Building Cyber Defense for the Agentic Era
a16z
Returning to Security After Mandiant 0:00
Kevin explains why he came back into cybersecurity after building and selling Mandiant. He says he did not consciously decide to start a new company, but meeting Armadin's founders, David Slater, Travis Lam, and Evan Pena, convinced him he had found rare talent he wanted to work with. After thirty years in security, he felt he could not sit out the shift brought by AI, since everything he had built before felt obsolete against this new wave.
What Armadin Builds 3:01
Armadin uses frontier AI models on offense to test whether a company has exploitable security risk, a product they call Armadin Red. The founders believe the future of cybersecurity requires good guys building offensive AI tools to attack networks before bad actors do, paired with defensive AI, called Armadin Blue, that can stop attacks and apply compensating controls once something is found.
How AI Attacks Differ From Humans 5:01
Kevin describes AI-driven attacks as already using thousands of coordinated agents, though still clumsy in places, sometimes looping back to targets they already breached. He says AI attacks dwarf human efforts in scale and speed, doing in a microsecond what would take seventy humans, and argues that since vulnerability-finding is a structured, code-based task, AI is naturally suited to it and open models are already capable enough for real attacks, limited mainly by GPU access and anonymity for criminals.
Nation States Versus AI Attacks 7:30
Kevin contrasts traditional nation-state hacking, which he compares to a precise sniper shot aimed at specific targets like defense contractors, with AI-driven attacks that behave more like a drone swarm, broader and louder but more comprehensive. He expects attribution to become harder as AI lets less skilled attackers appear highly capable, effectively democratizing sophisticated attack ability.
Pentesting versus AI-driven red teaming 15:01
Traditional pentesting is described as a hygiene exercise, scanning for already-known vulnerabilities without proving real exploitability, which produces long lists of flaws that often do not matter. The speaker contrasts this with Arm Ed's approach, where AI agents actually carry out exploits, achieving remote code execution or data extraction so there are no false positives. These AI agents, trained with real red teamers, work blackbox from the internet and have found over ninety zero days at Fortune 500 customer sites since January of this year, often notifying CISOs within 48 hours and pushing companies into real incident response.
Arm Ed Blue and autonomous defense 18:31
Arm Ed Blue is framed as the necessary counterpart to finding exploitable risk, working with endpoint and firewall platforms to build compensating controls at speed, even if early safeguards are rudimentary. The goal is autonomous defense across prevent, detect, and respond, since human-driven detection and response loops are too slow, though layered systems and traps are still needed in case something slips through.
The shrinking window of exposure 24:30
Vulnerability across Fortune 500 companies is described as rapidly shrinking as both offense and defense scramble, with the Hugging Face incident and the broader AI moment making clear that model capabilities were underestimated, prompting companies to devote major engineering resources to fortifying their own systems.
Testing Reveals a Compressed Capability Gap 29:31
Armadillo built twenty full kill chains, the complete attack sequences real human operators have carried out against actual victim networks, and used them as evaluation benchmarks. No model, open or closed, completed more than eight of the twenty. Surprisingly, both the open-weight models and the most advanced closed models topped out at the same eight, differing mainly in speed and cost rather than final capability. This suggests the usual gap between open and closed models is much smaller in cybersecurity than in other domains, though closed models remain faster for now.
Learning What an AI Breach Looks Like 31:31
Just as the industry had to learn what a cloud breach looked like, it now must learn what an AI-driven breach looks like, including what data model providers should log and how forensic trails need to improve. Everyone underestimates top-tier adversaries, human or AI, because they rarely encounter them directly. The right approach is neither fear nor carelessness: cage these systems enough to stay safe, but not so much that you lose their creative problem-solving edge. Classifiers and human review handle uncertain outputs, pausing and escalating when something unexpected comes back.
Veteran Operators Behind the Zero-Days 34:31
Armadillo's security team draws on operators with fifteen years of offensive and red-teaming experience, having red-teamed 99 of the Fortune 100 companies. While most of their ninety-plus zero-day discoveries have come from humans, AI now handles over ninety percent of the repetitive pentesting work. Notably, the most recent zero-days were found by the AI itself, a shift the speaker calls a turning point for offense-focused AI.
From Mandiant to Armadillo 35:30
The speaker's first company, Mandiant, founded in 2004, was self-funded and profitable, built on the then-unpopular premise that security breaches are inevitable and that responding to them generates intelligence to prevent recurrence. Antivirus represented a flawed first wave of defense, reactive and dependent on victims submitting malware samples. Mandiant became a stronger second layer, and Armadillo represents a third wave: rather than waiting for a victim to be breached, it proactively finds its own problems first.
Different Philosophies for Different Eras 38:01
Mandiant ran on the principle of paying top talent more while demanding harder work, resulting in a smaller but stronger team, one so influential that reportedly 43 percent of RSA mainstage keynote speakers are Mandiant alumni. Armadillo operates under different pressures: it needs external funding, rapid growth, and a go-to-market strategy built from scratch, including sales, international reach, and a roadmap already planned two and three stages ahead, all to outpace larger competitors while the window of opportunity stays open.
Scaling Without Losing Discipline 40:31
Growing quickly without the wheels coming off requires scalable leaders and institutionalized, almost industrialized processes rather than relying on grit alone. Because the technology changes every two weeks, sales teams need continuous retraining instead of a once-a-year kickoff. Enterprise security sales still depend on people buying from people, so a strong go-to-market structure remains essential even as AI reshapes other parts of the business. The underlying standard is to be the best in the world, not merely competitive, and to keep testing that standard constantly, treating customer feedback as a direct line back to the engineers.
Scaling fast without chaos 43:33
You need clear processes, or at least a clear person to go to, so growth does not feel chaotic. Because no one knows how long any technical edge will last, speed to market, keeping customers happy, and building a trusted brand matter more than ever.
Why differentiation now is harder 44:30
Security is in a once in a lifetime tsunami, and companies like CrowdStrike and Wiz grew fast by solving urgent, painful problems and quickly earning a halo through ecstatic enterprise customers rather than small, low profile ones.
More founders, more competition 45:31
There are more founders and startups than ever, so every market feels crowded and there is no guaranteed demand. The only real differentiator is getting customers, making them happy, and repeating that relentlessly, faster than before.
Culture and the current opportunity 46:31
Keeping engineers together in one room, rather than distributed, speeds up decisions and teamwork. Every industry, especially every cybersecurity tech stack, will be rebuilt in the next two years, making this an exciting, rare tailwind for new companies.
AI-generated summary. It can be wrong or incomplete - check anything that matters against the original.

