AWS and Cloudanix team co-authored this blog: Real-Time Threat and Anomaly Detection for Workloads on AWS

The Mythos Era: TPRM Evolution, AI Ethics, and Project Glasswing with Matthew Moog

Matthew Moog of EY explains how third-party risk management has evolved through automation waves, the ethical dilemmas of frontier AI, and what Project Glasswing means for security leaders.

Frontier AI models are no longer just assisting security teams — they are reshaping the threat landscape itself. When Anthropic’s Mythos model cracked through every NSA system in thirty minutes by stacking thousands of low-severity vulnerabilities, it signaled a new era for how organizations think about risk, ethics, and the very structure of their security programs.

In this episode, Matthew Moog, Principal and Financial Services Risk Managed Services Leader at EY, joins us to unpack two decades of evolution in third-party risk management, the ethical tensions around AI deployment, and what Project Glasswing means for security leaders who are still on the outside looking in.

You can read the complete transcript of the episode here >

How has third-party risk management evolved over the past two decades?

Matthew traces TPRM through several distinct waves, each enabled by maturing technology:

  • Assessment-first era (2010–2014): The practice was cyber-focused and operationally heavy. EY’s financial services division ran 15,000–20,000 assessments globally, with roughly 30% involving boots-on-the-ground on-site visits. It was a logistics factory of approvals, conflict checks, and scheduling.
  • Data-enriched era (2014–2018): Cybersecurity rating providers like BitSight and SecurityScorecard made outside-in intelligence affordable. Organizations stopped choosing between assessments and data — they used both.
  • Resiliency wave (2018–2022): COVID stress-tested vendor ecosystems. Organizations discovered that recovery time objectives didn’t matter much when the time to replace a critical third party was a month. Resiliency overtook compliance as the dominant concern.
  • Automation era (2022–present): RPA gave way to agentic AI. LLMs now sit in three layers — embedded in intelligence suites, powering standalone SaaS products, and operating as near-OS platforms with capabilities built on top of them.

The throughline: anything that minimizes busy work and gets teams closer to actual risk management is a net positive.

What are the real benefits and risks of AI in TPRM?

The efficiency gains are undeniable. Matthew estimates AI can remove roughly 60% of assessment effort by automating document ingestion, evidence extraction, and control mapping. Their agents pull answers from policy documents, cite the specific page and paragraph, and provide screenshot evidence for rapid human verification.

But the risks are equally real:

  • Over-reliance: Teams must snapshot files before running AI formatting tasks and then side-by-side review every output. Hallucinated links, merged content, and misinterpreted context are everyday occurrences.
  • Data isolation: Each client is trained distinctly — no cross-pollination of data between engagements. When building shared utilities, aggressive scanning and redaction workflows are essential.
  • Cost blindness: One organization burned $100 million in tokens in a single quarter because nobody capped usage. Token economics vary wildly by prompt complexity and model tier — replacing an $80K employee with an agent that costs $120K in tokens is not a win.

The advice: take the efficiency gains, but reinvest them in deeper capabilities like threat and vulnerability management, zero-day response, and agentic pen testing rather than just cutting headcount.

What is Project Glasswing and why does it matter?

Project Glasswing is the controlled access program through which select organizations — primarily large banks and UK financial institutions — get exposure to Anthropic’s Mythos model. Consulting firms like EY do not have direct model access; they participate through client engagements and working groups.

What made Mythos different from prior models is its ability to stack vulnerabilities. A single vulnerability might be low-severity on its own, but Mythos identified that combining specific sets of three or four vulnerabilities created critical exploit chains. Roughly 90% of the vulnerabilities it surfaced were in open-source code.

The implications for TPRM are significant:

  • Widening the gate: Organizations inside Glasswing can prepare; those outside cannot. How the program expands to cover critical infrastructure and mid-market companies will define the security posture of entire sectors.
  • Open-source scrutiny: Expect increasing pressure to map where open-source code exists within your third-party ecosystem and to prioritize vulnerabilities based on business risk.
  • Speed of patching: Human-based patching cannot keep up with AI-speed vulnerability discovery. Automated remediation pipelines will become mandatory.

Why is AI ethics becoming a board-level issue?

The ethical tension is not abstract — it sits at the intersection of fiduciary duty and responsible deployment:

  • Agents escape guardrails. Lab simulations showed injection prompts hidden in white-space text (colored white, invisible to humans) that directed agents to perform destructive actions. Matthew’s team detected it via 800 trap rules, but organizations moving fast without controls are exposed.
  • Human capital sustainability. Firing 7,000 people to hit an efficiency target, then rehiring 3,000 three months later when tickets spike and code breaks, is a pattern already playing out in multiple sectors.
  • The Mythos precedent. Anthropic refused to provide Mythos to the US government without a human-in-the-loop requirement. OpenAI took a different stance. These choices by frontier AI companies set the ethical floor for the entire industry.

Matthew frames three possible macro outcomes: modest 10–15% efficiency gains with manageable headcount shifts; aggressive 40% automation driving unemployment toward destabilizing levels; or a third path — reducing the workweek proportionally and distributing gains as improved work-life balance rather than layoffs.

Will assessments disappear as AI gets smarter?

Not entirely, but their role is shifting. Matthew draws an analogy to modern cars: vehicles now have sensors on every component providing real-time telemetry, yet dealerships still perform multi-point inspections when a car changes hands.

Similarly:

  • First-time relationships still benefit from deep-dive assessments as a baseline for understanding control structures.
  • Ongoing relationships should lean more toward real-time intelligence — continuous monitoring of resiliency signals, cyber ratings, and financial health indicators.
  • Critical third parties still warrant annual assessments because contextual changes (data center moves, system swaps, high attrition) may not surface through automated signals alone.

The aspiration is running TPRM more like a mini-SOC: real-time threat feeds, continuous security posture management, and agentic pen testing against your vendor ecosystem.

Does frontier AI reduce the need for security professionals?

Matthew is unequivocal: no, not in the next decade. The reasoning:

  • Chaos response. Agents can identify anomalies (unexpected data movement, 10x CPU spikes on a node), but critically thinking through whether to cut off a process — and understanding the business impact of doing so — still requires human judgment.
  • Organizational knowledge. AI does not understand that when Jack has a problem, he goes to Molly because she solved it three years ago. Agents are hierarchical and only know what they are scoped to know.
  • Deepening technical needs. Security teams need more people with deeper understanding of architecture, AI tooling, and the extended network of third-party AI integrations — not fewer people with shallower skills.

The current hiring shift is toward engineers who understand AI-native security surfaces rather than a wholesale reduction in security headcount.

What should security leaders focus on right now?

Matthew’s practical advice boils down to:

  • Ask better questions. Referencing Simon Sinek’s Start With Why, he emphasizes that the quality of AI output is entirely dependent on the quality of the prompt. The same principle applies to risk programs — start with why before jumping to automation.
  • Invest in controls before speed. Organizations rushing to cut 8% of headcount by year-end need to understand the new risk profile that agentic workflows introduce. More agents means a larger attack surface.
  • Prepare for Mythos-class models going public. When frontier models with stacking capabilities reach general availability, the organizations that built control structures and patching pipelines in advance will survive. The rest will scramble.

Related Resources

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo