Vivek Kumar, Alter Domus & Mayank Upadhyay, Snowflake | theCUBE + NYSE Wired: Cyber Security Leaders
Watch on YouTubeVideo summary
The discussion centers on a fundamental paradigm shift in enterprise cybersecurity driven by the rapid rise of autonomous AI agents. Historically, security frameworks were built on the assumption that every action within an organization was initiated by a human being, but this equation is now changing as AI agents gain the ability to operate independently, access multiple systems, and interact with one another. These agents possess their own "brains" capable of long-horizon reasoning and parallel processing, allowing them to explore every corner of an enterprise network in search of goals or vulnerabilities. While this capability offers massive productivity boosts, it introduces a significant risk where a single security flaw could be exploited by an agent to cause catastrophic damage, effectively turning the agents themselves into potential vectors for major breaches rather than just tools used by humans.
To manage this new dynamic landscape, industry leaders emphasize that moving back to on-premise infrastructure is not a viable long-term solution despite current fears about data sovereignty and shadow AI. Instead, the focus must remain on strengthening cloud-based architectures while implementing rigorous governance controls that ensure data stays within organizational boundaries and is not used for model training without consent. The conversation highlights the emergence of "shadow AI," where unauthorized agents and MCP gateways proliferate across networks, creating visibility gaps that traditional security tools cannot easily track. Consequently, companies are adopting strategies like sandboxing, strict identity management for non-human actors, and the use of deception technologies to detect intrusions quickly. The goal is to maintain a secure perimeter not by retreating in isolation, but by ensuring that any interaction with external partners or systems is monitored, audited, and constrained by clear guardrails.
A critical component of this new security posture is the transition from managing human identities to governing non-human identities at machine speed. As the number of AI agents grows faster than human employees, traditional permission models based on job roles are insufficient because agents will attempt every possible action within their granted scope. The proposed solution involves treating agents like interns with highly specific, limited permissions that allow them only to perform the exact task assigned before ceasing operation. This approach prevents privilege escalation and ensures that even if an agent is compromised or behaves unexpectedly, the damage is contained within pre-defined limits. Furthermore, AI is being leveraged to accelerate vulnerability patching, with advanced models now able to suggest fixes that developers accept at high rates, effectively closing security gaps in minutes rather than the months previously required.
Ultimately, the path forward requires a proactive approach where security operations evolve from reactive detection to continuous, real-time observability and remediation. Enterprises must build AI gateways that sit between agents and models to provide full transparency into agent behaviors and data flows, ensuring that no critical information leaks outside organizational boundaries. The industry is moving toward a future where security teams utilize AI to identify vulnerabilities, generate code patches, and automate responses at the same speed that threats emerge. By embracing these technologies and establishing clear standards for identity, governance, and data separation, organizations can harness the power of agentic AI while maintaining robust defenses against the evolving threat landscape, ensuring that trust is built on transparency and predictability rather than outdated assumptions about human-centric security models.
Read the full video transcript
Palo Alto Studio Connection Silicon
Valley and Wall Street. I'm John B here
with Dave Volante, my co-host.
Welcome to the Cube studio here at the
New York Stock Exchange. I'm Jim Allen
with NYC Wired cyber security leaders
where we talk to the people shaping and
securing the future of technology,
business, and markets. For decades,
enterprise cyber security has been built
around one basic assumption and that is
that there is a human on the other end.
But we know AI agents are changing that
equation rapidly. They can operate
autonomously, access multiple systems,
call tools, and increasingly we hear
call each other and they've been given
permissions that historically belong to
humans. With this raises a very
interesting question. Could the next
major enterprise breach come not from a
compromised employee but an agent
itself? Joining me are two security
leaders looking at this from very
different angles of enterprise. May OPDI
snowflake's chief security and trust
officer and Vivic Kumar global chief
information security officer at Alraas.
Welcome folks.
>> Thank you.
>> Thank you. Really exciting to be here.
>> What a great venue.
>> Two fascinating companies. I mean, we're
no stranger to ultradomus here on Wall
Street. And we're also no stranger to
Snowflake, right? You guys have had an
interesting year on the street. There's
a lot of enthusiasm for Snowflake and
for Altored. And the future we know is
changing very, very quickly. So, let's
get straight into it. We're going to
talk about trust security and what's
happening faster than I think many of us
predicted, perhaps even yourselves.
>> [snorts]
>> Let's start just unpacking the world of
2026. We're halfway through and I'm
going to start with you, Vic.
>> Yeah.
>> You have built the backbone of caption
markets, right? But it's essentially
about giving clients and customers
access to real-time data as efficiently
as possible. We know AI is changing
that. Talk me through how that changes
your job from the perspective of
security and trust. Break it down for
me. What's changed in the last two
years? I have I have more job security.
I'm just kidding. [laughter]
Uh it is changing a lot because the
landscape has for last two years 3 years
since the Aentic AI adoption the whole
landscape has changed. Earlier you know
uh whenever the new tools and new
products and new things which used to
come we used to do like a yearly review
or yearly new releases coming up and all
those kind of thing were very delayed
then it moved to you know 6 months then
monthly now weekly now daily. So if you
talk about anything happening in this
world especially in terms of uh security
in terms of technology releases are
happening every single day. So so it has
become very dynamic and to cope up with
that dynamic environment security as a
chief security officer it is it becomes
very very difficult task and challenging
task though I'm loving it to cope up
with that. So that's yeah whole dynamics
paradigm has changed now. So let's talk
about Snowflake. I mean fascinating
company. Everyone I think who's worth
their salt in the industry knows exactly
who Snowflake is and what you guys do.
We know though that the world of data,
the accessibility, the interoperability,
who and how that data is accessed is
changing at a scale that like I said no
one expected. Right. This year a lot of
enthusiasm around Cortex the gateway
that Snowflake is introduced. Certainly
did something interesting to your stock
price. Talk me through it though from
the perspective of the buildout like you
were you one of the kind of front minds
behind this
>> break it down for me like give me the
lowdown. Look, I think what's happened
in the last couple of years, people went
from simple chat bots to agents who can
take actions and um there's two things
which have happened really in the last
six months, I'd say. One, the agents
have got really good at parallelizing
everything they do. And their job
basically is to look under every rock,
look at every nook and cranny. You give
them a goal and they try to get to that
goal. And this means that if they're
operating as you, they're going to have
all the permissions you have. if there's
any security issues in your enterprise,
they're going to find those. That's a
huge problem. The second thing that's
going on is that these models have
gotten really smart. You know, these
agents are different from traditional
software in that they have their own
brain, right? Which is these models. So
with traditional software, you knew
exactly it was going to call this next
piece of software through an API. It was
going to have very very fixed
deterministic behavior. But these
agents, they have a brain of their own.
And these brains are getting smarter and
smarter. And the models have gotten so
good these days at what's called long
horizon reasoning without hallucinating,
right? They're able to go deep and find
issues uh as a result of that. So when
you put all these things together,
you're in this this interesting uh
scenario where on the one hand you've
got this massive productivity boost, but
when something goes wrong, it can go
spectacularly wrong. So it's honestly a
great time to be working in the security
industry and trying to bring all of this
chaos under control. So we started off
on this journey you know we've been in
the agentic journey for a year and a
half now. Um earlier this year we
acquired a company called Ntoma which
does bring some governance to MCP. We're
building on the back of that we've now
got an AI gateway that is coming out in
the market this month. And this AI
gateway gives you everything from
protecting the model protecting the
agents and integrating down to your data
stack. So it's the full shebang. We've
got our own experience for the last year
and a half how we've modernized our
further agentified our enterprise and so
we want to take that even uh further
offer to our customers and we're super
excited about that.
>> We hear a lot about MCP. It's become a
real buzz word. You know we talk about
it every day here on the show.
>> It seems as though again every company
is building towards this if not already
trying to execute on this strategy. We
also know though it's a different kind
of vector from the perspective of
security. How do you think about it like
from the perspective of you know your
footprint your ecosystem and the
interoperability elements like what does
it mean from a governance perspective?
>> Um first of all you know we all are
fighting the same enemy. So so the over
here the partnership is a big key thing
>> you know the MCP adoption is happening
so fast and so rapidly than your
security controls. So problem what is
happening is that there are bunch of MCP
uh gateways people are using which you
are not even aware of and and the pro
and and you it's very hard to keep track
of it and govern it and find it where it
is and it is creating a big issue in any
industry from the security perspective
they should be going in to a one
governed MCP gateway so that security
can watch it and do things so as you
said earlier that if an enterprise level
attack coming in it looks like a
legitimate thing
>> but although it's on track it's no
longer a traditional thing what my was
talking about earlier because now the
MCP gateway you know all the things are
going out looks like agent uh good thing
legit thing one agent is talking to
other agent delegating it to third agent
delegating it to fourth agent and that
delegation is working in such a manner
that it's very difficult to govern and
audit that piece so MCP gateways and all
this although It's the best thing which
has happened but if the governness is
not in place then you are going to lose
uh you know visibility and get into some
kind of a big problem and there were a
lot of things happened with the GitHub
and other things which you saw
>> and they were all because of these
breaches happened because of these
things of delegations and multi multi-
aent uh functionalities and MCB gateways
>> I mean let's stay on NC MCB for a second
but let's talk a little bit about models
because it's a very interesting
evolution, right? We know that in some
respects MCP, it opens the floodgate to
all sorts of different accessibility
vectors, right? Models, you know, we
hear a lot about anthropic. We hear a
lot about open AI. We hear a lot about
the security level of open weight models
versus, you know, the models we're more
familiar with here in the US. What are
your thoughts though from the
perspective of the kind of
non-negotiables from a risk perspective,
especially at a company like Snowflake
where there has to be some clear
parameters around what can and can't
happen, what can and can't engage.
>> Yeah. Look, first and foremost, we um
like both proprietary models as well as
open weight models, right? So we can get
that out of the way. We we we like to
use them both. Um you get a lot of
benefits from the openweight models. uh
as a security uh team, you don't have
constraints when you're doing an
investigation uh when you're doing
threat modeling. Also, from a cost
governance perspective, they're so much
better. The other thing which is a
non-negotiable for us and for many of
our customers is that um they don't want
they want their data to stay within
their parimeter. So, as you work with
these models, you kind of have to make
sure the data doesn't accidentally end
up with the model provider in a way that
that might get used up for training. And
I know you know everybody has lots of
different architectures for this but it
is the crown jewels that our customers
have and so that is a non-negotiable for
us. So uh a lot of the ideas behind what
we're rolling out right now with the AI
gateway are meant to give you that data
separation uh the visibility. You you me
use the word visibility use the word
trust. Trust comes from transparency and
and predictability, right? So with our
AI gateway, we want to give you that
observability so you know exactly what's
going on in the agent and the model and
we're watching it to make sure that
nothing bad is happening for you
>> and you have a complex network from some
perspective, right? Like there is
different folks who use many different
technologies, many different APIs, many
different tools and that's probably only
going to get even more diluted as this
world of AI and inference expands. How
do you think about it from the
perspective of accessing the data and
then securing the data once it's you
know in the hands or in the presence of
whatever actor you hope it hope redeem
it to be.
>> Yeah. So you this is very critical
because data is all very important. You
can't build an AI layer without having a
data security layer in place. So because
the AI sits on top of data. The problem
happening is this MCP gateways and the
models and all it's a new new thing
which is now it's turning into a shadow
AI thing.
>> Even the MCP gateways people are using
models people are using MCP gateways
they are downloading things and
everything and they are creating agents.
Suddenly this is becoming a shadow AI
kind of thing for us. It's a big
problem. Agents when they talk to a
different agent or other agent they have
a capability of escalating their
privileges. So all of these agents are
doing a lot of different things. So you
are like really scared to see that your
data, your critical data, your PI
information, your financial information
doesn't get pasted and it goes out of
your boundaries. So the cross broader
and cross organizational uh boundaries
should not be overlooked and that's a
main concern when this is happening. And
it is very very important that for that
not to happen you should know that what
kind of gateways you are using what kind
of models you are using and all the
agents what actions they are doing there
should be a least privilege actions what
what you mean is what I mean is that if
a agent is supposed to do a task he
should only get a permission and
escalation to only do that and then it
dies down. You cannot have a longl
lasting controls given to them to do the
perform the work. So definitely you have
to build the governance as snowflake was
talking about it.
>> But how do you truly do that? Right?
Like there's obviously governance,
there's compliance, is it sandboxing
first? Like what are you truly doing to
ensure you know that whoever it is or
whatever actor it is is trying to access
data. It's not just about verification.
It's about everything that comes after
that. Also,
>> I'd probably mention four different
things to you. On the one hand, you have
sandboxing, which makes sure you can do
stuff, you know, on your disk, steal
secrets. If you're going out to the
network, we know exactly where you're
going. I would throw MCP governance as
as a parimeter control because you can
see who's talking to what MCP tool. Are
they allowed to talk to that MCP tool?
The next layer I talk about is the
identity layer. When you have an agent
acting on your behalf, you don't want it
to act with all your permissions. If
you've been at a job for 5 years and
changed different roles, you probably
picked up a whole bunch of permissions
along the way, right? You don't want to
give all of them to your agent because
an agent is going to try each and
everything it can. Even look at paths
you didn't think it might, right? So the
first and foremost thing you need to do
with identity and where we're headed now
is we're coming up with new standards.
So when you kick off an agent, you can
say, "Hey, here's a scope set of things
you can do on my behalf." It's a little
bit like say, you know, I like to think
of agents as interns. They're untrained
employees, right? Now, let's say you
were a company, you know, you had an
office manager intern who was supposed
to go buy you a new printer and you send
them off to get a printer and they came
back with this Wi-Fi control
refrigerator, right? So, what do you do
instead? You give them a a gift card for
Best Buy which is set to like, you know,
$200. So, you put those constraints in
place and say, "Here's what you're
allowed to do." So, even if you sort of,
you know, wear off where you're supposed
to be, you're not it's not going to be
catastrophic. It's going to be more or
less within those guardrails I set for
you. [snorts] So those are the kinds of
primitives we're coming up with in the
industry and we have to make them easy
for people to use. So again you can use
AI to say hey you're asking your agent
to go research this topic for you. I
think it's going to go need to look at
all these tables. So let me scope
permissions to read only permissions to
just those tables. So so that's you know
a way of sort of making sure it doesn't
go off and do something on its own. So
that's the second big thing I think
that's coming. And I just want to
quickly mention I think we also have to
come and take care of more of the
observability detection techniques and
we can talk about that if
>> that that's what I was talking about the
agent have least privilege because the
agent the number of non-human identities
which is the AI agents is growing faster
and rapidly than the human identities.
>> You can control human identities based
on their birth rights and whatever
permissions and access privilege access
they have. But in an agentic space for
the AI agent it's very difficult to do
that. So with somebody coming up or
snowflake coming up with this kind of a
um you know security control identity
becomes very key key factor for us
>> and that non-human identity where
there's multiple versions of a human
based on a workflow or a task right that
that's a complex security system and
ecosystem to to oversee and you
mentioned observability I mean that also
changes the game fundamentally from
managing someone at a domain level to
managing somebody or a actor I guess you
can call it and multiple proliferations.
>> Yeah. H
>> how do you think about that? Is that a
you know when we really boil that down
does that come down to like governance
and compliance and very clear standards
of execution or is it something more
complex than that?
>> No it is complex because as I said it's
changing very rapidly very dynamically.
The entire access management system was
based on human identities.
>> It has a paradigm shift now and also
it's growing. Plus you don't even know
what they are doing. So people are
concentrating about the action what the
agent did but you also need to see that
who authorized it who gave them that
permission to do it. So there are a lot
of other complex piece which was missing
uh you know which has to be incorporated
in terms of this AI. Another thing you
talked about the the sandboxing just
want to touch upon it. What I see the
problem is with the agent agentic AI and
the whole AI thing is
>> you are sending a kindergartner to
college directly [laughter] right there.
Yeah. You have to go through elementary
school, middle school, high school and
then to college. So if you take anything
which has just came out of the market
and not sandboxing and not testing in
your lab suddenly implementing them in
your in your production environment, you
don't know what is going to happen,
right? And it creates one creates other
issue, the other issue and all that the
scale goes so big that it will be
difficult to control. You mentioned
something very interesting which is
observability right and the road map of
a company like Snowflake because again
the expectation is also shifting right
there was a time when we were so excited
just to be able to access data to be
able to see the data in some sort of
concrete and succinct way but now the
role 10 years from now is going to about
observing the data who's what who also
is watching that data
>> how do you think about that from a
company perspective like you know what
what does that road map look like who
owns that problem.
>> Yeah. So, um, look, I think a lot of
traditional security vendors are all
moving very fast to try and fill this
gap. Uh, at Snowflake, we just announced
our Cortex AI gateway, which is going to
sit right between any agent from any
company and the models you're using. So,
it just slides right into your
architecture and it gives you that
observability where it can see what
these agents are doing. Um, and it's
there's actually two sides to to the
observability problem. Obviously, you
want to make sure your agents are not
misbehaving, right? So, if they're if
it's a well behaved agent that's going
through this, you can you can look at
its what's called its traces, its
trajectories, and you can see is it is
it doing something it shouldn't be. But
there's a different side of
observability, but what if there's an
agent running in somebody else's
environment that's now breaking through
your parimeter and entering your
enterprise, right? You have to catch
those two. So that goes down to so so
while there's this whole new category of
agent observability to make sure your
agents are well behaved, there's also
the traditional security world of just
building detections into your parimeter,
uh fixing your security vulnerabilities
so agents outside don't find ways to get
inside your parimeter, right? And those
have to be taken super seriously and
there's probably a limited amount of
time for for enterprises right now to go
and patch these. So using uh AI to find
these vulnerabilities, to patch these
vulnerabilities, right? This is the time
to be doing all of that.
>> I want to go back to something you said
at the beginning which is very relevant
to your industry too, right? Because
financial services is very secure and
we're hearing a lot about companies
going back on prem sovereign AI bringing
actually AI to your data as opposed to
bring your data to AI from the
perspective of Snowflake and and I'm
going to put this to both of you. What
does that mean in terms of like what
you're building towards like how nuanced
and different is that from a security
perspective or is there kind of a
unilateral security guideline around
what it means to have data on prem
versus in the cloud and how folks are
going to go about again managing
monitoring and continually observing
what's happening with it.
>> So uh it's it's a great question and
every day we are exploring new things.
First of all, you need to know where
your data is to secure it to manage it,
right? So, as you said, bringing data to
AI or bringing AI to your data. So, that
has become a big challenge. First is we
need to know where your data is lying,
where which data link is sitting. It's
always scattered all over the things.
Agent as you know, they have a very
privilege access to go and talk to other
agents and try to dig in and go
everywhere. And the problem is that if
there is a agent sitting outside who can
come into your environment and can have
access to the data through the agent
which is inside which is a legitimate
agent is a problem. So we have to secure
our parameters. We have to make sure
where our data is and make sure that
that is secure. The governance and the
guardrails is the biggest things which
we have to work on this thing that how
data needs to be treated and who can
treat it and what kind of permission
that person or agent has for that data
and it is it has become very important.
The Sims of the worlds where they used
to do the detection like discovery and
detection and all all was based on very
traditional environment. It was not
based on the AI
agentric environment. So so you have to
go and change. So you have to change
from identity perspective, data security
perspective, SIM source perspective,
governance perspective, policies
perspective, everywhere there is a
change to see that how data can be
accessed, who can access this, who
authorized it, what kind of identity and
governance you have for them.
>> So if I could add to that Gemma, my take
is that going back to onrem is not the
answer. The way the world is headed,
everything is interconnected, right?
Unless you're a three-letter government
agency that is operating, you know, in
complete secret, I think in general, you
would expect people and and companies
want to have more trade, more uh more
commerce between them, right? And people
are talking about agents going and doing
shopping for you. So, uh I think these
are bringing more efficiencies into our
life on a daily basis. So I think they
and even if look the moment you expose
yourself to working with partners and
interacting with systems outside there's
a a threat surface there that you have
to worry about that can be attacked. So
I think you have to go back to the
basics and the basics don't mean going
onrem it means fixing finding and fixing
your vulnerabilities putting detections
in place so that if you're compromised
you can detect that at machine speed and
you can remediate at machine speed.
There's also a super interesting and
simple technology called deception. It's
kind of like, okay, let's say you have a
giant house and you've got lots of doors
and windows and you can't put a burglar
alarm everywhere. Well, guess what? You
can you can get a big safe in the middle
of your house. So, if a burglar gets in,
they get they zoom in on that safe and
the moment they open that safe, the
alarm goes off. So, there's lots of
interesting tricks to deal with this.
And I think the the it's we're headed to
a world where the the basic security
practices about cleanup and
vulnerability patching and management uh
as well as detections and remediations
are have to be carried out at AI speed.
Now,
>> so last question and I love when
somebody takes a position on something.
You know, we hear a lot about the move
back on prem though, right? And maybe
that's built on false assumption or
maybe there's a whole administrative
layer that was never fully fixed in the
era of cloud that is now suddenly coming
home to roost somewhat from the
perspective of security and it feels
like it's an easier solution when in
fact maybe it's not the long-term
solution companies need. Right.
>> That's right.
>> But h how do you and I'm going to put
this to both of you as as you both move
forward. Right. These are both
fascinating companies, industry leaders.
How do you think about the messaging
around what's happening in this
industry, conversations like that one,
and the role of of of companies like
yours to kind of in some way lead folks
forward at a time where there is so much
conflicting information and so much
worry?
>> U so I I would agree with Mang on is not
a solution. You can't move two step
backwards and one step forward right
because of the all the SAS platforms and
everything coming up you know you can't
go back on prim and lot of things yes
there are certain things you can still
go back but again are you going to
increase your footprint which which
which again involves a lot of cost right
so you may be focusing on the wrong
thing if you want to go back to on-prim
it's some people say that it could be
safer than sorry but that's not it is
because the whole world is open to the
SAS platform we are using a lot of these
kind of tools and techniques and
softwares. Now bringing everybody thing
back to on-pre will not be a solution.
It will be very very very expensive
solution though. So what we need to look
at it that whatever things we have like
blank was talking about vulnerabilities
management and all that kind of thing. I
was talking to one of the CEO was saying
it's no longer at zero day it's all
minus one day minus 2 day right. So
fixing the vulnerability
comes next but patching process has to
be very proactive. So in this
environment you have to be very
proactive. You should know where your
thing is. If you have that obsibility,
you have that visibility then
proactively go and uh face it and attack
it and solve it rather than thinking
back what's going to take the world to
onrem solution.
>> Let's say I'm patching and I want you to
finish with this. If we just take meters
as an example, right? We know that there
is huge vulnerabilities detected across
operating systems at large banks, large
enterprises. We also heard that the fix
from a patching perspective could take
anywhere from 6 to 9 months in a you
know minus 2 minus one day scenario
that's an alarming reality. How do you
think about that? Like what are your
thoughts from the perspective of where
we're at right now? the pace of where
we're headed to head on the gap
>> I think the way u software patching has
operated in the past is changing now um
right now not only can AI find
vulnerabilities it can also suggest
fixes and some of the cutting edge
models have a very high acceptance rate
when they suggest a fix the developers
like it like you know people are talking
about upwards of 85% acceptance rate
right so we're getting to a world where
you know traditionally when you found a
vulnerability you would have a long
argument about is it actually reachable?
Does it matter? Do you have other
mitigating controls in place? Right? Um
or or if you had open source packages,
you would think about, hey, should you
how do you get this package to be
upgraded? Is somebody even maintaining
it? But in the new world, you can you
can have software generated fixes. It's
like, you know, three lines of fix. Just
roll it out. Don't even bother debating
it, right? Or if it's a small open
source package of 300 lines or less,
which is the bulk of them, and nobody's
maintaining it, can you just get AI to
rewrite it for you? So there's all these
options which have opened up and I think
security teams have to think differently
in this new world.
>> Wow. Well, we certainly hope that they
will and that the world remains
protected. So folks, fascinating
companies, fascinating time, great
conversation. Thanks for joining us on
the cube and NYC Wired.
>> Thank you very much. Thank you for
having us. It was great. Thank you.
>> I'm Gemma Allen here at the Cube Studio
at the New York Stock Exchange. This is
Cyber Security Leaders, one of our
programs with NYC Wired. We connect
Silicon Valley to Wall Street. Thanks
for watching.