Skip to content
a16za16z

Building Cyber Defense for the Agentic Era

a16z General Partner David George sits down with Armadin founder and CEO Kevin Mandia to discuss what happens to cybersecurity when attackers can operate at machine speed. After 30 years in security and building Mandiant, Kevin says AI convinced him to get back on the field. He explains how AI changes the economics of cyberattacks, allowing attackers to probe thousands of paths simultaneously, and why that means defense will ultimately need to become autonomous too. They also unpack Armadin’s approach: continuously attacking customers’ systems with AI to find exploitable vulnerabilities before adversaries do, then building toward autonomous defenses that can respond in real time. Kevin shares what Armadin has learned from finding more than 90 zero-days in production environments this year, why humans can’t remain in the detect-and-respond loop, and how the entire security stack could change over the next few years. Timestamps: 00:00 - Intro 01:06 - Why Kevin came back to the field 04:19 - What AI attacks look like today 07:18 - Nation state vs AI drone swarms 14:34 - Why pen testing is dead 18:36 - Autonomous defense explained 21:22 - The future of the SOC 27:04 - Lessons from the Hugging Face incident 35:44 - Building a company at AI speed Resources: Learn more about Kevin Mandia and Armadin: https://www.armadin.com/team-members/kevin-mandia Follow David George on X: https://x.com/DavidGeorge83 Learn more about Armadin: https://www.armadin.com/ Stay Updated: If you enjoyed this episode, be sure to like, subscribe, and share with your friends! Find a16z on X: https://twitter.com/a16z Find a16z on LinkedIn: https://www.linkedin.com/company/a16z Listen to the a16z Show on Spotify: https://open.spotify.com/show/5bC65RDvs3oxnLyqqvkUYX Listen to the a16z Show on Apple Podcasts: https://podcasts.apple.com/us/podcast/a16z-podcast/id842818711 Follow our host: https://x.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see http://a16z.com/disclosures.

Kevin MandiaguestDavid Georgehost
Oct 6, 202647mWatch on YouTube ↗

CHAPTERS

  1. 0:00 – 1:16

    AI-era cyber defense requires AI-era offense (Armadin’s core premise)

    Kevin Mandia frames the central idea: you can’t build a credible defense without training against an elite, realistic offense—especially as AI changes the speed and scale of attacks. Armadin’s mission is to become that “all-star offense” so defenders can harden against what’s coming.

    • •Defense effectiveness depends on testing against a truly capable offense
    • •AI changes cyber from human-paced to machine-paced competition
    • •Armadin positions itself as the offensive pressure needed to train modern defenses
  2. 1:16 – 3:11

    Why Mandia returned: the “AI shift change” makes past playbooks obsolete

    Mandia explains why he re-entered operating roles after Mandiant: AI is a discontinuity that makes traditional security approaches insufficient. Meeting Armadin’s founding team convinced him the moment required building again, not observing from venture.

    • •He didn’t want to “sit out” a once-in-30-years platform shift
    • •Frontier AI collapses work that used to require large human teams
    • •The founding team’s talent and urgency pulled him back into the field
  3. 3:11 – 4:27

    What Armadin does: Armadin Red now, Armadin Blue next

    Mandia outlines Armadin’s roadmap: first, use AI offensively to find exploitable risk faster than attackers; second, stop it with rapid compensating controls. The product vision is an AI “force field” built from offense training defense.

    • •Armadin Red: AI-driven offensive testing to find real exploitable paths
    • •Act two (Armadin Blue): translate findings into rapid defenses
    • •Goal: stay minutes ahead of criminals and nation-states with continuous validation
  4. 4:27 – 7:49

    What AI attacks look like today: early innings, but scale and speed are decisive

    They discuss how AI-driven intrusions differ from human-led ones and why defenders haven’t yet seen the full force in the wild. Mandia argues open models are already sufficient, and broader criminal adoption hinges on cheap, anonymous access to compute.

    • •AI attacks show behavioral “tells” vs human, but will get cleaner
    • •Scale: parallel exploration of many paths versus one careful human path
    • •Speed: microseconds vs dozens of humans’ time; structured targets (code) favor AI
    • •Open models are “good enough”; GPU access and anonymity will accelerate crime
  5. 7:49 – 10:58

    Nation-states vs AI swarms: from sniper rounds to drone-swarm doctrine

    Mandia contrasts traditional nation-state tradecraft (targeted, stealthy) with the emerging AI-enabled “swarm” approach that’s louder but more comprehensive. He also flags a coming attribution problem: defenders will struggle to know who is behind model-driven attacks.

    • •Nation-states historically optimize for stealth and precise targeting
    • •AI pushes toward broad swarming: less subtle, potentially more effective
    • •Doctrine will evolve: when to swarm vs when to remain surreptitious
    • •Attribution gets harder as attacks become “model-shaped”
  6. 10:58 – 14:35

    Continuous validation at machine speed: hyperattacks, metadata twins, and change-driven retesting

    Mandia explains Armadin’s mechanics for continuous security assessment without constant full-cost attacking. A “hyperattack” rapidly maps the environment, then lightweight polling detects what changed so the system can retest only what matters.

    • •“Hyperattack”: fast swarm mapping of services, routes, assets—creating massive metadata
    • •Create an attacker-view ‘twin’ used for ongoing monitoring
    • •Poll for change cheaply (apps, routes, services, new machines) then “attack the change”
    • •Continuous pressure is necessary, but full-time attacking is costly and often unnecessary
  7. 14:35 – 18:46

    Why pentesting is dying: proof-of-exploit, not lists of CVEs

    They reframe the category: classic pentesting and vulnerability scanning often generates noise and false positives, while real adversaries (and AI) find exploitable paths, logic flaws, and custom-app weaknesses. Mandia emphasizes Armadin’s “verify by exploitation” approach and claims major real-world zero-day discoveries in production environments.

    • •Traditional pentesting = hygiene scanning for known issues; often high noise
    • •Armadin verifies exploitability (e.g., RCE/data access), reducing false positives
    • •AI attackers find logic flaws and exhaust routes continuously
    • •Claim: 90+ zero-days found externally (black box) in production at large enterprises
  8. 18:46 – 21:22

    Autonomous defense (Armadin Blue): compensating controls and rapid “tourniquets”

    Mandia argues CISOs’ true north is autonomous response: when attacks occur at AI speed, humans can’t stay in the loop for tactical decisions. Armadin Blue aims to take exploit findings and automatically inform EDR, firewalls, and other controls to block or contain attacks quickly.

    • •Autonomous response becomes mandatory as offense accelerates
    • •Blue integrates with defensive platforms (EDR, firewalls) to push safeguards
    • •First generation may be blunt—better a “bad patch” than an intrusion
    • •Ecosystem coordination: working with major defense vendors to operationalize controls
  9. 21:22 – 27:04

    The future SOC: humans can’t be in the detect/respond loop fast enough

    They discuss how SOC processes and cyber categories will blend as prevention, detection, and response compress into automated pipelines. Mandia predicts shrinking windows for human action, emphasizing layered controls and automated traps for inevitable escapes.

    • •Humans in detect-and-respond loops will be too slow against agentic attacks
    • •AI governs prevention, detection, and response; boundaries blur at machine speed
    • •Defense-in-depth still matters: assume failures and place traps behind the “force field”
    • •Organizations are rethinking headcount, process, and vendor roles—outcomes still unsettled
  10. 27:04 – 30:02

    Lessons from Hugging Face + securing offensive agents: guardrails, logging, and domain expertise

    Mandia reflects on what incidents reveal about underestimating model capabilities and the difficulty of securing agentic systems without deep domain expertise. He describes Armadin’s safety approach: layered controls, prompt inspection, deterministic rules, and exhaustive logging for replay and accountability.

    • •Incidents show teams underestimate what models/adversaries can do
    • •Security requires domain experts paired with AI builders; evals must be grounded in real tradecraft
    • •Layered safeguards: proxies, hypervisor isolation, classifiers, escalation to humans
    • •Deterministic “never do” rules plus full telemetry (IP/time/action) for replay and forensics
  11. 30:02 – 35:45

    Open vs closed models in cyber: similar endpoints, different cost and speed

    They note an unexpected finding: open and closed models converge to similar effectiveness over time in offensive security tasks, with differences mainly in speed and cost. Mandia frames this as accelerating pressure on defenders because capability spreads quickly as models commoditize.

    • •Testing showed performance convergence across open-weight and frontier closed models
    • •Differentiation shifts to time-to-find, operating cost, and operationalization
    • •Implication: cyber offensive capability commoditizes faster than many expect
  12. 35:45 – 47:49

    Building a company at AI speed: funding, process, and go-to-market discipline

    Mandia compares building Mandiant (self-funded, slower era) to building Armadin amid rapid AI-driven market change. He emphasizes funding, hiring scalable leaders, industrializing processes, and continuously training sales/GTMs as products change every few weeks.

    • •Self-funded models are rare now; speed demands capital and early scaling
    • •Need act two/act three readiness to avoid being boxed in by fast-moving markets
    • •Go-to-market and brand trust become key differentiators as IP cycles compress
    • •Operational discipline: reduce chaos, create tight customer→engineering feedback loops

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.