AGENT RESPONSE CENTER (ARC)
Adversaries break out in 29 minutes. The median organisation finds them on day 14, and almost half are told by somebody else. ARC is the response layer built for that arithmetic: a plug-and-play library of incident response endpoints that triage, investigate and contain at machine speed — running as autonomously as you decide to let them, action by action, from a sign-off gate on everything down to no human in the loop at all.
- 01 · ACTIVATIONAgent response initiatedIncident context and tools loadedT + 00:03:10
- 02 · INVESTIGATIONRoot cause isolatedEvidence captured, blast radius mappedT + 00:11:40
- 03 · CONTAINMENTAction executed and auditedUnder the autonomy policy you setCONTAINED · 00:18:20
- 01 · TICKET QUEUEDAwaiting a Tier-1 analystThe alert sits unassigned in the queueQUEUED · 4–48 H
- 02 · MANUAL TRIAGEWorked across shift rotationsContext is lost between handoversELAPSED · HOURS TO DAYS
- 03 · UNRESOLVEDThe attacker is still resident48% are told by an outside partyDAY 14 · MEDIAN DISCOVERY
Both lanes start from the same dispatch. ARC is finished at 00:18:20; the queue is still open on day 14. The ARC timings are MVP design targets, not measured production figures, and the human-lane waypoints are Grey Technologies' own estimates from EU enterprise SOC practice. The figure that lane ends on — a 14-day median before the intrusion is discovered at all, and 48% of organisations told by an outside party — is Mandiant M-Trends 2026, cited in full under Evidence Base.
TWO CLOCKS, FOUR ORDERS OF MAGNITUDE APART
The first two bands are not our data. They are what Mandiant, CrowdStrike and IBM published in 2026, plotted on one axis. Our own design targets sit underneath them, labelled as targets. The attacker's clock is measured in seconds and minutes. The defender's is measured in days and months. An alert queue worked by humans on a shift rota cannot close a gap that shape — not because the analysts are slow, but because the arithmetic does not permit it.
Defender dwell time — Mandiant M-Trends, 2023 to 2026 editions (16d, 10d, 11d, 14d), with the 122-day cyber-espionage median from M-Trends 2026. Attacker operational window — mean time-to-exploit, Google Threat Intelligence Group via M-Trends 2026: −1 day in 2024 and an estimated −7 days in 2025, where a negative figure means exploitation began before a patch was released. The 2022 and 2023 points are Grey Technologies' normalisation of the same measure onto this days-relative-to-patch axis. Hand-off and lateral movement figures as cited under Evidence Base.
You Are Told, Not Alerted
48% of organisations first learned of the intrusion from an outside party — a partner, a customer, law enforcement, or the attacker's own ransom note. In those cases the detection stack did not fail late. It did not fire at all.
The −7d Window
Roughly 29% of known exploited vulnerabilities were attacked on or before the day their CVE was published, rising to 32% in the first half of 2026. Organisations do not wake up to a fresh zero-day; they wake up to a breach that started before the patch existed. We call that pre-disclosure window −7d, and it is our term, not an industry statistic.
The Hand-Off Is Instant
Median time from an access broker selling entry to the crew that does the damage has collapsed from over eight hours in 2022 to 22 seconds. There is no longer a quiet period between intrusion and impact in which a queue can be worked.
CORRELATE. INVESTIGATE. CONTAIN.
AI-driven attacks execute in minutes. Alert queues are still worked in hours.
Three steps, and we are explicit about which of them is the product. The first is detection engineering we do with your team inside your own stack. The second and third are ARC.
The Entity Window
A sliding time window over an entity graph — user, host, IP, cloud role — so one intrusion arrives as one incident instead of thirty tickets. Peer-reviewed work on billion-scale correlation shows this is the approach that holds up in production. We build it in your stack. You keep it either way.
Agentic Forensics
Volatile evidence captured before anything is changed, blast radius mapped across identity and infrastructure, indicators correlated against threat intelligence, and a root cause stated with its evidence attached. The 03:00 Tier-1 investigation, run in the right order, every time.
Zero-Trust Guardrails
Containment executed over validated tunnels with no public inbound port, checkpointed so an action can never run twice, and gated on human sign-off wherever you decide the blast radius of being wrong is larger than the blast radius of waiting.
FOUR PLAYBOOKS, READY OUT OF THE BOX
Each endpoint is a tested playbook for one operational task, with its skills, integrations and safety boundaries already bound. You enable the ones you need rather than commissioning an automation project. Every playbook states what it does without asking you, because that is the only question worth answering first.
Identity Compromise Response
Rebuilds the sign-in story for the account across identity, endpoint and cloud telemetry, decides whether the session is the attacker or the user, and cuts the session where it is not.
FOUR NON-NEGOTIABLE PRINCIPLES
An autonomous agent with production credentials is a serious thing to put in an enterprise. These four constraints are what make it defensible in a security review, and none of them is configurable away.
Brokered Access, No Public Listener
Reaching an on-premise estate needs a path into it, and we will not pretend otherwise. That path is a dedicated tunnel or proxy you host and control, established outbound from your network and scoped to named systems — not a public inbound listening port on your perimeter, and not a standing route into a flat network.
Immutable Audit Trails
Every prompt, decision, parameter check and tool invocation is written to an append-only, time-locked store. When a regulator or an insurer asks why the agent did what it did, the answer is a record rather than a reconstruction.
Fail-Safe By Default
High-impact and destructive actions ship gated on operator sign-off. You can move that gate anywhere you want it, per action and per playbook — including running a playbook fully autonomously with no human in it. What ARC will not do is move it for you: the cautious setting is the one you get until your team decides otherwise.
Deterministic Orchestration
State checkpointing prevents repeated, looping or duplicated execution. An isolation action fires once. A retry after a network fault resumes rather than restarts, so a transient error during an incident cannot become a second incident.
BUILT IN EUROPE, FOR EUROPEAN OPERATORS
We are EU cybersecurity professionals building sovereign response infrastructure for EU enterprises, under the same regulatory regime our clients answer to. DORA and NIS2 are our obligations as well as yours, and a response platform that ships your incident telemetry out of the region does not solve that problem — it relocates it.
EVERY FIGURE ON THIS PAGE, SOURCED
We do not expect a security leader to accept a vendor's numbers. Here is the complete set with links to the primary reports — take them into your own board paper, with or without us. Our own threat modelling and correlation architecture notes are published openly on our research channel.
| FIGURE | FINDING | SOURCE (2026 EDITION) |
|---|---|---|
| 14 DAYS | Global median dwell time, up from 11 days the previous year | Mandiant M-Trends 2026 → |
| 48% | Of organisations learned of the intrusion from an outside party, not their own tooling | Mandiant M-Trends 2026 → |
| 22 SEC | Median hand-off from initial access broker to the group that does the damage, down from over 8 hours in 2022 | Mandiant M-Trends 2026 → |
| 29 MIN | Average eCrime breakout time — first host to lateral movement | CrowdStrike Global Threat Report 2026 → |
| 27 SEC | Fastest observed breakout, and fastest observed exfiltration was 4 minutes after initial access | CrowdStrike Global Threat Report 2026 → |
| +89% | Year-on-year growth in AI-enabled adversary operations | CrowdStrike Global Threat Report 2026 → |
| 247 DAYS | Mean time to identify and contain a breach, up 2.5% year on year | IBM Cost of a Data Breach 2026 → |
| ~$2M | Lower average breach cost for organisations using AI and automation in security operations. One in four still use neither | IBM Cost of a Data Breach 2026 → |
| 29% | Of known exploited vulnerabilities were attacked on or before the day their CVE was published — 32.1% in H1 2026 | VulnCheck State of Exploitation 2026 → |
| 99% | Peer-reviewed evidence that graph-based entity correlation with human-in-the-loop feedback resolves billions of alerts into incidents at production accuracy | Freitas & Gharib, arXiv:2406.01842 → |
Besides the ARC design targets in the chart above, one further figure on this page is ours rather than a published report's, and we label it as such: a 24/7 Tier-1 rota of 8–12 analysts costs an EU enterprise roughly €1.8M–€2.3M a year fully loaded. That is Grey Technologies' own model, not an IBM or Mandiant finding, and we will walk you through its assumptions on request rather than asking you to take it on trust.
TALK TO THE TEAM BUILDING IT
ARC is pre-GA, and we are deliberately not selling it yet. We are selecting a small cohort of European enterprise security teams to build it against — the deployments that shape what the product becomes. Nothing to sign and nothing to commit to: the next step is a technical conversation with the cybersecurity professionals building it, and you will know inside one call whether it is worth your time.