Frontier AI Finally Gave Us a Reason to Fix the Fundamentals

There’s a lot of talk right now about the best way to prepare for the serious threat posed by frontier AI models, specifically regarding vulnerability management.

For years, everyone has been trying to meet the minimum security requirements set for their organisation. The problem is that those minimum security requirements came in the form of regulatory compliance guidelines that could be “met” with a yearly checklist assessment or covered by vague standards that were never updated as the threat landscape moved on without them.

It was never about exceeding expectations, just doing the bare minimum to avoid being negligent. But compliant doesn’t equal secure. A mature security posture is hard to achieve and expensive to run, which is why it’s rare. Without the right drivers and motivation, good security is not always a priority. A dream rather than a reality.

Today, things are very different; the drivers and motivation have arrived, and they look like frontier AI. Everyone is watching the model releases and trying to work out what each new one means for them. Sol, Mythos and Qwythos (at this point, I’m starting to think about beer and Gyros).

Meanwhile, businesses are asking, “What do we need to do to prepare for threats from frontier AI?”

The vendors are saying, “We’ve got everything you need!”

And the engineers in the back are yelling, “Just stick to the fundamentals and keep your money!”

The engineers are right, but the fundamentals have quietly changed a little in the past couple of years, and the most important one of them is the least glamorous. It is not a tool you can buy. It’s the discipline of knowing what a vulnerability actually means in your environment, rather than what the report says it means in the exec summary.

The score is a claim, not a verdict

Let's define the baseline fairly first, because CVSS deserves credit for what it is.

The Common Vulnerability Scoring System gives the industry a shared language. When someone says "it's a 9.8", every defender on the planet understands the rough shape of the problem without requiring a meeting. That is genuinely useful, and nothing that follows is an argument against scoring vulnerabilities.

The problem is what we do with the number. The CVSS base score describes a worst-case, generic system with the vulnerable component present, loaded, reachable, and consequential. It is a starting hypothesis, not a finding about you.

A CVSS base score is a claim about a system that isn’t yours. Reachability, preconditions, and blast radius are how you test the claim.

Run that test and the same headline number splits in two directions. Sometimes a screaming critical turns out to be unreachable in the way you have deployed it, and the week-long fire drill was avoidable. Sometimes a mid-tier "high" is, on the specific system it landed on, the worst thing in your tech stack. The score did not change. The environment decided the outcome.

So what do the fundamentals look like in the age of AI? Here’s my top 5:

  1. Know your attack surface, external and internal. That now includes the agentic systems your own business is deploying, along with the tool access and permissions handed to them. For many organisations, this is the fastest-growing part of the tech environment and the least documented.

  2. Risk-based prioritisation of defensive effort based on factors such as business impact, financial and operational impact, and sensitive data leakage. If this customer-facing application or trusted account is breached, can we detect it?

  3. Patch, patch, patch. Let prioritisation decide what gets the focus, not what gets patched at all. Then weigh reachability, targetability, and the preconditions that turn a moderate finding into a severe one (like that trusty old NTP server ;)).

  4. Measure how fast you can act. If frontier AI changes anything on the offensive side, it is tempo. Faster triage of disclosed vulnerabilities, quicker weaponisation, cheaper reconnaissance at scale.

  5. Fix identity. Initial access still mostly occurs via valid credentials, session tokens, and the service desk. That is also where AI-assisted attacks hit the hardest now. Least agency, Role-Based Access Control (RBAC), Phishing-resistant MFA, long passphrases, rotated keys, and shorter token expiry are all must-haves now.

None of this is cheap. Accurate asset inventory at enterprise scale is still one of the genuinely unsolved problems in our field, and anyone telling you the fundamentals are the budget option has not tried to deliver them. Doing reachability analysis properly means knowing your environment better than the adversary does, and that knowledge is expensive to build and expensive to keep current.

So the argument was never that good security hygiene costs less. It’s that the money is much better spent here than it is on a shiny new platform. Frontier AI did not hand us a new problem to solve with a new product. It handed us the motivation to finally do the old work well, and a shrinking window in which to do it.

Next
Next

Harness(ing) AI: From Raw Power to Reliable Output