Submind YouTube summaries
Thumbnail for Michael Folks, Entergy | Crowdstrike Fal.Con 2026

Michael Folks, Entergy | Crowdstrike Fal.Con 2026

Watch on YouTube

Video summary

Michael Folks, Director of Cybersecurity Strategy and Engineering at Entergy, a major energy utility serving four states, discussed the critical challenges of securing essential infrastructure in an era of rapid technological change. He highlighted that while data centers are increasingly demanding fast, reliable power—often leading utilities to build new natural gas plants for quick deployment—the threat landscape has evolved dramatically due to artificial intelligence. AI has empowered attackers to create sophisticated phishing campaigns and execute breaches in minutes rather than weeks, forcing security teams to respond with incredible speed. Consequently, Folks emphasized the necessity of isolating critical systems using air gaps and relying on physical security measures, as digital connections can no longer be fully trusted given the potential for remote exploitation or compromised supply chains. The conversation also addressed the complexities of managing legacy systems alongside modern AI tools and the concept of "hidden AI" within corporate environments. Folks explained that Entergy utilizes CrowdStrike to scan workplaces for unauthorized or hidden AI usage, recognizing that employees might run programs from personal devices without realizing the security implications. A significant portion of the discussion focused on the integration of various cybersecurity tools; while having a unified platform simplifies operations and improves data visibility, it introduces challenges regarding financial sovereignty and vendor lock-in. Folks advised organizations to carefully manage their "Flex" credits and tool portfolios, ensuring they replace ineffective solutions and maintain control over their technological infrastructure rather than becoming dependent on a single supplier's ecosystem. A major turning point in the dialogue was the recent CrowdStrike incident, which Folks described as a catalyst that completely shifted boardroom expectations and operational priorities. Before the event, the focus was largely on development and standard protection, but the incident forced immediate action to reduce risk exposure and increase resilience across all suppliers and partners. Folks noted that responses from vendors varied significantly in quality; some provided generic statements while others offered specific, actionable plans. He recommended that companies demand individualized communication from their suppliers rather than accepting broad public announcements, as this demonstrates a genuine commitment to client safety. Ultimately, the industry must navigate the gray areas of shared responsibility in cloud environments and prepare for a future where machine-speed threats require immediate, automated responses that human analysts alone cannot manage.
Read the full video transcript
Good evening everyone, and welcome back to "The Cube's" live coverage of " Falcon 2026" here at the Mandalay Bay Hotel in Las Vegas. I'm your host Rebecca Knight, accompanied by Dave Volante, co-founder of "The Cube". Michael Faulks joins us . He is the Director of Cybersecurity Strategy and Engineering at "Intergy". It was a pleasure meeting you, Rebecca . Thank you very much for attending the program. For those who don't know " Entergy," you are a major energy company, and electricity is a basic necessity. Can you talk a little about your company and what you do there? Well, as I mentioned, I'm the director responsible for cybersecurity strategy and architecture, and we help to develop the roadmap for the security tools and controls that we implement at "Entergy". As a utility company, we provide power to four states. Therefore, we must protect our company so that we can provide energy to our customers. Which states do you operate in? Sorry. Texas, Louisiana, Mississippi, and Arkansas. Good. So, this is not within your scope of work. no. But I will ask you anyway . Texas, as you know, has many data centers . The governor says: Well, maybe not. You know, it's politics in all its dimensions. What is the truth about data centers' energy consumption ? Is it mixed? Perhaps older data centers are very inefficient. Are the new data centers effective? How should we view this matter ? That's a good question. I mean, when you think about data centers, they require a lot of power, do n't they? We will build several new power plants to help provide the energy needed for those AI data centers. When looking at the most efficient types of power plants you can build, most will likely be natural gas-powered because they are quick to produce and supply, and because AI data centers need power quickly as they try to get to market fast. So, they will need fast energy. Many of them are building their own power generation systems. Is this mixed? Is this correct? Is this...? That's a good question. I don't know the answer to that. Perfectly acceptable. Let's get down to business... Well, as Dave said, this is a very important infrastructure, and we've talked a lot about the types of patterns we've seen with these opponents. Are there any particular threat patterns that you observe in the energy sector? Well, I mean, with any type of threat, you see a huge increase in phishing, right ? With the capabilities of artificial intelligence, fraudulent emails have become more sophisticated, haven't they? Also, this reduces the time it takes for systems to be hacked, doesn't it? Things that used to take an attacker a few weeks to break into a system and do something. It only takes minutes now, doesn't it? From this perspective, the threat landscape is changing. When you look at this threat landscape, how do you respond or react with such incredible speed? I was asking Adam Myers, you know, about our feelings regarding the security of critical infrastructure, and he said that opinions are fundamentally divided. There are many old systems and there are also many things that are probably not directly connected . Your region of the world is probably well connected. So, well, when I look at critical infrastructure, we evaluate that intensively and want to isolate it as much as possible. important. You don't want access to those types of systems because it could be dangerous. Therefore, you rely on air gaps wherever possible. You want to get as much separation as possible. Good. So how do you manage your business if you rely on air insulation? correct. This is another challenge, is n't it? correct. You mentioned that there are many old systems, didn't you? correct. That's true. You have to transfer the data manually. You need to put in place controls that delay processes like debugging and things like that because you don't have that full connection. So, physical security was also a big part of the challenge it faced . I remember "Stuxnet" and I read about its anatomy and how they said, "Oh yes, the airtight seal, we can break through it, no problem, they'll just insert a drive," so you have to worry about those things too. You have to worry about everything, especially with artificial intelligence nowadays. Even if you are not connected to the internet, there may be a system somewhere connected to something you are unaware of , right? Therefore, you should always be careful and vigilant towards everything. So, the energy company established an artificial intelligence team two years ago, is that correct? Okay, so how do you think about building a long- term strategy for a technology that is evolving this quickly? How do you think about that, especially since your team works on a daily basis? It distracts my mind in the first place. Because things are moving very fast . You know, the purpose of the AI ​​team that was created was to build AI within our company, right? How can we utilize artificial intelligence in daily work? But when I think about threats from an AI perspective , I have to find a way to protect what they do and protect against bad actors, right? That threat is related to artificial intelligence. Okay guys, I mean it's a regulated industry . Generally speaking, how dangerous is " hidden AI" in your organization? How worried are you about it? I'm worried about it too. I mean, is this how you deal with it? Well, with CrowdStrike, we search and scan the workplace for hidden AI, right? We try to find out where it is being used and stop it, because you know anyone can take a laptop, download something, and run a program from their personal device. Therefore, you should be aware and constantly scan and research this in the work environment. What is your journey with CrowdStrike? Can you take us through that experience? Yes, we have used CrowdStrike for several years. We have a large amount of platform. We are AID customers, so in fact, with Guardian we will be able to take advantage of it, but the insight into the data, the enriched data we have, and the telemetry are truly amazing. It's the vision, actually, is n't it? As we work on developing our implementation of this, it brings many benefits to the company. Are you a Flex customer? May I ask a question? Yes. Good. And what is your opinion of Flex? It was interesting. We had some data from our partner Qualitate, and as you know, Crowd talks about Flex all the time on Wall Street. Of course, when you talk to customers, they don't necessarily see it as a contractual instrument. They see it as a way to simplify things, help us move faster, and allow us to add new units. We don't need to bring in a new supplier. How do you see it? I think about it the same way, don't I? So I feel that if there is something in my toolkit that I am not using, I want to redeem it and get Flex credit, and then use that credit to deploy something that I would like to use. This gives me the flexibility I need; So, if anything new comes up and I have a " flex" balance, as you said, I don't have to repeat the whole process, right? I can only say: Hey, that's what I want. Let's use " Flex" credits to get it. Are you able to integrate the number of tools you have ? certainly. Oh, really? Good. I mean, a lot of people in your position say, "We're trying. We're having trouble getting there, but you're managing it." We succeed in cases where the cybersecurity team has the tools, right? Therefore, if we already have the tools, it becomes easier to integrate those applications into the " CrowdStrike" platform. The part that becomes more difficult is when the tools are owned by another group outside of cybersecurity , where they prefer their tool and you prefer yours, and questions begin about which one wins in the end, right? With integration, you of course get better data and measurements, but you also give this unified platform, let's say "CrowdStrike" in this case, greater independence. millimeter. This forces you to sleep with one eye open. So how do you think about this? And how do you maintain your sovereignty? I don't mean territorial sovereignty here. I mean your control over your technological infrastructure, your operations, your pricing, i.e., your financial sovereignty, etc. How do you think about that? We had a customer who was very happy with the "Flex" service, but he said: "You should keep an eye on it." It's like a cloud bill; you need to make sure you use it wisely and that you get the most out of it. Therefore, we must certainly rely on the teams to ensure that they are achieving the desired value from the tools we have. If something is not useful, let's replace it and look for something else, right? When it comes to the story of competing tools, it's really about helping people figure out what CrowdStrike offers compared to what they have, and hopefully accompanying them on that journey to say, "Look , this is the best approach , and let's see if we can align to help reduce costs." To what extent do you rely on the cloud? I mean, you clearly know that "Crowd" starts from the cloud, but what percentage of your overall reliance is on the cloud versus... our footprint is small right now because you intentionally rely on local infrastructure. This is correct. The reason I'm asking is that I'm sure you're familiar with the shared responsibility model in the cloud. It is similar to our current situation in light of this new model of joint guarantee or joint liability. Nations, and it is a type of crystallization now. Much of this is completely new. Have you thought about that a lot ? How do you view this matter? For example, who is responsible? Okay, that's right. I don't know how capable the regulator is of determining whether we are still responsible or whether they are. So, this area is still a little gray . You know, you may have that shared responsibility, but ultimately it's up to the organizer to say, "No, you remain ultimately responsible for that even if they say they are involved in this part." So it will be interesting to see how this develops, won't it? Because I think about things like the General Data Protection Regulation (GDPR) when it happened. It took a long time to test it. certainly. So I think it will take some time to mature. We will see some real-life examples. There will likely be cases in the courts, and that will put us on the right track. No, but there is still a question of who is responsible when things go wrong. Well, we are here at the "Falcon" conference. There were lots of new product announcements and demonstrations on stage as well this morning. What do you see as a Falcon Flex customer? What did you find most impactful in terms of what you want to convey to your team? There are definitely two main elements that impressed me. The first is "SafeMind" to carry out operations for the Red Team and the Blue Team. We were already thinking about how to do it ourselves, and it seems that this will simplify things in many ways. The second thing is CrowdStrike's move towards the identity domain, doing more in this area , and being able to block things at the endpoint as a simple process , whereas we were looking at things like the allowed list , which is difficult to implement, whereas this is directly integrated into the sensor. If you say, " I do not want to run this particular executable," or if you have elevated privileges, you will be blocked and prompted for multi-factor authentication (MFA). I believe these two products will go a long way in helping us combat the threats of artificial intelligence in our environment. And to make sure that it continues as well. Not only when logging in, but the question is always: who uses this and how does it work? exactly . So how do you get that? Are you part of the " Quilt Works" project or are you doing so through a partner? " Coilt Works" is a type of union. I'm not sure. Good. So what I saw on stage was basically Team Red, Team Blue, and the system. This loop is endless. I believe it is available through what they call the "Quilt Works" project. So, we don't have that. Yes. correct. So, that's something we're looking forward to. I've spoken with our sales representative. I told him, "Wait, I have a lot of questions." This is correct. I have many questions. How can I get it? Good. And I believe it comes through that union. I call it a union if that is the correct term. But my understanding is that you operate it in a digital twin. That's what I heard. So you are creating a digital twin for your organization, which I found interesting, and it is really cool. So that's an experimental environment, isn't it? I mean, then you turn it on . Good. Once you are satisfied that all the vulnerabilities have been addressed, you then publish. This is correct. And then I do n't know what you do? Are you conducting more tests or what ? That's a good question. I can't wait to get our hands on the product so I can really test it and try it out completely. wow . surprising. It's exciting to see them on stage. As an executive in the cybersecurity and critical infrastructure sector, what are your thoughts when you are here or at other industry conferences talking with your peers? What is an area that you think people are not paying enough attention to at the moment? I mean, I think I'm asking you what's been bothering you at night and... well, artificial intelligence is one of them, is n't it? I mean, if you think about the speed at which artificial intelligence can move within the environment, that's the scariest thing for me. And also , as you know, people are lenient in their behavior. As mentioned before, "security through obscurity" means if you don't know that there's a dollar sign behind your shared hard drive , and that it's hidden, then you don't know it exists. Well, artificial intelligence will find that, wo n't it? He will exploit that. So, as I think about the industry as a whole and think about artificial intelligence... you know, when you look at some people who are taking OT technologies and connecting them to the cloud and so on, we take a step back and wonder, "How can I separate these things, right?" Because "with the speed at which artificial intelligence moves, I want to make sure we are protected ." It may be, as I said, completely airtight and protected. But these are some of the things that really worry me, namely the threat of artificial intelligence. Artificial intelligence, and also humans, as I mentioned . Well, I mean, with humans you have a little more time to detect and respond, because if someone is doing something , you'll get a notification somewhere. This gives the analyst at the security operations center the opportunity to see it, analyze it, and then take action on it, because that person works at human speed, which is not fast compared to artificial intelligence, which works at machine speed, so if an incident occurs, the analyst does not have the time or luxury to actually sit down and assess the matter. You must take immediate action. Are you being dragged into board meetings? No, I am not. My manager is the one who brings it. Good. Good. But it is assumed that you help your manager prepare for it. This is correct. Can you give us an idea of ​​how the nature of board discussions changed before and after "Mythos"? Has it changed? I think she's changed. Because before "Mythos", there was a completely different set of expectations for what you were trying to do . She is still trying to protect the environment. You are still trying to make sure you develop what you have. But when " Mythos" came, he turned the tables completely . And when that happened, you had to look at a lot of areas and move quickly if you wanted to address the issue, didn't you? Reduce the range of impact, increase resilience; you know, you want to reduce exposure to risks. When you think about these things, it completely changes the story. It changes the dynamic of what is expected of you. So, was that the first step? I mean, I'm sure there was a quick internal meeting. And what happened next ? Was the contact with a supplier? Was the contact with a consultant? Oh, yes. No, once it was released the following week, we received the announcement on Thursday. The following week, we were in contact with all our suppliers and partners. Hello, what are you doing to address this issue? exactly . Because we want to know what their situation is, well, we just received a notification too. Therefore, we are still formulating things. Did you see a variety of responses that gave you varying levels of confidence? Yes. Good. So, a lot of the things we were receiving reflected what we were doing . So, yes . I mean, you know, I don't want you to mention names. I conclude that CrowdStrike did a fairly good job in terms of its response. But what kind of things were you monitoring—I don't say measuring—that gave you confidence in some cases? This resource controls the situation, and that group needs to sort itself out. What advice would you give them to gain more confidence in you? That's a good question. Those who were truly in control of the situation clearly put their plan in place. They said, "That's what we're doing right now." This is how we handle these matters. This is what we recommend doing. So, whenever a partner or supplier is involved, if you have this in your environment, this is what we recommend doing to address the issue, right? You may have some who have only provided a general and comprehensive statement . From this perspective, I would say, to those who made that public statement, go back and address your clients individually. So that they know you care about them and that you are trying to address their concerns. I had some customers whose supplier's answer was, " Okay, buy this," right? Which did not necessarily make them happy. They were saying, "Okay, what else do you have?" So, I don't know . Have you experienced that? No, not to my knowledge. Good. Perhaps some of your colleagues. exactly . Michael, we were delighted to have you with us on The Cube. It was a truly wonderful conversation . Yes. I am Rebecca Knight on behalf of Dave Volante. Stay with us for more of The Cube's live coverage of Falcon 2026. You are watching The Cube, the leader in enterprise technology news and analysis .