Hello, and welcome to this next chapter in the AI Impact series, the AI Impact Blueprint for today's IT. This session is produced by Future B2B and sponsored by Automox, Datadog, KnowBe4, OneTrust, Strike48, and Wiz. If you're new to the AI Impact series, welcome. This series is designed to take a closer look at how AI is shaping our world across industries. HR, retail, education, IT, government, security, and more. There are so many facets to these conversations, so many interesting tidbits, and you will not want to miss any of them. So be sure to sign up for all the AI Impact Series events. And you can also watch and rewatch on demand. So lots to stay tuned for, but don't go anywhere just yet because we're about to get started.
on an absolutely fascinating conversation. So today we're taking a deeper look into how enterprise AI has rapidly evolved past simple chat interfaces into autonomous AI agents and integrated RAG pipelines. We'll also unpack the way that is AI is becoming the central operating system of the modern enterprise. It's also opening a massive unpredictable new attack surface. So our expert presenters are going to help us explore how to secure your enterprise AI footprint against next-gen autonomous threats, why IT teams are establishing visibility over unmanaged AI tools, what it means to embrace an AI-aware zero-trust architecture, and how IT departments are using AI to accelerate incident response and threat detection.
So that's just a lot of stuff to cover today. Let's go over some quick housekeeping to ensure that we get the most out of today's session, and then we're going to get things started. So my name is Scott Becker from Future B2B, and I'm excited to be your host for this timely conversation. And we'd like to get to know all of you a bit better, too. So why don't you find that chat tab in your console, and let's start out by saying hello and sending that out to the community here with you today. As a quick side note, that window is also the best place to reach out and let us know if you have any technical issues during the session. Browser refresh will fix most issues, but if not, just shoot a message in that chat tab and the future B2B crew will be there to help.
Now, don't forget to post your questions in that questions tab or Q&A. This is a great way to get... involved with the conversation and to get the answers that you're looking for to make this event your own. So we'll do our best to respond to you in the discussion or via live chat. And anything we don't get to, we'll respond via email. I also want to point out the Docs tab. Be sure to check out some of the fantastic resources and takeaways and be sure to sign up for the other upcoming AI Impact Series sessions. Now, there's one more exciting thing that I have to tell you all about, and this one is really cool. If you're innovating with AI, there's an opportunity to win an award and get your project in the limelight.
SmartBrief's newest innovation award is open for nominations from teams that are leading the development and application of AI to advance progress across industries. This operates in tandem with this AI Impact webinar series. So the Smart Brief Innovation Awards in AI will recognize the most cutting-edge solutions to business challenges. Categories include education, finance, IT cybersecurity, marketing, retail, and the public sector. So entrants may be in the market or poised for market entry in 2027, and submissions will be assessed based on the degree of innovation and business impact. Participating companies pay a fee to enter. Not all nominated products are winners.
However, all nominees and winners will be featured in a program guide published after judging is completed in October. So to learn more, go to the Docs tab again, where you can find a link outlining all of the details so that you can submit your application. And the deadline to enter is October 2nd. Now, I also want to remind everybody that there is a closed captioning that you could enable on your console at any time with 18 different language options. And last but not least, we do have a $250 Amazon gift card that we'll be giving away at the end of the event to someone who's here live and present. You do need to meet the future B2B terms and conditions, and you can find those in the Docs tab.
Okay, and now we're going to start things off with a short video message from one of our sponsors that's making this event possible, Wiz. My name is Roz Hertzberg. I'm CMO and VP Product Strategy here at Wiz, and I would like to introduce you to our platform. Let's see it in action, starting with the most important thing, true code to cloud context. Look at this container vulnerability. Examining just the CV isn't enough. It doesn't show the real risk. When we add in workload context, like inventory, exposed secrets, cloud context, like resource configuration, network, and identity, we start gaining clarity. Then we include Kubernetes context, like the cluster layout, and business context, including tags in which Teams owns this service.
This approach reveals not just the vulnerability, but why it matters. This resource is accessible from the internet and has sensitive data in production. Now, We can also see runtime context added through the Wiz runtime sensor that shows that this vulnerable software component is indeed executed in runtime. Connecting all the way from code to cloud to runtime, this is what context is all about. And context is what Wiz is all about. And since Wiz connects all the way back to code repositories, we can identify which developer actually committed this vulnerable image and then automatically suggest the right PR fix. back in the Dockerfile. Now, we have an actionable view of the risk, what's important, why it matters, and how to fix it.
Excellent. Okay, it's time for the keynote address, and I'm already on the edge of my seat because we're starting off with an incredible duo. So our keynote speaker today is John Brandt, who's Senior Director of Professional Practices and Innovation at ISACA. And here to chat with John is the one and only Susan Rush. Director of IT and Tech Content Strategy for SmartBrief. So Susan's going to lead us through our keynote conversation today all about AI in IT. Blast to explore here, Susan, so I'm going to hand things over to you to take it away. Thanks for that great introduction. John, thank you so much for joining me today. It's a pleasure to be here. Well, you know, you're the star of the show today, so I'm just going to pepper some questions at you, and I'm excited.
to hear your answers. So, you know, IT leaders are caught between this intense demand for rapid AI adoption and governance frameworks that are built for traditional IT. How do you suggest mature organizations navigate the tension between speed and control? That's a wonderful question. You know, preparing for today was really interesting, the myriad of views that come together here. So I'm pretty excited about this. I think that it's important to address the elephant in the room. And that's that most organizations that we've had any kind of insights with, the risk appetite for AI is... appears to be very different from how they address their traditional technology stack.
And that's where those that are charged with bringing the innovation to life are really kind of where that friction is really being seen there. I think for the mature organizations, they're going to recognize a few things. And then there's some attributes that are accompanied with that. The first thing is that AI isn't the solution to every problem. And I think there's a lot there surely is increased writings on this. And even in a short amount of time where organizations were, you know, it's chasing the AI, what I call AI FOMO, right? Fear of missing out. So it's from the top. You have to use it for everything. And then, you know, not long ago, the bill came due.
So that was a big problem, right? Which is adding to the friction. If you recognize that AI is just a tool in your toolbox, that's a really good starting point to evaluate. Is this the right tool for the business problem or outcomes that I'm trying to achieve? Because again, it's the alignment, the business problems and or outcomes that really matter when determining ROI, which is really hard to come by right about now. But the basics matter more than anything. And I can't overstress this right now that mature organizations, they didn't leap in haphazardly. They're doing the basics. All of the cybersecurity best practices that are out there, all that stuff matters now more than ever.
Data governance is key to it all. So those programs are already in place. They're pretty well tuned. And if they're not, when you jump into innovation automation projects, you're going to see that you're actually, you're going to compound some problems. you know, the attributes are associated with that. They're going to conduct risk assessments more frequently. They would have conducted an AI impact assessment. And that isn't, you know, ISACA has, you know, a assessment that we created that was pretty broad brush. And typically when you say impact assessment, Depending on where you're coming at that you might view it's, oh, it's just privacy. No, it's a lot bigger than that.
And if we recognize, you know, AI for what it is, which is a really pervasive operational technology, you're really asking all those questions, gaining the stakeholder insights early on and trying to treat it instead of treating it like very much a let's implement this technology and figure out all the other ripple effects that might be associated. But it's also not for just models. And I think every IT professional out there is well aware of this, but it's worth overstating, especially for these smaller organizations that are really strapped for resources, is all of those services and technology solutions, software packages that you previously vetted.
More likely than not, they're all having AI features added to them. So you have to also account for that. And all your acquisition processes, your security reviews, all of that is. So it's no longer this one and done. It's very much everything is on a continual cycle to re -review those things. And beyond that, then we get into some architectural concerns, which I think you might touch on a little later. approved platform standardizations agreed upon baselines those things that way you know the regulatory constraints that you know and that you might be subject to all those things are accounted for early on before you start introducing specific segments of technology yeah i think that's a great way to get us started here and i I really loved you just emphasizing that AI impact assessment and the need for that rather than just jumping in with both feet, which some organizations do.
You're right, FOMO is a real thing here these days. So I think it's important for everyone to know here, you lead the ISACA's thought leadership across audit, privacy, and risk. Let's face it, these areas are often viewed as innovation bottlenecks. You know, so how can these GRC leaders modernize their oversight models so risk management enables that AI adoption rather than slows it down? That's a fantastic question. And like you said, you know, I'm a security person by trade. And, you know, in my role, I've over the years have, you know, I've got thought leadership SMEs in all those areas that you talk about, you know, events. as well as we're doing some AI, I've got AI developers within my purview as well.
So it's been really interesting how to bring them along. I think the first thing to acknowledge is that when we look at, as soon as we talk about AI governance, what's really interesting to me is that it's taken on a different shape. And I think it's also, my frustration in it all, because technology leaders, those that are involved with enterprise risk, you know, they can speak to technical risk. They have been doing this for a long time. And for whatever reason, AI just jumbles it all. But in this regard, to answer your question, continuous oversight is a must. And that's the tagline, right, at the beginning of the day is, And the challenge right now for the GRC leaders is who actually has overall responsibility for the AI implementation, right?
And there's competing views on this. There are research thus far, as well as any industry research that I personally have seen right there. It's still a mixed bag as to where it is, which complicates this. To modernize your oversight models, I think is instead of looking at a word like modernize, which might actually, it might bring upon some resistance within organizations. It's how can we become more agile? And I think the community had been calling for this subtly for many years now. And AI has been the catalyst to kind of force it along. In all of this work, you know, you have to be really careful because when, you know, though we've done work, we've been trying to bring AI related solutions to the market, upskilling practitioner tools and aids for several years now.
And we want to be real cautious about treating everything that it had to be specific. And I think that's an important thing is in a lot of regards. The things you want to do within AI, you need to understand the nuances of it. How can you incorporate them in all of your existing administrative controls in particular? Policies, standards, all of that. Then it's the cross-functional team. And I think this is, if you want to talk about modernizing, it starts here. To get agility, it's not just one person. It's not. typically just one unit this is very much a cross-functional And it's that collaboration, which is really important. And I think we have a real good opportunity here to leverage the errors of yesteryear with security, where security people came on the scene and we were very rigid and it's thou shalt do.
And to your opening sentiment, we were very much a barrier to innovation. And now those... themes are let's shift left security started be taking on more advisory roles we're seeing the same thing for audit as well like it's not that they're competing i think it's they're complementary and the earlier you bring people in then it actually organically will modernize how you approach you know you do business but that's all easier said and done because At the end of the day, organizations still have the same number of people, maybe a few less, right? And they're being asked to do more. So what are some other things that are going to be contributed to this?
Proactive thinking regarding risk from the earliest onset. Being that AI is a non-deterministic technology. changes a lot of things for organizational thinking, right? IT professionals, we grew up with everything's binary. Yes, no, on, off, open, closed. AI doesn't work that way, right? So it's math, those that are in the trenches. You know, we're going back to statistics classes. It doesn't always create stable outcomes. And there's a multitude of variables that go into that. But the modern GRC leader is like, okay, what's my tolerance, right? And one of my team members had a really good way of saying this. He was like, we're moving more towards managing exposure.
And in a lot of ways, it's almost more of an insurance model, I guess, because this illusion of securing AI goes about as far as it does technology. Any IT computer from the beginning of the day. So your oversight should scale with... sensitivity, decision impact, and autonomy. In that regard, use case is going to drive the levels of it, right? Things that are higher criticality, more risk for the organization. You want more control, more human involvement, gating or whatnot. Things that are automated, lower level stuff, especially where AI has proven successful on smaller data sets is a lot more stable. And, you know, you could kind of, you know, pull back just a little bit.
I would, I think it's worthwhile. I want to give a shout out to a prominent industry person right now. And I hope I don't butcher her name, but DeSesde Cox, she runs the angles of attack substack. It's an AI security thing. There are some very prominent people making substantive impact out there and she's one of them. And, you know, I encourage any, IT leader shop. They need to be actually engaging with following, consuming material from people who truly understand the underlying architecture and the nuances that it poses. Yeah, that's a great piece of advice. And hopefully everyone listening takes you up on that, starts Googling, of course, after your...
after you're done speaking. But, you know, I kind of want to talk a little bit about process improvement. I know this is a big part of your background. So how do you think standard IT delivery models should evolve to support more non -deterministic AI systems and autonomous agentic AI? You know, especially they're continuously adapting after, you know, they're being deployed. Yeah. Wow. So organizations, there's so many of us that are in this right now. And anybody who has already gone through or is working with an AI project, especially, you know, large language models, a lot of data sets, trying to make sense of it. That's where you kind of see where your organization, where maybe you might.
you might've needed to improve some things right along the way. So again, we come back to, you know, I think there's a lot of common themes that come up in this and this notion of working more, you know, in agile type DevOps type environment. So in this regard, like your, your delivery models need to be adapted because you're really not. Not only are you creating solutions, but you have to maintain them. And that's the piece that I think that, you know, IT professionals are pretty good about. Here's a solution. We roll it out and we go to this point. And, you know, if somebody has a problem, they submit a ticket and we go respond to it. And it's relatively stable.
This is the one where it takes a little bit more thinking and you have to really consider your resourcing as part of this. the complexity of the ai solution is going to drive how you're going to respond to this and then what which models you're using and those that are out there and i know i'm you know in some regards i'm preaching to the choir but our work like new models are continuously getting released and so the notion is hey we want to let's go connect another model we want to route to another one we want to route to another one And personally, what we've seen on some of the projects that we've worked on, which is actually, it's been interesting, intriguing, frustrating, all the same, is that in response to the native, I will say danger for a lack of better words, right, with AI, where the harms are, where there's outcry about and the need for guardrails.
that actually becomes another input that organizations have to closely monitor because every model change, every release, every update, every adjustment within the supply chain of this, it actually is an additional variable that you're not necessarily controlling. And we actually had this where, you know, Depending on how you're getting your model, let's say you're going through Azure, for example. So the model's got safeguards. Azure's going to have some safeguards. And sometimes they're not aligned, right? Or there's some competing things. And so you might have operated and implemented a solution that was tested under certain variables. And then something changed and all of a sudden something isn't working.
So all of a sudden it's like, Lineage, data providence, all these things become extremely important, which ties back to your opening question about, you know, in my response of, yeah, the basics matter now more than ever. And I do, I'm concerned for the profession that technology undoubtedly makes our lives easier, but it doesn't negate the understanding that you have to have. So how many? organizations truly have an accurate network map, truly understand the information flows. And in that regard, it then has their data appropriately classified and controlled because data is the lifeblood of AI and you can get some unintended consequences. But because your behavior can vary, agents can adapt.
You need ongoing observation, evaluation, observation, versioning, and risk-based human oversight. Like that's the thing is how do they need to evolve? It's very much risk-based and none of this is easy. If it were, ROI would be through the roof. Organizations would see a lot of success. And I think this is that. that friction that most technology leaders are finding right now is, hey, how can we get to a point where there's some value? But there is a tie-in and it goes beyond IT, right? And IT is a business enabler. We've long grown to accept that. AI is no different. And the views on AI are being highly shaped outside of enterprise right now. And both in good and bad ways.
So when you're looking at your delivery to support these things, there's close alignment with their ERM because it's no longer just about monitoring and maintain your IT ops because there is a brand piece of this at the end of the day. And how do you put a price tag on some of that? The tagline for this, deployment's no longer the finish line. It just begins a continuous cycle evaluation. There are some solutions in place. There's some maturity frameworks that are in place. CMMI does have one. Obviously, there's some other ones out on the market. Organizational size, construct, industry, location is all going to derive. what they need to help them properly, you know, adequately implement it and monitor it for success.
Yeah, John, I think you've given us a really nice picture of the full landscape and, you know, agility, knowing that technology really is only half the battle. But before we wrap up today, you know, let's say an IT leader is listening. What's that one action item that they should execute to get their AI house in order, say, in the next hundred days or so? What should that be? This one's easy for me. Fix your data. The statistics and a lot of anecdotal evidence right now is that. The data is the problem right now. And if we operate from a notion of data fuels AI, which is common knowledge, then the next logical thing and what I say is you can't really do AI governance without data governance being in place.
Otherwise, you're working the problem backwards. And so that's where I would start right then and there. You can't adequately protect. manage any kind of infrastructure if you don't know what you have and the existing protections that are in place. And to really, AI is interesting in the fact that it's, and again, there's tons of controls and there's lots of IT general controls that will assist with the AI problem set. But there's some other additional ones and how you stack them to address your risk assessment all matters on the threat modeling of your use cases at the end of the day. So again, first hundred days, look at all your data. Assuming you have all that, you want a baseline.
It's as simple as going back to basics and trying to not replicate the errors of all, implement a lot of tech solutions and increasing your technical debt. Yeah, that's a perfectly crisp, actionable directive to kick off our AI Impact Summit on IT here. And John, I really appreciate you setting the stage for us. Thank you so much, Susan. This has been a pleasure. Great. Thanks. Scott, back to you. All right. Thank you, Susan and John. What a fascinating conversation and a perfect way to start our day together. So my brain is buzzing already with fresh ideas from that conversation, which is perfect because we're moving into our smart panel and we have a whole crew of incredible experts joining me here with many more insights ahead.
So let's get to it. So today we're chatting with Catherine Chipty, who's Senior Director for Solutions Engineering and Alliances at Automox, Diamond Bishop, Director of Engineering and AI at Datadog, Eric Krohn, who's Security Awareness Advocate at KnowBe4, Michael Seacrest, who's Risk Field CTO at OneTrust, and Tim Leehealey, who's Co-Founder and Vice President of Strategy and Operations at Strike48. One of the things that you're going to notice right away as you look at that lineup of experts is that we have a lot of different lenses and perspectives all coming together here to give us a look at the direct and indirect impacts of AI in our IT environments.
I know we're going to have a layered and insightful conversation ahead, so let's get rolling. Enterprise AI has rapidly evolved past simple chat interfaces into autonomous AI agents and integrated RAG pipelines. But as AI becomes the central operating system of the modern enterprise, it's also opened a massive, unpredictable new attack surface. For CISOs and IT leaders, the challenge has shifted from basic enablement to mitigating real-world threats. you know, systemic data leakage via shadow AI, prompt injection vulnerabilities, and model supply chain risks. So today our panel is going to break down how to secure your AI footprint, establish visibility over unmanaged tools, embrace an AI-aware, zero-trust architecture, and leverage AI to accelerate threat detection and incident response.
So it's a lot to cover. I'm really excited to be here with all of you to do that. Let's start by addressing how the mental model of enterprise AI is changing. Most business leaders still think of AI as a chatbot that you ask questions of, but IT teams are facing autonomous agents that act directly on infrastructure. Diamond, most people still view AI through that simple conversational lens. Why is that? the wrong mental model for IT leaders going forward and across your enterprise customers running AI production, what's the single biggest operational challenge that they're hitting right now? Yeah, I love chat. We use chat for a lot of things at Datadog for answering questions, helping people understand how to do things.
But you have to start thinking about kind of how, what it really means to replace coworkers. That's more than just chat. Chat is just one modality. But most of the work, at least in software development and DevOps that we're seeing, doesn't get done through. chatting. It gets done by someone sitting down, improving the system that they're working on, fixing problems in the background. And much of what I think of as kind of the useful AI that's going to be going forward for our kind of systems is going to look beyond Q&A chatbot interactions. This will be these autonomous proactive agents. We're seeing this a lot with things like our Bits AI SRE that solves problems in the background that are like alert go off, go and fix it for you before you even wake up.
And we're seeing a lot more of that in the future. Biggest problem right now, though, is that eval is really hard. It's hard to know if this is going well, and it's hard to know if your autonomous agents are doing what you want from them. All right. All right. So, you know, as we transition from passive LLMs to activogenic systems, the social engineering and threat landscape, it changes completely. Eric. How are agents altering the social engineering game, and what key operational risks do agentic systems introduce that traditional LLM chat interfaces didn't? Yeah, so one of the key things I see here is what people are doing is they're using agents a lot to do things like check your email box.
to check your messages, to do all that kind of stuff. And I think that's going to end up with more and more power in the agent side as we go along. But we're already seeing some like indirect prompt injection being injected into emails in white space, zero point text or 0.5 font and white that's trying to socially engineer the agents. So we know social engineering people has been going on for a very long time. That's no surprise. Now we're starting to see where these agents are also susceptible to that. And where it becomes a problem is we've even seen agents go so far in some of the test scenarios to modify their logs, basically, like their output summary to make it look like they didn't do the things they were doing, which is kind of terrifying if you think about it.
And the difference between the LLMs and the agents is you give an agent a goal. And it runs through multiple steps, accesses the tools it needs to get to. It does all those things where with an LLM, it's one thing at a time and then you give it the next prompt. Yes, I want to do this. I want to do that. So we're also losing track of what these things are deciding and how they're getting to the decisions they're making while giving them access to some pretty critical things in our organizations. Yeah, it's definitely that Sorcerer's Apprentice analogy comes up a lot with Agentic. So, Catherine, everyone's focused on complex AI security frameworks, but attack timelines can move fast.
Why is remediation speed still the biggest issue in mitigating AI vulnerabilities? And how should IT leaders balance smart automation against real-time attack timelines? Yeah, this is such an interesting one to me because it's the one that's not new, right? Like even everything that Diamond and Eric have talked about so far is a lot newer for teams when it comes to the problem. And so what I mean by that is like AI didn't create the remediation problem. It's just one that removed a lot of the slack. that was hiding this really big problem. Like the gap was always there when we talk about the mindset shift and, you know, teams not wanting to patch because they were worried about a patch breaking something, right?
Like we still see customers that are in that mindset and AI and a lot of the announcements around the release and the volume of vulnerabilities has just kind of skeletons in the closet are coming out, right? Boards are more involved, executives are more involved in. our risk tolerance our customers risk tolerance and you've got those two curves of disclosure volume right uh roughly doubling or more than that over the exact same period the remediation got worse and so we all know we all know the bad or kind of the scary and so i think when it comes to focusing on those basics it's It's just refreshing to see teams starting to take that problem a little bit more seriously.
And, you know, I think the thing to be careful of here is there's a version of the conversation that kind of overclaims. And what I mean by that is like AI is generating large amount of these vulnerabilities, the discoveries we just talked about, and automation is getting brought up more and more as part of that, which I love. Right. But I think we're jumping the gun. and ignoring the basics of teams are trying to automate the decision, which I don't think is step one, right? Like we're just not there yet, especially what I just mentioned of so many teams having to undo this massive risk tolerance of not wanting to remediate or not wanting to patch or having SLAs that are just far too long with that shrinking volume or shrinking window of vulnerability exploit.
And so I think what should start being automated is the low hanging fruit of execution, right? once you decide what needs to change, we should have automated reach and effect of that actually take effect on the endpoint. And so it's still going to involve, or it's simple to say, it's going to revolve a lot of like playbook and process changes from Teams. And so I think the one thing I'd offer is... know, the security posture isn't necessarily your patch compliance percentage and you have to spray and pray and do everything. People are getting a better idea of what the risk is. Now it's just a matter of how quickly you can change and prove that change on your endpoints.
Yeah, and I really like that analogy there about the slack, you know, and the way that's sort of removed by things happening at machine speed, really sort of revealing those gaps. Let's move a little bit into some governance and risk management, Zero Trust Blueprint. So, you know, as agentic adoption accelerates, governance cannot be an afterthought. It has to be built directly into the IT operating model. So, Michael, when organizations attempt to build an AI risk framework, they often end up creating a standalone silo. How can IT leaders launch an effective AI governance committee in, say, 90 days that connects AI risk directly into existing cybersecurity, privacy, and enterprise risk models?
Sure. Now, that's an important topic that I've been discussing with a lot of our customers and other CISOs around the world, is really how do you stand up this program and really work at the speed that the business wants it to work at? As the panels really eloquently pointed out, there's a lot of new and novel risks like Diamond and Eric were talking about. And then there's some examples of existing risks and security programs that Catherine mentioned that we have to look at. So it really impacts both existing risks. and security concerns that we have. And then you need to blend the new risks and security concerns that are coming up because of the adoption of agentic AI and LLMs.
And so one of the advice I give to companies is you're managing technology risk. Technology risk isn't new. It's always been there. And if you look at guidance frameworks like the NIST frameworks or ISO, The NIST AIRMF specifically says that the AIRMF should be an extension of an existing risk management program because in order to be fully effective in building risk against AI projects and programs, you have to understand risk management. You have to have a program of assessing risks. identifying the risks themselves with mitigating measures and attaching to proper controls and monitoring. And so it's important to really look at that. So look at the existing program you have.
Most notably, I've seen a lot of our customers look at the NIST CSF. They look at ISO 27001, and then they extend and add the AI specific and related risk management programs and controls to it. Data guidance is a product at OneTrust that we provide that has a team of attorneys and experts look at the frameworks. And what we found is if you are adopting the NIST AI RMF, for instance, and you already have the NIST CSF implemented, you have about 39% of the necessary controls implemented in the system. There's a lot of overlap. from an existing security program that you can leverage and use. And those programs will be more familiar with your team members and the company at large so that you're able to identify and manage the risks that you're very familiar with, the cybersecurity controls, your third party risks.
the risks for data privacy, all those things that you're already managing, and then layer on top of it some of the newer risks and controls that you need to implement to manage AI and the AI-specific situations because there are some very new risks and there's a lot of new controls that you need to put in place to really manage those. But taking some familiar processes so you're not having everything new and building on top of that into a single program is where we're finding the most success. I was at a conference a couple months ago, and one of the takeaways was if you have a fragmented risk program, so if you have one for your existing cybersecurity and IT risks, and you have another one for AI, you're going to have fragmented decision-making.
But if you incorporate that into a single view, you're going to be able to have good, consistent evaluation, and then you'll be able to make good, consistent decisions amongst all the teams that have to participate in that risk management program. Because again, it's the cyber team, IT teams, third and fourth party teams, as well as the AI and data teams. So everybody on the same page will lead to a much easier route in standing up a program in the next 90 days. Yeah. And, you know, just sticking with you for a second, Michael, you know, how can CISOs prioritize risk based on business impact and measure true, you know, governance at scale using concrete metrics like?
policy coverage and control effectiveness rather than just counting inventory use cases right now the speed of adoption the promise of the efficiencies that you're going to get uh on the back side as well as the new profit making or acceleration of revenue that you could get by adopting customer facing ai technologies or releasing products with ai in it is very, very attractive to companies right now, and they want to move really fast. So I've CISOs that have asked me, hey, the CEO or the board has asked us to speed up the implementation of AI technologies. How do I do that and maintain that I'm mitigating the risks that we're identifying and making sure that we're responsibly building these things?
And so to do that, I've seen a shift in maturity. So most companies, if you ask a few years ago, were really trying to ensure that they complied with certain frameworks. You know, PCF, they're taking credit cards. Maybe they have a NIST or an ISO or a SOC 2. They have the normal, you know, compliance mandates that they were tracking. And they would do that in IT and then people would get the assessments and they would answer them. But it's, you know, almost like a nuisance, right? It's a cost of doing business. What we're finding is, is that shift towards a more business -aware risk management program. where you're able to understand what the top-down risks are.
So if you think about a 10K, a lot of publicly traded companies have risks I've identified. They've had identified risks around third parties. They've had risks around cyber. They've had risks around the products and services they provide and whether they are compromised in a way that hurts the bottom line. Those risks need to be evaluated and understood and then communicated down to the IT risk cyber. data teams so that they can build their programs that also provide guidance and feedback so that the top-down risks and the bottoms-up risks that the teams are doing every day come together and tell a full story. And so typically, the first step is really looking at the process or system risk assessment that you have.
So a good example would be if you have connected devices that your company sells. or you have applications that customers use to make purchases, or any of those components, you should be able to run a risk assessment before you start that project to identify the data, the assets, the systems, third parties, relevant regulatory requirements, AI models that the team might be building or buying, and the data that's going to go into it. Have that bundled in a way that you can run a risk assessment against to understand the importance. the monetary value of that project and then the risks associated with it and quantify those risks so that you can really understand the true picture of the benefit as well as the chance or the risks that you can have or that may occur and then how are you going to mitigate those whether the mitigation mitigating program is a framework or a security control what that would look like, and how are you going to continuously monitor that to ensure that you understand in real time whether your mitigating measures are properly implemented, whether they're working, and if not, what does that mitigation program look like to identify and then fix the problem in the first place?
Because, as what Catherine's mentioned before, we don't have that slack anymore. You have to have real-time view in the risks you have identified. the controls that you have put in place, all those measures, and then you have to be able to monitor them and act quickly to ensure that you're mitigating those. With that, you're going to have that ability to have everybody from the CEO down to the server admin understand the real business process, how valuable it is, and what you need to do to ensure that the company is moving forward, but also in a risk-aware, very responsible manner. Okay. All right. Well, Michael, you give us a lot to think about there.
And one of the things you mentioned that I want to come back to Catherine on is about, you know, sort of the risk management and sort of new elements of that. You know, everyone's talking about the need to patch AI discovered vulnerabilities faster. But what about the ones that you don't have a patch for yet? You know, with AI tools now servicing vulnerabilities faster than vendors can ship the fixes. What should IT and security teams actually be doing to reduce risk in that gap when patching isn't even yet an option? Yeah, it's a great question, Scott, because I also, right, just during this panel got done saying how the low-hanging fruit is patching, right?
And that response was around patching. And I do think we are behind there, and it's a shift that teams, security teams are having to make. very much in real time like i said for some it's a complete 180 where patching is the exception versus the rule um but also fully aware that at the same time we have to address a gap that's also no longer the exception but it's the default and that's the mitigations that michael just uh you know touched on and discussed and when the patch is not available um and that's a growing trend where um i want to be careful like the numbers maybe i'm using here but even just first half of this year um something like over a quarter of vulnerabilities were showed exploitations for before the CDE was even published, let alone there being.
a patch available. So think about that scale in terms of the race. If we're behind on patching, the CVE hasn't even been identified or labeled, and now the vulnerabilities are how to exploit them is out there. It's very real, these mitigations that we're just talking about, as far as us needing to think about it and take it more seriously. And like I said, it's no longer the exception, but the default. I think what teams should do, and hopefully the more helpful part, not the fear-mongering that we're all used to in terms of the state of the union here, is a few different things. The first one's not the cute answer, and it's the one that everyone on this call, I'm sure, is going to touch on or already has touched on at some point, but enumerate, right?
The enumeration, it's no longer... okay to not know what we don't know, right? Ignorance is bliss type thing. And so making sure that your teams and tools are being held accountable to understand the state of your environment and confidently identify which assets are actually missing required security controls is the baseline, right? So forget about like point in time mitigations, but for your organization, again, I'll use the... old term of risk tolerance, what security controls should be in place as simple as like password complexity to admin permissions right across your environment and things of that nature. And second, I mentioned like patching is critical.
It's low hanging fruit, but it's also only one of the four risk responses. If you look at NIST 840 that we were talking about earlier to mitigate, avoid, accept or transfer. And so, you know, disabling a vulnerability feature or really pulling a management interface off the internet, disconventioning a box that's out of support, right, quarantining, those are all legitimate and teams treat them sort of as failures when I don't think they should anymore, right? It's all part of the mitigation. And then I think to expand a little bit more on what I keep saying mitigation and the part that I think that gets missed is... are telling you actually what to do during the gap.
The vendors are getting better because they have to when it comes to keeping up with AI and what's out there for the attackers to see. There's this underlying theme for me of like holding the vendors accountable, but also trust when it comes to how to mitigate. So just examples of that is like the office zero day, the mitigation recommendation was a registry key edit. Right. Or the recommendation is often to install or to roll back to a certain version, you know, or enabling something like ASMI on the SharePoint tool shell attacks and vulnerabilities. And WSUS bug was disabling the actual server roles and blocking certain ports. So these are endpoint configuration changes, right?
Which means that the capability that closes the gap is the ability to quickly and confidently make a configuration change. Like I said, the term Michael was using, mitigations is one that we're using a lot because it's how we need to keep up with that gap. days or even weeks for these organizations is where we need to start looking. And the thing that I'll use to support that a little bit and hopefully a piece that when it comes to us, like everybody on this call knows that and we can preach it. The thing is, everybody we're talking to that's probably, you know, joining this session also knows that. So how do you get leadership to buy in on, hey, we're trying to change our patch program, we're trying to change our risk tolerance, but now we also need to have the confidence and ability to make endpoint configuration changes, it is a big shift for them.
And so if you look at somebody like Microsoft in their own guidance, they said the registry workaround was something that would prove either difficult was the wording or difficult for organizations to deploy consistently at scale. So that's a vendor telling you the mitigation exists and it's what you should do, but it's probably hard for a lot of people to do. And so that's the gap, right, in my mind. It's the operational gap. It's not an intelligence gap. And fixing that operational gap starts with a few things. People process and I think product are like the three Ps we could. boil it down to we talked a little bit on the people gap right you need to have buy-in from your leadership you need to be sharing right what you're hearing from folks in the industry from microsoft themselves telling you we have a mitigation it's probably difficult for a lot of you to execute on but then the operational gap for product i think is interesting because You know, we're from products.
And I think if your tooling can't support this at a time when some of the biggest institutions and folks on the forefront of the good guys, right, telling you we need to be better at executing this mitigation, it's time to review that tooling, right? Because again, this isn't a problem that humans can actually solve, right? It's untenable, the volume that we have of these patches and mitigation. Looking at, you know, boiling it down again to looking at the recommendations from the good guys, from folks who are posting those mitigations before a patch is even available and understanding in your own program, hey, what's our biggest gap when it comes to, is it a people gap of allowing us to make those configuration changes?
Do we even have tooling that can help us make a reliable, true registry key edit or, you know, uninstall or whatever the mitigation might be? on our devices when the time comes so that we can prove right to our leadership to our boards that we've got a program in place that's able to meet those sla times that are now required hope that helps oh yeah definitely yeah great appreciate all that that context around uh potential moves that people can make and and really paying attention to what the vendors are offering in terms of mitigations before before patch is available um So a critical promise of modern AI is giving IT and security operations their time back.
And we're seeing a major shift toward... agentic NOCs and SOCs to accelerate detection and response. Tim, you've been waiting there patiently next to your awesome giant giraffe. I appreciate your patience. I've got a question for you. So as IT teams look to layer AI agents into their existing IT and observability stack, how do you actually build an agentic NOC that connects data seamlessly across IT security and dev teams without creating chaos? Yeah, I mean, I actually think I would start my answer by rephrasing what we even mean by an agent. Because people come in, like they've built their cloud code agent, or they've done their N8N agent, or they've had their chatbot or whatever.
And they have this perception that they're going to give this thing a knowledge set. And they're going to give it, you know, some boundaries, some guardrails, whatever, and then they're just going to set it loose. Nothing could be farther from the truth. It was just like Diamond was saying. It's not like it's 90% of the tasks that we're looking to automate. If you were to hire a new person for that job, you wouldn't sit that person down and say, think deeply. That's not what you're asking them to do. You give them a list. You're like a list of 10 items. And you're like, do this list in this order. Never do anything different. And maybe between steps like five and six, you'll develop intuition.
And that will be why you're better in six months than you are today. But don't sit there and think deeply. Do this. Right. And that is that it's not the agent when you're trying to automate a knock or a sock or whatever, or we're even trying to talk about giving something autonomous sort of remediation capabilities to sort of follow on what Catherine was talking about to actually take that next step and provide you protection from these zero day type incidents. You're not, it's not the agent we're all thinking about. It's not the agent you're going to sit down and you give a knowledge set and you're going to interact with. That doesn't work. You have to build a workflow.
90% of it is going to be deterministic. Probably 95% of it is going to be, it's scripting, it's tooling layers. And somewhere in there, you're going to insert an agentic decision. and try to replace that intuition that the human, you had asked the human to do previously. And then you don't expect that agent that I actually like to refer to it as a microagent. Don't expect that agent to be something you or your coworkers are going to interface with. It only exists in that. In that playbook, in that ecosystem, it knows what it's going to get asked. It knows what is required of it to output. And that's how you can start to deliver sort of IT level precision.
Because when you roll in to automate your NOC or automate your SOC, you're not looking for... thinking clever insights so much as you're looking for predictability because listen in your sock like we talk about ai agents giving people free time that's not happening in security listen it's nowhere close to that what we're trying to do is elevate right i have seen issues of replacing people reducing head counts in in Knox, but I have never seen it in a sock. We are just looking to elevate people, take the simple tasks away from them that can be automated and get them behaving as L3s when previously they were L1s. They're still fully tasked, but they're doing more high-level cognitive work.
And it comes from cutting the processes up into small deterministic or, excuse me, small achievable sort of micro problems almost, building a workflow and inserting that micro agent in those points of intuition. And you can get a predictable result that way. But it's not the cod agent that people are thinking about. It's not the N88. It's not going to work. Maybe one day in the future, who knows, but it is nowhere close to it today. Interesting. And Tim, sticking with you, what specific architectural criteria should IT practitioners look for when they're deploying high fidelity agents for IT level precision? Yeah, it's really, to me, it's almost less about architecture.
The architecture plays a key role and more about defining the problem. And getting really specific about what you want the agent to do versus what might be a dream scenario from upper management. Like in the case of a knock, we implemented a knock with ultimately great success. It's always this process. It's a roller coaster ride. You think you've got it. You think you're a stud and then you slam into some edge case you hadn't planned out. But there they were really just trying to. respond to effectively you know grafana alerts and then input tickets into jira that their cloud ops will take it that would follow up on right that's a really simple process right to implement that it's really about building the right knowledge set finding that sort of list of 10 items boiling them down to programmatic versus cognitive and then putting together that sort of holistic workflow and then honestly, spending a lot of time with it because it is a roller coaster.
You'll roll in, you think you've got it because you figured out the 80% use cases. There are those 20% lurking in the sidelines waiting to bite you. And you just got to accept that as part of the process. And I think actually falls a lot into what Michael was saying about sort of governance and understanding risks and enumerating stuff. It plays into the process of going agentic as well. Don't be unrealistic about what it's going to be able to deliver out of the box. And I'm sure when you test the new system, when you take it online, the first three things that you hit are edge cases. I mean, it's always the way. And don't like, don't, I did this. I got punched in the face by this issue.
I implemented a Gentix system. I told the customer it was awesome. They turned it on. They moved away their human process. Three weeks later, I was trying to explain why they shouldn't fire us, right? There were edge cases that hadn't been disclosed. And now what we do, I mean, that was back in November of last year. Now we say, let's turn on the agent. Let's run it in parallel. Let's spend some time breaking this system in. They're a new employee. It's one you don't have to pay. It's one you don't have to feed, but it's a new employee and treat it as such. November of last year, that's like, what, 10 years ago? All right. So Diamond, Datadog is actively building agents to accelerate incident response and threat detection.
What does an AI agent actually do inside that response loop that a human operator physically can't? Yeah. Kind of like Tim was saying, we've spent a lot of time taking two steps forward, one step back as we kind of work through what agents are capable of. models getting better, everything like that over the last few years. And we've been working on a variety of these task-specific agents to improve incident response speed, debug issues like an SRE would. And then on the security side, we actually have an automated security analyst as well that does kind of simple first-pass triage across security-related sim issues and a variety of others. But I'll talk a little bit about why parts of this are better than a human and parts of this humans are still better at.
But the simple part, in my opinion, is that a lot of it all comes down to speed of completing a task successfully. And yes, a team of humans can do the same or many times better with infinite time. But our agents have the advantage of being able to run at any time of the day without getting tired so that 3 a .m. pager alert doesn't bother you. It bothers them instead, and they don't mind. They're not cranky in the morning. They don't lose some sleep. They don't lose time on the task that they were supposed to be doing the next day. And for me, I get groggy when I'm woken up in the middle of the night. I get groggy if I'm trying to juggle a few different things.
That's not really a problem for these agents. And on top of that, they can look at all permutations of a problem quickly. They can scour your system, look at logs, metrics, traces, all the fun stuff that we have available. And yeah, they aren't quite as smart as a senior plus human. Many of you, many people on your team can do these jobs a lot better if they have the time and they have the focus. But you have this army of them running around that can uncover issues quickly. And they might find things you haven't seen. And they usually do so a lot faster than you can for the gnarly but not completely novel problems that you run into. So that's really where a lot of it comes down to.
Saving time, saving effort. speeding things up and kind of cloning your expertise many many times over and until we out how to do that with organic humans, these are probably useful for that thing. Okay. I love that framing of gnarly, not novel. That's a really interesting way to think about it. All right. Well, to wrap up our technical discussion, we want to look at where IT infrastructure is headed over the next 12 to 18 months as multi-agent ecosystems become standard. As we were talking about from the November example, I don't know that anybody can predict what's going to happen in 12 to 18 months, but let's start there. So, Eric, KnowBe4 has been leveraging specialized security agents like ADA for years.
For IT departments looking at a market flooded with new agentic vendors, how can they distinguish between mature, safe agent implementations and risky market hype? Yeah, I think a lot of it has to do with, you know, if you think about it, the agents and stuff, they need some background. They need to be trained on something that's good, that's quality. And a lot of these newer ones, unfortunately, the data that they're training on isn't all that extensive. And, you know, to plug no before, again, we've been doing this for a while. You mentioned, Scott, like 2018, we started playing with AI in there. We've got, what, 15 years worth of... experience with human behavior.
And so we're using that to leverage that. I think that's an important thing to look at when you're talking to somebody about, Hey, you know what? These agents look pretty cool. How, what's it been trained on? What's the background on it? What does it already know so that I don't have to kind of start from scratch? And I love the talks that we're having, like, you know, with Tim and You know, these things right now, you don't just plug them in and go. And I'm a huge fan of agentic, right? I have N8N running here. I love that. I've played with Hermes. I've done a lot of that kind of stuff, but you don't just plug it in and go, hey, go do your thing. And it knows exactly what it's doing.
That's going to take time to build up. We're going to have to gain confidence with that. And I think the other thing you want to do is anytime you deploy agents within your organization, you want to be monitoring that. And Tim mentioned running in parallel. I think that's very important, especially. as you move into this to see what it's doing how the decisions compare to the human but also you need to be able to put a human in the loop in those critical decisions it's going to take a while to trust these and unfortunately you know we we don't always have a long time to trust these i love the approach that our goal is to go in and take out the low hanging fruit right we want to triage some of the stuff so nobody's spending all that time triaging all of this garbage that comes in We create more and more data, more and more log information, more and more alerts every day just by the way the technology grows.
And we need to make sure that these things are able to keep up with that and the throughput that's going to happen with that while still making the non-critical decisions but having a way to pull a human in the loop to make those that are especially scary. And I love the approach of not just monitoring you know, inputs from agents, but also what are they doing? Because there's all these novel things, because there's the ability to social engineer them, to do all this kind of stuff, we want to be looking at what are the actions it's taking. And if it seems like it's an aberration, we want to be able to throw in a human in the loop to go, hey, did you really mean to wipe this whole database?
Like, is this really cool? And I think that's an important thing that we have to think about as we're... deploying these agents and for organizations that are creating agents, we have to consider that side of things. And it's going to be an interesting ride, man. This is all kind of new. We're all hanging on, right? But we're going to see these novel things. We're going to have to be prepared for that kind of stuff. And I love what Catherine was saying about mitigations too. I want to go back to that because patching and mitigating are two different things. A patch can be a mitigation, but there's a lot of things you can do to hold on to your patches are tested and all that stuff instead of leaving the door wide open.
And I think that's an important distinction. And I just want to say kudos on that, Catherine. That was a good thought there. I appreciate that. All right. Excellent. Well, we've got... Two more questions here, and I'm going to open both of these up to all of you guys. So at the risk of PTSD, you know, now that we're back in school season, I'm going to put you guys back in school. If you could raise your hand, if you have a point to make on the question, just go ahead and I'll call on you just so we're not all stepping on top of each other. But, you know, so the first one, enterprise collaboration isn't just human to agent anymore. It's human to human, human to agent, and agent to agent.
Which of those three interaction models is the IT industry least prepared for today? And why is locking your enterprise into a single favorite AI model a strategic mistake? Anybody want to grab that? Tim, I saw your hand first. Yeah, I mean, I have a lot of thoughts on it. Certainly agent to agent is the one that leads to the Terminator movies. That's the one that leads to the scary outcomes. I don't know if emotionally I'm really ready for it. You know, in the context, though, of true enterprise, what's achievable today, what I see people moving towards is actually fundamentally changing their interface, which is connected to this topic. Instead of sort of coming into my tool natively at Strike 48, what people are generally doing is hooking up their workflow agents into their Slack and are actually like...
with them as though they were Slack employees. And it's a really sort of fundamentally cool way to interface with the program because you need to conceptually change them, if you will, from a tool to almost an employee. So that's what I'm seeing a lot of that sort of connects to this topic. But agent to agent is definitely the most scary to me. Interesting. Who else? Diamond, go ahead. Yeah, I'd love to follow up on the agent-to-agent part. It is the most interesting one. Not sure of scary yet, but I mean, I'm sure you've all read the Hugging Face Hack paper from OpenAI, right? I found it to be interesting. I think there's a lot we can do there to improve it.
And I think it's like a great example of where we've discovered something new. Agents are talking to agents on their own message board, effectively. And that means there's a chance for some new products here too, some new software. We're selling Slack to humans. There's some sort of agent-to -agent communication product missing here, ignoring the security and other concerns here. But I think it really means there's a lot to think about for any of these teams that deploy agents on how do we control these things appropriately for talking to each other, but how do we also enable it? So I think there's a lot of cool stuff to go on. And I'll try not to, I'll try to be more optimistic than scared at the moment until we see more of these come out.
You just get, I mean, literally it's how the Terminator started. Just watch the end of the series, man. I never watched the ending. Don't worry. The beginning is pretty good though. And Eric, I saw your hand and then Catherine will go to you after. Yeah, I have to agree. Yeah. The agent to agent thing is, is probably the scariest thing that we got going on here, but there is going to be a very interesting way that the, the human to agent. kind of stuff happens here. And the way that I picture a lot of this going, at least in the world that I'm in for the most part, is I expect pretty much every employee in an organization to have an agent within a year, year and a half that's going to be connected to their email, connected to their Slack, connected to all of those sorts of things.
And people within an organization are going to be able to send a message to that person and the agent may be able to respond, you know, like, hey. What time is this meeting today? And then the person doesn't have to stop and respond. The agent just goes, oh, it's at dah, dah, dah, dah, dah. Or what's the latest on this? You know, the agent takes care of it. The person doesn't have to look it up. It's that trivial kind of work that's going to happen. But what I think is going to be interesting is, are we going to be identifying in those reactions or those discussions that you are talking to the agent, not the person? OK, we know AI makes mistakes. We know that it makes mistakes with confidence.
If you've ever done the whole games on chat GPT like a couple of versions ago, asking it how many of the letter R is in strawberry, it will fight you to the death with the wrong answer. Right. And so that's going to be an issue that I think we're going to have to think about with this. And that can be just as scary if it's giving you the wrong information and the person has never seen it. Maybe they got a phone call or a text that said this has changed. You're not going to know that that may not be the authoritative source unless we start labeling that somehow so people know where that comes from. I think that's going to be a very interesting interaction that we have between the humans and the agents.
And it's going to be here before we know it. I mean, people are already rolling this stuff out right now. And this is all part of the fun, man. Catherine. I just, I mean, when you asked the question, I had like an interesting thought process. I figured I'd just speak out loud, see if it's helpful to anybody. But like initially my thought was, well, human to human has had decades, right? Like we know human to human, it's really the biggest thing that we have controls around, we have experience with. But then that thought kind of formed into, I feel like something that we might not be. talking about as much or speaking about is how human to human is going to change with, you know, with the introduction of, of AI.
And, you know, what I mean by that is there's definitely, there's definitely the security side, like the vishing, are you actually talking to a human, right? And everything we've seen there, as far as security controls go and, you know, leaks, people are wiring money because they thought they're speaking to lawyers and companies that their investment funds and, you know it's no longer just the gift cards that we have to gift card phishing schemes we have to worry about right so there's a security layer to the human to human that's that's changing and i think we are aware of but kind of this effort stopped being a signal is an interesting one for human to human too um And so I think better understanding roles and responsibilities now that we've introduced human to agent and agent to agent is going to be important.
How we quantify impact and effort, right? And even like driving our own individual careers when we think about folks in IT and security. Like there's a whole layer to human to human that I feel like is a separate rabbit hole, but just one I thought I'd call out. Excellent. Yeah. I'd like to take us home real quick because one of the things that we've had internal discussions with is How do we use the agents to actually manage or govern the actual agents? Because everything we're talking about has the motions moving so fast that there's no way in the world that humans or any person or organization or group could actually monitor all these activities.
And so beyond the risk, which I do feel agent to agent might be the biggest one. It is a conversation on how we can have agents actually help us govern because of that speed and complexity that we honestly may not even be able to contemplate yet, but it's going to happen. Yeah, if I may real quick, Scott, that's actually an approach we're taking to know before. Like everyone knows us for our security awareness training, right? That's 90% of what people know us for. But again, we've been dealing with agents and Agentech for a while. And we have a product called Arm. It's agent risk manager. And that's exactly what it's designed for because we're working at machine speed here, not human speed to your point, Michael.
It's way too fast for us to stop all of these things. We need agents monitoring agents. And I don't know how far down the rabbit hole that's going to go. Do we have an agent monitoring the agents that are monitoring? I mean, at some point in time, right? But I think that's the very important approach. And I love the way that they're doing that. the monitoring of the agents as well. All right. Well, so to close us out today, if there's one key takeaway or action item that you want our audience to implement in their strategy tomorrow, you know, what would that be? And Michael, you gave our last answer in the last one. So I'll ask you to go first here on that closing thought.
Sure thing. Again, when you're looking at your programs, it's unnecessary to fully reinvent the wheel. Find the program that you have today that people are familiar with, that people understand, that the groups have a full understanding, and expand it out and make sure that you are extending it. to the AI adoption challenge that you have at your company or, of course, the incoming or security risks of AI that are coming into you. Because a little bit of familiarity will help you expand your program faster because they're going to have to learn a lot of new things. And we don't want to have to throw all the baby out with the bathwater. But just the expansion or the extension will help make that program stick a little easier with your organization.
And hopefully it will lead to reduced risks and you'll have less regulatory findings and challenges as you go through this AI journey that everyone is doing. OK, excellent. Catherine? Yeah, I mean, I think key takeaway and action item. One thing that I think is I love about talking about the low hanging fruit, the patching, the mitigations is improvement is so quantifiable. like it is black and white. And that's the advantage of being foundational in terms of your security posture and process. So even at Automox, like part of the operational blueprint we build for customers is you could decide what you want for the scale. But I think just in the lens of this panel, like pick and identify, I should say first and pick your three highest risk software titles, time yourself, right?
How long from the decision to make a verified configuration change or a mitigation to actually enacting that change, does it take on every endpoint? And whatever that number is, that's your actual security posture. That is your risk tolerance. It's not just a percentage. And it's something that anybody can run. This week, it is a small pool set for sure, but it helps open those conversations on next steps of we don't have the tooling to even identify or we don't have the tooling then to make a configuration team and the change and the timing that we're happy with. Building those operational blueprints, like I said, is critical. It is quantifiable. And the other reason I love that is it's a good point to pat yourselves on the back and show off a little bit.
That's the human element of you had the impact on reducing your risk by X amount, by reducing that time to remediation by X amount. So lean on those quantifiable metrics for your program and take it from there. Okay, excellent. Eric? Yeah, I think when it comes to this, I'm kind of thinking like organizations really need to consider the fact that it's here. Agents are coming. It's going to be included in a lot of our stuff anyways. I mean, if you've opened a browser and it goes, hey, you want to enable or hey, this is enabled, right? This stuff is coming. It's there. One of the things we have to do with the agents is we have to understand that people are going to use them.
And we need to understand how to control those permissions that are assigned to those, what it can do, what it can't do. And I hadn't really talked about this much before, but managing those NHIs, those non-human identities is going to be absolutely critical with this stuff. And I want to make sure everyone's thinking about that. identity management is tricky as it is sometimes. And now when we start rolling in all these new NHIs that are attached to people that you don't necessarily want them to have the same permissions as everybody else, right? You don't want your email bot to be able to access shares over here and files, okay? So that kind of stuff has to go in our minds and we have to think that through as we're deploying this stuff and as we're putting it out.
Use those considerations. Just consider that, think about that because it may save you in the long run okay all right excellent uh diamond yeah my main point is more about the product side of it um don't assume where we're at today is where things are going to be in a few months you should be building to where the puck is going that's autonomous agents that work for you without human input and that requires you know the right visibility eval security that people have mentioned to get ahead of it But you should be heading in that direction. And it won't be easy. And a lot of times people are thinking about ways to fall back to humans in the loop, to fall back to humans as kind of a double check.
That's not your answer. You should think more about what it really means to automate more and more every day, faster and faster. All right. And last word, Tim. Yeah, I mean, I agree with Diamond there. I basically say, hey, it was my... final comment is, guys, just get started because we can sit here and talk all day long about the risks of going agentic, all the things you have to do. You're going to get it wrong. You're going to mess up. You're going to look like a fool. I know it's all that's happened to me. But think of what you're going to look like in a year from now if you don't. follow this route, if you don't adopt, if you don't move forward, trying to explain to your CIO how your plan of remediation response was to compete against an agentic adversary with human speak.
It's just a non-tenable argument. You've got to get in. You've got to move forward because the attack vector is now agentic. We see organizations getting hit and then swept like that now. The idea that, hey, you were waiting until the technology was really good so that you could then implement it, it's just not a viable position. So you got to start somewhere and recognize you're going to get punched in the face. But, you know, that's the price to really get good at this stuff. All right. All right. Yeah, great closing words. You're going to get punched in the face. You might as well do it now rather than later on, right? All right. Excellent. Well, all right.
All right, everybody. Well, we're just about out of time. I want to thank our incredible panel, Catherine, Diamond, Eric, Michael, and Tim. Thank you all for sharing your time and your technical insights with us. Really appreciate it. Thanks for having us. Thank you. Thank you, Scott. Wow. Well, what a day it has been. I wish we didn't have to start wrapping things up, but it has come to that time. So a reminder, again, your homework assignments await your chance to learn more and expand on what we've learned about today. Go explore that Docs tab for more takeaways and handouts to follow up from our speakers and bring this discussion into your team. Now, also, you will receive a recording of the session so you can rewatch any segments or so you may share the session with your team, colleagues or friends who would benefit from this discussion.
And we do have one more piece of excitement here. Our prize winner of $250 who is here live and present with us today. is Lisa Chubbuck from Colorado. Congrats, Lisa. We're going to follow up with you after we wrap. Well, on behalf of the team at Future B2B, I want to once again thank John for an excellent keynote discussion with Susan and to the panel, people who joined me, Catherine Diamond, Eric, Michael, and Tim. and to Automox, Datadog, KnowBe4, OneTrust, Strike48, and Wiz for making this all possible. And of course, a big thank you to all of you for taking time out of your day to come and join us. I hope you've all gotten some interesting ideas and tips, and maybe you're feeling inspired to bring some of these ideas into your environments.
Have a great day.