, egress filtering, phishing-resistant MFA, secrets rotation, dependency lockdown, software minimization.
→ PA7 · PA8
Zero Trust Policy
The Kipling Method applied to every Protect Surface, including AI agents as a new asset class. Bounds blast-radius before exploitation, not after.
→ PA3 · PA8
Expert Incident Response
24×7 Global SOC, Netherlands-sovereign, AUXO™-orchestrated. Pre-authorized containment playbooks execute at machine speed; humans handle the calls humans must own.
→ PA5 · PA9 · PA10
Zero Trust in five steps: the operating sequence
Kindervag's five-step methodology is not a marketing framing. Each step satisfies specific priority actions; the sequence is what makes the program executable rather than aspirational.
- Define the Protect Surface (DAAS). Identify the data, assets, applications, and services that matter most, including coding agents and other AI systems as a new asset class. Satisfies PA7, feeds PA3.
- Map transaction flows. Trace how the Protect Surface actually talks to the rest of the environment. Without this, segmentation is a guess. Supports PA7, enables PA8.
- Architect the Zero Trust environment. Place enforcement points where flows demand them: deep segmentation and egress filtering, both named in the Mythos-Ready briefing. Satisfies PA8.
- Create Zero Trust policy (Kipling Method). Who, what, when, where, why, how, for every flow, including agent-to-tool and agent-to-data calls. This is how PA3 ("Defend Your Agents") is operationalized. Satisfies PA3, PA8.
- Monitor and maintain (Global SOC). 24×7 detection, response, patch orchestration. Pre-authorized containment turns "human-speed defense vs machine-speed offense" into a service-level commitment. Satisfies PA5, PA10, partial PA9.
Four numbers. Not one of them is cost-of-breach.
Cost-of-breach figures describe the bill, and the bill arrives after the news cycle does. What matters before that is what you actually control: whether the fire starts, how far it spreads, what you can prove while it's happening, and how fast it stops.
Asset inventory, least-privilege, lateral-movement bounding, documented response, the four conditions present in 20+ breach simulations at Antwerp Management School, all addressed in MDR Prevent.
One compromise reaches one protect surface. Architectural guarantee, not a probability. The spread stops at the segmentation boundary.
Per protect surface, with traffic flows, policy drift, MTTD / MTTR. On demand. The evidence your auditor and your board are asking for.
Post-onboarding steady-state, with pre-authorized Global SOC playbooks. When prevention is bypassed, response is bounded.
"The next breach isn't a question of if. It's a question of how far it spreads, and whether the answer fits in a paragraph, or in a regulatory filing." — ON2IT
One week on-site: SHERPA Onboarding Week
SHERPA Onboarding Week is how we start. An ON2IT CISO and Enterprise Consultant come to you for five working days. We walk your stack, map your protect surfaces, find your exposures, and stand up a live AUXO™ view of your environment before the week is out. You don't leave with a report. You leave with a strategy, an exposure list, and momentum.
From → To
From not knowing where you stand, to knowing, and from standing still, to moving.
With you, all week
ON2IT CISO + Enterprise Consultant, on-site, five working days.
You walk away with
A documented Zero Trust strategy, exposure list, and live AUXO™ posture view.
Capacity, by design
Senior consulting time is finite. A limited number of SHERPA engagements run each quarter. Earlier requests get earlier slots.
Thirty minutes. We'll walk one of your protect surfaces with you.
Your board is asking. Your auditor is asking. Regulators are asking. Most organizations answer with a policy document or last quarter's audit. Documents describe intent, not state. AUXO™ does: every protect surface visible in real time, with traffic flows, policy drift, MTTD and MTTR.
The summer window matters. The Mythos frontier AI preview is rolling out this season. NIS2's first audit deadline is 30 June. Senior consulting capacity is limited each quarter, so earlier requests get earlier slots. Contact us at us@on2it.net.