Mythal
the brief
01/ 12 An operational brief

Autonomous remediation for critical infrastructure — closing the velocity gap.

A briefing for Infrastructure and Cybersecurity leadership on why human-speed vulnerability management has structurally broken, and what a fabric of twelve specialist agents — operating under a strict policy gate — does about it without compromising operational safety or audit integrity.

Prepared by Next-Era LLC · May 2026 · Press or PgDn to advance

02/ 12 The state of play

Two clocks. One losing.

Inside every large operator today, two clocks run side by side. One has accelerated dramatically in the last twenty-four months. The other has not moved.

↻ Discovery & exploitation

Machine-speed

  • 163 CVEs addressed in April 2026's Patch Tuesday alone
  • Hours between vendor patch and public proof-of-concept
  • AI-assisted patch diffing shrinks reverse-engineering from weeks to a single afternoon
  • KEV catalog grows faster than CISA can publish
→ Defender response

Human-speed

  • 22 days average mean-time-to-remediate for IT assets
  • 15 analysts typical patch-management team — flat for five years
  • 4-hour windows for OT firmware, twice a year
  • Change advisory boards meet weekly, queue depth grows monthly
This gap is now the largest unhedged risk on the modern CISO's balance sheet.
03/ 12 Why this matters now

What changed in the last twenty-four months.

A specific technology shift broke the old equilibrium. Three velocities moved at different rates, and the slowest one now governs the outcome.

Discovery went machine-speed
AI tools diff vendor patches against unpatched binaries and reconstruct the underlying vulnerability in hours. Auditing large open-source codebases at scale flags exploitable patterns.
Exploitation went machine-speed
Public proof-of-concept exploits arrive within days of a vendor advisory. Ransomware operators automate target selection from KEV listings.
Response stayed human-speed
Same analyst headcount. Same ticket queues. Same change advisory boards. Same scarce maintenance windows on the OT side.

When two of three speeds change and the third does not, that third becomes the constraint that defines every operational outcome.

04/ 12 The problem, in numbers

Where the time and the risk go today.

Average IT MTR
22 days
discovery to verified fix
CVEs / Patch Tuesday
163
April 2026 alone
Sec-ops headcount growth
0%
5-year baseline
Breaches via known CVE
87%
Verizon DBIR 2025
OT maintenance windows
2 / yr
~4 hours each
Avg breach cost
$4.88M
IBM cost of a data breach 2025
Twenty-two days is also the average duration the asset spends vulnerable. The MTR is the breach window.
05/ 12 The legacy choreography

How a single patch moves through your organization today.

Day 1

Scanner detects the CVE

Qualys / Tenable / Defender flags the finding overnight. Enters a queue.

Day 2–3

Analyst triages

An engineer reads the advisory, checks vendor PSIRT, opens a ticket in ServiceNow.

Day 4–7

Asset owner research

Identify affected assets, confirm versions, decide cohort strategy.

Day 8–14

Change advisory board

Weekly CAB meeting. Approvals gathered. Rollback plan documented. Maintenance window selected.

Day 15–21

Maintenance window

02:00–06:00 nightly canary ring. Wave promotion. Watch for collateral damage.

Day 22

Verify · close · file evidence

Rescan. Update ticket. Manually copy reasoning into the audit log for next year's TSA review.

06/ 12 The blast radius

What is actually at stake when the clock loses.

IT

An outage you reboot from

Email, internal portals, finance systems. Painful, recoverable. Postmortem on Tuesday.

OT

An outage you do not reboot from

A misapplied firmware update on a track switch, a substation RTU, or a pipeline valve. Physical consequence, not informational.

CCS

A regulator's investigation

TSA SD 1580-21-01 mandates remediation timelines and segmentation for Critical Cyber Systems. A breach is a board-level event.

MULTI-ZONE

A national-level incident

Lateral movement from corp IT through an industrial DMZ into PTC infrastructure. The kind of event Congress holds hearings about.

07/ 12 The proposition

We close the loop. You keep the controls.

A fabric of twelve specialist agents, orchestrated by a Supervisor, sitting above the security tools you already own. Each agent performs one job and emits a signed handoff. A strict policy gate sits between every decision and any side effect.

↘ INPUT

Watches every scanner you own

Qualys VMDR, Tenable.io, Rapid7, Wiz, Microsoft Defender VM. Claroty xDome and Nozomi on the OT side. Scanner-agnostic by design.

↘ INPUT

Correlates every advisory

NVD, CISA KEV, EPSS, vendor PSIRTs, ICS-CERT, GitHub Security Advisories, pre-disclosure feeds for entitled tenants.

↗ OUTPUT

Plans, gates, and applies fixes

Ansible, SCCM, Tanium, Panorama, AWS Systems Manager, Azure Arc, OT-native vendor tooling. Drives what you already deploy.

↗ OUTPUT

Audit evidence as a byproduct

Every closed fix generates a control-tagged evidence unit. PDF + machine-readable bundle. Auditor-ready.

A fabric above your tools — not another tool to procure.
08/ 12 Defining the term

"Agent" — defined for this room.

The word means many things in the technology press. In this platform it has a precise definition that should be reassuring rather than alarming.

An agent IS

A small program with one job

It reads a typed input, produces a typed output, optionally consults a language model for one specific decision, and emits a signed audit record. Like a well-named function with a docstring.

An agent IS NOT

A chatbot

No free-form conversation. No open-ended prompts. Every interaction is bounded by a schema the next agent expects. Reading the trace is reading structured records, not chat logs.

An agent IS NOT

Autonomous

A deterministic policy gate sits between every agent decision and any side effect. The gate denies actions that violate the seven default rules. The agents propose; the policy disposes.

Twelve specialists with signed handoffs. The reasoning trace is the audit log — same artifact for both audiences.
09/ 12 The closed loop

What happens between discovery and verified fix.

01
Discovered
Scanner Liaison ingests + normalizes
02
Enriched
Threat Intel adds KEV · EPSS · exploit signals
03
Prioritized
Patch Hunter · Impact Analyst · Change Risk
04
OT review
OT Safety Officer veto or pass
05
Planned
Remediation Planner emits runbook + rollback
06
Approved
Policy gate · auto-apply · or human approval
07
Executing
Executor drives Ansible · SCCM · Panorama · OT
08
Verified
Verifier · rescan · health · exploit retest
09
Closed
Compliance Reporter emits evidence
+
Inventory sweep
12th agent runs continuously in parallel
A
Rolled back
Verifier reject — escalated
B
Escalated
Beyond retry budget — paged to human
10/ 12 The differentiator

An agent with veto rights — and why your OT lead signs the contract.

Operational technology is the part of the estate where a "fix" can derail a train, blackout a substation, or over-pressurize a pipeline. Mythal treats OT as a different physical reality, and bakes that treatment into a named agent.

DEFAULT POSTURE

Veto direct patching

For any asset in an OT zone or carrying the Critical Cyber System flag, the agent's default response is to refuse a direct patch. This is not an exception path — it is the path.

PROPOSE INSTEAD

Compensating controls

Industrial firewall ACL tightening · IPS signature that virtually patches the bug at the network layer · monitored isolation with elevated alerting sensitivity. Surgical, reversible, no firmware touch.

SCHEDULE

Inside a planned window

The firmware update itself is scheduled into the next documented OT maintenance window — weeks or months out — with dual approval (Security + OT Operations) and a tested rollback as preconditions.

FRAMEWORKS

NIST 800-82r3 · IEC 62443

Every veto, every compensating control, and every scheduled window emits an evidence record tagged to §6.2 of 800-82r3 and parts 2-3 / 3-3 of IEC 62443. Audit by construction.

11/ 12 Compliance by construction

Every closed fix is also an audit artifact.

The reasoning trace the engineering team reads is the same record the auditor walks through. Two audiences, one source of truth, generated automatically.

FRAMEWORK

TSA SD 1580-21-01

§3.A segmentation · §3.B CCS access · §3.D timelines · §4 incident reporting. Class I rail directive.

FRAMEWORK

NIST CSF 2.0

Identify · Protect · Detect · Respond · Recover. Evidence flows under RS.MI-01 and RC.RP-01.

FRAMEWORK

NIST 800-82r3

Industrial Control Systems. §5.1 risk mgmt · §5.4 zones & conduits · §6.2 patch mgmt.

FRAMEWORK

IEC 62443

Parts 2-1 program · 2-3 patch · 2-4 service · 3-2 risk · 3-3 system security.

OUTPUT

Machine-readable bundle

JSON Lines, ingest-ready for ServiceNow IRM · Archer · MetricStream.

OUTPUT

Auditor-ready PDF

Generated in < 60 seconds. Control-by-control. Includes reasoning-trace excerpts.

OUTPUT

Insurance attestation

Posture package for Marsh / Aon / Lockton renewal cycles (roadmap Q1 2027).

12/ 12 The engagement

What a ninety-day commitment looks like.

A bounded, low-risk pilot designed to produce a measurable result and a credible internal advocate before any commercial discussion. Engineering is at-cost. The platform stands up alongside your existing tools.

DAYS 1–30 · STAND UP

Connect & observe

  • Tenant provisioned, OPA policy bundle loaded
  • Scanner connectors live (Qualys / Defender / Claroty)
  • CMDB ingestion + Inventory Insights first sweep
  • Console training for the security analyst team
DAYS 30–60 · OPERATE

Close the loop in IT, gate the OT

  • One Patch Tuesday handled end-to-end
  • One KEV uplift handled in the fast-track path
  • OT Safety Officer issues compensating controls on a real OT finding
  • First closed plans generate evidence units
DAYS 60–90 · EVIDENCE

Auditor & broker conversations

  • TSA SD 1580 evidence package walkthrough with your auditor
  • Insurance broker reviews the attestation
  • MTR metric established for the pilot cohort
  • Joint go / no-go decision on production roll-out
Engineering at-cost. No commercial commitment until the pilot is green. Reference pricing thereafter: $750K–$3M ACV scoped by estate size and integration breadth.