Blog library

A collection of Protiviti blogs. 

No Audio

Blogs

June 24, 2026
6 min read

Vulnerability Management After Claude Mythos: How to Prioritise, Patch, and Reduce Exposure When Findings Spike

Within just a few weeks, Mythos has completely shifted how we talk about vulnerabilities. Instead of asking “How many new findings are there?” we’re now wrestling with a much more practical challenge: “When vulnerability reports start flooding in with increasing complexity, how do we maintain smart prioritisation, effective patching, and solid exposure management...
Build an AI and data literacy programme that supports EU AI Act compliance, strengthens governance, reduces risk and prepares your workforce for AI.
The European Union’s AMLA (Anti-Money Laundering Authority) consultation on the draft Customer Due Diligence Regulatory Technical Standards closed in May 2026. The final Regulatory Technical Standards (RTS) is expected to be submitted to the European Commission during the third quarter of 2026, ahead of the broader AML package becoming applicable in July 2027.
Within just a few weeks, Mythos has completely shifted how we talk about vulnerabilities. Instead of asking “How many new findings are there?” we’re now wrestling with a much more practical challenge: “When vulnerability reports start flooding in with increasing complexity, how do we maintain smart prioritisation, effective patching, and solid exposure management decisions?”If you’re managing a vulnerability…
In November 2022, ChatGPT 3.5 debuted, marking a major milestone for generative AI. Since then, new tools and models have emerged rapidly—bringing distinct capabilities and new security risks. As these technologies evolve toward more advanced reasoning and agentic capabilities, security leaders are evaluating what they could mean for vulnerability discovery, exploit development, and defense.
Exit planning has become a critical element of the third-party risk management lifecycle as organisations contend with a rapidly evolving threat landscape and increasingly disruptive events. Protiviti’s 2026 Executive Perspectives on Top Risks and Opportunities survey ranks third-party risk as the second-highest near-term global risk.These findings reflect growing vulnerabilities across complex vendor ecosystems.…
The organisations that thrive in 2030 will be those that treat talent development, AI integration and organisational agility as interconnected priorities requiring coordinated action today and careful consideration of implications.
On January 21, 2026, a platform-wide security update in Salesforce Marketing Cloud generated an issue that caused links in previously sent emails to stop working. Salesforce Security identified a vulnerability within Marketing Cloud Engagement and responded by deploying enhanced encryption across the platform. While this critical update strengthens data protection, it exposes a risk to organisations that requires…
Many financial and non-financial organisations are only now beginning to assess the impact of the Authority for Anti-Money Laundering (AMLA). AMLA marks a fundamental shift from Europe’s previously fragmented supervisory landscape to a single EU level authority with direct and indirect powers. AMLA’s Single Rulebook will apply uniformly across all 27 member states from 10 July 2027, establishing one common standard…
Finance organisations are at a pivotal moment. What began as AI experimentation for productivity is now becoming functional transformation, with Microsoft Copilot enabling finance teams to accelerate analysis, reduce manual effort and deliver higher value insights.
Last month, I wrote about how AI investments expose the cracks in your operating model. The response was clear: "We get it. But what does good actually look like?"Most organisations are approaching this backwards. They're automating tasks when they should be reimagining how work gets done. The difference? One saves you 10%. The other unlocks 10x potential.
Loading...