1Password reposted this
Security was built for a world where developers were the bottleneck. Humans wrote and reviewed code, then deployed it and found the bugs. AI is removing the human bottleneck constraint. Now an engineer can generate in an afternoon what used to take weeks. At the same time, attackers can use the same tools to find and exploit vulnerabilities faster. The gap between how fast systems change and how fast security adapts is widening. That’s one of the ideas explored in AIUC-1’s latest paper, After Mythos: Defending at Machine Speed, which I was fortunate to contribute to. My contribution focused on a simple question: what does “assume breach” mean when systems, identities, and permissions are changing continuously? At the end of the day, it comes back to identity and access. If an identity is compromised, does the blast radius stay small? Are permissions scoped tightly enough to prevent lateral movement? Can you tell whether the controls you put in place six months ago still reflect reality today? What is changing is the rate of change: agents add more identities, more delegated access, and more automation. The underlying challenge remains the same: understanding who can access what, under whose authority, and then making sure that those assumptions still hold at any given point in time. Thanks to everyone who contributed to the paper, and especially Lena Smart for pulling me into the discussion. Mandy Andress, Neil Bennett, Manfred Boudreaux-Dehmer, David Campbell, Rajiv Dattani, Jen Easterly, Lars Falch, Bil Harmer, CISSP, CISM, CIPP, Erik Hart, Jimmy Heschl, Matt Hillary, Mark Hillick, Heather Hinton, Simon Hodgkinson, Rune Kvist, Dr. David Mussington, Daniel Nuñez, Kevin Powers, Rajiv Singhal, Phil Venables, Dan Walsh, Adeel S., Craig Weatherhead, Min Xu Ph.D, CISSP, Tom Zick, PhD., Emil Bender Lassen, Abby Shen, Scott Roberts, John I., Amyn Jan., Katie Jenkins, Louise McElvogue, Omar Khawaja, Santosh Kumar, Xabier Muruaga, Rinki Sethi Ravi Soin ...and many more