Why Federal Cyber Defense Must Evolve for the Frontier AI Era
Earlier this week, we announced that we have been awarded a Certificate to Field from the Department of War and an Authority to Operate from a US Intelligence Community agency. This is opening doors for MixMode to expand on the contracts that we have won to date, and make it easier to land incremental environments across these agencies. We feel very fortunate to serve some of the most advanced cyber organizations in the world.
Cyber has had a major problem for decades. It has long been the case that the most damaging successful attacks have been those that could be classified as new and novel attacks. Basically, unknown attacks not seen before, created to bypass rules and signatures-based detection systems. In the last few years, 80% of successful breaches come from unknown / novel attacks (Ponemon Institute). And in 2025, Cyber Defense magazine pegged the global breach cost from attacks at $1.5T.
In the last year or so, this major problem has exploded and is getting drastically worse by the day. What’s changed? By using the breakthrough capabilities of Frontier AI, these new exploits can not only be created faster, but also can autonomously attack critical systems. Just look at news of the most recent models from Anthropic and ChatGPT breaking out of containment and hacking other companies.
So how are companies responding? There is a lot of discussion around incorporation of LLM technology into the Cybersecurity stack to combat the bad guys using Frontier AI. There is no question that the ability to translate and label data is a valuable tool. In addition, the defensive side of Frontier AI to detect vulnerabilities allows organizations to quickly develop patches to help harden systems.
This is a good, albeit incomplete, piece of the Cyber program puzzle. Mythos is not built to tell you about Frontier AI attacks, much less tell you that in real time. Organizations need both. They need to know where their vulnerabilities are. AND they also need to know if they are being attacked right now. Any attack, whether known or unknown, needs to be detected and mitigated in real time.
Real-time, precise detection is super hard, as the breach data tells us. One reason is that the balance of velocity will always tilt in favor of the bad actors. Large organizations will necessarily have steps and tradeoffs when building and deploying patches, as well as blindspots of new vectors of attacks. In addition, insider threats fall into a similar bucket of difficulty to detect.
The bottom line is that if detections are not incorporating these unknown attacks, and prioritizing them appropriately, the environment will be breached. A great UI or a great SOAR will not solve this detection problem.
MixMode’s solution aims to address the detection of unknown attacks and AI-driven attacks using a proprietary AI. This AI is built to scale and accurately build predictions against time series data. It is not born out of a foundational model like LLMs, but out of a foundational algorithm from Dynamical Systems. This is a different approach than anyone in the market, but the point is that it can ingest a tremendous amount of data, build an evolving forecast to understand and predict activities related to the entities in an environment, and then detect activity that could be nefarious.
In short, it finds these new advanced attacks automatically. In real time. Because of the prediction capabilities inherent in MixMode, telling us what an environment should look like in the next 5 minutes, we have also seen customers finding pre-attack activity well before damage can be done. Our platform is able to do this fully on-prem in air-gapped environments, supporting organizations that require data sovereignty.
Big shout out to our team for being granted these opportunities from the Department of War and the US Intelligence Community. We look forward to bringing this technology to an increasing number of critical environments to help defend the US and its allies against advanced cyber attacks. Let’s go!
Read the release here: https://www.mixmode.ai/newsroom/mixmode-cleared-to-broadly-deploy-its-ai-cyber-platform-in-u-s-defense-and-intelligence-community-environments