Published: 01/10/26

Wingman Security Connect Key Takeaways 2026

Wingman Security Connect Key Takeaways 

At SEP2, our commitment to delivering tech-driven, people-powered cyber security is at the heart of everything we do. We put this philosophy into practice at our recent Wingman Security Connect 2026 event at the Royal Armouries in Leeds, bringing cyber security professionals together for a day of insightful presentations from Wiz and Google, discussions on how analysts and AI can work in tandem, and a crossbow challenge at the end to put our medieval security skills to the test!

Below is a summary of the key themes, threat intelligence, and announcements shared throughout the day.

Ground Rules and Evolution: The SEP2 Agentic SOC and Introducing curTIS

James Woodward, Head of Technology at SEP2

James kicked off the day by establishing SEP2’s core philosophy on artificial intelligence: AI is built to empower security professionals, not replace them. While AI can accelerate triage and investigation workflows, accountability, strategy, and critical decision-making will always rest with human experts.

Grounding AI in the SOC

Wingman AI 2.0: The Agentic SOC

Building on our previous discussions around what an Agentic SOC actually means, James detailed Wingman AI 2.0 – the transition to an Agentic SOC where specialised AI agents handle specific workflows within a unified case management ecosystem:

  • Casey (Alert Powerhouse): Automatically triggers on incoming cases, pre-loads context, runs auto-triage, and utilises vector search across historical case notes and past context.
  • S.I.T.H (Special Intelligence Threat Hunter): Passively learns environment norms, executes automated threat hunts based on client profiles, generates Software Bill of Materials (SBOMs), and suggests detection rule optimisations.

Introducing curTIS (CURated Threat Intelligence System)

James introduced a brand-new addition to the ecosystem: curTIS. 

Designed to deliver actionable threat intelligence at speed, curTIS:

  • Gathers threat intelligence strictly from trusted sources over a rolling 24-hour window.
  • Filters for high-severity, impactful threat events.
  • Leverages custom-tuned AI prompts to generate concise summaries.
  • Human validation ensures every output is thoroughly reviewed by SEP2 security analysts before being disseminated.
Explore our Wingman MDR service

AI Threat Readiness and Machine-Speed Defence

Abdullah Khan-Cheema, Partner Solutions Architect at Wiz

Abdullah provided a hard-hitting look at how AI is actively compressing the gap between vulnerability discovery and exploitation.

Key Insights and Takeaways

  • Shrinking Attack Windows: The time from vulnerability discovery to active exploitation has dropped dramatically – from ~2.3 years in 2018 to just ~10 hours in 2026.
  • AI-Accelerated Development Risks: AI code generation (“vibe-coding”) allows software to be shipped up to 100x faster, but often results in unclear code ownership and expanded attack surfaces across SDLC tooling, CI/CD pipelines, and open-source packages.
  • Agentic Threat Vectors: Frontier models are increasingly capable of chaining zero-days and reasoning through complex environments autonomously.
  • The AI Readiness Framework: To counter machine-speed attacks, security programmes must adopt continuous AI scanning (“Radar” for total visibility) alongside periodic deep AI stress-testing (“X-Ray” for critical risk elimination).
Learn more about our partnership with Wiz

The Evolving Threat Landscape and Autonomous Defence

Arron Thundercliffe, Google Security Engineering

Arron presented insights from frontline incident response data, walking through the shifting tactics used by modern threat actors and how Google is driving semi-autonomous security operations.

Key Insights and Takeaways

  • Shift in Targeted Verticals: According to the 2026 M-Trends Report, High Tech has overtaken Financial Services as the #1 targeted industry (accounting for 17% of investigations), followed by Finance (14.6%) and Business Services (13.3%).
  • Initial Infection Vectors: Exploits on edge devices remain the top vector (32%), while human-centric threats are surging – voice phishing (vishing) has risen to 11% (becoming the #1 cloud intrusion vector), while email phishing dropped to 6%.
  • Speed vs. Stealth: The global median dwell time rose to 14 days (driven by stealthy espionage actors), yet the defence window for initial access hand-offs has collapsed down to just 22 seconds.
  • Moving Towards Autonomy: Arron detailed the SOC maturity spectrum – moving from Manual and Assisted (GenAI summaries) into Semi-Autonomous operations, where AI agents drive routine tasks while delegating exceptions to human analysts.
Discover our partnership with Google Cloud

The Road Ahead

Whether leveraging vendor-native capabilities like Wiz and Google SecOps or extending workflows through specialised tools like Casey, S.I.T.H, and curTIS, the goal remains identical: eliminate busywork, give analysts time back to perform deep investigations, and keep humans at the heart of security operations.

Contact us to learn how our Agentic SOC can support your team

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.