Building Defense for the Agentic Era: Kevin Mandia
- 01AI turns cyber offense into a scale-and-speed problem humans cannot match
- 02Cyber is the domain where AI attack capability is structurally easiest, and the "slow the models down" window has closed
- 03Defense must become autonomous because humans in the detect-and-respond loop are too slow
- 04Offense trains defense: the "best offense" as a continuous practice opponent
- 05Red teaming at scale replaces pen testing as a category
- 06The near-term pain: offense is advantaged and enterprises are in a "digital cocktail party" race
1. Key Themes
AI turns cyber offense into a scale-and-speed problem humans cannot match
Mandia's core claim is that AI attackers differ from human attackers in kind, not just degree. Humans had to pick one path into a network; AI swarms probe everything at once and acts in microseconds.
"What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges." — Kevin Mandia [00:06:12]
"The scale of what AI can do dwarfs humans, like in ways humans don't even get. So you have a scaling problem in that humans could always find only one path into a network." — Kevin Mandia [00:06:12]
He also describes the experience of watching his own agents move: "As a human, you're like typing on your keyboard... This thing just does a thousand things at once. It's just everywhere." [00:23:45]
Cyber is the domain where AI attack capability is structurally easiest, and the "slow the models down" window has closed
Vulnerability discovery is code, which is a structured language, so AI excels at it. Mandia argues open models are already sufficient, so regulatory brakes come too late.
"What Arminen's doing on offense is we're finding vulnerabilities, exploitable risk. That is code. That's a structured language, a structured process. Because it's structured, AI is going to be great at it." — Kevin Mandia [00:06:41]
"The whole, let's slow down the models. We don't want cyber risk. Too late. The open models are already good enough." — Kevin Mandia [00:07:11]
His internal testing supports this: on 24 real-world kill chains, "We tested the open weight ones and the most advanced closed models. They all found eight." [00:30:52] The differentiator was speed and cost, not ultimate capability.
Defense must become autonomous because humans in the detect-and-respond loop are too slow
Mandia expects prevent, detect, and respond to each be governed by AI, with the SOC being restructured as the window for each phase narrows.
"If you have humans in the detect and respond loop, you're going to be too slow... you have prevent, detect, respond, prevents going to be governed by AI and detect and respond is going to be done by AI." — Kevin Mandia [00:22:18]
"You can't really have a human in the loop in the AI... for tactical autonomous defense. Like you got to do something fast. You know, you got to tourniquet the wounds as fast as you can." — Kevin Mandia [00:11:54]
He frames the first generation of automated defense as "field dressing in war": imperfect compensating controls pushed into EDR and firewalls, followed by deeper fixes later.
Offense trains defense: the "best offense" as a continuous practice opponent
Armadin's product thesis is that you cannot have a defense without a great offense to train against, and that the testing must be continuous but cost-efficient, triggered by change rather than running constantly.
"You don't have a defense unless you have a great offense to go up against... if you want to be the Baltimore Ravens defense at 2000, you kind of want to have your practice offense really push you." — Kevin Mandia [00:11:25]
The mechanism is a "hyper attack" that builds a metadata twin of the network, then polls for change like a heartbeat: "We pull cheaply for change and then attack the change." [00:12:51] Triggers for retesting are new models or intelligence, network changes, and ad hoc audits.
Red teaming at scale replaces pen testing as a category
Mandia positions Armadin as a category redefinition, in the mold of CrowdStrike's AV-to-EDR move. Pen testing is a hygiene step; AI makes true red teaming economically feasible for everyone.
"Pen testing to me is always just scanning for what's already known. And it doesn't prove whether you're really exploitable or not... it's always created a larger list of volumes that don't matter." — Kevin Mandia [00:16:11]
"I think over time, everybody would have red teamed everything all the time if they could. It was cost prohibitive and people prohibitive. With AI and an agent doing it... I think it'll replace pen testing over time." — Kevin Mandia [00:18:26]
He predicts Armadin "will be as ubiquitous as AV because you have to have that AI force field." [00:15:41]
The near-term pain: offense is advantaged and enterprises are in a "digital cocktail party" race
Both sides are desperate, attackers to exploit before defenses harden, and defenders to patch every window. Large enterprises are mobilizing cross-functionally.
"We have near-term pain in the AI age that it advantages offense... both sides recognize it's for long-term gain." — Kevin Mandia [00:25:12]
"It's like, it's team ball everywhere. Like the CIO, the CISO, the product teams, the business lines are all like, okay, we found something and it's almost like war roomed." — Kevin Mandia [00:26:10]
David George corroborates: "One of our most sophisticated companies told us they took a large percentage of their engineers and research organizations and just devoted it toward fortifying their own walls." [00:26:45]
Every layer of the cybersecurity stack gets rebuilt in the next two years
Mandia sees a rip-and-replace cycle, with vendors, CISOs, and head counts all being re-examined.
"In cybersecurity, every single tech stack is going to be different over the next two years... People are going to get ripped out, put in new tech. It's all got to be revamped." — Kevin Mandia [00:47:25]
David George's summary: "It's the tailwind of a lifetime in cyber." [00:47:56]
Domain expertise must be fused with AI research to build and secure offensive agents
Mandia argues the frontier labs' safety lapses reflect a missing pairing of AI researchers and experienced security practitioners. Armadin's evals are built by red teamers.
"Our evals most of the time are made by the red teamers. You know what I mean? They're the ones that understand this stuff." — Kevin Mandia [00:30:23]
"It does take domain expertise to secure agents behaving in certain domains." — Kevin Mandia [00:29:55]
Armadin's safety stack assumes every layer fails: hypervisor, host lockdown, proxy awareness, passive review of every prompt, classifiers on inbound and outbound traffic, and deterministic rules, with human escalation when a classifier flags the unknown.
Building at AI speed: funding, go-to-market, brand, and process discipline
Compared with self-funded Mandiant in 2004, Armadin must raise capital and build distribution before product-market pressure arrives, while institutionalizing process without chaos.
"You can't win with grit, gut, and moxie... you actually have to proceduralize, almost industrialize, the Armand and way." — Kevin Mandia [00:41:35]
"The only way to differentiate is get customer, make customer happy and repeat. There is nothing else that will differentiate you other than your customer base raving about you." — Kevin Mandia [00:46:25]
2. Contrarian Perspectives
The AI attack wave is a democratizer, not just an escalator, and attribution will break
Conventional wisdom focuses on nation-states getting stronger. Mandia argues the larger effect is that weak attackers look strong, and attacker identity becomes unknowable.
"Less capable attackers, less technical, less successful, are going to appear way more successful. It's the equalizer, right?... We're being attacked by these models, but we're not sure who's behind them... attribution will get a little difficult." — Kevin Mandia [00:10:23]
He also notes that crime is currently constrained by identifiability: "It's hard to do crime when people know your name... The minute you have anonymous availability of GPUs, you'll see far more criminal attacks." [00:07:11] His implication is that the current lull in criminal AI attacks is a function of GPU traceability and cost, not a lack of capability.
Source-code vulnerability scanning (the "Mythos moment") is noise; black-box production exploitation is the signal
While the industry reacted to models that scan source code and find thousands of bugs, Mandia dismisses that as noise relative to verified, remotely exploitable production risk.
"Everybody's like, wow, Mythos came out and you can scan source code and find vulnerabilities and you find thousands of them. That's noise... We are black box coming from the internet over 90 zero days in major software companies." — Kevin Mandia [00:17:58]
His point is that verified exploitation in a real network, with no false positives, is what drives enterprises into incident mode, not a theoretical bug list.
Closed and open models converge in cyber, so the moat is domain post-training, not model access
Most investors assume frontier closed models give a durable edge. Mandia's testing found all models plateaued at the same point; the difference was only time and cost.
"In the cyber world, the differentiation between closed and open is not as great as in other domains. And it's compressed." — Kevin Mandia [00:31:22]
Coupled with his belief that IP has a short half-life, he argues Armadin's durable advantage must come from post-training with real red teamers, go-to-market, and brand rather than the underlying model.
Don't cage the AI so tightly that you lose its creativity
Contrary to the instinct to lock agents down with deterministic rules, Mandia warns that over-constraint destroys the value.
"Cage it too much, release a little bit. Find the line... If you get too deterministic and disallowed too much, you're probably not leveraging the creativity of it." — Kevin Mandia [00:34:01]
The compromise is classifiers plus human escalation on unknowns, not blanket prohibition.
An early, sloppy autonomous patch beats a clean intrusion
Security purists resist imperfect automated controls. Mandia accepts rudimentary autonomous defenses because the alternative is worse.
"I'd rather have a bad patch stopping a bad guy from getting in than have an intrusion... You never want an unknown person with arbitrary access on your network." — Kevin Mandia [00:20:09]
3. Companies Identified
Armadin
Founded by David Slater, Travis Lanham, and Evan Pena, with Kevin Mandia as founder and CEO. It uses frontier models and AI agents on offense (Armadin Red) to find exploitable risk in customer networks, and is building Armadin Blue to push autonomous compensating controls into defensive platforms. Mentioned as the subject of the episode, with over 90 zero days found at customer sites since January 2026.
"Armaden since January this year, we have found over 90 zero days at customer sites, all in production." — Kevin Mandia [00:00:51]
"There's 25,000 agents on concert, all working together, doing really, really smart things without going on bizarre fishing trips." — Kevin Mandia [00:05:17]
Mandiant
Incident response and threat intelligence company founded by Mandia in 2004, self-funded and profitable, later acquired by Google. Mentioned as his prior success and the origin of "security breaches are inevitable."
"The premise was that let's respond to every breach that matters so we have first mover intelligence on how to prevent it happening again." — Kevin Mandia [00:37:12]
CrowdStrike
Endpoint security leader founded by George Kurtz. Cited as the model for category redefinition (AV to EDR) and as a partner integrating Armadin findings into autonomous defense.
"We're working with CrowdStrike on it and they know it has to exist." — Kevin Mandia [00:20:37]
Wiz
Cloud security company. Cited as the benchmark for hypergrowth in security, reaching over $100M in ARR within 18 months of first release, and as an a16z portfolio company. Armadin aims to beat that pace.
"Wiz got to over 100 million in AR in 18 months from their first release, right? We're going to try to beat that." — Kevin Mandia [00:40:43]
Palo Alto Networks
Referred to as "Pan." A security platform vendor Armadin is working with on autonomous defense integration.
"We're working with Pan on it. They know that it has to exist." — Kevin Mandia [00:20:37]
Fortinet
Firewall and security platform vendor, cited as one of the defense platforms Armadin needs to inform with exploit findings.
"We need to inform those defense platforms, you know, the Fortinets and everybody else. Here's what you can do about it." — Kevin Mandia [00:20:37]
Foundstone
Security consultancy where Mandia and George Kurtz worked together in 2000, noted as a talent spawner for successful companies.
"Look at Foundstone. Look at George Kurtz. He and I worked together at Foundstone in 2000. You've spawned a lot of successful companies and people." — Kevin Mandia [00:39:21]
Tenable, Rapid7, and Qualys
Legacy vulnerability management and scanning vendors, characterized as hygiene-oriented tools that map known exposures and CVEs, in contrast to Armadin's verified exploitation.
"The old versions of pen testing, you know, the Tenable, the Rapid7, the Qualys was more a hygiene sort of thing." — Kevin Mandia [00:16:42]
Anthropic and OpenAI
Frontier labs whose models and incidents Mandia discusses. He argues they should build better audit trails and forensic logging, and notes they learned hard lessons about underestimating model capability.
"They've learned lessons the hard way. And they're probably way better today than they were even three months ago at OpenAI and Anthropik." — Kevin Mandia [00:33:02]
Mythos (Anthropic model)
Model referenced as the catalyst moment that made AI offense widely understood among enterprises.
"The Mythos moment from a marketing standpoint got everybody to go, okay, threats changed." — Kevin Mandia [00:27:02]
Hugging Face (incident)
Discussed as an example of a model-safety failure caused by underestimating model capability and lacking domain security expertise.
"In this case, we underestimated the model's capability because, you know, when you really read it post facto, ah, they could have stopped that." — Kevin Mandia [00:28:07]
METR
AI evaluation organization whose publication Mandia read and critiqued as lacking investigative domain expertise.
"I did read the, you know, the, the meter publication and I was like, well, these guys are AI people, but I'm not sure they've done a lot of investigations." — Kevin Mandia [00:32:05]
4. People Identified
David Slater
Co-founder of Armadin. Mandia calls him a "freak of nature" in a positive sense.
"David Slater's, and I mean, it's in a positive way, freak of nature. Like, these guys are really, really good." — Kevin Mandia [00:02:19]
Travis Lanham
Co-founder of Armadin, described by Mandia as a generational talent.
"Travis is a generational talent." — Kevin Mandia [00:02:19]
Evan Pena
Co-founder of Armadin, previously known to Mandia, praised as exceptional.
"Evan Pena is exceptional at what he does." — Kevin Mandia [00:02:46]
George Kurtz
Founder and CEO of CrowdStrike, former Foundstone colleague of Mandia, credited with redefining the endpoint category and spawning talent.
"They famously redefined the category from AV to EDR." — David George [00:15:05]
Kevin Mandia
Founder and CEO of Armadin and founder of Mandiant, with 30 years in cybersecurity. His red teams have tested 99 of the Fortune 100.
"I think we've red teamed literally 99 of the Fortune 100 throughout our careers." — Kevin Mandia [00:35:14]
David George
a16z growth investor and host of this conversation, an investor in Wiz and CrowdStrike relationships.
"It's the tailwind of a lifetime in cyber." — David George [00:47:54]
LeBron James and Tom Brady
Cited as models for the "best in the world" mindset Mandia wants at Armadin.
"Tom Brady never walked on the field going, well, I'm the second best quarterback out here." — Kevin Mandia [00:43:02]
5. Operating Insights
Make "get customer, make customer happy, repeat" the only differentiation in a crowded market
With more founders and startups than ever, noise and marketing no longer separate companies. Mandia insists on customer love as the sole differentiator and targets the hardest customers first to earn a halo.
"You get the halo by getting the right customers and making them ecstatic... The money center banks do. The best retail does. The airlines do." — Kevin Mandia [00:45:27]
His corollary is a direct customer-to-engineer feedback loop: "You learn very quickly from your customers if you got to do better." [00:43:31]
Re-engineer sales enablement on a weekly cadence because product changes every two weeks
Annual sales kickoffs no longer work when the product shifts constantly. Mandia wants an institutionalized weekly training process and recognizes enterprise security still buys from people.
"We're different every two weeks. What is the modality now of having a sales core that is right up to date?... We have got to create a process, institutionalized, where sales is trained every week." — Kevin Mandia [00:42:03]
Hide chaos from employees and hire scalable leaders early
He frames a CEO's job as shielding the team from disorder, and says hypergrowth requires leaders who understand institutionalized process from day one.
"A CEO's job is to absolutely, like, hide chaos at a company from the employees... All you need to know is a guy or a person's name." — Kevin Mandia [00:43:58]
"You have to hire scalable leaders right away that understand institutionalized process." — Kevin Mandia [00:41:12]
Co-locate engineers in one room to maximize speed
Armadin keeps all engineers physically together, trading distributed flexibility for instantaneous Q&A.
"We have all our engineers in one room... managing distributed teams is more complex than standing up and asking questions and 20 people are in the room to answer. Slow speed, if nothing else." — Kevin Mandia [00:47:25]
Kill agents on cost-waste, not just safety, and log everything for replay
Most agent terminations at Armadin are for wasting money, not unsafe behavior. Every action is logged with source IP, time, and activity so incidents can be replayed rather than forensically reconstructed over weeks.
"The majority of the time, if we kill an agent, it's probably nothing to do with safety. It's that the agent's wasting money." — Kevin Mandia [00:29:30]
"We log every single thing our agent does, source, IP address, time and date and what it did, you know? So you got to go backwards and replay these things." — Kevin Mandia [00:33:02]
6. Overlooked Insights
Armadin's recent zero days were found by the AI agents, not the humans
A throwaway line marks a crossover point: the majority of the 90-plus zero days were human-found, but the most recent ones were found by the agents themselves, meaning the human-in-the-loop advantage is already eroding in the offense product.
"The last few zero days, tech found it... So we've made the turn... If you're on offense leveraging AI, your AI agents are finding zero days." — Kevin Mandia [00:36:04]
This implies Armadin's cost structure and scalability improve sharply as human red-teamer time stops being the bottleneck.
The incumbent defense platforms will deliver autonomous defense "even if you don't ask for it"
Mandia briefly notes that CISOs will receive autonomous defense through platforms they already own, which suggests Armadin's go-to-market can ride through existing CrowdStrike, Palo Alto, and Fortinet deployments, and that standalone autonomous-defense startups face an embedded distribution challenge.
"You're going to see autonomous defense happen even if you don't ask for it. Right. Because of the defensive platforms you've already invested in." — Kevin Mandia [00:21:06]
Cloud and AI breaches create a new forensics and audit-trail market
Mandia mentions that responding to AI-driven breaches requires logs from the model providers themselves, hinting at demand for AI-native forensics, auditability, and accountability tooling that does not yet exist.
"We now have to learn what's an AI breach look like. How much data is that anthropic or the model companies that are being leveraged to do the attacks? What do you wish they logged?... It shouldn't be like two weeks of forensics to figure it out." — Kevin Mandia [00:32:34]