Loris Degioanni: Why AI Is Breaking Cybersecurity, and What Comes Next
May 06, 2026
343
51:15

Loris Degioanni: Why AI Is Breaking Cybersecurity, and What Comes Next

AI has fundamentally changed the cybersecurity threat landscape, not by inventing new attack types, but by collapsing the timeline. The same tools that make software developers more productive are now being used by attackers to move from vulnerability disclosure to active exploit in a matter of hours. That shift, argues Loris Degioanni, CTO and founder of Sysdig, changes everything about how defense needs to work.

In this episode, Craig Smith talks with Loris Degioanni about why human-centered security is becoming a structural liability, what "headless cloud security" means in practice, and why the coding agent (tools like Claude Code or Codex) may become the new operating system through which all enterprise security workflows run. It's a conversation about architecture, urgency, and what it actually means to fight a tank when you've been trained to use a baseball bat.

If this conversation made you think differently about AI and security, subscribe to Eye on A.I. for weekly conversations with the people building and defending the future.

[00:00:00] A.I. has done a lot of wonderful things, but it's done a lot of scary things. Attacks can be scaled much faster through the use of A.I. It makes it easier for cyber criminals to attack systems. So every time there's something new that is being discussed, first of all, these tools can find new vulnerabilities in software, but then once something is found, the speed at which this can be leveraged to perpetrate attacks is, you know, used to be weeks, now it's hours.

[00:00:30] Okay, so I usually start by having you introduce yourself, give your background so far as it's relevant, and how you got to Sysdig. But I wanted, because Sysdig is sort of deep tech, and a lot of the listeners are not necessarily familiar with that.

[00:00:54] So I'm going to ask you, from what I understand, Sysdig is a cloud and container security platform that gives users visibility into what's running in their Kubernetes container and cloud environments.

[00:01:17] Can you just explain in very brief terms to listeners who don't know what a container is, what Kubernetes is, and how that relates to security? And then we'll start asking questions. Yeah, in a nutshell, Sysdig is an AI-powered real-time cloud defense platform. What does it mean? What does it mean? Let's start from cloud.

[00:01:47] Cloud is where all of the software that you, I, our listeners are using on a daily basis, right? You do a checkout at the supermarket, you do your banking, you do your Uber, it doesn't matter. Anything that you do, you do, you know, nowadays, is powered in the cloud and is powered by software that is running in the cloud. AI is running in the cloud.

[00:02:17] So we are talking about AI here, you know, and all of the AI infrastructure is definitely working on cloud-based and cloud-native infrastructures. So cloud is where software runs nowadays, and Sysdig protects and defends the software that is running in the cloud.

[00:02:38] Software running in the cloud normally is based on stacks, on ways to, you know, organize and run the software, which are, you know, based on some of the terminology that you mentioned before, containers, Kubernetes. These are the way, the same way you run your software, you know, on your Mac, on macOS.

[00:02:59] Typically software in the cloud runs on distributed software infrastructure that is, you know, based on so-called containers, which are, you know, little. It's a way to partition your software in little independent pieces that can be deployed easily and they can run everywhere and can scale up and down. And Kubernetes is essentially the operating system for the cloud, right?

[00:03:24] So it's what takes the software and runs it and makes sure that the software, you know, like the software that you're running is able to grow when there's more demand and shrink when there's less demand and use the appropriate resources and so on and so forth. So Sysdig is a company that specializes and leads essentially, you know, the ability to protect all of this kind of stuff.

[00:03:49] So Sysdig also protects most, you know, most of the environments where AI runs. Okay. Thanks. That's very concise. So can you, I mean, I'm sorry, I didn't ask you to introduce yourself before that. Introduce yourself and give a little bit of your background.

[00:04:12] I know that you've navigated a few major cybersecurity transitions in your career. So can you, yeah, talk about that? Sure. And thanks for having me. My name is Loris DeGioanni. I'm a CTO and founder at Sysdig. Sysdig is my second company. My first company was called Case Technologies, was the company behind a very well-known open source network analyzer called Wireshark.

[00:04:42] This is a tool that pretty much everybody that has to do with the computer network in the world uses, you know, to observe, troubleshoot, optimize computer networks. Still going strong now. The company was acquired in 2010.

[00:04:58] And then after a few years of taking a break, I started Sysdig essentially with the goal of securing modern cloud infrastructures and bringing all of my expertise in visibility and security and open source to the world of cloud.

[00:05:19] And cloud is, you know, whatever you do in your life, sorry. Checking in your bank account, paying at the supermarket, chatting with friends, getting a cab. It's all, you know, run by software that runs in the cloud.

[00:05:44] So, uh, Sysdig, you know, originally set out to solve the problem of securing these infrastructures that are running in the cloud, which is also incidentally where most of the AI, not most, all of the AI runs nowadays. Uh, today Sysdig, I'm a CTO. I run product and engineering.

[00:06:06] And also I focus on all of the initiatives, uh, uh, that we have, uh, Sysdig related to AI, including some of the stuff that we're going to talk about today. Yeah. Uh, you know, AI has done a lot of wonderful things, but it's, it's, uh, done a lot of scary things.

[00:06:23] And one of the scary things is it makes it easier for cyber criminals to attack systems, to, to increase their speed and scale. Uh, so there's this, as there always has been in cybersecurity, this, uh, sort of arms race between the attackers and the defenders. Uh, the defenders generally, uh, catch up to a new attacker.

[00:06:53] We're going to back vector fairly quickly and, and fortunately, uh, are staying ahead, it seems. But, uh, but there's, uh, we're in a new era of cybersecurity with, with the implementation of AI. Can you talk about the current threat landscape for me? Uh, break it down somewhat. Yeah. Yeah.

[00:07:21] And, uh, um, we are in a new era for humanity, in my opinion, you know, and, uh, and therefore, you know, cybersecurity is no exception yet. Uh, and, uh, uh, first of all, my first comment is, uh, this is evolving so quickly that, uh, the, the moment, you know, you make, you make a comment on this, it's already outdated.

[00:07:48] Uh, and, uh, uh, this is particularly interesting because, uh, it feels like, uh, you know, uh, with stuff like, uh, um, you know, mythos and project blast wing, for example, from anthropic. It really feels like we've reached the point where AI is becoming very, very relevant for cybersecurity.

[00:08:07] In general, in terms of, uh, threat landscape, I feel that, uh, uh, the threat landscape, uh, remains, uh, similar to, uh, what, uh, we've seen, you know, historically in cybersecurity, uh, but with, uh, uh, incredible acceleration. Right. Right.

[00:08:29] And in CRE incredible increase in volume and speed, uh, in terms of what we're seeing, uh, in terms of attacks, uh, uh, attacks, uh, can be scaled, uh, much faster, uh, through the use of AI.

[00:08:45] You know, the same coding tools that make developers so productive and are sort of revolutioning the software development, uh, uh, arena are, uh, leverageable, uh, very effectively by attackers.

[00:09:00] So, you know, stuff like, uh, uh, uh, I don't know, uh, uh, producing, uh, going from vulnerabilities to, to exploits of this vulnerability, which required, you know, advanced, uh, programming and development skills now can be largely done by, by, by through the help of an AI, which means that, for example, our trade research team, uh, a couple of weeks ago released an article where they were showing that between the disclosure of

[00:09:30] of a vulnerability. So essentially a fault in a piece of software that can be exploited for security attack purposes and, uh, being able to see the, the, the attacks, the exploits based on the vulnerability. Uh, now it's a matter of hours, you know, just few hours. So every time there's something new that, that, that has been disclosed, first of all, these tools can, uh, find, uh, new vulnerabilities in, in software.

[00:10:00] But then once something is found, the speed at which this can be leveraged to perpetrate attacks is, uh, you know, used to be weeks. Now it's hours, uh, in general, uh, you know, things that are used to be complex, uh, to attack and leverage and used to be the domains of, uh, sophisticated attackers that could invest, you know, like, like, uh, uh, state actors.

[00:10:29] Or stuff like that, that could invest heavily, you know, in, uh, maintaining this list of vulnerabilities and, uh, and creating, you know, the texts and using them at the, at the right time. And so on. And so on. We can say it's been democratized, you know, so many, uh, many more people and many more entities are in a position to do stuff at levels of speed and sophistication.

[00:10:53] That was, uh, uh, uh, earlier in, in, in the domain of people that had much bigger budget. Um, and in general, uh, what we're seeing is that, uh, um, these attacks, uh, are also look impersonating humans better and better. Right.

[00:11:15] So when we're talking about stuff like fishing, like, uh, you know, um, uh, fake, uh, videos and all of this kind of stuff is becoming easier and easier essentially to be full. Even people that are very well prepared to this, it's easier and easier to be full, uh, because these technologies are becoming more and more credible. Yeah. Yeah.

[00:11:38] Uh, the, the, the, the, you know, that's again, for, for listeners who aren't that familiar, uh, can you break down what are the main attack vectors? I mean, I, I, I'm certainly fishing is one and it's, it's amazing that it's so effective because it's relatively, uh, crude. Um, um, but I, I know that there are still one of the main entry points.

[00:12:05] I would say, uh, you know, typically, uh, there's, uh, the entry points, uh, to do attacks on software. Typically there's, uh, mistakes and misconfigurations. Right. Uh, bugs, uh, and, uh, people taking advantage of people like fishing and so on. Right. So mistakes and misconfiguration, at least in the cloud, which is a domain where Sysdig operates and where I have the most expertise,

[00:12:34] uh, still tend to be, you know, like, uh, uh, the, uh, prevalent ones. Uh, it's like, uh, you just human mistakes, you know, you forget your data on a storage, uh, that is open to the internet and, uh, not protected by password.

[00:12:54] You know, this is how, and then somebody can easily discover it, uh, or your firewall is, uh, not configured to block certain specific traffic, maybe to certain specific targets. And you didn't realize that, you know, and so very, very often this is basic, you know, like we, we call it posture.

[00:13:16] So, and the, the attack surface, uh, is, uh, uh, essentially a function of, uh, you being able to figure out this kind of stuff and realize where, uh, where, where these issues, uh, uh, are. And then, you know, uh, the other one is bugs.

[00:13:34] So you, you can have the best possible posture and you cover your bases, but, uh, then people are able to come, uh, and, uh, find, you know, a disclosed or undisclosed bug in, uh, uh, your software that can be leveraged to, you know, create a buffer overflow or remote execution or stuff like that.

[00:13:58] So, uh, this is stuff that, uh, sometimes you're actually, most of the times you're not even aware of, you know, and this is the kind of sophisticated ones that I was, uh, uh, mentioning, uh, before. Uh, and the third one is, uh, yeah, people. So, uh, a lot of these attacks are like, uh, uh, being able to, uh, impersonate maybe contractors, you know, in your organization, uh, and through that, you know, escalate the privileges.

[00:14:26] Or phishing. So having to do with email, with, uh, instant messaging by, you know, uh, uh, essentially, you know, social engineering and being able to take advantage of, uh, the natural weaknesses that we have as human beings and the natural, you know, maybe lack of attention that we have with human beings, even if we are, you know, very trained and sophisticated in this. Yeah. Yeah.

[00:14:53] And on, on the, uh, misconfigurations a few years ago, I had a guy showing me that there is a website, I think, uh, or, or he had a tool that could scan the internet for, uh, public S3 buckets or, or, uh, exposed S3 buckets, you know, these, uh, these, uh, data stores.

[00:15:20] And, you know, he could go in and, you know, read the documents, uh, there, there was during COVID. He could look at people's lung x-rays and it was really remarkable. Um, is, is, is, is there a difference between securing, uh, servers that are on premise and servers that are in the cloud?

[00:15:51] Yeah. Um, for sure. And yeah, the S3 example that you, that you made is a, is a classic one in cloud, you know? And, uh, yeah, the, that's why I was saying it's still based on what we're seeing as is the probably, you know, this, this kind of, uh, attacks, uh, this kind of issues are still the most common ones.

[00:16:12] Uh, and, uh, um, it, when comparing, uh, traditional data centers with, with the cloud, I often, uh, use, uh, a metaphor, which is, uh, the medieval castle versus the modern city. Right? Typically on-prem data centers, uh, used to contain, you know, uh, all of, all of your hardware and software.

[00:16:39] You were managing it, you were controlling it, uh, the solution essentially to secure them was, uh, uh, put firewalls at the edge, make sure that you control everything that enters and exits this data center and make, make sure that you're as tight as possible at, uh, you know, blocking or killing what, what enters.

[00:16:59] And comparing this to a medieval castle, because it's like, you know, big walls, the important stuff inside these big walls, a little bridge, uh, and everybody has to go through that little bridge. That's the firewall, you know? And you do careful thorough checking, uh, at the bridge and you make sure that only, you know, the people that you select, uh, enter and exit, you know? And that's the way you protect it.

[00:17:26] Uh, modern cloud infrastructure are, are designed, are running, uh, in, uh, on hardware that is provided by the cloud provider. Right? Amazon, Microsoft, uh, Google, you, you mentioned it, right? There's, there, there's many of them. You, your team, your developers are sort of, you know, accessing this, uh, this environment from all over the world.

[00:17:51] Your users are accessing the software that you're building and you're providing them from all over the world. There's a million entry and exit points. There's a million, uh, different people and personas that are entering and exiting, you know, to, with, with different scopes, uh, with different goals, with different tasks that they have to perform. Uh, it's like a city, you know?

[00:18:18] There are many highways going in and out, uh, and, uh, there's, uh, it's, it's not only useless, but it's counterproductive to try to block these people from, from going in and out. Right? You, you actually want to do the opposite. You want, you want, you, you, in a city, you are productive if you have all of these people that can move, you know, and can interact with each other and so on. So the solution is not anymore, you know, just the firewall at the edge. There's no edge anymore.

[00:18:45] And the solution has to do much more with being able to police, uh, being able to detect. So for example, one thing that Sysdig does that we are very strongly doing is what they call a security camera for, for software infrastructures. Right? We have an open source tool called Falco for this, which is a very popular open source tool. And this is something that you can place in different places of your cloud infrastructure, collects the data, brings it to a centralized point so that you can then understand what's happening.

[00:19:14] The same way the police does by putting, you know, like security cameras in different parts of the city. And then you can, first of all, detect when something happens and you can also react very quickly. And the, and the better this data is, the more granular, the more real time this data is, the more you can react. So there's the difference, you know, with between on-prem and cloud. It's, it's like city versus, uh, versus medieval castle. Yeah. Yeah. That's a good analogy. That's interesting.

[00:19:43] The, uh, I mean, you know, cybersecurity has developed very quickly when you look in terms of, of, uh, technological history. Um, and, uh, you know, originally it, it was, uh, professionals that were looking at code or looking at, um, at systems, uh, as humans.

[00:20:13] But as the, uh, the, uh, the attacks become increasingly automated, security is now a machine driven. So, so how do we stay ahead? What's, uh, what's broken or not working about our current approach to cybersecurity? Yeah. Yeah. What's broken, what's not working?

[00:20:35] Uh, let's, let's talk about the problem and these mirrors what we were talking about, uh, earlier when, uh, we were mentioning essentially how security is changing. Uh, right? Uh, now that, uh, it, uh, and, and, and the, uh, the threat, uh, landscape is changing, uh, as the attackers become more and more empowered by AI. Right? So we have a situation where attackers are at this point

[00:21:03] leveraging AI effectively and aggressively with all of the implications that we discussed before. And on the other hand, we have a defense landscape, in particular when we're talking about approaches, tooling that is still in the early stages of evolving. And, you know, security tradition has been human-centered,

[00:21:30] tool-supported, but human-centered, right? And the goal, I've been part of this industry now for quite a bit, you know, and trying to provide tools that make the good guys as effective as possible. But the purpose has always been build tools that empower humans to be as best as possible at defending from the bad guys, right?

[00:21:59] This is quickly becoming not good enough. When the attackers move at AI speed, this just doesn't work if the defenders work at human speed, right? So you were asking, what's the issue? The issue is that either we find a new paradigm

[00:22:26] that allows the defenders to do the same and to move at AI speed, or there's going to be a huge imbalance and it's going to be very, very hard to protect not only cloud software, but everything, you know, in general in cybersecurity. Yeah. I mean, you mentioned, did you say Falco?

[00:22:55] Was that the camera product that you put into a system? Do the attackers at this point, because we're now into the age of agentic AI, do they have, are there agents that crawl through publicly facing software looking for vulnerabilities autonomously?

[00:23:26] Is that what's happening? And something like Falco, what exactly does it see? Because this is all happening at the level of bits and transistors. Yes. Stuff like Falco is essentially, it works by having a set of agents,

[00:23:53] sensors that you deploy across your infrastructure, and this collect essentially data coming from multiple sources, data coming from, you know, running software. So which network connections are done, which files are open, you know, which commands are executed, all of this kind of stuff. It also collects signals that are coming from cloud trails and logs.

[00:24:23] So, you know, what AWS actions you are executing. AWS, you know, is the Amazon cloud. So what are you doing there? You know, are you starting something? Are you changing configurations? Are you opening, are you putting data in some place? You know, this kind of stuff. So it collects all of these signals and then it's able to tell you, you know, by analyzing the signals,

[00:24:52] if something either is an attack or is it something that is suspicious, essentially. And Falco traditionally, and here when we're talking about, you know, like what's changing in securities, data is becoming more and more important, right? So Falco provides the best data that can be, you know, consumed for this purpose. What's changing now is that this data normally traditionally

[00:25:22] goes to humans in the end, you know, for under the form of alerts, logs and so on for judgment, for prioritization and then for taking action. The way I describe it is the traditional software stack is B2H, right? Business to human. And what is changing and in particular,

[00:25:51] what Sysdig is changing in the way we're doing it and what we're changing in cloud security is that we're working, we're moving toward the model that I define more like B2A, right? Business to agent. So Sysdig, this week is introducing headless cloud security, which means that it's security, it's cloud security, but built for agents. So assume that, you know, we provide a software that still needs to be, you know,

[00:26:21] like the best software for cloud security, but now assume that it's not designed anymore for consumption by humans. So we're abandoning, you know, like the traditional UIs and we're making it headless. We're making it essentially, you know, agent first, API first, so that it's designed essentially, you know, not to be consumed by humans as at least, you know, the main users of this,

[00:26:50] but it's designed to be consumed by agents so that workflows can be accelerated and automated by essentially basing them on agents first. And is, how do you know, I mean, that requires a tremendous amount of trust in the agents. So is it simply through testing that you develop that trust that you, you know, these agents are not going to block legitimate

[00:27:21] activity or that they're not going to miss illegitimate activity? How do you develop the trust in those agents? Yeah, let's talk a little bit about what we mean when we talk about headless cloud security. In my opinion, there are some really important, you know, paradigms here. first one is data is everything, right?

[00:27:51] This is, in general, being made very clear, you know, in the world of AI. Even when we're looking at all of these companies that are providing, you know, like the best incredibly powerful AI models, in the end, data is the mod, right? The model that can be trained on the best data is the model that produces the best results. This is also very true in cloud security.

[00:28:21] So, these agents operate on data and the better, the more granular, the more valuable this data is, the better outcome you will get from these agents and the less mistakes they will make. Paradigm number two, core concept number two is everything needs to be API based, right? So, that is designed for consumption by agents.

[00:28:51] So, the UI, this is quite radical, but the UI, you know, the dashboards, the point and click and so on, is something of the past because if you need, you know, like a dashboard, you just point your agent to the data coming from the security tool and the agent will create the visualization that you need. We call this hyper-personalization. So, the security experience, the security

[00:29:21] product at this point is hyper-personalized for every single use, for every single outcome, for every single individual that points the agents to the security product. The third important element is this becomes outcome and workflow oriented. So, you need to infuse these agents and this, you know, speaks to your question. How do you make them reliable and accurate?

[00:29:51] It's a work, you know, players like Sysdig, what they bring is they bring deep expertise in areas of security, right? So, the question is how do you infuse the agents with the workflows, with the expertise, with the ability to reach the outcomes that become goals, you know, when you need to detect in real time what's happening, prevent it, block it, take action, remove vulnerabilities,

[00:30:21] understand the attack surface, understand, you know, when sensitive data is exposed to the internet and remediate it automatically, right? So, it's all about outcomes and it's all about making sure that these outcomes are converted in skills that are heavily validated. And then there's the, how do you make, the last, the part to answer your question is, think about humans. How do you

[00:30:50] make humans more reliable at performing tasks? tasks because humans fail too, right? Humans can make mistakes as well. What we do in companies is we assemble them in teams and then we put together processes and give them tools that allow them to work productively and constructively in teams and minimize mistakes because there's proper workflows and proper, you know,

[00:31:20] checking of what everybody else is doing, right? We, there's a whole industries in software. Git is essentially, you know, if you, if you look at the core of what it is or, or JIRA, you know, these are just tools that are designed to essentially make humans cooperate in solving issues and do that with less mistakes. And this is something that, these are tools, for example, that are used

[00:31:50] heavily in cybersecurity. So the question is, how do you create something similar, but for the world of agents? How do you make sure that, for example, there's a common shared memory for these agents in terms of, you know, security and protecting so that a learning from one agent can be taken, the other agents can be taken advantage and it's coordinated, you know, there's not, there's less guesswork because the decision is taken together and agreed, you know.

[00:32:20] So the other thing that CISIC is working on when working on headless cloud security is these constructs, you know, to make sure that not only agents can operate well independently, but we heavily believe that agents make less mistakes if they are properly trained and they're properly aligned with each other with the proper support and tooling that is coming from products and tools like ours. Yeah.

[00:32:50] And you talked about personalization. Can you explain a little more what that means? Personalization, personalizing data for enterprises and the era of the dashboard is over, cybersecurity, the cybersecurity industry for decades, you know, like if you look at these products and

[00:33:19] it's, you know, data collection and then a bunch of data visualization on top of it, you know, and every product is a way, you know, to assemble, you know, like the views and get the reports and generate them as PDFs because, again, that supports very much the human workflows, right? When I do some kind of work in cybersecurity, for example, in posture, I then need to share my results with the CISO and the CISO takes my results and

[00:33:49] the results from the other teams and creates essentially, you know, like a report for the, so it's like humans that are working together in secure infrastructure. Now, there's two things that are happening here. Number one is data is the important thing at this point and if you need a specific view on the data, gone are the days where you go in the product and the product is hyper, you know, because what you do is you just point an AI to this data and it's like I need this report for

[00:34:19] my CISO next week, you know, the CISO is going to talk to the board and needs this for me. let's build it and let's build it in a way that is compatible with the look and feel of what our organization presents to the board, you know, and the AI becomes, that's why I say hyper personalized, you know, because the AI builds exactly what you need, exactly with the data you need and it's

[00:34:48] the goal, it's the purpose of the AI and to go and find the right data, slice and dice it, organize it, present it, and then you can iterate, you know, with the AI. But this becomes, you know, like conversation the same way you would do with a teammate, with an assistant, rather than pointing and clicking on a user interface. So that's number one. number two is more and more

[00:35:18] will automate and delegate this kind of stuff to agents that will do it for us. Does the CISO really need to invest the valuable time of a skilled analyst in just, you know, creating a report with the right look and feel? No, probably you can do it once or twice and that gets converted at a certain point into a skill for an AI which will also be connected to your calendar

[00:35:47] and know when the presentation for the board meeting needs to be delivered and the prior night will, you know, put in your folder or in your email the report and maybe the first time it's not exactly what you need, you will provide feedback and the second time it will be much better and the third time it's ready to go and you don't have to worry about it anymore and you can just give it to the board and it's prepared like that. So all of these together

[00:36:18] makes us believe that as I was saying the UI is a thing of the past and that the future is exposing the data, the right data, in the right way so that you can enable this workflow. Yeah, and the interface for the user then, is it conversational, I mean, text-based, natural

[00:36:48] language? The user interface for the user, so this is interesting as well because if we look at the evolution of how cybersecurity, and not cybersecurity, software in general, has been embracing AI, I would say we are at step number three. step number one is, okay, wow, there's these models that can speak and reason like

[00:37:17] human. Let's include a chat bot in our software that can be an assistant inside the user interface of our software and brings our user interface to be conversational. Since it has done that very early on, years ago, big results, very nice. you see this in many cybersecurity products. The first wave of announcement was all about that. Then there has been wave two where we're currently part of

[00:37:47] the wave two, which is agentic. More and more this kind of AI that is embedded in cybersecurity products goes from being single step and question and answer into becoming more and more independent and being able to perform tasks independently. This is like the inclusion of agentic inside

[00:38:17] cybersecurity products. Sysdig, especially with our launch of Headless, has a different point of view. Our point of view is that the user interface of the future for cybersecurity tools for any kind of software is codex, you name it. One of these. People will these coding

[00:38:47] agents, let's put it this way, will become the operating system of the future. Will become the Windows or the Mac OS of the future. They will be the place where we people sit when we integrate with software. This integration will be conversational, probably voice in the future, probably other ways to do this, but we believe that software will escape just the user interface of software.

[00:39:17] When we talk about Headless, we don't mean only there's agentic functionality and the AI is able to do stuff, but we really embrace SSD, the fact that workflows will run in the coding agent and when you do cybersecurity, no matter if it's vulnerability management, posture, threat detection and so on, you will do it from inside cloud code or equivalent. So then the question becomes, okay, what is the best

[00:39:46] way for a cybersecurity product to be cloud code first rather than providing any kind of user interface? That's the concept of headless essentially. The place where users live is cloud code. Let's make our software integrate and provide as much value as possible there and let's make people get the best out of it in those environments. Yeah, so the

[00:40:18] user as it asks the software to do something code code a solution on the fly instead of it being a static piece of software. Is that what you mean? It's coding, yes, but it's also performing tasks. Let's take an example. And again, let's go back to nowadays software.

[00:40:48] Typically, there's a bunch of constructs in nowadays cybersecurity software that has designed essentially to surface to the user the best data so that the user, the human, can take decisions. But then the final decision is still taken by the human. In vulnerability management,

[00:41:18] for example, vulnerability management is the area in cybersecurity where you go and look at all of your software components one by one and all of the software that you've written, line of code by line of code, and you try to identify vulnerabilities. And then, of course, you try to fix them. And doing these software tools, security products, what they do is they analyze your software. There's many ways to do that. And they look essentially

[00:41:48] where are your vulnerabilities. They tell you what are your vulnerabilities and where they're running. And then the human decides, okay, this vulnerability is pretty bad. It was disclosed yesterday. The world is talking about it. It's a serious one. It's a very bad one. And by the way, it's running in production for me. So what I need to do is I need to go and upgrade my software to fix this vulnerability and then I need to push a new version of my software. Actually,

[00:42:18] I'm not the person in charge of this software. So what I need to do is I need to go identify the owner of this vulnerability and open a ticket for this person and tell them, there's this urgent. Please take a look because we have this vulnerability now. You need to make a new release with a fix for this vulnerability and you need to push the software in production as soon as you can. This is not necessarily writing code in the classic sense, but it's performing all of these actions that are done by humans today.

[00:42:48] So from within cloud code, you will be able to do most of through agents and through AI assistants. So it's like this AI assistants will be able to take a look, receive the data in terms of vulnerabilities, express judgment calls, like this one is bad and it's running in an environment that is very sensitive for me. So let's focus on this one. And then the AI can talk to you and tell you, okay,

[00:43:18] when you wake up in the morning and you talk to the AI, the AI will tell you, while you were sleeping, I analyzed this data, there's this one that is urgent. Should we go ahead? And you say maybe yes, what do you propose? And the AI will be like, okay, I see where this is and I see that there's a new version I searched online, there's a new version of the software, I can make a patch for you, I can open a PR for you, for this piece of software, and then I can communicate with the developer and let the

[00:43:48] developer know. This is step number one. In the even successive future, the AI could make the fix, decide that the fix is sane, and push the software in production for you, right? All of these from your coding agent, where you will discuss with your coding agents, and in some cases this will actually produce artifacts that are software. In some other cases, this will produce actions on your software, on your

[00:44:18] code, on your infrastructure that are what today, you know, the practitioners do, and it will become more and more automatic. That's how you fix, how you solve the problem of the attackers being so aggressive and so quick at doing stuff. you can compensate by automating on the good guys side as well, and by therefore accelerating the detection and the resolution of these problems.

[00:44:48] And this starts from the environments where the users live. So this is not point and click and you try to figure out what you should do first, but it's by in your operating system of the future in your coding agent by talking to, you know, agents and AI that have been properly instructed and trained to perform these workflows together with you. No, that's fascinating. So how should organizations

[00:45:17] start thinking about this shift? And what will separate companies that succeed in this new model from those who don't? Again, I'm putting this in the micro trend of adopting AI, right? I think that we will see, we are already starting seeing major adoption of AI from organizations of any kind,

[00:45:47] any size, in any industry. And this is unescapable. It's a matter of competition and survival for every single enterprise on this planet. it will require adapting to these workflows and embracing them as quickly as possible. What we are seeing in software right now, I mean, you read the news

[00:46:17] and especially software news like news that are specialized in software and every other day there's an article about this particular person is claiming that they have not written a line of code since last December, you know, well-known developers and so on and so forth. And it's pretty clear that in software development specifically, the future

[00:46:46] role of humans will be coordinators, right? and enablers in my personal, you know, daily workflow. Essentially, what I try to set as a goal is block AI as least as possible, you know, keep having the AI working for you because you are the one that, especially with the current state of technology,

[00:47:15] enables these agents, directs them, prevents them from making mistakes, they still very much make mistakes, right? So, the human will become more and more an orchestrator and a provider of vision and a provider of strategy and oversight, right? So, that's what we do as humans. That's pretty clear in

[00:47:45] code already and we can all see how it looks in code already. my thesis, Sysdig's thesis is that the same will just translate everywhere, you know? So, no matter what our field is, product management, sales, logistics, I have no idea, you know, we'll become orchestrators of little teams that we control to perform what we're doing and

[00:48:14] we'll get our hands less dirty with the immediate, you know, stuff and like the single line of code, but we'll be empowered to accomplish a lot by having essentially each of us a team of skilled and efficient individuals that can go after our goals and our guidance. that is

[00:48:43] very much, in my opinion, what will happen in cybersecurity. So I gave you some examples before, you know, but the practitioners that right now have to worry about, you know, like the single vulnerability inside a single piece of software will be more like, you know, will guide initiatives, will define and guide initiatives inside the organization and then they will leverage their tools to perform these initiatives and to make them since they are designing today,

[00:49:14] what is the cybersecurity software that empowers people to do exactly this? Yeah. Yeah. That's a new world. It's a new world. Yeah. The companies that aren't employing AI solutions to defend their software infrastructure are,

[00:49:43] is the threat going to overwhelm them? I mean, if companies aren't using things like Sysdig? I think the problem will become your ability to just sustain volume, the pace, the quality, the sophistication of these attacks. So, no matter

[00:50:13] what, how many humans you employ and how skilled they are, I believe that if we don't accelerate them and we don't support them through these technologies, and that's why Sysdig is embracing them so aggressively, they will become the bottleneck, you know, and it's, you know, it's like fighting a tank with a baseball bat, you know,

[00:50:42] or something like that. We won't just be equipped to the volume and strength of what comes to us. So, we need to, you know, superpower the defenders so that they can, you know, contrast a tank with a cannon and not a baseball bat. Yeah. And that would be very important. Thank you.