Our industry is now split into two cohorts - AI skeptics and AI enthusiasts. I get to spend plenty of time with people from both of these camps. Each side has its own merits and its own pretty solid arguments.
All that said, I have recently come to the conclusion that both AI skeptics and AI enthusiasts in cyber are wrong. Let me explain why.
Before we dive in…
If you don’t yet follow me on LinkedIn, here are several of the most recent posts:
You don’t have to be in the Bay Area or Tel Aviv to win in cyber. A new Inside the Network episode with Sachin Nayyar, who built two cyber giants at once (!), commuting between Securonix in Dallas and Saviynt in Southern California.
The market has finally woken up to the realization that AI isn’t killing cyber - it needs it. Just look at the graphs of how the cyber market is doing.
I took two months off from writing because the whole internet started feeling like one huge ChatGPT prompt. I was drowning in AI slop. I am now back.
And if you’re not yet subscribed to Venture in Security, now is the time -
People skeptical about what AI will do for cyber are behind on what’s already possible
We live at a time when technology is changing at an unprecedented speed. The tech that existed 3 months ago is outdated. The tech that existed a year ago is ancient. Don’t get me wrong: the architectural patterns and the foundations still apply, but the art of possibility is completely reset. As someone who has led products in the pre-AI world, I will be the first to admit that it’s not easy to unlearn what worked before, and to try what works today. But it’s really important that we do that regardless.
Every once in a while I hear the skeptics say things like “Nothing is really changing; AI is just some fad; it will all pass”. Although I respect different opinions, I strongly believe that this perspective is terribly wrong.
Let me be clear: I am not talking about all this “Cyber is solved because Claude Code can find vulnerabilities”, “AI is going to take over everyone’s jobs”, or “We can stop buying tools and instead we’ll vibecode our own security products” stuff. I respect readers of my blog too much to go down this path.
At the same time, it’s impossible not to see how AI is truly reshaping cyber. Before we talk about that, let’s think through some parallels, and there is no better parallel than the cloud.
When Amazon launched AWS, few people understood what the promise of the cloud was going to bring. The majority was terribly wrong:
Companies in regulated industries were adamant that they would never adopt the cloud. Fast forward to 2026, and every financial institution, every hospital, and every utilities provider has moved at least some of their most critical workloads to the cloud. Many of them are now cloud-only. It took two decades and a global pandemic to get here, but it started slower than people assumed, and then it progressed much faster than anyone predicted.
Security people assumed that the biggest issue with the cloud is going to be cloud misconfigurations. Don’t get me wrong - that’s still a huge issue, but I would argue that what’s even more impactful are the second- and third-order consequences that the cloud brought. The explosion of SaaS (since companies could deliver software at scale without massive upfront investments), sprawl of identities (because cloud leads to the growth in applications and services which all come with identities), explosion of third-party risk (because more software vendors means more risk), and so on.
The same is true when it comes to AI. The cycle mirrors the same behaviors, but companies that were left behind because they were too slow to adopt cloud have learned their lesson and are now super aggressive about AI. Not just that, but I think we all have learned our lessons:
Companies in regulated industries are looking for ways to say “Yes” to AI. It’s not about coming up with arguments against it, it’s about looking at where they’re at and starting small but going steady about AI adoption.
Security people still get too excited about prompt injections, but we are now starting to realize that problems like patching and vulnerability management are actually going to be more impactful. It took us as an industry over a decade to start paying attention to real threats brought by the cloud, but we’re much faster this time with AI, which I think is great.
We are also starting to recognize that second- and third- order consequences of AI explosion have to be tackled now, not 15 years from now. That’s why companies are starting to invest in reducing exposure (think of AI pentesting, etc.), in hardening their environments (think of prevention, etc.), and so on.
Then the most important bit: the cloud has truly changed how cyber is delivered. Companies like CrowdStrike, Palo Alto Networks, Zscaler, and Cloudflare became massive because the cloud allowed them to achieve unprecedented scale.
AI is exactly like the cloud: it is changing how software is built, it is changing the velocity with which software is shipped, it’s creating a massive attack surface, and it’s also making it possible to deliver security in ways and at the scale that weren’t imaginable before. The amount of manual work and low-level decision-making that can be delegated to AI agents is mind-blowing.
People who understand the power of AI are paying attention to the wrong things
The issue with people who do understand the power of AI is that they are paying attention to the wrong things.
The entire industry is focused on tracking how the model released in October is better than the model released in September. We are talking about AGI, about AI agents escaping their sandboxes, and how AI is becoming more intelligent than it was yesterday. I am not here to debate any of these topics; my question is - why does any of this matter to an average security team that isn’t working for Anthropic or OpenAI?
We gotta stop caring who the actors are, and start focusing on a) how do they achieve their goals?, and b) how do we stop them? What difference does this make - are we fighting against a nation-state adversary, an AI agent, or a script kiddie, if they are all now armed with the same tools? What matters is how they break in. In other words, what matters is the cyber kill chain.
Whether it’s a new frontier model or a nation-state actor, they are going to go through the very same series of steps (the Cyber Kill Chain Framework was developed by Lockheed Martin back in 2011):
Reconnaissance...
Weaponization...
Delivery...
Exploitation...
Installation...
Command & Control (C2)...
Action on Objectives...
If you look at it from this perspective, then the right question to ask isn’t “Are we being attacked by an AI agent or a human?” but rather “How do we break the kill chain?”
If you put it this way, now suddenly, security teams aren’t dealing with something new and ever-changing like AI. We have the kill chain framework. We have MITRE ATT&CK. We have NIST. We have the Cyber Defense Matrix… We are familiar with what attackers are doing, and we know what defenders must do to stop them. We are just confused and paying attention to the wrong things.
AI doesn’t change the reasons why companies get breached. As one smart friend put it, “Twenty years ago we had two problems, patches and passwords. Today, we still have the same two problems, patches and passwords”. AI doesn’t change that reality. What it changes is a) the speed of exploitation and b) the duty of care.
For decades, we were able to sweep all the issues under the rug. Tech debt? “We’ll fix it someday”. Critical vulnerabilities? “We’ll remediate someday”. Needed patches? “We’ll patch someday”. The economics of defense allowed us to ignore decades of accumulated gaps because we knew that attackers also have limited resources, and so they’ll most likely not be able to find these issues. We basically said, “If a sophisticated attacker goes after us, we’re screwed anyway”. AI changes the game because it forces us to now treat every attacker as a sophisticated actor. The exploitation time is decreasing rapidly. And yet, the defenses that were effective 5 years ago will continue to be effective tomorrow. Start with fundamentals: knowing what you have, understanding what matters to the business, having a solid control of the data, and other pretty boring practices.
Closing thoughts
Someone smart once said that “the future is already here, it’s just not evenly distributed”. That is exactly how I see AI. We don’t have to wait until something changes in cybersecurity, as cybersecurity has already been changed many times. We’ve moved from on-prem to the cloud. We moved from rule-based detection to machine learning. We moved from static everything to dynamic everything. Neither of these changes “ended” cybersecurity, and neither will this new wave led by LLMs and AI agents.
While security teams should absolutely be looking for ways to become more effective and efficient with AI, it’s equally (or I’d say even more) important to step back and think about what needs to be done to defend our environments. Where I think AI is making the most difference is when it comes to solving all these problems that have been lingering forever - asset management, vulnerability management, patching, identity, and so on. The opportunities lie in making a dent in solving the gnarly problems of cyber, not in pretending that the only thing that matters is how fast frontier labs release new models and how well they perform.
When in doubt, remember that the Cyber Kill Chain and MITRE ATT&CK frameworks (both of which are over 10 years old) are as relevant after AI as they were before AI.


