newsfilter.io
Interview, Fireside Chat

Building Cyber Defense for the Agentic Era

Company Founding & Strategy

  • Kevin Mandia returned to founding a company at age 50, driven by the convergence of meeting a specific team (Travis Lanham, David Slater, Evan Pena) and an urgent "AI shift change" in cybersecurity.
  • Mandia explicitly states he did not found the company for entrepreneurship's sake but felt compelled to build a solution he believes every company needs immediately.
  • The company, Armaden, is structured with a two-act strategy:
    • Act One (Armaden Red): Using AI on offense to find exploitable risks and zero-days before adversaries do.
    • Act Two (Armaden Blue): Creating autonomous "compensating controls" or a "force field" to stop attacks the moment they are detected.
  • Mandia views the current market as a "tsunami," asserting that open models are already capable enough for cyberattacks, making the "slow down" narrative insufficient for security preparedness.

Market Data & Capabilities

  • Since January 2026 (within the transcript's timeline), Armaden has identified over 90 zero-days at Fortune 500 customer sites that were active in production.
  • These findings are not based on source code review but on black-box attacks where agents successfully achieved remote code execution (RCE) or data exfiltration.
  • The company trains its models using "real red teamers" with an average of 15 years of offensive security experience, creating 20 full kill chains derived from real-world attacks.
  • Testing revealed that while closed models find risks faster, open models eventually reach the same effectiveness level but at a lower cost and higher latency.
  • 8 out of 20 full kill chains created by human operators were successfully executed by AI models; no open-weight or closed model completed more than 8 chains, indicating a ceiling on current model creativity without human guidance.

AI Threat Landscape & Tactics

  • Speed Disparity: AI can execute tasks in a microsecond that would take 70 humans, making human-in-the-loop defenses ineffective for rapid lateral movement.
  • Scale: AI attacks utilize "drone swarms" of agents (e.g., 25,000 agents working simultaneously) rather than the single-path "sniper" approach of nation-states.
  • Nation-State Evolution: Modern nation-state attacks are shifting from "sniper" tactics to "drone swarm" tactics, balancing the need for speed against the need for surreptitiousness; AI currently lacks the stealth of human actors without extensive post-training.
  • Attribution Blurring: As AI democratizes attack capabilities, the distinction between human actors and AI agents will blur, making attribution to nation-states versus criminal groups increasingly difficult.
  • Anonymity: The primary catalyst for increased criminal AI attacks will be the ability to commit crimes anonymously; without this, the cost of risk remains a deterrent.

Product Methodology & Differentiation

  • Hyperattack: Armaden employs a "hyperattack" (drone swarm of agents) to map networks and create a "metadata twin," allowing them to detect changes (new apps, routes, services) and immediately attack them.
  • Continuous Defense: The strategy moves beyond periodic pen testing to continuous "heartbeat" polling and attack testing triggered by network changes or new threat intelligence.
  • False Positive Elimination: Unlike traditional pen testing that lists vulnerabilities based on known CVEs, Armaden verifies exploitability by achieving RCE, ensuring no false positives.
  • Category Redefinition: Mandia argues AI-driven red teaming will replace traditional pen testing, which he characterizes as a "hygiene step" that fails to test custom applications for logic flaws.
  • Autonomous Response: Future defense requires "tourniquet-style" automated response to stop bleeding before human intervention can occur, integrating with platforms like CrowdStrike and Palo Alto Networks.

Operational Philosophy & Execution

  • Speed vs. Process: The company is prioritizing rapid capitalization to match a "meteoric" market demand, acknowledging that the "Mandiant model" of slow, self-funded growth is insufficient for the current AI speed.
  • Go-to-Market: Armaden is building a scalable sales infrastructure to match its 80-mile-per-hour tailwind, requiring constant sales training updates as the product changes every two weeks.
  • Talent Density: The company maintains a philosophy of hiring "better people" who work "harder," currently housing all engineers in one physical room to maximize speed and collaboration.
  • Customer Obsession: Differentiation is achieved exclusively through making customers "ecstatic," focusing on the hardest problems for Fortune 500 companies to generate a "halo effect" that scales.
  • Chaos Management: Mandia emphasizes that a CEO's role is to "hide chaos" from employees by institutionalizing processes to allow for rapid scaling without operational disarray.

Forward-Looking Statements

  • SOC Evolution: The Security Operations Center (SOC) will undergo significant shrinkage in human involvement; humans in the detect-and-respond loop will be too slow, necessitating 100% AI automation for prevention, detection, and response.
  • Innovation Pace: The gap between AI offense and defense will narrow, but defense must adapt autonomously to prevent the "window of exposure" from becoming catastrophic.
  • Market Saturation: The market will become crowded with founders and startups, meaning the only viable differentiator will be customer retention and satisfaction.
  • Model Safety: As AI agents are "caged" for safety, developers must balance deterministic rules with the need for creativity; over-constraining models will limit their offensive effectiveness, while under-constraining risks rogue behavior.
  • Future of Security: The next two years will see every enterprise tech stack completely revamped as organizations scramble to fortify against AI-native threats.