Divert deployed "diversions" on the customer's edge before we launched our experiment. While we didn't enable blocking so we could properly observe the timing of everything, we found that Divert blocked the models from real customer assets on average nearly 10 minutes before they could reach RCE.
We don't think that fixing all security debt is a realistic goal. Unpatched apps, config mistakes, marketing/sales teams shipping their own code, breached creds, and an accelerating vulnerability landscape (among so many other possibilities) make it hard to stay safe.
We built a defense on that premise; turn your org's edge into a minefield.
https://www.divert.cloud/blog/autonomous-ai-attacker-field-r...