Video summary
The opening segment of Day One at Black Hat 2026 in Las Vegas focused on dispelling the pervasive fear that artificial intelligence will render cybersecurity jobs obsolete or trigger an immediate digital apocalypse. Host Christa Casease and her partner John Ull discussed how, while AI is indeed causing problems unprecedented in their scale and speed, these challenges are manageable rather than catastrophic if approached with a balanced strategy involving people, processes, and technology. A key takeaway for practitioners was that understanding the underlying technology allows professionals to thrive by identifying new opportunities it creates, ensuring that human decision-making remains essential within the loop. The conversation emphasized that while adversaries can leverage AI tools for automation at velocities never seen before, defenders are not facing Armageddon but rather a shift in dynamics where strategic integration of AI is crucial for maintaining security posture.
The dialogue then shifted to the critical concept of cyber resilience as a core component of modern operating models, particularly within complex enterprise environments involving third parties and interconnected systems like IoT and OT technologies. Security leaders such as CISOs are increasingly being asked by business stakeholders not just to prevent attacks but to prove their capability to operate effectively even after an adversary penetrates the environment. This requirement drives a deeper understanding of end-to-end business processes, helping organizations identify which systems cannot go down versus those with some flexibility, thereby focusing resilience efforts where they matter most. The discussion highlighted that navigating this landscape requires CISOs to engage closely with boards and understand specific system attributes like revenue generation, connectivity, and access points to build a robust threat model against evolving complexities.
A significant portion of the day's insights revolved around identity management as it evolves to address AI agents operating at runtime. Since AI agents can perform tasks autonomously based on their capabilities, there is a risk that they may exhibit rogue behavior if not properly constrained by dynamic identity controls and continuous authorization mechanisms. Experts noted the emergence of new roles like security agent orchestrators who must define guardrails for what an agent should or should not do without blocking its ability to function effectively. Furthermore, while visibility into shadow AI remains the foundational first step before any intelligent decision-making can occur, there is a growing trend toward "DIY agentic stacks" where enterprises build their own solutions using internal teams rather than relying solely on third-party vendors, challenging traditional industry models and raising questions about who best understands an organization's specific environment.
As the day concluded with wrap-up remarks, both hosts agreed that much of the current discourse surrounding AI in cybersecurity is overly simplistic or driven by fear-mongering among customers and even some vendors. The consensus was clear: stakeholders need to take a step back, breathe deeply, and adopt a strategic mindset rather than succumbing to panic fueled by FUD (fear, uncertainty, and doubt). Vendors are urged to move away from merely scaring clients with worst-case scenarios and instead focus on educating their customers about how to navigate these changes safely. Looking ahead to the next day of coverage, John expressed interest in exploring vendor strategies regarding multi-agent ecosystems and whether enterprises will continue developing internal AI capabilities or revert to buying solutions, underscoring that the industry must evolve from a binary debate into nuanced discussions about integration, management, and practical implementation.
Read the full video transcript
Welcome back to the Cube. We're wrapping
up day one of our live coverage of Black
Hat 2026 here at the Mandalay Bay in
Scorching Las Vegas. I'm Christa
Casease. I'm joined here with John Ult,
my uh my partner in crime here at the
show. How you hanging in there, John?
>> Hanging in there. Almost done for the
day.
>> Almost done. You know, it's at least a
little chilly here on the set. They got
the AC blast in.
>> Don't walk outside. It's that
>> I know for two seconds. So, kind of I
guess on that line. So, you know, you
and I chatted this morning, John, to
kick off the day before we had a number
of conversations here at the cube and I
know you were taking another a number of
briefings as well. You said this morning
you got a sense that the sky is falling
a little bit. I thought I'd get a pulse
check and see how you're feeling after
the conversations today. Yes, this
afternoon I was saying it's a hair on
fire problem [laughter]
and I think it's being presented as a
haironfire problem and certainly it's
unprecedented in terms of scale and
speed
but uh I'm starting to hear from people
it's uh it's a manageable problem. Yes,
>> but you have to go into it with strategy
and intelligence and the right balance
of people, process and technology and um
I don't think a lot of companies are
doing that but those that are are
managing.
>> Absolutely. So John, what do you think
in terms of you know navigating this
from the standpoint of our pol our
people and our processes? What are some
things that you think you know
practitioners will walk away from in
terms of just some guidance there? Well,
practitioners will walk away with a
couple things. One is that there are
tremendous opportunities.
>> So, forget the notion of this is going
to replace your job.
>> If you understand the technology, you'll
thrive. And if you look for new
opportunities that the technology will
create, you'll thrive.
>> In terms of processes, um, we have to be
much more sensitive to where the human
in the loop takes place. And the human
in the loop is important. Uh we have to
guide this technology.
We have to understand this technology.
Um but humans are still necessary to
make decisions and will be. So there's
still opportunity. There's still work to
be done.
>> Absolutely. So nobody's job is being
displaced and then at the same time from
the adversarial perspective yes it can
operate at a speed and a scale that
we've never seen before and it is
unprecedented. We do potentially have
the tools available to address that.
Again, like you say, provided we rethink
different roles and responsibilities and
provided we really think strategically
about where we can integrate AI as part
of our processes.
>> Correct. But also another anti-hair on
fire notion that I've heard all day is
um we're not seeing massive new amounts
of malware created. We're seeing
adversaries doing what uh defenders are
doing and that is using the tools for
automation and scale and velocity and so
yes you have to be prepared for that but
it's not Armageddon.
>> I agree and John I've also had a couple
conversations instances where AI has
actually created some novel types of
attacks. Have you heard this as well?
And I guess kind of what's your
barometer in terms of how concerned we
should be about that versus the speed
and scale piece of the conversation?
>> Yes. So, we're going to see these novel
attacks. Sometimes they're accidental
uh or negligence, internal negligence.
Sometimes they'll be adversarydriven.
The other thing we'll see is um we will
see script kitties using the tools to
advance your skills. I heard a a a term
called uh u claude cadetses is the new
script kitty. We'll also see less
experienced hackers who get really
experienced at using the AI tools. So
it's sort of a balance of power. So
there's all kinds of dynamics on the
threat side.
>> Absolutely. Absolutely. So building on
the the conversation about the threats,
um I know you know you know cyber
resilience is near and dear to my heart
and I know we've we've had a number of
conversations about that and I think
what I'm what's really solidified for me
here at a security show with security
practitioners is that cyber resilience
is a part of that operating model and
that CISOs are being asked by the
business to prove not only how many
attacks they can stop but more than that
to prove that in the event an adversary
does penetrate the environment that they
have the capabilities in place to be
able to operate through that. I'd love
to just get your reaction to that. I
know you've studied security deeply for
so long. Are you hearing that as well?
>> I am. Uh it's certainly a CIO CISO
prerogative,
>> but at the same time, the bigger the
enterprise, the more complex the
business process is. It may involve
third parties. It may involve systems
that can't go down. It may involve uh IT
or IoT and OT type of technologies. So
that's the challenge for security people
is to understand the business process
end to end and then determine what can't
go down, what we have some flexibility
on and then how to make those systems
resilient. So it's it's definitely an is
an initiative. Uh, I think it's the
future and I think your study of it is
really important, but we're on the
on-ramp. There aren't many companies
that know how to do this and that's uh
that's a prerogative moving forward,
>> right? And it goes back to the
conversation around the people, right?
It's a it's an issue of, you know,
navigating the CS the CISO and how
they're engaging with the board um and
kind of navigating this together.
>> Yes. And that that means understanding
what the system is. um is it a revenue
producing system? What it's connected
to? Who's accessing it? Are they
accessing it internally or externally?
So that's you can see the threat model
gets more and more complex, but that's
what we're up against.
>> Absolutely. And I think part of that
conversation is going to lie in the
identity space. You know, I've had a
number of conversations today around the
need to kind of evolve identity controls
at runtime to address AI agents. Um
because, you know, they they really
disrupt that paradigm. And I think
that's going to be if we think about how
the technology stack is going to evolve
for both security and resilience. I
think that's going to be a really
important um control point moving
forward.
>> You couldn't be more right, Christa. Um
the thing is that uh and we've done
UEIBA for years. We can do behavior
analytics.
People have limited ability to do things
and we can also do identity governance
to say you can do this, you can't you
can't do this. entitlements, etc.
If you ask an agent to do a task, it's
going to do whatever it needs to do
orever what it can do to accomplish that
task. And some of that may be rogue
behavior. So that's where I think
identity, non-human identities, gentic
identities, that's the challenge there.
And it's not static. It's very dynamic.
>> It is very dynamic. And I had a
conversation actually a couple around
this concept of you know continuous
authorization um and really it's also
about understanding you know the
behavior of the agent as well.
>> Yes. And uh there is one of the roles I
think is evolving is an a security agent
orchestrator. So that is what does this
what do I want this agent to do but what
don't I want it to do and putting the
right guard rails but not putting up
blocks where it can't get its job done.
So that that's a real challenge.
>> Absolutely. So, I'll get off my little
resilience and identity soap box for a
minute. And John, I've also been having
a number of conversations around the
fact that we're really kind of honing in
at, you know, runtime for these AI
agents and how do we establish security
controls and guard rails to be able to
allow these AI agents to move safely
into production. Um, I'm trying to get a
sense, you know, are practitioners kind
of solving that piece of the equation
while they're also solving the
visibility and kind of the shadow AI
component of it. Um, I'd be interested
to get your take on it. Do you think
they're trying to do both at the same
time?
>> Um, well, they'd like to do both at the
same time, but I think you've had
several guests on today. I've had
several conversations. The first thing
everyone says is we need visibility. So
what's out there? What's it doing? Who
owns it? What's it connected to? Uh
that's you can't move on. You can't
what? You can't secure what you don't
know or whatever that cliche is. So
visibility is the start. Once you have
visibility, then you can make
intelligent decisions. So I think it's
sequential more than um simultaneous.
>> Yeah. Yeah. I agree. So, John, looking
ahead to tomorrow, you know, I guess
what are some of the things that you're
going to be listening listening for in
your conversations tomorrow?
>> I'd like to hear more about this
complexity that I talked about because
>> there's a little bit of a simplistic
[snorts]
binary discussion on uh we can't secure
AI, we can secure AI, and that's just
not realistic. All of these tools are
being instrumented with agents. How do
all those tools work together? I mean,
so do the does one vendor's agent know
about another's vendor vendor's agent?
Is there some central management of
that?
>> The other thing that I find interesting
and and uh you know, we're surrounded by
what I don't know 500 vendors here or
something.
>> AI makes development easier. So, one
person can do the development work of
several if they're good. what's stopping
enterprises from doing the development
themselves and I actually heard that
from a company that I've worked with in
the past. He we were talking about the
agentic sock and the CEO said oh yeah
we've done that I said oh did you buy
from this vendor that vendor said no we
did it ourselves it took one person and
uh they could do the work of three
people and that's really increased our
velocity and our efficiency
okay now their environment isn't that
complex but what if you applied five
people to that if you're a big
enterprise so that's a question that I
hadn't really considered is
>> is there an opportunity for smart
engineers who understand their
environment, you know, uh intimately
>> to do this themselves. And so I'll be
looking out for that tomorrow and I'll
ask every vendor, are you seeing that?
Because that's a a threat to this whole
industry.
>> The DIY agentic sock, that's that's
pretty wild. But what I mean, what are
some of the pitfalls there? Well, I
think it's a common pitfall is that if
you're a security department, you don't
want to be in the software development
business. You don't want to um be having
to maintain that. But that's gotten
easier from waterfall to um to different
types of development environments, CI/CD
pipelines, and now you add agents and
agent coding, and it gets even easier.
And again, who knows their environment
better than those people?
>> Absolutely. you have to bring in a third
party vendor and then customize their
solution. Why don't we just do it
ourselves? Now, there's certainly plenty
of room for some of the vendors in this
in this show to succeed, but I just
wonder how um how prevalent that trend
will be.
>> Yes. Yeah, I definitely agree. All
right. Well, John, I know we're going to
be back on first thing in the morning.
Um
>> Yes, we are.
>> Yeah.
[gasps and laughter]
>> Anything else top of mind for you from
the day?
Um, it's very crowded here.
>> Yes,
>> there's a lot of energy here. So, I
think it's a very successful black hat.
But again, I think I I I see a lot of
fear-mongering. And I I've said to
everyone I've met, every vendor I've met
with, take a step back, take a deep
breath,
>> think strategically, talk to your
customers, educate your customers. So
hopefully I'll see more customer
education tomorrow.
>> I agree. I think there's a lot of FUD
amongst customers, but are they at the
level of panicked?
>> I'm not sometimes.
>> Sometimes, but like you say, I think the
roles of the vendors should be to help
them to navigate that and to kind of
provide actually some resolution, some
potential.
>> The vendors, yes, the salespeople, no,
they should scare the their [laughter]
customers.
>> That's very fair. All right. Well, John,
thank you so much. I look forward to
chatting with you in the morning.
>> Talk to you in the morning.
>> Sounds good. And thank you so much for
joining our coverage of the first day
here at Black Hat 2026. We'll be right
back with you tomorrow morning. So, uh,
join us then. And thank you so much.