GREY TECHNOLOGIES • AI & SECURITY ARCHITECTURE, CONSULTING & RESEARCH
ENTERPRISE SECURITY & AI • PGP: 2D9C 18DE 5B30 A269
EU DESIGN PARTNER PROGRAMME • INVITE ONLY

AGENT RESPONSE CENTER (ARC)

Adversaries break out in 29 minutes. The median organisation finds them on day 14, and almost half are told by somebody else. ARC is the response layer built for that arithmetic: a plug-and-play library of incident response endpoints that triage, investigate and contain at machine speed — running as autonomously as you decide to let them, action by action, from a sign-off gate on everything down to no human in the loop at all.

THE ARITHMETIC2026 THREAT REPORTING
29 minutes
Average adversary breakout — the time from first host to lateral movement.
14 days
Global median dwell time before the intrusion is discovered at all.
247 days
Mean time to identify and fully contain, once it has started.
INGRESS · YOUR TELEMETRY
EDR / ENDPOINTProcess exec · credential access
IDENTITY & AUTHToken replay · impossible travel
NETWORK TRAFFICOutbound beacon · port scan
CLOUD & HOST LOGSPrivilege escalation attempt
SIEM TELEMETRYContinuous event stream
EXISTING PIPELINE · YOURSCORRELATION ENGINE
CORRELATED · 24 H WINDOW130 ALERTS CORRELATED
TRIGGER · YOUR THRESHOLD98/100CRITICAL RISKONE SIGNED HTTPS CALL
ARC · MACHINE SPEED UNDER 20 MINUTES
  1. 01 · ACTIVATIONAgent response initiatedIncident context and tools loadedT + 00:03:10
  2. 02 · INVESTIGATIONRoot cause isolatedEvidence captured, blast radius mappedT + 00:11:40
  3. 03 · CONTAINMENTAction executed and auditedUnder the autonomy policy you setCONTAINED · 00:18:20
CLASSIC HUMAN SOC · QUEUED MEDIAN DISCOVERY ON DAY 14
  1. 01 · TICKET QUEUEDAwaiting a Tier-1 analystThe alert sits unassigned in the queueQUEUED · 4–48 H
  2. 02 · MANUAL TRIAGEWorked across shift rotationsContext is lost between handoversELAPSED · HOURS TO DAYS
  3. 03 · UNRESOLVEDThe attacker is still resident48% are told by an outside partyDAY 14 · MEDIAN DISCOVERY

Both lanes start from the same dispatch. ARC is finished at 00:18:20; the queue is still open on day 14. The ARC timings are MVP design targets, not measured production figures, and the human-lane waypoints are Grey Technologies' own estimates from EU enterprise SOC practice. The figure that lane ends on — a 14-day median before the intrusion is discovered at all, and 48% of organisations told by an outside party — is Mandiant M-Trends 2026, cited in full under Evidence Base.

THE SPEED GAP

TWO CLOCKS, FOUR ORDERS OF MAGNITUDE APART

The first two bands are not our data. They are what Mandiant, CrowdStrike and IBM published in 2026, plotted on one axis. Our own design targets sit underneath them, labelled as targets. The attacker's clock is measured in seconds and minutes. The defender's is measured in days and months. An alert queue worked by humans on a shift rota cannot close a gap that shape — not because the analysts are slow, but because the arithmetic does not permit it.

VELOCITY CONVERGENCE • 2022 → 2025/26The attacker's window collapses through the patch boundary. Defender dwell time does not move.
30d+30d20d+20d10d+10d0d0d-10d-10dDEFENDER DWELL TIME (DAYS)ATTACKER WINDOW (DAYS)2022202320242025/26PATCH BOUNDARY (0d)CYBER-ESPIONAGE MEDIAN: 122d+20d+8d−1d−7d16d10d11d14d2025/26 ATTACK PROFILETime to exploit: −7d (pre-patch)Initial hand-off: 22sLateral movement: 29mATTACKER OPERATIONAL WINDOWDEFENDER DWELL TIME (GLOBAL MEDIAN)

Defender dwell time — Mandiant M-Trends, 2023 to 2026 editions (16d, 10d, 11d, 14d), with the 122-day cyber-espionage median from M-Trends 2026. Attacker operational window — mean time-to-exploit, Google Threat Intelligence Group via M-Trends 2026: −1 day in 2024 and an estimated −7 days in 2025, where a negative figure means exploitation began before a patch was released. The 2022 and 2023 points are Grey Technologies' normalisation of the same measure onto this days-relative-to-patch axis. Hand-off and lateral movement figures as cited under Evidence Base.

ADVERSARY — MEASURED, 2026 REPORTING
Access handed to second crew
22 seconds
Fastest observed exfiltration
4 minutes
Median breakout to lateral movement
29 minutes
INCUMBENT SOC — MEASURED, 2026 REPORTING
Median dwell before discovery
14 days
Mean identify and contain
247 days
ARC — MVP DESIGN TARGET, NOT YET GA
Triage verdict returned
~3 minutes
Evidence and blast radius mapped
~12 minutes
Containment action executed
under 20 minutes
22 SECLOGARITHMIC SCALE • EACH DIVISION = 10×247 DAYS
FINDING 01

You Are Told, Not Alerted

48% of organisations first learned of the intrusion from an outside party — a partner, a customer, law enforcement, or the attacker's own ransom note. In those cases the detection stack did not fail late. It did not fire at all.

FINDING 02

The −7d Window

Roughly 29% of known exploited vulnerabilities were attacked on or before the day their CVE was published, rising to 32% in the first half of 2026. Organisations do not wake up to a fresh zero-day; they wake up to a breach that started before the patch existed. We call that pre-disclosure window −7d, and it is our term, not an industry statistic.

FINDING 03

The Hand-Off Is Instant

Median time from an access broker selling entry to the crew that does the damage has collapsed from over eight hours in 2022 to 22 seconds. There is no longer a quiet period between intrusion and impact in which a queue can be worked.

HOW IT WORKS

CORRELATE. INVESTIGATE. CONTAIN.

AI-driven attacks execute in minutes. Alert queues are still worked in hours.

Three steps, and we are explicit about which of them is the product. The first is detection engineering we do with your team inside your own stack. The second and third are ARC.

01 // CORRELATE
CONSULTING ENGAGEMENT

The Entity Window

A sliding time window over an entity graph — user, host, IP, cloud role — so one intrusion arrives as one incident instead of thirty tickets. Peer-reviewed work on billion-scale correlation shows this is the approach that holds up in production. We build it in your stack. You keep it either way.

02 // INVESTIGATE
ARC

Agentic Forensics

Volatile evidence captured before anything is changed, blast radius mapped across identity and infrastructure, indicators correlated against threat intelligence, and a root cause stated with its evidence attached. The 03:00 Tier-1 investigation, run in the right order, every time.

03 // CONTAIN
ARC

Zero-Trust Guardrails

Containment executed over validated tunnels with no public inbound port, checkpointed so an action can never run twice, and gated on human sign-off wherever you decide the blast radius of being wrong is larger than the blast radius of waiting.

ARC is the MVP we are building to close that gap: a plug-and-play library of response playbooks that does one job only, agentic cybersecurity response.

PLUG AND PLAY
Drop in a playbook. Not a six-month integration project.
RESPONDS
It acts on the incident. It does not add another dashboard.
HUMAN SIGN-OFF
Destructive actions stop and wait for an operator.
EU RESIDENCY
Hosted in Europe. Telemetry stays inside the region.
ENDPOINT LIBRARY

FOUR PLAYBOOKS, READY OUT OF THE BOX

Each endpoint is a tested playbook for one operational task, with its skills, integrations and safety boundaries already bound. You enable the ones you need rather than commissioning an automation project. Every playbook states what it does without asking you, because that is the only question worth answering first.

Identity Compromise Response

Rebuilds the sign-in story for the account across identity, endpoint and cloud telemetry, decides whether the session is the attacker or the user, and cuts the session where it is not.

TRIGGER: Impossible-travel, MFA-fatigue or token-replay signal raised on a correlated identity.
01CORRELATEPulls sign-in history, device posture, access-policy verdicts and recent grants for the identity into one timeline.
02INVESTIGATESeparates the legitimate session from the hostile one by device, network path and behavioural delta, then maps what the token could already reach.
03CONTAINRevokes refresh and session tokens, quarantines the session, and disables the account when the compromise is confirmed.
04EVIDENCEWrites the identity blast radius — groups, roles, delegated grants, OAuth consents — into the incident record.
AUTONOMY: Default — token revocation autonomous, account disable gated. Configurable to full autonomy.TARGET: Sub-minute to revocation
IDENTITY PROVIDERMFA / ACCESS POLICYEDRCLOUD IAM
SECURITY ARCHITECTURE

FOUR NON-NEGOTIABLE PRINCIPLES

An autonomous agent with production credentials is a serious thing to put in an enterprise. These four constraints are what make it defensible in a security review, and none of them is configurable away.

PRINCIPLE 01

Brokered Access, No Public Listener

Reaching an on-premise estate needs a path into it, and we will not pretend otherwise. That path is a dedicated tunnel or proxy you host and control, established outbound from your network and scoped to named systems — not a public inbound listening port on your perimeter, and not a standing route into a flat network.

PRINCIPLE 02

Immutable Audit Trails

Every prompt, decision, parameter check and tool invocation is written to an append-only, time-locked store. When a regulator or an insurer asks why the agent did what it did, the answer is a record rather than a reconstruction.

PRINCIPLE 03

Fail-Safe By Default

High-impact and destructive actions ship gated on operator sign-off. You can move that gate anywhere you want it, per action and per playbook — including running a playbook fully autonomously with no human in it. What ARC will not do is move it for you: the cautious setting is the one you get until your team decides otherwise.

PRINCIPLE 04

Deterministic Orchestration

State checkpointing prevents repeated, looping or duplicated execution. An isolation action fires once. A retry after a network fault resumes rather than restarts, so a transient error during an incident cannot become a second incident.

EU SOVEREIGNTY

BUILT IN EUROPE, FOR EUROPEAN OPERATORS

We are EU cybersecurity professionals building sovereign response infrastructure for EU enterprises, under the same regulatory regime our clients answer to. DORA and NIS2 are our obligations as well as yours, and a response platform that ships your incident telemetry out of the region does not solve that problem — it relocates it.

DATA RESIDENCY
Processed and stored in Western Europe. No cross-border telemetry transfer, no US-region fallback.
NETWORK POSTURE
Reached over validated zero-trust tunnels. ARC opens no public inbound listening port in your estate.
AUDIT EVIDENCE
Append-only, time-locked logging of every decision and action, exportable for regulatory review.
REGULATORY FOCUS
Designed with DORA, NIS2 and GDPR Article 32 obligations as the target, and built for the EU financial and critical-infrastructure operators they bind.
EVIDENCE BASE

EVERY FIGURE ON THIS PAGE, SOURCED

We do not expect a security leader to accept a vendor's numbers. Here is the complete set with links to the primary reports — take them into your own board paper, with or without us. Our own threat modelling and correlation architecture notes are published openly on our research channel.

FIGUREFINDINGSOURCE (2026 EDITION)
14 DAYSGlobal median dwell time, up from 11 days the previous yearMandiant M-Trends 2026
48%Of organisations learned of the intrusion from an outside party, not their own toolingMandiant M-Trends 2026
22 SECMedian hand-off from initial access broker to the group that does the damage, down from over 8 hours in 2022Mandiant M-Trends 2026
29 MINAverage eCrime breakout time — first host to lateral movementCrowdStrike Global Threat Report 2026
27 SECFastest observed breakout, and fastest observed exfiltration was 4 minutes after initial accessCrowdStrike Global Threat Report 2026
+89%Year-on-year growth in AI-enabled adversary operationsCrowdStrike Global Threat Report 2026
247 DAYSMean time to identify and contain a breach, up 2.5% year on yearIBM Cost of a Data Breach 2026
~$2MLower average breach cost for organisations using AI and automation in security operations. One in four still use neitherIBM Cost of a Data Breach 2026
29%Of known exploited vulnerabilities were attacked on or before the day their CVE was published — 32.1% in H1 2026VulnCheck State of Exploitation 2026
99%Peer-reviewed evidence that graph-based entity correlation with human-in-the-loop feedback resolves billions of alerts into incidents at production accuracyFreitas & Gharib, arXiv:2406.01842

Besides the ARC design targets in the chart above, one further figure on this page is ours rather than a published report's, and we label it as such: a 24/7 Tier-1 rota of 8–12 analysts costs an EU enterprise roughly €1.8M–€2.3M a year fully loaded. That is Grey Technologies' own model, not an IBM or Mandiant finding, and we will walk you through its assumptions on request rather than asking you to take it on trust.

DESIGN PARTNER COHORT • OPEN NOW

TALK TO THE TEAM BUILDING IT

EU DATA RESIDENCY

ARC is pre-GA, and we are deliberately not selling it yet. We are selecting a small cohort of European enterprise security teams to build it against — the deployments that shape what the product becomes. Nothing to sign and nothing to commit to: the next step is a technical conversation with the cybersecurity professionals building it, and you will know inside one call whether it is worth your time.

WHO WE ARE LOOKING FOR
CISOs, SOC managers and security engineers at EU enterprises already running correlated detection — you need alerts worth responding to before response automation earns its place.
WHAT YOU GET
Direct architecture time with the cybersecurity professionals building it, endpoints tailored to your infrastructure, and priority onboarding when ARC reaches general availability.
WHAT WE ASK
Honest operational feedback and a named technical counterpart. We are building against real incidents, not a roadmap document.