Nick Warner, Neo Security | theCUBE + NYSE Wired: Cyber Security Leaders
Watch on YouTubeVideo summary
Nick Warner, co-founder and CEO of Neo Security, discusses how the rapid rise of agentic software driven by artificial intelligence has fundamentally disrupted traditional cybersecurity paradigms. Historically, threat detection relied on the assumption that software behavior could be predicted to identify anomalies as malicious; however, the emergence of autonomous AI agents renders this approach obsolete because these new entities operate with unpredictable autonomy. Warner emphasizes an optimistic view of AI's potential while acknowledging the dual-edged nature of this shift: just as organizations must leverage AI tools to scale their own research and operations, they simultaneously face a radically evolved threat landscape where swarms of malicious agents can form their own economies. Consequently, security strategies must evolve from reactive anomaly detection to proactive control surfaces that understand and govern this new software universe before it runs amok.
To address these challenges, Neo Security has built an "AI-native" platform designed to operate at the intersection of human intent and machine action, specifically targeting the endpoint where users interact with AI prompts. A core component of their strategy involves utilizing open-weight models that offer significant advantages in cost efficiency, portability, and specialized tuning for specific security contexts. Unlike monolithic cloud solutions that require moving all data to a central brain, Neo's approach allows for small, local models to run directly where the data resides, ensuring protection without compromising privacy or incurring excessive costs. This architecture is particularly vital given the explosion of "skills"—small, downloadable AI tools introduced recently—that can inadvertently introduce malicious capabilities into enterprise environments, requiring immediate and precise understanding rather than broad, generic detection methods.
The operational impact of this technology extends deeply into workforce dynamics and market strategy, effectively leveling the playing field between well-funded enterprises and smaller organizations with limited resources. By deploying agentic research workforces that can learn complex domain expertise in months rather than years, Neo drastically reduces the time required to train human researchers or upskill existing teams, allowing security practitioners to focus on high-level strategy rather than manual data sifting. The company's business model relies heavily on channel partners to deploy these solutions alongside broader IT projects involving agentic software rollouts, reflecting a market shift where IT and security are becoming increasingly interchangeable disciplines. With significant funding from top-tier investors and a focus on hiring across engineering and sales, Neo aims to provide the necessary intelligence and control layers for an enterprise future where nearly all applications will eventually possess agentic capabilities.
Read the full video transcript
Palo Alto Studio Connection Silicon
Valley and Wall Street. I'm John Fost
here with Dave Volante, my co-host.
Hello, I'm John Furry, your host of the
Cube. We are here in the Cub's NYC
studio. Of course, we have our Peloto
studio connecting Silicon Valley to Wall
Street. All the deep tech coverage here
and in Peloto. It's our cyber security
leader series. As we talk to the leaders
who are making it happen, startups, the
new innovations around AI and AI
infrastructure continues to accelerate
and enable more use cases and new
opportunities. Nick Warner, the
co-founder and CEO of Neo Security,
veteran in the space. Nick, thanks for
coming into the cube.
>> Happy to see you. You have a lot of
roots in security at Sentinel One among
other things. Yeah.
>> Um, you're back at it with your with
your fast growing startup. Yeah.
>> Neo.
>> Um, I think of the Matrix. when I reckon
Neo I was like okay we use a lot of
matrix analogies here you know just
automate give me the instructions
congratulations
>> thank you tell about Neo tell about the
uh the focus the origiation story why
Neo now sure um so Neo is focused on
agentic software control and the genesis
of that was in my my 10 years in in EDR
and endpoint uh a lot of threat
detection was built on a on a a
foundational assumption which was
software could be predicted and if If
you can predict uh good behavior, you
can detect anomalistic behavior against
that. And with pretty high aptitude, you
you can determine that that that's
malicious. And what we started to see is
with the introduction of agentic
software and platforms, all of that goes
out the window. And so we felt in
forming Neo that the world really needed
a new platform to better understand and
control this new software world that
we're living in in this AI era. It's
interesting, you know, a lot of stuff in
the news these days is uh you got the
doom and gloomers and you got the
optimist. We I fall on the optimist
side. I think AI is awesome. Just this
week, the anthropic uh junior six week
employee wrote this
>> scathing post like 100 million views.
Who knows if the numbers are real, but
it got a lot of attention. Um you know,
AI is going to kill us all. It's right
Terminator meets you know [laughter]
but but you know there's a lot of fear
but also there's so much opportunity um
there's a lot's changed in your
perspective seeing kind of where you've
come from and where we are now what's
the biggest change because you know
there's certainly examples we saw the
hugging face example laid out at black
hat with open AI you see the agents
constituting their own economies and
armies swarms of agents what's the big
difference right now for the security
posture and for companies for to deal
with agentic Well, I think it cuts both
ways. I mean, one, the threat landscape
has radically changed, but I think
people forget that we ourselves on the
practitioner side and the vendor side
can use those AI tools. And so, take for
example the case of Neo. We do agentic
software research that we could not have
done 5 years ago. We'd have to hire
hundreds or thousands of threat
researchers to do what thousands of
research AI agents are doing for us now.
So, you know, I think that balance of
power will shake out and um what what it
really means is that customers need to
embrace AI, but they also need to take a
fresh look at how to secure that because
so much has changed in it.
>> There's no doubt after Black Hat and
before that RSA and every conference we
go to, security has become almost an
infrastructure pillar.
>> Yeah.
>> Everything's in there. You got
governance, huge factor, identity,
machine and human, tracking,
observability, all that stuff that's
been in there. What's your take on this?
Because has the market shifted? You
mentioned endpoints kind of like been
been there done that. Yeah. Now you have
more threats, huge long tail. We're
seeing in models themselves.
>> Is the approach that you're taking to
build a model, use that model, build a
product around it? What's the What are
you guys doing different? What's the the
main value proposition?
>> Well, a couple things there. I think you
know Jensen's recent announcement around
um putting putting uh putting it out
there with uh openw weight models u for
folks I think that's going to be
revolutionary for those of us in cyber
to use. Um I think so much has changed
in terms of how software is built. So
there was this uh really high barrier of
entry and so there was this idea of a
software factory that would produce
software throw it over the wall. We
would adopt and deploy. Everybody's a
developer now though it's totally
changed. So cyber itself needs to get
very much in in sort of the the dev
cycle. Um because development's
happening everywhere. It's happening on
on laptops. It's happening in servers.
It's happening in the cloud.
>> It's interesting you mentioned Jensen
open ways. I was talking with Arvin
Krishna, CEO of IBM recently um this
week and we were talking about hybrid
computing hybrid cloud basically which
is basically what we live in. You got
hyperscalers, you got neoclouds, onrem
is booming. I mean it's clear that you
have distributed computing paradigm with
hybrid cloud. Okay, good. We got
Kubernetes and all that stuff going on.
>> Great. Now you got the open weight
models. What is the big um
value there? Because a lot of people are
talking about open weights. Is it the
ability to tune data? Is it cost size or
clusters? Because open weights and
hybrid cloud go to really well together.
>> What's your perspective on open weights?
Because we're seeing a lot of people
digging in hard on this. I think there's
there's really three things that we
think about. The first is obviously cost
because you know in cyber security we
don't want to add you know we don't want
to drag down the bottom line. Um we want
to be efficient and provide value and uh
that really helps us provide the best
products uh at a reasonable cost. I
think the the the second is really this
idea about ultimately we're going to see
those things graduate into being more
and more portable. And so this idea of
having small local models that can run
um that's super important with security
because this idea that you can somehow
shim or port all the data uh to some
giant uh cloud brain to take a look at
all of it.
>> People want protection where the data
lives and where it acts. And I think
having a small model will help there.
>> Cost and efficiency.
>> Correct.
>> And effectiveness.
>> Yes. And I think the third thing is, you
know, a lot of cyber detection is highly
specialized. And so this idea that an
openw weight model can be very much
tuned to to be fit for purpose. That's
really important.
>> Yeah. You know, it's funny. We've had an
expression we said on the cube going
over 17 years now in I think Andy Jasse
probably used the quote the most. I
think he might have originated. He said,
"There's no compression algorithm for
experience."
>> Yeah.
>> That's kind of old. You could actually
compress learnings. You mentioned
research. Yeah.
>> Talk about this aspect. We're starting
to see that trend happen in the power
law of these models where I was just
interviewing cognitive out of Silicon
Valley. They're essentially have
consolidated a model around
semiconductor physics.
>> Yeah. And they could design chips in
hours and essentially have all that
expertise, domain expertise compressed
and available for practitioners.
>> Yeah.
>> Security makes total sense. What's your
thoughts on that? Is that something that
you guys are doing? Is that something
you're thinking about? Well, in you know
what one of one of our foundational
technologies something that we call the
neoverse which is we're mapping out the
agentic software universe that's a lot
of work there there are tens of millions
of pieces of software out there both
binary non-binary so even like skills
tools extensions you think about this
huge uh amount of data that we need to
crawl through we went from basically
zero to having a hyperscaled agentic
research workforce in something like six
months
>> give an example of the of the
application just give us a scope of like
the order of magnitude of value that you
you
>> well you know I think um in sort of a
non-traditional software perspective
this notion of skills so skills didn't
exist until December they were literally
first introduced in December and now you
know someone can download a skill
inadvertently they could think that it
it it does something uh you know
productive and benign uh and it can be
malicious and so there's naturally no
security controls in place for that and
so we literally had to be able to train
a model to understand in plain in
English skills, uh, what they represent,
what do they do, are they malicious or
not? And that's the type of thing that
would have taken, you'd maybe have to
hire a very specialized researcher to do
that, train them up, train the team up.
We're able to get 0 to 100 miles an hour
on that in something like two years.
>> And what would be the equivalent time to
get that research person trained,
peaked,
>> effective?
>> Years. Uh and so I think one other
aspect of what you said really resonates
which is you know your mile there are a
lot of really good security tools out
there even traditional tools but the
mileage very much uh really the wide
disparity is between sort of typea
forward-leaning cyber teams at big
companies that can spend a lot and
companies that have small overresourced
and you know underfunded security teams
and I think that AI really helps level
the playing field with that from like a
training assistance perspective. There's
a lot of really interesting companies
out there that are that are also doing
agentic sock uh you know security
operation centers. Um all of that stuff
is is really fascinating to see because
before it was really human power was was
the main holdback on this. It's you go
back uh go back four years from now and
then say go back another 8 to 10 years
almost every RSA or security conference
had skilling and reskilling like talks.
>> Yeah.
>> Um okay you mentioned skilling but let's
go into the operationalizing it because
when you start saying okay we need job
uh training for people staffing and now
agents as an extension of the workforce
yeah
>> are essentially need to be trained. How
does that skilling reskilling change the
operations? Because you have one
skilling of the machines aka the agents.
>> Sure.
>> And the humans driving and turning on
those agents.
>> Well, I think a big part of it also is
um you know with AI native security
tools like Neo,
>> we have a fully agentic platform
ourselves. So we could drop in a rookie
onto our our platform and they can start
to query it in in plain English and it
will do a lot of the heavy lifting. And
and that's true for a lot of new modern
security solutions out there. And so I
think that is a big difference versus
you know I've been in cyber 25 years and
generally it would take people years
from the practitioner side to get up to
speed. I think we're going to really be
able to narrow that gap today.
>> All right. So we just nailed the what's
happening. We know agents are
everywhere. There's a lot of demand.
It's a good fit.
>> What does it mean would be okay stuff's
off the rails. We hear stories about
that. We saw the hugging face example.
You said, you know, benign activity
turns into malicious, you know, attacks.
There's a lot of things going on
operationally. Sure. Where does it go in
your opinion? What's your vision?
Because you have this layer of of I
won't say reigning in the chaos mode
now.
>> Yep.
>> We're kind of cleaning up, getting it
stable for ops. What's next? Well, I
think um we're going to get to a stasis
where we're going to much better
understand and uh empower end users to
define the capabilities of software
before it runs because I think right now
it's sort of uh spray and prey. U and
you know I think increasingly again as
I'd mentioned the balance of power
really works both ways. So
>> there's there's amazing opportunity on
the defender side. There's also going to
be uh vastly increased threats. But I
think what's very underplayed in the
headlines is that security tools
themselves are getting radically better
by the month.
>> Yeah. With AI with the humans
>> tuning it, managing it, driving it.
>> Yes. And and you we're in the early
early innings of it. But it it it is
pretty amazing like the journey even
we've been on at Neo
>> and being fully AI native from day one
seeing how critical it is for us and how
helpful it is for us to to build and
have a product that has a very low
barrier of entry
>> as an entrepreneur share that AI native
experience because I think this is a
very unique time where you're you had an
opportunity with a clean sheet of paper
yeah to start Neo
>> as an AI native security company what
does that mean what what's the velocity
What's it been like?
>> Well, for us it's really top to bottom.
You know, it's um our HR finance
software fully agentic. Our CRM, we went
with a modern fully agentic platform.
For us doing uh compintel market
research, we have AI agents that are
trained and give us briefings every
week. Uh you know, for for our product
in terms of doing security research,
fully agentic um and really helping us
run lean and run fast.
>> How did you do it? What was the what was
the secret sauce? Was it just get native
with the tools?
>> I you know I think it takes discipline
because all of us at Neo many of us are
are are very experienced in the
industry. So we all come with our own
biases of software that we prefer
>> and it's saying no no like let let's do
clean sheet uh and and uh you know
practice what we preach. Um, but we also
felt really strongly from day one that,
you know, as a new company, you just
can't keep up with your competitors
unless unless you're embracing AI in all
aspects of of and and and that's really
not even uh mentioning sort of AI
development, which um really changes the
game for us that the speed that we can
iterate and reiterate um and that's
needed in this AI world. It's
interesting, you know, language is
changes too with fashion and tech
trends. You know, back in the old days,
old days, let's just recent days, the
word stand up, stand up some
infrastructure, uh build some software
is is turning into um words like turn
on.
>> Yeah.
>> You know, so you know, in all the
conversations, the things that rhyme the
most, and I want to get your thoughts on
this, how it applies to you guys is
whether it's graph, databases, or AI,
the word context and intent come up a
lot.
>> Yes.
>> You're seeing user intent.
>> Yep. in the security world for you guys,
what is that intent that you're
targeting behavior you want to impact
the most with?
>> Yeah, you know, for for us that that was
probably the the the most important um
influence on how we architected the
product. So what when we designed and
and built Neo, we wanted to get as close
to the humanto AI interaction as
possible so we could understand intent
and for us that that meant building an
endpoint sensor. So rather than having
sort of a cloud platform which is vastly
easier to build, we thought it would be
really important to to get right next to
that that first activity of human to AI
at the prompt and that way you
understand context and intent.
>> Yeah. And that's where the practitioners
are right now.
>> That's right.
>> You're meeting them where they are. They
want the headless system.
>> Correct.
>> I have a task could be whatever it is.
Yep.
>> Now I have to go spin my chair around
between five different tools.
>> Yeah.
>> All right. All right, let's get into the
uh opportunity you guys have because um
I appreciate the the insights on the
market and and what's next um product
market fit. What's your market? What's
the product? Explain strategy and the
plan. [laughter]
>> Yeah. So, so, so, so our market is vast.
It's really um any enterprise that's
that's running software and that
software is becoming agentic which you
know the the stats are are breathtaking.
You know if you look at
>> Gartner themselves says in 2025 5% of
enterprise apps were agentic by the end
of this year it will be 40% by 2030 100%
of apps uh and software will be agentic
and so that that paradigm shift really
demands a new way of securing software
and so that that's our market small
large companies uh government every
every
>> and that's a huge tan because unlike
other software paradigms the users
themselves will create the agents.
That's right. I mean, you can't stop the
AI demand. I mean, people love AI. It's
like, yeah,
>> it's not like a new tool like virtual
desktop or some of the IT generated
technology. Yeah.
>> It's it's in high demand. Okay. What's
the business model for you guys? Take us
through some of the momentum you have
and what should people know about Neo?
>> Well, so our business model, you know,
we're we're we're channel first. You
know, I've been at cyber security 25
years and um a critical go to market is
is our channel partners both from a
distribution marketplace and local VAR
perspective. Uh and you know for for us
it's getting people to understand that
there is a there's a problem brewing and
I I think that as you mentioned with the
headlines that's that's becoming pretty
obvious to to most folks. Um and but
there there's a way to do it in a in a
very elegant easy to deploy manner and
um and so we're spending a lot of time
with customers doing deployments doing
tests um and and really helping them
understand that there there really needs
to be a new control surface for
software.
>> Yeah. Talk about the channel opportunity
because
>> the customers want services wrapped
around security. It's not a one and
done. How do you align with some of the
channel needs and how are customers
resonating to the channel partners? Yes.
Is there a new playbook? Is there a new
kind of value equation?
>> Yeah. So, we're seeing opportunities
where we're getting deployed alongside
um
>> an agentic software rollout. Um and so,
you know, there there's a a new
engineering tool that's that's highly
agentic and they and they want to be
able to understand, control, have
context around that. And so as part of
that IT project, Neo's getting deployed
as well. So that's a services
opportunity. We're what's really
fascinating about uh this AI revolution
that we're in is it's also changing the
game. Um, and you know, you and I talked
about about this briefly before we
started filming here is um there are a
lot of it's like the intersection of of
IT and and IT security now is almost
fully complete where the two are
interchangeable both from like an
infrastructure development
>> and uh you know and security
perspective. And so, um, we're we're
we're seeing a lot of, uh,
conversations, much more than I've ever
had in my career, with the CIO and the
CTO rather than it just being a, uh, a
security challenge.
>> I mean, agents are horizontal.
>> I mean, they're everywhere. Yes.
>> You have to have a full IT picture. Yes.
>> And the data that they have access to
>> is also challenging. Well, and this and
you know, one thing I would add, John,
is that um you know, we spend a lot of
time um and the headlines are all around
the frontier AI software products, but
it's that HR software that you've known
and trusted for seven, eight years that
that becomes agentic. It's that
accounting software uh that that you
used for 6 years that now is a Gentic
next week. It's like how do you
understand and control that? How do you
even know when it becomes agentic?
That's that's sort of like what we're
seeing right now is just the tip of the
iceberg. It's going to be a fascinating
>> and your promise to customers is hey,
we're going to make that secure. We are.
Yeah. We're gonna we're gonna let you
know what apps have become agentic. What
are they capable of? Yeah. And we can
secure all of that for you.
>> Yeah. It's Andy Gro's favorite
expression we use a lot too. Let chaos
rain and rain in the chaos. That's what
you're good doing.
>> That's right.
>> Yeah. All right. Put a plug in for the
company status of the firm. I know you
got some financial close series A. You
got you're growing. You got needs.
You're hiring. What's your focus? What
are you optimizing for? Put a plug in.
>> So, uh, you know, we're about a year and
a half old. Um we raised 100 million
from top tier investors like A16Z and
Bessmer. Um we are in uh massive
expansion mode now. So if there's folks
out there who want to join an amazing AI
native security company with seasoned
operators who have been there and done
that uh you know we're open for business
and we're we're hiring and expanding
like
>> all departments engineering obviously
right AI
>> engineering go to market channel sales
sales engineering
>> and you guys your vision is to have the
intelligence layer and control layer for
agentic
>> agentic software
>> so specialized models are in your future
open weights I can probably feel that
coming
>> yes
>> it's fast yep
>> thanks for coming on the cube sharing
what you guys are doing.
Congratulations, by the way.
>> Thanks for having me.
>> All right, I'm John F. This is our cyber
security leaders. Cyber security, you
know, big market opportunity category,
but as it gets more infrastructure
oriented, you got to get down to the
lowest levels to track all the agents,
all the data, all the governance, all
the identity, so the agents know what
they're doing, they're getting smarter,
and if they don't go off the rails,
that's a good thing. And of course,
cyber security is going to protect that.
Doing our part here on the cube. Thanks
for watching.