Published: 22/09/26

Securing the AI and Cloud Era Key Takeaways

Securing the AI and Cloud Era Key Takeaways

We recently hosted a morning session at The Culloden Hotel on Securing the AI and Cloud Era, bringing together our esteemed partners and cyber security leaders for a morning focused on how organisations can safely govern AI adoption and modernise security operations as offensive AI capabilities accelerate across cloud and identity perimeters.

1. CrowdStrike: Achieving Frontier AI Readiness and Resilience

Ben O’Shea, Corporate Account Executive for Ireland at CrowdStrike

The time between a vulnerability being discovered and it being exploited has collapsed from weeks to minutes.


Frontier AI models like Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber are fundamentally shifting the security landscape. We are moving into an era where AI models autonomously discover software vulnerabilities at an unprecedented scale, making discovery massively scalable while outperforming human security testers on false-positive rates. Adversaries are no longer taking weeks to operationalise disclosures – weaponised exploits and automated vulnerability discovery are collapsing response windows to mere minutes.

  • The Speed Collapse: Time-to-Exploit (TTE) has plummeted from 2.3 years in 2018 down to hours in 2026.
  • Massive Offensive Scale: Anthropic’s Project Glasswing reported finding 10,000+ high- or critical-severity vulnerabilities in its first month alone (with Cloudflare identifying over 2,000 bugs).
  • Exploding Threat Velocity: CrowdStrike’s Threat Report highlights an 89% increase in attacks by AI-enabled adversaries, a 42% increase in zero-day vulnerabilities exploited prior to public disclosure, and a record-fast adversary breakout time of just 27 seconds.
  • The 5-Step Readiness Framework: To build resilience, organisations must pivot to prioritising exploitability over CVSS volume, adopting continuous validation across cloud and identity, enforcing zero standing privileges, automating machine-speed SecOps, and applying deliberate, safe AI use. 

As threat actors leverage AI to accelerate exploit creation, modernising your security operations is no longer optional. To explore how next-generation operations combat these rapid attack cycles, read our guide: Agentic SOC Models to Help You Outrun the Vulnapocalypse.

2. Check Point: AI – The New Security Conversation

Seamus McCorry, Country Manager at Check Point

AI is everywhere - from browser extensions, desktop apps, and code assistants to drag-and-drop autonomous agents.


AI adoption in the workplace is moving at breakneck speed. Employees are actively integrating AI into their daily flows through browser extensions, Claude Desktop, Cursor, and Model Context Protocol (MCP) connectors to corporate resources like Asana, Jira, Box, and Google Drive. However, this rapid rollout creates critical visibility gaps and new risk vectors, from prompt injections and data leakage to uncontrolled agentic autonomy.

  • Pervasive AI Surface: Uncontrolled shadow AI usage exposes corporate credentials, internal notes, and sensitive files across unsanctioned tools and desktop extensions. 
  • Real-World Pitfalls: Examples like a chatbot selling a $30,000 Chevy Tahoe for $1.00 (“legally binding offer – no takesies backsies”) highlight the humorous yet stark reality of prompt injection, jailbreaks, and insecure output handling. 
  • The AI Defense Plane: Securing the AI transformation requires a single control plane across Employees, Applications, and Agents: 
    • Discover: Monitor sanctioned and Shadow AI tools, inspect MCP and agent traffic, and classify user intent and prompt content. 
    • Govern: Set granular access policies for managed vs. unmanaged apps, block risky connections, and set strict rules for 3rd-party SaaS integrations. 
    • Protect: Enforce inline, context-aware DLP with real-time, automated redaction (redacting API keys, AWS secret keys, or PII before prompts are processed). 

Securing the AI lifecycle spans both productivity tools and infrastructure. To see how these defense mechanisms extend into multicloud environments, check out our analysis on what Google’s new “AI Threat Defense” means for Wiz & multicloud security.

3. SEP2: The Agentic SOC – AI-Driven Operations

James Woodward, Head of Technology at SEP2

AI is there to empower people, not replace them. People currently are, and always will be, the center of our SOC operations.


At SEP2, our philosophy for AI usage is clear: AI must empower security professionals, be applied where it makes operational sense, never put data at risk, and never be held accountable for security outcomes – accountability stays with human experts. AI agents are used to eliminate ‘busy work’ and accelerate investigation times, giving analysts more space to make informed, critical decisions.

  • Wingman AI 2.0 (The Agentic SOC): Moving from basic summarisation to specialised AI agents connected via Model Context Protocol (MCP) tooling into Google SecOps and ticketing systems. 
  • Meet the Specialised Agents:
    • Casey (Alert Powerhouse): Triggers automatically on every incoming case to perform instant context pre-loading, vector search across past analyst notes and case history, and automated triage – guiding analysts with actionable suggestions while taking guidance from human facts. 
    • S.I.T.H (Special Intelligence Threat Hunter): Passively learns environment norms and IoCs/TTPs, executes automated threat hunts tailored to client setups, generates automated SBOMs, and delivers on-demand coverage summaries. 
  • Collaborative AI Ecosystem: Instead of duplicating effort or cost, SEP2 integrates directly with vendor-provided AI platforms (like Google SecOps and Wiz), building custom workflows that keep analysts at the centre. 

This ground-up re-engineering strips away traditional SOC bottlenecks, accelerating triage times by 20x while enforcing strict Human-in-the-Loop governance to ensure human analysts review and approve every remediation action. Moving beyond the hype of what an “Agentic SOC” actually means to SEP2, this practical approach delivers machine-speed response times backed entirely by expert, UK-based human analysts. Our collaborative work on this architecture is also explored in The Agentic SOC Revolution: An Exclusive Interview with Google Cloud and SEP2.

Modernising Your Security Posture

Securing the AI and cloud era requires a balanced combination of frontline threat intelligence, unified AI governance, and automated SOC workflows. By integrating continuous telemetry with expert human-in-the-loop oversight, organisations can stay ahead of modern adversary speed.

To discover how SEP2 maximises advanced threat context to keep modern enterprises secure, learn more in our overview on how SEP2 maximised Google Threat Intelligence.

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.