The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The ITSPmagazine Podcast
The ITSPmagazine Podcast artwork

We Made Everything Faster. We Never Defined Better. | Lens Four by Sean Martin | Read by TAPE9

The ITSPmagazine Podcast · 2026-07-01 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

58 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality12 / 20
Guest Caliber11 / 20
Specificity & Evidence15 / 20
Conversational Craft7 / 20

At InfoSecurity Europe in London, Sean Martin identifies a structural crisis in cybersecurity messaging and capability: the industry has become expert at velocity and rhetoric - using terms like 'outcomes,' 'resilience,' 'sovereignty,' and 'human-in-the-loop' - but cannot connect these words to verifiable definitions of success. The conference revealed uncomfortable truths through conversations with Forrester's Madeline Vanderhout, FBI veteran Cynthia Kaiser (now at Halcyon), Qualys' Matt Middleton-Leal, Corelight's Matt Ellison, Intel 471's Ian Schenkel, and others. Attack timelines have collapsed to 22 seconds in agentic scenarios and under an hour for ransomware, forcing security programs to operate at machine speed. Yet measurement frameworks remain underdeveloped - one Qualys client faced 62 million risk findings that compressed to under 1% when business context and executability were applied. The real problem: vendors are selling stories backed by controlled demos and friendly references, not proof that outcomes hold across messy, under-resourced, mismatched environments. As Sarah Armstrong Smith bluntly noted, 'we have more tools, more people, more AI than ever...and it is still getting worse.' Martin predicts significant market consolidation in 12-18 months as AI adoption forces the gap between marketing claims and actual capability into sharp relief.

Key takeaways

  • →Attack response windows have collapsed from 8 hours to 22 seconds in agentic scenarios, making manual human-speed security obsolete and forcing programs to operate at machine speed or fail.
  • →Most security programs cannot distinguish between what they measure and what actually works, with vendors selling controlled-environment stories rather than proof of outcomes across different teams, budgets, and threat models.
  • →The industry has mastered the language of outcomes, resilience, and sovereignty without defining what success looks like, creating a vocabulary gap that AI adoption will expose within 12-18 months.
  • →Security vendors in silos lack consolidation and integration; 40-plus disconnected tools force customers to buy solutions rather than products, signaling imminent market sorting between survivors and acquisition targets.
  • →Post-quantum cryptography and AI-driven attack tooling (expanding from 38 posts to 1,402 in criminal markets) are purchasing decisions boards must make today, regardless of current internal understanding.

Guests

Marco Ciappelli (Studio C60 co-founder)Madeline Vanderhout (Forrester)John Soteropolis (OWASP Gen.AI Security Summit)Matt Middleton-Leal (Qualys)Matt Ellison (Corelight)Ian Schenkel (Intel 471)

Topics in this episode

InfoSecurity Europe LondonRSACForrester analyst Madeline VanderhoutOWASP Gen.AI Security SummitMachine speed attack timelines (22 seconds)Ransomware attack timing and durationRisk measurement and remediation frameworksQualys risk finding compressionCorelight network detection and verificationAI-driven security orchestration and MCP servers

Questions this episode answers

How fast are modern ransomware attacks from initial access to full encryption?

The average ransomware attack takes about four hours from initial access to encryption, with some completing in under an hour, and the most common attack timing is Wednesday nights according to Halcyon's Cynthia Kaiser.

What happened when Qualys applied business context and executability testing to a client's 62 million risk findings?

The findings collapsed to roughly 2 million theoretical risks, then 1 million with business context applied, and finally under 1% once tested for actual execution capability.

How much did the cybercriminal AI attack tool market grow in a single month?

The market grew from 38 posts in December to over 1,400 posts just months later, featuring tiered free and paid access, redundancy across platforms, and even AI-run call centers handling 120 simultaneous calls.

What is the core problem preventing vendors from proving their security solutions work?

Vendors can demonstrate results in controlled booth environments and with friendly reference accounts, but cannot prove outcomes hold up consistently across different teams, budgets, threat models, and under-resourced real-world conditions.

Why is post-quantum cryptography a purchasing decision companies need to make today?

Infrastructure installed today will still be running when current encryption math breaks, and 'harvest now, decrypt later' attacks with existing criminal intent and infrastructure are not theoretical - it is a Y2K-style purchasing decision that happens whether organizations realize it or not.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode is packed with specific and non-obvious data points - attack timelines collapsing to 22 seconds, ransomware completing in under an hour on Wednesday nights, risk findings collapsing from 62 million to under 1% actionable - but the macro narrative (AI overhyped, vocabulary outpaced products, consolidation coming) is familiar to any attentive B2B operator in security. The specific numbers rescue the density score; the broader thesis does not.

The time from an attacker's initial access to the next stage has, in agentic scenarios, collapsed from 8 hours to 22 seconds.
62 million risk findings that collapsed to roughly 2 million theoretical risks, then to about a million once business context was applied, then to under 1% once they tested which findings could actually be executed.

Originality

12 / 20

The central framing - 'a marketing achievement masquerading as a market' - is genuinely sharp and well-articulated, and the vocabulary-convergence critique is a more precise version of a familiar gripe. But the underlying arguments (tool sprawl, AI hype-reality gap, boards demanding proof, consolidation looming) are well-worn in cybersecurity commentary, even if assembled here with editorial care.

The go-to-market caught up to the language. The capability did not. That is a marketing achievement masquerading as a market.
When the whole floor agrees on the vocabulary, what is the language hiding? That nobody has agreed on what the words mean, and a word everyone shares is a word that has stopped helping anyone choose.

Guest Caliber

11 / 20

The practitioners cited - former FBI deputy assistant director Cynthia Kaiser, Forrester analyst Madeline Vanderhout, former UK MP James Morris, and 30-year veteran Sarah Armstrong-Smith - are genuinely credentialed and relevant. However, this is an editorial essay narrated by an AI voice, not a direct interview; all guest input is filtered and paraphrased, denying listeners the depth that actual conversations would provide.

Cynthia Kaiser, who ran cyber threat intelligence work as a deputy assistant director at the FBI and now tracks ransomware at Halcyon
James Morris, a former UK member of Parliament now running a cyber and resilience policy centre

Specificity & Evidence

15 / 20

This is the episode's strongest dimension - specific timelines, dollar-context figures, named companies, named individuals with institutional affiliations, and criminal-market metrics are woven throughout, giving concrete texture to every major claim. The 62-million-to-under-1% funnel, the Wednesday-night ransomware peak, and the 90,000 MCP agents are the kind of numbers operators can actually use.

an AI-run call center for sale that handles 120 simultaneous calls with simulated keystrokes
for a $40 billion company. Cutting mean time to resolve by 20% is real money.

Conversational Craft

7 / 20

There is no actual conversation here - this is a solo essay read aloud by an AI narrator, so host question quality, follow-up discipline, and willingness to push back are structurally absent. The closing rhetorical questions show genuine craft as writing, but they cannot substitute for the real-time probing and accountability of an interview format.

If you cannot say in one sentence what success looks like for your customer, what exactly is your dashboard counting?
If you can say it, can you prove it twice in two environments that share nothing but the problem?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

floor10market8question8security7three6tools6resilience6different6faster5whole5industry5speed5outcome5answer5team5already5

Episode notes

⬥EPISODE NOTES⬥ Almost every booth at Infosecurity Europe 2026 had settled on the same four words. Outcomes. Resilience. Sovereignty. Human in the loop. The messaging had grown up, more tempered than RSAC, more honest in its European register. The tell was quieter - almost none of it could connect those words to a definition of success a buyer could actually verify. Strip away the polish and the show floor was a working argument about what the cybersecurity market is for, at the exact moment the clock that governs it collapsed to seconds. The go-to-market caught up to the language. The capability did not. This is the prove-it problem, and it is worth pulling apart clearly.

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

Music We made everything faster. We never defined better. Lens 4. Where Business, Innovation, and Messaging Come into Focus.

By Sean Martin. I look at the intersection of business, technology, and messaging through three lenses. How organizations run their programs, where the market and its innovations are heading, and how the language we use shapes what gets funded and what gets believed. Then there is the fourth lens, the connective one, where I try to name what the first three keep pointing at.

I spent three days at InfoSecurity Europe in London with Studio C60 co-founder Marco Ciappelli, recording conversations with journalists, analysts, former government cyber leaders, policy directors, and the vendors working the floor. The first thing you notice is what is missing. After RSAC, where you cannot escape AI, London felt quieter, more tempered. As Forrester's Madeline Vanderhout put it when we caught up, the messaging here is more pragmatic, less flashy, a bit less to the far extent.

AI is in the room, but it is a piece of the conversation rather than the whole maniacal pitch. That restraint is the good news. It is also the cover story. Underneath the calmer signage, an industry is quietly arguing with itself about what it even is anymore.

and doing it while the clock that governs the whole business accelerates past the point where humans can keep up. Three days of conversations kept landing on the same uncomfortable question. When everything moves at machine speed and every booth promises an outcome, what are we actually measuring? What does a security program measure when the clock runs in seconds?

The honest answer is that most programs do not yet know and the timeline no longer waits for them to figure it out. At the OWASP Gen.AI Security Summit, John Soteropolis shared a number that should reorganize how every SOC thinks about response. The time from an attacker's initial access to the next stage has, in agentic scenarios, collapsed from 8 hours to 22 seconds.

Cynthia Kaiser, who ran cyber threat intelligence work as a deputy assistant director at the FBI and now tracks ransomware at Halcyon, put the same physics in operational terms. The average ransomware attack she tracks runs about four hours from initial access to encryption, with some completing in under an hour, and the most common time to strike is a Wednesday night. Put your phone down at dinner, pick it back up, and the whole event is over. As she said plainly, humans cannot move at that speed.

So the program has to. And here is where the measurement problem starts, because moving at machine speed forces a question most teams have been allowed to defer. What does working mean? Matt Middleton-Leal at Qualys was blunt about it.

Measuring risk was never the point. His team showed me a client environment with 62 million risk findings that collapsed to roughly 2 million theoretical risks, then to about a million once business context was applied, then to under 1% once they tested which findings could actually be executed. The dashboard was never the deliverable. Remediation was.

If we have got to rely on service desk tickets before we make a change he said we have already failed Corelight Matt Ellison framed the same tension from the network side A detection is only the opening question What matters is whether you can prove what it actually is. He's blunt that a black box tells you little. Something goes in, something comes out. Corelight keeps the data behind every conclusion in the open, so an analyst can follow the flow and verify it rather than trust it.

In one proof of value, his team surfaced a smoking gun in 30 minutes, sensitive traffic crossing the network unencrypted that the customer had never seen. And on the compliance tools bought to satisfy NIS2 and DORA, he is unsparing. A box you switch on and never look at, then wave at the auditor, is a cost that returns nothing. Meanwhile, the board has started asking the only question that matters and the one hardest to answer.

Ian Schenkel at Intel 471 described the rhetoric shift he is hearing from CISOs. Boards have moved from, my IT team has this handled, to show me proof we are okay. Madeline framed the engine behind it precisely. AI is moving from experimentation to deployment inside organizations, and that creates boardroom liability.

Liability is driving the caution I felt on the floor. James Morris, a former UK member of Parliament now running a cyber and resilience policy centre made the structural version of the point. Resilience has stopped meaning power plants and rail lines, and started meaning the entire economy. The Marx and Spencer and Jaguar Land Rover breaches paralyzed real businesses, and as he noted, they would not even have been captured by the legislation currently moving through Parliament.

The definition is changing faster than the rules that depend on it. If the work moves in-house and the floor cannot prove its claims, what is left to sell? Less than the floor thinks, and the next 12 to 18 months will sort out which companies were selling a capability versus a category that AI is about to absorb. I have said this to Marco a few times now, and I will put it in writing.

I do not think this environment looks the same in 12 to 18 months. Not because AI kills startups, though some will run out of runway and a few will get acquired for doing something genuinely unique. It is that as AI gets adopted inside the security organization, some of what fills today's expo hall stops being necessary. New roles appear, the orchestration roles, the people Madelaine and I kept returning to when we talked about where the security architect even sits now.

Those roles need new tools, and someone has to manage them with new systems. It will not just be networks, endpoints, and ASOC. Teams will also, I suspect, trust their own AI over a vendor's. They will want their own model, fed by their own knowledge base.

My function, not someone else's black box. The market is broadening at the same time it is thinning. Salesforce had a presence at a security conference. Non-security players are moving in because the buyer is now the business, not just the SoC.

And the most honest mirror on the floor came from the criminal economy. Cynthia's team watched the market for AI attack tools in the cybercriminal underground go from 38 posts in December to over 1,402 months later. Tiered free and paid access, redundancy across platforms, an AI-run call center for sale that handles 120 simultaneous calls with simulated keystrokes. As she said, it sounds like what software as a service companies do.

The attackers have already productized. The defense is racing to match it. Sumo Logic's Bill Peterson showed the defender's version of the same move. His SOC analyst agent and MCP server are not built to remove the analyst They take the work that has already been proven Fix one server prove the solution then let an agent apply that proven fix to the other 599 identical machines under human oversight, collapsing three weeks of manual effort into a weekend.

He frames the payoff the way a board hears it, for a $40 billion company. Cutting mean time to resolve by 20% is real money. Proof first, then repeated at scale. Qualys described a client preparing to roll out 90,000 MCP agents that nobody fully understands yet.

And then there is the cost of waiting, made concrete. Rick Ferguson reframed post-quantum cryptography as something most procurement conversations leave out entirely. Whatever you install today will still be running when the math that protects it breaks. Harvest now, decrypt later is not theoretical.

The infrastructure and the intent already exist. His point was not fear. It was a purchasing decision you are making today whether you realize it or not. The same Y2K logic I worked through decades ago.

Not will it survive, but what should we replace anyway and who holds the checkbook? Underneath all of it sits the consolidation question. Manage Engines Vaimalraj Sampathkumar argued the problem is not a lack of tools. It is that 40-plus tools sit in silos refusing to work together, so they sell solutions rather than products.

Apricorn's new chief executive told me he was hired specifically to connect a niche storage product to the macro security picture. When positioning a product as relevant becomes the executive's primary job, that tells you the market is already sorting survivors from the soon-to-be-absorbed. When the whole floor agrees on the vocabulary, what is the language hiding? That nobody has agreed on what the words mean, and a word everyone shares is a word that has stopped helping anyone choose.

Listen across the floor and you hear remarkable agreement. Everyone enables. Nobody is the department of no anymore. Qualys disowned the phrase, and at the OWASP summit a Deloitte panelist said the quiet part out loud.

Stop being the ministry of no because people will bypass you and do it anyway. Everyone keeps the human in the loop. Intel 471 selling human-led intelligence against AI only upstarts. Marco noting that nobody believes the pitch where you take the human out.

Everyone sells resilience. At RSAC, Madeline and I agreed. The drumbeat was resilience. In London, the word I heard over and over was sovereignty.

sharpened by the European Sovereign Cloud announcements landing that very week and the Cyber Resilience Act sitting underneath them. Sumo Logic's booth had the concrete version, joining the AWS European Sovereign Cloud, so a regulated customer can keep incident response running while proving to regulators that the data and the people watching it sit in region. Dan Raywood, who has covered this industry for 18 years, gave the optimistic read, Marketing has moved away from buy this or everything falls apart toward here is where the failings were.

Buyers are discerning. They know when they are being oversold. That is real progress. But Dan also asked the question the whole pragmatic grown-up floor still cannot answer.

How does anyone actually know what to buy? Is it the reseller, the analyst's upper right quadrant, or something else entirely? That is the tell. When every booth converges on the same three or four words, the words stop doing the one job language is supposed to do at a trade show.

Help a buyer tell two things apart And the gap between the vocabulary and the outcome is exactly where Sarah Armstrong Smith after nearly 30 years in the field refused to be polite We have more tools more people more AI than ever she said and it is still getting worse How many wake-up calls do you need? The narrative says we are maturing. The data says we are losing ground. Both cannot be the measure of success.

The fourth lens. What were we actually measuring? Here is the connective view, and it is not comfortable for the side I have worked on for 30 years, the messaging and go-to-market side of this industry. The vocabulary on that floor moved faster than the products underneath it.

The industry learned to say outcomes, resilience, sovereignty, and human-in-the-loop, all the right words, in the more honest European register. But very few of the booths I walked could connect any of those words to a definition of success a buyer could verify. Madelaine said it, and I agreed in the moment. A large share of what is down in the expo hall does not address what the analysts and CISOs are actually wrestling with upstairs.

The go-to-market caught up to the language. The capability did not. That is a marketing achievement masquerading as a market. And proving it is the harder half of the job.

Naming the outcome a customer gets, the value, the result, the line on the slide, is the easy part. Proving you can produce that outcome again, in a different environment, with a different team, different assumptions, a different budget, a different threat model, different everything, is the part the vocabulary quietly skips. A result that lands once, in a controlled booth demo or a friendly reference account, is a story. Proof is the same result holding up across messy, under-resourced, mismatched reality, and then holding up again for the next buyer who shares nothing with the first except the problem.

Much of the floor was selling the story and calling it the proof. Machine speed is what turns that gap from an annoyance into a reckoning. When the clock ran in days, we will measure the value later was a survivable answer. When the time from initial access to the next stage is 22 seconds and ransomware finishes in under an hour, there is no later.

A market that never agreed on what working means is now being asked to prove it in real time, in front of a board that has discovered it is personally liable. The identity crisis is not that the industry does not know what to call itself. It is that it repositioned around outcomes without ever defining the outcome, and the bill for that is what I think comes due over the next 12 to 18 months. Not because AI arrives, but because AI removes the last place to hide the question.

So the questions I would put to my own side of the table. If you cannot say in one sentence what success looks like for your customer, what exactly is your dashboard counting? If you can say it, can you prove it twice in two environments that share nothing but the problem? When AI absorbs the function your product performs, what is the line item that survives the budget review?

And when the buyer finally asks the only question that was ever real, are we okay, does your roadmap answer it, or does it just say it faster? We made everything faster. We got very good at saying so. We still have not said what better means.

Until we do, speed is just a more efficient way of not knowing. If you would rather listen than read, you can find every Lens 4 edition narrated and waiting for you. Thanks for listening. Explore more at seanmartin.

com. We'll see you next time.

More from The ITSPmagazine Podcast

All episodes →
  • A Forrester Analyst on the Security Roles Coming Next - and What AI Makes Obsolete in Cybersecurity | A Conversation with Madelein van der Hout | On Location With Sean Martin And Marco Ciappelli - Infosecurity Europe 2026
  • The Identity Gap Behind Nearly Every Breach | A Brand Spotlight Conversation with Kevin Surace, CEO of TokenCore
  • When You Can't Trust the Face on the Call | A Brand Highlight Conversation with Kevin Surace, CEO of TokenCore
  • Who Gets to Tell Your Story? Maggie Alphonsi on Strength, Resilience & Owning the Narrative | An Analog Brain In A Digital Age With Marco Ciappelli - On Location at Infosecurity Europe 2026
  • Technology Got Safer, But The Smartest Hackers Don't Hack. They Just Ask | An Interview with Lee Clark | An Analog Brain In A Digital Age With Marco Ciappelli - On Location at Infosecurity Europe 2026
Explore the best B2B Ops podcasts →
All The ITSPmagazine Podcast episodes →