Anthropic Expands Claude Cybersecurity With Three-Tier Access | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Anthropic has expanded access to Claude’s cybersecurity capabilities through a three-tier verification programme, introducing separate pathways for defensive analysis, authorised red-team operations and testing of highly sensitive systems.

The change, announced on October 6, brings the company’s Cyber Verification Programme and Project Glasswing into a broader access framework. Anthropic’s updated Project Glasswing page says the tiers cover Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, alongside future models. Existing Glasswing participants will move into the highest tier, Specialized Access.

The decision addresses a difficult problem for AI providers and security teams: capabilities useful for investigating weaknesses can also support attacks. Its practical significance extends beyond model availability. It makes the user’s identity, working environment and authorised scope part of the conditions under which advanced cybersecurity assistance is delivered.

Three Tiers for Different Security Tasks

According to Anthropic’s announcement, Defense Access covers incident response, security operations, malware reverse engineering and vulnerability analysis. Red Team Access adds authorised penetration testing and adversarial assessments, while retaining blocks on activities associated with physical harm or mass disruption.

Specialized Access has the fewest cybersecurity blocks and serves a limited group authorised to assess sensitive systems, including power grids, flight systems and interbank infrastructure. Anthropic says applicants for this tier undergo detailed review with the US government.

The distinction matters operationally. A team investigating suspicious software needs different permissions from one conducting an adversarial assessment of a live environment. Testing technology with potential consequences for public safety introduces another level of responsibility.

For organisations evaluating the programme, the relevant question is therefore which tier fits a defined task. Treating the highest tier as a routine upgrade would overlook the relationship between permitted activity and the controls required to support it.

Independent Researchers Face a Different Access Route

Anthropic’s programme documentation says individual researchers, maintainers and bug bounty hunters can apply for Defense Access on a paid plan. Red Team and Specialized Access are restricted to organisations.

Applicants submit information about their work, identity and applicable security controls. Organisations apply once, with administrators allocating access internally. The help centre gives a target of seven business days for a decision or request for further information.

For independent researchers, this creates a meaningful boundary: eligibility for defensive assistance does not automatically extend to the organisational tiers.

That raises an access question for the wider security community. Independent researchers often work without the administrative infrastructure of a large employer. Whether the programme broadens useful access will depend partly on how well its individual route accommodates legitimate research while keeping verification manageable.

Stronger Authentication Becomes a Condition of Access

The accompanying security requirements turn account protection into a central programme obligation.

Defense users must adopt phishing-resistant multifactor authentication and stop using static or long-lived credentials by December 15, 2026. Until then, permitted API keys require secure storage, individual assignment and replacement at least weekly.

Red Team and Specialized Access require stronger protections from admission, including short-lived credentials and phishing-resistant authentication. Both normally limit workspaces to 25 approved users, with additional seats available on request. They also require managed devices, user verification and logged outbound allow-lists for offensive or agentic work. Specialized Access adds further endpoint protection and federated organisational sign-in requirements.

Individual Defense traffic is retained and monitored; zero data retention is unavailable for that route.

These conditions suggest that implementation could require work across identity management, endpoint administration and security operations before a team starts using the expanded capabilities.

The underlying risk is straightforward: an account authorised for powerful security work could itself become a valuable target. Protecting the account and constraining the environment in which it operates are therefore inseparable from deciding what the model may do.


Verification Does Not Remove Usage Restrictions

Anthropic’s help centre says its Usage Policy continues to apply, and access grants may be narrowed or withdrawn. Client-facing products using the capabilities are governed separately.

The broader policy prohibits harmful conduct such as unauthorised access, malicious compromise and abusive use of the platform. Verification should consequently be understood as permission to perform approved classes of work within the programme’s rules.

For security leaders, that distinction has a practical consequence: provider approval cannot replace a clearly documented assessment scope. A team still needs to establish which systems it may test, who has authorised the work and which actions require additional review.

An organisation considering integration into a commercial service must also distinguish its own internal use from a product delivered to customers. Those are different deployment decisions, with different questions about access, responsibility and oversight.

Anthropic’s Tests Show How the Tiers Change Blocking

Anthropic evaluated Opus 5.5 using CyScenarioBench, running five attempts across 10 multi-stage cybersecurity challenges.

Without programme access, every trial was blocked at the opening prompt. Defense Access blocked 46 of 50 trials at some stage; the other four succeeded. Red Team Access produced no blocks and completed 34 trials, broadly matching the reported 67.6% result without safeguards.

Those findings illustrate intended differentiation, but remain company-reported results from a limited evaluation.

The distinction between blocking and completion is essential. Removing a restriction does not mean a model completes every permitted task. Equally, a high blocking rate on deliberately offensive scenarios does not measure how well a defensive tier performs everyday incident analysis.

The published exercise supports a narrower conclusion: under the tested conditions, Anthropic could substantially change the model’s access to offensive workflows through tier-specific safeguards. It does not establish how reliably those boundaries will hold across every real-world environment, unusual request or attempted misuse.

Glasswing Provides the Background to the Expansion

Project Glasswing launched in April with partners including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, the Linux Foundation and other major technology and financial organisations. Anthropic committed up to $100 million in model usage credits and $4 million in donations to open-source security organisations.

Reuters reported that Anthropic attributed at least 129,000 verified vulnerability discoveries between April and July to Glasswing partners, with an additional 5,500 found through its own scanning through October. More than 33,000 were rated critical or high severity. The company said the partner survey was incomplete and estimated the wider impact could be substantially greater.

Those figures describe reported discoveries. They should not be interpreted as an equivalent number of deployed fixes or prevented intrusions.

For decision-makers, the more useful operational measures would include how many findings were reproducible, how many affected deployed systems, how quickly maintainers delivered patches and how promptly organisations installed them.

A discovery engine can expand visibility into weaknesses. Turning that visibility into reduced exposure requires engineering capacity and dependable remediation processes.

Open-Source Maintainers Need More Than Additional Findings

The Linux Foundation’s account of Glasswing, written by chief executive Jim Zemlin, describes the pressure on maintainers from growing volumes of contributions, security reports and supply-chain threats.

Zemlin argues that advanced defensive tooling must reach maintainers with limited resources. He also points to the potential for AI to assist with patches as well as discovery.

This is an important measure of the programme’s eventual value. Producing additional reports can create work for the very people responsible for protecting widely used components. Useful assistance must help separate actionable findings from noise and support fixes that survive testing and review.

For organisations relying on open-source software, the implication is that access to stronger models should sit alongside investment in maintenance. Faster identification of weaknesses delivers limited protection if the projects receiving those findings lack the time or resources to address them.

Data Retention Could Shape Enterprise Adoption

The CVP documentation says retention supports misuse detection, with limited transitional exceptions for eligible existing customers. That creates a deployment consideration for teams working with sensitive code or incident material.

Anthropic’s proposed Enterprise Frontier Safeguards seeks to address that tension. Announced in September, it is scheduled for phased availability later in the autumn and would allow monitoring data to remain in customer-controlled cloud infrastructure.

The company says automated systems would review activity for misuse patterns, while customer personnel could handle flagged cases without requiring human review by Anthropic. Customers could retain control over encryption keys, access policies and audit logging.

For enterprise buyers, the significance is the proposed separation between automated misuse detection and custody of sensitive records. However, availability, eligibility and the actual deployment configuration need to be established before organisations assume those arrangements apply to their use.

Security teams investigating an incident may handle proprietary code, personal information and details of unresolved weaknesses in the same workflow. Decisions about what enters the model, where records reside and who can inspect them should therefore be made before deployment.

The Real Test Will Be Measurable Defensive Improvement

Anthropic’s expansion creates a more structured route to advanced AI security capabilities. Its success will depend on whether the verification process admits legitimate users efficiently, whether safeguards distinguish authorised work accurately and whether participating organisations can translate analysis into practical improvements.

For a security team, a useful initial deployment would have a clearly bounded purpose and measurable outcomes: shorter investigation times, better-quality vulnerability validation or faster delivery of reviewed fixes. Those outcomes are more informative than the volume of prompts submitted or findings generated.

The programme also places responsibility on the customer’s operating environment. Identity controls, restricted execution, accountable users and review procedures become part of the deployment itself.

Ultimately, the strongest evidence for the three-tier approach will be safer software and reduced exposure across organisations of different sizes. Broader access is an enabling step; the decisive question is what defenders can reliably accomplish with it.

Article content

Article content

——————————————————-


Click Here For The Original Source.