Logo ECIJA

    Mythos is forcing the financial sector to reform cyber risk insurance

    Articles5 June 2026
    Cybersecurity is becoming a strategic priority in business decision-making.

    The development of advanced artificial intelligence models like Claude Mythos is marking a turning point in how organizations approach cybersecurity and risk management. Their ability to automatically, quickly, and at scale identify vulnerabilities introduces a new dimension to traditional protection systems, characterized by the speed, complexity, and unpredictability of attacks.


    In this new context, particularly sensitive sectors such as finance, insurance, and energy are facing a structural change: risks are no longer isolated events but have become dynamic threats capable of escalating within minutes. This transformation not only affects technological operations but also has a direct impact on the ability to anticipate risks, on risk assessment models, and on strategic decision-making within organizations.


    Moreover, technological advancements are putting traditional frameworks to the test, both from the insurer's perspective and from the legal standpoint. The difficulty of predicting incidents in environments where attacks can be generated in real-time through AI demands a rethinking of concepts such as coverage, liability, and due diligence. The focus is no longer limited to reacting to an incident but shifts to the capacity for prevention and the adoption of increasingly stringent technical standards.


    In this environment, the role of governance takes on particular importance. As Javier Arnaiz, Cybersecurity Partner at ECIJA, pointed out, cybersecurity is no longer a purely technical issue but has been fully integrated into the responsibilities of the board of directors. Regulations like NIS2 and DORA are reinforcing this trend by requiring active, informed, and risk-proportional oversight from governing bodies.


    This change means that organizations need to place cybersecurity at the center of their strategy, raising the bar regarding control, oversight, and decision-making. In a scenario where AI tools allow for the detection of errors with unprecedented accuracy, the boundaries of liability are also being redefined: it's no longer just a matter of how an incident is managed but whether it could have been anticipated.


    Ultimately, the emergence of these technologies is accelerating the transition to a model where cybersecurity, regulation, and governance converge as key elements of business resilience. Organizations that effectively integrate these dimensions will be better positioned to face an increasingly complex environment, where competitive advantage largely depends on the ability to anticipate and strategically manage risk.


    Read the full article published in Cinco Días here.

    Related professionals

    LATEST FROM #ECIJA

    Articles
    8 July 2026
    Your company processes far more personal data than you realise

    Most companies believe they have a clear understanding of what personal data they process. However, this perception is often limited to their customer database, when in fact the processing of personal data covers much more than that.

    Read more
    News
    15 June 2026
    ECIJA Dominican Republic, a founding member of the Cyber Cluster RD

    A new chapter for cybersecurity in the Dominican Republic, with ECIJA playing an active role as a founding member.

    Read more
    Articles
    5 June 2026
    Mythos is forcing the financial sector to reform cyber risk insurance

    The emergence of AI models like Claude Mythos is transforming risk management and cybersecurity, and forcing organizations to strengthen their ability to anticipate and respond.

    Read more
    Articles
    21 May 2026
    Democratisation of AI in the legal sector

    When people talk about artificial intelligence (AI) in the legal sector, they almost always refer to the large law firms and their multi-million pound investments in LegalTech.

    Read more
    Articles
    20 May 2026
    CIOs and CISOs facing the new Zero Trust: maintaining control without hindering automation

    Understand how identity management is changing in an environment where AI, agents, and automated processes are playing an increasingly significant role in operations.

    Read more
    News
    12 May 2026
    Madrid will bring together representatives from the CCN, the police, and strategic experts in a meeting on cybersecurity

    Madrid will soon host the Osintech forum, a high-level private meeting organized by ECIJA that will bring together representatives from the National Cryptology Centre (CCN), the police forces, and strategic experts from the public and private sectors.

    Read more
    Reports
    14 April 2026
    Draft law on the protection and resilience of critical infrastructures: transposition of Directive (EU) 2022/2557 (CER)

    Spain is drafting a law that will require public and private organizations in strategic sectors to demonstrate their ability to withstand and recover from any kind of threat.

    Read more
    News
    3 March 2026
    Javier Arnaiz, new partner in cybersecurity and data protection at ECIJA

    Javier Arnaiz advises companies and national and international regulatory bodies on strategic projects related to cybersecurity, data protection, and compliance.

    Read more
    Reports
    22 January 2026
    The importance of AI literacy despite the regulatory simplification of the RIA for the European Digital Omnibus

    The European Artificial Intelligence Regulation (AIR) introduces a comprehensive approach to literacy in artificial intelligence as an essential element to ensure the safe, ethical, and legal use of this technology.

    Read more