Submind YouTube summaries
Thumbnail for Mayank Agarwal, Infosys | Crowdstrike Fal.Con 2026

Mayank Agarwal, Infosys | Crowdstrike Fal.Con 2026

Watch on YouTube

Video summary

Mayank Agarwal, Vice President and Head of Cyber Security Americas at Infosys, joins the discussion to reflect on his two-decade tenure with the company and the evolving landscape of cybersecurity. He highlights that while the core principles of security—such as zero trust and the CIA triad (confidentiality, integrity, availability)—remain constant regardless of whether the target is a human or an AI agent, the environment has shifted dramatically due to Artificial Intelligence. Agarwal introduces his "Three V's" framework to describe these changes: velocity, where attack speeds have accelerated from hours to mere seconds; volume, which has surged significantly due to machine-speed capabilities; and vulnerabilities, noting that the number of known flaws has increased tenfold. He emphasizes that defenders no longer have the luxury of time to patch systems before exploits are deployed, fundamentally altering the traditional advantage held by security teams. Despite the increase in the sheer number of vulnerabilities, Agarwal argues that the fundamental nature of attacks has not changed; adversaries still primarily focus on stealing credentials rather than breaking locks. This shift underscores the industry's need to move beyond a sole focus on prevention and real-time detection toward cyber resiliency. He explains that modern security strategies must now prioritize how organizations recover from incidents, including the loss of business context when relying on AI agents. To address these challenges, Infosys advocates for a "3C" approach: continuous discovery and management of attack surfaces, contextual understanding of critical assets and processes to ensure rapid recovery, and correlation of multiple low-priority vulnerabilities that could chain together to form significant attack vectors. This holistic view ensures that security measures are not just about finding flaws but about understanding their real-world business impact. The conversation also delves into the strategic partnership between Infosys and CrowdStrike, illustrating how their combined strengths create a comprehensive defense ecosystem. Agarwal details three key areas of collaboration: utilizing Project Quilt Works to leverage enterprise context alongside CrowdStrike's technology for stress testing new capabilities like Safe Mind; integrating CrowdStrike's Falcon platform as the core engine for their Cyber Next initiative while adding deep customer intimacy; and establishing robust guardrails for enterprise AI programs so businesses can focus on outcomes rather than just safety. Their engagement model is problem-centric, where Infosys acts as a solution provider that maps specific industry challenges to CrowdStrike's capabilities, ensuring that the technology delivers tangible results. They operate with a philosophy of being "hammers" ready to solve any "nail," whether by tailoring processes or jointly engineering solutions for hard problems that neither party could solve alone. Ultimately, Agarwal concludes that while platforms provide the necessary tools, true security success depends on delivering outcomes that align with specific business needs. The partnership allows them to address the gap between available technology and actual threat landscapes, focusing on the spaces between vulnerabilities where adversaries often strike. By combining CrowdStrike's advanced detection and response technologies with Infosys' deep understanding of enterprise operations and AI governance, they aim to help organizations not only survive attacks but thrive in an increasingly complex digital environment. This collaborative approach ensures that security is viewed as a continuous journey of resilience, adaptation, and recovery, rather than a static state of defense.
Read the full video transcript
Hello everyone and welcome back to the cub's live coverage of Falcon 2026 here at the Mandalay Bay in Las Vegas. I'm your host Rebecca Knight alongside Dave Volante, co-CEO of the cube. We have our penultimate guest. I would like to welcome Agarwal, VP and head of cyber securityurities America's at Infosys. Welcome. >> Hey man, thank you for having me here. So before we get into the questions, tell us a little bit about your role leading cyber security for Infosys and and what your job covers in the day-to-day. >> So it's a very exciting job uh for me. Uh in fact, I lead the cyber practice for Infosys in Americas. Uh been with Infosys for almost uh 21 years now. So it's been a long time and doing this role where we are helping the enterprises protect themselves and protect the brand and happy to be kind of working with them our customers happy to be working with our partners like Crowd Strike and uh just doing the right things for them. So it's it's so so impactful. I truly love what I do. >> Okay. So let's see 21 years. So post post Y2K. >> Oh yeah. [laughter] Okay. So when you started at Infosys uh it didn't matter right right everybody was down on it post.com but then it came back in a big way so you went through the the the cloud era the big data era right the social mobile all that you saw that right you guys are had to secure all of that right now the AI so what would you say are the the biggest differences and what's the same so first First of all, by making sure you talked about that 21 years, you made me sound look and very very old. Not [laughter] >> you're so much younger than I. I could take I could take you back 40 50 years if you really want. So, [laughter] >> but that's just a stint with Infosys. So, but there's work that was done prior to it as well. But coming back to the interesting questions, uh there are three things that have truly changed with AI and I call it the three V's. The velocity, the volume and the vulnerabilities. So truly what has changed with AI. Three V's. >> I love it. The velocity of uh the attacks which are happening, the way the adversaries are kind of attacking us in such a quick manner. It was earlier hours now minutes sometimes even seconds which is there. Second piece is just the sheer volume of attacks they have increased significantly and those volumes just because they are able to uh do lot of work at machine speed that has increased and third is the vulnerabilities. In fact, uh, everyone talks about the mythos moment and the number of vulnerabilities has increased by 10x and those three things have truly changed the way things are being worked. So truly the advantage that the defenders had with respect to time. They had time to patch the system. They had times to make remediations. They had time to do lot of things. Now they have no time because as soon as there is a vulnerability that comes out maybe in 10 minutes 15 minutes there is exploit which is already happening that so that is something that has changed. Coming to what has not changed the core principles of cyber security they still remain the same principles of zero trust principles of what we called at the CIA triad uh back when we started which is confidentiality integrity availability those three things that applied to humans they still applied to agents >> very interesting answer thank you for that and it sounds like >> we've been hearing that a lot of another v the variety to steal from Gartner, you know, shout out to th those guys. But the the variety of attacks actually has been very similar. In other words, it's still stealing credentials. Yep. >> Right. It's that's like that's not new. It's just better, faster, you know, more efficacious. >> No, absolutely. And that's why I didn't call in my three V's I didn't call variety because variety still remains the same. The core principles of attack are still the same. Rather than breaking the lock, rather than breaking the lock, steal the key. >> Yeah. If they can and steal the key is getting the credentials. Once I have the key, then I can move anywhere in the house. Once I move anywhere in the house, I can take whatever step that I need to take back out. So that's truly in a very very a normal language, layman language. That's all all attacks are all about. >> Or or of course, if the door's open, just walk in. >> Yeah. It goes back to something George Curts was saying on our show this morning. He he said after the hugging face incident, he was on the phone day day in day out talking to board members who were obviously stressed and talking about how and he said one of the things I said to assuage them I mean obviously they were worried was this is not this is not necessarily new. This is not something out of a sci-fi movie that this is the these are the tactics that they're using we're see we've seen before. So how did you talk to your clients about it and and how did you try to plate their nerves a bit? >> So when we talk to our customers uh about uh this hugging face moments, the mythos moments, those are two watershed moments in the uh in our industry right now. >> Uh so we still tell them that the core principles like I talked about zero trust, I talked about the CIA tri that applied to humans that still applies to agents. the non-human identities they still work in the same fashion. One thing that has changed significantly is earlier the industry was very focused on preventing attacks, detecting attacks in real time and machine speed. What has happened now is there is a huge focus that has come back on cyber resiliency because of all of these challenges which are happening. There is a very big focus in not just in testing the IT cyber resiliency part of it but also testing out the business processes which are there from a cyber resiliency perspective. How it impact different functions within the organization. How different departments work together to get you back on the rails which are there. How do you put the right set of guard rails? So that's something that has uh changed significantly and the focus coming back on resiliency has increased tremendously. I mean recovery from ransomware was you know after W to cry was kind of the that's kind of when the cyber resilience term first came up but now it's morphing again like what if an agent does something that is like of course everybody's talking about here and at black hat it comes down to the business processes. How do I recover, you know, my business? People talking about context. It's not just being able to recover the data. What about the business context? If we're going to increasingly rely on agents to interpret, learn tacet knowledge, etc. Something goes wrong, you're going to have to recover that context that was in, you know, Jack's brain. >> Oh, absolutely. and and and that's where uh what I call as the 3C approach which is when we are protecting uh or discovering things have to be continuous earlier things used to be maybe I'll do patching cycle once in a month now there has to be continuous discovery attack path analysis continuous say attack surface management say things which are there so first is things have to be continuous in nature second you talked about It has to be contextual with respect to the assets that have that are there in my environment. Which are my critical applications? What are the critical business processes these assets are running? How do I recover them? How do I ensure I get back to work in a quick fashion? So that becomes the second C. And the third C is all about correlation. Earlier and and this is something that has changed with AI and at machine speed. Earlier lot of these vulnerabilities there is a CV associated with one vulnerability and we would have patched maybe if a vulnerability comes in as critical we'll come in and patch it if it's not critical maybe we'll come back and look at it 6 months sometimes few years later what has happened today is multiple of these vulnerabilities which are could be very low priorities can be changed together correlated and then form an attack path and an attack vector. So coming back the approach that has changed is the 3C. It has to be continuous. It has to be contextual and it has to be correlated. >> You need to get into marketing because you are good at these these uh these >> we're going through the alphabet here. [laughter] >> Exactly. You >> mentioned correlation. What about causality? Do do we need to know like the real reason why is that and is that too hard to do today? We heard Michael Conus today said, you know, it's not just about what happened, what what did happen, but it's what's happening now. And then Adam Myers was like sort of like what's going to happen, but but is does this how does causality play? >> Actually, that's a very important part and and that's where you would have heard about this whole risk prioritization that everyone talks about. So with this whole mythos moment, everyone talked about can I find more vulnerabilities and most large enterprises they will have close to a million vulnerabilities at any given point in time in their estate. They are all there people are working through it >> and they know they know about they know about it. Yeah. So the question is when this whole mythos moment happened, can frontier vulner with the frontier models help me find maybe 1,000 more vulnerabilities? That's not the big thing. The big thing is once you have found what the critical ones are, the chained ones which are there, what are the steps that you will take to act on it? How do you really see the impact on those sets which are there? And the impact is the business impact. Then can all these vulnerabilities can this whole thing can it be exploited? And once you have found the impact then the core things that you have to work as the three-step process. First you have to remediate whatever you can remediate. Second if you can't remediate you put the right compensating controls in place. Those controls could be technology controls those could be uh process related controls in place. And third, coming back to cyber resiliency. So if anything happens, how do you get back up and get back running? >> Okay, that's the three Rs. Reveal, remediate, and recover. Oh, awesome. [laughter] We're going to get the whole all 26 letters here. >> We're going to do this. We're going to do this if it kills us. So the Crowd Strike Infosys partnership, talk a little bit about what each brings to the table that you couldn't do on your own. So it's a very interesting partnership uh with Crowdstrike and we've been partners for a long time now. We've done several large implementations across the globe. Uh if I just look at the three things that have happened very very recently. So one uh there's this whole project quilt works when the mythos moment happened uh crowd strike realized uh while they bring in the technology we as a company have lot of the enterprise context the customer context which is there so we were one of the founding partners for project quilt works which was there second important thing uh from our perspective is our cyber next platform so what we have done is we've created our cyberext platform and it has some underlying technologies. Falcon is one of the core technology platforms which is the underlying for our cyber next piece and then in addition to it we bring a lot of the enterprise context to it that helps us to protect our customers. That's the second piece. So bringing uh the tech stack the customer intimacy from our side and third is today for uh AI it's all about putting the right guard rails. So we are in lot of the enterprise AI programs and when we help the customers put the right guard rails then the customers can focus on the business outcomes from AI as compared to guarding uh AI itself. So with these three things we think we have a great partnership together and we can amplify the the benefits to our customers. So the project quilt works um relationship is I I think huge y >> because if I understand it correctly that's how um blue salano and red tempest and safe mind are going to be at least initially delivered. is sort of um stress testing it through project quilt works of which you are you know one of the founding members and then it'll get released through you and then maybe eventually well I guess it's going to be embedded into Falcon right and then you'll be able to leverage that for your customers >> yeah absolutely in fact I was part of the partner advisory board uh for the gsis uh yesterday and and when DB and other leaders from crowdstrike they talked about it uh they've made a determination to have quilt works uh as the core uh onboarding platform for our customers. So that's that's exactly uh how uh safe mind and other things are going to be offered to the customers right now. >> What's the sort of take us through the operating you know model and your partnership how you work with crowdstrike what's a typical engagement look like? What do you bring? What do they I mean I know they bring the product and falcon but maybe how an engagement works with a customer. So, so there are three uh ways in which we work uh along with crowdstrike from a engagement model perspective. First and foremost, uh it's all about solving a customer problem. So as uh a true solution provider, we work with customers in their uh problem statements and the problem could be I have uh agent identities uh which are I'm not able to figure out how do we manage them and that's where once we look at those then we come back look at the uh solution and the capabilities of the platform which is the Falcon platform create the right success criteria from a customer standpoint and what we deliver is a outcome to the customer. So that's one model and and this is a model where the customer may or may not have the Falcon platform by uh themselves. Second piece is if a Falcon platform is already being leveraged by a customer. What we do is we truly look at it while the customers are leveraging the platform. They may be leveraging one or two capabilities within the platform. Essentially from a CISO perspective they are only looking at how do I protect myself, how do I reduce risk, how do I look at compliance, how do I focus on cyber resiliency, how do I do the compliance part of it and how do I provide a extremely good user experience. So th those are the five matrices and that's what we bring uh along with the Falcon platform to the customers. So that's the second piece. Third important piece is there are some hard problems that may not be solved right now by the Falcon platform. And that's where when we work with customers, we work with Crowd Strike, we are able to bring some of those hard problems and we put our joint might, our engineering might together and try to solve those hard problems. >> Okay, great. So, but you but really you guys set really deeply understand the business problem in that specific industry and then you map the capabilities within Falcon to that that problem. You're ultimately responsible for making sure that that what CrowdStrike says it can do it can it can be done and so you have to vet that make sure it maps and then you're responsible for the outcome. It's I guess it's jointly responsible for the outcome right >> I think uh most important piece is uh platform is great but platform needs to provide the outcome that the customers are looking for so how it needs to be done sometimes it needs a tailoring of the process from a customer side and that's something that what we deliver to our customer >> the reason I I sort of stumbling around here but but if I'm if I'm if I'm a salesperson for crowdstrike every opportunity is a nail and I'm a hammer. You know, you've got to be, you know, the sort of you've got to be able to mold that that solution in a way that is is going to deliver that outcome at a high probability. >> So, so this in fact uh you pointed it pretty nicely Dave because uh cyber security had this whole nail and a sledgehammer problem. Yeah, >> we had too many nails that we were trying to put sledgehammers to. And when the adversary are looking at, they don't look at the uh nails which are there. They look at the entire surface and then the space between the two nails that's where they meander through and that's what we focus on. >> Okay. >> Great not to end on M. Thank you so much for coming on the show. Really interesting conversation. >> Thank you. It was a pleasure for me to be here. Thank you. >> I'm Rebecca Knight for Dave Volante. Stay tuned for more of the Cub's live coverage of Falcon 2026. You're watching The Cube, the leader in enterprise tech news and analysis. [music]