Every executive eventually asks some version of the same question. Sometimes it is about cybersecurity. Sometimes it is about financial controls, operational risk, compliance, or business continuity. The wording changes, but the intent is always the same. They want to know whether everything is okay. They want confidence that the organization has identified the important risks, addressed the significant weaknesses, and reduced the likelihood of unpleasant surprises. It is a reasonable expectation. Unfortunately, it is also one of the most expensive pursuits in modern business.
I remember sitting in a boardroom after the results of a security assessment had been presented. The report was positive. The organization had invested heavily in technology, training, and governance. Independent reviewers had found only minor issues. The leadership team was pleased with the outcome until the CEO asked a simple question. "So are we secure?" The room became quiet because everyone understood the problem. The assessment had provided useful information. It had demonstrated that many controls were working as intended. What it could not do was prove that nothing was wrong.
That moment is not unique to cybersecurity. The same conversation takes place after audits, compliance reviews, quality inspections, and financial examinations. Leaders are often seeking certainty, while the experts in the room know that certainty is not actually available. The best any organization can achieve is a higher degree of confidence. There is a significant difference between the two and understanding that difference changes the way risk should be managed.
The Cost of Chasing Assurance
Many organizations believe they are investing in risk reduction when they are investing in reassurance. The distinction matters because reassurance has no natural endpoint. A vulnerability assessment is completed, so another one is scheduled. An audit comes back clean, so management requests additional validation. A compliance review produces favorable results, but leadership still wants confirmation from another source. The cycle continues because every positive result creates confidence while leaving a small amount of uncertainty behind.
The challenge is that uncertainty can never be fully removed. There is always another scenario that could be tested, another system that could be reviewed, another consultant who could be hired, or another report that could be generated. As a result, organizations often find themselves spending increasing amounts of time and money pursuing a level of assurance that can never actually be achieved.
What makes this particularly difficult is that the effort often feels productive. Reports are produced. Findings are tracked. Metrics improve. Dashboards become greener. From the outside, it appears as though risk is steadily declining. Many organizations are simply becoming more efficient at measuring themselves. Measurement has value, but measurement alone does not create resilience.
The Mathematics of Risk
One of the realities of risk management is that proving the existence of a problem is usually much easier than proving the absence of one. If a vulnerability exists, someone may eventually find it. If a financial control fails, evidence will often emerge. If a process is broken, an audit can identify the weakness. The discovery may take time, but there is generally a clear outcome.
The opposite is far more complicated. How do you prove that no vulnerabilities exist? How do you prove that every control will function perfectly during a crisis? How do you prove that no employee will ever make a mistake or that no supplier will ever experience a disruption? The answer is that you cannot. You can gather evidence. You can conduct testing. You can increase confidence. What you cannot do is eliminate uncertainty altogether.
This creates a difficult economic problem. The cost of identifying meaningful risks is often finite. The cost of proving their absence approaches infinity. Each additional assessment may provide a little more confidence, but it rarely provides complete certainty. Eventually the investment required to gain a small increase in assurance becomes disproportionate to the value received.
When Good Metrics Create Bad Decisions
This dynamic is particularly visible in cybersecurity. A company conducts a vulnerability scan and identifies one hundred issues. The team works diligently to remediate every finding. A second scan identifies ten additional vulnerabilities. Those are addressed as well. A third scan comes back clean. At that point, many organizations celebrate because the metrics suggest success.
The problem is that the absence of findings is often mistaken for the absence of risk. A clean report does not necessarily mean an environment is secure. It simply means that a specific tool, operating under specific conditions, failed to identify any problems at that moment in time. That distinction may seem subtle, but it has significant implications for decision making.
The same issue appears outside of cybersecurity. Organizations frequently use audit scores, compliance ratings, assessment results, and operational metrics as proxies for resilience. Over time, leaders begin optimizing for the metric rather than the outcome. The goal shifts from improving the organization's ability to withstand disruption to proving that the organization appears healthy on paper.
Why Mythos Doesn't Change the Real Problem
The recent release of Anthropic's Mythos-class technology provides an interesting example of how easily organizations can become distracted by capability while missing the larger issue. Anthropic spent months limiting access to Claude Mythos through Project Glasswing, a program that allowed a small group of vetted organizations to use the model to identify software vulnerabilities at scale. According to Anthropic, participants discovered thousands of high and critical security flaws using the technology before the company released a public version known as Claude Fable 5 with additional safeguards in place.
Predictably, much of the discussion has focused on what this means for defenders and attackers. Will organizations now be able to find vulnerabilities faster? Will threat actors gain access to more sophisticated capabilities? Will software security become dramatically more difficult? The answer is probably not.
The uncomfortable reality is that organizations have never struggled because vulnerabilities were impossible to find. Most companies already have far more identified vulnerabilities than they can realistically address. Security teams routinely maintain backlogs containing hundreds or thousands of known weaknesses. Scanners generate reports faster than organizations can remediate them. Penetration tests uncover findings that remain unresolved for months. The challenge has rarely been discovery. The challenge has always been prioritization, remediation, and operational execution.
Mythos may accelerate vulnerability discovery, but accelerating discovery does not automatically improve security. In many organizations it simply increases the size of the queue. Finding one thousand vulnerabilities instead of one hundred does not reduce risk if the organization lacks the resources, processes, or discipline to address them. In some cases, additional visibility can create the illusion of progress while the underlying exposure remains largely unchanged.
This is where the conversation returns to the pursuit of certainty. New tools promise deeper visibility, broader coverage, and greater confidence. Leaders understandably hope that better technology will finally provide a complete picture of risk. Yet every improvement in visibility tends to reveal additional complexity rather than eliminate uncertainty. The closer organizations look, the more they discover.
Anthropic's release does not fundamentally change that equation. Whether vulnerabilities are found by human researchers, traditional scanners, or advanced AI models, the business problem remains the same. Organizations still have finite budgets, limited staff, competing priorities, and operational constraints. They still must decide which risks matter most and how they will continue operating when prevention inevitably falls short.
The real significance of Mythos is not that it changes the vulnerability landscape. It demonstrates how quickly the cost of searching for risk is approaching zero. What remains expensive is everything that comes afterward. Understanding impact. Making decisions. Implementing changes. Recovering from failure. Those have always been the hard parts of risk management, and they remain largely human problems.
As AI continues to make discovery faster and cheaper, the organizations that succeed will not be the ones that find the most vulnerabilities. They will be the ones that know which vulnerabilities matter and can recover when they miss one.
What Actually Matters
The organizations that perform best during periods of disruption rarely achieve that success because they eliminated every risk. They succeed because they built the ability to operate despite uncertainty. They understand that systems fail, employees make mistakes, vendors experience outages, and unexpected events occur. Instead of treating these realities as exceptions, they plan for them as part of normal business operations.
When a crisis occurs, customers do not care how many assessments were completed during the previous year. They care whether the company can continue delivering products and services. Investors do not focus on the number of controls documented in a policy manual. They focus on whether leadership can navigate the disruption effectively. Employees are not concerned with audit scores when systems become unavailable. They want to know whether critical business functions can continue.
These outcomes are measures of resilience, not measures of certainty. They reflect an organization's ability to adapt, recover, and continue operating when assumptions prove incorrect.
A Different Question
For many years, organizations have approached risk management by asking how they can prove that nothing is wrong. It is an understandable question, but it leads leaders toward an endless pursuit. There will always be another test to run, another assessment to perform, and another layer of validation to purchase. The search for certainty has no finish line because certainty itself is unattainable.
A better question is what happens if the organization is wrong. What happens if the vulnerability exists despite the scan? What happens if the supplier fails despite the review? What happens if the disruption occurs despite the planning? Those questions shift the focus away from prediction and toward preparation.
The most resilient organizations understand that uncertainty is not a problem to be eliminated. It is a condition of doing business. Their goal is not to prove that nothing is wrong. Their goal is to ensure that when something inevitably is, the organization can continue moving forward. That may not provide the comfort of certainty, but it creates something far more valuable: the ability to survive reality.
