On 8 April 2026, Anthropic introduced Claude Mythos: AI that autonomously finds vulnerabilities and builds the corresponding exploits. Available via AWS Bedrock and Microsoft Azure. The threat landscape has fundamentally shifted as a result.
01 — From guideline to liability
The 30-day patch window was a guideline. It is becoming a matter of liability. The model scans more than a thousand systems at once and builds usable exploits within 24 hours. The burden of proof shifts: patch within 72 hours and document who did it, when, and why.
02 — The new calculus
It is no longer about patching faster, but about being able to prove that you can patch.
03 — DORA sets four requirements
- Art. 5–16 (ICT risk management): the risk framework must be demonstrably up to date; the board is accountable for this itself.
- Art. 28–44 (Third-party providers): contracts with suppliers must be tightened; trust on paper is not enough.
- Art. 24–27 (Resilience testing): AI-driven attacks must become the standard in penetration testing and red teaming.
- Art. 19 (Incident reporting): the first report must be ready within 4 hours of classifying an incident.
Why this is different: the CISO versus the board
The CISO wants
- A workable patch window of 24–72 hours
- Tighter SLAs with third-party providers
- The mandate to take systems offline
The board wants
- Continuity and planning
- Predictable costs
- Services that keep running
Both are right. But the real solution demands that governance be redesigned — and that begins at board level.
The question for your board meeting
Will cyber sit structurally at your board table — or only make the agenda after the incident? Who has the authority to change that tomorrow? And: is that person already in place?
How VigIT People helps
We help healthcare institutions, governments and regulated organisations find the security leaders who make the difference — before the regulator comes knocking.
Get in touchMarc Magrijn MSc LLM CISM — marcmagrijn@vigitpeople.tech
Source: Anthropic announcement 08-04-2026 · Regulation (EU) 2022/2554 (DORA) · NIS2 · NEN 7510 · Cyberbeveiligingswet · ENISA aligned