Introduction: The Time for "Security" Norms to Change is Now
Is security really that important?""Are we safe if our company is a small/medium enterprise?"
If you have these questions, now is the time to read this article completely. AI technology evolution is fundamentally changing cyber attacks.
By reading this article, you can understand "what is happening" and "what specific actions companies should take." This is a major topic relevant not only to manufacturing or financial sectors but to all business professionals.
Radical Changes in Cyber Attacks Caused by AI "Mythos": Why Manufacturing Industry is Facing Crisis Now
The emergence of new AI "Mythos" developed by US artificial intelligence company Anthropic is causing significant upheaval across the entire industry. The fundamental premises for "security measures" that humanity has built are being rewritten
"What was the state of 'Traditional Security'?"
Traditionally, human hacking operations were conducted to launch cyber attacks. Understanding system environments and testing for vulnerabilities typically takes several weeks to months in general processes. Therefore, there has been recognition that "attack costs are too high, so small/medium enterprises don't get targeted."
"How AI Brought About Change"
Self-operating AI at Mythos level simultaneously and automatically executes screening, reasoning, and adaptation against countless targets.This dramatically increases attack speed and scale. Small/medium enterprises that were traditionally "not targeted" can now become entangled in automated attacks.<br
Furthermore, a manufacturing-specific problem is that they are highly integrated through ERP (Enterprise Resource Planning) systems or MES (Manufacturing Execution Systems) networks. Even small companies face risks if infiltrated, as the damage could spread to the entire supply chain. Companies like Toyota recognize the need to refresh their basic information security policies.
Specific Countermeasures Companies Should Take: "Containment" Becomes Priority
Anthropic and security experts are proposing actions that need to be taken immediately. Here's a summary of key points
- Completely grasp all devices within your company environment
First, confirm how much you understand about your security infrastructure. Check for hidden terminals or outdated systems.
- Completely grasp all devices within your company environment
- Accelerate applying patches (correction programs) to vulnerabilities
Rapidly responding to discovered weaknesses helps create conditions where attackers cannot exploit them. However, against AI there is no time buffer—attacks happen within minutes. - Verify that patches are being applied as intended
Even with countermeasures taken, they're meaningless if effects aren't confirmed. Audit systems need strengthening too. - "Containment" Becomes Priority: Contain Faster
Traditional security basics were "apply patches quickly (Patch Faster)," but against AI there's no time. Assuming infiltration, instantly restricting access to vulnerable paths or networks and stopping the bleeding is important.We'll explain this part in detail here.
"Why is 'Containment' Important? Technical Explanation"
To fill the time gap until patch application, temporary access restrictions prevent damage expansion from occurring. If large companies cut off small/medium enterprises like this, Japan's once-strong manufacturing supply chain could collapse.<br
As Finance Minister stated there is "a crisis that exists right now," your company too will face these threats.
Additional Info: AI Security Future and What We Can Do
This technological innovation isn't just "hacking got faster." More fundamentally important is the changing relationship between "defense cost vs attack revenue.
Necessity of Security Investment
The defensive side cannot win without catching up with technological innovation."AI-based vulnerability discovery is far more efficient than traditional methods. Counteracting requires same-level measures.
Beyond excessive vigilance, note that basic concepts like "Information Security Basic Policy" need updating (considering 'security' as 'information security,' not just 'cybersecurity').


