Three Key Cyber Resilience Insights from theCUBE

0
2

Key Takeaways

  • AI is shrinking attacker response windows to seconds, making traditional human‑only defenses inadequate.
  • Cyber resilience now hinges on understanding minimal viable operations, rapid restoration to a trusted state, and contextual intelligence.
  • Autonomous agents and dynamic non‑human identities require continuous visibility and machine‑scale governance, not static entitlements.
  • Defenders must extend security into software development, shared telemetry between security and engineering, and proactive attribution through cybercrime bounty programs.
  • Scaling AI to production demands coordinated data discovery, encryption, and governance across hybrid, multi‑environment landscapes.
  • Industry collaboration, shared telemetry, and community‑driven intelligence (e.g., Fortinet’s bounty program) are essential to close the accountability gap and slow cybercrime growth.

The Growing Imperative for Cyber Resilience in the AI Era
Cyber resilience has shifted from a desirable capability to a business imperative as artificial intelligence accelerates attack speed, expands the enterprise attack surface, and grants autonomous systems unprecedented access to sensitive data and critical operations. Krista Case, principal analyst and practice lead for cyber resilience and security at theCUBE Research, emphasizes that preventing every disruption is no longer a realistic measure of security success, even for mature organizations. With attack windows contracting dramatically, enterprises must identify which operations are essential and verify they can restore them quickly to a trusted state. Case notes that it is practically inevitable that any security organization will experience some disruption, shifting the conversation to understanding minimal viable operations and having confidence in rapid, confident recovery.

Context and Dynamic Control: Closing the AI‑Driven Response Gap
Jon Oltsik, analyst in residence at theCUBE Research, highlights how AI widens the gap between attack speed and human‑led security response. The Mandiant “M‑Trends 2026” report shows the median interval between an initial access event and handoff to a secondary threat group plummeted from over eight hours in 2022 to just 22 seconds in 2025. As this response window contracts beyond what human‑only teams can match, contextual intelligence becomes crucial for closing the AI security skills gap. Case explains that frontier AI models accelerate attacker scale and speed, compressing defenders’ response windows, and therefore defenders need rich context to act effectively. Simultaneously, autonomous agents can access sensitive systems and improvise toward goals, rendering static entitlements insufficient. Oltsik warns that agents will pursue any means to complete a task, making dynamic non‑human identity oversight a pressing challenge.

AI‑Driven Threats Force a Broader Defense Across Development, Operations, and Enforcement
AI lowers the cost of discovering and exploiting vulnerabilities, eroding the reliance on faster patching alone. David Weston, corporate vice president of AI security at Microsoft Corp., advocates safer software construction through memory‑safe languages and formal verification, noting that AI agents helped catch a potentially catastrophic flaw that passed all human expert analysis. Once software reaches production, resilience depends on breaking down data silos between security and engineering. Emilio Escobar, CISO at Datadog Inc., stresses the need for a unified telemetry context so both teams can view the same activity through different lenses, accelerating root‑cause analysis and prioritizing vulnerabilities by runtime exposure and business impact rather than severity scores alone. Beyond internal defenses, Fortinet Inc.’s cybercrime bounty program—partnering with Crime Stoppers International—addresses the attribution gap by incentivizing anonymous reporting of cyber threats, validating and packaging intelligence for law enforcement. Derek Manky, chief security strategist at FortiGuard Labs, argues that focusing on human intelligence is essential to slow the cybercrime industry’s growth and hold attackers accountable.

Production AI Turns Cyber Resilience into a Governance Challenge
Scaling AI from pilot to production often stalls when organizations lack visibility, protection, and policy enforcement over the underlying data. Robin Braun, vice president of AI business development and hybrid cloud at Hewlett Packard Enterprise, asserts that trust to scale AI starts with trusting the data: organizations must know where data resides—SaaS apps, cloud, on‑prem, laptops—and how models were trained, governed, and guarded. Asset discovery now extends beyond traditional hardware to identities, applications, networks, agents, large language models, and prompts. Dean Sysman, co‑founder and executive chairman of Axonius Inc., observes that the problem is not a lack of data but an overload of interconnected assets whose relationships influence each other, necessitating intelligent asset intelligence. Autonomous agents can legitimately combine permissions—e.g., accessing Salesforce and email—yet lack the judgment to recognize unsafe data transfers. Dev Rishi, general manager of AI at Rubrik Inc., introduced Rubrik Agent Identity to govern access per tool call, but cautions that machine‑scale oversight cannot rely on human manual approvals, which would devolve into security theater given agents can perform ten times the work of a human in the same period.

Asset Discovery, Autonomous Agents, and the Need for Machine‑Scale Oversight
Effective cyber resilience in the AI era requires continuous discovery of all assets—including non‑human identities and AI components—so that policies can be applied dynamically. As agents operate with legitimate entitlements that traditional controls were not designed to evaluate, organizations must adopt real‑time monitoring and automated enforcement mechanisms. Shared telemetry between security and engineering teams enables a common operational view, allowing faster identification of anomalous behavior rooted in agent misuse or compromised credentials. Furthermore, attributing attacks to criminal networks remains a top priority; initiatives like Fortinet’s bounty program illustrate how incentivizing community participation can improve threat intelligence and support law enforcement efforts. By coupling granular asset visibility with automated governance controls, enterprises can better contain the blast radius of autonomous agent actions and maintain confidence in their ability to recover critical operations.

The Role of Industry Collaboration and Community Engagement
The insights from Black Hat USA underscore that cyber resilience is no longer a solitary technical challenge but a collective effort spanning vendors, enterprises, law enforcement, and the broader security community. Programs that extend anonymous reporting models to cyber threats, share telemetry across teams, and foster trusted networks—such as theCUBE’s Alumni Trust Network—amplify defensive capabilities and accelerate knowledge transfer. As AI continues to reshape both attack tactics and defense mechanisms, maintaining open channels for intelligence sharing, investing in automated governance, and cultivating a culture of rapid, context‑aware response will be essential for organizations aiming to thrive amid an increasingly volatile threat landscape.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here