The window between initial access and the next attacker move has collapsed from eight hours to twenty-two seconds, and no human-paced incident response process survives that math. John Sotiropoulos and Rock Lambros close out a day of OWASP GenAI Security work at Infosecurity Europe 2026 with the launch of an Agentic Security Council and a Top 10 for LLM update built on real incident data.
Sean Martin catches John Sotiropoulos and Rock Lambros at the end of the OWASP GenAI Security Summit, held alongside Infosecurity Europe 2026 at ExCeL London. Both are deep in the standards work: John Sotiropoulos co-leads the OWASP Agentic Security Initiative and sits on the board of the OWASP GenAI Security Project, and Rock Lambros serves as Director of AI Standards and Governance at Zenity and co-leads the OWASP Top 10 for LLM 2026 update.
The headline from the day is the launch of the Agentic Security Council, bringing Oxford University, Queen's University Belfast, CSIT, and other research institutions into the same room as practitioners and industry. John Sotiropoulos frames the reasoning bluntly: content on its own does not create change. Papers and Top 10 lists matter, but they only matter if the people building and defending systems can act on them.
The number that reframes everything is twenty-two seconds. That is the average time from an initial access event to the next attacker action, down from eight hours. John Sotiropoulos puts the question directly to anyone still running a human-speed playbook: how do you respond to that? A panel on incident response with participants from AWS and Microsoft, a keynote from Microsoft's National Security Officer, and a walkthrough of the State of Agentic Security and Governance report all point at the same shift toward runtime security.
Rock Lambros brings a different kind of grounding. For the first time in the four-year history of the OWASP Top 10 for LLM, the update draws on a corpus of reported incidents rather than opinion and community vote alone. It is one data point among several, but it is data, and that changes what the list can claim.
A panel with the heads of AI security at Deloitte supplies the operational counterweight. As one of them puts it, security has to stop being the Ministry of No, because people will route around it and ship anyway. The report's adoption tiers and maturity levels exist for exactly that reason: security that lives only inside a PDF is not security.
The invitation from both John Sotiropoulos and Rock Lambros is the same. Join the work. Research, red teamers, defenders, builders, and SecOps all looking at one view of what is actually happening is the only version of this that scales to machine speed.
⬥HOST⬥
Sean Martin, CISSP | Co-Founder, ITSPmagazine & Studio C60 | Host, Redefining CyberSecurity Podcast & Music Evolves Podcast | https://www.seanmartin.com/
⬥GUESTS⬥
John Sotiropoulos, Deep Cyber | Co-Lead, OWASP Agentic Security Initiative; Board Director, OWASP GenAI Security Project | On LinkedIn: https://www.linkedin.com/in/jsotiropoulos/
Rock Lambros, Director of AI Standards and Governance, Zenity; Founder, RockCyber | Co-Lead, OWASP Top 10 for LLM 2026 | On LinkedIn: https://www.linkedin.com/in/rocklambros/
⬥RESOURCES⬥
Infosecurity Europe 2026 is taking place June 2-4, 2026 | ExCeL London. Follow our coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage
OWASP GenAI Security Project | https://genai.owasp.org
Contribute to the OWASP GenAI Security Project | https://genai.owasp.org/contribute
The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/
Redefining CyberSecurity Podcast | https://www.seanmartin.com/redefining-cybersecurity-podcast
On Location | https://www.itspmagazine.com/on-location
🥁 🎶 A very big THANK YOU to our Infosecurity Europe 2026 Full Coverage Sponsors: Corelight · Qualys · Sumo Logic 👏 👏 👏
⬥KEYWORDS⬥
sean martin, john sotiropoulos, rock lambros, infosecurity europe 2026, owasp, genai security project, agentic security, agentic security initiative, agentic security council, owasp top 10 for llm, ai security, incident response, runtime security, ai governance, zenity, rockcyber, deep cyber, dwell time, secops, red teaming, on location, itspmagazine