The Project Glasswing press release has dominated security discourse lately. The tl;dr for it:

The Mythos frontier model not only identified many new security flaws but also built and demonstrated the exploits, with no humans in sight. [Check out the Red team blog for deep technical details.]

This might be the most stark reminder of security fragility in a long time; it might also be a press release that scares beyond its real impact. Similarly concerning model announcements from the past were not so accurate, in hindsight!

Regardless, we're now in a new era, where the full vulnerability exploit process (discover/test/implement) appears to be just an API key and a bucket of tokens away.

What does it all mean in practice, for CISOs and organizations? Certainly, a surge in software updates will follow, as vendors put Mythos to work. Newly uncovered risks will drive network mitigations and system patching work, along with tech investments for low-disruption updates and system recovery.

Every exposed system, every port, and every accessible network path is now more of a risk, so systems to identify exposures will rise in priority.

What's my take? In a world where anyone can find new zero days… we can't just react faster with the same toolset and expect to be OK. We need to invest in ways to automate and prevent, and Mythos might just be the trigger for a positive, industry-wide change.

This new era requires a more aggressive, automated, proactive, and ultimately more autonomous approach to defense.

This is where the network might be an unexpected ally, because every identified vulnerable system has a useful network context.

The next action to take - whether to block the app/port directly, whether to mitigate attacks at a nearby firewall, whether to narrow access, whether to patch now – or whether to do nothing (because access and ensuing risk is sufficiently low) – depends on that context.

Zooming out – what do you have? How is it connected? Is it intended? These questions apply to every environment, and answering them is critical to contextualizing, prioritizing, and best addressing the new patch workload.

The need for autonomy-grade data

Lately, CSPMs/CNAPPs/CAASM (pick your favorite category name), like Wiz, help by inferring potential attack sequences from cloud data. They automate the identification of vulnerabilities, cloud connectivity, and credential access. But they don't see the full network (including on-prem), so they can't understand the full scope of exposure risks, their current reality, or their evolution.

In comparison, a Network Digital Twin sees the whole picture. What is it, though?

A Network Digital Twin is a precise mathematical representation of the complete network, covering every system that sees a packet. It makes that understanding available to people and machines.

Every network snapshot taken by the Network Digital Twin contains a complete model of connectivity - and with it, the data needed to understand the prior existence and new creation of exposure risks. This model is key to contextualizing, prioritizing, and then remediating exposure vulnerabilities…. but when automated, it enables a network to change more rapidly, with 'security confidence' coming from automated review.

Trusted data is always the key to efficiency and automation. But here, in a way you may not realize, there's a critical connection to a future of more autonomous network operations.

The self-driving network?

Today, a digital twin acts like advanced driver assistance for your network, grounded in a precise, deterministic model:

  • Topology shows exactly what’s there, monitoring even your blind spots.
  • Path analysis is your navigation system, revealing which traffic lanes are truly open.
  • Security analysis views (like exposure, blast radius, and segmentation) are your lane assist, helping to alert you the moment your security posture starts to drift.

All of these examples can't be achieved with LLMs alone! You need a guarantee of consistency and correctness to decisions. You need to know that every decision is based on complete, accurate, and up-to-date data, which can only come from the structured mathematical precision of a Digital Twin, vs the helpful-but-inherently-probabilistic nature of LLMs.

Think about it: to comfortably drive a network with autonomous assistance - where the network comes to us with a suggested implementation of needed changes, along with evidence of their safety and correctness - we need to cross a trust bar. LLMs or cloud data are not enough. We need autonomy-grade data for the complete picture. We need this level of data to even consider automated remediations, safe firewall cleanups, and proactive segmentation improvements - and, really all security actions from the networking side.

That's why I'm excited today, more than ever, about the core we have built, and its potential. A Network Digital Twin provides autonomy-grade data, unlocking network data in places where it hasn't been previously accessible.

This data puts your digital environment not just on a path to automation, but to actual network autonomy, where the requirements of security, tools, and application teams can be met for every network change, with proof.

I don't think we've tapped the full power of this data to enable smarter security choices, let alone autonomous network operations. If you take away anything, I hope it's this:

Achieving autonomous operations requires the data and insights to make comfortable automated change decisions, without introducing unwanted risk. Increasingly, trusted network data and insights from it are the keys to autonomous network operations, with the Network Digital Twin at the core.

This is what we do, and at Forward, it's all we've ever done. For some of us, like Peyman, whose high-impact research made this direction possible, it's been over 15 years and counting.

Stay tuned ... Join us on Innovation Day, we'll unlock the full potential of the Network Digital Twin.