a16z Podcast - Building Defense for the Agentic Era: Kevin Mandia

Episode Date: October 6, 2026

a16z General Partner David George sits down with Armadin founder and CEO Kevin Mandia to discuss what happens to cybersecurity when attackers can operate at machine speed.After 30 years in security an...d building Mandiant, Kevin says AI convinced him to get back on the field. He explains how AI changes the economics of cyberattacks, allowing attackers to probe thousands of paths simultaneously, and why that means defense will ultimately need to become autonomous too. They also unpack Armadin’s approach: continuously attacking customers’ systems with AI to find exploitable vulnerabilities before adversaries do, then building toward autonomous defenses that can respond in real time. Kevin shares what Armadin has learned from finding more than 90 zero-days in production environments this year, why humans can’t remain in the detect-and-respond loop, and how the entire security stack could change over the next few years.Resources:Learn more about Kevin Mandia and Armadin: https://www.armadin.com/team-members/kevin-mandiaFollow David George on X: https://x.com/DavidGeorge83Learn more about Armadin: https://www.armadin.com/ Stay Updated:Find a16z on YouTube: YouTubeFind a16z on XFind a16z on LinkedInListen to the a16z Show on SpotifyListen to the a16z Show on Apple PodcastsFollow our host: https://twitter.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Transcript
Discussion (0)
Starting point is 00:00:00 You don't have a defense on this, you have a great offense to go up against. You want to be the Baltimore Ravens defense at 2000. You kind of want to have your practice offense really push you. That's what Arminan's going to do. We're going to be the All-Star team on offense coming at you so you can train your defense with what we're doing. But you built Mandia, a great success. Why did you decide to get back on the field?
Starting point is 00:00:22 I don't want to sit out the AI shift change when I've done 30 years in security and the whole damn things about the change. What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges. This is a tsunami like has never been seen before in security. The whole, let's slow down the models. We don't want cyber risk too late.
Starting point is 00:00:42 The open models are already good enough. Armid in since January this year. We have found over 90-0 days at customer sites, all in production. This is not like rinky-dink companies. Like these are like Fortune 500 companies. The differences are similarities between nationals nation-state attacks compared to AI today and then where you think AI can be in a couple of years. On the defensive side, we're going to say, we're being attacked by these models,
Starting point is 00:01:07 but we're not sure who's behind them. Is it a nation? Is it a human? Is it? Kevin Mandia has spent 30 years in cybersecurity. His view of the AI transition is simple. Everything I did is dead, and then everything else is new. In this episode, David George sits down with Kevin, founder and CEO of Armadon and the founder of Mandiant to talk about what happens when cyber attacks move from human speed to machine speed. Kevin explains why AI gives attackers an immediate advantage, from probing thousands of paths
Starting point is 00:01:38 simultaneously to making less sophisticated attackers dramatically more capable. And he makes the case that there's only one viable response. Defense has to become autonomous too. We also get into how Amidin uses AI to continuously attack customer networks. What the team has learned from finding more than 90s. zero days this year, and why Kevin believes the next two years could remake nearly every layer of the cybersecurity stack. Kevin, thanks for being here.
Starting point is 00:02:08 No, thank you. Okay, so you built Mandia. Yes. Obviously a great success, many different chapters. You know, it ended up inside of Google, ultimately. Why did you decide to get back on the field? It's a good question. And I don't know if I decided it, and that'll sound weird.
Starting point is 00:02:23 But I met with David Slater and with Travis Lanham, the other founders. and Evan Pena, I knew, I could say they started this company. They are the founders. I met them. They had the idea. They pitched me on what they wanted to do. And I saw the talent in them. Travis is a generational talent.
Starting point is 00:02:43 David Slaters, and I mean, it's in a positive way, freak of nature. These guys are really, really good. Evan Pena is exceptional at what he does. And when you meet that team and you talk to them, the whole time I was listening to what they were doing, I was thinking, I want to be a part of this. I don't want to sit out the AI shift change when I've done 30 years in security
Starting point is 00:03:04 and the whole damn things about the change. That's great. Everything I did is dead and everything else is new. But meeting that team and they were starting the company and me realizing, I think I'm a real good fit with these guys to accelerate the need. What Armadon is building every company needs now? And I was like, this team that can build it,
Starting point is 00:03:26 and I think I can answer the. than now. 30 years in security, you meet a few people. Let's go to those people and say, we've built what you need. So I almost felt compelled to do it. I know that sounds weird, but I would not have founded a company again in mid-50s and I was doing venture. It wasn't like, oh, I'm an entrepreneur and I love starting companies. That's not it. And it wasn't, I'm not a VC. I'm just an operational guy. That's not it. I met the team and went, we have to do this. Yeah. I mean, that's really it. Yeah. And this, whole AI change was happening.
Starting point is 00:03:59 Totally. That's the catalyst, right? Yes. So tell us about what Armiden does. So Arminan leverages frontier models and AI. On offense, the test, do you have exploitable risk? And that's what we do today. We call it Armidon Red.
Starting point is 00:04:15 But when we started a company, Travis and David Slater and Evan all knew the future of cybersecurity is going to be, A, the good guys have to build the offensive cyber cannon and shoot it at networks to make sure those networks can withstand these attacks because they're the ones that are coming. But we also knew it's going to be AI on offense
Starting point is 00:04:35 built by the good guys working in training with AI on defense built by the good guys. And you have to have both. So our act one was we got to be the best in the world of finding exploitable risk. If we're five minutes ahead
Starting point is 00:04:48 of the bad actor, whether it be a nation state, criminal, nuisance, if we're five minutes ahead of them, We also recognized our act too, Armidin Blue. We got to stop it. Compensating control, turnicit. And so that's what Armidon does.
Starting point is 00:05:04 We're building the force field you will need in the AI age to defend yourself from AI attacks. Yeah. Tell us about the nature of the capabilities of AI attacks today and then where you think it goes. Great. So the nature of them is, first off, we're getting a weird window in time where we're seeing them, but not at the same level you'd expect.
Starting point is 00:05:26 I've seen nothing like what Arminan's already built in the wild, which is there's 25,000 agents on concert, all working together doing really, really smart things without going on bizarre fishing trips. Because when you respond to an AI attack, you can tell it's AI very quickly. At least I can, because I've thought about a lot of offense, I've responded to a lot of attacks in the past
Starting point is 00:05:50 that were led by humans. Right. And a human goes to point. point A, then to point B, then to point C through their intrusion. AI does little things, like four or five differences, but one would be it'll break into point A, then laterally move to point B. Next, you know, it's trying to break into point A, I guess. You know what I mean?
Starting point is 00:06:07 It's like, I get the drone swarm, but you can probably coordinate and think a little bit better. That's where it's at today. It'll get better and cleaner. But the differences are, first and foremost, the scale of what AI can do dwarfs humans, like in ways humans don't even get. Right. So you have a scaling problem in that. could always find only one path into a network.
Starting point is 00:06:26 Yeah, they had to be selective because they had to devote their limited resources to one direct path, right? Yes. And then so scale is a challenge. Speed, ridiculous. What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges. And then, so what was always lacking is AI creative or effective.
Starting point is 00:06:46 But when it comes to what we do, we don't need the fanciest model. We're not trying to speak 400 languages with our model. and all that kind of thing. What Arminen's doing on offense is we're finding vulnerabilities, exploitable risk. That is code. That's a structured language, a structured process.
Starting point is 00:07:04 Because it's structured, AI is going to be great at it. Right, right? So I really think it's already here today. Like the whole, let's slow down the models. We don't want cyber risk too late. The open models are already good enough, and these things are common now.
Starting point is 00:07:18 It's just a matter of the minute you have anonymous availability, of GPUs, you'll see far more criminal attacks. Oh, interesting. Yeah, you know what I mean? Yeah, of course. Until you can attack anonymously, and it's hard to do crime when people know your name. It's better. If you can commit a crime anonymously, here's my tip for criminals. If you can commit a crime anonymously, that's a lot smarter than doing it with your jersey on, with your name on it. And so anyway, the difference in attacks and what we're seeing now, we're at the precipice, first inning still, of AI-led attacks coming. And I think that's just because of the cost and availability of
Starting point is 00:07:53 the models is not as readily available to a criminal element as it will be in the future. Yes, exactly. Okay, so you, your experience in working in the security industry for 30 years, you probably saw a fair amount of nation-state attacks, right? Every day. Every day. So talk about the differences or similarities between nation-state attacks, and I use that just to say the most sophisticated, most successful, if you will,
Starting point is 00:08:21 types of attacks compared to AI today and then where you think AI can be in a couple of years. So everything's going to change rapidly, right? But I can tell you, nations on offense have never, in my opinion, they've never really been. When you're hacking for espionage and for security reasons, you hack with what I would call kind of a sniper round. You're not spraying and praying. For the most part, modern nations on offense restrict their targeting. and they go deep at very specific things, like 30 defense contractors or dot mill, when they go hard at that,
Starting point is 00:08:59 kind of think of it as that sniper round. With AI, I think it becomes more like a drone swarm. It becomes a little bit different in the cyber domain, and I think even modern nations are thinking, what will our protocol be? If we want to attack this company, do we swarm it and just burn tokens on it? Because AI is going to do a lot of things,
Starting point is 00:09:20 humans just wouldn't. Right. So it's a little sloppier, a little louder, but it's more effective. Yeah, that's the problem. You got it. It's more effective, probably. And so there's going to be so many things a nation's got to think through right now, and their whole doctrine will shift as the AI shift change comes. Like, how does AI change what our mission is? Do we maybe use the cyber domain differently? Do we drone swarm sometimes, snipe around other times? How do we balance the two? Does it depend on risk, target, how surreptitious we want to be? Because right now, AI is not a surreptitious action on offense. Unless you've done a ton of post-training,
Starting point is 00:09:57 you've got maybe a human in the loop really looking at, are we doing smart things? Because if you just go, hey, here's a prompt, hack, ABC.com, AI is not going to do it in a surreptitious, a smart way. And I think even if you ask it to, it's still not going to, until it's been really trained and really had some human influence on it. So, but more generally, what you're going to see is less capable, attackers, less technical, less successful, are going to appear way more successful. It's the
Starting point is 00:10:28 equalizer, right? Because of the boy. Yeah. When you start using models, over time, what it's going to be is on the defensive side, we're going to say, we're being attacked by these models, but we're not sure who's behind them, those attacks. Is it a nation? Is it a human? Is it, and we'll have some clue, but attribution will get a little difficult. So that's a long-winded answer saying in the AI age, it does democratize far greater expertise for attacking victim networks. Yeah. So then that is a good segue back to arm it in. So you have talked about the defense needs to be a great offense, right?
Starting point is 00:11:05 Yes. Like best defense. Got to train your defense with something. Yeah, of course. You got to train your defense with something. And then it needs to be continuous. Right. Right.
Starting point is 00:11:12 So how does the product work? And then how do you get a level of sophistication such that, you can identify and remediate these vulnerabilities, like what you're describing. They're more sophisticated than a basic prompt. Okay, a lot there. I could talk for 45 minutes on it. But first, I can tell you this.
Starting point is 00:11:29 You don't have a defense on this. You have a great offense to go up against. You know what I mean? So even think in sports terms, if you want to be the Baltimore Ravens defense at 2000, you kind of want to have your practice offense really push you. You know what I mean? So you know how good you are.
Starting point is 00:11:43 And that's what Arminan's going to do. We're going to be, you know, the All-Star team on offense coming at you. so you can train your defense with what we're doing. And that's going to be important. And you can't really have a human in the loop in the AIH for tactical autonomous defense. Like you got to do something fast.
Starting point is 00:12:00 You've got to turn and kick the wounds as fast as you can. So thinking back to our, like you want to be able to do it continuously, and that's the complexity. So we do a thing called a hyperattack. And David, that's just a fancy word for we throw a drone swarm of agents at you and we map your network. Every service, every route, every system, all assets. We may end up with terabytes of metadata on your network
Starting point is 00:12:25 from this hyperattack. Done super fast. It lights you up. So that way we can now, it's almost like a metadata twin of what we can see. If on the inside, do the same thing. Let's just map everything. This is the attackers of view of your network.
Starting point is 00:12:40 But with that metadata, we now just pull you almost like a heartbeat. What's changed? What's changed? That's continually looking for. did a app change, did a route change, did a service get updated, did a new machine get presented onto the,
Starting point is 00:12:53 you know, into the target area so that we can pull cheaply for change and then attack the change. What you really want in the future in the AI age is you want the constant pressure of models attacking you, but you can't do it all the time because, A, it's not, it's cause prohibitive,
Starting point is 00:13:10 but B, it's unnecessary. You do it when either the threat changes, hey, new models come out, new intelligence is available, or B, your network changes. So you want to test whether that happens. And then C, you probably just want to test. We have a board meeting tomorrow.
Starting point is 00:13:25 Let's see how we do. Yeah, exactly. Yeah. It's audited ourselves and see where we're at. And that's what we had over the weekend. There was a zero day and a popular product. And immediately, we've already got the heartbeat. We just polled who's got the problem.
Starting point is 00:13:37 Yeah. And our goal at Armid in is to go from, you know, common vulnerability or CVE to a, we can find. if it's exploitable or not before bad guys can. Right. You know, and not all bugs allow for human access to your system in a stable way. So not all bugs are created equal, right? And so we want to make sure, hey, this one is one you really need to worry about
Starting point is 00:14:03 or which ones don't give remote command execution. So long story, made sure that that hyperattack, that metadata that we get allows us to kind of pull for change and attack you when your network changes. And that's the best you can do for continual. And we'll get better and better at it. and the cost for the polling will go down. You know, it's on small networks, it doesn't cost much. But on a network that changes all the time and it's very large,
Starting point is 00:14:25 you'd be polling it quite a bit to make sure you don't have an exposure window. Yeah, of course. Yeah. So that is actually a very good explanation for why this continuous approach matters. Right. It's so fun, like, you know, you and I share it. Well, you're already up against it. Somewhere out there, the criminal element will always have that random scanning,
Starting point is 00:14:42 and they probably aren't even using AI for it. They've got one exploit that they think works, and they're just kind of scanning the world for it and then coming at the exploitable risk, you know? And so you're already getting some pressure on your network from an unseen force that's not well-intentioned, you know what I mean? So you might as well have a better force built by the good guys, constantly putting pressure on you.
Starting point is 00:15:05 Yeah, it's interesting. So you would kind of, arm it in, I don't know, a year ago, would probably be placed in the category of pen testing. and you and I share history and relationship with George at CrowdStrike. Right. And so they famously redefined the category from AV to EDR. And of course they did it. Right.
Starting point is 00:15:23 But the category redefinition was on the back of major infrastructure changes and product changes, you know, and allowed them to create a product category that was far greater and bigger than AV. Talk about pen testing. What is the historical view of pen testing and why that's not what the future is? Yeah, a couple of things. I mean, you had to do it, right? It was kind of like first-gen A-V. You have to buy A-V.
Starting point is 00:15:47 And I think when you look at Armidon, we will be as ubiquitous as A-V because you have to have that AI force field of AI on offense, training, A-on-Defense. You have to do it, and you can do it, so why wouldn't you? And so you look at that, and it's pen-testing to me
Starting point is 00:16:05 is always just scanning for what's already known, and it doesn't prove whether you're really exploitable or not. Right. So it's always created a larger list volons that don't matter. Right. And so the way we wanted to do it at Armaden was we actually can carry the exploit out. We verify so there's no false positives.
Starting point is 00:16:25 We can get remote code execution or get data off of that machine. And a lot of Penn tests are nothing but hit your infrastructure, not with a thinking learning technology that memorizes and knows your infrastructure like an AI agent can. So it's not going to do custom apps. It's going to, at least the old versions of pen testing, you know, the Tenable, the Rapid Seven, the Qualis was more a hygiene sort of thing. Right. What do I have out there and what services are exposed and are there CVs available against
Starting point is 00:16:54 their services or no unexploitable vans against them? When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time. And it's like all I can tell you is arm it in since January of this year. year in 2026, we have found over 90-0 days at customer sites, all in production. And by the way, your customer base is like they're happy we found them before someone listed. And they're like fortune, this is not like, you know, rinky dink companies. Like these are like Fortune 500 companies.
Starting point is 00:17:29 Yeah. And I don't mean that as fear and certainty and doubt. But the difference is that we've trained our models, we post-trained all our models with real red teamers, real folks that actually can develop exploits. And that's important. And So when we're scanning networks, we don't have source code to review. We're not finding these zero days with source code. We're not finding these zero days because we can log into an app and now we have access and we can get to other things. We are black box coming from the internet over 90 zero days in major software companies.
Starting point is 00:17:58 And they're thankful. And so everybody's like, wow, mythos came out and you scan source code and find vulnerabilities and you find thousands of them. That's noise. Yes. We're coming from the outside and then we're calling a CISO, you know, usually. you within 48 hours, hey, we've got remote code execution in your DMZ, and usually from there we're getting in. And they agree with us. And they, and the nice thing is we're going through,
Starting point is 00:18:23 you know, the fixed side's a little bit harder, takes a little bit longer, but those companies go right into incident mode. They respond as if it's an incident. And that's not a pen test. That is like a real adversary coming at you. And the difference between red teaming and pen testing is pen test to me is a hygiene step. And I think over time, everybody would have red teamed everything all the time if they could. Right. It was cost prohibitive and people prohibitive. With AI and an agent doing it, or in our case, we have lots of different types of agents doing different things. You can now do that. So I think it will replace pen testing over time. Yeah. That's just, that's like a small portion of what a red team coming at you would do. Yeah. So you talked, you mentioned,
Starting point is 00:19:10 earlier, you know, obviously that's arm in red. Yeah. You mentioned Armid and Blue. Talk about Armid and Blue. The Armid and Blue is like, we can't, David, just show up and say, hey, you know, you're vulnerable, see you later. Right. And, hey, the true North for every CISSO should be effective autonomous response.
Starting point is 00:19:27 We got to build that. And we knew all along, you can't just say, hey, we want to be the best reward at finding exploitable arrest. That's goal number one. But then goal number two and be the best more of doing something about it. And that means arm it in blue. And arm it and blue will be take the information about exploitable risk and work with the defense plane,
Starting point is 00:19:50 whether it be endpoint EDR or firewalls, and create compensating controls at speed. Yes. So that if we find an attack five minutes for someone else using a model finds an attack, you're already safeguarded. And these safeguards are going to be rudimentary potentially out of the gates, right? Over the next few months, year from now, they're just going to be there. Yep.
Starting point is 00:20:09 Because the whole cyber domain is progressing at a speed where you're going to have to defend autonomously for better or for worse. You know, I'd rather have a bad patch stopping a bad guy from getting in than have an intrusion. Right. You know what I mean?
Starting point is 00:20:26 So you've got to take your lesser of two things and one's much more manageable. You never want an unknown person with arbitrary access on your network. Yes, yeah. And so you want to prevent that anywhere you can. And I would say the first generation is we're working with Kraustrike on it, and they know it has to exist. We're working with Pan on it.
Starting point is 00:20:44 They know that it has to exist. They want to all, you know, shift into the AI age with autonomous defense as well. And so we need to inform those defense platforms, you know, the Fortinets and everybody else. Here's what you can do about it. And I likened it to, you know, kind of field dressing and more. Someone gets shot. You patch it up, but that's not the hospital, you know. Yeah, yeah.
Starting point is 00:21:07 say, hey, we kind of stop the bleeding. And but then you've got to maybe do something else with more time in humans, potentially, or even, you know, agenic approach to it down the road. So you're going to see it happen even if you're a CISO, you're going to see autonomous defense happen even if you don't ask for it. Right. Because of the defensive platforms you've already invested in. Yeah.
Starting point is 00:21:27 You mentioned earlier, you know, some of the blurring of the lines of different categories within cyber. And I think you joked that your old days, your 30, you know, your 30 years of experience is out the window or relevant or something like that. What is the future of the SOC? And then how do the categories, how do the categories within cyber blend together or change? You know, if I'm a SISO, I do believe my True North is effect of autonomous security. You want to keep your best people engaged. You want to automate the processes that work for your organization. but you are absolutely saying what survives in the AI age and what doesn't.
Starting point is 00:22:09 Right. And I think we're still working through that process. I think there's whole processes in the SOC that will just go away. And for whatever reason, we're automating right now. Yeah. You know, over time, I can tell you this. If you have humans in the detect and respond loop, you're going to be too slow. Yes.
Starting point is 00:22:27 You know what I mean? It's just not going to work well. So you have prevent, detect, respond. Prevent is going to be governed by AI. and detect and respond is going to be done by AI. And the goal in cybersecurity has always been, if you have, you know, you want to prevent. Yeah, of course, yeah.
Starting point is 00:22:41 You don't want to detect and respond. So I just see the constant narrowing of the window of every phase to the point where, you know, we're really not doing a lot of detection and response because the window to do it is almost, you got it. It's a little bit too fast. So, but you still got to have that onion peel to some extent of systems, backing up systems,
Starting point is 00:23:01 and assuming failure somewhere. Right. You know, like even Armidon creating in the force field, sooner or later somebody is going to get around it. Someone's going to create an exploit before we find it somehow, some way, on a platformers or an app that we just haven't assessed yet. It hasn't been in production at a customer site. And so we haven't looked at it. And someone else finds it. And when they do that, you will want to have a trap behind saying, we've got unauthorized access or unlawful access to a system.
Starting point is 00:23:29 Those traps are that did you? just can't have a human there. Yeah. I mean, it's just going to, because we've already done it at Armadon, and when we break in and have a gentic-aware internal command and control, it proliferates at a speed that is shocking. You know, like, I remember as a human, you're like typing on your keyboard. I want to go laterally move with this passphrase from here to here, and you're so slow and
Starting point is 00:23:52 you're doing one thing at a time. This thing just does a thousand things at once. It's just everywhere. And you're like, whoa, okay, done. Yeah. So the, so the, each one. one of those steps of the process has to be automatic. It can't be a human loop.
Starting point is 00:24:06 Yeah, it's as bad as this. I mean, I don't have great analogies. It's like the balloon popped, you know, so he gets in. It's just like, they're gone. Your whole defense apparatus just popped. So you got to get prevention right. And then an immediate lockdown on detect and respond, however you want to. And there's always gray areas between those phases.
Starting point is 00:24:24 Because people say if you detect and respond automatically and fast, that is prevention. Yep. So all of it's going to change. Every sister's examining it. every vendor's examining their role in changing into the AI shift. And so it's going to all change now, but I can't tell you if anyone's positive on how it changes. They're examining their workforce. They're examining their headcount.
Starting point is 00:24:45 They're examining their processes, meaning the Sissos are. And they're saying, what do I need to look like in the modern era? But it's too soon to tell where it lands. Yep. So too soon to tell what they look like, what their defense apparatus looks like. maybe so you have a bunch of Fortune 500 customers you're close with a bunch of others that are not customers like what is the state of their vulnerability today rapidly shrinking you know everybody's worried there's a desperation in a moment in both directions by the way if you're on offense in Iran or
Starting point is 00:25:19 Russia you have a desperation in a moment of getting now yeah could get it get it now while you get it now while you can't you got it and if you're on defense you're of a desperate uh you're desperate to patch every window, you know. And in fairness, both sides are accurate in their desperation. I mean, because we have near-term pain in the AI age that it advantages offense, right? So that's fine.
Starting point is 00:25:44 That's just the nature of it. But both sides recognize it's for long-term game. Meaning AI on defense, being trained by AI on offense, and being autonomous is gonna do a far better, more diligent job than humans peering at packets, you know. And so we're just going through the window of exposure, let's call it, where everyone's at risk on defense, and they're all hustling. I've seen incredibly powerful efforts at every company right now,
Starting point is 00:26:10 and I'm not aware of any large 1A enterprise, not actively scanning for exposure and doing something about it in real time. And what's interesting, David, is it's like team ball everywhere. Like the CIO, the CISO, the product teams, the business lines are all like, okay, we found something. and it's almost like war-roomed. Like, we got to go fix this. And they composite of those teams are pretty broad.
Starting point is 00:26:35 So there's no way to make the next year pretty. That's the best way to say. You know what I mean? It's a cocktail party out there right now, digital cocktail party. And everybody's in a race. Yep. Yeah, it's one of our most sophisticated companies
Starting point is 00:26:48 told us they took a large percentage of their engineers and research organizations and just devoted it toward fortifying their own walls. Yeah. Which was like an all-hands-on-deck. And, you know, the alarm bells started ringing very recently. Like, this is within the last few months, right? I think Mythos was the biggest.
Starting point is 00:27:05 I mean, we saw it coming long before Mythos, but the Mythos moment from a marketing standpoint got everybody to go, okay, threats changed. Yep. And a lot of people said Mythos came out, find vulnerabilities in our own software. And you have to do that if you're doing software, security at a station. So all the vendors ran out and did that. But the way I respond to Mythos is that just made it very well known about AI on offense coming at you.
Starting point is 00:27:27 And I think that's what accelerated it. You know, that was pretty much a firm stamp. It's common. Yep. What about the hugging face incident? I'd love for you to talk about the learnings from that. I've given that a lot of thought. I mean, I'm certain at opening, I was like, oh, we're at a regular.
Starting point is 00:27:43 They were like, oh, we could have done this and this, and it wouldn't happen. You know what I mean? So they've already figured it out. It's been my experience. In every technical modality shift, we underestimate the adversary's capability. And in this case, we underestimated the model's capability. because, you know, when you really read it post-factor, they could have stopped that, you know.
Starting point is 00:28:03 And they could have put guardrails on it, some deterministic things. And I think they realize that now. But I think when you're in a race, it's almost like a lunar landing race, right? And you have R&D people, and they're doing the work to create models in a way where even those CEOs are like,
Starting point is 00:28:20 we can't slow it. Let's get the government to help us slow it. You know, that means you can't even control your own innovation. I have views on that. but we could take it another time. And so when you have, and I get that, R&D people are like chasing that innovation. And it's really hard to package them
Starting point is 00:28:36 with then like security, experience security people that have the skill sets to cage that thing, you know? And it's hard to marry those two up because the security people don't understand the AI as well. And the AI people don't realize. One of the things that we did in our model, I mean, make no mistake, Arminan has made the beast that we're all worried about.
Starting point is 00:28:54 We've made a model that attack. We made many of them. We have a system that attacks production networks, and it's highly successful breaking in. Well, is it safe? Well, our guys instinctively knew we got to have, obviously, a secure, you know, we got to have a hypervisor, we got to secure this thing, we got to lock it down, host-based.
Starting point is 00:29:14 We have to have a proxy. It knows the proxy. It's proxy. Where, that's fine. But then our guys did something, and even I was like, nice job. They passively, serptitiously look at every single, prompt on do we like it do we not like it and the majority of the time if we kill an agent it's probably nothing to do with safety it's that the agent's wasting money yeah you know what it means so kill it
Starting point is 00:29:37 it's off on a goose chase we've already done or don't want to do but there are so many layers of validation that the agent was doing the right thing and the other thing was assume every layer of your security will fail and you have to have deterministic rules that eliminate certain activities But what I did learn, reading those incidents, it does take domain expertise to secure agents behaving in certain domains. You know what I mean? Yeah, it's a great. So I get that. So like without a cyber background, I get how you're going to make, you're going to test something go, oh, didn't think of that.
Starting point is 00:30:13 Yes. And you would have had to have an experienced team look at what the evals look like to say, you know what, it's going to do this and it's going to do that. So that's why Armidon we combine the exploit developer types and red teamers with the AI folks, because our evals most of the time are made by the red teamers. Right. You know what I mean? They're the ones that understand this stuff. And we created 20 full kill chains at Armidon that humans have done in the real world, period,
Starting point is 00:30:42 at different victim sites and our experience operators have done when testing networks. And we had no model go through the entire kill chains of more than eight. So that's where it's eight out of 20. And here is what's weird, by the way. We tested the open weight ones and the most advanced closed models. They all found eight. Yeah, really? Yeah, so it was all about just speed and cost.
Starting point is 00:31:03 Of course. And the closed models were faster to finding exploitable risk, but that's coming down. But we kind of let the open models run longer, and they got to the same place. That's it. So in the cyber world, the differentiation between closed and open is not as great as in other domains probably. And it's compressed, yeah. Yeah. I would say that's somewhat consistent in terms of like the capability gap,
Starting point is 00:31:27 at least closing a little bit. But that's interesting that their performance is basically the same. From my perspective, seeing the charts from the team, all the lines ended up in the same place. When you're looking at it was immediately time, cost, and then call it effectiveness or creativity, they all ended up at the end of all their operations, where they hit diminishing returns, they ended up in the same place.
Starting point is 00:31:53 Not on cost, though. Yeah, not on cost. Yeah, that makes sense. Yeah, that makes sense. So it's a decent segue maybe to talk about what kind of models you guys are using, and then what role do you think the lab companies play in the future? Well, and I don't even know if I finished answering your last question other than domain expertise on security is going to have to work with the AI folks.
Starting point is 00:32:12 Because I did read the meter publication, and I was like, well, these guys are AI people, but I'm not sure they'd done a lot of investigations. Yeah, and that's going to happen. Again, the modality shift, because here's one. When cloud started emerging, you know, I was running a bunch of incidents. We were responding to breaches for living at Mandia, and we had to learn what's a cloud breach look like. Right.
Starting point is 00:32:34 We now have to learn what's an AI breach look like. How much data is that anthropic or the model companies that are being leveraged to do the attacks? What do you wish they logged? And how they will change behavior as well to have better audit trails, better forensic capability. So it's early onset to the technology, and we all clearly have to mature into it
Starting point is 00:32:53 in a way where we have the accountability when these things go rogue. You can say, here's what happened and when. And it shouldn't be like two weeks of forensics to figure it out. I hate to say it. Like, we log every single thing our agent does. Source IP address, time, a date, and what it did.
Starting point is 00:33:07 You know, so you got to go backwards and replay these things. And I think they've learned lessons the hard way, and they're probably way better today than we're even three months. I'd open AI and entroping and testing these things. And whoever had a regular labs, they're looking at this going, okay, we gotta tighten up a little bit here.
Starting point is 00:33:24 And I get, they were surprised because they underestimated it. And we've done the same with human adversaries. It is the weirdest thing. My whole career, everybody underestimates the top tier of what you're up against. Because you don't have to see it every day. Yeah. You know, and you don't want to fear the boogeyman,
Starting point is 00:33:42 as they say under the bed, so you don't want to have fud. But you still want to respect the technologies that you're creating and test them in a way that is meaningfully guarded. Got a caged beast, David. You know what I mean? You do. And I would argue, cage it too much, release a little bit.
Starting point is 00:34:00 Find the line because if you do overly deterministic, here's the art form to safety running AI, at least in cyber on offense, is you want to leverage the intelligence of the frontier labs to do stuff, but not do the wrong stuff. Right. So you need classifiers.
Starting point is 00:34:17 You need a model that looks at everything going outbound, everything coming inbound. We've created that with people and humans going thumbs up, thumbs down. That's good, that's bad. You've got to train it, classify, and look at it. But if you get too deterministic and disallowed too much, you're probably not leveraging the creativity of it. You let it out. So it is a gray area.
Starting point is 00:34:35 And the problem with that gray area is that's why no one would ever say we're 100% certain, we're going to get what we expect. You know, period. It's a battle we even have, but we have yet to have an issue because we can put a human in the loop or we have classifiers to say, human needs to decide this. We don't know what the hell just happened. You know what to do you? Yeah, yeah. So if you're inspecting everything that's coming, you know, ivory prompt to the labs, everything coming back and something comes back, and we don't know what the hell it is.
Starting point is 00:35:06 Pause, escalate, judge. Yeah. What do those great security operators look like inside Arminan? A lot of experience. 15 years on offense, 15 years of red teaming. I think we've read team literally 99 of the Fortune 100 throughout our careers. We didn't get one, and I know who it is. And they've never hired me, and I love their products.
Starting point is 00:35:26 So one day, maybe I'll get it. How do we get? Let's go get those guys. Talk to them all the time, never landed them. That's all right. They might be good. But, you know, they are very experienced. And they all, you know, when I look at our 90 plus zero days,
Starting point is 00:35:41 the majority have been found by human. Right. But they're found by humans because we're leveraging AI to do 90 plus percent of the tedious work, which is pen testing, done automated, web app pen testing and creative articular way, done automated for the 98th, 99th percentile. But we're still putting humans on it. But here's where it gets interesting, David, the last few zero days, tech found it. Really?
Starting point is 00:36:04 Yeah. Oh, wow. So we've made the turn. Yeah. You know, and most people already have made the turn. They're tech. if you're on offense leveraging AI, your AI agents are finding zero days. Yeah.
Starting point is 00:36:15 I want to shift gears now to your philosophies and mindset in building a company. You know, they're different. Yeah, so a couple things there. Like the first time I built a company was 2004, and I wouldn't have said I was an entrepreneur. I started Mandi at No 4 February, and it was self-funded and profitable. And we were successful because in hindsight, it's like you almost learned nothing at the time. I look back and go, oh, I did learn right then and there. because of the pain, usually.
Starting point is 00:36:42 But I look back on Mandient now, we had a premise nobody actually believed in 2004 because our first website said security breaches are inevitable, and nobody believed it. And I don't even know how much I believed it. It's a pretty good headline. By the way, I'm slightly off. Our first headline was,
Starting point is 00:37:03 you cannot solely rely on preventive measures, and that was so boring. But that's the same as security breaches are inevitable, you know. Can't rely on the defense. Better ring on this. Yeah, I got it wrong because I'm not a marketing guy. But anyway, so security breaches are inevitable.
Starting point is 00:37:16 And the premise was that let's respond to every breach that matters. So we have first mover intelligence on how to prevent it happening again. Yeah. And so the first model of intel and all cybersecurity was antivirus. You know, it was like we look for malware. Yeah. We have signatures for it. And if we miss, David George has to find the malware and submit it to us so we get better.
Starting point is 00:37:37 That's a bad model. My mother's not finding malware on her lap. You know what I mean? It's just going to eat her laptop a lot. So that model was bad. So we decided a better model because I responded to breaches. And the reason I was responding to them is AV was easily evaded. And so we were like, well, let's learn all the, you know, let's second layer AV because it stinks.
Starting point is 00:37:57 And that's what George now owns, you know. So that's second layer AV. You still have to have AV, though. I beat it up, but the reality is you still need it or something that replaces it. So the second layer of defense was required. So AV was a marginal line to hear, then you extend the marginal line with something that can learn and think.
Starting point is 00:38:15 And so we wanted to do that. And I actually look at Armand, it's just the third wave of intel. Like, why are we waiting for a victim and learn from that? That's ridiculous. You've got to find your own problems first. Don't wait for, you know, defense contractor A to be compromising and quickly share the information to make sure it never happens again. And that model still needs to exist for the things that are somehow get there.
Starting point is 00:38:38 They beat you. but we got that model now and it's just not good enough. So back to your question, you know, Mandia was self-funded. There's not a lot, I don't know self-funded companies these days, David. Well, the speed requires that you've got to be fast. That's the difference. Yeah, you look at, we started Armid and the philosophies were different. When I started Mandia, it was, hey, this is what we do for a living.
Starting point is 00:39:02 Let's make enough money to do it for a living. That's it. I mean, so we hired the best people. and we had a philosophy of, we're going to pay you more than our competition, but you're going to work harder. So we always felt like we had less people working harder, but better people.
Starting point is 00:39:17 Yeah, I think we were known for having great talent, and that talent has prevailed. There was a time about a year ago, somebody sent me a text, and they said, congratulations, 43% of the RSA mainstage keynotes are Mandy and alumni. Come on.
Starting point is 00:39:30 That's the text I got. I never verified it, but the guy's pretty accurate. I'll take that stat if that's true, you know, and I think it probably was. You know, we've got a lot of reach over time with a lot of talent.
Starting point is 00:39:43 And, I mean, look at Founstone. Look at George Kurtz. He and I worked together at Foun in 2000. You know, he has spawned a lot of, from Founstone, you've spawned a lot of successful companies and people. So same thing with Mandy, but the differences are this.
Starting point is 00:39:59 A, got to be funded. Yep. B, oh, your growth rate, get the market now. Like, I look at Arminan's opportunity. I feel like we have an 80 mile an hour tailwind, but we don't have a sales force. We don't have a go-to-market. We're not international.
Starting point is 00:40:13 All that just has to happen. And the only way to thread the needle in today's economy to beat the bigs is get this go-to-market in place with exactly the right tech at the right time, and you better already have your Act 2 ready. And you're Act 3 behind that ready because you don't want to get box into a corner. So Armadon's got an Act 2.
Starting point is 00:40:30 We have our Act 3 planned, but we're in the process of building go-to-market, which requires the funding. and you have to build it ahead of time. The consumer AI companies created such meteoric rises in revenue. I don't think they can be replicated in enterprise security sales.
Starting point is 00:40:48 But you just saw the compression. Wiz got to over 100 million in AR and 18 months from their first release, right? We're going to try to beat that. And that's what you have to do, especially when you're needed, necessary, and you have to exist. And that's not easy to do.
Starting point is 00:41:02 So you've got to get the funding. You've got to constantly think How do you rapidly grow? You can't let the wheels on the bus get wobbly, meaning how do you go that fast and maintain process? At Mandian's pace of we were self-funded and profitable with no competition because nobody believed the premise, we didn't get that wobbly, you know?
Starting point is 00:41:21 Yeah. We just had great leadership and discipline and we could do it. Growing this fast, you have to hire scalable leaders right away that understand institutionalized process. You can't win with grit, gut, and moxie. You know, you actually have to proceduralize, almost industrialize, uh, the armiden way. Yes.
Starting point is 00:41:43 That, you know what I mean? And that's what I'm trying to figure out. It's, uh, how do we do that and feel comfortable doing it? And here's complications. So let's do it. A, you got to grow fast. Be in the AI age. It used to be development was at a speed where you trained sales at sales kickoff in January and you're good. Yeah, exactly. Yeah. So I'm trying to figure out, wait a minute. We're different every two weeks. What is the modality now of having a sales core that is right up to date? And here's the challenge that I thought.
Starting point is 00:42:13 Every CEO I've talked to is like, how does AI change our business? And we all sort that out. But how does it change our manpower? When I look at AI's influence on sales, the reality in enterprise security sales is people still buy from people. Yes. You still need the same damn go-to-market structure for now. And in fact, it's even more emboldened because the tech's changing so fast
Starting point is 00:42:36 you can't put that onus on the customer to figure out how did you change? Where is it at? So we have got to create a process, institutionalized, where sales is trained every week, where are we at? How are we doing? And these are processes that will get you to when, you know, you think about... Yeah, with the credibility on the security software, right?
Starting point is 00:42:53 Exactly, yeah, you got to be great... Yeah, and by the way, there is no replacement for any company I'm involved in. We are not ever aiming to be... Let's be number two in our space. that sounds fun. It is be the best in a world of what you do. And when we hire people,
Starting point is 00:43:06 I remember getting a question once, somebody asked, well, how do you know when you're the best? And I'm like, when you are the best, you know it. You know, you have to be the best. If you have to ask the question, you probably not. Yeah. Like, I'm pretty sure, you know, there was a time in, you know,
Starting point is 00:43:19 LeBron James' career where he knew I'm going to have to work harder to stay the best. Yes, right? And that's how I want us to feel at Armaddon. The sports analogies all work. Tom Brady never walked on the field going, well, I'm the second best quarterback out here. No, always.
Starting point is 00:43:31 But it requires harder work, better people, and you have to constantly test, are we the best? Are we the best? And you learn very quickly from your customers if you got to do better. Right. So that feedback loop, customers straight in to the engineers is critical as well. So long, term, made short, speed has changed, got to do a capital raise, got to scale processes and test those processes all the time. What I can't stand is chaos. A CEO's job is to absolutely show.
Starting point is 00:44:01 hide chaos at a company from the employees. Period. You've got to make sure they're not like, we're like so loose. We have no idea. Wrong. You have to just say, here's the process.
Starting point is 00:44:13 If process is too much for you to study, that's the person you go to. All you need to know is a guy or a person's name. And that's how I look at it. How do we grow rapidly without feeling chaotic? How do we grow rapidly earning it with better product? And how do we change fast? I don't know how long IP lasts.
Starting point is 00:44:30 So it's like you've got to build. to Ferrari engine and say, you know what, whatever we're doing today, someone else is doing in six months. Yeah, yeah, yeah, yeah. So how do you differentiate over the next six months is go to market? Go to market, trust, and make them happy. You got it. The brand itself has to be built, too. You have to become a brand that is the seal of approval. Yep. So I just gave you a jumbled answer. I wish AI could summarize really quick. So here's the four differences, the funding, the speed, the branding matters, the go-to-market build-up. You have to build it way faster today than you had two years ago. And the big reason why that's the case is because this is a tsunami like has never been seen before in security.
Starting point is 00:45:08 In the security market, right? CrowdStrike, you know, and then the other players that were around it, they redefined the category. But they had to create the category. In the case of WIS, part of the reason that it was able to grow so fast is because it was a, oh, bam, hit you like a ton of bricks pressing need. And so everyone felt like they needed to buy this or something. I think they innovated really fast, too, though. You get a halo early. like, you know, you got to get the halo.
Starting point is 00:45:32 And I personally think you get the halo, trade secrets. You get the halo by getting the right customers and making them ecstatic. Yes. You know, like, no offense, if there's a place called, I don't know, Susie's cupcakes, they don't get you to halo if you make them happy in cybersecurity. Right. But the money center banks do, the best retail does, the airlines do. You can get it.
Starting point is 00:45:52 Yeah, of course. And so that's why Arminans making one-A enterprise focus number one. Solve the hardest problems. Yep. And I think WIS did that. So, yeah, they did a great job of it One of our companies, too, and we love those guys. All right, what else do you want to talk about anything?
Starting point is 00:46:05 Well, I'd ever answer your question on the differences, too. There's more founders today than ever before. Yes. There's more startups than ever before, and they're all able to capitalize now. So you will have competition in anything you choose to do right now. There's not going to be a mandian. Security breaches are inevitable, and it's right, and there's nobody else there. Yep, that's not going to happen right now.
Starting point is 00:46:27 So everyone's in a crowded market. So I think every founder has to recognize you have to differentiate, and probably right now because of the noise in marketing more than ever before, the only way to differentiate is get customer, make customer happy and repeat. Yep, there is nothing else that will differentiate you other than your customer base raving about you. Yep. So you better go do that. That's it.
Starting point is 00:46:48 So I just get away every trade secret. God, but none of it's rocked at times. It's like literally, honestly, it's the same thing that's always been in business. Yeah, but it's just at hyperspace now. Just got to do it faster, and that speed requires never forget what you should focus on. Get customer, make customer happy repeat. That's it. And you've got to do that.
Starting point is 00:47:06 And then everything else is like around that is to make sure you do that really well, the training, the sales enablement, the marketing, the people you're hiring, your hiring process, the teamwork, you know. So in some of the ways we differentiate as well. Well, you know, you know, we have all our engineers in one room. Yeah, we're a big believer in that, you know. I think managing distributed teams is more complex than standing up and asking questions and 20 people are in the room to answer. Slow speed, if nothing else. Yeah. So it's a great time to start a company, though, because almost every, well, every industry is going to change.
Starting point is 00:47:43 Yes. And in cybersecurity, every single tech stack is going to be different over the next two years. Yes. Yeah, people are going to get ripped out, put in new tech. It's all got to be revamped. And so it's fun and exciting to be part of that. It's the tailwind of a lifetime in cyber. Yep.
Starting point is 00:47:58 Well, look, we're so excited about what you're building and thrilled new partners. So thanks for being here. That was fun. Thanks for listening to this episode of the A16Z podcast. If you like this episode, be sure to like, comment, subscribe, leave us a rating or review and share it with your friends and family. For more episodes, go to YouTube, Apple Podcast, and Spotify. Follow us on X at A16Z and subscribe to our substest.
Starting point is 00:48:25 at A16Z.substack.com. Thanks again for listening, and I'll see you in the next episode. As a reminder, the content here is for informational purposes only. Should not be taken as legal business, tax, or investment advice, or be used to evaluate any investment or security and is not directed at any investors or potential investors in any A16Z fund. Please note that A16Z and its affiliates may also maintain investments in the companies discussed in this podcast.
Starting point is 00:48:51 For more details, including a link to our investments, please see a16z.com forward slash disclosures.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.