RSS Amplifier

Rob T. Lee's Sleep. Diet. Exercise. AI. · Apr 12, 2026

Mythos, entry-level job panic, and my new favorite word: apocalyptimist

0
Sign in to vote or save

Rob T. Lee · Rob T. Lee's Sleep. Diet. Exercise. AI.

Big week. Watching smart people get wrapped up in Mythos, workforce panic. But first -- Kate Marshall recommended a documentary called The AI Doc a few weeks back. They coined a word I’m stealing for every talk going forward: apocalyptimist. Apocalypse plus optimist.

That’s where most of us actually sit when we’re being honest. AI is terrifying and exhilarating in the same breath, and holding both of those simultaneously is uncomfortable, but that’s the reality.

Every day there’s some big news thing. This week it’s Mythos, autonomous exploit chains, another zero-day tsunami framed as the end of everything. But the same technology is letting doctors catch cancers on MRIs that specialists would have missed, and it’s about to make secure coding a realistic organizational practice instead of something we say we do but don’t.

Today the world is falling apart because there are 10,000 zero days on our doorstep. In six months, we might actually produce secure code. The apocalyptimist lives in both worlds. (Welcome. It’s uncomfortable here.)

Two things in this Substack: a signal and some noise.

It’s a polished rollout of something those of us in the industry have known for a long time: AI can find a massive number of zero days and vulnerabilities through fuzzing and code analysis. The capability is real. The packaging is new.

Flip the lens. If organizations had a much more efficient way to do secure coding without line-by-line analysis, that closes off most of the ways people break into systems.

Full vulnerability analysis could become routine. Taking your medicine, because now you actually have medicine to take. (Both things are true at the same time. That’s what makes this an inflection point, not a crisis.)

Anthropic delayed Mythos specifically because of cybersecurity implications.

That’s the first time I’ve seen anyone pump the brakes on an AI capability, and they chose cybersecurity. Not bioweapons. Not drug synthesis. Not autonomous weapons systems. Not the capability that lets someone engineer a more lethal COVID variant in their basement. Cybersecurity. (I genuinely want someone to explain that decision calculus to me over a beer, because I can’t make the math work.)

The same acceleration applies to drug therapies and bioweapons. We want to save a kid’s life from brain cancer, but we also don’t want that same capability creating lethal agents in the fridge next to little Susie’s Easy-Bake Oven.

That’s the nuclear proliferation debate, the gun control debate structure, on an exponentially faster timeline. And the industry isn’t prepared for how fast this conversation needs to happen. (We can’t pump the brakes if nobody agrees where the brake pedal is.)

I’ve been pulling at this thread for a while and I fault the industry. That massive “unfilled cybersecurity jobs” number everyone quotes? It came from surveys asking CISOs: “How many people do you need to do your job correctly?” Not “how many unfilled positions do you currently have?”

A CISO with 10 people says they need 30. That delta became the “workforce gap.” Nobody was funding those 30 positions. The actual number of unfilled, budgeted positions was micro compared to the number that got quoted. (Pay attention to how survey questions are phrased and you realize how those numbers were built.)

The real problem is a skills gap, not a headcount gap. You fight with the team you have, not the team you want. The only way to close that is continuous skill development, and the workforce survey data backs this up. Skill development reduces burnout, increases retention, and keeps practitioners concurrent with the threat landscape. Senior people who haven’t taken formal training in years are running on inertia, not current capability.

Doctors don’t become surgeons by starting in the mailroom. Lawyers don’t become partners by being paralegals for a decade. These fields figured out residencies and apprenticeships to take people from formal education to senior practitioner without requiring them to grind through every rung. Cybersecurity still runs on the “start in the SOC, move up” ladder, and AI is about to rip the bottom rungs off.

We need to adopt residency and apprenticeship models. Maybe tied to certifications, maybe requiring a two-year equivalency before moving into senior roles. The system exists in other professions. We’re not the unique snowflake we sometimes think we are. (I don’t have the exact mechanism yet, but the pattern is proven -- we just need to mirror it.)

Rob T. Lee is Chief AI Officer & Chief of Research, SANS Institute

Read the original on robtlee73.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.