Summary
- Frontier AI models could accelerate vulnerability discovery, reducing the time organisations have to identify and remediate weaknesses.
- Resilience operations, or ResOps, centre on continuously testing and validating recovery capabilities rather than relying on backup technology alone.
- Defining a Minimum Viable Company can help organisations establish which systems and services must be restored first to maintain essential operations.
Frontier AI models such as Mythos and GPT-5.5 Cyber currently represent the absolute cutting edge of security tech. Their capabilities have attracted so much attention that the US government took the unprecedented step of temporarily restricting foreign access to some of these models, citing national security concerns.
As we all know, ‘transformative’ is a word that is thrown around quite easily across the global technology ecosystem, but in this case, it’s fully justified. Fundamentally, these models have the potential to dramatically accelerate vulnerability discovery and reduce the already short time organisations have to respond before weaknesses are exploited.
On the flipside, they also offer huge opportunities to strengthen cyber resilience by helping defenders identify vulnerabilities earlier, giving them more time to remediate them before they can be exploited. As ever, AI brings both opportunities and risks.
As many AI organisations race to develop their own frontier capabilities, access is likely to remain concentrated among the largest organisations with the greatest financial resources because these models are exceptionally expensive to develop and deploy. This raises questions about whether exclusion from early access programmes could create a resilience gap. Critically, this is not only about missing out on the technology itself, but also losing the opportunity to understand how existing security processes, governance structures and recovery plans perform when exposed to AI-driven vulnerability discovery at unprecedented speed and scale.
The most recent reported Hugging Face incident is a case in point. Despite being designed as an isolated testing environment, the AI models reportedly identified and exploited an unintended pathway out of their environment. The lesson is not that advanced AI systems cannot be controlled, but that even carefully designed safeguards can leave unexpected weaknesses. Organisations therefore need to prepare for a future where AI capabilities evolve faster than traditional security assumptions, and where resilience depends on the ability to detect, contain and recover when controls fail.
The role of ResOps
This raises a novel and important question: if the most advanced resilience capabilities become commercially inaccessible to some, does cyber resilience itself risk becoming something only large enterprises can realistically achieve?
It’s certainly a risk, but the emergence of these latest models also serves as an important reminder that, for most organisations, there is still significant scope to improve resilience if, for whatever reason, preventative measures fail.
Rather than viewing resilience as something that depends on emerging AI capabilities, organisations should ask what practical steps they can take today to minimise operational disruption following a cyber incident. Ultimately, operational preparedness is what separates organisations that recover quickly and cleanly from those that experience prolonged disruption.
For instance, many organisations still think about resilience primarily in terms of backup technologies or recovery products. Yes, these are absolutely key, but this mindset can create a false sense of security (pun intended) because owning recovery technology is not the same as being able to recover successfully under real attack conditions.
True recovery capabilities that deliver when desperately needed also rely on planning, continuous testing, validation and understanding how critical business services depend on one another. This is more formally characterised as resilience operations, or ResOps, which focuses on continuously validating recovery capabilities so organisations know they can recover when it matters most.
For example, imagine two organisations hit by the same ransomware attack. Both have backups, but only one knows exactly which systems need to be restored first and has already validated its forensics, cleaning, and recovery procedures. The other still needs to establish system dependencies and work through recovery decisions while the business remains offline and before it can resume operating. The difference between the two has very little to do with the technology they own and everything to do with how well prepared they were before the attack occurred.
Establishing a Minimum Viable Company
So, preparing for frontier AI and everything it seems likely to bring requires organisations to think differently about resiliency & recovery. They should regularly assess whether their recovery posture reflects the speed of modern attacks, looking beyond the existence of backups to whether critical systems can be restored cleanly. Isolated, immutable recovery environments should become a baseline assumption, not least because they provide a trusted fallback when remediation cannot keep pace.
The key is knowing what matters most to keeping the organisation operating. One of the first practical steps is defining the organisation’s Minimum Viable Company (MVC) status, which is the smallest combination of systems and services needed to keep the business operating after an incident. The objective is to restore those capabilities that allow the organisation to continue serving customers and carrying out its most important activities, and that might be different from restoring absolutely everything at the same time.
Defining the MVC requires organisations to identify important business services, impact tolerances, map dependencies between systems before an incident occurs, so they can avoid having to make mission-critical recovery decisions under pressure. Components typically include identity services, operational databases, communications platforms, finance or billing systems and other applications essential to day-to-day operations. These will vary from one organisation to another.
Depending on the degree of integration, it may also be necessary to determine whether AI-related components such as data pipelines or agentic workflows have become operationally critical. The point is that the MVC parameters should evolve alongside the business rather than remain static. It stands to reason that organisations that have identified and validated their MVC are generally able to restore essential operations more quickly because recovery priorities have already been agreed. Add to that a renewed focus on what being resilient actually means and organisations are already in a much better position to cope with whatever frontier AI-powered threat actors have to throw at them.




