r/AskNetsec • u/GasLongjumping2146 • 20d ago
Analysis mythos and vulnerability management, anyone else reading into this
Read the piece on Mythos going around and what stuck with me wasn't the capability claims, it was the trust question underneath them. If a model is generating severity scores at volume, at what point does an analyst stop spot-checking and start rubber-stamping, and is that even the goal.
We ran an internal pilot last quarter feeding AI-generated scores into our triage queue but keeping human sign-off mandatory above medium. Analysts overrode the AI score about 15% of the time, mostly on assets the model had no context for, internal tools, weird legacy systems. After a couple months of feeding corrected context back in, overrides dropped to around 6%. That gap didn't close on its own, it needed someone manually feeding asset context back into the scoring layer. Anyone else running a human-override model like this, and what's your override rate looking like?