The initial focus on faster patching—in the wake of the disclosure of frontier AI models such as Anthropic’s Claude Mythos—is giving way to a broader rethinking of exposure management, Accenture’s Jason Lewkowicz tells CRN.
Many businesses are moving beyond an initial focus on faster patching in response to surging vulnerability discovery by frontier AI models and are increasingly rethinking how to identify and reduce security exposures in a broader way, according to Accenture’s Jason Lewkowicz.
In the wake of frontier models such as Anthropic’s Claude Mythos and OpenAI’s GPT Cyber, models have shown that AI can be highly proficient at discovering vulnerabilities and exploits, experts have said. That has led to a surge in new vulnerabilities being discovered and disclosed.
For instance, Microsoft’s September security update included patches for more than 900 vulnerabilities—as compared to “Patch Tuesday” updates as recently as earlier this year, which often did not exceed 100 vulnerabilities in any given month.
However, in the months that followed Anthropic’s original disclosure of details about Mythos, the industry has increasingly recognized that accelerated patching is not the full answer to the challenge, said Lewkowicz (pictured), global lead for cyber resiliency and defense at Dublin, Ireland-based Accenture, No. 1 on CRN’s 2026 Solution Provider 500.
“In the beginning, it was probably 80 percent, ‘Let’s go patch faster and play whack-a-mole,’” he said. “Now it’s probably 80 percent in the bucket of, ‘Let’s really rethink our approach to this.’”
The assessment reflects a notable shift in conversations with customers since the introduction of Mythos, according to Lewkowicz.
Initially, calls from concerned clients had largely centered around how to patch vulnerabilities more rapidly as a way to address the fact that the models were identifying software flaws so much faster, he said.
“I was finding more clients spending time on wanting to patch faster, versus rethink their broad-stroke program,” Lewkowicz said.
However, as time went on—and with the help of Accenture—many customers have eventually come to see the limitations of that approach and recognize the need for a more sweeping change to their approach, he noted.
That is translating, for instance, into heightened interest among customers in approaches such as continuous threat exposure management (CTEM) and attack surface identification, as well as penetration testing and offensive security, according to Lewkowicz.
The shift does not, of course, eliminate the need to prioritize vulnerabilities and patch as quickly as possible, he said. But it significantly broadens the overall objective, to now include goals around reductions in the volume of recurring problems—as well as in continually being able to demonstrate that the security program is working, Lewkowicz said.
All of this helps to explain why more customers are now willing to reconsider their overall approach, he said.
Ultimately, “there are tangible, valuable outcomes [available]—that if we do it right up front, it will pay for the program in the long term,” Lewkowicz said. “So I remain very encouraged.”






