Time-to-exploit collapsed but most AppSec programs haven't

    Paul Bleicher
    2026-07-27

    A new checklist for a world that changed faster than our tools did.

    When I tell security people I used to work at Sqreen, I get one of two reactions. A blank look, or: "Oh, Sqreen. I remember using the CTO Security Checklist."

    That checklist was read and downloaded by tens of thousands of people. Plenty of companies have borrowed it, reworded it, and shipped their own version since. Honestly, I love that. A checklist that gets copied is a checklist that was useful, and I'm glad it's still around.

    But it was written for a different world.

    The world moved

    Over the past two years I've had hundreds of conversations with security engineers and leaders. Lately a lot of them carry the same undertone, somewhere between overwhelmed and quietly panicking.

    Time-to-exploit has collapsed from years to hours. Claude Mythos showed that autonomous models can find and weaponize vulnerabilities at machine speed. Then in July, an OpenAI model in an internal capability eval chained a zero-day, a privilege escalation, and stolen credentials to break out of its test sandbox and onto Hugging Face's production servers. Safeties were off and it was a controlled test, but it was a real preview of where this goes.

    The annual pentest, the bounty queue, the scanner backlog. All of it assumes you have weeks to work with. You don't anymore.

    So I built a new one

    The Mythos-ready AppSec Checklist is my attempt to help. It's built on those hundreds of conversations, so first: thank you to everyone who talked it through with me.

    The Mythos-ready AppSec Checklist cover

    It's 59 checks across six areas: know what can be hit, find what matters, prioritize by exploitability, fix through automation, contain the blast, and govern the machine.

    The part I care about most is that every check is sorted into three maturity levels, by who does the work:

    • Reactive: humans do the work.
    • Automated: machines do the work, humans approve it.
    • Autonomous: the system runs inside bounds you set, and humans handle the exceptions.

    Each level includes everything from the levels before it. So you can see where you actually are, and what the next step looks like. Most teams aren't even at Reactive yet, and that's fine. It's a starting line, not a grade.

    Use the checklist

    Work through it online with filters and a shareable progress link, or download the PDF and send it to your team.

    Open the checklist →

    Tell me what I got wrong

    I'll keep this one updated as the picture changes. If you go through it and something is missing, wrong, or you just disagree, tell me. That's how the last one got good, and it's how this one will too.