Anthropic Revamps Cyber Verification Program

The tiered approach helps manage access to evolving capabilities.

Person holding digital AI chip interface with warning alerts and error monitoring symbols on dark background
istock.com/ismagilov

Anthropic has announced a revamped Cyber Verification Program (CVP), integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.

Until now, CVP and Glasswing ran as separate programs: Glasswing gave organizations securing critical software access to Claude Mythos, while the original CVP loosened safeguards on Opus and Sonnet models for approved teams. Under the new structure, all three tiers include Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. Each tier comes with its own verification requirements and security controls.

The Defense Access tier covers SOC and incident response work, malware reverse engineering, and vulnerability analysis and validation. Eligible applicants include security teams defending their own systems, critical infrastructure operators, small security firms, open-source maintainers, and individual researchers with a history of reported vulnerabilities. 

Anthropic aims to respond to these applications within a few days.

Red Team Access adds authorized penetration testing and red teaming, limited to systems the organization is permitted to test. Actions that could cause physical harm or mass disruption, such as deploying ransomware, are still blocked in real time. Reviews are expected to take a few weeks, and qualifying applicants get Defense Access in the meantime.

Specialized Access has the fewest cyber blocks. It’s reserved for a small number of organizations authorized to test safety-critical systems such as power grids, flight systems, telecom networks, and interbank transfer infrastructure. Anthropic currently vets these applicants in collaboration with the U.S. government, and existing Glasswing members are moving into this tier.

Industry stakeholders offered the following feedback.

John Gallagher, Vice President at Viakoo

"The expanded Anthropic CVP complements our company focus to provide enterprise scale remediation at AI-speed.  The Defense Access tier assists in defining vulnerability remediation that can scale across vast enterprise device fleets.  Likewise, for lab environments the Red Team Access tier can allow stress-testing of OT/IoT devices to optimize the remediation process and gain a sense of how adversaries will behave. 

"Recent research showed only three out of 300 CVEs discovered by Project Glasswing were exploited, however, a one percent exploitation rate isn’t a sign of failure—it’s proof that proactive defense is working as intended. In enterprise IT, finding unexploited vulnerabilities is helpful; in OT/IoT and critical infrastructure, finding them before they become weaponized is critically important.  

"Getting early visibility into obscure OT/IoT vulnerabilities gives defenders the lead time needed to close doors before threat actors even realize they’re unlocked.

"Cyber defense has always had an asymmetric aspect to it; defenders need to be right all the time, while attackers need to be right once. The goal should always be to level that playing field, especially given the speed of AI. Defensive tools must keep pace, otherwise defenders are fighting automated attacks with manual workflows. 

"In OT/IoT and cyber-physical environments where attacks jump the digital-physical divide, responsible distribution of advanced AI tooling is an operational necessity."

Aviv Nahum, Co-founder and CEO at Above Security

"I like the tiered model from Anthropic because it recognizes something security people already understand: capability should be proportional to trust, use case and blast radius. The answer is not one universal set of restrictions for everyone.

"The fact that only a tiny percentage of AI-discovered vulnerabilities are later observed in active exploitation doesn’t make the technology less powerful. Vulnerability discovery and real-world exploitation are two very different things. 

"Attackers choose bugs based on reachability, economics, access, and operational value — not simply because a vulnerability exists. If anything, finding weaknesses before adversaries operationalize them is exactly what a defensive program should be doing. 

"The useful measure is not ‘how many bugs eventually got exploited?’ It is how much faster defenders can discover, validate, and understand meaningful weaknesses than they could before.

"While AI-assisted cyber capabilities are being made available to everyone now, I’m more worried about defenders being artificially held back than I am about capable cyber-AI becoming widely available. These capabilities are going to proliferate across models and providers regardless. Anthropic has already shown that other frontier models are reaching sophisticated end-to-end exploitation capability."

Ram Varadarajan, CEO at Acalvio

"Defense Access is the tier that most helps human analysts, since it takes on the SOC triage, malware reverse engineering, and vulnerability validation work that buries people while leaving judgment and accountability with them.

"A low exploitation rate shows that finding vulnerabilities was never the real bottleneck. Knowing which ones matter and stopping the ones that do is, and that's where AI-speed discovery must be paired with architectural defenses rather than treated as a finish line.

"I'm cautiously supportive of verified, tiered access for defenders, but it isn't truly 'everyone,' and attackers will reach comparable capability through other channels regardless. Therefore, we must design defenses that assume an adversary with the same tools." 

Diana Kelley, CISI at Noma Security

"We shouldn’t have to wait for an attack before a vulnerability is worth fixing. However, a large CVE count isn’t proof of value either. Risk depends on how likely exploitation is in that environment, the business impact if it happens, and whether compensating controls reduce the likelihood or consequences. 

"A valid finding on an exposed critical system is different from one behind effective isolation. The useful measure is how much risk the team can reduce, not just how many vulnerabilities the AI finds.

"Powerful cyber capabilities shouldn’t be limited to the biggest organizations. But the same capabilities can help attackers, so who gets access and under what conditions matters."

Amir Boldo, Co-Founder and CTO at Above Security

"Access is the right model because it treats capability as something you keep earning, not something you're granted once. For defenders, the real value isn't model-writing exploits. It's compressing the hours an analyst spends reconstructing what happened, why it happened and whether it's actually risky. 

"That's where we see the most leverage: the AI correlates activity across identity, SaaS and endpoints, and the human investigator makes the call. As these capabilities spread, the control question must move from 'who is allowed to use the model' to 'what is this identity actually doing with it.' 

"Mandatory retention and real-time blocks on high-risk actions are a good start on Anthropic's side. Every enterprise rolling out AI internally needs that same behavioral visibility on theirs."

More in Cybersecurity