Cisco is open-sourcing its model-agnostic Foundry Security Spec blueprint for agentic security evaluation that taps into the latest frontier large language models (LLMs) like Anthropic’s Mythos and OpenAI’s GPT-5.5-Cyber, a move that takes advantage of the networking giant’s core location within surging AI-related traffic flows.
Omar Santos, a distinguished engineer at Cisco, noted in a blog post that the blueprint is designed to be used with GitHub’s spec-kit development workflows that can be used with different AI agents. It’s being published as a pair of main artifacts that include supporting documents.
The “spec” artifact includes eight core agent roles, five extension roles, the finding lifecycle, a coordinated substrate, and approximately 130 functional requirements, “each with an inline rationale explaining why it exists.”
The “constitution” artifact includes 11 inviolable principles, each of which encodes a real production failure Cisco has shipped, diagnosed, and fixed.
Santos explained that this model is a “full agentic system” that can reduce the large output of “unbounded, unverifiable output” that comes from using frontier LLMs to “find the bugs.”
“It wraps the model in orchestration, roles, and guardrails so that detection, validation, and coverage are designed up front instead of improvised in a chat window,” Santos noted. “The difference is stark – one is an interesting demo; the other is a security evaluation system you can defend in front of your CISO and your auditors.”
The system is targeted at security teams increasingly challenged by AI-fueled cybersecurity attacks.
“As frontier AI models create a new dual-front challenge, attackers are now identifying vulnerabilities at machine speed, leaving security teams struggling to keep pace with manual, legacy processes,” Santos wrote, adding that this means “the old ‘find-and-patch’ cycle is no longer sufficient to address this new velocity of risk.”
“However, the true potential of these models is realized only when we combine the right harness – the agents and orchestration – with the skilled professionals who drive them,” Santos continued. “By moving beyond incremental productivity gains to rethink how we find and fix vulnerabilities at scale, we are introducing the Foundry Security Spec as a critical opportunity to empower our teams and help tip the scales in favor of the defenders.”
Anthony Greco, chief security and trust officer at Cisco, noted in an accompanying “fireside chat” that the vendor’s access to Mythos and GPT-5.5-Cyber showed a “material step forward in terms of the model and their capabilities from the foundational model providers.”
“When we think about the harness with these models, it is the changing the game of what it means to automate and find things at scale, at scope that we hadn't been able to do before,” Greco said of this integration. “So it's a really exciting time and one that we've been preparing for a while and are excited to see how we as defenders can use it to defend better.”
Cisco claims Mythos advantage
That Mythos angle is somewhat unique to Cisco, as it’s one of only a handful of entities Anthropic has deemed worthy of accessing the LLM.
Cisco Chief Product Officer Jeetu Patel explained to SDxCentral in a recent exclusive interview that the networking giant feels “a lot of responsibility” in being part of that small group.
“We feel a lot of privilege to be in the position that we are, but we also feel a lot of responsibility to make sure that this goes right, and it’s an intense time,” Patel said. “We're working round the clock, and there's a reason for that because we want to make sure that we are keeping the world safe and secure and be able to fully harness the potential of AI.”
That “round the clock” work also highlights what Patel said was Cisco’s positioning as a “critical infrastructure vendor” within the broader AI and cybersecurity architecture.
“If you think of a world which is end-to-end encrypted. If you think of a world which is going to be something that can't be trusted just at the endpoint because people can install all kinds of things on the endpoint, you have to know exactly what's traversing through the network, but you can't decrypt the files when everything's end-to-end encrypted,” Patel explained. “So you have to make sure that you can, from the pattern of the movement of the packet, be able to determine whether or not there's anonymous behavior, and then you need to know what originated on the endpoint and what terminated on the host and be able to observe everything end to end. And that's an area that we've actually invested a fair amount of dollars.”
Peter Bailey, SVP and GM for security at Cisco, added in a separate exclusive interview with SDxCentral that there is also a time element to this investment and positioning.
“I think right now we have the advantage because we have access to models that the attackers do not. We can get ahead of this and patch all of this stuff. That is an advantage we have,” Bailey said. “We've got to use that time advantage right now because once these models are in the hands of threat actors … then it's, we're offense and defense, and frankly it always favors the attacker because you just have to be wrong once, so you've got to build these defenses and have some certainty around that.”
Comments