Meanwhile, enterprise environments have grown more complex, with data scattered across cloud infrastructure, remote workers, newly acquired companies and business units that don’t talk to each other, making the attack surface larger than ever and harder to secure.

Yet most enterprises are defending against these threats with tools and processes built for a slower pace.

A new operating model is emerging: agentic cyber defense, a fundamentally different architecture for enterprise defense.

Take a classic phishing attack. It once had obvious tells: a typo-ridden email or formatting that gave the game away. Now, agentic AI writes believable messages and adjusts them at scale, testing what works and refining along the way. One careless click is all it takes to let an attacker in. From there, autonomous agents get to work immediately: stealing credentials, moving through connected systems and expanding their reach, all without waiting for a human hacker to guide the next step.

“The fastest attack we’ve seen so far this year has been about five minutes of reconnaissance, attack and data exfiltration attempt,” says Joe Partlow, chief technology officer at ReliaQuest.

The Speed Gap: Five Minutes To Attack, 40 Minutes To Notice

Security analysts juggling alerts from fragmented tools and coordinating responses manually lose valuable minutes while attackers keep moving. Partlow says it can take 30 to 40 minutes for an analyst to even become aware of an attack, and even more time to contain it.

Visibility is patchy: security teams see only what feeds into their tools. One common fix — routing all security data into a central system before acting — doesn’t solve the speed problem. The data has to arrive and be translated into a format it understands before your human defenders can respond.

Adding AI to only one function of the security operations center (SOC) isn’t enough to beat attackers. “There’s a million AI startups right now that are focusing on one problem,” says Partlow — incident response, or detection, or threat hunting, but rarely all of it. A siloed approach leaves gaps and drives costs up.

The most effective approach applies AI across the SOC.

ReliaQuest’s answer is GreyMatter, an agentic defense layer for the enterprise. Rather than funneling data into a central repository first, GreyMatter’s Universal Translator normalizes telemetry across vendors at ingest, and detection runs at source, at storage or in transit — so threats are caught before data is ever indexed.

It autonomously detects, investigates and contains threats in less than five minutes, and it has analyzed more than 100 million events and alerts in the past 12 months alone, resolving them with 99.4% accuracy.

It’s built around three capabilities that make that possible:

1. An Agentic Orchestration Layer

Security analysts can interact with GreyMatter through a single interface, asking it to perform tasks such as launching a threat hunt or checking for a specific vulnerability, rather than using the specialized query syntax that each underlying system typically requires.

Behind that interface, the orchestrator manages hundreds of tools and agents on its own, so an analyst doesn’t need to know what’s available, only what they want to accomplish.

“It’s basically figuring out, ‘Hey, what do I need to do?’ And then [does it],” says Partlow, whether an analyst asks a question in chat or the platform acts autonomously.

Underneath that orchestration layer sit GreyMatter’s six agentic teammates — incident response analyst, detection engineer, threat hunter, intel researcher, IT engineer and operational technology engineer — each built to operate autonomously across hundreds of specialized skills.

Many AI security startups are “building siloed, standalone agentic flows or agents that aren’t able to look at the whole ecosystem,” says Partlow. In contrast, GreyMatter’s approach offers defense-in-depth .

That breadth multiplies a team’s capacity. “Maybe I have three threat hunters on my team, but I need 10,” he says. “You can’t go out and hire those folks. You can’t keep throwing more bodies at that.”

That capacity multiplier is part of what drives the platform’s return: GreyMatter customers see $2 to $4 back for every $1 they spend.

Every time the orchestrator or a teammate needs a model, GreyMatter’s AI model broker decides in real time which of more than 20 integrated models is right for the job, weighing cost, speed and accuracy for each request.

To quickly look up a specific threat group, for example, it doesn’t “need the latest and greatest, most expensive model to … answer that,” says Partlow. Meanwhile, a harder task, like investigating a suspected insider threat and deciding how to respond, gets routed to a stronger one.

That approach controls cost at the infrastructure layer, which is what makes flat, predictable pricing possible regardless of volume. No security leader should ever decide between a thorough investigation and a price tag.

Veralto specializes in water and product quality and comprises 14 different operating companies, each with its own IT environment and technology stack — a sprawl that forced analysts into manual triage just to piece together data across disparate systems, often taking days or even weeks. Threat volume and speed were outpacing what human intervention could handle.

Part of the problem was structural: until Veralto’s late-2023 separation from its former parent company, ReliaQuest had been restricted to flagging issues without authority to act, leaving GreyMatter’s agentic AI capabilities largely dormant.

The split changed that. Philip Propes, global chief information security officer at Veralto, put it plainly: “We told our teams early on, you need to take your hand off the wheel and let GreyMatter drive.”

See how Veralto’s shift to agentic defense quickened threat hunting from weeks to under a minute:

  • The mean time to contain threats has been reduced from weeks to under a minute.
  • Veralto executed 154 automated threat hunts in one quarter versus 10 in the previous year.
  • 94% of alert noise — false positives, duplicates, benign triggers — eliminated.

Propes added, “GreyMatter has allowed us to scale our people to address issues that matter, to craft something custom for us that works in our environment with all of our disparate environments, and empowers our people to do things beyond traditional [security operations center] duties to really level up our team as a whole.”

Writer & Editor: David MacLean

Designer: Kristine Francisco and Jennifer Ramos