Ep 112 ·
The Mythos Era: TPRM Evolution, AI Ethics, and Project Glasswing with Matthew Moog
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Matthew Moog is a security professional with more than 20 years of experience and a principal at EY, where he leads financial services risk managed services. He previously served as general manager for third-party risk management at OneTrust and brings deep expertise in third-party risk management, financial services risk and GRC.
Ep 112 ·
Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.
Moog estimates about 60% of the effort, possibly more, can come out of the assessment itself. His team's agents read dozens of documents and point to the exact policy, page and a screenshot of the evidence, so reviewers can verify answers quickly, and each client's model is trained separately to keep data isolated. He advises putting the savings into areas like threat and vulnerability management, incident response, agentic pen testing and security posture management rather than cutting staff.
Project Glasswing gives a select group, largely large banks, access to Anthropic's Mythos model; consulting firms like EY see it only through client projects and working groups. Moog says what makes Mythos different is that it stacks vulnerabilities, combining ones that are insignificant on their own into a much bigger one. He warns that organizations rushing to adopt agents need controls and an understanding of these new risks, which takes people who are deeply technical and understand the business context.
Moog sees the ethical questions inside third-party risk as small next to the broader board discussion of AI ethics. Agents are given judgment and access that mirror an employee, and they have tunneled outside firewalls and interacted in ways no one expected, so the real dilemma is where to say no. He also treats workforce impact as an ethical choice, raising options such as working 20% less for 20% less pay instead of cutting 20% of staff.
Not entirely. Moog compares it to a modern car full of sensors that still gets a 160-point inspection before resale: an assessment remains the best way to understand a new third party's controls and is still worth doing every year for critical ones. Because mature assessments rarely change year to year, he expects more time to go to continuous signals and to running third-party risk almost like a mini SOC.
Moog says AI coding models are very good at checking their own code for vulnerabilities, so scanning will be built in by default whether code is written by humans or agents, although the models still struggle with user personas, access and non-linear workflows. He expects constant scanning of code bases and external perimeters, and says patching what is found will have to be automated in many cases because that would be very difficult with a human-based labor force.
Moog does not expect a fully autonomous security organization in the next 10 years outside some very small startups, because agents cannot yet think critically through chaos the way a SOC analyst does when deciding whether to cut off an anomaly. He sees demand for more security professionals, especially those with a deep technical understanding of their architecture, their tools and where AI fits in, including through third parties.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.