Better, Faster, More Cost-Effective – TENEX Leverages AI and Automation to Transform Security Operations

contact us

8586 Potter Park Dr.
Sarasota, FL 34238

Time-to-Value: A New Performance Standard for the AI-Native SOC

The Industry’s SOC Metrics Are Broken.

AI Broke Them. AI Will Fix Them Permanently.

Time-to-Value: A New Performance Standard for the AI-Native SOC

By – Jan Grzymala-Busse

THE PROBLEM

For two decades, security operations have been measured in MTTx terms Mean Time to Acknowledge, Detect, Respond, and Resolve. The premise behind those metrics was that detection speed correlated with risk reduction. That premise no longer holds.

Three forces have decoupled detection speed from real risk. First, frontier-AI capability research is now surfacing zero-day vulnerabilities in every major operating system and browser, with thousands more in the disclosure pipeline. Second, public agentic exploitation workflows can take a CVE number alone and produce a working exploit in minutes, at retail API pricing. Third, supply-chain compromises now drop malicious code into millions of developer environments inside hours, before any detection rule has been written.

The net effect: time-to-exploit has collapsed from 63 days in 2018 to -7.4 days in 2026, attackers, on average, now exploit a week before patches are available. Adversary hand-off inside compromised networks now happens in 22 seconds. Median dwell time, the metric every MDR claims to drive down, has actually risen for the first time in over a decade.

THE FIX: TIME TO VALUE

An MDR cannot honestly report success in MTTx terms when the attacker’s clock no longer starts when the detection fires. It starts when the vulnerability becomes exploitable in the wild, often days before any customer’s SIEM has a signal to detect.

TENEX, with its AI-native, human-led SOC approach, measures performance in Time-to-Value (TTV), the elapsed time from the first whitehat or public signal of a new threat to the moment customers are protected against it.

  • TTV-TI (Time to Value Threat Intelligence): elapsed time from first signal to operationalized indicators in customer environments.
  • TTV-DTEN (Time to Value Detection Engineering): elapsed time from first signal to a deployed, tested detection rule covering the threat.

They start the clock when the threat does, not when the SOC notices a problem.

THE BOTTOM LINE

MDRs that continue to report only MTTx are measuring the wrong clock. As frontier-AI offensive capability proliferates, the industry’s moral obligation is to measure, the only clock that matters: time to value, end to end, against an attacker who is moving at machine speed.

TTV is not a metric a provider or team can simply choose to adopt. An MSSP monitors and escalates. A traditional provider or team adds threat-intelligence and detection-engineering teams, but those teams work manually, at analyst pace, and the service still engages off the customer alert. TENEX’s AI SOC runs both functions as

continuously operating agents that proactively monitor the software supply chain, vulnerability disclosures, and the broader threat landscape, then assess, enrich, and deploy validated protection at T0, before a customer environment ever produces a signal. Proactive, agentic threat intelligence and detection is a fundamentally different operating model, and it is why only TENEX’s AI SOC and MDR offerings can commit to TTV rather than merely report it.

The technical appendix that follows documents the threat data behind this argument and TENEX’s measurement framework in detail.

Keep Reading The White Paper

  • Drift Protocol Suffers $285 Million Cryptocurrency Theft – The decentralized finance platform experienced an active cyberattack resulting in hundreds of millions in losses, demonstrating the continued vulnerability of financial technology infrastructure to sophisticated threat actors [1].
  • Nissan Data Breach Through Third-Party Vendor – The Everest hacking group claimed access to 910 gigabytes of customer and dealership data through a compromised vendor, highlighting the persistent risk of third-party supply chain vulnerabilities [2].
  • North Dakota Water Treatment Plant Hit by Ransomware – Critical infrastructure continues to face targeted attacks, with the Minot water treatment facility experiencing ransomware deployment while maintaining operational continuity [7].
  • CERT-UA Impersonation Campaign Distributes AGEWHEEZE Malware – Threat actors successfully impersonated Ukraine’s cybersecurity agency to distribute remote access trojans to over one million email addresses, targeting state organizations and critical infrastructure [10].
  • Apple Deploys Emergency iOS 18 Security Patch – Apple broke precedent by providing security updates for older iOS versions due to the severity of the DarkSword exploit, which can infect devices through malicious websites with zero user interaction [15].
  • VMware ESXi Remains Prime Ransomware Target – Multiple ransomware families including LockBit, DragonForce, and Akira continue targeting hypervisor infrastructure, with recent zero-day exploits (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) being used in the wild for over a year before disclosure [18].
  • Fortinet Faces Seventh SQL Injection Vulnerability in 12 Months – CVE-2026-21643 in FortiClient EMS allows unauthenticated remote code execution, with active exploitation confirmed as recently as four days ago [30].
  • Google Patches Fourth Chrome Zero-Day of 2026 – CVE-2026-5281, a use-after-free vulnerability in Dawn WebGPU implementation, was actively exploited in the wild, marking an acceleration in browser-based attack campaigns [27].
  • Cisco Releases Critical Security Updates – Multiple vulnerabilities across Cisco’s infrastructure portfolio, including CVE-2026-20160 (CVSS 9.8) in Smart Software Manager On-Prem, allow unauthenticated remote command execution [21].
  • Latin American Governments Face Intensified Cyber Pressure – Coordinated attacks against government systems across Puerto Rico and Colombia’s health sector indicate state-sponsored campaigns targeting regional infrastructure [11].

AI & Innovation Watch: The Future of Cyber

Artificial intelligence has crossed a critical threshold from defensive tool to offensive weapon, with researchers demonstrating that LLMs can now discover and exploit zero-day vulnerabilities faster than human security teams can patch them. This development fundamentally alters the economics of cybersecurity and demands immediate strategic response.

Security researcher Hung Nguyen demonstrated that Anthropic’s Claude Code could identify zero-day remote code execution vulnerabilities in both Vim and GNU Emacs within minutes using simple prompts [20]. The AI not only discovered the flaws but also generated proof-of-concept exploits, including CVE-2026-34714 in Vim with a CVSS score of 9.2. This represents a paradigm shift where AI tools can outpace traditional vulnerability discovery and exploitation timelines by orders of magnitude.

The implications extend beyond individual vulnerabilities to systemic risk. Anthropic previously revealed that its Opus 4.6 model identified 500 high-severity security vulnerabilities, suggesting that AI-powered vulnerability research will soon exceed human capabilities in both speed and scale [20]. Organizations must now assume that their code bases contain discoverable vulnerabilities that AI tools can identify and weaponize faster than traditional security processes can address them.

Simultaneously, Apple’s deployment of Background Security Improvements demonstrates the defensive potential of AI-augmented security operations [28]. These continuous, lightweight security updates delivered between major releases represent a new model for rapid response to emerging threats. However, the defensive applications of AI remain reactive compared to the proactive offensive capabilities demonstrated by vulnerability discovery tools.

Threat Intelligence (The “Bad Guys”): Who is Attacking?

Nation-state actors and ransomware groups are converging on supply chain attacks and AI-assisted reconnaissance, creating a multi-vector threat environment that traditional perimeter defenses cannot address. The sophistication and coordination of current campaigns indicate a fundamental evolution in adversary capabilities.

Sapphire Sleet (North Korean State Actor): Successfully compromised the Axios npm package supply chain, injecting malicious dependencies into versions 1.14.1 and 0.30.4 that automatically deployed platform-specific remote access trojans across Windows, macOS, and Linux systems [14]. The attack leveraged silent install-time code execution through dependency insertion, affecting any projects with auto-update configurations. This demonstrates advanced understanding of modern development workflows and represents a significant escalation in supply chain targeting.

UAC-0255 (Cyber Serp): Conducted a sophisticated impersonation campaign targeting Ukrainian organizations by masquerading as CERT-UA to distribute AGEWHEEZE malware [10]. The group claims to have sent phishing emails to one million ukr[.]net mailboxes and compromised over 200,000 devices. Their use of AI-generated websites and strategic timing during conflict periods indicates advanced social engineering capabilities combined with technical sophistication.

Ransomware Ecosystem Targeting VMware ESXi: Multiple ransomware families including LockBit, DragonForce, Akira, Black Basta, and Cactus have developed specialized ESXi encryptors, recognizing hypervisor infrastructure as high-value targets [18]. Recent campaigns exploited zero-day vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) that remained unpatched for over a year, enabling mass encryption of virtual machine fleets. The Marks & Spencer attack in April 2025 resulted in over $400 million in damages, demonstrating the business continuity impact of hypervisor compromise.

Everest Ransomware Group: Claimed breach of Nissan’s third-party vendor systems, accessing 910 gigabytes of customer and dealership data [2]. The group’s focus on supply chain infiltration rather than direct organizational targeting reflects the broader shift toward vendor-mediated attacks that bypass primary security controls.

Critical Vulnerabilities (The “Fix List”): What to Patch Now

These vulnerabilities represent immediate existential threats to enterprise infrastructure, with active exploitation confirmed and potential for catastrophic business impact. Priority patching within 48 hours is essential to prevent compromise.

CVE-2026-20160 (CVSS 9.8): Cisco Smart Software Manager On-Prem suffers from unintentional exposure of internal services, allowing unauthenticated remote attackers to execute arbitrary commands with root-level privileges [21]. This critical vulnerability affects centralized software management infrastructure and requires immediate patching to prevent complete system compromise.

CVE-2026-5281 (CVSS 8.8): Google Chrome use-after-free vulnerability in Dawn WebGPU implementation is actively exploited in the wild [27]. This represents the fourth Chrome zero-day patched in 2026, indicating sustained targeting of browser infrastructure. Organizations must ensure immediate Chrome updates across all endpoints.

CVE-2026-21643 (CVSS 9.8): Fortinet FortiClient EMS SQL injection vulnerability allows unauthenticated remote code execution via crafted HTTP requests [30]. With over 2,400 internet-exposed instances identified and active exploitation confirmed, this vulnerability poses immediate risk to endpoint management infrastructure.

CVE-2026-34714 (CVSS 9.2): Vim text editor remote code execution vulnerability discovered through AI-assisted analysis allows arbitrary command execution when opening malicious files [20]. While Vim has released patches, the discovery method demonstrates how AI tools can rapidly identify previously unknown vulnerabilities in widely-used software.

Axios npm Package Compromise: Versions 1.14.1 and 0.30.4 contain malicious dependencies that deploy platform-specific remote access trojans [14]. Organizations must immediately audit development environments, rotate exposed credentials, and implement npm package pinning to prevent automatic updates to compromised versions.

The TENEX 10X

Implement immediate supply chain governance controls and AI-augmented threat detection capabilities to address the fundamental shift in attack vectors and discovery timelines. Traditional reactive security models are insufficient against AI-assisted adversaries operating at machine speed.

Organizations must immediately audit all third-party dependencies, implement package pinning for critical development frameworks, and establish continuous monitoring of supply chain integrity. The Axios compromise demonstrates that trusted development tools can become attack vectors overnight, requiring proactive dependency management rather than reactive patching. Simultaneously, deploy AI-powered vulnerability scanning across all code bases to identify potential zero-days before adversaries can exploit them, as demonstrated by the Vim and Emacs discoveries.

Prioritize hypervisor security and endpoint management infrastructure as primary attack surfaces, implementing network segmentation and privileged access controls to limit blast radius from successful compromises. The concentration of ransomware attacks on VMware ESXi and the Fortinet EMS vulnerabilities indicate that centralized management platforms represent high-value targets that can provide adversaries with broad organizational access through single points of failure.

Establish continuous threat intelligence integration with automated response capabilities to address the acceleration in attack timelines. The combination of AI-discovered vulnerabilities and supply chain compromises creates a threat environment where manual security processes cannot maintain adequate response speed. Organizations that fail to implement automated threat detection and response capabilities will face inevitable compromise as adversaries leverage AI tools to outpace human-driven security operations.

Sources

[1] The Record from Recorded Future News (April 1, 2026). “Crypto platform Drift suspends services after millions stolen in security incident.https://therecord.media/drift-crypto-heist-solana-hacker

[2] The Record from Recorded Future News (April 1, 2026). “Nissan says stolen data came from third-party vendor after hacking group claims breach.https://therecord.media/nissan-hackers-data-breach

[7] The Record from Recorded Future News (April 1, 2026). “North Dakota water treatment plant reports March ransomware attack.https://therecord.media/north-dakota-ransomware-water-plant

[10] The Hacker News (April 1, 2026). “CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails.https://thehackernews.com/2026/04/cert-ua-impersonation-campaign-spread.html

[11] Dark Reading (April 1, 2026). “Cyberattacks Intensify Pressure on Latin American Governments.https://www.darkreading.com/cyber-risk/cyberattacks-latin-american-governments

[14] Microsoft Security Blog (April 1, 2026). “Mitigating the Axios npm supply chain compromise.https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios-npm-supply-chain-compromise/

[15] Latest news (April 1, 2026). “Still running iOS 18? Install this critical update ASAP.https://www.zdnet.com/article/ios-18-darksword-security-patch/

[18] Security Risk Advisors (April 1, 2026). “Single Point of Failure: Threat Hunting and Defending ESXi Attacks.https://sra.io/blog/single-point-of-failure-threat-hunting-and-defending-esxi-attacks/

[20] CSO Online (April 1, 2026). “Vim and GNU Emacs: Claude Code helpfully found zero-day exploits for both.https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html

[21] Cisco Security Advisory (April 1, 2026). “Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability.https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Smart%20Software%20Manager%20On-Prem%20Arbitrary%20Command%20Execution%20Vulnerability%26vs_k=1

[27] BleepingComputer (April 1, 2026). “Google fixes fourth Chrome zero-day exploited in attacks in 2026.https://www.bleepingcomputer.com/news/security/google-fixes-fourth-chrome-zero-day-exploited-in-attacks-in-2026/

[28] SecureMac (March 31, 2026). “Apple Is Moving Faster, but So Are the Scams.https://www.securemac.com/news/apple-is-moving-faster-but-so-are-the-scams

[30] CSO Online (March 30, 2026). “Fortinet hit by another exploited cybersecurity flaw.https://www.csoonline.com/article/4152117/fortinet-hit-by-another-exploited-cybersecurity-flaw.html

Keep Up with TENEX.AI

Press Releases and Company News

TENEX Partners with Google Cloud on Google AI Threat Defense

TENEX.AI partners to deliver Google Cloud’s new autonomous, continuous security platform at...

It’s Time To Protect.

https://www.youtube.com/watch?v=uqMRRrm6IgM AI-native. Human-led. Because one without the other...

Why Piers Morgan Joined TENEX

And Why the Future of Global Cybersecurity Is Being Rewritten Right Now After more than 20 years...

Reviews

Perspectives from Those Who Know Us Best

Eric Foster
CEO of TENEX
"TENEX was founded to help enterprises overcome persistent security challenges by leveraging the scale and efficiency of modern cloud provider security stacks combined with AI-driven services. We aim to deliver exceptional outcomes with agility and cost-effectiveness."
Zane Lackey
General Partner, Andreessen Horowitz
"TENEX is tackling one of the most critical challenges in cybersecurity: the inefficiency of managing comprehensive security programs”
Iman Ghanizada
Godfather of Autonomic Security
"In an era where modern threat actors can bypass years of security controls in minutes, the industry needed a fundamentally different approach to security operations. Tenex represents the first true implementation of what autonomic defenses must look like in an AI-first world."
Elias "Lou" Manousos
Shield Cap
"At TENEX, we’re not just delivering another cybersecurity service—we’re redefining how security operates in an AI-driven world."
Zane Lackey
General Partner, Andreessen Horowitz
With their AI-driven, cloud-native platform and deep security expertise, TENEX is strongly positioned to deliver automated, scalable solutions that modern enterprise customers need. We are proud to support Eric Foster and the TENEX team as they redefine the way cybersecurity is delivered.
Chad Kreimendahl
CEO, Onspring
Imagine a cybersecurity partner that redefines industry standards. An AI-first approach that integrates seamlessly with your infrastructure, automating routine tasks and enabling your team to focus on strategic priorities. With advanced technology and expertise, we envision a future that sustains and enhances our operational excellence. That's what the team at Tenex has done for us, and what they can do for you.
#side-panel.side-panel .side-panel_sidebar {background-color: #070C1F;}
White Papers

Download To View

View Our Open Positions

Plan 3

Comprehensive MDR

Please fill out your information below to get started!

Name
Plan 2

Advanced Oversight

Please fill out your information below to get started!

Name
Plan 1

Core Security Platform

Please fill out your information below to get started!

Name