Video summary
The podcast episode focuses on the industry's transition from using artificial intelligence as a simple speed-up for existing security processes to entering a "second phase" where AI is granted agency to perform complex tasks like investigating incidents and invoking tools. The hosts, Krista Keys and John Oltsik, discuss how enterprises are rushing to deploy these autonomous agents without perfect guardrails in place, forcing security teams to rapidly establish governance frameworks. They highlight that while the concept of a fully autonomous Security Operations Center (SOC) is realistic and evolving quickly, it currently exists in an amorphous middle zone where organizations know what they want but lack certainty on execution. A key challenge identified is the widening gap between the scale of security operations and the inability to hire enough personnel to fill that void, necessitating a shift toward agentic AI to handle tasks like alert enrichment, triage, and threat hunting.
A central theme of the discussion is the critical role of human judgment, particularly when decisions involve significant business risk or ambiguity. While AI can present evidence, calculate risk scores, and suggest remediation playbooks, humans must remain in the loop for consequential actions such as taking servers offline or decommissioning identities in mass. The conversation suggests that over time, the role of the security analyst will evolve from manual execution to becoming an "orchestrator" or "conductor" who understands intent, guides AI swarms, and applies high-level analytic skills. This shift implies that while Tier 1 analyst roles may be largely automated, advanced functions like threat hunting and red teaming will persist but will rely heavily on AI as a helper application to manage the increasing complexity of the threat landscape.
The dialogue also addresses the competitive landscape between established vendors and new AI-native startups, noting that history suggests most innovative tools will eventually be acquired or integrated into existing platforms rather than replacing them entirely. The hosts emphasize that securing these new agentic systems requires managing a non-deterministic attack surface where agents act on their own intent, making visibility and identity management for non-human entities paramount. Furthermore, the episode underscores the necessity of communicating security risks in business terms, specifically dollars and cents, to gain board approval. Security leaders are advised to frame AI adoption not just as a technical upgrade but as a strategy to enable business operations while ensuring cyber resilience, proving value through metrics that align with revenue protection and cost reduction.
Looking ahead to Black Hat 2027, the experts predict a "tale of two cities" where successful implementations of agentic solutions will coexist with catastrophic failures due to the pressure to move fast and break things. They caution against automating broken processes and stress the importance of understanding current workflows before layering AI on top of them. Ultimately, the consensus is that while the technology will advance rapidly, the industry must balance innovation with careful consideration, ensuring that security teams can effectively govern autonomous agents that have access to sensitive data and business processes. The episode concludes with an expectation that by next year, discussions will become more rational as CISOs distinguish between features that offer real value and those that are merely hype, leading to a more mature approach to integrating AI into the core of cybersecurity operations.
Read the full video transcript
[music]
>> Hey, welcome to Cyber Shift, the podcast
where we're digging into all the change
and disruption that's happening in the
markets for cybersecurity and cyber
resilience. I'm Krista Keys, principal
analyst um for cybersecurity here at The
Cube.
So, we are about a week and a half or so
out from Black Hat when we're recording
this podcast, and The Cube, we were on
the ground having a number of
conversations about sort of this second
phase of AI in cybersecurity that we're
entering.
Phase one was all about using copilots
and pieces of artificial intelligence to
make existing security processes move
faster.
Phase two is increasingly giving agency
to that artificial intelligence.
Um looking at tasks like it assembling
context, investigating um potential
incidents, invoking tools, and even in
some instances taking action on behalf
of um a practitioner.
So, what we heard time and time again
was that security operations was having
to make some decisions about how much
work and authority um can actually move
from people to AI.
At the same time, there's a flip side to
this coin, which is the fact that
enterprises are also moving AI into
production. So, you know, the business
can't wait for the perfect guardrails to
be in place, and what that means for
security teams is that they are trying
to catch up and establish, you know,
appropriate levels of governance for
agents that are being given access to
data, applications, tools, and business
processes.
I'm joined here today by John Oltsik.
John is a principal with the Seco
Cybersecurity Group, and he is also my
colleague. He's an analyst in residence
for cybersecurity here at The Cube.
John, great to see you today.
>> Good to see you, too, Krista.
>> Yeah, thanks so much for joining.
So, John, I know we were kind of
together, you know, boots on the ground
at Black Hat. And as you've had some
time to really kind of take a step back
and think about all the conversations,
where do you think we're at in this
shift towards more agentic security?
>> In some type of amorphous middle zone
where we
kind of know what's coming, we kind of
know what we're doing, we kind of know
what we want to do,
but we aren't sure of anything.
And so, there's a lot of questions, and
a lot of the answers are are very
reactive in my view. Um we have to be
more strategic. We have to really
understand this
to a much greater degree than we do
right now.
>> Yeah, I I definitely agree, John. Like I
was saying, you know, I think security
is kind of playing catch-up a little
bit, and a theme that just consistently
came out was that, you know, the
enterprise is not going to wait for us.
Um we also have the adversarial
perspective where, you know, adversaries
are using AI to execute attacks faster.
So, there's a lot of buzz about this
autonomous security operations center.
Um and I'd love to get your take on
that. You know, how realistic do you
think this view of the autonomous
security operations center is? Because
my personal take is I think there's
going to be, you know, a relationship
between AI and the human, but I'd I'd
love to get your perspective on that.
>> Well, to start, it's very realistic. And
so, even if you look at some of the
quote-unquote legacy vendors in this
space,
they're all adopting AI technologies,
agentic technologies, typically on top
of their existing platform,
um which could be sufficient for now. Um
I think in the future everything will be
built on AI. So, I think there's some
strategic changes that will happen in
their code base, but I think for now
that's pretty good. Um, so it's
realistic. Um, is it happening? Yeah,
it's happening fairly quickly, but I
think
what we've done is if you if you look
back like 10 years when soar came into
play, the thought was let's automate
mundane tasks. But, you had to hardcode
the workflows with Python or some type
of scripting and you used soar to do
that.
If you had the resources to do that, if
you proceeded to do that and understood
your manual processes, you could make a
lot of progress in automation. And now
we have the added benefit of AI, agentic
AI, LLMs, MCP servers, etc. that can
really um
accelerate those those trends as well.
>> Yeah, it's a great point, John. You
know, there's definitely some new tools
that we didn't have in the past. And um
I'm glad you brought up kind of the
vendor discussion. It's something I want
to get into for sure.
Before we um sort of unpack that, what
do you see being some of the key
opportunities for full autonomy or at
least more autonomy? I know we kind of
had conversations across areas like
triage, investigation, threat hunting,
prioritizing vulnerabilities. Um, but
what are some of the areas that you
think will be, you know, sort of passed
off, if you will, to some of these
autonomous tools?
>> Well, I think the context for me is that
the scale of the job of security
operations is increasing
quite rapidly.
And we can't hire people to take on that
scale. We We could, but now we
especially can't. So, how do we how do
we bridge that gap?
Uh and this is where the tool sets will
come in. So,
there's common themes that we see and
and I'm certainly
um I certainly believe these are
happening. Um so, one is just enrichment
of alerts.
So, and this is again where we used
soar, but I get an alert. Um
put this in context. Who owns that
asset? What is the IP address? What's
the it relative threat intelligence? So,
agentic solutions can do a a good job of
that and they can automate that task
versus hard coding it. Um
alert triage. So, I was just doing some
research on this and we have to think in
terms of tiered alert triage. So, there
are things that we we've done
historically with SIM rules and um
detection engineering and things like
that to filter things out, but there'll
be a level that we get to where things
are ambiguous. We're getting multiple
alerts from different uh vectors and
therefore we'll use
agents or we'll use AI to sort that out.
And I think that's happening, too.
Um
there's some definitely some threat
hunting
uh
additions that we're seeing. Just some
automation there based on IOCs and
things. Just again, workflow based. Um
but what we're not seeing yet is the
full automation end-to-end of the life
cycle. Um
detecting a problem and all the way to
remediating that problem. And
I I I I I'm optimistic, but I think
it'll take a while.
>> Yeah, I agree, John. I think it'll take
a while in terms of, you know, for the
capabilities in the underlying
technology to develop and also for the
security teams to learn that they can
trust these technologies. You know, I
think it's a naturally, you know, a for
good reason a kind of a skeptical
audience. Um so I do think that'll take
some time.
You mentioned the potential um
ambiguity, right? And I think there's
some areas where AI can do a better job
in terms of really digging into
potentially various threat intelligence
feeds and threat signals and make
correlations that a human couldn't, but
there's still going to be, you know, use
cases where the human is going to have
to apply some judgment. I think
especially where there's some ambiguity.
I know we're hearing that some tools are
trying to translate this into levels of,
you know, confidence and even potential
risk to the business. So, the question
back to you, John, is where do you think
um the human judgment is really going to
come into play here?
>> With anything that has the risk of
disrupting the business. So, taking a
server offline,
uh
decommissioning identities,
especially in mass, like we need to get
rid of these ident- this group of
identities,
um
taking a a you know, a a router or a
switch offline. So, all of those things
will have to have a human in the loop
for the business decisions that are that
go along with them. Now,
what the AI can do is present us with
evidence, present us with a risk score,
and even present us with a remediation
playbook,
but a human may have to push the button
to say, "Okay, that seems logical to me.
The confidence level is right. I like
it."
That's where I think where
it's it's a little bit dicey.
Historically, as security pro-
professionals, we've been really
reluctant to do anything that will
impact a business operation,
take a an executive offline, things like
that.
So, we'll have to have human judgment
there. Over time, we'll get more
confident, the technology will improve,
but I think that's a a distinction that
that should be made today and is being
made today.
>> Yeah, it's um kind of the trade-off
because on one hand, you can't have the
human approve everything, otherwise
you're going to be, you know, slowing
down those business processes too much,
but then at the same time you have to
give enough, you know, um
I guess authority, you know, back to the
AI. So,
um I guess taking a step back and
looking at this more broadly, John, in
the context of
the role of the security analyst and the
security team,
uh you know, I guess do you think that
there are going to be tiers of security
operations work that are removed? Um
what do you think really the role of the
analyst is going to become moving
forward as we do start to, you know,
make more pieces of that process
autonomous?
>> Good question. So, I wrote an article
about this that was published in CSO
online a while ago.
Um we can assume that 90 95% of tier one
analyst roles will be automated.
And so,
there's a good question of what happens
to those people and how do we train them
up for other roles, but I
I mean, my my conclusion in this article
and my conclusion after Black Hat is
that
we have to get smarter about how AI
helps in the security operations
processes.
So, that means
better understanding our intent.
So, what is it we're trying to
accomplish here? Is it risk reduction?
Is it rapid threat detection? Is it
automated remediation?
And then understand how that works in
terms of agentic swarms and their
ability to reason. So, that
that role has been talked about as the
AI SOC orchestrator or the say I the AI
SOC conductor using a musical metaphor.
But, that job will change.
Um threat hunting, so it's a lot of the
advanced skills will will still exist,
but will use AI as a helper app. So,
threat hunting,
red teaming
and then the integration of of the SOC
with exposure management, that will
happen and so we'll have to understand
the context of those exposures and of
course the business value and all of
those things. So,
there's a lot more
analytic skills that the humans will
need so that they can guide the agents
appropriately.
>> Yeah, I agree John. Like you say, all
about the intent and the context and we
had a couple of really interesting
conversations on the cube with some
threat researchers, you know, and
they're kind of digging into the cutting
edge of how the adversaries are evolving
and what that means for things like
threat remediation and response. So, you
know,
definitely
very much in line with you there.
Um so, I you kind of talked to a couple
areas, you know, these AI SOC
orchestrators
um you know, being one new category that
we see emerging and they're really if
you watch the show floor, there was a
flurry of startup activity around you
know, these AI SOC companies whether
they be like you say orchestrating,
whether they be, you know, kind of
investigation side of things.
I'm curious your take on if this points
to sort of
an existing gap in the security
operations
and really if so, if you think this is
going to be sort of a new category of
vendors that we should be paying
attention to moving forward.
>> That's a great question.
And if I'm being honest, the answer is I
don't know. I think things are evolving
very quickly.
Um
I think it's it's unwise to dismiss the
existing players um because there is
something like if if you are a Splunk
shop and you know what you're doing,
you've put a lot of work into it, you
have a lot of really advanced skills.
And to Splunk's credit, they're making
it easier to use some of those advanced
skills. So things that you really didn't
need to be an expert at, they're going
to make easier. And they are they they
see the writing on the wall. They're
they are adding AI functionality. Now,
will that be enough?
That's where I say I don't know because
there some of these startups are are
built from the ground up around AI. Now,
typically what they're doing is if they
do win an account, they come in as a
supplement to the existing tools.
What I like to say call a manager of
managers and then the thought is that
they'll slowly start to usurp the stack
down below them.
Some of the tools are old SOAR vendors
who've gotten really good at
orchestration and automation, but they
depend upon the data that lives below
them, the data in
XDR and EDR, the data in the SIM. And so
if you don't control the data,
you I to me, you're you're sort of lost
in that
the data really feeds the models and
feeds the agents.
So there's a lot of moving parts here.
It's a really fascinating thing to
follow, but I I really am at a loss for
how things will turn out. I could make
some guesses, but I'd probably be wrong.
>> Yeah, and you bring a great point, John,
that, you know, security teams are
already managing dozens of tools, and
I do think there's an appetite to try to
consolidate where they can. So, it would
be a fine line between, okay, do we want
to introduce, like you say, another, you
know, another tool into that tool set,
potentially add complexity. So, I guess
one speculation, you know, I'd love to
I'd love to run by you is, do you think
some of these companies will maybe
become either acquisition targets or
features of existing platforms?
Um I'd love to get a quick speculation
from you there based on what you saw.
>> Well, history would tell us they
absolutely will. That happened with
UEBA, it happened with SOAR.
Um
it happens all the time. It happened
with um chip. It happens all the time.
So, it will. I mean, some of them
some of them will succeed, some of them
will be uh acquired, and some of them
will fail. And
the the thing is that the market
opportunity is by 2030 is in the
hundreds of billions of dollars because
the autonomous SIM, the agentic SIM,
starts to
cre- creep across a lot of categories
like the MSSP market, the MDR market,
the XDR market.
And so,
if you're a VC, you're saying, okay, I'm
willing to bet that my company
can
re- carve a big role in that huge market
as these products coalesce. And so,
that's why I think we see so many uh
VC-backed startups in the space.
>> Yeah, and I think it's an interesting
time to be a VC, and, you know, trying
to place your bets. We actually did have
a couple conversations with some folks
in that space. So, like you say, it'll
be really interesting, I think, to see
how it plays out.
So, John, we were also talking about the
fact that, you know, enterprises are
moving AI into production and so, from a
security standpoint, this does create
some new concerns. We we think a lot
about protecting the model itself, but
there's also issues
in terms of the fact that these AI
systems are accessing enterprise data,
they're accessing other applications and
tools within the enterprise. They're
maybe even consuming external content,
for example.
And also, like we've been talking about,
we're we're giving them some agency to
be able to affect business processes.
So, you know, I'm curious your sense on
what is actually new here in terms of
securing AI? What are some of the new
considerations?
And where do enterprises maybe have an
opportunity to either take existing
learnings or existing practices and
controls that they already has and apply
them to some of these new, you know, AI
tools that their businesses using?
>> Good question.
I mean, what's new
they're expanding the attack surface. We
know that in ways that we're not used
to, but it's the attack surface, so we
we understand how to manage that. But,
the big change is that AI agents are
non-deterministic. They're intent-based
and so, you ask an agent to do something
and it's
it's role is to figure out how to do it.
So,
it's acting on its own.
Well, that can be manipulated.
And so,
it's really that it there there's a
consistent model that we've seen in the
past. It's
can I visualize what's going on? Do I
know
who is using AI? Do I know where the
agents are? Do I understand what they're
doing?
Then there's the well, how do I govern
this? So,
how do I create the right policies? How
do I put the right structures in place?
How do I
enforce my policies? And then how do I
secure this? So, what are the unique
things that I need to do?
And again, just like we talked about
before Krista, things are moving so
quickly that a lot of companies don't
have their don't have a handle on all
three of those aspects.
And I'm encouraged by a lot of the
companies that are arising to secure AI.
I just think it's really early in the
game and so there's a lot of really
smart models out there, people who
really understand the risks and how to
how to control those risks or mitigate
those risks.
But the question is is AI development
moving fast enough that these companies
will find a market or is it a little bit
slower than we think and maybe few of
them will find a market, a lot of them
won't succeed. So, that's that's really
what I'm watching.
>> Yeah, that makes sense John. And like
you say, there's you know,
there's a lot to kind of, you know, keep
up with, right? So, if I'm a security
leader and I am faced with the reality
that I do have signet resources, where
would you recommend that they focus
their time in terms of what will be some
of the biggest points of risk for the
enterprise maybe call it over the next
12 months or so?
>> Well, I think we're we're we're already
in one of those cycles and that is
getting your arms around who's doing
what in the enterprise. And I mean, if
every business unit is doing its own
thing, if developers are off using
different models, different development
tools,
you're in trouble. You you you can't
secure what you don't know about or some
such
statement like that.
And so, that's the first thing that
everyone talks about is what's out
there. I need the visibility. Um in your
area, the non-human identities. So, we
have to understand what those agents are
and give them an identity.
Um but we also have to understand the
entitlements. So, what do we want them
to do? What do we not want them to do?
And how do we restrict that? So, I I I I
mean I I do think the progression
happens, but I I'd say that the primary
thing that I'm hearing in the market
today is we just don't know what's going
on. We need to get visibility.
>> Right. Yeah, I think the visibility
pieces is very important and I think the
enterprises are trying to solve that as
step one and then they're trying to
figure out, like we've been talking
about, what governance tools need to be
put in place.
So, so John, if you were um advising a
security leader
um in terms of how to communicate to
their board about everything we've been
talking about, you know, the need for to
integrate some pieces of AI into the
security operation center, the need to
be able to um put the proper guardrails
in place to, you know, um safely adopt
AI,
what would be, you know, kind of I guess
maybe the the one thing if they had to
impress upon their board, what would it
be?
>> It would be
supporting
the business operations,
um protecting the business, but also
using business metrics to prove that. Um
And the business metrics have to be in
dollars and cents. So,
AI
We've all talked about this that the
CISO can't be Dr. No, that they have to
enable the business. So, fine, let's
enable the business, but let's go to the
board and present them with a threat
model
that they understand
in dollars and cents terms, and then
talk about threat mitigation. So, what
do we need? What do we need to do? And
what is what are the metrics that that's
succeeding?
So, that's really what I'm hearing from
CISOs. Now, that's a difficult
discussion. There's a lot of people
obviously can't get bogged down in the
technical side. Um
but
the ship has sailed, and we just as
security professionals need to
understand the risks, understand what we
need to do to mitigate the risk,
understand how much that will cost, and
be able to communicate that
effectively in dollars and cents terms.
>> Yeah, it's very easy to get the fun or
it's easier, I should say, to get the
funding when you can kind of, like you
say, point to, you know, this risk
quantifies into potentially X amount of
dollars for the organization.
>> Yeah, and um let's let's face it, a lot
of
what we're trying to do is
increase revenue or lower costs.
And at the same time, a subject near and
dear to your heart, we have to do that
with a cyber resilient infrastructure.
And so, think of those
two elements or those two sides of the
coin,
and um apply security principles to
both. And if you can communicate that in
business terms, you should be fine.
>> Right. And from a resilience standpoint,
you know, I'm seeing that there's a
recognition that this is an issue about
business continuity. There's an
understanding that it's more likely
we're going to be impacted by a cyber
incident than a fire or a flood. And so,
we need to make sure that whatever
critical services we have from a
business standpoint, that those can
withstand that disruption. So, you know,
I definitely would agree with that. I
think it's really changed the
conversation around resilience.
>> Yes, but I I I just add that
resilience is is a
gray area. It's not a black and white
area. And you have to get agreement from
everyone on what you're willing to spend
for resilience and what systems or
business processes need to be resilient.
And of course, different people are
going to have different perspectives, so
you definitely, definitely need the
board and the executives involved in it.
>> Oh, absolutely. It's a process of
understanding what the minimal viable
operations are. And again, tying back to
like you say, the impact of the business
and where can we tolerate X amount of
downtime, you know, versus what really
needs to stay online as critical.
>> Yes.
>> So, next up, John, we have our signal or
noise rapid fire section. I know we had
a lot of fun with this the the first
time that you were here on Cyber Shift.
So, um I have as handful of topics here.
I'm going to run them by you um for your
impression on is it an actual indication
of where the market's heading? Is it too
early to tell? Is it something that, you
know, really we don't necessarily need
to be paying attention to?
So, the first statement here is AI
eliminates most tier one SOC work within
5 years.
>> Signal. That's going to happen.
>> The second one is the largely autonomous
security operations center is achievable
by 2030. And this one kind of goes to
putting actually a time frame. I know
we've talked about there's a lot of
uncertainty, but if we're going to try
to put a time frame on this thing.
>> That's a little harder. I I'd say we'll
get
75% of the way there,
but um what what we we can't anticipate
what we need to do. We can't anticipate
what the threat actors are going to do.
And um they're going to get really
creative. They're going to disrupt
uh AI models and AI agents, and so
rough mostly signal.
>> Got it. Yep, and I agree. I think the
adversarial piece of it is going to be
very dynamic and fast-moving.
Um, so the third one, John, is AI-native
security startups have a lasting
advantage over incumbent vendors.
>> Noise.
>> Yeah, I I think they have some
advantage,
um, but again, we've seen this movie
before, and
there are legacy vendors, I mean,
there's a lot of sweat equity in some of
those installations, and I don't think
they get pulled out rapidly. So, they
have some runway.
>> Right, I agree.
Um, the fourth one here, human approval
remains necessary for consequential
agent actions.
>> Oh, big time signal. Yeah, let's And
that's that will remain true
probably forever, but I mean, that that
the the volume of human interaction will
decrease over time, but there's still
going to be decisions where you need the
human in the loop.
>> Yep, I agree, John.
And the last one, this sort of
piggybacks a little bit on the AI-native
conversation, but if we think more
broadly about this market for AI
security,
the statement is AI security becomes a
durable, standalone security market.
>> That one's
I don't know. I It's the That's the
answer is Does AI security become part
of the development process?
One of the issues I'm hearing right now
from the AI security companies is they
don't know who to approach, who's the
buyer, what budget it comes from. So,
that one's a little bit
the more difficult to to, um,
anticipate. It probably becomes part of
app security, um, but when you get into
governance, and, um, policy, and things
like that, not too sure.
>> Yeah, I agree. I think there's
definitely some gray area there.
All right, John, So, we have just a few
minutes left here. I have um a couple
questions kind of forward-looking. So,
um
one is kind of around this concept of
the agentic sock. I know we've kind of
established we do think that this is,
you know, the future.
I've been trying to dig into the
potential control points within the
agentic sock. You know, we have, for
example, your SIM and SecOps platforms
that have telemetry and workflows. You
have endpoint and identity platforms
that have pieces of enforcement there,
for example. Um there can be a lot of
context that's found in, you know, kind
of the data layer as well as kind of the
cloud infrastructure layer.
So, taking a step back,
is there a layer that you think will
sort of own the agentic sock in terms of
that enforcement or control point, or do
you think this is going to remain a
somewhat distributed or fragmented
market?
>> Well, uh I think
it the the agents have to coordinate.
The agents have to know about each other
and
I
work together for reasoning purposes.
So, it makes sense that there's a
central control point. And again, that's
going back to my point about the VCs,
that's what the VCs that's why the VCs
are gaga about this market because
can an agent replace endpoint security?
Can an agent replace identity and access
management? Um to some extent,
it can. And And in a in the future, do I
need um
user interfaces around all of those
different places? Well, no, because the
agents are communicating with each other
and they're producing some type of
output.
So, um
it's likely there there'll be some
coordination. Now, whether that's based
on some standards or it's a platform
play,
I'm not sure. I will say this that in
the large enterprises, just think of the
biggest companies in the world,
um
they already have
dozens and dozens of tools, and ripping
and replacing those is just going to be
really difficult. So, there has to be
some kind of coordination.
I don't I I mean, that's as far as far
as I can go. I I I think there has to be
a central control plane. Um how that
develops,
we'll see.
>> Right. I agree, John. I think the
enforcement will still be fairly
distributed, but we will need that kind
of common, you know, oversight and
control. So, I I definitely would agree
with that.
>> Yeah, there's a school of thought, and
I've thought about this for years, but
if you've got central intelligence, or
if you've got at least central ability
to gather intelligence, then everything
else becomes a sensor or an actuator.
And um and that really reinforces a
point you just made.
>> Absolutely.
Well, John, unfortunately, we have only
time for one more question, which is, as
you think ahead to the next Black Hat
2027, 1 year from now, like we've talked
about, there's so much in flux. What do
you think we will have learned when you
and I hopefully sit down together again
at this point next year, you know,
reflecting on Black Hat 2027?
>> I think well, it'll be a tale of two
cities. It'll be
wonderful success with agentic solutions
and catastrophic failures with agentic
solutions. There's a lot of players out
there. I can't imagine everyone is doing
everything right.
And the pressure, there's always the VC
pressure is get product to market, bind
it customers, you know, improve along
the way, move fast and break things.
Um so, I think that's what will happen.
Well, the lessons learned will be pretty
amazing next year.
>> Absolutely. And it's that balance
between moving fast and breaking things
and then, like you say, kind of taking
the learning. So, it'll be it's going to
be a big year, I think.
>> I think so, too. And um
it was there were CISOs that I talked to
were pragmatic about this. So, a lot of
this is uh
crazy talk and I think we'll have more
rational discussions next year,
hopefully.
>> Yeah, I hope so. And I agree. And I
think CISOs are recognizing that they
really need to start digging in and
understanding, like for example, with
these AI capabilities, what's actually
adding some what has some meat in the
bone and what's actually solving some of
these problems for them. So, I think
there's some skepticism, careful
consideration, and I think we'll, like
you say, we'll have a lot of learnings.
So.
>> Yes, so another quote is I think it was
Bill Gates who said, "You can't automate
a broken process."
So, or you can't achieve benefits from
automating a broken process. So, we need
to understand our processes before we
put AI and automation on top of it.
>> Right. And kind of how they need to
adapt. I agree with that.
All right. Well, John, thank you so much
um for sitting down with me today. Um
I'm really looking forward to continuing
to to dig into all of this with you. So,
really appreciate it.
>> My pleasure, Krista. Anytime.
>> Thank you. And thank you much uh thank
you so much for joining this episode of
Cyber Shift. Um we'll be exploring all
of these topics and more across
cybersecurity and cyber resilience here
in Cyber Shift and really a kind of
across our our coverage at the Cube. So,
we look forward to uh seeing you on the
next segment. Thank you.
>> [music]
>> Mhm.