Through NIS2, DORA, and the GDPR, the EU has established a regulatory framework of Acts and Directives – complete with a system of financial penalties to compel companies to build greater operational resilience. To date, fines totalling nearly €6 billion have been imposed for GDPR violations – an increase from just under €5.5 billion as of May 2025. NIS2 and DORA will govern enforcement through a similar penalty-based mechanism, with one key distinction: corporate executives themselves may be held personally liable, potentially risking their own assets. The first high-profile cases involving NIS2 and DORA are anticipated to emerge soon.
Unfortunately, a rise in such incidents is to be expected, given that the advent of AI modelshas fundamentally shifted the landscape of security risks. Claude Mythos, if the hype is to be believed, possesses the capability to autonomously identify previously undetectedvulnerabilities within IT systems and to chain together security flaws to exploit them. Since almost every company processes personal data, threat actors can use such AI-driven attacks to breach systems faster and on a larger scale. Open-source software, in particular, appears to be an Achilles’ heel, as Mark Surman explains in a commentary for The New York Times.
Mythos discovered a DoS vulnerability in OpenBSD – an operating system widely regarded as the most secure in the world – that had lain dormant for 27 years. A 16-year-old flaw was also detected in FFmpeg, a widely used video processing tool. According to Anthropic, the specific line of code in question had already been scanned five million times by other automated security tools without the vulnerability being detected. These cases serve as a powerful demonstration of both the capabilities of Mythos and the inherent vulnerability of these systems.
Cybercriminals will undoubtedly develop their own AI tools to enhance the sophistication of their attacks – part of the reason Mythos was held back from full public release. Phishing attacks, in particular, will become more highly personalised and specifically designed to harvest the credentials of internal users. Indeed, even today, nine out of ten cyberattacks are orchestrated by exploiting identities and identity management systems.
Finally, the use of AI presents a temptation for employees themselves. Many employees feed internal corporate data into models provided by external vendors without a GDPR-compliant Data Processing Agreement (DPA) being in place.
One of the most stringent requirements within regulatory frameworks is the mandatory reporting of cyber incidents. The GDPR mandates that data breaches be reported within 72 hours of the organisation becoming aware of it. NIS2 and DORA require affected companies to report severe cybersecurity incidents – should they occur – within 24 hours, and within 4 hours if classified as major in the case of DORA.
Companies should therefore make it a priority to implement automated processes to gain a comprehensive understanding of their data assets and to categorise critical data accordingly. Even more importantly, a company must remain operationally capable in the event of a crisis– even while an attack is actively underway.
To achieve this, they should adhere to the concept of the “Minimum Viable Company.” In this concept, they precisely define – in advance – which infrastructure, systems, applications, processes, and environments are absolutely essential for maintaining emergency operations. This minimal package is then securely stored in an isolated environment, ensuring it remainsuntouched by threats.
In the event of an attack, this emergency package is activated within an isolated “cleanroom,” from which the IT security and infrastructure teams can securely rebuild and redeploy the production environment – while simultaneously investigating the attack itself, the compromised data, and any back doors.
Only those capable of acting immediately and pivoting directly into analysis will be able to meet the strict regulatory reporting deadlines. Incidentally, companies that are not prepared in this manner take an average of 24 days to restore full operational capability following a cyberattack – 24 days against a regulatory requirement of just 24 hours.
Should unknown vulnerabilities be uncovered on a large scale – whether through Mythos or other models – attackers could exploit them to slip past all established security and defensebarriers, thereby successfully compromising the company.
It will be essential to contrast these automated processes with workflows that mitigate the consequences of a successful attack and restore systems in a structured manner.
These processes for greater cyber resilience are called ResOps. This organisational discipline firmly anchors resilience in daily operations. It moves organisations away from passive, reactive backup strategies toward an active, continuous model. ResOps addresses one central question: Can the teams maintain the operational stability of their systems, and where they can’t, can they restore every critical service right now – with complete certainty and verifiable proof?
This discipline brings together teams from security, infrastructure, business, and operations around a common goal: to identify the organisation’s Minimum Viable Business (MVB) –those critical systems, data, and processes that are essential for business operations – and to ensure that these services can be operated and restored quickly and cleanly after a disruption.
AI will also help automate these processes in a positive way, thus restoring the balance with the capabilities of attackers. The power of LLMs plus large-scale automated security tooling is key to a safe secure and resilient future. However, leaders should embrace this ResOpsstrategy. Otherwise, the company is likely to contribute to the GDPR, NIS2 or DORA damage statistics. A purely defensive strategy is no longer a viable option on its own and has proven –frequently and publicly – to be prone to failure. ResOps, operating hand in hand with a strong defence, are key to the future success of business operations.

