网络安全领域30年来最大的转变
在安全行业工作30年后,AI正在颠覆网络安全格局,Kevin Mandia因此重返创业一线。 他说,Armadin的创始团队和打造每家公司都需要的产品这一机会让他无法置身事外:“我不想错过AI带来的变化”,因为“我过去做的一切都已经过时”。
AI正把网络攻击从受资源约束的“狙击式打击”,变成更快、更广的“无人机蜂群”。 Armadin已经协调过25,000个智能体;Mandia称,AI在微秒内完成的事可能需要70名人类,甚至人类根本做不到。开放模型“已经足够好”,一旦攻击者能够匿名获取GPU,犯罪组织的采用速度可能会加快。
Armadin的目标,是用持续、经漏洞利用验证的压力测试客户网络,取代周期性渗透测试。 其“hyperattack”会把资产映射为一份元数据副本,像心跳一样轮询这份网络画像,并在网络或威胁环境发生变化时发起攻击。自2026年1月以来,它已在财富500强客户环境中发现超过90个零日漏洞,通常能在48小时内报告DMZ中的远程代码执行。
产品逻辑不止于发现漏洞,还要在攻击者到来前自主遏制漏洞。 Armadin Blue将把攻击型产品发现的问题转化为EDR和防火墙上的补偿性控制,理想状态下把5分钟的情报优势转化为即时防护。Mandia的取舍非常直白:“我宁愿要一个能阻止攻击者的失败补丁”,也不愿让未知入侵者获得任意网络访问权限。
按人类节奏运行的检测与响应无法应对智能体攻击速度,但分层防御仍不可或缺。 Mandia预计,随着预防、检测和响应不断压缩为一个瞬时周期,AI将驱动这3个阶段;人类会监督例外,而不再停留在战术层面的“回路中”。短期内,AI更偏向进攻,但用攻击型AI训练的防御型AI最终应能比人类逐包检查更全面。
在网络安全领域,开放模型与闭源模型的性能差距可能比其他AI工作负载收敛得更快。 在20条真实世界攻击链中,没有任何测试模型完成超过8条;最先进的闭源模型更快找到可利用漏洞,但开放模型只要允许运行更久,也能到达同一终点。讨论的关键因此转向攻击 expertise、评测、成本、编排和遏制能力,而不只是能否获得模型。
George将安全格局的转变称为“海啸”,Mandia则表示,这要求公司在不放弃企业级执行力的同时,按创业公司级速度推进。 Armadin拥有“80英里/小时的顺风”,但仍需为销售、品牌、国际扩张以及第二幕、第三幕融资;它希望跑赢Wiz所引用的、18个月达到1亿美元以上ARR的路径。技术优势可能6个月就被复制,但运营护城河仍是:“找到一个客户,让他们满意,再重复。”
1. AI把一名并不情愿的创始人重新拉回牌桌
Mandia说,重返创业一线并非出于毕生的创业冲动:当时他已50多岁,也已经在做风险投资,原本没想过再次创业。但与David Slater、Travis Lam、Evan Peña及更广泛的创始团队见面后,他产生了完全相反的反应:“我想参与其中。”
真正的催化剂,是AI可能让他30年安全经验中的很大一部分失效。他得出的结论不是怀旧,而是紧迫感:团队拥有技术人才,而他能贡献关系网络、模式识别能力,以及进入那些已经需要这款产品的企业的通道。
Armadin Red利用先进模型和攻击型AI,验证哪些风险确实可以被利用。计划中的对应产品Armadin Blue,则会把这些发现转化为防御;两者合起来的目标,是打造一个“力场”(force field),让优秀的攻击型AI持续训练优秀的防御型AI。
2. 狙击式打击时代正在变成蜂群作战
当前已观测到的AI攻击仍不如Armadin内部系统成熟。Mandia描述,智能体会从A点移动到B点,然后又莫名其妙地回头攻击A点:协同程度已经像无人机蜂群,但相比训练有素的人类操作者,仍然“更粗糙一点、更喧闹一点”。
在模型变得更有创造力之前,规模就已经足以改变竞争态势。网络作战涉及代码和结构化流程,因此Armadin不需要一个能熟练使用400种语言的模型;现有模型已经能以远高于受资源约束的人类团队的速度,探索多得多的路径。
传统的国家级行动通常像狙击:针对约30家国防承包商或军事目标展开一场范围狭窄的行动。AI带来的是隐蔽性与全面性之间的战术选择——什么时候保留狙击,什么时候在蜂群上“烧掉token”,以及需要多少人类判断才能让蜂群保持隐蔽。
战略后果是攻击能力的民主化:技术水平较低的攻击者可能取得实质性更好的结果,而防守方则更难判断攻击来源。模型驱动的攻击可能暴露自动化痕迹,却无法说明“这是一个国家”,还是只有一个人在幕后操作。
3. 持续利用漏洞可能取代传统渗透测试
Mandia借体育作比:2000年的Baltimore Ravens拥有顶级防守,但仍需要一支能够真正考验自己的进攻陪练队。“没有一套防守,除非有一支伟大的进攻组来与之对抗”,而这种压力必须持续施加,不能只在固定周期出现。
Armadin的“hyperattack”会让智能体蜂群遍历每项服务、每条路由、每个系统和资产,生成数TB元数据,并还原一份从攻击者视角观察的网络副本。随后,它会“几乎像心跳一样”轮询这份副本,以较低成本识别变化,再将攻击集中到新增部分。
触发条件包括应用、路由、服务或机器发生变化,出现新的威胁情报或模型,以及在董事会会议等活动前进行有意的自我审计。目标是判断漏洞是否真的可利用,而不只是罗列CVE,因为很多缺陷并不能提供稳定访问权限或远程命令执行。
Mandia将Tenable、Rapid7和Qualys等扫描器归为基础卫生工具。Armadin则从外部以黑盒方式发起攻击,不查看源代码,验证远程执行或数据提取,并让客户真正进入事件响应状态,而不是面对“一大串其实无关紧要的漏洞”。
4. 自主防御成为必需的第二幕
Armadin Blue拒绝“你有漏洞,回头见”的做法。如果Red比对手提前5分钟发现攻击,Blue就应立即通知终端EDR、防火墙,以及CrowdStrike、Palo Alto Networks和Fortinet等平台,创建补偿性控制。
Mandia把第一代产品比作战场急救:先包扎伤口、止住出血,再让人设计永久修复方案。控制措施起初可能很粗糙,但无论你愿不愿意,自主防护最终都会通过安全平台到来。
SOC的预防、检测和响应窗口会持续收窄,直到整个流程实际上变成瞬时完成。攻击者一旦进入网络,可以“同时做1,000件事”;把人留在这个战术循环里太慢,就像眼看着气球爆裂,而整套防御系统早已失效。
George提出的反驳仍然成立:分层的“洋葱式”防护依然重要。Mandia也承认,力场最终一定会漏掉某些东西,因此还需要能够识别非法访问并立即锁定系统的陷阱;但这些后备阶段同样必须自主运行。
5. 安全的网络智能体需要懂得攻击如何失败的专家
被问及Hugging Face事件时,Mandia给出的更广泛判断是:每一种新的技术形态出现,防守方都会低估对手——这一次,被低估的是模型本身。AI研究人员可能缺乏安全直觉,而安全专家又可能不够了解AI,无法“把这东西关进笼子”。
Armadin预设每一道控制都可能失效:主机级隔离、虚拟机监控器、代理、对每个请求的被动检查,以及确定性禁令彼此叠加。有意思的是,智能体最常被停下,并不是因为行为危险,而是因为它们在“追风”,白白浪费资金。
约束不能变成绝对封锁。Mandia说:“别把它关得太死。”用人类赞成和反对判断训练的分类器应监控输入与输出;真正模棱两可的行动则应暂停并升级给人处理,让系统保留有用的创造力。
Armadin对20条攻击链的评测暴露了模型的边界:没有任何开放模型或最先进的闭源模型完成超过8条攻击链。闭源模型找到可利用漏洞的速度更快,但开放模型运行时间更长后也能追上;Mandia说,90多个零日漏洞大多由人类发现,AI则负责约90%的常规工作,不过最近发现的几个漏洞是技术找到的。
6. 公司建设的护城河,是由客户约束的速度
Mandia将Armadin定义为第三波情报浪潮。杀毒软件是一条“马奇诺防线”;Mandiant是在不可避免的入侵发生后从受害者身上学习;Armadin的前提则是,公司应在等待国防承包商或另一名受害者遭到攻陷之前,先发现自身可被利用的弱点。
与2004年那个自筹资金且已经盈利的Mandiant不同,Armadin需要资本来利用自己的“80英里/小时顺风”、建立分销体系,并为后续第二幕和第三幕做准备。Mandia认为,4项要求已经改变:融资能力、推进速度、品牌价值和市场进入体系。
企业销售仍然依赖人,尤其是在技术快速变化的情况下。因此,销售团队需要每周接受技术培训,管理者需要能够放大组织流程,客户反馈也要直接传给工程师;CEO的工作是“把混乱彻底挡在员工视线之外”。
竞争如今不可避免,Mandia说,公司今天做出的东西,6个月后就可能被复制。他真正持久的公式刻意不具光环:赢下要求苛刻的银行、零售商、航空公司及其他能提供信誉背书的客户,然后“找到一个客户,让他们满意,再重复”。George补充说,网络安全领域的每一套技术栈都可能在2年内改变。
完整逐字稿
You won't have a defense if you don't have a strong offense to play against. You want to be like the 2000 Baltimore Ravens defense. You need your training attack to push you. This is exactly what Armadin will do. We'll be the star team on offense, attacking you so you can train your defense on our actions.
1. Why Kevin came back to the field
Kevin, thanks for coming.
No, thank you.
You created Mandiant. It's a great success. Why did you decide to return to the game?
That's a good question, and I'm not sure it was my decision. This is going to sound weird, but I met with David Slater, Travis Lam, the other founders, and Evan Peña. I knew—I could say that they started this company; they are the founders. I met with them, they had an idea, and they presented me with a plan for what they wanted to do. I saw talent in them.
For example, Travis is a talent of a generation, and David Slater—and I say this in a positive sense—is a true phenomenon. These guys are really, really good. Evan Peña is exceptional at what he does. When you meet this team and talk to them, the whole time I was listening to what they were doing, I was thinking, “I want to be a part of this.”
2. Building a company at AI speed
I don't want to miss out on the changes brought about by AI. I was in security for 30 years, and now everything is about to change dramatically. That's great. Everything I did before is outdated, and everything else is new.
After meeting this team when they were starting the company, I realized that I would be a great fit to work with them to accelerate this process. What Armadin is building is something every company needs right now, and I thought, “This team can do it, and I have 30 years of experience in security. I know a lot of people, so let's go to them and say we've built what they need.”
I almost felt like I had to do it. I know it sounds strange, but I wouldn't start a company again in my 50s. I was in the venture business. It wasn't like I was an entrepreneur who loved starting companies. This isn't about that, and I'm not a venture capitalist. I'm just a businessman.
That's not true.
I met the team and said, “We have to do this.”
Yes. Really, that's all.
Yes.
All these changes were happening through AI. That's the catalyst, isn't it?
Yes.
So tell us what Armadin does.
Armadin uses advanced models and offensive AI to check whether you have exploitable risks. That's what we're doing today. We call it Armadin Red, but when we started the company, Travis, David Slater, and Evan knew that the future of cybersecurity was for the good guys to build an offensive cyber cannon and fire it at networks to make sure they could withstand attacks, because those attacks were inevitable.
We also knew that it would be an offensive AI created by the good guys, working and learning alongside defensive AI created by the same good guys. You should have both.
Our first act was to become the best in the world at finding vulnerabilities and risks. If we're 5 minutes ahead of the attacker—whether it's a nation-state or a criminal—we've also realized our second act: Armadin Blue. We must stop this. Compensating controls, like a tourniquet—that's what Armadin does. We're building the force field you'll need in the AI era to protect yourself from AI attacks.
3. What AI attacks look like today
Yes. Tell us about the nature of AI attack capabilities today and how you see them developing in the future.
The nature of these attacks is that we're in a strange period: we see them, but not at the level one would expect. I haven't seen anything like what Armadin has already created in real life: 25,000 agents acting in unison and doing very smart things without resorting to weird phishing attempts. When you respond to an AI attack, you very quickly realize that it's AI.
At least, I understand because I've been thinking a lot about offensive action. I've responded to many attacks in the past that were led by humans. A person goes to point A, then to point B, then to point C during an invasion. AI does little things differently. There are 4 or 5 differences, but one of them is that it will break point A, then move to point B, and then try to break point A again.
It's like a swarm of drones. I get the idea, but it could be coordinated and thought out a little better.
That's the level it's at today. It will be better and cleaner in the future. The differences lie primarily in the fact that the scale of what AI can do far exceeds the capabilities of humans, in ways that people don't even fully understand.
So there is a scaling problem: people could only ever find 1 way into the network.
Yes. They had to be selective because they were forced to direct limited resources along 1 direct path.
Of course. Yes.
Scale is a challenge. The speed is simply incredible. What AI does in a microsecond would take 70 people so long that they wouldn't even be able to do it. This is a comparison of the incomparable.
What has always been missing is whether AI is creative or efficient?
When it comes to what we do, we don't need the most perfect model. We're not trying to know 400 languages with our models and all that. What Armadin does offensively is look for vulnerabilities and risks that can be exploited. This is code. It's a structured language and a structured process. Because it's structured, AI will be great at handling it.
Of course. Yes.
I really believe that this is already happening today. There's all this talk about slowing down the development of models. We don't want cyber risk to become an afterthought. Open models are already good enough, and these things are now common. It's only a matter of time. Once anonymous access to GPUs becomes available, you'll see a lot more criminal attacks.
Oh, interesting. Yes.
Do you understand what I mean? Until you can attack anonymously, it's hard to commit a crime when people know your name. It's better if you can commit a crime anonymously. Here's my advice to criminals: if you can commit a crime anonymously, it's much smarter than doing it while wearing a T-shirt with your name on it.
In short, in terms of the difference in attacks and what we're seeing now, we're in the first inning of AI attacks. I think it's simply because the cost and availability of models aren't yet as favorable for criminals as they will be in the future.
4. Nation state vs AI drone swarms
Yes. That's right. Okay. With your 30 years of experience in the security industry, you've probably seen a lot of attacks from nation-states, right?
Daily. Daily.
Tell me about the differences or similarities between nation-state attacks—I use this to refer to the most sophisticated, most successful types of attacks—and AI today, and where you think AI will be in a few years.
Things are going to change quickly. I can tell you that nations on the offensive never, in my opinion, really attack randomly when they hack for espionage and security reasons. They attack with what I would call a sniper shot. You don't shoot at random, hoping to hit.
For the most part, modern nations on the offensive limit their targets and dig deep into very specific things, like 30 defense contractors or military targets, and they push hard for that. Think of it like a sniper shot. With AI, I think it becomes more like a swarm of drones.
It becomes a little different in cyberspace, and I think even modern nations are thinking, “What would our protocol be if we wanted to attack this company? Should we throw a swarm at it and just burn the tokens?” AI will do a lot of things that humans simply wouldn't do. It's a little sloppier and a little louder, but it's more effective and more comprehensive.
That's the problem. It's probably more effective because the nation will now have to think about so many things, and its whole doctrine will change with the advent of AI. How does AI change our mission? Could we perhaps use cyberspace differently? Do we sometimes use a swarm of drones and sometimes act as snipers? How do we find a balance between these approaches?
Does it depend on the risk, the goal, and how inconspicuous we want to be? AI is not an invisible tool for offensive operations.
Yes, unless you did a bunch of extra training.
Maybe we need someone to monitor whether these actions are reasonable. If you just say, “Here's a prompt for hacking, for example, abc.com,” AI will not do this in a subtle and intelligent way. I think even if you ask it to, it won't be able to unless it's properly trained and given human oversight.
Overall, we'll see less capable, less technically savvy, and less successful attackers appear significantly more successful.
It's a means of equalizing the odds, right? Because over time, when you start using models, the defenders will say, “We are being attacked by these models,” but we won't know who is behind these attacks. Is this the state? Is this a person? Who is this? We will have some assumptions, but it will become more difficult to establish the author.
So, the long answer is that in the age of AI, it democratizes access to significantly higher expertise for attacks on victim networks.
Yes, this is a great transition to Armadin. You said that defense should be a great offense, right? It's best to practice defense on something.
Yes, of course you need to train your defense on something, and it should be an ongoing process.
Right. Right. So how does the product work, and how do you achieve this level of sophistication to detect and remediate vulnerabilities that you say are more complex than a basic query?
Okay. There is a lot here. I could talk about this for 45 minutes, but first I'll say this: You have no defense unless you have a great offense to stand up to. Do you understand what I mean? Even in sports terms, if you want to be like the 2000 Baltimore Ravens defense, you want your offensive practice squad to really test you. You want to know how good you are.
And that's exactly what Armadin will do. We will be that star team on offense that will attack you so you can train your defense on what we do. That will be important.
You can't really keep a human in the loop in the AI era for tactical autonomous defense. That means you have to act quickly. You need to put a tourniquet on the wounds as soon as possible. So, going back to our point, you want to do this continuously, and that's where the difficulty lies.
We do a thing we call hyperattack. And David, that's just a fancy word for us sending a swarm of agent drones at you and mapping your network: every service, every route, every system, and all assets. We can obtain terabytes of metadata about your network after this super-fast hyperattack. It just lights you up.
So now we have almost a metadata duplicate of what we can see. If we are inside, we do the same. Let's just map everything out. This is a view of your network through the eyes of an attacker.
But with this metadata, we are now polling you almost like a heartbeat. What has changed? It's a constant search: Has the app changed? Has the route changed? Has the service been updated? Has a new asset appeared in the target area? So we can cheaply test changes and then attack those changes.
What you really want in the future, in the age of AI, is a constant pressure of models attacking you, but you can't do that all the time because, first, it's too expensive, and second, it's unnecessary. You do this when either the threat changes—new models emerge, new intelligence emerges—or, secondly, your network changes and you want to see what happens.
And then, thirdly, you probably just want to pressure-test. We have a board of directors meeting tomorrow. Let's see how we do. Do you understand what I mean? Let's do a self-audit and see what stage we are at.
And that's why, when a zero-day vulnerability in a popular product surfaced over the weekend, we instantly got that “heartbeat.” We just discovered a problem.
Yes.
Our goal at Armadin is to move from known vulnerabilities, or CVEs, to being able to determine whether they're exploitable before attackers do, right? Not all bugs provide stable access to your system. Not all mistakes are the same, right? We want to make sure: This one is worth worrying about, but these ones don't allow remote code execution.
So, in short, this hyperattack and the metadata that we get allow us to track changes and attack you when your network changes. That's the best thing we can do for continuity, and we'll get better at it.
The cost of network polling will decrease. In small networks, it doesn't cost much. But in a large, constantly changing network, you will have to poll it frequently to avoid leaving windows for vulnerabilities.
Yes, of course. So that's actually a very good explanation of why this continuous approach is important. This is so exciting.
Somewhere out there, criminal elements will always be conducting random scans, and they probably don't even use artificial intelligence to do it. They have one exploit that they think works, and they just scan the world for it and then attack the vulnerabilities. Your network is already under pressure from an unseen force with bad intentions. Do you understand what I mean?
5. Why pen testing is dead
So you should have a better force, made up of good guys, that will constantly put pressure on you.
Yes, that's interesting.
So, Armadin, I don't know—a year ago, it would probably have been categorized as penetration testing. You and I have a history and relationship with George from CrowdStrike. They famously reimagined the category from antivirus to EDR, and of course they did incredible things, but the reimagining of the category was due to significant infrastructure and product changes. That allowed them to create a product category that was much larger than antivirus.
Let's talk about penetration testing. What is the historical view of penetration testing, and why is it not something we can expect in the future?
Yes, there are several points. It had to be done. It was similar to first-generation antivirus: You should buy antivirus.
I think when you look at Armadin, we're going to become as ubiquitous as antivirus, because you need to have a force field of AI on offense that trains AI on defense. You should do it, and you can do it. So why not?
When you look at it, to me, penetration testing is always just scanning what is already known, and it doesn't prove whether you are actually vulnerable or not. So it always created a huge list of vulnerabilities that didn't matter, right?
At Armadin, we wanted to make it so that we could actually execute the exploit. We check the results to ensure there are no false positives. We can get remote code execution or extract data from a machine, whereas many penetration tests just beat up your infrastructure, lacking the thinking and learning technology that remembers and knows your system the way an AI agent does.
The old versions of testing, like Tenable, Rapid7, and Qualys, were more of a hygiene issue: What do I have there? What services are open? Are there any available CVEs for these services or known exploits against them?
When you have an AI-based attack, it will find logic flaws, not bugs in the code of custom applications. It will exhaust all avenues every time.
All I can say is that Armadin has found over 90 zero-day vulnerabilities on customer sites in a real production environment since January of this year, in 2026. Your customer base is glad we found them early, and they're Fortune-level companies. These are not small offices. These are Fortune 500 companies.
I'm not saying this to sow fear, uncertainty, or doubt, but the difference is that we trained our models and retrained all of our models with the participation of real red teamers—people who actually know how to develop exploits. This is important.
When we scan networks, we don't have the source code to inspect. We don't find these zero-days through source code. We don't find these zero-days simply because we can log into an application, gain access, and get to another one.
We act as a black box from the Internet, having found over 90 zero-days in large software companies, and they are grateful to us. Everyone says, “Wow, there's this myth that you can scan code and find thousands of vulnerabilities.” It's just noise.
We come from outside and then call the CISO, usually within 48 hours: “Hey, we got remote code execution in your DMZ.” Usually from there, we penetrate inside, and they agree with us.
The nice thing is that we go through the remediation side. It's a little more complicated and takes a little longer, but these companies go into incident-response mode right away. They react as if it were a real incident.
This is no longer a penetration test. It's like a real opponent attacking you. The difference between red teaming and penetration testing is that penetration testing, for me, is a hygienic minimum.
I think over time, everyone would test everything all the time if they could, right? It was too expensive and required a lot of people, but with AI and an agent doing the work—or, in our case, a lot of different agents doing different tasks—you can do it now.
So I think over time this will replace penetration testing.
6. Autonomous defense explained
Yes. This is just a small part of what the red team would do when attacking you. You mentioned earlier that this is obviously Armadin Red. You mentioned Armadin Blue. Tell us about Armadin Blue.
Armadin Blue is when we can't just come in, David, and say, “Hey, you're vulnerable. See you later.” The real benchmark for every CISO should be effective autonomous response. We have to create it.
We always knew that you can't just say, “We want to be the best in the world at identifying exploitable risks.” This is goal number 1. But goal number 2 is to be the best at doing something about it. And that means Armadin Blue.
Armadin Blue is about taking information about exploitable risks and working with the defense plane. Whether it's endpoint EDR or firewalls, we build compensating controls at speed.
So if we find an attack 5 minutes before anyone else using the model, you're already protected. These protections may be rudimentary at first over the next few months. They will be there in a year.
The entire cyberspace is developing at such a speed that you will have to defend yourself autonomously, whether you want to or not.
I would rather have a failed patch that stops an attacker from breaking in than have an intrusion. You have to choose the lesser of 2 evils, and one of them is much easier to control. You never want to have an unknown person with arbitrary access on your network.
So you want to prevent this in any way possible. I would say the first generation—we're working on this with CrowdStrike, and they know it needs to exist. We are working on this with Palo Alto Networks, and they know it must exist. They all want to move into the AI era with autonomous defense as well.
And we need to inform these security platforms—Fortinet and everyone else—“Here's what you can do about it.” I compare it to providing first aid on the battlefield. Someone was injured, and you bandaged the wound, but it's not a hospital yet; it's just an attempt to stop the bleeding.
Then maybe you need to do something different, with more time, involving people, or even taking a different approach in the future. So you'll see this happening. Even if you're a CISO, you'll see autonomous protection, even if you didn't ask for it, through the protective platforms you have already invested in.
You mentioned earlier the blurring of lines between different categories in cybersecurity, and you seemed to be joking that your old days—your 30 years of experience—were worthless or had lost their relevance or something. What is the future of the SOC, and how are categories in cybersecurity merging or changing?
7. The future of the SOC
If I were a CISO, my main focus would be effective autonomous security. You want your best professionals to stay engaged. You want to automate the processes that work for your organization, but you're determining exactly what will survive in the AI era and what won't. I think we're still working on that process.
I believe that entire processes in the SOC will simply disappear, and for some reason, we are automating them right now.
Yes.
Over time, I can tell you one thing: if you have people in the detection and response cycle, you're going to be too slow. It just won't work effectively. So you have prevention, detection, and response. Prevention will be driven by AI, and detection and response will be performed by AI. The goal in cybersecurity has always been that you want to prevent; you don't want to deal with detection and response.
So I see a constant narrowing of the window for each phase, to the point where we're not really doing a lot of detection and response because the window for that happens instantaneously.
That's right. But still, to some extent, there has to be this “onion” protection, where systems back each other up, assuming that there's going to be a failure somewhere. Even if you created a force shield, sooner or later someone would bypass it. Someone will create an exploit before us, somehow finding it on a platform or in an application that we haven't yet tested.
It hasn't been used in production at the client yet, so we haven't seen it, but someone else found it. When they do, you'll need a trap that will alert you to unauthorized or illegal access to the system. These traps—you simply cannot rely on humans here.
Yes. It's just going to happen, because we've done it before at Armad: when we hack a system and gain inside control, it spreads at an amazing rate. As a human, you type on the keyboard and try to move the payload from here to here; you're so slow, and you do everything one at a time. This thing does a thousand things at once. It's just everywhere, and you're like, “Wow, okay, done.”
Got it.
Yes. So each of these process steps must be automated. This cannot be a person in the cycle. This is so bad. I don't have any apt analogies. It's like a balloon bursting: someone gets inside, and that's it—they're gone. The entire defense apparatus simply exploded.
You need to set up protection, then immediately lock the system upon detection and respond as you see fit.
Of course.
So all of that will change. Every CISO considers this. Each vendor is assessing its role in the transition to AI. They are checking their staff. They analyze the number of personnel. They are reviewing their processes—the CISO is doing this—and they ask, “What should I look like in the modern era?”
But it's too early to say how it will all end.
Of course.
It's too early to say what they will look like, or what their defense apparatus will look like. You may have many Fortune 500 clients. You also have close relationships with many others who are not your clients. What is the state of their vulnerability today?
It is rapidly decreasing.
Everyone is worried. At this point, there is a sense of desperation on both sides. If you are on the offensive, like Iran or Russia, you have a desperate desire to penetrate right now—to get a foothold.
You're right.
And if you're on the defensive, you're desperately trying to patch up every crack. It would be fair to say that both sides have reason for their despair. In the age of AI, we experience short-term difficulties because it gives an offensive advantage, period. That's normal. It's just the nature of things.
That is.
This means that defensive AI, trained on examples of offensive AI and acting autonomously, will do much better and more thoroughly than humans reviewing data packets. We're going through a period of vulnerability right now, where everyone on defense is under threat and they're all rushing.
I see incredibly strong efforts in every company right now, and I don't know of a single large, first-tier enterprise that isn't scanning for vulnerabilities and responding to them in real time. What's interesting, David, is that it's teamwork everywhere: CIOs, CISOs, product teams, and business lines are all saying, “Okay, we found something.” It's like working in the situation room: we have to fix this.
The composition of these teams is quite broad, so there is no way to make next year easy. That's the best way to say it. This is a real cocktail party now—a digital cocktail party—and everyone is in a racing state.
Yes. One of our largest technology companies told us that they have dedicated a large percentage of their engineers and research teams solely to strengthening their own defenses.
Yes. It was like a full mobilization of forces. The alarm bells started ringing quite recently—it was within the last few months. I think “Mythos” was the biggest; we saw it long before that. But the moment with “Mythos,” from a marketing perspective, made everyone realize, “Okay, the threats have changed.”
Many people said that with the release of “Mythos,” you have to “find vulnerabilities in your own software,” and that's what you have to do if you're in software security. All the vendors rushed to do it, but my response to “Mythos” is that it just made it common knowledge that AI can be used offensively against you.
I think that's what accelerated the process. That was the final confirmation: this is coming.
What about the case of Hugging Face? I'd like you to talk about it. I've thought about this a lot.
I'm sure at OpenAI they were saying, “Oh, we could have done this and that, and it wouldn't have happened.” They've already figured it all out.
In my experience, every time we change the technical modality, we underestimate the capabilities of the adversary. In this case, we underestimated the capabilities of the model. When you read about it after the fact, you think, “They could have stopped it.” They could have put in some safeguards, some deterministic things.
I think they understand that now, but when you're in a race, it's almost like a “moon race,” right? AI racing. You have R&D specialists working on creating models in such a way that even the CEOs themselves say, “We can't slow this down. Let's ask the government to help us slow it down.”
It means you can't even control your own innovation. I have my views on this, but we can leave that for another time.
Yes.
When R&D people are chasing these innovations, it's very difficult to combine them with experienced security professionals who have the skills to “cage this thing.” It's hard to put them together because security experts don't really understand AI, and AI experts don't realize one of the things that we did in our model.
Make no mistake: Armadin created the very beast we all fear. We created a model that attacks. We created many of these. We have a system that attacks industrial networks and is very successful at hacking them.
Is it safe? Our guys instinctively knew that we needed a hypervisor. We have to secure this thing. We have to block it at the host level. We need a proxy server. It knows about proxies. It works through a proxy, and that's good.
But then our guys did something that even I said, “Good job.” They passively and covertly check every single request: Do we like it? Do we not like it?
For the most part, if we stop an agent, it's most likely not security-related. It's because the agent is wasting money. Stop it. It is chasing the wind—something we have already done or don't want to do.
But there were so many levels of verification to ensure the agent acted correctly.
It’s another thing to assume that every level of your security will fail, and you have to have deterministic rules that eliminate certain actions. But what I learned from reading about these incidents is that protecting agents that operate in certain areas requires domain expertise.
I understand that. Without cyber experience, I understand how you’re going to do it: you’re going to propose something and say, “Oh, I didn’t think of that.”
Yes. You would need an experienced team to look at the evaluation results and say, “You know what? This will do this, and this will do that.” That’s why at Mandiant we combined exploit developers and red teams with AI experts, because most of the time our assessments are done by red teams. They’re the only ones who understand this.
We created 20 full attack chains in Armadin that people implemented in the real world on various sites and that our experienced operators ran during network testing. No model ran the full chain more than 8 times, so it was 8 out of 20. Here’s what’s weird, by the way: we tested models with open weights and the most advanced closed models. They all found 8.
Really?
Yes. So it was just a matter of speed and cost. Closed models were faster at finding exploitable vulnerabilities, but that gap is closing. We just let the open models run longer, and they achieved the same result.
In cyberspace, the distinction between closed and open models is probably not as great as in other areas, and it’s shrinking.
I would say it’s somewhat consistent, in terms of the capability gap at least narrowing a little bit.
Uh-huh. But interestingly, their performance is practically the same. From my perspective, looking at the graphs from the team, all the lines ended at one point. When you look at inference time, cost, and then efficiency or creativity, they all ended at one point where they hit diminishing returns, except for cost.
Aside from the cost, it makes sense. It’s a good transition to maybe talk about what models you’re using and what role you think the labs will play in the future.
I don’t even know if I’ve finished answering your previous question, other than that security experts will have to work alongside artificial intelligence experts. I read this MITRE paper and thought, “These guys are AI experts, but I’m not sure they’ve done much.”
It’s going to happen again—a paradigm shift. Here’s an example: when the cloud was first starting to emerge, I was dealing with a bunch of incidents. We at Mandiant were professional breach responders, and we had to study what a cloud breach looks like.
Now we need to study what an AI hack looks like, how much data Anthropic or the companies developing the models use to carry out attacks, and what we would like them to log. I’d like to know how they will change their behavior to have better audit trails and better forensic capabilities.
This is an early stage in the development of the technology, and we all need to gradually mature to a level where we have accountability when these things get out of control. You should be able to say, “This is what happened and when.” It shouldn’t take 2 weeks of expertise to figure this out.
I hate to say it, but we record every action our agent takes. Do you know the originating IP address, time, date, and what he did? You should be able to go back and replay those events.
I think they learned their lessons the hard way. They’re probably much better today than they were even 3 months ago at OpenAI and Anthropic, at testing these things. Anyone who’s had a regular lab looks at this and says, “Okay, we need to tighten up a little here.”
Yes.
I understand they were surprised because they underestimated it. We both did the same thing with human opponents. This is the strangest thing: throughout my entire career, everyone has underestimated the highest level of threat they face because they don’t see it every day.
Yes.
You don’t want to be afraid of the boogeyman under the bed, as they say. You don’t want to give in to fear, uncertainty, and doubt, but you still have to respect the technologies you’re building and test them in a way that makes them properly secure.
We need to keep the beast in a cage, David. Do you understand what I mean?
Yes.
I would argue: don’t cage it too tightly. Let it out a little and find a limit, because if you make everything too deterministic, that’s the art of using AI safely, at least in cyber operations. You want to use the intelligence of advanced models to do things, but not to do nonsense.
You need classifiers. You need a model that keeps track of everything that goes out and everything that comes in. We created it with the help of people who give a thumbs-up or a thumbs-down: this is good and this is bad.
You have to train it, classify it, and monitor it. But if you become too categorical and prohibit everything, you probably won’t use your full creative potential. You loosen control a little, so it’s a gray area.
The problem with this gray area is that no one can ever say that we’re 100% sure we’ll get what we expect. This is a struggle that we have, but there have been no problems so far because we can involve a person, or we have classifiers that say the person must decide here.
We don’t know exactly what happened. Do you understand what I mean?
Yes.
If you review everything that comes in—every request to the labs, every response—and something comes in that we don’t understand, we stop, pass it on, and evaluate it.
What do these awesome security specialists at Arman look like?
A lot of experience: 15 years in attack and 15 years on red teams. I think we’ve audited the security of 99 out of 100 Fortune 100 companies in our careers.
Wow.
We didn’t get just 1. I know who it is. They never hired me, even though I love their products.
Maybe someday I can—how do we get to them? Let’s find these guys.
Yes, we communicate with them constantly. But they still weren’t convinced.
It’s okay. Maybe they’re good.
They’re very experienced. When I look at our 90-plus zero-day vulnerabilities, most of them were found by humans, right? People find them because we use AI for 90% of the routine work: automated penetration testing of web applications, in a creative way, for 98% to 99% of cases.
We’re still getting people involved, but here’s what’s interesting, David: the last few zero-day vulnerabilities were found by the technology.
Really?
Yes.
Wow.
So we made a breakthrough. Most have already made this breakthrough: if you work on an AI attack, your AI agents find zero-day vulnerabilities.
I want to change the subject to your philosophies and mindsets on building a company. You know, they’re different.
Yes.
So, a few points.
For example, I first started a company in 2004, and I wouldn’t say I was an entrepreneur. I started Mandiant in February 2004. It was self-funded and profitable, and we were successful.
Looking back, it seems like you’re learning almost nothing at the time, and then you look back and say, “Oh, I learned then,” usually through pain. Looking back at Mandiant now, we had a thesis that nobody believed in 2004. Our first website said that security breaches were inevitable, and nobody believed it. I don’t even know how much I believed it myself.
That’s a pretty good slogan.
By the way, I was a little wrong. Our first headline was, “You can’t rely on precautions alone,” and it was so boring, but it’s the same as “Security breaches are inevitable.”
It’s better to—
Yes, I was wrong because I’m not a marketer. But no matter what, security breaches are inevitable.
The idea was to respond to every significant breach so that we would have a head start in getting intelligence on how to prevent it in the future. That’s why the first analytics model in all of cybersecurity was antivirus. It was like, “We’re looking for malware.” We have signatures for it, and if we miss it, David George has to find the malware and send it to us so we can get better.
This is a bad model. My mom won’t find malware on her laptop. It will simply eat her laptop alive. Do you understand what I mean?
So that model was bad. We decided we needed a better model because I was reacting to the breaches. The reason I responded to them was because antivirus is easy to bypass. We thought, “Let’s study everything. Let’s make a second level of antivirus, because it’s useless.”
That’s what EDR has now, so let’s do a second layer of antivirus. Although antivirus is still needed—I criticize it, but the reality is that it’s still needed, or something that will replace it. A second level of protection was necessary.
Antivirus was the Maginot Line. Then you extend the Maginot Line with something that can learn and think. We wanted to do that, and I actually view Armen as the third wave of intelligence.
Why wait for a victim to learn from this? This is ridiculous. You have to find your own problems first. Don’t wait until, say, defense contractor “A” is hacked to then quickly share information and ensure it never happens again.
This model should still exist for when something does sneak up and defeat you. But we have this model now, and it’s just not enough. So, going back to your question, Mandiant was self-funded. I don’t know of any self-funded companies right now, David.
Speed requires you to be fast. That’s the difference.
Yes. You see, we founded Armored, and the philosophies were different. When I started Mandiant, it was, “Hey, this is what we do for a living. Let’s make enough money to live on.”
That's all. We hired the best people and had a philosophy: We pay you more than our competitors, but you will work harder. We always felt like we had fewer people working harder, but they were better people.
I think we were known for having great talent, and those talents prevail. About a year ago, someone sent me a message saying, “Congratulations, 43% of the keynote speakers on the RSA main stage are Mandiant alumni.” That's the message I received. I've never checked, but this guy is usually accurate.
I'll accept that statistic if it's true, and I think that's how it was. We've covered a lot over time thanks to a lot of talent. I mean, look at Foundstone; look at George Kurtz. He and I worked together at Foundstone in 2000. He spawned a lot of successful companies and people from Foundstone. The same is true with Mandiant, but here's the difference.
First, you need to have funding.
Yes.
Second, your growth rate—you need to enter the market now. When I look at Armored's capabilities, I feel like we have an 80-mph tailwind, but we don't have a sales department. We don't have a go-to-market strategy. We aren't represented internationally. All this has to happen.
The only way to succeed in today's economy, to beat the big players, is to enter the market with the right technology at the right time. You'd better have the second act ready, and then the third, because you don't want to find yourself at a dead end.
Arman has a second act, we have a third planned, but we are currently building a go-to-market strategy that requires funding. This needs to be done in advance.
No, consumer AI companies created this rapid revenue growth. I don't think that can be replicated in corporate security sales, right?
But you just saw this time compression. Wiz reached over $100 million in annual recurring revenue within 18 months of its initial release, right? We're going to try to top that.
That's what you should do, especially when you're needed. It is necessary; you must exist, and it is not easy to do. So you need to get funding.
Do you have to constantly think about how to grow fast? You can't let the wheels of the bus get loose. How do you move so fast and maintain your processes?
Yes. At Mandiant's pace, we were self-funded and profitable with no competition because no one believed in the concept. We didn't falter that much. We had great leadership and discipline, and we could do it.
When you're growing so quickly, you must immediately hire leaders capable of scaling who understand institutional processes. You can't win with just determination, intuition, and perseverance. You actually need to implement procedures—to almost industrialize the Armadin way.
Yes.
Do you understand what I mean? That's what I'm trying to figure out: How do we do this and feel comfortable doing it? Here's the complication.
So let's do it.
You have to grow up fast. In the AI era, development used to happen at a speed where you trained the sales team at the January launch, and that was enough.
Yes, exactly. Yes. I'm trying to understand this: We change every 2 weeks. What is the current approach to having a sales team that's always on top of things?
Here's the challenge I've been thinking about. Every CEO I've spoken to asks, “How is AI changing our business?” We all understand that, but how does it change our human resources?
When I look at the impact of AI on sales, the reality in enterprise security sales is this: People still buy from people.
Yes, you still need the same damn go-to-market structure for now.
In fact, it has become even more relevant because technology is changing so quickly that you can't put the responsibility on the client to figure out what has changed and where you are now.
We need to create an institutionalized process where the sales team is trained every week. What stage are we at? How are our successes? These are the processes that will lead you to the point where you care about your authority.
That's right.
You have to be the best.
Yes.
By the way, nothing will replace this in the companies I'm associated with. We never strive to be second in our field.
That sounds interesting.
You have to be the best in the world at what you do. When we hire people, I remember someone asking, “How do you know you're the best?” I answer, “When you're the best, you just know it.”
You have to be the best in the world. You have to ask yourself this question. You probably know that there was a time in LeBron James's career when he realized, “I have to work harder to stay the best.”
Yes. Right.
I want us at Armadin to feel the same way. Sports analogies always work. Tom Brady never stepped onto the field thinking, “Wow, I'm the second-best quarterback here.” No. Always the first.
But it takes hard work and the best people, and you have to constantly check: Are we the best? Are we the best? You learn very quickly from customers if you need to do better, right? Therefore, this feedback loop from the customer to the engineers is also critically important.
In short, the speed has changed. It is necessary to attract capital. It is necessary to scale processes and constantly test them. What I can't stand is chaos.
The CEO's job is to completely hide the chaos in the company from employees.
True. Point.
You need to make sure they don't think things are too relaxed. You can't say, “We have no idea.” That's wrong. You should just say, “Here is the process. If you find the process too difficult to learn, this is the person you turn to.” All you need to know is that person's name.
That's exactly how I look at it. How can we grow quickly without feeling chaotic? How do we grow quickly while earning it with a better product? How can we change quickly?
I don't know how long intellectual property rights last. It's like building a Ferrari engine and saying, “You know what? Everything we do today, someone else will do in 6 months.”
Yes.
So how do you stand out over the next 6 months? Go to market, attract customers, and make them happy. You understand. The brand should also be built in parallel. You must become a brand that's a sign of quality.
Of course.
I gave you a somewhat confusing answer that I wish an AI could quickly summarize. Here are 4 differences: financing, speed, brand value, and development of a go-to-market strategy.
Today, we need to build much faster than we did 2 years ago.
Well, the main reason for that is because this is a tsunami that has never been seen before in security—in the security market, right?
CrowdStrike and other players around it redefined the category, but they had to create it. In the case of Wiz, part of the reason they were able to grow so quickly is that it was an urgent need that struck like a bolt from the blue. Everyone felt like they needed to buy this or something like it.
Plus, you also scaled very quickly.
You get the halo early on. You have to get that halo, and I personally think you get it by attracting the right customers and making them excited about you.
No offense, but if there's a place called, say, “Susie's Cupcakes,” they're not going to give you that halo if you make them happy in cybersecurity, right? But the big banks, the best retailers, and the airlines—they give you that halo. That's why Armadin focuses on the corporate sector, number 1: solving the most complex problems.
Of course. I think Wiz did just that.
Yes, they did a great job with it at one of our companies, too. We love these guys.
Okay, what else do you want to talk about? Anything?
Well, I never answered your question about the differences. There are more founders today than ever before.
Yes.
There are more startups than ever, and they're all able to raise capital now. So you'll have competition in whatever you take on. There will be no shortage of competition. Security incidents are inevitable, it's true, and no one is immune.
Of course.
So everyone is in a crowded market. I think every founder should understand that they need to be different, probably now more than ever because of the marketing noise. The only way to stand out is to get a customer, make them happy, and repeat.
Of course.
There is nothing else that will set you apart other than your customer base being thrilled with you. So you'd better go and do it. That's all.
I'm just revealing all my professional secrets. There is no higher mathematics here. Honestly, it's the same as it has always been in business.
Yes.
But now everything is happening at hyperspeed. We just need to do it faster. This speed requires not forgetting what to focus on: Find a customer, make them happy, repeat. That's all. You have to do it.
Everything else around it is just to make it the best it can be: training, sales support, marketing, the people you hire, the hiring process, teamwork.
There are some methods by which we differ, too. We keep all our engineers in one room.
Yes.
We firmly believe in this. I think managing distributed teams is harder than standing up and asking a question when there are 20 people in the room ready to answer.
At least it's slow.
So this is a great time to start a company because almost every industry is going to change.
Yes. In cybersecurity, every technology stack will change over the next 2 years.
Yes. Old technologies will be replaced by new ones. Everything has to be updated, so being a part of it is fun and exciting. This is a once-in-a-lifetime wind of change in cyberspace.
8. Lessons from the Hugging Face incident
Yes. Well, we are excited about what you're creating and are happy to be your partners. Thank you for coming. It was fun.