ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Recruitment is the defence Mythos just exposed

Daniel Spicer at Ivanti explores the possibility of redirecting teens and displaced workers away from underground marketplaces and instead using their skills more constructively

Linked InXFacebook

A big factor is missing from the recent Glasswing/Mythos chatter.

 

Anthropic now claims one of its AI models can find zero-day vulnerabilities in every major operating system. Since this reveal, I’ve heard a lot of talk about defensive responses. There are certainly technical elements in play, but the missing factor is people: who we hire, how we train them and whether we are willing to compete with criminal recruiters for the same talent.

 

Mythos identified a 27-year-old flaw in OpenBSD in a single prompt. About forty organisations have early access to it through Project Glasswing. The rest of the UK security industry will see the downstream effects – sooner exploits against the same backlog of unpatched flaws – without the tool to help defend.

 

Offence has always moved faster than defence, but the comparative rate is changing. For serious flaws, the window between disclosure and exploitation is now measured in hours. Microsoft’s own statement about joining Glasswing says that what once took months now takes minutes.

 

More vulnerabilities mean more decisions

Every vulnerability Mythos surfaces produces work for the security teams that have to deal with it: triage, prioritisation against existing backlogs, patch testing and conversations with business unit owners about timing. That work doesn’t get any easier when more vulnerabilities surface and the teams handling it are already short-staffed.

 

That is why AI should be framed as a force multiplier, not workforce replacement. Automated patching can execute a task on schedule, but deciding whether to patch now, defer until after quarter close or accept temporary exposure is a business judgment call – specifically a human judgement call. Those decisions depend on context, trade-offs and institutional knowledge. In practice, that makes investment in people more important, not less, because organisations still need to train junior analysts so they can become the principal-level talent capable of making those calls at scale.

 

We are filtering out the people we need

ISC2 estimates a global shortage of 4.8 million cyber-security professionals. That figure gets quoted in every workforce article. Less often quoted: why the shortage persists when technically skilled young people are sitting in every secondary school in the country.

 

The reason is the filter we apply. Standard security job postings ask for a computer science degree or near equivalent, industry certifications that cost money and time most young people do not have, and two or three years of relevant experience for what is nominally an entry-level role.

 

That filter screens out the self-taught kid who has been taking things apart since they were a toddler – the one who knows more about a particular protocol’s behaviour under stress than most graduates, but who lacks the credentials a hiring manager has been told to require.

 

Criminal recruiters do not use this filter

The NCA’s pathways research found the median age of referrals to its cybercrime prevention team is 15, with children as young as nine caught launching DDoS attacks. Around 61 per cent of UK cyber-offenders began before age 16.

 

Criminal enterprises are recruiting from the same talent pool legitimate security teams need, and they are recruiting earlier. The pitch does not require certifications or degree transcripts. It offers money, status within the group and an immediate sense that the technical work matters. That’s an effective first offer, especially if it feels like the alternative is an entry-level role that will only open up after expensive, lengthy training.

 

This is why, even before the latest conversation got underway, I’ve argued that a curriculum taught by ethical hackers, embedded in schools, with paid mentorship and a direct route to legitimate work is the structural fix. Mythos accelerates the case for it.

 

How to improve recruitment

Drop the credential filter on entry-level roles. Demonstrated capability – a take-home challenge, an evaluated CTF exercise, a portfolio of legitimate research – should be sufficient evidence. Certifications have their uses; they are weak proxies for what an analyst can do at the entry level.

 

Pay mentees. Ethical hackers and senior practitioners should be running structured programmes inside schools and apprenticeship routes, and the teenagers learning from them should be on a stipend. Legitimate work has to compete with illegitimate offers on pay, not principle.

 

Hire for trajectory. A candidate who taught themselves to write exploits at 14 and spent five years probing systems no one assigned to them is precisely the analyst worth bringing in. The hiring conversation should make room for what someone can already do.

 

Don’t underestimate talent supply

Again, most of the conversation about Mythos focused on which organisations have early access and which do not. Access matters for the immediate window. The longer game is decided by something else.

 

Specifically, it is decided by who builds the human capability to operate at the speed AI-discovered vulnerabilities now require. That effort – recruitment, training and retention – is where the industry has been losing to hackers for years.

 

This talent shortage predates Mythos. Mythos has only made every other failure to address it more visible. We can keep posting job adverts that filter out exactly the people we need, or we can do the work to bring them in. The skills exist. Where they end up – that is on us.

 


 

Daniel Spicer is VP of Security and CSO at Ivanti

 

Main image courtesy of iStockPhoto.com and AndreyPopov

Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543