How Mythos changes the assumptions underpinning Australia's banking regulations
By Niraj Naidu, Head of Sales Engineering A/NZ, Rubrik
Thursday, 23 July, 2026
Anthropic’s release of Claude Mythos Preview earlier this year has completely changed cybersecurity’s rules of engagement. While every industry is impacted, the consequences are most pronounced in financial services.
The frontier model was unlike anything that had come before it, capable of identifying and exploiting vulnerabilities so quickly that defenders would have almost no time to respond.
Shortly after its release, Australia’s Prudential Regulation Authority (APRA) issued a call to arms to the local banking sector. APRA’s letter warned of a step-change in how Australia’s financial services industry manages AI-related risk and that “AI models such as Anthropic’s Claude Mythos … are expected to further increase the probability, speed and scale of cyber attacks.”
Following APRA’s warning was an equally urgent missive from the leaders of the Five Eyes cybersecurity agencies. These agencies did not mince their words; “The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats.”
These agencies are not prone to hyperbole. Against these warnings, Australia’s financial sector organisations must urgently review their adherence to APRA’s operational risk standard — CPS 230 — as tolerance statements written under the regulation in the past 12 months no longer reflect reality.
Seeing CPS 230 in a new light
CPS 230 came into force on 1 July 2025. It requires APRA-regulated entities to identify critical operations, set tolerance levels for maximum disruption, and demonstrate the ability to operate during severe but plausible scenarios. Maximum tolerable downtime, data loss and degradation are now board-attested numbers.
The implicit model behind most tolerance statements assumes an attacker gains initial access, there is a dwell period (typically days or weeks), detection occurs, containment follows, then recovery begins.
Mythos invalidates all these numbers. An attacker with access to a frontier AI model does not need weeks of careful reconnaissance to map an environment. The reconnaissance, exploit development and lateral movement can collapse into a single operation. Months and days become hours, minutes or just seconds.
Today’s new shot clock requires a new approach. You cannot patch your way out when attackers can find new vulnerabilities faster than vendors can ship fixes. The defensive posture must shift from a focus on prevention to one that prioritises recovery.
Redefining compliance assumptions
Understanding whether CPS 230 compliance is adequate in a post-Mythos world requires organisations to answer four critical questions:
- Does our dwell-time assumption account for AI-accelerated attacks? The assumption in most tolerance work is that detection happens before significant damage. When exploitation can outpace detection, tolerance must be sized against worst-case recovery scenarios.
- Have we tested a recovery scenario where the attacker was already inside our retention window? The question alone quietly breaks most existing resilience programs: if a sophisticated attacker established access months ago, every restore point may carry their payload and risk reinfection. Mitigating against this requires the ability to interrogate backups for indicators of compromise before restoring, and to recover to a known-clean state.
- How dependent is your recovery on the same vendors in your production environment? If your production environment and recovery environment depend on the same hyperscaler, the same identity provider and the same endpoint agent, then a compromise in one place takes all out simultaneously. Both the APRA and Five Eyes warnings also call out this risk.
- How do we measure time and does it reflect reality? The attacker’s clock now runs in seconds, but the recovery clock still runs in days. The gap between the two must be addressed.
What this means for the next 12 months
Vulnerabilities existed before Mythos. What has changed is the cost of finding and exploiting these weak points. We may have been given a head start with Anthropic’s release, but the capability will diffuse.
Over the next 12 months, defensive architectural decisions will need to be made before the asymmetry that Project Glasswing temporarily granted defenders evaporates. The work includes compressing recovery time, hardening identity, reducing blast radius and avoiding vendor concentration in recovery and production.
CPS 230 already asks for most of this. The post-Mythos threat model changes the urgency and demands a faster clock.
Securing the new financial year: prioritising autonomous cyber defence
As Australian businesses enter a new financial year, they need to evaluate their security...
Australia is building AI faster than it can secure it
The pace of AI adoption is being set by competitive pressure and internal demand, and security is...
Why Australia's ransomware spike misses the bigger story
The apparent rise and fall in Australia's ranking tells a broader story about how ransomware...
