Video summary
Michael Folks, Director of Cybersecurity Strategy and Engineering at Entergy, a major energy utility serving four states, discussed the critical challenges of securing essential infrastructure in an era of rapid technological change. He highlighted that while data centers are increasingly demanding fast, reliable power—often leading utilities to build new natural gas plants for quick deployment—the threat landscape has evolved dramatically due to artificial intelligence. AI has empowered attackers to create sophisticated phishing campaigns and execute breaches in minutes rather than weeks, forcing security teams to respond with incredible speed. Consequently, Folks emphasized the necessity of isolating critical systems using air gaps and relying on physical security measures, as digital connections can no longer be fully trusted given the potential for remote exploitation or compromised supply chains.
The conversation also addressed the complexities of managing legacy systems alongside modern AI tools and the concept of "hidden AI" within corporate environments. Folks explained that Entergy utilizes CrowdStrike to scan workplaces for unauthorized or hidden AI usage, recognizing that employees might run programs from personal devices without realizing the security implications. A significant portion of the discussion focused on the integration of various cybersecurity tools; while having a unified platform simplifies operations and improves data visibility, it introduces challenges regarding financial sovereignty and vendor lock-in. Folks advised organizations to carefully manage their "Flex" credits and tool portfolios, ensuring they replace ineffective solutions and maintain control over their technological infrastructure rather than becoming dependent on a single supplier's ecosystem.
A major turning point in the dialogue was the recent CrowdStrike incident, which Folks described as a catalyst that completely shifted boardroom expectations and operational priorities. Before the event, the focus was largely on development and standard protection, but the incident forced immediate action to reduce risk exposure and increase resilience across all suppliers and partners. Folks noted that responses from vendors varied significantly in quality; some provided generic statements while others offered specific, actionable plans. He recommended that companies demand individualized communication from their suppliers rather than accepting broad public announcements, as this demonstrates a genuine commitment to client safety. Ultimately, the industry must navigate the gray areas of shared responsibility in cloud environments and prepare for a future where machine-speed threats require immediate, automated responses that human analysts alone cannot manage.
Read the full video transcript
Good evening everyone,
and welcome back to
"The Cube's"
live coverage of "
Falcon 2026" here at the
Mandalay Bay Hotel in Las
Vegas. I'm your host
Rebecca Knight, accompanied by
Dave Volante,
co-founder of "The Cube".
Michael Faulks joins us
. He is the Director of
Cybersecurity Strategy and Engineering at
"Intergy". It was a
pleasure meeting you, Rebecca
.
Thank you very much for attending the
program. For those
who don't know "
Entergy," you are a
major energy company, and electricity
is a
basic necessity. Can you
talk a little about
your company and what you do there?
Well, as I mentioned, I'm the
director responsible for
cybersecurity strategy and architecture,
and we help to develop the
roadmap for the
security tools and controls that
we implement at "Entergy".
As a utility company,
we provide power to four
states. Therefore, we must
protect our company
so that we can provide
energy to our customers.
Which states do
you operate in? Sorry.
Texas, Louisiana,
Mississippi, and Arkansas.
Good. So, this is not
within your scope of work. no.
But I will ask you anyway
. Texas, as you know,
has many data centers
. The governor says:
Well, maybe not. You know,
it's politics in all its
dimensions. What is the truth
about data centers' energy consumption
? Is it mixed?
Perhaps older data centers are
very inefficient. Are the
new data centers
effective? How should we
view this matter
?
That's a good question. I mean,
when you think about
data centers, they require
a lot of power, do
n't they? We will build
several
new power plants
to help provide the
energy needed for
those AI data centers. When
looking at the most
efficient types of power plants
you can build,
most will
likely be
natural gas-powered because they are quick to
produce and supply, and
because AI data centers
need power
quickly as they try to
get to market
fast. So, they will need
fast energy.
Many of them are building
their own power generation systems. Is this mixed? Is
this correct? Is this...?
That's a good question. I don't
know the answer to that.
Perfectly acceptable. Let's get down
to business...
Well, as Dave said,
this is a very
important infrastructure, and we've talked
a lot about the types of
patterns we've seen
with these opponents. Are
there any particular threat patterns that
you observe
in the energy sector?
Well, I mean, with any type
of threat, you see a
huge increase in
phishing, right
? With the capabilities of
artificial intelligence, fraudulent emails have become
more
sophisticated, haven't they?
Also, this reduces the
time it takes for
systems to be
hacked, doesn't it?
Things that used to
take an attacker
a few weeks to break into a
system and do something. It only
takes
minutes now, doesn't it? From
this perspective, the
threat landscape is changing.
When you look at
this threat landscape, how do
you respond or react with such
incredible speed? I was
asking Adam Myers, you
know, about our feelings regarding the
security of
critical infrastructure, and he said that
opinions are
fundamentally divided. There are many
old systems and
there are also many
things that are probably
not directly connected
. Your region of the world is
probably well connected. So,
well, when I look at
critical infrastructure, we evaluate
that intensively and want
to isolate it as much as possible.
important. You don't want
access to those
types of systems
because it could be
dangerous.
Therefore, you rely on
air gaps wherever
possible.
You want to get as much
separation as possible.
Good. So
how do you manage your business if you
rely on air insulation?
correct. This is another challenge, is
n't it?
correct. You mentioned that there are
many
old systems, didn't you?
correct.
That's true. You have to transfer
the data manually. You need to
put in place controls that delay
processes like
debugging and things like that
because you don't have that
full connection.
So,
physical security was also a big part
of the challenge it faced
. I remember "Stuxnet"
and I read about its anatomy
and how they said, "Oh yes, the
airtight seal, we can
break through it, no problem,
they'll just insert a
drive," so you have to
worry about those things
too.
You have to worry about
everything, especially with
artificial intelligence
nowadays. Even if
you are not connected to
the internet, there may be a
system somewhere
connected to something you are unaware of
, right?
Therefore, you should
always be careful and vigilant
towards everything.
So, the energy company established an
artificial intelligence team two years ago,
is that correct? Okay, so
how do you think about building a
long-
term strategy for a technology that is
evolving this quickly?
How do you think about that, especially
since your team works on a
daily basis?
It distracts my mind
in the first place.
Because things are moving very fast
. You know,
the purpose of the AI team
that was created
was to build
AI
within our company,
right? How can we
utilize
artificial intelligence in
daily work? But when
I think about threats from an
AI perspective
, I have to find a
way to protect what they do
and protect against
bad actors, right?
That threat is related to
artificial intelligence.
Okay guys, I mean it's a
regulated industry
. Generally speaking,
how dangerous is "
hidden AI" in your
organization? How worried are you about it?
I'm worried about it
too. I mean, is this
how you deal with it?
Well, with CrowdStrike, we
search and scan the workplace
for
hidden AI,
right? We try to
find out where it is being
used and stop it,
because you know
anyone can take a
laptop, download something, and
run a program from their
personal device. Therefore, you should
be aware and
constantly scan and research this in the
work environment.
What is your journey with CrowdStrike? Can you
take us
through that experience?
Yes, we have used
CrowdStrike for several years. We
have a large amount of
platform. We are AID customers,
so in fact, with
Guardian we will be able to
take advantage of it, but
the insight into the data, the
enriched data we
have, and the telemetry are truly
amazing. It's
the vision, actually, is
n't it? As
we work on developing
our implementation of this, it
brings many
benefits to the company. Are
you a Flex customer? May I
ask a question? Yes.
Good. And what is your opinion of
Flex? It was
interesting. We had
some data from
our partner Qualitate, and as
you know, Crowd talks about Flex
all the time on Wall
Street. Of course, when
you talk to customers,
they don't necessarily see it as a
contractual instrument. They see
it as a way to simplify
things, help us
move faster, and
allow us to add
new units. We don't need to
bring in a new supplier. How do
you see it?
I think about it the same
way, don't I?
So I feel that if there is
something in my toolkit that I am
not using,
I want to redeem it
and get Flex credit, and
then use that credit
to deploy something that I would like to
use. This gives me the
flexibility I need; So, if
anything new comes up and
I have a "
flex" balance, as you said, I
don't have to repeat the
whole process,
right? I can only
say: Hey, that's what
I want. Let's use "
Flex" credits to get it. Are
you able to integrate the
number of tools you have
? certainly. Oh,
really? Good. I mean,
a lot of people in your
position say, "We're
trying. We're having trouble
getting there, but you're
managing it."
We succeed in cases where the
cybersecurity team has the
tools, right?
Therefore, if we
already have the tools, it becomes
easier to integrate those
applications into the "
CrowdStrike" platform. The part
that becomes more difficult
is when the tools are
owned by another group
outside of cybersecurity
, where they prefer their tool and
you prefer yours, and
questions begin about
which one wins in
the end, right?
With integration, you of course get
better data and measurements, but you also give
this unified platform,
let's say "CrowdStrike"
in this case,
greater independence.
millimeter. This forces you to
sleep with one eye
open. So how do you think about
this? And how do you maintain your
sovereignty? I don't mean
territorial sovereignty here. I mean
your control over your
technological infrastructure,
your operations, your pricing,
i.e., your financial sovereignty, etc.
How do you think about that?
We had a customer who was very happy with
the "Flex" service, but he
said: "You should keep an eye
on it." It's like a
cloud bill; you need to
make sure you
use it wisely and that you get the
most out of it.
Therefore, we must
certainly
rely on the teams
to ensure that they are achieving the
desired value from the
tools we have.
If
something is not useful, let's replace it and
look for
something else, right?
When it comes to the story of
competing tools, it's
really about
helping people
figure out what CrowdStrike offers
compared to what
they have, and hopefully
accompanying them on that
journey to say, "Look
, this is the best approach
, and let's see if we
can align to
help reduce
costs."
To what extent do you rely on
the cloud? I mean,
you clearly know that "Crowd"
starts from the cloud, but
what percentage of your
overall reliance is on the cloud
versus...
our footprint is small right now
because you intentionally rely
on
local infrastructure.
This is correct. The
reason I'm asking is that I'm sure you're
familiar with the
shared responsibility model
in the cloud. It is similar to
our current situation in light of this
new model
of joint guarantee or
joint liability.
Nations, and it is a type of
crystallization now. Much
of this is
completely new.
Have you thought about that a lot
? How do you view this
matter?
For example, who is
responsible?
Okay, that's right. I don't
know how capable the regulator is
of determining whether
we are still responsible
or whether they are.
So, this
area is still a little gray
. You know, you may have
that
shared responsibility,
but ultimately it's up to
the organizer to say,
"No, you remain
ultimately responsible for
that even if they say they are
involved in this part."
So it will be
interesting to see how
this develops,
won't it? Because I think
about things like the
General
Data Protection Regulation (GDPR) when it
happened. It took a
long time to
test it. certainly.
So I think it will take
some time to
mature.
We will see some
real-life examples. There will likely be
cases in
the courts, and that will
put us on the
right track.
No, but there is still a
question of who is responsible
when things go wrong.
Well, we are here at the
"Falcon" conference. There were
lots of
new product announcements and
demonstrations on stage
as well this morning. What do
you see as a
Falcon
Flex customer? What did you find
most impactful in terms of
what you want to convey to your
team?
There are definitely two
main elements that impressed me. The
first is "SafeMind"
to carry out operations for the
Red Team and the
Blue Team. We were already
thinking about how to
do it ourselves,
and it seems that this will simplify things in
many ways. The
second thing is
CrowdStrike's move towards the
identity domain, doing
more in this area
, and being able to block
things at the
endpoint as a simple process
, whereas we were looking at things
like the allowed list
, which is difficult
to implement, whereas
this is directly integrated into the
sensor. If you say, "
I do not want to run this
particular executable," or if you
have elevated privileges,
you will be blocked
and prompted for
multi-factor authentication (MFA).
I believe these two
products will go a long way
in
helping us combat the
threats of
artificial intelligence in our environment. And
to make sure that it
continues as well. Not only
when logging in, but
the question is always: who
uses this and how does it work? exactly
.
So how do you get that?
Are you part of the "
Quilt Works" project or are you doing so
through a partner? "
Coilt Works" is a type
of union. I'm not
sure. Good. So
what I saw on stage
was basically Team
Red, Team
Blue, and the system.
This loop is
endless. I believe it is
available through what
they call the "Quilt
Works" project.
So, we don't have that.
Yes. correct.
So, that's something we're looking forward to. I've
spoken with
our sales representative.
I told him, "Wait, I have a
lot of questions."
This is correct. I have many
questions. How
can I get it?
Good. And I believe it
comes through that
union. I call it a
union if that
is the correct term.
But my understanding is that you operate it
in a digital twin. That's what
I heard. So you are creating a
digital twin for
your organization,
which I found
interesting, and it is really
cool.
So that's an
experimental environment, isn't it?
I mean, then you turn it on
. Good. Once you are
satisfied that all the
vulnerabilities have been addressed, you then
publish.
This is correct. And then I do
n't know what
you do? Are you conducting more
tests or what
?
That's a good question. I can't
wait to get our hands on the
product so I can
really test it and try it out
completely. wow
. surprising. It's exciting to
see them on stage.
As an executive in the
cybersecurity
and
critical infrastructure sector, what are your thoughts
when you are here or at
other industry conferences
talking with your peers? What
is an area that you think
people are not paying
enough attention to at the
moment? I mean, I
think I'm asking you what's been bothering you
at night and...
well,
artificial intelligence is one of them, is
n't it? I mean, if
you think about the speed at which
artificial intelligence can move
within the environment, that's the
scariest thing for me. And also
, as you know,
people are lenient in their behavior. As
mentioned before, "security
through obscurity" means if
you don't know that there's a
dollar sign behind your
shared hard drive
, and that it's hidden, then
you don't know it exists.
Well,
artificial intelligence will find that, wo
n't it? He will
exploit that. So,
as I think about the industry
as a whole and think about
artificial intelligence...
you know, when you look at
some people who are
taking
OT technologies and connecting them to
the cloud and so on,
we take a step back and
wonder, "How
can I separate these
things, right?"
Because "with the speed at which
artificial intelligence moves, I want to
make sure we are protected
." It may be, as I
said,
completely airtight and protected. But
these are some of the things that
really worry me, namely the
threat of
artificial intelligence.
Artificial intelligence,
and also humans, as I mentioned
.
Well, I mean, with
humans you have a little more time
to detect
and respond, because if
someone is doing something
, you'll get a notification
somewhere. This gives the
analyst at the security operations center
the opportunity to see
it, analyze it, and then take
action on it, because that
person works at
human speed, which is not fast
compared to artificial intelligence,
which works at
machine speed, so if an
incident occurs, the analyst does not have the
time or luxury to
actually sit down and assess the
matter. You must take
immediate action. Are you being
dragged into
board meetings?
No, I am not. My manager is the one who
brings it.
Good. Good. But it is assumed that you
help your manager
prepare for it.
This is correct. Can
you give us an idea
of how the nature of
board discussions changed
before and after "Mythos"?
Has it changed? I
think she's changed.
Because before "Mythos", there was a
completely different set of expectations for what you were trying to do
. She is
still trying to protect the
environment. You are still trying to
make sure you develop what
you have. But when "
Mythos" came, he turned the tables completely
. And when
that happened, you had to
look at a lot of
areas and move
quickly if you wanted to address the
issue, didn't you?
Reduce the range of impact,
increase resilience; you
know, you want to reduce
exposure to risks.
When you think about these
things, it
completely changes the story. It
changes the dynamic of what is
expected of you.
So, was that the
first step? I mean,
I'm sure there was a
quick internal meeting. And what happened next
? Was the contact with a
supplier? Was the contact with a
consultant?
Oh, yes. No, once it was
released the
following week, we received
the announcement on Thursday. The
following week,
we were in contact with all our
suppliers and partners.
Hello, what are you doing
to address this issue? exactly
. Because we want to
know what their situation is,
well, we just received a
notification too.
Therefore, we are still
formulating things. Did
you see a variety of
responses that
gave you
varying levels of confidence?
Yes.
Good.
So, a lot of
the things we were
receiving reflected what we were doing
. So, yes
.
I mean, you know, I don't want you to
mention names.
I conclude that CrowdStrike did a fairly
good job in
terms of its response. But
what kind of things were you
monitoring—I don't
say measuring—that
gave you confidence in some
cases? This resource
controls the situation,
and that group needs to
sort itself out. What
advice would
you give them to gain
more confidence in you? That's a
good question. Those who
were
truly in control of the situation
clearly put their plan in place.
They said, "That's what we're doing
right now." This is
how we handle
these matters. This is what we
recommend doing.
So, whenever a
partner or supplier is involved,
if you have this in
your environment, this is what we recommend
doing to address the issue,
right? You may have
some who have only provided a
general and comprehensive statement
. From this perspective,
I would say, to
those who made
that public statement,
go back and address
your clients individually. So that
they know you
care about them and that you are
trying to address
their concerns. I had some
customers whose
supplier's answer was, "
Okay, buy this,"
right? Which did
not
necessarily make them happy. They were
saying, "Okay, what
else do you have?" So, I don't know
. Have you experienced that?
No, not to my knowledge.
Good. Perhaps some of
your colleagues. exactly
. Michael, we were delighted to have you with us
on The Cube.
It was a truly wonderful conversation
.
Yes. I am Rebecca Knight on behalf of
Dave Volante.
Stay with us for more of
The Cube's live coverage of
Falcon 2026. You are watching
The Cube, the leader in enterprise
technology news and analysis
.