Meeting Bank of Italy AI Guidance in the Post-Mythos Era with Picus

Umut Bayram | 7 MIN READ

| August 09, 2026

Key Takeaways

  • The Bank of Italy warns that advanced AI models find and exploit software vulnerabilities in very little time.
  • Attackers no longer need the skill or time once required, shrinking exploitation windows from months to hours.
  • Bank of Italy guidance spans governance, cyber hygiene, exposure management, patching, monitoring, resilience testing, and third-party risk.
  • Severity alone does not predict breaches, so validation evidence should drive patch, mitigate, monitor, or accept decisions.
  • Picus Swarm connects BAS, Autonomous Pentesting, Exposure Validation, threat intelligence, and response in one governed workflow.

The Bank of Italy has warned financial institutions that advanced AI models can find software vulnerabilities and generate ways to exploit them in very little time. Attackers no longer need the same level of skill or time they once did [1].

That changes the security problem.

You have less time to assess a new threat, decide what matters, test your controls, and fix the gaps. At the same time, the Bank of Italy expects financial institutions to strengthen governance, cyber hygiene, asset management, vulnerability management, monitoring, defensive controls, and resilience testing under DORA.

Picus helps you turn those requirements into a working validation process. In this blog, we will explain how it does.

What the Bank of Italy Is Asking Security Teams to Do

The Bank of Italy treats digital operational resilience as more than a compliance task. It links resilience to business continuity and the reliable delivery of financial services.

Its guidance focuses on seven areas:

  • Governance
  • Cyber hygiene
  • Asset and exposure management
  • Vulnerability and patch management
  • Monitoring, detection, and defense
  • Digital operational resilience testing
  • Third-party risk

The guidance also asks boards to review their current exposure, identify gaps, set priorities, define investments, and track progress.

This is where validation matters. Inventories, policies, and dashboards tell you what should work. Testing shows you what does work.

Why the Post-Mythos Era Changes the Risk

The post-Mythos shift is changing both the speed and scale of attacks.

One comparison shows a frontier model increasing its output from two Firefox exploits to 181. The same research found thousands of vulnerabilities across major operating systems and browsers, including a 27-year-old OpenBSD bug [2].

The problem is not limited to zero-days.

An AWS Threat Intelligence report describes one attacker targeting 2,516 devices across 106 countries [3]. The campaign moved from target to target in minutes. The attacker did not need advanced skills. AI handled much of the work.

This creates three problems for defenders:

  1. The time between discovery and exploitation has dropped from months to hours.
  2. Attackers can run complex operations across many targets at once.
  3. Most security teams still depend on manual handoffs between threat intelligence, vulnerability management, red teams, blue teams, and IT.

Making one tool faster does not fix a slow process. Your whole response workflow has to move faster.

Start With Identify, Protect, and Verify

Picus uses a simple operating model with three steps:

  1. Identify: You need a clear view of your attack surface. That includes external assets, internal networks, identities, cloud environments, exposed services, and misconfigurations.
  2. Protect: You need effective controls across your network, endpoints, applications, and detection stack.
  3. Verify: You need to test whether attackers can exploit your exposures and whether your controls can stop them.

The third step connects the first two. An asset inventory shows what exists. A scanner shows what may be vulnerable. A security tool shows what policy is enabled. Validation shows whether those layers work together during an attack.

Picus combines defensive validation and offensive validation to give you that evidence.

Defensive Validation Shows Whether Your Controls Work

The Bank of Italy asks financial institutions to strengthen monitoring and defense across applications, identities, access activity, and network traffic. This includes traffic to and from third-party providers.

Picus Breach and Attack Simulation tests those controls with real-world attacker techniques.

For each simulation, you can answer three questions:

  • Did a control prevent the activity?
  • Did a control detect it?
  • What risk remains?

This matters because coverage on paper does not mean protection in practice. A rule may exist but be disabled. A control may log activity but fail to alert. A detection may work in one region but not another.

Picus runs simulations and collects evidence from your network, endpoint, and detection tools. You can see what blocked the activity, what created telemetry, what raised an alert, and what passed through.

Figure 1. Picus BAS simulation results showing whether threats were prevented, detected, or generated alerts.

This also gives you a safer way to test sensitive environments. You may not want to run live exploitation against an ATM network, a payment system, an old server, or a restricted production segment. In those cases, BAS can test the relevant attacker behaviors without running a full exploit chain.

Offensive Validation Shows What Attackers Can Use

The Bank of Italy also asks financial institutions to find vulnerabilities faster and fix the most critical ones first. It highlights internet-facing systems, open source software, and zero-day vulnerabilities as key areas of concern.

The problem is that severity alone does not tell you what will lead to a breach.

Picus Autonomous Pentesting follows four steps:

  1. Recon: It maps external assets, internal networks, identities, services, and misconfigurations.
  2. Exploit: AI agents test real exploitation techniques within the approved scope. They can chain weaknesses across systems and adjust when an initial route fails.
  3. Prove: The platform shows whether the attack can reach a critical asset or privilege level. It records evidence of the result.

This gives you proof of which weaknesses an attacker can exploit, how they can chain them, and what they can reach.

Exposure Validation Turns Test Results Into Priorities

The Bank of Italy asks financial institutions to fix the most critical vulnerabilities first. Picus Exposure Validation helps you decide which ones are truly critical by combining Autonomous Pentesting results with BAS evidence.

Autonomous Pentesting shows which weaknesses attackers can exploit and chain to critical assets. BAS shows whether your controls can block or detect the techniques linked to those exposures.

The Picus Exposure Score adds security control performance, asset importance and business context, vulnerability severity, and exploit signals such as CVSS, EPSS, and KEV. This helps you focus on exposures your controls cannot stop and deprioritize those already covered by effective defenses.

Figure 2. Picus Exposure Score

Each exposure leads to an evidence-backed decision: patch, mitigate, monitor, or accept the risk with evidence.

Picus Swarm Enables Machine-Speed Defense Against Machine-Speed Attacks

The Bank of Italy recommends using AI systems, where appropriate, "to reduce the gap with potential attackers." It also says AI-based defensive tools should align with an institution's AI strategy.

Picus Swarm puts this principle into practice by enabling machine-speed defense against machine-speed attacks. It connects BAS, Autonomous Pentesting, Exposure Validation, threat intelligence, and response tools in one governed workflow built to act at machine speed.

When a new alert appears, agents can extract TTPs, CVEs, and indicators of compromise, check existing evidence, run missing tests, prioritize exposures, and trigger approved actions or tickets in minutes instead of waiting on days of manual handoffs.

You stay in control. Every step is logged, and you can review, pause, or change the workflow. You can begin with manual runs, move to scheduled validation, and adopt more autonomy as trust grows.

Build a Continuous Validation Loop

The Bank of Italy's message is clear. AI-driven threats leave you less time to find, assess, and fix risk.

You cannot solve that by adding another isolated tool or producing more findings.

You need a loop:

  1. Identify the assets and exposures that matter.
  2. Test what attackers can exploit.
  3. Validate whether your controls can stop the attack.
  4. Prioritize the fixes that reduce the most risk.
  5. Apply or assign the remediation.
  6. Test again.
  7. Report the result to technical teams, risk owners, and the board.

Picus Swarm connects these steps in one governed workflow. It coordinates threat intelligence, BAS, Autonomous Pentesting, Exposure Validation, remediation, and reporting so your teams can move from alert to action at machine speed while staying in control.

That is how Picus helps you prepare for the post-Mythos era.

Book a demo now and see how Picus turns validation into action at machine speed while keeping your team in control.

References

[1] Banca d’Italia, “Comunicazione al mercato in materia di resilienza operativa digitale e modelli avanzati di Intelligenza Artificiale.” Accessed: Aug. 06, 2026. [Online]. Available: https://www.bancaditalia.it/compiti/vigilanza/avvisi-pub/2026.07.17-comunicazione/Comunicazione-al-mercato-in-materia-di-resilienza-operativa-digitale-e-modelli-avanzati-di-intelligenza-artificiale.pdf

[2] “Project Glasswing.” Accessed: Aug. 06, 2026. [Online]. Available: https://www.anthropic.com/glasswing

[3] The Hacker News, “AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries,” The Hacker News. Accessed: Aug. 06, 2026. [Online]. Available: http://thehackernews.com/2026/02/ai-assisted-threat-actor-compromises.html

 
The Bank of Italy has warned financial institutions that advanced AI models can find software vulnerabilities and generate ways to exploit them in very little time. Attackers no longer need the same level of skill or time they once did. The warning links digital operational resilience to business continuity and the reliable delivery of financial services rather than treating it as a compliance exercise.
The post-Mythos era refers to the shift in both the speed and scale of attacks driven by frontier AI models. One comparison shows a frontier model increasing its output from two Firefox exploits to 181. The same research found thousands of vulnerabilities across major operating systems and browsers, including a 27-year-old OpenBSD bug.
Very fast. An AWS Threat Intelligence report describes one attacker targeting 2,516 devices across 106 countries, moving from target to target in minutes. The attacker did not need advanced skills because AI handled much of the work. The time between discovery and exploitation has dropped from months to hours.
Picus Breach and Attack Simulation tests controls with real-world attacker techniques and answers three questions for each simulation: did a control prevent the activity, did a control detect it, and what risk remains. Evidence is collected from network, endpoint, and detection tools, showing what blocked activity, what created telemetry, what alerted, and what passed through.
Picus Autonomous Pentesting maps external assets, internal networks, identities, services, and misconfigurations, then uses AI agents to test real exploitation techniques within the approved scope. Weaknesses can be chained across systems, with routes adjusted when an initial attempt fails. Results prove whether an attack can reach a critical asset or privilege level and record evidence.
Picus Exposure Validation combines Autonomous Pentesting results with BAS evidence, since severity alone does not tell you what will lead to a breach. The Picus Exposure Score adds security control performance, asset importance and business context, vulnerability severity, and exploit signals such as CVSS, EPSS, and KEV. Each exposure leads to a decision to patch, mitigate, monitor, or accept the risk.
Picus Swarm enables machine-speed defense against machine-speed attacks by connecting BAS, Autonomous Pentesting, Exposure Validation, threat intelligence, and response tools in one governed workflow. When a new alert appears, agents can extract TTPs, CVEs, and indicators of compromise, check existing evidence, run missing tests, prioritize exposures, and trigger approved actions or tickets in minutes. Every step is logged.

Table of Contents

Ready to start? Request a demo