Submind YouTube summaries
Thumbnail for Nick Warner, Neo Security | theCUBE + NYSE Wired: Cyber Security Leaders

Nick Warner, Neo Security | theCUBE + NYSE Wired: Cyber Security Leaders

Watch on YouTube

Video summary

Nick Warner, co-founder and CEO of Neo Security, discusses how the rapid rise of agentic software driven by artificial intelligence has fundamentally disrupted traditional cybersecurity paradigms. Historically, threat detection relied on the assumption that software behavior could be predicted to identify anomalies as malicious; however, the emergence of autonomous AI agents renders this approach obsolete because these new entities operate with unpredictable autonomy. Warner emphasizes an optimistic view of AI's potential while acknowledging the dual-edged nature of this shift: just as organizations must leverage AI tools to scale their own research and operations, they simultaneously face a radically evolved threat landscape where swarms of malicious agents can form their own economies. Consequently, security strategies must evolve from reactive anomaly detection to proactive control surfaces that understand and govern this new software universe before it runs amok. To address these challenges, Neo Security has built an "AI-native" platform designed to operate at the intersection of human intent and machine action, specifically targeting the endpoint where users interact with AI prompts. A core component of their strategy involves utilizing open-weight models that offer significant advantages in cost efficiency, portability, and specialized tuning for specific security contexts. Unlike monolithic cloud solutions that require moving all data to a central brain, Neo's approach allows for small, local models to run directly where the data resides, ensuring protection without compromising privacy or incurring excessive costs. This architecture is particularly vital given the explosion of "skills"—small, downloadable AI tools introduced recently—that can inadvertently introduce malicious capabilities into enterprise environments, requiring immediate and precise understanding rather than broad, generic detection methods. The operational impact of this technology extends deeply into workforce dynamics and market strategy, effectively leveling the playing field between well-funded enterprises and smaller organizations with limited resources. By deploying agentic research workforces that can learn complex domain expertise in months rather than years, Neo drastically reduces the time required to train human researchers or upskill existing teams, allowing security practitioners to focus on high-level strategy rather than manual data sifting. The company's business model relies heavily on channel partners to deploy these solutions alongside broader IT projects involving agentic software rollouts, reflecting a market shift where IT and security are becoming increasingly interchangeable disciplines. With significant funding from top-tier investors and a focus on hiring across engineering and sales, Neo aims to provide the necessary intelligence and control layers for an enterprise future where nearly all applications will eventually possess agentic capabilities.
Read the full video transcript
Palo Alto Studio Connection Silicon Valley and Wall Street. I'm John Fost here with Dave Volante, my co-host. Hello, I'm John Furry, your host of the Cube. We are here in the Cub's NYC studio. Of course, we have our Peloto studio connecting Silicon Valley to Wall Street. All the deep tech coverage here and in Peloto. It's our cyber security leader series. As we talk to the leaders who are making it happen, startups, the new innovations around AI and AI infrastructure continues to accelerate and enable more use cases and new opportunities. Nick Warner, the co-founder and CEO of Neo Security, veteran in the space. Nick, thanks for coming into the cube. >> Happy to see you. You have a lot of roots in security at Sentinel One among other things. Yeah. >> Um, you're back at it with your with your fast growing startup. Yeah. >> Neo. >> Um, I think of the Matrix. when I reckon Neo I was like okay we use a lot of matrix analogies here you know just automate give me the instructions congratulations >> thank you tell about Neo tell about the uh the focus the origiation story why Neo now sure um so Neo is focused on agentic software control and the genesis of that was in my my 10 years in in EDR and endpoint uh a lot of threat detection was built on a on a a foundational assumption which was software could be predicted and if If you can predict uh good behavior, you can detect anomalistic behavior against that. And with pretty high aptitude, you you can determine that that that's malicious. And what we started to see is with the introduction of agentic software and platforms, all of that goes out the window. And so we felt in forming Neo that the world really needed a new platform to better understand and control this new software world that we're living in in this AI era. It's interesting, you know, a lot of stuff in the news these days is uh you got the doom and gloomers and you got the optimist. We I fall on the optimist side. I think AI is awesome. Just this week, the anthropic uh junior six week employee wrote this >> scathing post like 100 million views. Who knows if the numbers are real, but it got a lot of attention. Um you know, AI is going to kill us all. It's right Terminator meets you know [laughter] but but you know there's a lot of fear but also there's so much opportunity um there's a lot's changed in your perspective seeing kind of where you've come from and where we are now what's the biggest change because you know there's certainly examples we saw the hugging face example laid out at black hat with open AI you see the agents constituting their own economies and armies swarms of agents what's the big difference right now for the security posture and for companies for to deal with agentic Well, I think it cuts both ways. I mean, one, the threat landscape has radically changed, but I think people forget that we ourselves on the practitioner side and the vendor side can use those AI tools. And so, take for example the case of Neo. We do agentic software research that we could not have done 5 years ago. We'd have to hire hundreds or thousands of threat researchers to do what thousands of research AI agents are doing for us now. So, you know, I think that balance of power will shake out and um what what it really means is that customers need to embrace AI, but they also need to take a fresh look at how to secure that because so much has changed in it. >> There's no doubt after Black Hat and before that RSA and every conference we go to, security has become almost an infrastructure pillar. >> Yeah. >> Everything's in there. You got governance, huge factor, identity, machine and human, tracking, observability, all that stuff that's been in there. What's your take on this? Because has the market shifted? You mentioned endpoints kind of like been been there done that. Yeah. Now you have more threats, huge long tail. We're seeing in models themselves. >> Is the approach that you're taking to build a model, use that model, build a product around it? What's the What are you guys doing different? What's the the main value proposition? >> Well, a couple things there. I think you know Jensen's recent announcement around um putting putting uh putting it out there with uh openw weight models u for folks I think that's going to be revolutionary for those of us in cyber to use. Um I think so much has changed in terms of how software is built. So there was this uh really high barrier of entry and so there was this idea of a software factory that would produce software throw it over the wall. We would adopt and deploy. Everybody's a developer now though it's totally changed. So cyber itself needs to get very much in in sort of the the dev cycle. Um because development's happening everywhere. It's happening on on laptops. It's happening in servers. It's happening in the cloud. >> It's interesting you mentioned Jensen open ways. I was talking with Arvin Krishna, CEO of IBM recently um this week and we were talking about hybrid computing hybrid cloud basically which is basically what we live in. You got hyperscalers, you got neoclouds, onrem is booming. I mean it's clear that you have distributed computing paradigm with hybrid cloud. Okay, good. We got Kubernetes and all that stuff going on. >> Great. Now you got the open weight models. What is the big um value there? Because a lot of people are talking about open weights. Is it the ability to tune data? Is it cost size or clusters? Because open weights and hybrid cloud go to really well together. >> What's your perspective on open weights? Because we're seeing a lot of people digging in hard on this. I think there's there's really three things that we think about. The first is obviously cost because you know in cyber security we don't want to add you know we don't want to drag down the bottom line. Um we want to be efficient and provide value and uh that really helps us provide the best products uh at a reasonable cost. I think the the the second is really this idea about ultimately we're going to see those things graduate into being more and more portable. And so this idea of having small local models that can run um that's super important with security because this idea that you can somehow shim or port all the data uh to some giant uh cloud brain to take a look at all of it. >> People want protection where the data lives and where it acts. And I think having a small model will help there. >> Cost and efficiency. >> Correct. >> And effectiveness. >> Yes. And I think the third thing is, you know, a lot of cyber detection is highly specialized. And so this idea that an openw weight model can be very much tuned to to be fit for purpose. That's really important. >> Yeah. You know, it's funny. We've had an expression we said on the cube going over 17 years now in I think Andy Jasse probably used the quote the most. I think he might have originated. He said, "There's no compression algorithm for experience." >> Yeah. >> That's kind of old. You could actually compress learnings. You mentioned research. Yeah. >> Talk about this aspect. We're starting to see that trend happen in the power law of these models where I was just interviewing cognitive out of Silicon Valley. They're essentially have consolidated a model around semiconductor physics. >> Yeah. And they could design chips in hours and essentially have all that expertise, domain expertise compressed and available for practitioners. >> Yeah. >> Security makes total sense. What's your thoughts on that? Is that something that you guys are doing? Is that something you're thinking about? Well, in you know what one of one of our foundational technologies something that we call the neoverse which is we're mapping out the agentic software universe that's a lot of work there there are tens of millions of pieces of software out there both binary non-binary so even like skills tools extensions you think about this huge uh amount of data that we need to crawl through we went from basically zero to having a hyperscaled agentic research workforce in something like six months >> give an example of the of the application just give us a scope of like the order of magnitude of value that you you >> well you know I think um in sort of a non-traditional software perspective this notion of skills so skills didn't exist until December they were literally first introduced in December and now you know someone can download a skill inadvertently they could think that it it it does something uh you know productive and benign uh and it can be malicious and so there's naturally no security controls in place for that and so we literally had to be able to train a model to understand in plain in English skills, uh, what they represent, what do they do, are they malicious or not? And that's the type of thing that would have taken, you'd maybe have to hire a very specialized researcher to do that, train them up, train the team up. We're able to get 0 to 100 miles an hour on that in something like two years. >> And what would be the equivalent time to get that research person trained, peaked, >> effective? >> Years. Uh and so I think one other aspect of what you said really resonates which is you know your mile there are a lot of really good security tools out there even traditional tools but the mileage very much uh really the wide disparity is between sort of typea forward-leaning cyber teams at big companies that can spend a lot and companies that have small overresourced and you know underfunded security teams and I think that AI really helps level the playing field with that from like a training assistance perspective. There's a lot of really interesting companies out there that are that are also doing agentic sock uh you know security operation centers. Um all of that stuff is is really fascinating to see because before it was really human power was was the main holdback on this. It's you go back uh go back four years from now and then say go back another 8 to 10 years almost every RSA or security conference had skilling and reskilling like talks. >> Yeah. >> Um okay you mentioned skilling but let's go into the operationalizing it because when you start saying okay we need job uh training for people staffing and now agents as an extension of the workforce yeah >> are essentially need to be trained. How does that skilling reskilling change the operations? Because you have one skilling of the machines aka the agents. >> Sure. >> And the humans driving and turning on those agents. >> Well, I think a big part of it also is um you know with AI native security tools like Neo, >> we have a fully agentic platform ourselves. So we could drop in a rookie onto our our platform and they can start to query it in in plain English and it will do a lot of the heavy lifting. And and that's true for a lot of new modern security solutions out there. And so I think that is a big difference versus you know I've been in cyber 25 years and generally it would take people years from the practitioner side to get up to speed. I think we're going to really be able to narrow that gap today. >> All right. So we just nailed the what's happening. We know agents are everywhere. There's a lot of demand. It's a good fit. >> What does it mean would be okay stuff's off the rails. We hear stories about that. We saw the hugging face example. You said, you know, benign activity turns into malicious, you know, attacks. There's a lot of things going on operationally. Sure. Where does it go in your opinion? What's your vision? Because you have this layer of of I won't say reigning in the chaos mode now. >> Yep. >> We're kind of cleaning up, getting it stable for ops. What's next? Well, I think um we're going to get to a stasis where we're going to much better understand and uh empower end users to define the capabilities of software before it runs because I think right now it's sort of uh spray and prey. U and you know I think increasingly again as I'd mentioned the balance of power really works both ways. So >> there's there's amazing opportunity on the defender side. There's also going to be uh vastly increased threats. But I think what's very underplayed in the headlines is that security tools themselves are getting radically better by the month. >> Yeah. With AI with the humans >> tuning it, managing it, driving it. >> Yes. And and you we're in the early early innings of it. But it it it is pretty amazing like the journey even we've been on at Neo >> and being fully AI native from day one seeing how critical it is for us and how helpful it is for us to to build and have a product that has a very low barrier of entry >> as an entrepreneur share that AI native experience because I think this is a very unique time where you're you had an opportunity with a clean sheet of paper yeah to start Neo >> as an AI native security company what does that mean what what's the velocity What's it been like? >> Well, for us it's really top to bottom. You know, it's um our HR finance software fully agentic. Our CRM, we went with a modern fully agentic platform. For us doing uh compintel market research, we have AI agents that are trained and give us briefings every week. Uh you know, for for our product in terms of doing security research, fully agentic um and really helping us run lean and run fast. >> How did you do it? What was the what was the secret sauce? Was it just get native with the tools? >> I you know I think it takes discipline because all of us at Neo many of us are are are very experienced in the industry. So we all come with our own biases of software that we prefer >> and it's saying no no like let let's do clean sheet uh and and uh you know practice what we preach. Um, but we also felt really strongly from day one that, you know, as a new company, you just can't keep up with your competitors unless unless you're embracing AI in all aspects of of and and and that's really not even uh mentioning sort of AI development, which um really changes the game for us that the speed that we can iterate and reiterate um and that's needed in this AI world. It's interesting, you know, language is changes too with fashion and tech trends. You know, back in the old days, old days, let's just recent days, the word stand up, stand up some infrastructure, uh build some software is is turning into um words like turn on. >> Yeah. >> You know, so you know, in all the conversations, the things that rhyme the most, and I want to get your thoughts on this, how it applies to you guys is whether it's graph, databases, or AI, the word context and intent come up a lot. >> Yes. >> You're seeing user intent. >> Yep. in the security world for you guys, what is that intent that you're targeting behavior you want to impact the most with? >> Yeah, you know, for for us that that was probably the the the most important um influence on how we architected the product. So what when we designed and and built Neo, we wanted to get as close to the humanto AI interaction as possible so we could understand intent and for us that that meant building an endpoint sensor. So rather than having sort of a cloud platform which is vastly easier to build, we thought it would be really important to to get right next to that that first activity of human to AI at the prompt and that way you understand context and intent. >> Yeah. And that's where the practitioners are right now. >> That's right. >> You're meeting them where they are. They want the headless system. >> Correct. >> I have a task could be whatever it is. Yep. >> Now I have to go spin my chair around between five different tools. >> Yeah. >> All right. All right, let's get into the uh opportunity you guys have because um I appreciate the the insights on the market and and what's next um product market fit. What's your market? What's the product? Explain strategy and the plan. [laughter] >> Yeah. So, so, so, so our market is vast. It's really um any enterprise that's that's running software and that software is becoming agentic which you know the the stats are are breathtaking. You know if you look at >> Gartner themselves says in 2025 5% of enterprise apps were agentic by the end of this year it will be 40% by 2030 100% of apps uh and software will be agentic and so that that paradigm shift really demands a new way of securing software and so that that's our market small large companies uh government every every >> and that's a huge tan because unlike other software paradigms the users themselves will create the agents. That's right. I mean, you can't stop the AI demand. I mean, people love AI. It's like, yeah, >> it's not like a new tool like virtual desktop or some of the IT generated technology. Yeah. >> It's it's in high demand. Okay. What's the business model for you guys? Take us through some of the momentum you have and what should people know about Neo? >> Well, so our business model, you know, we're we're we're channel first. You know, I've been at cyber security 25 years and um a critical go to market is is our channel partners both from a distribution marketplace and local VAR perspective. Uh and you know for for us it's getting people to understand that there is a there's a problem brewing and I I think that as you mentioned with the headlines that's that's becoming pretty obvious to to most folks. Um and but there there's a way to do it in a in a very elegant easy to deploy manner and um and so we're spending a lot of time with customers doing deployments doing tests um and and really helping them understand that there there really needs to be a new control surface for software. >> Yeah. Talk about the channel opportunity because >> the customers want services wrapped around security. It's not a one and done. How do you align with some of the channel needs and how are customers resonating to the channel partners? Yes. Is there a new playbook? Is there a new kind of value equation? >> Yeah. So, we're seeing opportunities where we're getting deployed alongside um >> an agentic software rollout. Um and so, you know, there there's a a new engineering tool that's that's highly agentic and they and they want to be able to understand, control, have context around that. And so as part of that IT project, Neo's getting deployed as well. So that's a services opportunity. We're what's really fascinating about uh this AI revolution that we're in is it's also changing the game. Um, and you know, you and I talked about about this briefly before we started filming here is um there are a lot of it's like the intersection of of IT and and IT security now is almost fully complete where the two are interchangeable both from like an infrastructure development >> and uh you know and security perspective. And so, um, we're we're we're seeing a lot of, uh, conversations, much more than I've ever had in my career, with the CIO and the CTO rather than it just being a, uh, a security challenge. >> I mean, agents are horizontal. >> I mean, they're everywhere. Yes. >> You have to have a full IT picture. Yes. >> And the data that they have access to >> is also challenging. Well, and this and you know, one thing I would add, John, is that um you know, we spend a lot of time um and the headlines are all around the frontier AI software products, but it's that HR software that you've known and trusted for seven, eight years that that becomes agentic. It's that accounting software uh that that you used for 6 years that now is a Gentic next week. It's like how do you understand and control that? How do you even know when it becomes agentic? That's that's sort of like what we're seeing right now is just the tip of the iceberg. It's going to be a fascinating >> and your promise to customers is hey, we're going to make that secure. We are. Yeah. We're gonna we're gonna let you know what apps have become agentic. What are they capable of? Yeah. And we can secure all of that for you. >> Yeah. It's Andy Gro's favorite expression we use a lot too. Let chaos rain and rain in the chaos. That's what you're good doing. >> That's right. >> Yeah. All right. Put a plug in for the company status of the firm. I know you got some financial close series A. You got you're growing. You got needs. You're hiring. What's your focus? What are you optimizing for? Put a plug in. >> So, uh, you know, we're about a year and a half old. Um we raised 100 million from top tier investors like A16Z and Bessmer. Um we are in uh massive expansion mode now. So if there's folks out there who want to join an amazing AI native security company with seasoned operators who have been there and done that uh you know we're open for business and we're we're hiring and expanding like >> all departments engineering obviously right AI >> engineering go to market channel sales sales engineering >> and you guys your vision is to have the intelligence layer and control layer for agentic >> agentic software >> so specialized models are in your future open weights I can probably feel that coming >> yes >> it's fast yep >> thanks for coming on the cube sharing what you guys are doing. Congratulations, by the way. >> Thanks for having me. >> All right, I'm John F. This is our cyber security leaders. Cyber security, you know, big market opportunity category, but as it gets more infrastructure oriented, you got to get down to the lowest levels to track all the agents, all the data, all the governance, all the identity, so the agents know what they're doing, they're getting smarter, and if they don't go off the rails, that's a good thing. And of course, cyber security is going to protect that. Doing our part here on the cube. Thanks for watching.