Skip to content
a16za16z

Building Cyber Defense for the Agentic Era

a16z General Partner David George sits down with Armadin founder and CEO Kevin Mandia to discuss what happens to cybersecurity when attackers can operate at machine speed. After 30 years in security and building Mandiant, Kevin says AI convinced him to get back on the field. He explains how AI changes the economics of cyberattacks, allowing attackers to probe thousands of paths simultaneously, and why that means defense will ultimately need to become autonomous too. They also unpack Armadin’s approach: continuously attacking customers’ systems with AI to find exploitable vulnerabilities before adversaries do, then building toward autonomous defenses that can respond in real time. Kevin shares what Armadin has learned from finding more than 90 zero-days in production environments this year, why humans can’t remain in the detect-and-respond loop, and how the entire security stack could change over the next few years. Timestamps: 00:00 - Intro 01:06 - Why Kevin came back to the field 04:19 - What AI attacks look like today 07:18 - Nation state vs AI drone swarms 14:34 - Why pen testing is dead 18:36 - Autonomous defense explained 21:22 - The future of the SOC 27:04 - Lessons from the Hugging Face incident 35:44 - Building a company at AI speed Resources: Learn more about Kevin Mandia and Armadin: https://www.armadin.com/team-members/kevin-mandia Follow David George on X: https://x.com/DavidGeorge83 Learn more about Armadin: https://www.armadin.com/ Stay Updated: If you enjoyed this episode, be sure to like, subscribe, and share with your friends! Find a16z on X: https://twitter.com/a16z Find a16z on LinkedIn: https://www.linkedin.com/company/a16z Listen to the a16z Show on Spotify: https://open.spotify.com/show/5bC65RDvs3oxnLyqqvkUYX Listen to the a16z Show on Apple Podcasts: https://podcasts.apple.com/us/podcast/a16z-podcast/id842818711 Follow our host: https://x.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see http://a16z.com/disclosures.

Kevin MandiaguestDavid Georgehost
Oct 6, 202647mWatch on YouTube ↗

At a glance

WHAT IT’S REALLY ABOUT

Kevin Mandia on AI swarm attacks and autonomous cyber defense

  1. Kevin Mandia explains why he returned from venture investing to help build Armadin, arguing the AI “shift change” will radically reshape cybersecurity faster than traditional teams and tools can adapt.
  2. He describes how AI-led attacks differ from human-led intrusions—operating at extreme speed and scale, exploring many paths in parallel, and increasingly enabling less-skilled attackers to achieve higher impact.
  3. Armadin’s approach uses AI on offense (“Armadin Red”) to identify and verify exploitable risk—including zero-days discovered from the outside as a black-box adversary—rather than producing noisy vulnerability lists.
  4. The company’s next phase (“Armadin Blue”) focuses on autonomous defense: rapidly translating discovered exploit paths into compensating controls across existing security platforms to shrink exposure windows.
  5. Mandia argues SOC workflows and cyber categories will blur as prevention, detection, and response compress into automated loops, forcing CISOs to redesign processes and staffing for agent-speed operations.

IDEAS WORTH REMEMBERING

5 ideas

In the agentic era, defense without an AI-grade offense is incomplete.

Mandia argues that effective defense in an AI world requires continuously exercising your environment with high-fidelity offensive pressure—similar to how elite sports defenses train against elite offenses. Armadin positions itself as a “practice offense” at machine speed so defenders can close windows before real adversaries exploit them.

AI attacks change the game via scale and speed, not just sophistication.

He describes AI-driven intrusions as massively parallel, fast, and often “non-linear” (e.g., re-hitting earlier steps, trying many routes), unlike a human attacker’s more sequential path. This shifts the core constraint from attacker labor to defender reaction time and system-level resilience.

“Pen testing is dead” because verifying exploitability beats counting CVEs.

Traditional pen testing and vulnerability scanning are framed as largely hygiene checks that generate noisy lists of known issues and false positives. Armadin’s thesis is that what matters is proving exploitability (e.g., demonstrating RCE/data access) and finding logic flaws and custom-app issues via agentic exploration.

Continuous security becomes change-driven: map once, then attack what changes.

Armadin’s “hyperattack” maps an enterprise quickly, producing a rich metadata picture of services, routes, and assets. Instead of endlessly re-attacking everything, it cheaply polls for meaningful change and re-attacks deltas—balancing continuous assurance with cost and operational practicality.

Autonomous response (compensating controls) becomes mandatory, even if imperfect.

Mandia’s “Armadin Blue” vision is to automatically deploy compensating controls (tourniquets) through existing enforcement layers (EDR, firewalls) minutes—or seconds—after exploitable risk is discovered. The thesis is that human-in-the-loop response will increasingly be too slow for agentic intrusions.

WORDS WORTH SAVING

5 quotes

I don't wanna sit out the AI shift change when I've done 30 years in security and the whole damn thing's about to change.

— Kevin Mandia

What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges.

— Kevin Mandia

Like, how does AI change what our mission is? Do we m- maybe use the cyber domain differently? Do we drone swarm sometimes, sniper round other times? How do we balance the two?

— Kevin Mandia

If you have humans in the detect-and-respond loop, you're gonna be too slow.

— Kevin Mandia

Gotta cage the beast, David.

— Kevin Mandia

Agentic AI attacks: speed, scale, non-linear behaviorNation-state ‘sniper’ vs AI ‘drone swarm’ doctrineContinuous red teaming vs legacy pen testing/scanningHyperattack network mapping and change-based re-testingVerified exploitability (RCE/data access) and zero-day discoveryAutonomous defense and compensating controls (Armadin Blue)SOC evolution: prevention/detection/response compression and auditability

High quality AI-generated summary created from speaker-labeled transcript.

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.