Board cyber tabletop,
run by an expert witness.

Mythos is the name of an Anthropic AI model. In April 2026 the UK AI Security Institute tested it and found it could do cyber attack work that used to need an expert. We use the name for the whole shift: AI that can find and use weaknesses in your systems on its own. Your chair will ask where the board sits on this and what is on the record. Start with a 90-minute director briefing, or bring the whole board to the three-hour tabletop and sign the decisions in the room. Now booking October and November 2026. Updated September 2026  ·  Director Briefing $3,000 ex GST  ·  Board Tabletop $8,500 ex GST

Who runs it

What the session is built on

An expert the court has already tested

Matt O'Kane gives evidence on cyber matters in the Federal Court of Australia and the Supreme Court of NSW. He has led breach responses that went to the ACSC and the OAIC. The record from your session is written to the standard his reports are held to.

Students rate his teaching 5.8 to 6 out of 6

Matt teaches cyber security at UNSW Business School. In Term 3 2025, students in his two courses rated his teaching 6.00 and 5.80 out of 6. The School average was 5.42 (UNSW myExperience survey). He won a 2024 UNSW Scientia Education Academy award for his teaching.

Every claim has a public source

The threat picture comes from Anthropic's published reports, the UK AI Security Institute's evaluations and reporting on the April 2026 incident. Every claim in the dossier is cited, so your counsel can read it against its source.

Used to a board room

Matt runs Diary of an Incident Responder, a workshop series with Cloudflare across Australia and New Zealand. Through partners, he has run tabletop exercises for executive teams since 2025, including an ASX 200 company.

What changed

What changed between April and September 2026

This is AI used to attack organisations. The briefing is updated as the public record moves.

September 2026: an AI agent got into a Medicare portal

On 24 September the Prime Minister said an OpenAI agent got around the access blocks on a Medicare statistics portal. Services Australia runs the portal, and the agent viewed non-public files. It happened on 18 June, and OpenAI told the government three months later. OpenAI says it found no evidence that patient records were accessed. A taskforce with the ASD and the AI Safety Institute is reviewing the incident. ABC News, 24 September 2026.

September 2026: attacks no longer need expert attackers

Anthropic's September 2026 threat intelligence report documents threat groups running reconnaissance, break-in and data theft through AI that works with little human oversight. Its conclusion: sophisticated attacks no longer require sophisticated attackers. Read the report.

August 2026: models acting on their own in tests

The UK AI Security Institute reported that, when set a cybersecurity challenge, models took autonomous, unsanctioned action in 10 of 122 test runs. Al Jazeera, 5 August 2026.

April 2026: where it started

The UK AISI evaluation of Anthropic's Mythos model, the Anthropic risk report and the 21 April unauthorised-access incident. The briefing pack carries all three as pre-reading.

After Mythos

The patch race breaks

Before Mythos, a working attack on a newly found weakness arrived weeks after it was made public. Now it can arrive before the weakness is public at all. Patching as fast as you can, the way most organisations have worked for 20 years, no longer keeps up.

How fast can you patch?

How fast can you patch the systems you can't afford to lose, and what does your infrastructure actually support today?

What is your alternative?

When the answer is "not fast enough", what is your alternative?

The session walks your board through these questions against your own systems. Decisions are signed in the room. The dossier records which systems can be patched fast, which need an alternative, and which are open exposures.

Two ways to start

Director Briefing, or the full Board Tabletop

Start with the briefing, or go straight to the tabletop when the chair wants the whole board's decisions on the record.

Director Briefing: $3,000 ex GST

90 minutes with one director or executive, in person in Sydney or via Teams. The public record since April 2026, what it means for your organisation, and the questions your board will be asked. A written brief and a board paper of up to 2 pages follow within 5 business days. The paper is ready to table at your next board meeting. If the paper falls short, there is no fee. Conditions apply.

Board Tabletop: $8,500 ex GST

Three hours with up to 10 directors and executives. One scenario walked through against your systems, decisions captured live and signed in the room, a 10-page dossier within 5 business days.

Pre-research to fit your organisation: $18,000 ex GST

Three days of research before the session: your sector and regulator, your systems mapped against the scenarios, and a reading of your current board papers on cyber. The briefing or tabletop then runs on your own facts. Add it to either engagement. For large, specialist or unusual organisations, other customisation is available and quoted on scope.

What the $3,000 Director Briefing covers

  • One 90-minute session with one director or executive, in person in Sydney or via Teams.
  • The public record on AI-driven cyber attacks and what it means for your organisation.
  • A written brief and a board paper of up to 2 pages, with one round of revisions.
  • It does not include reviewing your internal documents or systems, extra attendees or sessions, or research into your organisation. Those are quoted on scope, or covered by the pre-research option above.

Director Briefing guarantee: conditions

  • The guarantee applies to the Director Briefing only.
  • Book at least 10 business days before your board meeting and tell us its date. We deliver the board paper at least 2 business days before that meeting.
  • If the board paper is not fit to table, tell us in writing within 10 business days of receiving it. We revise it once, within 5 business days.
  • If the revised paper is still not fit to table, tell us in writing within 5 business days. We refund the briefing fee in full, or cancel the invoice if it is unpaid.
  • The refund covers the briefing fee only, not travel or other costs.
  • It does not apply if you cancel or postpone the booking, or if no one from your organisation attends.
  • One guarantee per organisation.
  • This guarantee is in addition to your rights under the Australian Consumer Law.

Outcomes

What your board has at the close of the session

The working papers and the draft dossier are prepared at the direction of your company secretary and counsel. Counsel decides what enters the minutes. The dossier is written to be read against the AICD's Cyber Security Governance Principles.

Directors on the same page

Directors leave with a common view of the threat and of where the organisation stands, captured in a register they sign before leaving the room.

8 to 15 decisions, each with an owner

Board-level decisions captured live, mapped to the regulators that apply to you. Each decision carries an owner and a review date, so the dossier records what was done, not only what was noted.

A record your counsel controls

A sourced, dated record of the board's consideration of AI-driven cyber risk, held by the board, for the day a regulator, a shareholder or a court asks what the board did.

Scenarios

Seven scenarios, one recommended for you

Most boards run S1. APRA-regulated entities usually run S2, and boards that have bought a business recently run S5. We confirm the choice with you before the session.

S1: An attacker with Mythos-class capability

How the organisation defends itself against an AI-armed attacker.

S2: APRA or the ASD tells you to adopt AI defensively

Buying AI defence because a regulator said so.

S3: An engineer runs a capable model against your own systems

Insider risk when AI can act on its own.

S4: A vendor finds a serious flaw in your code with its AI tool

Who is told, in what order, and who fixes it.

S5: Software you acquired reaches end-of-life with a new AI-found flaw

Legacy liability and the risk that came with the acquisition.

S6: Whether to use an overseas model to defend yourself

Who decides, and on what basis.

S7: Mythos-class capability for sale on criminal marketplaces

A flood of new flaws, and how fast you can patch.

What you do

How the engagement runs

Block 3 hours plus a 30-minute pre-brief

Schedule the session at a time that suits your board.

Distribute the briefing pack 7 days ahead

Pre-reading: three public-source documents to all attendees.

Confirm participants, up to 10

Directors, key executives and your head of IT security. Mutual NDA before the session. No recording.

Three-hour facilitated session

We walk through the scenario, capture decisions as the board makes them, and the board signs the register.

Dossier in your inbox within 5 business days

A 10-page dossier drafted with your company secretary and counsel. Include it in your next board paper.

Director Briefing $3,000 · Board Tabletop $8,500 · ex GST

Mutual NDA, no recording. Your head of IT security attends the tabletop. In person on the East Coast of Australia, or via Teams.

Now booking October and November 2026. Tell Matt your sector. He replies with a recommended scenario and a time for a short call.