This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Cyberdéfense à la vitesse de la machine

Download resources

About this session

An Arctic Wolf presenter, never named on the recording, argues that generative AI has compressed the gap between a vulnerability's disclosure and its exploitation from years to weeks, predicting hours by late 2026 and minutes by 2028. He describes Anthropic's controlled release of a cyber-capable model to roughly fifty software vendors (heard on the recording as 'Glasswing'/'MITOS') and an open-source model heard as 'DeepSea', both used by attackers to find and exploit flaws automatically, while generic AI tools remain unreliable for defenders due to hallucination and fragile reasoning. His recommendation is to 'operate at machine speed': structured, risk-based vulnerability management instead of raw scanner output, full attack-surface and exposure visibility, and resilience over pure prevention. He walks through Arctic Wolf's SOC, replatformed two years ago around orchestration, context, decision and AI-judge agents with a human always kept in the loop, its endpoint, MDR, vulnerability-management, attack-surface, awareness-training, incident-response and threat-intelligence products, an upcoming endpoint AI protection module, and 2025 ransomware statistics from its own incident-response caseload, including a large drop in ransom paid when professional negotiators are used.

Face à l'accélération des risques liée à l'IA, les organisations doivent adopter des défenses proactives pour rester compétitives. Venez entendre comment Arctic Wolf à adopté l'IA pour vous aider à vous défendre

Key takeaways

  • Move from flat vulnerability lists to risk-based, prioritized vulnerability management so critical issues surface first instead of being buried under low-priority findings.
  • Pair vulnerability management with full attack-surface/exposure visibility so unmanaged or forgotten devices aren't left uncovered.
  • Assume incidents will happen and invest as much in detection and incident-response readiness (a retainer, a named response team) as in prevention.
  • When evaluating agentic SOC tooling, look for a human-in-the-loop design that escalates new or low-confidence detections to a person rather than one that fully automates response.
  • If facing a ransomware demand, use experienced negotiators before paying; the presenter's incident-response caseload showed a large reduction in amounts actually paid versus initial demands.

Speakers

Martin Paré
Martin Paré
Architecte de solution · Arctic Wolf
Martin has been in the IT fields for over 20 years, on the client, partner and manufacturer side in the field of virtualization, data protection and security. --- Martin est dans les domaines des TI depuis plus de 20 ans, autant du côté client… Read moreRead less

Martin has been in the IT fields for over 20 years, on the client, partner and manufacturer side in the field of virtualization, data protection and security.
---
Martin est dans les domaines des TI depuis plus de 20 ans, autant du côté client, partenaire et manufacturier dans le domaine de la virtualisation, la protections des données et la sécurité

Resources

Photos

Tags

More from GoSec 2026

Also from Martin Paré

On the same topic