Closing the Real Speed Gap: Takeaways from Our International Cyber Expo Roundtable
The response window is now measured in minutes, and most organisations are still organised to respond in days. That was the argument at the heart of our roundtable, Closing the Real Speed Gap: Building Security Ecosystems for Faster Cloud Security Decisions, held at International Cyber Expo on Tuesday 29 September, the first day of the two-day event at Olympia Exhibition Centre in London.
The session was led by Adam Levy, Cloud Security Solutions Leader, and Paul Allen, Leader Pre-Sales UK & Europe, and coordinated by Rita Smith, UK & US Marketing Manager. It brought together senior security leaders to talk candidly about their own environments, then tested whether their organisations could act inside that window through a live scenario exercise.
The discussion ran under the Chatham House rule, so this post covers the themes and the exercise, not what any individual said.
The speed gap is real, and AI is widening it
Attackers now begin scanning within 15 minutes of a CVE being announced. AI and automation have compressed every stage of the threat lifecycle: vulnerabilities are exploited faster, adversaries can work hundreds of targets in parallel, and deployment and extortion are increasingly automated.
The React2Shell vulnerability in 2025 showed what this looks like in practice. It carried a CVSS score of 10.0, and exploitation activity was observed within hours of disclosure as threat actors moved quickly to find exposed systems. The lesson the team drew was blunt: the patching window is no longer measured in days.
The data on exfiltration tells the same story. In 2025, the fastest quarter of intrusions reached data exfiltration in 72 minutes, down from 285 minutes in 2024. Yet attackers are not winning through sophistication. Around 90% of breaches begin with exposure: limited visibility, inconsistent controls and permissive identity. Speed and scale, applied to preventable gaps, are enough.
One upstream breach, cascading downstream impact
Trusted access has become the attacker’s force multiplier. Two real-world cases framed the discussion.
In the 2025 Salesloft Drift campaign attributed to Scattered Spider, attackers accessed Salesloft’s GitHub environment, extracted Drift OAuth tokens from AWS, and used that inherited trust to reach connected Salesforce environments. More than 700 downstream organisations were affected, none of which had been breached directly.
In 2026, the TeamPCP campaign compromised Aqua Security’s Trivy, a widely trusted security tool. The attackers harvested CI/CD credentials and used them to spread through GitHub Actions, Docker Hub, npm, PyPI and OpenVSX, reaching five or more software ecosystems and the developers, pipelines and businesses that depend on them.
Both cases prompted the same uncomfortable questions for the room. How confident are you that you could list every third-party integration and OAuth token connected to your core systems right now? And when did your team last review the access and scope granted to the security and developer tools you rely on?
How breaches get missed
Breaches rarely go unnoticed because nobody saw anything. They go unnoticed because the right signals never meet. The team walked through a pattern that will feel familiar to many security leaders:
- A vendor advisory reports active exploitation of a critical vulnerability.
- An affected asset managed by a third party is missed during scoping.
- Unusual authentication activity is detected elsewhere in the environment.
- In isolation, that activity looks low risk.
- Nobody connects it to the vulnerable asset.
For CISOs, the result is less time to deal with more: more adversarial behaviour, more entry points and more tools to manage. With the response window shrinking this fast, security teams have to act earlier in the threat lifecycle. Cloud adds complexity, but the fundamentals of detection and response still decide the outcome.
From signals to decisions
Making a single good security decision means pulling together threat intelligence, vulnerability data, asset criticality, cloud telemetry, identity activity and business context. Those signals live in different systems, use different formats, belong to different teams and change constantly. There are too many to correlate by hand and too many relationships to define in advance, and context changes faster than rules can be updated.
The industry has spent 20 years chasing this insight. SIEMs centralised data but not context. SOAR connected events but demanded constant maintenance. Risk scores simplified prioritisation but lacked environmental context. Threat intelligence added an external view but stayed disconnected. Platform consolidation unified tools, but not understanding.
The team argued that AI marks a genuine inflection point, because context generation can scale for the first time. It can draw together what happened before (historical incidents, forensics, known attack paths), what attackers are doing now (threat and vulnerability intelligence, industry targeting) and what your own environment is doing (exposures, assets, identity, telemetry and business criticality).
The team walked the room through an architecture for AI-powered decision-making that runs from alert ingestion through triage, investigation and enrichment to containment. AI decision points escalate when needed, loop back for further context, and keep an incident storyline updated as evidence arrives. The goal is simple to state: correlate more signals automatically, see real risk earlier, and make faster decisions with full context.
The exercise: Trusted Access at Ravensgate Freight
The second half of the session put the theory under pressure. Participants worked through a branching scenario in three decisions, answering as themselves about their own organisations as they are today. Each decision had a 15-minute budget in the story, and the facilitators chose the next inject based on the room’s answers. There was no score and no right answer, only consequences.
The setting was Ravensgate Freight, a fictional UK logistics group with 2,400 staff, a hybrid estate across Microsoft 365, AWS and a co-located data centre, and a booking platform used by 300 retail customers. It had a six-person security team, an outsourced SOC with limited cloud coverage, a monthly vulnerability review, and a conversational marketing tool integrated into its CRM by an agency three years earlier. Many in the room recognised more of those details than they would have liked.
At 14:10 on a Friday, the marketing vendor publishes an advisory: its GitHub environment has been accessed and OAuth tokens connecting customer CRM tenants may have been extracted. The advisory lands in a shared marketing mailbox. Nobody in security is copied.
From there, the story split two ways.
Outcome A: Contained. Security takes ownership at 14:32 and rotates the vendor tokens at 14:55, ending the attacker’s session. A look-back hunt finds an export of 18,400 contact records at 14:52, three minutes before rotation, and confirms the shipment schedules on a connected SharePoint site were not touched. The DPO concludes by 17:10 that the ICO must be notified, the largest customers are pre-notified with facts on Saturday, and when a major customer’s CISO calls on Monday morning, Ravensgate has a timeline. The ICO is notified 21 hours inside the 72-hour limit. Attacker dwell time: 45 minutes.
Outcome B: Loss of control. The same export happens at 14:52. At 15:25 the SOC raises a low-severity ticket for an unfamiliar login and bulk export from a legitimate service account, and queues it for Monday. At 15:40 the account reaches the shipment schedules, and no alert fires. By 02:10 on Saturday, shipment data for all 300 customers has gone. On Monday the data is on a criminal forum with a 48-hour extortion demand, a customer is asking whether it should tell the ICO itself, and a journalist wants comment. Friday’s ticket is still unread. Attacker dwell time: 66 hours and counting.
The difference between the two outcomes was two decisions made before 17:00 on a Friday. In Outcome B, every signal existed on Friday afternoon. None of them met.
Three questions to take back to your organisation
The exercise was built around three questions, and they are worth asking of any live incident:
- Who owns this? Which person or team would be holding it right now, and would they know?
- What do you know? Not what you suspect, but what evidence you actually have in front of you.
- What would you do in the next 15 minutes? The first action, not the plan. The attacker is not waiting for the plan.
If your honest answers would put you closer to Outcome B than Outcome A, you are not alone, and that was the point of the session. Closing the speed gap is less about adding another tool and more about making sure the signals you already have reach the right people, with enough context, fast enough to act.
Thank you to everyone who joined us at our roundtable and spoke so openly. If you would like to talk through how to improve your own security operations, get in touch with the SecurityHQ team.