← All transcripts

Building Cyber Defense for the Agentic Era Transcript, AI Summary & Key Points

a16z · 3 days ago · Science & Technology · 47:50 · EN

Watch on YouTube

AI Summary

A conversation between a16z General Partner David George and Armadin founder and CEO Kevin Mandia on how AI changes cybersecurity. After 30 years in security and building Mandiant, Kevin Mandia rejoined the field because AI changes everything he built: AI attackers probe thousands of paths simultaneously, work at machine speed, and democratize elite offensive expertise, so defense will ultimately need to become autonomous too. Armadin's approach has two acts — Armadin Red, continuously attacking customer networks with a swarm of AI agents to find exploitable vulnerabilities before adversaries do (over 90 zero-days found in production at Fortune 500 customers since January 2026), and Armadin Blue, building toward autonomous defenses that generate compensating controls in real time with partners like CrowdStrike and Palo Alto Networks. Mandia argues pen testing is dead — it scans only for known issues, produces noise, and can't carry exploits — while continuous AI red teaming verifies exploitability with no false positives. Humans cannot remain in the detect-and-respond loop; AI will govern prevention and execute detection and response. The Hugging Face incident shows that securing agents requires security domain expertise plus layered, classifier-based guardrails. He closes with lessons on building a company at AI speed: fundraise, scale processes, build the go-to-market ahead of time, and differentiate only by getting customers and making them happy, repeating fast.

Key Points

  • AI changes the economics of cyberattacks: attackers are no longer limited to one path into a network, and what AI does in a microsecond would take 70 humans — 'apples to oranges'.
  • Modern nation-state attackers hack with a 'sniper round' — restricted targeting going deep on specific objectives — while AI turns offense into a 'drone swarm': sloppier, louder, but more comprehensive and effective; nations must now decide when to swarm and when to snipe.
  • Less capable, less technical attackers will appear far more successful with AI, making attribution harder — defenses will be attacked by models without knowing if a nation or a human is behind them.
  • Armadin's Act One is Armadin Red: a 'hyperattack' throws a drone swarm of agents at a customer network, maps every service, route, system and asset into a metadata twin, then cheaply polls for change and attacks the change.
  • Armadin's Act Two is Armadin Blue: building autonomous defenses with CrowdStrike, Palo Alto Networks and Fortinet that create compensating controls at speed — a bad patch stopping an intruder beats an intrusion.
  • Pen testing is dead: it scans only for what's already known, produces lists of vulns that don't matter, and can't carry the exploit — Armadin verifies remote code execution with no false positives and calls CISOs within about 48 hours.
  • Armadin has found over 90 zero-days at customer sites, all in production at Fortune 500 companies, since January 2026, found black-box from the internet without source code.
  • If you have humans in the detect-and-respond loop, you'll be too slow — AI will govern prevention and perform detection and response; every security phase's window is narrowing.

Tools & resources

3 items

Links mentioned

🔒 Full analysis locked

Unlock more videos and the full analysis

A credit unlocks one video's full analysis for good — the build steps, the tools and how each was used, the methods behind every use case. Pro opens the whole library instead, and raises how many videos you can analyse a day.

Unlock full analysis — free

Transcript

Searchable transcript of Building Cyber Defense for the Agentic Era — a16z (47:50). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by a16z. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:00 You don't have a defense unless you have a great offense to go up against. You want to be the Baltimore Ravens [music] defense of 2000. You kind of want to have your practice offense really push you. That's what Arman's going to do. We're going to be the all-star team on offense [music] coming at you so you can train your defense with what we're doing.

00:15 You built mandate a great success. Why did you decide to get back on the field? >> I don't want to sit out the AI shift change when I've done 30 years in [music] security and the whole damn thing's about to change. What AI does in a microcond would take 70 humans. They can't even do it. It's apples to oranges. [music] This is a tsunami like has never been seen before in security.

00:34 >> The whole let's slow down the models. We don't want cyber too late. The open models are already good enough. Armadin since January of this year, we have found over 90 zero days at customer sites all in production. This is not like rinky dink companies like these are like Fortune 500 companies. The differences or similarities between nation state attacks compared to AI today and then where you think AI can be in a couple years.

00:56 On [music] the defensive side, we're gonna say we're being attacked by these models, but we're not sure who's behind them. Is it a nation? Is it a human? Is it >> Kevin, thanks for being here. >> No, thank you. >> Okay, so you built Mandette. >> Yes, >> obviously a great success. Um, many different chapters, you know, it ended up, you know, inside of Google ultimately.

01:16 Um, why did you decide to get back on the field? It's a good question and you know I don't know if I decided it and that'll sound weird but I met with David Slater and with Travis Lam the other founders and Evan Pñena I knew uh you know I I could say they started this company they are the founders you know I met them they had the idea they pitched me on what they wanted to do and I saw the talent in them like Travis is a generational talent David Slater's and I mean this in a positive way freak nature, you know, like

01:50 these guys are are really, really good. Evan Pñena is exceptional at what he does. >> And when you meet that team and you talk to them, the whole time I was listening to what they were doing, I was thinking, I want to be a part of this. You know, I don't want to sit out the AI shift change when I've done 30 years in security and the whole damn thing's about to change.

02:09 You know, that's great. Everything I did is dead and everything else is new. Uh but meeting that team and they were starting the company and me realizing I'm I think I'm a real good fit with these guys um to accelerate the need like what Armadin is building every company needs now and I I was like this team that can build it and I think I can answer the now let's you know 30 years in security you meet a few people let's go to those people and say we've built what you need.

02:39 Yeah. You know so I almost felt compelled to do it. I know that sounds weird, but I would not have founded a company again in my, you know, in mid50s and I was doing venture. >> It wasn't like, oh, I'm an entrepreneur and I love starting companies. That's not it. >> And it wasn't, I'm not a VC. I'm just an operational guy. That's not it. I met the team and went, we have to do this.

03:03 Yeah. I mean, that's really it. >> Yeah. And this whole AIC change was happening. Like that's the catalyst, right? >> Yes. So yeah tell us about what Armanin does. So, Armadin leverages frontier models and AI on offense to test do you have exploitable risk and the re and that's what we do today. We call it armored in red. But we when we started a company Travis and and David Slater and Evan all knew the future of cyber security is going to be a the good guys have to build the offensive cyber cannon and shoot it at

03:36 networks to make sure those networks can withstand these attacks because they're the ones that are coming. But we also knew it's going to be AI on offense built by the good guys working and training with AI on defense built by the good guys. And you have to have both. So our act one was we got to be the best in the world at finding exploitable risk.

03:55 If we're five minutes ahead of the bad actor, whether it be a nation state, criminal nuisance, if we're five minutes ahead of them, we also recognized our act too, armed it in blue. We got to stop it. compensating control tourniquet. >> And so that's what Armadin does. We're building the force field you will need in the AI age to defend yourself from AI attacks.

04:19 >> Yeah. Tell [snorts and clears throat] us about the nature of the capabilities of AI attacks today and then where you think it goes. >> Well, great. So the nature of them is first off, we're getting a weird window in time where we're seeing them, but not at the same level you'd expect. Like I've seen nothing like what Armadin's already built in the wild, which is there's 25,000 agents all in concert, all working together doing really, really smart things without going on bizarre fishing trips.

04:47 Because when you respond to an AI attack, you can tell it's AI very quickly. At least I can because I've done, you know, I've thought about a lot of offense. I've responded to a lot of attacks in the past that were led by humans, >> right? and a human goes to point A, then to point B, then to point C through their intrusion. AI does little things like four or five differences, but one would be it'll break into point A, then laterally move to point B, next thing you know, it's trying to break into point A again.

05:17 >> Yeah. >> It's like, I get the drone swarm, but you could probably coordinate and think a little bit better. And that's that's where it's at today. It'll get better and cleaner. Um, but the differences are first and foremost, uh, the scale of what AI can do dwarfs humans. like in ways humans don't even get right. >> Um so you have a scaling problem in that humans could always find only one path into a network.

05:39 >> Yeah. They had to be selective because they had to devote their limited resources to one direct path. Right. >> Yes. And and then uh so scale is a challenge. Speed ridiculous. What AI does in a microscond would take 70 humans they can't even do it. It's apples to oranges. And then so what was always lacking is is AI creative >> or effective? But when it comes to what we do, u we don't need the fanciest model.

06:06 We're not trying to speak 400 languages, you know, with our models and all that kind of thing. What Armenan's doing on offense is we're finding vulnerabilities, exploitable risk. That is code. That's a structured language, a structured process. Because it's structured, AI is going to be great at it. Right. >> Right. So, I really think it's already here today.

06:26 Like the whole let's slow down the models. We don't want cyber risk too late. the open models are already good enough and and these things are common now. It's just a matter of the minute you have anonymous availability of GPUs, you'll see far more criminal attacks. >> Oh, interesting. >> Yeah. You know what I mean? But until you can attack anonymously and you know, it's hard to do crime when people know your name.

06:49 It's better to if you can if you can commit a crime anonymously, here's my tip for criminals. If you can commit a crime anonymously, that's a lot smarter than doing it with your jersey on with your name on it. And uh so anyway the diff the difference in attacks and what we're seeing now we are at the precipice first inning still of AIE attacks coming um and I think that's just because of the cost and availability of the models is not as readily available to the crim criminal element as it will be in the future.

07:17 Yes. Exactly. >> Okay. So you your experience in working in the security industry for 30 years, >> you um probably saw a fair amount of nation state [snorts] attacks, right? >> Every day. >> Every day. So talk about the differences or similarities between nation state attacks and I use that just to say the most sophisticated most you know most whatever most successful if you will types of attacks compared to AI today and then where you think AI can be in a couple years.

07:48 So everything's going to change rapidly, right? And uh but I can tell you nations on offense have never, in my opinion, they've never really been when you're hacking for espionage and for security reasons, you hack with what I would call kind of a sniper round. You're not spraying and praying. For the most part, modern nations on offense restrict their targeting and they go deep at very specific things like 30 defense contractors or mill you know and they go hard at that kind of think of it as you know that sniper

08:25 round with AI I think becomes more like a drone swarm you know it becomes a little bit different in the cyber domain and I think even modern nations are thinking what will our protocol be if we want attack this company, do we swarm it and just burn tokens on it? Because AI is going to do a lot of things humans just wouldn't, right? You know, so it's a little sloppier, a little louder, >> but it's more effective, >> but it's more comprehensive.

08:54 >> That's the problem. You got it. It's more effective probably because if if the and so there's going to be so many things a nation's got to think through right now and their whole doctrine will shift as as the AI shift change comes like how does AI change what our mission is? Do we maybe use the cyber domain differently? Do we drone swarm sometimes, snipe around other times?

09:13 How do we balance the two? Does it depend on risk, target, how surreptitious we want to be? Because right now AI is not a surreptitious action on offense. Yeah. >> Unless you've done a ton of post training. You got to maybe a human in the loop really looking at are we doing smart things? Because if you just go, hey, here's a prompt hack, you know, abc.com.

09:36 AI is not going to do it in a surreptitious smart way. And I think even if you ask it to, it's still not going to till it's been really trained and really had some human influence on it. So, but more generally, what you're going to see is less capable attackers, >> less technical, less successful are going to appear way more successful. It's the equalizer, right?

09:57 because every when you start using models over time what it's going to be is on the defensive side we're going to say we're being attacked by these models but we're not sure who's behind them those attacks is it a nation is it a human is it and we'll have some clue but attribution will get a little difficult so that's a long-winded answer saying in the AI age it does democratize far greater expertise for attacking victim networks >> yeah so then that is a good segue back to Armadin So um you have talked about the

10:30 defense needs to be a great offense, right? Like like best train defense with something. >> Yeah, of course you got to train your defense with something and then it needs to be continuous. Right. >> Right. So so how does the product work and then how do you get a level of sophistication such that you can identify and remediate these vulnerabilities like what you're describing that are more sophisticated than a basic prompt.

10:55 >> Okay. Lot there. I could talk for 45 minutes on it, but first I can tell you this. You don't have a defense unless you have a great offense to go up against. You know what I mean? Like, so even think in sports terms, if you want to be the Baltimore Ravens defense of 2000, >> you kind of want to have your practice offense really push you. You know what I mean?

11:11 So that you know how good you are. And that's what Arman's going to do. We're going to be, you know, the all-star team on offense coming at you so you can train your defense with with what we're doing. And that's that's going to be important. And you can't really have a human in the loop in the AIH for tactical autonomous defense. Like you got to do something fast.

11:28 You know, you got to tourniquet the wounds as fast as you can. Um so thinking back to our like you want to be able to do it continuously and that's the complexity. So we do a thing called a hyper attack. >> Yep. >> And David that's just a fancy word for we throw a drone swarm of agents at you and we map your network. Every service, every route, every system, all assets.

11:52 We may end up with terabytes of metadata on your network from this hyperattack done super fast. Just it lights you up. >> So that that way we can now it's almost like a metadata twin of what we can see. If we're on the inside do the same thing. Let's just map everything. This is the attacker's view of your network. But with that metadata we now just pull you almost like a heartbeat.

12:12 What's changed? What's changed? That's continually looking for did an app change? Did a route change? Did a service get updated? Did a new machine get presented onto the you know into the target area >> so that we can pull cheaply for change and then attack the change. Yep. >> What you really want in the future in the AI age is that you want the constant pressure of models attacking you but you can't do it all the time >> because a it's not it's cost prohibitive but b it's unnecessary.

12:40 You do it when either the threat changes, hey, new models come out, new intelligence is available, or B, your network changes, so you want to test whether that happens. And then C, you just probably just want to test. We have a board meeting tomorrow. Let's see how we do. You know what I mean? Let's audit ourselves and see where we're at. >> Um, and that's why we had over the weekend there was a zero day in a popular uh product.

13:01 And immediately we've already got the heartbeat. We just pulled the problem. >> Yeah. And our goal at Armadin is to go from, you know, common vulnerability or CVE to a a uh we can find if it's exploitable or not before bad guys can, right? You know, and not all bugs >> allow for human access to your system in a stable way. So not all bugs are created equal, right?

13:29 And so we want to make sure, hey, this one's one you really need to worry about or which ones don't give remote command execution. So, long story made short, that hyperattack, that metadata that we get allows us to kind of pull for change and attack you when your network changes. And that's the best you can do for continual and and we'll get better and better at it.

13:46 And the cost for the polling will go down. You know, it's um on small networks doesn't cost much. But on a network that changes all the time and is very large, you'd be pulling it quite a bit to make sure you don't have an exposure window. >> Yeah. Of course. So, that is actually a very good explanation for why this continuous approach matters, right?

14:03 Uh, it's so fun. Like I, you know, you and I share, >> well, you're already up against it. Somewhere out there, the criminal element will always have that random scanning and they probably aren't even using AI for it. They've got one exploit that they think works and they're just kind of scanning the world for it and then coming at the exploitable risk, you know, >> and so you're already getting some pressure on your network from an unseen force that's not well-intentioned.

14:27 You know what I mean? So, you might as well have a better force >> built by the good guys constantly putting pressure on you. Yeah, it's interesting. [clears throat] So, um, you would kind of, Armaden, I don't know, a year ago, would probably be placed in the category of pentesting, >> and you and I share history and relationship with George at CrowdStrike, right?

14:47 >> And so, they famously redefined the category from AV to EDR, and of course, they did incredible things, but the category redefin um was on the back of major infrastructure changes and product changes um, you know, and allowed them to create a product category that was far greater and bigger than AV. um talk about pentesting. What is the historical view of pentesting and why that's not what the future is?

15:11 >> Yeah, a couple things. I mean, you had to do it right. It was kind of like first gen AV. You have to buy AV. And I think when you look at Armadin, we will be as ubiquitous as AV because you have to have that AI force field of AI on offense, training AI on defense. You have to do it and you can do it. So, why wouldn't you? And um so you look at that and uh it's pen testing to me is always just scanning for what's already known and it doesn't prove whether you're really exploitable or not.

15:39 So it's always created a larger list of vans that don't matter, right? >> And so the way we wanted to do it at Armadin was we actually can carry the exploit out. We verify so there's no false positives. we can get remote code execution or get data off of that machine and a lot of pentests are nothing but hit your infrastructure not with a thinking learning technology that memorizes and knows your infrastructure like an AI agent can um so it's not going to do custom apps it it's going to uh at least the old versions of

16:13 pentesting you know the tenable the rapid 7 the qualice was more a hygiene sort of thing you know what do I have out there and what services are exposed and are there CVS available against those services or known exploitable vans against them. When you have an AI based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time.

16:36 Um, and it it's like all I can tell you is Armadin since January of this year n in 2026, we have found over 90 zero days at customer sites all in production. And >> and by the way, your customer base is [clears throat] like >> they're happy we found them before and they're like Fortune. This is not like, you know, rinky dinking companies. Like these are like Fortune 500 companies.

16:58 >> Yeah. And I don't mean that as fear, uncertainty, and doubt. But the difference is that our we've trained our models, we've post-trained all our models with real red teamers, real folks that actually can develop exploits. >> And that's important. And so when we're scanning networks, we don't have source code to review. We're not finding these zero days with source code.

17:16 We're not finding these zero days cuz we can log into an app and now we have access and we can get to other things. We are blackbox coming from the internet over 90 zero days in major software companies and they're thankful. And so you everybody's like wow mythos came out and you can scan source code and find vulnerabilities and you find thousands of them.

17:35 That's noise. >> Yes, >> we're coming from the outside and then we're calling a siso, you know, usually within 48 hours. Hey, we've got remote code execution in your DMZ. And usually from there, we're getting in and they agree with us. And they and the nice thing is we're going through uh you know the fixed side's a little bit harder, takes a little bit longer, but those companies go right into incident mode.

17:58 They respond as if it's an incident. And that's not a pentest. That is like a real adversary coming at you. And the difference between red teaming and pentesting is pentest to me is a hygiene step. And I think over time everybody would have redte teamed everything all the time if they could right it was cost prohibitive and people prohibitive with AI and an agent doing it or in our case we have lots of different types of agents doing different things >> you can now do that so I think it'll replace pen testing over time

18:28 that's just that's like a small portion of what a red team coming at you would do. >> Yeah. So [clears throat] um you talked you you mentioned earlier you know obviously that's armed and red. Yeah. >> Um you mentioned armed and blue. Talk about armed and blue. >> The armed in blue is like we can't David just show up and say hey you know you're vulnerable.

18:49 See you later you know [laughter] >> and hey the true north for every syso should be effective autonomous response. We got to build that and and we knew all along you can't just say hey we we want to be the best in world at finding exploitable risk. That's >> y >> goal number one. But then goal number two and be the best in the world at doing something about it.

19:08 And that means arm it in blue and arm it in blue will be take the information about exploitable risk and work with the defense plane. You know whether it be endpoint EDR or firewalls and create compensating controls at speed. Yes. So that if we find an attack five minutes before someone else using a model finds an attack, you're already safeguarded.

19:30 And these safeguards are going to be rudimentary potentially out of the gates right over the next few months. >> A year from now, they're just going to be there. Y because the whole cyber domain is progressing at a speed where you're going to have to defend autonomously for better or for worse. >> You know, I I'd rather have a bad patch stopping a bad guy from getting in >> than have an intrusion.

19:53 You know what I mean? So, you got to take your lesser of two things. and one's much more manageable. You never want an unknown person with arbitrary access on your network. >> And so you want to prevent that anyway you can. And I would say the first generation is we're working with Crowdstrike on it and they know it has to exist. We're working with Pan on it.

20:14 They know that that it has to exist. >> They want to all, you know, shift into the AI age with autonomous defense as well. And so we need to inform those defense platforms, you know, the Fordinets and everybody else. Here's what you can do about it. And I likened it to, you know, kind of field dressing and war. Someone gets shot, you patch it up, but that's not the hospital, you know, that's a, hey, we kind of stop the bleeding.

20:39 >> And um, but then you got to maybe do something else with more time in humans potentially or even, you know, agenic approach to it down the road. So you're going to see it happen even in if you're a siso, you're going to see autonomous defense happen even if you don't ask for it, right? >> Because of the defensive platforms you've already invested in.

20:57 >> Yeah. you mentioned earlier um [clears throat] you know some of the blurring of the lines of different categories within cyber and I think you joked that your your old days your 30 you know your 30 years of experience is uh is out the window or relevant or something like that um >> what is the future of the sock and then what do how do the categories how do the categories within cyber blend together or change >> you know if I'm a siso I do believe my true north is effective autonomous security.

21:27 You want to keep your best people engaged. You want to automate the processes that work for your organization, but you are absolutely saying what survives in the AI age and what doesn't, right? And I think we're still working through that process. I think there's whole processes in the sock that will just go away and for whatever reason, we're automating right now.

21:47 Yeah. >> You know, it over time you I can tell you this, if you have humans in the detect and respond loop, you're going to be too slow. Yes, you know what I mean? It's just not going to work well. So, you have prevent, detect, respond. Prevent's going to be governed by AI and detect and respond is going to be done by AI. And the goal in cyber security has always been if you have, you know, you want to prevent, you know, you don't want to detect and respond.

22:11 So, I just see the constant narrowing of the window of every phase to the point where, you know, we're really not doing a lot of detection and response because the window >> to do it is it happens. You got it. It's a little bit too fast. So, but you still got to have that onion peel to some extent of systems backing up systems and assuming failure somewhere, right?

22:32 >> You know, like even Armadin creating the force field, sooner or later, somebody's going to get around it. Someone's going to create an exploit before we find it somehow someway on a platform or or a um or an app that we just haven't assessed yet. It hasn't been in production at a customer's site and so we haven't looked at it and someone else finds it.

22:49 And when they do that, you will want to have a trap behind saying we've got unauthorized access or unlawful access to a system. Those traps are that you just can't have a human there. Yeah. >> I mean, it's just going to because we've already done it at Armad and when we break in and have a gentic aware internal command and control, it proliferates at a speed that is shocking.

23:13 You know, like I remember as a human, you're like typing on your keyboard, I want to go laterally move with this passphrase from here to here and you're so slow and you're doing one thing at a time. This thing just does a thousand things at once. It's just a everywhere [snorts] and you're like, "Whoa, okay, done. Got the >> Yeah. So, so the so the each [clears throat] one of those steps of the process has to be automated.

23:33 Can't be a human." >> Yeah. It's as bad as this. I mean, I don't have great analogies. It's like the balloon popped. You know, someone gets in, it's just like they're gone. the whole defense apparatus just popped. >> So, you got to get prevention right and then an immediate lock down on detect and respond however you want. And there's always gray areas between those phases because people say if you detect and respond automatically and fast, that is prevention.

23:57 >> Yep. >> So, all of it's going to change. Every sister's examining it. Every vendor is examining their role in changing into the AI shift. Um and uh so it's going to all change now, but I can't tell you if anyone's positive on how it changes. They're examining their workforce. They're examining their head count. They're examining their processes, meaning the sysos are.

24:16 And they're saying, "What do I need to look like in the modern era?" But it's too soon to tell where it lands. >> Yep. >> Um so too soon to tell what they look like, what their defense apparatus looks like. >> Um maybe so you have a bunch of Fortune 500 customers. Uh you're close with a bunch of others that are not customers. like what is the state of their vulnerability today?

24:42 >> Rapidly shrinking. You know, everybody's worried. There's a desperation in a moment in both directions. By the way, if you're on offense in Iran or Russia, you have a desperation in a moment of get in now. >> Yeah. Get get in place. You got it. And then if you're on defense, you're have a desperate uh you're desperate to patch every window, you know.

25:00 And in fairness, both sides are accurate in their desperation. I mean, because we have near-term pain in the AI age that it advantages offense, period, right? So, that's fine. That's that's just the nature of it. >> But both sides recognize it's for long-term gain. Y >> meaning AI on defense being trained by AI on offense and being autonomous is going to do a far better, more diligent job than humans peering at packets, you know.

25:29 And so we're just going through the window of exposure, let's call it, where everyone's at risk on defense and they're all hustling. I've seen incredibly powerful efforts at every company right now and I'm not aware of any large 1A enterprise not actively scanning for exposure and doing something about it in real time. And what's interesting, David, is it's like and it's team ball everywhere like the CIO, the SISO, the product teams, the business lines are all like, okay, we found something.

25:57 And it's almost like war roommed like we got to go fix this, >> you know, and the composite of those teams are pretty broad. >> So there's no way to make the next year pretty. That's the best way to say it. You know what I mean? It's it's a cocktail party out there right now. Digital cocktail party. >> And um everybody's in a race. >> Yep. >> Yeah. It's one of our most sophisticated companies told us they took a large percentage of their engineers and research organizations and just devoted it toward fortifying their

26:24 own walls. >> Yeah. >> Which was like a all hands- on deck. Um and you know the alarm bell started ringing very recently like this is within the last few months right >> I think mythos was the biggest I mean we saw it coming long before mythos but the mythos moment from a marketing standpoint got everybody to go okay threats changed y >> and a lot of people said mythos came out find vulnerabilities in our own software and you have to do that if you're doing software security at astation so all the vendors ran out and

26:49 did that but the way I respond to mythos is that just made it very well known about AI on offense coming at you. Um, and uh, I think that's what accelerated it. You know, that was pretty much a firm stamp. It's coming. >> Yep. What about the hugging face instant? I'd love for you to talk about the >> I've given that a lot of thought. I mean, I'm certain at open AI like, oh, at a regular they were like, ah, we could have done this and this and it wouldn't happen.

27:14 You know what I mean? So, they've already figured it out. >> It's been my experience in every technical modality shift, we underestimate the adversar's capability. And in this case, we underestimated the model's capability because, >> you know, when you really read it postfactor, ah, they could have stopped that, you know, >> and um they could have put guard rails on it, some deterministic things.

27:35 And uh >> and I think they realize that now. But I think when you're in a race, it's almost like a lunar landing race, right? The AI race. And you have R&D people and they're doing the work to create models in a way where even those CEOs are like, "We can't slow it. Let's get the government to help us slow it." you know that means you can't even control your own innovation.

27:56 >> I have views on that but we we can take that to another time. Yeah. And so when you have and I get that R&D people are like chasing that innovation and it's really hard to package them with then like security experienced security people that have the skill sets to cage that thing you know and it's hard to marry those two up because the security people don't understand the AI as well and the AI people don't realize one of the things that we did in our model I mean make no mistake Armadin has made the beast that we're

28:22 all worried about. We've made a model that attacks. We've made many of them. We have a system that attacks production networks and is highly successful breaking in. Well, is it safe? Well, our guys instinctively knew we got to have obviously a secure, you know, we got to have a hypervisor. We got to secure this thing. We got to lock it down hostbased.

28:42 We have to have a proxy. It knows the proxy. It's proxy where that's fine. But then our guys did something and even I was like, nice job. They passively, surreptitiously look at every single prompt on. Do we like it? Do we not like it? And the majority of the time if we kill an agent, it's probably nothing to do with safety. It's that the agent's wasting money.

29:05 >> Yeah. >> You know what I mean? So kill it. It's off on a goose chase. We've already done or don't want to do. But there was so many layers of validation that the agent was doing the right thing. And the other thing was assume every layer of your security will fail and you have to have deterministic rules that eliminate certain activities. But what I did learn reading those incidents, >> it does take domain expertise to secure agents behaving in certain domains.

29:31 You know what I mean? So I get that. So like like without a cyber background, I get how you're going to make >> you're going to test something go, "Oh, didn't think of that." >> Yes. And you would have had to have an experienced team look at what the the evals look like to say, you know what, it's going to do this and it's going to do that. So you got that's why Armed and we combined the exploit developer types and redteamers with the AI folks because our evals most of the time are made by the red teamers, right?

30:01 You know what I mean? They're the ones that understand this stuff. And we created 20 full kill chains at Armadin that humans have done in the real world period at different victim sites and and our experienced operators have done when testing networks and we had no model go through the entire kill chains of more than eight. >> So that's where it out of 20.

30:22 And here was what's weird by the way. We tested the open weight ones and the most advanced closed models. They all found eight. Really? So if you're Yeah. So it was all about just speed and cost you know and there you know the closed models were faster to finding exploitable risk but that's coming down but we kind of let the open models run longer and they got to the same place.

30:44 >> So in the cyber world the differentiation between closed and open is not as great as in other domains probably >> and it's compressed. Yeah I would say that's somewhat consistent um in terms of like [clears throat] the capability gap at least closing a little bit. Um >> u but that's interesting that their performance is basically the same >> from my perspective seeing the charts from the team all the lines ended up in the same place you know when you're looking at >> it it was immediately time >> uh cost and then

31:11 call it effectiveness or creativity they all ended up at the end of all their operations where they hit diminishing returns they ended up in the same place not on cost though >> yeah not on cost yeah that makes sense that makes sense so it's a it's a decent segue maybe to talk about what kind of models you guys are using and then what role do you think the lab companies play in the future?

31:34 Well, and I don't even know if I finished answering your last question other than domain expertise on security is going to have to work with the AI folks because I did read the, you know, the the meter publication and I was like, well, these guys are AI people, but I'm not sure they've done a lot. Yeah. And that's going to happen again, the modality shift because here's one as when cloud started emerging, you know, I was running a bunch of incidents.

31:57 We were responding to breaches for a living at Mandian and we had to learn what's a cloud breach look like, right? We now have to learn what's an AI breach look like, how much data is that entropic or the model companies that are being leveraged to do the attacks. What do you wish they logged? And how they will change behavior as well to have better audit trails, better forensic capability.

32:17 So it's early onset to the technology and we all clearly have to mature into it in a way where we have the accountability when these things go rogue. You can say here's what happened and when. And it shouldn't be like two weeks of forensics to figure it out. I hate to say it, like we log every single thing our agent does. Source IP address, time and date, and what it did, >> you know?

32:37 So, you got to go backwards and replay these things. And I think they've learned lessons >> the hard way. >> And they're probably way better today than they were even three months ago at Open AI and Enthropic and testing these things. And whoever had a regular labs, they're looking at this going, "Okay, we got to tighten up a little bit here." And and I get they were surprised because they they underestimated it.

32:58 And we've and we've done the same with human adversaries. It is the weirdest thing. My whole career, everybody underestimates the top tier of what you're up against because you don't have to see it every day. Yeah. You know, and and you don't want to fear the the boogeyman, as they say, under the bed. So, you don't want to have FUD, >> but you still want to respect the technologies that you're creating and test them in a way that is meaningfully guarded.

33:21 Got to cage the beast, David. >> You know what I mean? You do it. And I would argue cage it too much. release a little bit, find the line because if you do overly deterministic, here's the the art form to safety running AI, at least in cyber on offense, >> is you want to leverage the intelligence of the frontier labs to do stuff but not do the wrong stuff.

33:45 So, you need classifiers. You need a model that looks at everything going outbound, everything coming inbound. We've created that with people and humans going thumbs up, thumbs down, that's good, that's bad. You got to train it, classify, and look at it. But if you get too deterministic and disallowed too much, you're probably not leveraging the creativity of it.

34:01 You let it out some. And so it is a gray area. And that's the problem with that gray area is that's why no one would ever say we're 100% certain we're going to get what we expect. Y >> you know, >> period. It's it's it's a battle we even have, but we have yet to have an issue because we can put a human in the loop or we have classifiers to say human needs to decide this.

34:23 We don't know what the hell just happened. You know what I mean? Yeah. >> So if you're inspecting everything that's coming, you know, every prompt to the to the labs, everything coming back and something comes back and we don't know what the hell it is, pause, escalate, judge. >> Yeah. What do those great security operators look like inside Armen? >> A lot of experience.

34:44 15 years on offense, 15 years of red teaming. I think we've red teamed literally 99 of the Fortune 100 throughout our careers. >> Wow. We didn't get one and I know who it is and they've never hired me and I love their products. So, one day maybe I'll get >> How do we get Let's go get those guys. >> Yeah, talk to them all the time. Never landed them.

35:00 That's all right. They might be good. But, uh, you know, they are very experienced and, uh, and they all, you know, when I look at our 90 plus zero days, the majority have been found by human, >> right? But they're found by humans because we're leveraging AI to do 90 plus% of the tedial work which is pentesting done automated web app pentesting in creative articular way done automated for the 98th 99th percentile but we're still putting humans on it but here's where it gets interesting David the last few zero days tech

35:32 found it >> really >> yeah oh wow >> so we've made the turn yeah you know and and most people already have made the turn their tech if you're on offense leveraging AI your AI agents are finding zero days. >> Yeah. I want to shift gears now to uh your philosophies and mindset in building a company. >> You know, they're different. Yeah. So, couple things there.

35:53 Like the first time I built a company was 2004 and I wouldn't have said I was an entrepreneur. I started Mandy 04 February and it was self-funded and profitable and we were successful because in hindsight it's like you almost learn nothing at the time and you look back and go, "Oh, I did learn right then and there because of the pain usually." But uh I I you know I look back on Mandant now we had a premise nobody actually believed in ' 04 because our first website said security breaches are inevitable and nobody

36:21 believed it and I don't even know how much I believed it and uh >> it's a pretty good tagline >> by the way I'm [clears throat] slightly off. Our first headline was you cannot solely rely on preventive measures and that was so boring but that's the same as security breaches are inevitable. You know can't rely on >> better ring on the Yeah, I got [clears throat] it wrong because I'm not a marketing guy.

36:43 But anyway, so security breaches are inevitable. And the premise was that let's respond to every breach that matters so we have first mover intelligence on how to prevent it happening again. No. >> And so the first model of intel and all of cyber security was antiirus. You know, it was like we look for malware. Yeah. >> We have signatures for it and if we miss, >> David George has to find the malware and submit it to us so we get better.

37:05 That's a bad model. My mother's not finding malware on her laptop. You know what I mean? was just going to eat her laptop alive. So that model was bad. So we decided a better model because I responded to breaches. And the reason I was responding to them is AV was easily evaded. And so we were like, well, let's learn all the, you know, let's second layer AV because it stinks.

37:25 And that's what George now owns, you know, >> so let's second layer AV. You still have to have AV though. I beat it up, but the reality is is you still need it. >> Um, or something that replaces it. [clears throat] So the second layer of defense was required. So AV was imaginal line to here. Then you extend imaginal line with something that can learn and think.

37:44 And uh so we wanted to do that and I actually look at Armen as just the third wave of intel. Like why are we waiting for a victim and learn from that? That's ridiculous. You've got to find your own problems first. Don't wait for you know defense contractor A to be compromised and then quickly share the information to make sure it never happens again.

38:02 Now that model still needs to exist for the things that are somehow get there that beat you. But um we got that model now and it's just not good enough. So back to your question, you know, mandate was self-funded. There's not a I don't know self-funded companies these days, David. >> Well, the speed the speed requires that you got to be fast. That's the difference.

38:25 >> Yeah. You you look at we started Armad and the philosophies were different. When I started Mandy, it was hey, this is what we do for a living. Let's make enough money to do it for a living. That's it. I mean, so we hired the best people and we had a philosophy of we're going to pay you more than our competition, >> but you're going to work harder.

38:42 So, we always felt like we had less people working harder, >> but better people. >> Yeah. I think we had a we were known for having great talent and that talent has prevailed. There was a time about a year ago, somebody sent me a text and they said, "Congratulations, 43% of the RSA mainstage keynotes are Mandian alumni." >> Come on. >> And that's the text I got.

39:00 I never verified it, but the guy's pretty accurate. Um, I'll take that stat if that's true, you know, and I think it probably was. You know, we we've got a lot of reach over time, uh, with a lot of talent and, uh, I mean, look at Found Look at George Curts. We he and I worked together at Found 2000. You know, he he has spawned a lot of, uh, from Found you've spawned a lot of successful companies and and people.

39:23 So, same thing with Mandy, but uh, the differences are this a got to be funded. Yep. B, ow, your growth rate, get the market now. Like I look at Armadin's opportunity. I feel like we have an 80 mph tailwind, but we don't have a sales force. We don't have a go to market. We're not international. All that just has to happen. And the only way to thread the needle in today's economy to beat the bigs is get this go to market in place with exactly the right tech at the right time.

39:52 And you better already have your act two ready and your act three behind that ready because you don't want to get boxed into a corner. So Arman's got an act two, we have our act three planned, but we're in the process of building go to market which requires the funding and you have to build it ahead of time. No, the the consumer AI companies created such meteoric rises in revenue.

40:10 I don't think they can be replicated in enterprise security sales, >> right? >> But you just saw the compression. Whiz got to over 100 million in AR in 18 months from their first release, right? We're going to try to beat that. And that's what you have to do, especially when you're needed. necessary and you have to exist and that's not easy to do. So you got to get the funding.

40:31 You got to constantly think how do you rapidly grow? You can't let the wheels on the bus get wobbly. Meaning, how do you go that fast and maintain process? Yeah. >> At Mandian's pace of we were self-funded and profitable with no competition because nobody believed the premise. >> We didn't get that wobbly. You know, we just had great leadership and discipline and and we could do it.

40:53 Growing this fast, you have to hire scalable leaders right away that understand institutionalized process. You can't win with grit, gut, and moxy, you know. You actually have to proceduralize >> almost industrialize uh the armadin way. Yes. >> That you know what I mean? And that's what I'm trying to figure out. It it's uh how do we do that and feel comfortable doing it?

41:18 And here's >> complications. So let's do it. A you got to grow fast. Being in the AI age, it used to be development was at a speed where you train sales at sales kickoff in January and you're good. >> Yeah, exactly. >> Yeah. >> So, I'm trying to figure out, wait a minute, we're different every two weeks. What is the modality now of having a sales core that is right up to date?

41:39 And here's the challenge that I thought every every CEO I've talked to is like, how does AI change our business? And we all sort that out. But how does it change our manpower? When I look at AI's influence on sales, the reality in enterprise security sales is people still buy from people. Yes, you still need the same damn go-to market structure for now.

42:00 And in fact, it's even more emboldened because the tech's changing so fast, you can't put that onus on the customer to figure out how did you change, where is it at? So, we have got to create a process institutionalized where sales is trained every week. Where are we at? How are we doing? And these are processes that will get you to when you know you think about with the credibility on the side.

42:21 Exactly. Yeah. You got to be great. Yeah. And by the way, there is no replacement for any company I'm involved in. We are not ever aiming to be let's be number two in our space. That sounds fun. It is be the best in the world at what you do. And when we hire people, I remember getting a question once somebody asked, well, how do you know when you're the best?

42:39 And I'm like, when you are the best, you know it. You know, you have to be the best in the world. You have to ask the question. You're probably like I'm pretty sure, you know, there was a time in, you know, LeBron James' career where he knew I'm going to have to work harder >> to stay the best. Yes. Right. And that's how I want us to feel at Armadin.

42:54 The sports analogies all work. Tom Brady never walked on the field going, "Wow, I'm the second best quarterback out here." >> No. Always. >> But it requires harder work, better people, and you have to constantly test, are we the best? Are we the best? >> Um, and you learn very quickly from your customers if you got to do better, right? So that feedback loop customer straight in uh to the engineers is critical as well.

43:16 So long story made short speed has changed. Got to do a capital raise. Got to scale processes and test those processes all the time. What I can't stand is chaos. A CEO's job is to absolutely like hide chaos at a company from the employees. Right. Period. You got to make sure they're not like we're like so loose. We have no idea. Wrong. You have to just say here's the process.

43:41 If process is too much for you to study, >> that's the person you go to. All you need to know is a guy or person's name. And that's how I look at it. How do we grow rapidly without feeling chaotic? How do we grow rapidly earning it with better product? >> And how do we change fast? I don't know how long IP lasts. So it's like you got to build a Ferrari engine and say, you know what, >> whatever we're doing today, someone else is doing in six months.

44:06 >> Yeah. Yeah. So how do you differentiate over the next 6 months is go to market get customers and make them happy. You got it. The brand itself has to be built too. You have to become a brand that is the seal of approval. Yep. >> So I just gave you a jumbled answer I wish AI could summarize really quick. So here's the four differences. The funding, the speed, the branding matters, the go to market buildup.

44:25 You have to build it way faster today than you had two years ago. Well, and the big reason why that's the case is because this is a tsunami like has never been seen before in security in the security market, right? Crowd Strike, >> you know, and then the other players that were around it, they redefined the category, but they had to create the category.

44:46 In the case of Whiz, part of the reason that it was able to grow so fast is because it was a oh bam, hit you like a ton of bricks, pressing need >> and so everyone felt like they needed to buy this or something. >> For youated really fast, too, though. You get a halo early like you know you got to get the halo and and I personally think you get the halo trade secrets um you get the halo by getting the right customers and making them ecstatic.

45:08 >> Yes. >> You know you like do no offense if there's a place called I don't know Suz's cupcakes >> they don't get you the halo if you make them happy in cyber security right but the money center banks do the best retail does the airlines do you get it >> and so that's why Armadin's making one enterprise focus number one solve the hardest problems. >> Yep.

45:27 And I think Whiz did that. So, >> yeah, they did a great job of it in one of our companies, too. We love those guys. >> Um, all right. What else you want to talk about? Anything? >> Well, I never answered your question on the differences, too. It's uh >> there's more founders today than ever before. Yes. >> There's more startups than ever before, and they're all able to capitalize now.

45:45 So, you will have competition >> in anything you choose to do right now. There's no going there's not going to be a mandate. Security scared breaches are inevitable and it's right and there's nobody else there. Yep. That's not going to happen right now. So everyone's in a crowded market. So I think every founder has to recognize you have to differentiate and probably right now because of the noise in marketing more than ever before.

46:06 The only way to differentiate is get customer make customer happy and repeat. Yep. There is nothing else that will differentiate you other than your customer base raving about you. Yep. So you better go do that. That's it. So I just give away every trade secret I've got. None of it's rocket science. It's like literally honestly it's the same thing that's always been in business.

46:24 >> Yeah. But it's just at hyper speed now. >> Just got to do it faster. And that speed requires never forget what you should focus on. Get customer, make customer happy, repeat. That's it. And you got to do that. And then everything else is like around that is to make sure you do that really well. The training, the sales enablement, the marketing, the people you're hiring, your hiring process, the teamwork, you know.

46:44 So, and some of the ways we differentiate as well. Well, you know, you know, we have all our engineers in one room. Yeah. We're a big believer in that. You know, I I think managing distributed teams is more complex than standing up and asking questions and 20 people are in the room to answer. >> Slow slow speed if nothing else. >> Yeah. So, it >> it's a great time to start a company though because almost every well, every industry is going to change.

47:12 >> Yes. >> And in cyber security, every single tech stack is going to be different over the next two years. Yes. Yeah. People are going to get ripped out, put in new tech. It's all got to be revamped and so it's fun and exciting to be part of that. >> It's a tail tailwind of a lifetime in cyber. >> Yep. >> Well, look, we're so excited about what you're building and thrilled to be your partners. Um, so thanks for being here. >> That was fun.