Daniel Spicer at Ivanti explores the possibility of redirecting teens and displaced workers away from underground marketplaces and instead using their skills more constructively

A big factor is missing from the recent Glasswing/Mythos chatter.
Anthropic now claims one of its AI models can find zero-day vulnerabilities in every major operating system. Since this reveal, I’ve heard a lot of talk about defensive responses. There are certainly technical elements in play, but the missing factor is people: who we hire, how we train them and whether we are willing to compete with criminal recruiters for the same talent.
Mythos identified a 27-year-old flaw in OpenBSD in a single prompt. About forty organisations have early access to it through Project Glasswing. The rest of the UK security industry will see the downstream effects – sooner exploits against the same backlog of unpatched flaws – without the tool to help defend.
Offence has always moved faster than defence, but the comparative rate is changing. For serious flaws, the window between disclosure and exploitation is now measured in hours. Microsoft’s own statement about joining Glasswing says that what once took months now takes minutes.
Every vulnerability Mythos surfaces produces work for the security teams that have to deal with it: triage, prioritisation against existing backlogs, patch testing and conversations with business unit owners about timing. That work doesn’t get any easier when more vulnerabilities surface and the teams handling it are already short-staffed.
That is why AI should be framed as a force multiplier, not workforce replacement. Automated patching can execute a task on schedule, but deciding whether to patch now, defer until after quarter close or accept temporary exposure is a business judgment call – specifically a human judgement call. Those decisions depend on context, trade-offs and institutional knowledge. In practice, that makes investment in people more important, not less, because organisations still need to train junior analysts so they can become the principal-level talent capable of making those calls at scale.
ISC2 estimates a global shortage of 4.8 million cyber-security professionals. That figure gets quoted in every workforce article. Less often quoted: why the shortage persists when technically skilled young people are sitting in every secondary school in the country.
The reason is the filter we apply. Standard security job postings ask for a computer science degree or near equivalent, industry certifications that cost money and time most young people do not have, and two or three years of relevant experience for what is nominally an entry-level role.
That filter screens out the self-taught kid who has been taking things apart since they were a toddler – the one who knows more about a particular protocol’s behaviour under stress than most graduates, but who lacks the credentials a hiring manager has been told to require.
The NCA’s pathways research found the median age of referrals to its cybercrime prevention team is 15, with children as young as nine caught launching DDoS attacks. Around 61 per cent of UK cyber-offenders began before age 16.
Criminal enterprises are recruiting from the same talent pool legitimate security teams need, and they are recruiting earlier. The pitch does not require certifications or degree transcripts. It offers money, status within the group and an immediate sense that the technical work matters. That’s an effective first offer, especially if it feels like the alternative is an entry-level role that will only open up after expensive, lengthy training.
This is why, even before the latest conversation got underway, I’ve argued that a curriculum taught by ethical hackers, embedded in schools, with paid mentorship and a direct route to legitimate work is the structural fix. Mythos accelerates the case for it.
Drop the credential filter on entry-level roles. Demonstrated capability – a take-home challenge, an evaluated CTF exercise, a portfolio of legitimate research – should be sufficient evidence. Certifications have their uses; they are weak proxies for what an analyst can do at the entry level.
Pay mentees. Ethical hackers and senior practitioners should be running structured programmes inside schools and apprenticeship routes, and the teenagers learning from them should be on a stipend. Legitimate work has to compete with illegitimate offers on pay, not principle.
Hire for trajectory. A candidate who taught themselves to write exploits at 14 and spent five years probing systems no one assigned to them is precisely the analyst worth bringing in. The hiring conversation should make room for what someone can already do.
Again, most of the conversation about Mythos focused on which organisations have early access and which do not. Access matters for the immediate window. The longer game is decided by something else.
Specifically, it is decided by who builds the human capability to operate at the speed AI-discovered vulnerabilities now require. That effort – recruitment, training and retention – is where the industry has been losing to hackers for years.
This talent shortage predates Mythos. Mythos has only made every other failure to address it more visible. We can keep posting job adverts that filter out exactly the people we need, or we can do the work to bring them in. The skills exist. Where they end up – that is on us.
Daniel Spicer is VP of Security and CSO at Ivanti
Main image courtesy of iStockPhoto.com and AndreyPopov
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543