google.com, pub-8701563775261122, DIRECT, f08c47fec0942fa0
Hollywood News

Banks, telcos take test to check cybersecurity score

Mumbai: Essential service providers such as banks, telecom operators and power companies have started stress testing their codebases to prepare for a potentially wider launch of Anthropic’s Mythos model in the next six-seven months.

Their concern is the unprecedented ability attributed to the currently restricted-access AI model to discover serious software vulnerabilities, which could enable large-scale cyberattacks and potentially disrupt critical services.

Executives and advisors told ET that companies are testing their public assets using existing AI models such as Opus 4.7 and GPT 5.5 and have also asked their suppliers to identify possible gaps.

The Data Security Council of India (DSCI), an industry think tank affiliated with software industry body Nasscom, is helping organizations prepare for this challenge.

DSCI has launched a sandbox environment where they can use generative AI models to evaluate them for potential vulnerabilities and data privacy risks.


“Organizations are actively strengthening their cyber hygiene to prepare for AI-driven threats by reducing attack surfaces, adopting micro-segmentation, improving identity and authentication systems,” DSCI CEO Vinayak Godse told ET.
Anthropic stated that it will launch the model soon. Expecting it to be available in about six months, experts say cybercriminals can exploit vulnerabilities faster than organizations can fix them. They also point out that there is a serious shortage of cybersecurity talent needed to tackle the rapidly evolving threat.

Banks and telcos take tests to check cybersecurity score

‘Collaborative Governance’

Anthropic’s latest update to Mythos, announced last week, alarmed chief information security officers (CISOs) due to the system’s unprecedented speed at detecting vulnerabilities in the software.

Mythos detected 23,019 vulnerabilities in just one month. Only 97 of them were patched, as it took cybersecurity experts an average of 14 days to fix each bug.

“The global cybersecurity landscape is evolving at an unprecedented pace, introducing new and increasing risks,” said Srikanth Velamakanni, CEO of AI services firm Fractal Analytics and chairman of Nasscom.

“Systems like Mythos show that releasing high-capacity models without tight security frameworks can pose serious national security threats. But simply trying to contain AI development is not a viable long-term solution; we need proactive, collaborative governance,” he said.

DeepSeek or OpenAI’s Mythos-enabled models are also expected to hit the market within three to six months, according to the researchers.

Experts warn that this could bypass traditional cybersecurity infrastructure and expose critical national systems in sectors such as banking, telecom, healthcare, cloud infrastructure and energy networks.

Slow cyber readiness

As risk increases rapidly, the talent gap, especially in markets like India, is causing organizations great concern about ensuring cyber readiness.

“The scale and speed with which systems like Mythos can detect vulnerabilities is fundamentally changing the threat landscape for banks,” said the CISO of a large private sector bank. “Previously it would take cyber attackers weeks or months to detect exploitable vulnerabilities, now AI models can compress that window into hours.”

He added that the concern is not about discovering vulnerabilities, but about the widening gap between detection and remediation.

“Banks still rely heavily on manual patch management cycles, legacy infrastructure dependencies, and fragmented supplier ecosystems,” he said. “If offensive-level AI capabilities become commoditized over the next few months, the industry could face a situation where attackers can weaponize vulnerabilities faster than organizations can fix them.”

Another CISO with a state-run lender said Indian banks already operate in an environment where there is a significant cybersecurity talent gap.

“Security teams were never designed to handle tens of thousands of vulnerability alerts at machine speed. The real risk is alert fatigue and failure to prioritize, where critical vulnerabilities in online banking, telecom integrations or third-party fintech systems remain unpatched because security teams become overwhelmed,” he said.

But discovering vulnerabilities in software doesn’t mean criminals can cripple the world’s digital infrastructure.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button