Video summary
Mayank Agarwal, Vice President and Head of Cyber Security Americas at Infosys, joins the discussion to reflect on his two-decade tenure with the company and the evolving landscape of cybersecurity. He highlights that while the core principles of security—such as zero trust and the CIA triad (confidentiality, integrity, availability)—remain constant regardless of whether the target is a human or an AI agent, the environment has shifted dramatically due to Artificial Intelligence. Agarwal introduces his "Three V's" framework to describe these changes: velocity, where attack speeds have accelerated from hours to mere seconds; volume, which has surged significantly due to machine-speed capabilities; and vulnerabilities, noting that the number of known flaws has increased tenfold. He emphasizes that defenders no longer have the luxury of time to patch systems before exploits are deployed, fundamentally altering the traditional advantage held by security teams.
Despite the increase in the sheer number of vulnerabilities, Agarwal argues that the fundamental nature of attacks has not changed; adversaries still primarily focus on stealing credentials rather than breaking locks. This shift underscores the industry's need to move beyond a sole focus on prevention and real-time detection toward cyber resiliency. He explains that modern security strategies must now prioritize how organizations recover from incidents, including the loss of business context when relying on AI agents. To address these challenges, Infosys advocates for a "3C" approach: continuous discovery and management of attack surfaces, contextual understanding of critical assets and processes to ensure rapid recovery, and correlation of multiple low-priority vulnerabilities that could chain together to form significant attack vectors. This holistic view ensures that security measures are not just about finding flaws but about understanding their real-world business impact.
The conversation also delves into the strategic partnership between Infosys and CrowdStrike, illustrating how their combined strengths create a comprehensive defense ecosystem. Agarwal details three key areas of collaboration: utilizing Project Quilt Works to leverage enterprise context alongside CrowdStrike's technology for stress testing new capabilities like Safe Mind; integrating CrowdStrike's Falcon platform as the core engine for their Cyber Next initiative while adding deep customer intimacy; and establishing robust guardrails for enterprise AI programs so businesses can focus on outcomes rather than just safety. Their engagement model is problem-centric, where Infosys acts as a solution provider that maps specific industry challenges to CrowdStrike's capabilities, ensuring that the technology delivers tangible results. They operate with a philosophy of being "hammers" ready to solve any "nail," whether by tailoring processes or jointly engineering solutions for hard problems that neither party could solve alone.
Ultimately, Agarwal concludes that while platforms provide the necessary tools, true security success depends on delivering outcomes that align with specific business needs. The partnership allows them to address the gap between available technology and actual threat landscapes, focusing on the spaces between vulnerabilities where adversaries often strike. By combining CrowdStrike's advanced detection and response technologies with Infosys' deep understanding of enterprise operations and AI governance, they aim to help organizations not only survive attacks but thrive in an increasingly complex digital environment. This collaborative approach ensures that security is viewed as a continuous journey of resilience, adaptation, and recovery, rather than a static state of defense.
Read the full video transcript
Hello everyone and welcome back to the
cub's live coverage of Falcon 2026 here
at the Mandalay Bay in Las Vegas. I'm
your host Rebecca Knight alongside Dave
Volante, co-CEO of the cube. We have our
penultimate guest. I would like to
welcome Agarwal, VP and head of cyber
securityurities America's at Infosys.
Welcome.
>> Hey man, thank you for having me here.
So before we get into the questions,
tell us a little bit about your role
leading cyber security for Infosys and
and what your job covers in the
day-to-day.
>> So it's a very exciting job uh for me.
Uh in fact, I lead the cyber practice
for Infosys in Americas. Uh been with
Infosys for almost uh 21 years now. So
it's been a long time and doing this
role where we are helping the
enterprises protect themselves and
protect the brand and happy to be kind
of working with them our customers happy
to be working with our partners like
Crowd Strike and uh just doing the right
things for them. So it's it's so so
impactful. I truly love what I do.
>> Okay. So let's see 21 years. So post
post Y2K.
>> Oh yeah. [laughter] Okay. So when you
started at Infosys uh it didn't matter
right right everybody was down on it
post.com but then it came back in a big
way so you went through the the the
cloud era the big data era right the
social mobile all that you saw that
right you guys are had to secure all of
that right now the AI so what would you
say are the the biggest differences and
what's the same so first First of all,
by making sure you talked about that 21
years, you made me sound look and very
very old. Not [laughter]
>> you're so much younger than I. I could
take I could take you back 40 50 years
if you really want. So, [laughter]
>> but that's just a stint with Infosys.
So, but there's work that was done prior
to it as well. But coming back to the
interesting questions, uh there are
three things that have truly changed
with AI and I call it the three V's. The
velocity, the volume and the
vulnerabilities. So truly what has
changed with AI. Three V's.
>> I love it. The velocity of uh the
attacks which are happening, the way the
adversaries are kind of attacking us in
such a quick manner. It was earlier
hours now minutes sometimes even seconds
which is there. Second piece is just the
sheer volume of attacks they have
increased significantly and those
volumes just because they are able to uh
do lot of work at machine speed that has
increased and third is the
vulnerabilities. In fact, uh, everyone
talks about the mythos moment and the
number of vulnerabilities has increased
by 10x and those three things have truly
changed the way things are being worked.
So truly the advantage that the
defenders had with respect to time. They
had time to patch the system. They had
times to make remediations. They had
time to do lot of things. Now they have
no time because as soon as there is a
vulnerability that comes out maybe in 10
minutes 15 minutes there is exploit
which is already happening that so that
is something that has changed. Coming to
what has not changed the core principles
of cyber security they still remain the
same principles of zero trust principles
of what we called at the CIA triad uh
back when we started which is
confidentiality integrity availability
those three things that applied to
humans they still applied to agents
>> very interesting answer thank you for
that and it sounds like
>> we've been hearing that a lot of another
v the variety to steal from Gartner, you
know, shout out to th those guys. But
the the variety of attacks actually has
been very similar. In other words, it's
still stealing credentials. Yep.
>> Right. It's that's like that's not new.
It's just better, faster, you know, more
efficacious.
>> No, absolutely. And that's why I didn't
call in my three V's I didn't call
variety because variety still remains
the same. The core principles of attack
are still the same. Rather than breaking
the lock, rather than breaking the lock,
steal the key.
>> Yeah. If they can and steal the key is
getting the credentials. Once I have the
key, then I can move anywhere in the
house. Once I move anywhere in the
house, I can take whatever step that I
need to take back out. So that's truly
in a very very a normal language, layman
language. That's all all attacks are all
about.
>> Or or of course, if the door's open,
just walk in.
>> Yeah.
It goes back to something George Curts
was saying on our show this morning. He
he said after the hugging face incident,
he was on the phone day day in day out
talking to board members who were
obviously stressed and talking about how
and he said one of the things I said to
assuage them I mean obviously they were
worried was this is not this is not
necessarily new. This is not something
out of a sci-fi movie that this is the
these are the tactics that they're using
we're see we've seen before. So how did
you talk to your clients about it and
and how did you try to plate their
nerves a bit?
>> So when we talk to our customers uh
about uh this hugging face moments, the
mythos moments, those are two watershed
moments in the uh in our industry right
now.
>> Uh so we still tell them that the core
principles like I talked about zero
trust, I talked about the CIA tri that
applied to humans that still applies to
agents. the non-human identities they
still work in the same fashion. One
thing that has changed significantly is
earlier the industry was very focused on
preventing attacks, detecting attacks in
real time and machine speed. What has
happened now is there is a huge focus
that has come back on cyber resiliency
because of all of these challenges which
are happening. There is a very big focus
in not just in testing the IT cyber
resiliency part of it but also testing
out the business processes which are
there from a cyber resiliency
perspective. How it impact different
functions within the organization. How
different departments work together to
get you back on the rails which are
there. How do you put the right set of
guard rails? So that's something that
has uh changed significantly and the
focus coming back on resiliency has
increased tremendously. I mean recovery
from ransomware was you know after W to
cry was kind of the that's kind of when
the cyber resilience term first came up
but now it's morphing again like what if
an agent does something that is like of
course everybody's talking about here
and at black hat
it comes down to the business processes.
How do I recover, you know, my business?
People talking about context. It's not
just being able to recover the data.
What about the business context? If
we're going to increasingly rely on
agents to interpret, learn tacet
knowledge, etc. Something goes wrong,
you're going to have to recover that
context that was in, you know, Jack's
brain.
>> Oh, absolutely. and and and that's where
uh what I call as the 3C approach which
is when we are protecting uh or
discovering things have to be continuous
earlier things used to be maybe I'll do
patching cycle once in a month now there
has to be continuous discovery attack
path analysis continuous say attack
surface management say things which are
there so first is things have to be
continuous in nature second you talked
about It has to be contextual
with respect to the assets that have
that are there in my environment. Which
are my critical applications? What are
the critical business processes these
assets are running? How do I recover
them? How do I ensure I get back to work
in a quick fashion? So that becomes the
second C. And the third C is all about
correlation. Earlier and and this is
something that has changed with AI and
at machine speed. Earlier lot of these
vulnerabilities there is a CV associated
with one vulnerability and we would have
patched maybe if a vulnerability comes
in as critical we'll come in and patch
it if it's not critical maybe we'll come
back and look at it 6 months sometimes
few years later what has happened today
is multiple of these vulnerabilities
which are could be very low priorities
can be changed together correlated and
then form an attack path and an attack
vector. So coming back the approach that
has changed is the 3C. It has to be
continuous. It has to be contextual and
it has to be correlated.
>> You need to get into marketing because
you are good at these these uh these
>> we're going through the alphabet here.
[laughter]
>> Exactly. You
>> mentioned correlation.
What about causality? Do do we need to
know like the real reason why is that
and is that too hard to do today? We
heard Michael Conus today said, you
know, it's not just about what happened,
what what did happen, but it's what's
happening now. And then Adam Myers was
like sort of like what's going to
happen, but but is does this how does
causality play?
>> Actually, that's a very important part
and and that's where you would have
heard about this whole risk
prioritization that everyone talks
about. So with this whole mythos moment,
everyone talked about can I find more
vulnerabilities and most large
enterprises they will have close to a
million vulnerabilities at any given
point in time in their estate. They are
all there people are working through it
>> and they know they know about they know
about it. Yeah. So the question is when
this whole mythos moment happened, can
frontier vulner with the frontier models
help me find maybe 1,000 more
vulnerabilities? That's not the big
thing. The big thing is once you have
found what the critical ones are, the
chained ones which are there, what are
the steps that you will take to act on
it? How do you really see the impact on
those sets which are there? And the
impact is the business impact. Then can
all these vulnerabilities can this whole
thing can it be exploited?
And once you have found the impact then
the core things that you have to work as
the three-step process. First you have
to remediate whatever you can remediate.
Second if you can't remediate you put
the right compensating controls in
place. Those controls could be
technology controls those could be uh
process related controls in place. And
third, coming back to cyber resiliency.
So if anything happens, how do you get
back up and get back running?
>> Okay, that's the three Rs. Reveal,
remediate, and recover. Oh, awesome.
[laughter]
We're going to get the whole all 26
letters here.
>> We're going to do this. We're going to
do this if it kills us. So the Crowd
Strike Infosys partnership, talk a
little bit about what each brings to the
table that you couldn't do on your own.
So it's a very interesting partnership
uh with Crowdstrike and we've been
partners for a long time now. We've done
several large implementations across the
globe. Uh if I just look at the three
things that have happened very very
recently. So one uh there's this whole
project quilt works when the mythos
moment happened uh crowd strike realized
uh while they bring in the technology we
as a company have lot of the enterprise
context the customer context which is
there so we were one of the founding
partners for project quilt works which
was there second important thing uh from
our perspective is our cyber next
platform so what we have done is we've
created our cyberext platform
and it has some underlying technologies.
Falcon is one of the core technology
platforms which is the underlying for
our cyber next piece and then in
addition to it we bring a lot of the
enterprise context to it that helps us
to protect our customers. That's the
second piece. So bringing uh the tech
stack the customer intimacy from our
side and third is today for uh AI it's
all about putting the right guard rails.
So we are in lot of the enterprise AI
programs and when we help the customers
put the right guard rails then the
customers can focus on the business
outcomes from AI as compared to guarding
uh AI itself. So with these three things
we think we have a great partnership
together and we can amplify the the
benefits to our customers. So the
project quilt works um relationship is I
I think huge y
>> because if I understand it correctly
that's how um blue salano and red
tempest and safe mind are going to be at
least initially delivered. is sort of um
stress testing it through project quilt
works of which you are you know one of
the founding members and then it'll get
released through you and then maybe
eventually well I guess it's going to be
embedded into Falcon right and then
you'll be able to leverage that for your
customers
>> yeah absolutely in fact I was part of
the partner advisory board uh for the
gsis uh yesterday and and when DB and
other leaders from crowdstrike they
talked about it uh they've made a
determination to have quilt works
uh as the core uh onboarding platform
for our customers. So that's that's
exactly uh how uh safe mind and other
things are going to be offered to the
customers right now.
>> What's the sort of take us through the
operating you know model
and your partnership how you work with
crowdstrike what's a typical engagement
look like? What do you bring? What do
they I mean I know they bring the
product and falcon but maybe how an
engagement works with a customer. So, so
there are three uh ways in which we work
uh along with crowdstrike from a
engagement model perspective. First and
foremost, uh it's all about solving a
customer problem. So as uh a true
solution provider, we work with
customers in their uh problem statements
and the problem could be I have uh agent
identities uh which are I'm not able to
figure out how do we manage them and
that's where once we look at those then
we come back look at the uh solution and
the capabilities of the platform which
is the Falcon platform create the right
success criteria from a customer
standpoint and what we deliver is a
outcome to the customer. So that's one
model and and this is a model where the
customer may or may not have the Falcon
platform by uh themselves. Second piece
is if a Falcon platform is already being
leveraged by a customer. What we do is
we truly look at it while the customers
are leveraging the platform. They may be
leveraging one or two capabilities
within the platform. Essentially from a
CISO perspective they are only looking
at how do I protect myself, how do I
reduce risk, how do I look at
compliance, how do I focus on cyber
resiliency, how do I do the compliance
part of it and how do I provide a
extremely good user experience. So th
those are the five matrices and that's
what we bring uh along with the Falcon
platform to the customers. So that's the
second piece. Third important piece is
there are some hard problems that may
not be solved right now by the Falcon
platform. And that's where when we work
with customers, we work with Crowd
Strike, we are able to bring some of
those hard problems and we put our joint
might, our engineering might together
and try to solve those hard problems.
>> Okay, great. So, but you but really you
guys set really deeply understand the
business problem in that specific
industry and then you map the
capabilities within Falcon to that that
problem. You're ultimately responsible
for
making sure that that what CrowdStrike
says it can do it can it can be done and
so you have to vet that make sure it
maps and then you're responsible for the
outcome. It's I guess it's jointly
responsible for the outcome right
>> I think uh most important piece is uh
platform is great but platform needs to
provide the outcome that the customers
are looking for so how it needs to be
done sometimes it needs a tailoring of
the process from a customer side and
that's something that what we deliver to
our customer
>> the reason I I sort of stumbling around
here but but if I'm if I'm if I'm a
salesperson for crowdstrike every
opportunity is a nail and I'm a hammer.
You know, you've got to be, you know,
the sort of you've got to be able to
mold that that solution in a way that is
is going to deliver that outcome at a
high probability.
>> So, so this in fact uh you pointed it
pretty nicely Dave because uh
cyber security had this whole nail and a
sledgehammer problem. Yeah,
>> we had too many nails that we were
trying to put sledgehammers to. And when
the adversary are looking at, they don't
look at the uh nails which are there.
They look at the entire surface and then
the space between the two nails that's
where they meander through and that's
what we focus on.
>> Okay.
>> Great not to end on M. Thank you so much
for coming on the show. Really
interesting conversation.
>> Thank you. It was a pleasure for me to
be here. Thank you.
>> I'm Rebecca Knight for Dave Volante.
Stay tuned for more of the Cub's live
coverage of Falcon 2026. You're watching
The Cube, the leader in enterprise tech
news and analysis.
[music]