Gray Matters
Mission Matters Podcast
🎙️ Ep 29 - Ent: The AI Cybersecurity Arms Race – Defending at Machine Speed
0:00
-56:54

🎙️ Ep 29 - Ent: The AI Cybersecurity Arms Race – Defending at Machine Speed

How cyber defenders can use AI to keep up with hackers

AI lets hackers attack at machine speed. Human defenders cannot keep up. Luckily, the team at Ent is building the future of AI-native cyber defense and prevention.

In the latest episode of the
Mission Matters Podcast, Akhil Iyer and I sit down with Ent CEO Lou Manousos to discuss Ent and the future AI for cyber offense and defense. We discuss everything from:
👉 The recent
OpenAI attack on Hugging Face
👉 How AI agents deployed at the edge can prevent hackers from attacking in the first place
👉 Why defenders need access to locally deployed open source models to ensure they have control over their cyber defense in the face of rogue offensive agents
👉 Why the current security stack is insufficient in the world of AI
👉 And much more...

As always, please reach out if you or anyone you know is building at the intersection of technology and national security, or if you have any interest in joining the team at Ent. If you’re interested in working in the Shield Capital portfolio, please fill out this
form to Work in Defense Tech.

You can listen to the podcast on Spotify, YouTube, the Shield Capital website, or right here on Substack.

Transcript

Maggie 01:12

Offensive cyber attacks are officially moving at machine speed. Just last month in July, OpenAI reported a cyber incident in which one of its AI agents broke out of its sandbox and hacked into Hugging Face in an attempt to obtain solutions to a test that OpenAI was running against the model. Notably, during this Hugging Face attack, the Hugging Face team reported that they actually couldn’t use closed source frontier AI models to help defend themselves against this attack because all of the frontier AI labs have put up guardrails on their models to prevent people from using the models for cybersecurity tasks. Now, of course, they’re trying to prevent offensive attacks like the attack Hugging Face themself was actually experiencing, but ultimately, these guardrails prevent any kind of defensive use of these models as well. The Hugging Face team ultimately ended up needing to use a Chinese open source model, specifically ZAI’s GLM 5.2 model, to defend themselves in this situation. How can companies defend themselves today against automated machine speed attacks in the age of AI? In this episode of the Mission Matters podcast, we sit down with Lou Manousos, the co-founder and CEO of Ent Security. Ent is building the future of what they call intent-aware cybersecurity, leveraging edge deployed AI agents to prevent cyber attacks in real time at the endpoint. This kind of technology is absolutely crucial for companies to have to defend themselves in this age of AI for offensive cyber. Ent is working to bring security tooling into the AI era. By deploying AI agents on the edge at the operating system layer, Ent can detect and prevent attacks as they happen at machine speed with full context of a user’s typical behavior on a system. Since it was founded in 2025, Ent has raised more than $100 million and started working with enterprises across financial services, defense, hospitality, and more. This conversation covers everything from the current state of AI for offensive and defensive cyber, what it takes to build AI agents for cybersecurity, the debate over closed versus open source models, what it takes to deploy AI agents at the edge, and what it takes to build a successful cybersecurity business. All right, Lou, thank you so much for joining us on the Mission Matters podcast. This has been one of the interviews I’ve been most excited to do back since Akhil and I started this podcast more than a year ago. There’s been a lot of hype and discussion publicly recently about the role that AI agents can play in both cyber defense and of course, offense. I mean, lots of discussion around Anthropic’s Fable models, OpenAI’s newest models, even some of these Chinese open source models about their ability to conduct offensive cyber. Akhil and I, and Lou, you yourself, have all sat through many, many pitches for all kinds of uses for AI and security, whether it’s automated pen testing, SOC management, incident response, threat intelligence analysis, and much more. But I wanna hear it from you, what do you see as the state of AI for cybersecurity today? What is actually real versus what is just hype around what AI agents can do in this space today?

Lou 04:32

Look, I mean, it’s amazing. All offense will be AI entirely, I think by the end of this year. Mythos really gave us a window into that. So a lot of the hype really is people who worked with these models hands-on and have seen some of the capabilities. And so it’s pretty clear to me where this is heading. The models are really great at coding, they’re really great at technical tasks, and that’s what a lot of the security incidents are built around. So I think that Frontier AI labs, they’ve been talking a lot about this through this lens of safety, and I think they’re taking it seriously, but the cat’s kinda out of the bag, and that means those capabilities are gonna flow to open models, and attackers are gonna be able to increasingly use offensive AI. And what that means for security teams and the whole industry is it’s a speed question. So it all comes down to speed. If an offensive attack is operating at machine speed, people operate at human speed. We’re humans, we can only type so quickly, we can only move the mouse around so fast. So even if you have a defensive agent as a human operator, you may already be too late, even by the time you start to triage these incidents. And if you can’t understand the incident, really wrap your arms around what’s going on... I mean, frankly, if you look at some of these attacks, like 27 seconds, under a minute, that amount of time, just to reason in your own mind as a human, it’s unlikely. So to me, it’s pretty obvious that as offense is all AI, defense is gonna have to be mostly automated and able to execute in under a second and really prevent these attacks. So we’ve heard about all these different dramatic things that have happened recently, and whether it’s discovering vulnerabilities... I mean, you mentioned a bunch of them. Software inventory, hacking a system. These are all real risks that we’ve seen AI successfully pull off. So at this point, whether you’re a defender or somebody doing offense, you’re using AI at this point. It’s just a matter of how much the human is in the loop versus out of the loop. And I don’t think it’s about convincing anyone about the impact here. So that’s my view of it. It’s not hype, it’s happening. I think what’s maybe under-hyped is just how important it’s gonna be to stop thinking about response and focus more on prevention.

Akhil 07:21

Hey, Lou, I love that framing of offense versus defense. Actually, Maggie, I think on our first podcast we were talking about, obviously, here at Shield Capital, we talk a lot about and discuss revolution, military affairs generally. What I find interesting about this conversation, whether it’s in the digital world or whether it’s drone, counter-drone, there’s always this balance of power and velocity when it relates to technology as applied to the offense versus the defense. Correct me if I’m wrong, Lou. What I’m hearing from you is that where we are with AI today, you are arguing that that naturally favors the offense right now. Is that a correct statement?

Lou 07:58

Yeah. The investment certainly has gone into offense and, you know, even the first wave of companies in cybersecurity largely were around pen testing vulnerability. You know, that’s what the models were really good at, whether that’s in source code or in actually scanning live systems. And then the second wave went into understanding SOC operations, but that was really much more of a response function. So does it favor offense or defense? I think it’s really hard to build real-time defense and prevention. These agents are actually, while they’re faster than humans, they’re slower than a normal prevention system which operates in under a second. The agents do need to reason over larger quantities of data. And so I don’t think that the frontier labs are focused on that type of use case right now, and most security companies are just adopting what they can get from these frontier labs. I wouldn’t characterize it as the offenders have the advantage. They almost always have the advantage, right? Even before AI. It’s just much easier to find one hole in a system than it is to defend a system.

Maggie 09:28

Now, Lou, one of the big debates that I know we’ve discussed and a lot of the industry is discussing right now is really around the models’ capabilities for offense and defense, and really around the model providers putting in these guardrails to try and ensure that these models are being used in a safe way. But, of course, a lot of these guardrails maybe actually make it harder for defenders to use the model for defensive cyber operations. So I just wanted to get, what is your take on this debate around, to what extent the model providers should be building these safety guardrails in, especially in this world where we’re seeing this proliferation of open models that don’t necessarily have those same guardrails in place?

Lou 10:14

Yeah, this is kinda how we kicked it off. I think some of the recent incidents, Hugging Face and others that have happened in the last couple weeks really underscore that when you give an agent an objective, it’s... You’re not telling it, like, “Go hack this system.” It’s trying to get to its objective, and you didn’t have to give it step-by-step instructions like, “Go do this.” And it finds a way to work around the controls that you put in place. As long as you’ve got the tokens, it’s just gonna keep going. And so as a defender, if you’re specifically asking the model to do things and you’re using a frontier lab or an API provider that’s blocking you, I mean, that’s very troubling. And you don’t have control over that. You don’t really know at what point you might be blocked. That might happen once it understands what you’re trying to do, that might happen later. So I think organizations, defenders have to have some ability to run local models and switch out their model provider. I mean, that really became painfully clear last week when several people blogged about how they were blocked while they were defending themselves, and that caused them to spin up local capabilities. Now, what’s interesting about that, and Hugging Face, I mean, they’re like the experts in running local models, so they were able to do it. But how many organizations really have the capability to deploy and run a local model in that way? Probably not many. So yeah, to me, it is the digital right to bear arms or the right to bear technology. As a defender, if you’ve been given a guardrail, it’s like fighting a fight with one hand tied behind your back. So I feel pretty strongly that, as a security expert, you need to have exact knowledge as to when you’re gonna be blocked and what the model’s gonna do, and frankly, what it’s not gonna do when you ask it to do that. I think that’s where it ultimately ends up is you’ll need to remove guardrails for defenders. There will need to be... At least the frontier labs are gonna be challenged by this. But it will drive the best security teams towards open-weight models and open local models. At least as a backup plan, you’ll need to have that capability. I don’t see a way around it.

Maggie 12:59

Yeah, can you tell us more about what you think the proliferation of these open source and open-weight models will mean for both offensive and defensive cybersecurity?

Lou 13:11

Well, it lowers the costs, whether it’s social engineering, deception, just basic types of phishing, credential theft, data leakage. I mean, really you go through all the bad things that can happen in a security program. The models are trained on all this amazing research that’s been published. I have background in threat intelligence, published thousands of articles over the years. All of that information is in the memory of the model, so they’re quite good at this. And that I think is... Yeah, I think that’s the basic problem that you’re facing as a defender is, like, you’ve just lowered the bar for offense. I do think... We saw this in the early days of web exploits where just average cyber criminals could go online and buy a web exploit. They didn’t have to know very much about exploiting a web browser. They just go buy this exploit, they run the exploit kit, and now they’re able to target, whether it’s a nation state threat actor or just your average cyber criminal. It just made it way harder as a defender when you could get your hands on these. I think we’re entering a new phase now where that’s gonna become the new normal, where fairly effective attacks will be in the hands of ordinary cyber criminals. So in a world where we know that that’s gonna happen, and we have the speed of the attack being driven by AI, you have to be able to prevent and actually go beyond just detection and response. And this is gonna require a shift in thinking on architecture and how we’ve architected these systems. They’re currently architected to deal with human-driven attacks, which are, again, relatively slow. Once I go back to the exploit kit example, once I had a foothold on your network, as an attacker, I’d go to this panel, be like, “Oh, great, I hacked Maggie’s computer.” And now I would start tasking and going to look for my objective. That’s very slow. That might take hours, at least many minutes. So if you had an EDR system in place, your threat hunters would see that activity, and then they’d be able to isolate that machine. When that occurs in like under a minute, by the time your security architecture alerts you and your team starts responding, the damage has been done, the data has already leaked. So the answer is to move back to something where as soon as you detect this behavior that is potentially malicious or suspicious, that machine must be isolated immediately. You have to intervene at the moment that you see this behavior. And that’s a change in terms of how we’ve been behaving as a security industry the last almost 15 years now.

Maggie 16:29

Yeah. So maybe we’ve been hinting at it a little bit, but let’s move to discussing Ent itself. Can you tell us a little bit about what Ent is building and how it relates or compares to this old generation of security tools?

Lou 16:45

So we’re building an intent-aware security platform, and it’s designed to secure both human and AI-driven work. Our goal is to move the industry back to prevention because it’s only with prevention that you can see productivity and secure it and really increase the adoption of this AI technology faster. So we deploy an intelligent agent directly on the endpoint, and we model what people are doing, what applications are doing, what the AI agents are doing, and how that accrues to the work that’s happening. And we understand that in context. And so by understanding what the intent is, what humans and AI agents are doing, we’re able to see if there’s any risk there, if it’s deviating, and then we can intervene before that becomes an incident. What makes the endpoint super interesting in this AI world is I believe that humans are always gonna be in control at some point. And so you have to think where’s the place where humans and machines are going to meet. That’s how I define an endpoint. That is the place where a human and an AI agent or some future AI comes together. Once you start using your endpoint, you’re moving around a lot. You move between browsers, chat, other business applications. These agents are working hand in hand with users at that endpoint layer. So we provide security for this modern workspace. Instead of looking at each application separately, we look at the entire endpoint, from the operating system up, and that’s why operating systems were built. They are supposed to provide a platform and common primitives like security. So that’s Ent in a nutshell.

Akhil 18:54

No, Lou, that’s awesome, and exciting just how quickly too you have moved, and a lot of that obviously based upon your background experience and the team that you could bring together. Let me dig into a couple comments you made. The first is you talk about this shift back to prevention. So what has been missing, Lou, that you really felt like, “Hey, this is the one”? You’ve done many startups in the cyberspace. You decided to focus in this particular... Why this approach and why this vector?

Lou 19:25

You know, again, on why is the endpoint so special, I was just thinking about all these risks that are now playing out. I mean, I thought we’d have a little bit more time, but they’re happening now. Where’s the right place to build security? You have the cloud. So definitely a lot of things happening there. You have the network layer, and you have the endpoint. Again, the endpoint is where humans and machines meet, and that is the logical place to put the security control. That’s where the information’s gonna leak back to the user. That’s where the user is actually prompting or tasking their agents. And so when I thought about... I looked across the market and say, who’s doing this, and who’s got the capabilities? There’s plenty of great security companies out there, but they’re challenged. The incumbents are challenged because their model is based on detection and response, and we moved away from prevention about 13 years ago when the EDR market took off. And it would require a complete reboot, reset as to how prevention is done, which really relies on detecting a threat, using threat intelligence to hunt and then sending that as rules back to endpoints. The latency there is just too long. So that’s why we stepped up here. It’s just a ground up first principles rewrite of prevention and security.

Akhil 21:09

Yeah. Thanks, Lou. We’ve got some folks who listen to this podcast who are deep in cyber and know what EDR and SOC automation is, and then some that don’t, might be coming from different domains, but this certainly applies to them regardless of industry. Can you give an example, maybe a tangible one, of a threat that Ent agents have or were or will be able to detect and prevent?

Lou 21:35

So one example might be, you have an employee who is working on sensitive data on their local machine, and you wanna move that data from one machine to the next. In this example, this is kind of an anonymized example. This organization uses WhatsApp to communicate with some of their customers. So WhatsApp is an approved application in this environment. The data that the employee is using is approved. What’s not approved is for the AI model built inside WhatsApp, which there’s Meta AI, should not have access to this specific data. They’re only supposed to use WhatsApp to communicate with customers. So what happened was this approved communications app all of a sudden now had proprietary data put into it, and that was kinda cut and paste from another application on the desktop. So unless you have local AI capabilities that are watching the sequence of events, like data is taken from a Word document and pasted into WhatsApp, but into this portion of WhatsApp that has Meta AI for summarization, you would not be able to detect a company policy violation and potential regulatory violation and exposure. So it’s only when you have the context of the work, the legitimate work that that person is doing and the knowledge of the data, and putting that whole picture together, which is very difficult to do when you don’t have AI running directly at the operating system, watching not just the web browser, but communication applications, productivity applications, and you can design an adaptive policy that protects that entire environment. So that’s just one example.

Maggie 23:49

And so moving to a little bit of the discussion of the technology behind Ent, one of the things I found really interesting about it is that you guys did decide to deploy this on the edge, on the endpoint. Can you talk a little bit about what that decision gets you, and maybe also some of the challenges with deploying on the edge?

Lou 24:07

Yeah. The edge gives you context of what the user is doing. I’ll go back a little bit to, like, intent aware. One of the inspirations for Ent was autonomous vehicles. Riding in an autonomous vehicle here in San Francisco, I was, like many people, amazed at how the car can adapt to the world around it. So they have a world model, and then the vehicle intervenes. If that worked like a security system, right, it would log accidents, and then some analyst would come in and then tell it not to do that again. That’s not how it works, right? It doesn’t log an accident. It just intervenes so that there isn’t an accident. And so when you’re kind of at that point, at the edge, you actually have the ability to intervene in sub-second time. So you have the context of the environment, you have speed, and you have total control. And so that, in the world of cybersecurity really only exists at the endpoint itself, at the edge. And that’s where all these applications interact. That’s where human work is handed from your mind and translated through the keyboard or through your voice. It could be different modalities, right? It will be at that point where we hand off control to AI agents. And so if you don’t have that context, if you’re not living at that point, if you’re living sort of in application logs, or through network events or through the logs at the cloud, you completely miss the intent of the operator and what they’re trying to do. And so that’s really was one of the key pieces. And the other is that when you run locally, you can run very quickly, so that removes this sort of roundtripping that happens where I have to log the event, send it to the server, the server processes the information, sends it back. When you have something that has to complete in less than a second, you’re gonna gate the user and intervene, you’re gonna lock process execution or something. Like it has to be quick, otherwise the machine will crash or the user will complain. So that’s a really critical second reason. And then the last one is we really believe in the data boundaries. We wanna have a decentralized system. There’s a lot of sensitive data that happens on the endpoint, and we wanna keep as much of that information there and allow customers and their organizations to decide what they collect, how they analyze that. So all these things now can happen within the memory and compute of a modern endpoint. So we’re designing Ent around this future where we have a lot more happening locally, and these handoffs between humans and AI are just increasingly sort of the norm. So we just thought that’s the logical place, is the endpoint.

Akhil 27:37

Oh, that’s awesome, Lou. Hey, Lou, can I follow up on, as you decentralize and take action at the edge, there’s some trade-offs associated with potentially the decision-making or something broader. So two questions. One, as you look at proliferating at the edge, how do you find commonalities between different attacks if you’re trying to prevent and engage with those? And number two is, if you have to make some major refinement to how your agents respond or prevent at scale, how do you think about doing that? Where I’m going with this is, what is the trade-off between being able to prevent at the edge and being able to have a little bit of that centralized pivot or adjustment at scale?

Lou 28:27

Look, there’s some trade-offs, but there’s also barriers. I think the first one is are we sort of ready to hand off control to some local, very fast, Ent-like agent that can prevent. I mean, that’s just a change in the way security systems work now. So that I think is the first one. The second part of it is, are end users themselves ready for this security system to intervene and potentially coach them away from risky behavior? ‘Cause if I can predict the next thing you’re gonna do will put your computer at risk, or you’re falling for some social engineering scam, or you’re gonna run a command that could compromise your machine... I can’t just block it. Again, going back to the examples we talked about earlier, if it’s an agent, it’ll just keep trying to go through the steps. And also, humans do the same thing, by the way. If they get blocked, they just keep trying to go around you. And so having a system in place that intervenes and can also convince the operator, like, the next thing you do is gonna be really bad, it’s a total change in the relationship that end users have with security systems. And then the third thing is local hardware and the speed of the models. And we’ve done a lot here to build our own models. We can use what customers have access to. A lot of this relies on the local compute, which is changing. It’s getting faster. We’re getting more capabilities at the edge. And that I think has been playing out. It’s driven by broader market forces than just cybersecurity. In terms of what are the trade-offs, there really are no trade-offs because you can still go grab threat intelligence. You can still share within your own company or within cohorts. Whether you’re in financial services or government, there’s no reason you cannot share the threat intelligence of the types of attacks that you’re seeing with your peers, what is now magnified by the fact that you have both local reasoning capability and global threat intelligence or market threat intelligence. So I think this is sort of the best of both worlds.

Maggie 31:05

How do you think about combining both deterministic and non-deterministic models together in your platform?

Lou 31:12

Yeah. Basically, to answer the question on deterministic and non-deterministic, security controls generally are deterministic. And for example, access control. I’m either granted access or denied access, very strict, constrained. But I think where it becomes difficult is where you have unconstrained language models. How do you use such a thing in security? So the way we do it is we combine three forms. We start with the deterministic controls, which provide clear policy, clear, predictable enforcement, and that’s usually regulatory driven. If these things happen, I must block it. And then we layer in behavioral. So what action is normal for this user or the types of users that work in the company like this user works with, their role, we try to derive the role, and the generative models and multimodal models can interpret what’s ambiguous in this context and map it to intents, and then those intents will help you really understand, again, what is normal for this user. So a policy might start with, again, a deterministic, like, all right, I’ve got clipboard activity, and inside the clipboard is sensitive data. That’s fairly easy to determine deterministically. But now the action, like what is the user doing with that data, is non-deterministic, and then the destination is deterministic. Like, oh, I’m pasting it into Meta AI, I’m pasting it into WhatsApp. That’s very easy to determine. So, and then finally, looking at the entire action, and understanding the boundary conditions of the policy and reasoning over it and reasoning over larger time periods, for that we use reasoning models. And so we combine all three approaches, again, under a second, and that’s a very powerful thing because now you get the compliance things you need, but you also get this flexibility to deal with benign false positives and try to capture more recall and make sure you can broaden the net for situations which you’re unsure if you can act deterministically.

Maggie 34:01

And are these models that you all built yourself to be able to fit on an edge device, are these open source models that you’ve used or distilled?

Lou 34:09

Yeah. We distilled and we started with things that we can get, and there are certain things that we could build from scratch that are really useful for data classification and are becoming easier to build on your own. But for the larger reasoning tasks, we’re taking off-the-shelf models, just quantizing and distilling those down. But it’s still very, very hard work and you have to have training data and other scenarios. And the way we do that is we do have a synthetic environment which allows us to take real world information that we’ve populated with these virtual workers, these virtual workers that represent what you commonly see in the enterprise, and they are repeating tasks, and they’re repeating adversarial tasks as well. And so we can take that data without using any customer-sensitive information to help train and fine-tune our models.

Maggie 35:15

And are these reasoning models multimodal models? Do they have, like, vision capabilities to see the screen, or are they more relying on text data that’s coming in or current data?

Lou 35:26

Yeah, the model itself combines being able to operate on the operating system telemetry, which is very technical telemetry. The application layer, user layer telemetry, which is more human content, mouse moves, copy and paste actions, the text that’s actually on the screen, and what’s in a document, and then the visual aspect of what’s on the screen, using vision capabilities when that’s appropriate. And then many customers, they wanna change the way this behaves for different reasons, so we also allow customers to turn off some of these capabilities or tune some of these capabilities. And then the thing that we always do is we use very lightweight embeddings models and specialized small language models, and yes, those also can optionally have these vision capabilities. So we’re pretty deliberate in this, and we attempt to stay model agnostic when a customer is saying, “No, I wanna use this particular frontier model.” We choose the best model depending on the customer constraints, and also the limitations of hardware and other things within that customer environment. So that’s what we’ve been doing. I don’t think I’ve talked to anybody who says that, “Hey, this isn’t a problem.” It’s just a matter of how they’re gonna tackle it.

Maggie 37:01

Yeah, one question I have, and I ask this of a lot of companies that are building these AI solutions for mission-critical use cases. What have you done to build trust with customers to actually allow you to have these autonomous agents operating on these mission-critical systems?

Lou 37:21

Well, I think, again, it goes back to the way you’ve architected the system. Have you built a product so that you as the author of that product cannot see the customer data, you can’t control the environment? Once you’ve deployed it, it is completely in the hands of your customer. So we’ve designed... And some of this goes back to my background. I’ve done a lot of work in governments and critical infrastructure, worked at some of the largest tech players in the industry. And in those environments, these are table stakes things. Like, sensitive data must stay in the customer’s data boundary. Then it’s all about when the product is running, like customers see what we would have detected and how the product would have responded before we actually turn on interventions or prevention capabilities. And that creates a real proof, like this is what this product will detect, this is how it will respond. And once that happens, then... You know, we had just a kind of a story. We had a customer who was worried about inside risk and they told us, like, Ent is the first product that made them feel like an expert on the first day, like, explained what was happening in their environment in terms that they understood as an inside risk expert. And it took all these technical signals and put them together in a narrative that made sense to them. So some of that trust comes from just building the product properly for not just security experts, but the business leaders and the end users. It should feel... The product should feel natural. That’s one of the amazing things about this gen AI movement, is we’re actually able to build products that speak in the language of real humans. And so it’s a magical moment in building things.

Maggie 39:29

You mentioned that at some of your past companies, you’ve done work with the government, and in past roles you’ve had. Is that something that you all are focused on for Ent? Are there any defense or government customers that you’re working with?

Lou 39:41

So Ent is an American company. We’re built and headquartered in the United States. That actually matters quite a bit in this AI race, and it matters to us. We’re here for our government customers, and we care about accountability, having a supply chain that you could verify, like, where we wrote the code and how it operates. I also think the legal jurisdiction matters. Alignment with national security really matters quite a bit. Government and defense customers, they face the same challenges that we’ve been talking about in this podcast, but the impact is just so much greater. Like, AI attacks just have much bigger consequence in those environments. And it’s not that they want local control, they absolutely require it. They have to have a very decentralized system. Obviously, it has to be sovereign. The provenance of the data, everything has to work within very strict environments.

Maggie 40:52

You’ve been working on building AI agents for cybersecurity longer than probably almost anybody else on the planet. After your last company, RiskIQ, was acquired by Microsoft, you stayed on at Microsoft to lead their initial security co-pilot product development. I’m curious, where have you seen the tech change the most these last four years, and what have been the biggest surprises watching this tech evolve over the past few years?

Lou 41:19

Yeah, I mean, it’s been... It’s wild, but it’s five years of thinking about gen AI and cybersecurity, which is an awfully long time. So during that, I think the biggest change is we were using AI to help security analysts and make their life better, and that was more around summarizing incidents, querying systems, like things that security experts do or threat analysts do, really important stuff. And we’ve seen the models evolve from being great at writing code to now these agentic flows, which are amazing. The multimodal stuff has come an awfully long way in the last year. And then finally, these small models and being able to distill and quantize and run them locally, which makes all of the local security possible. So the biggest surprise to us really has been how much you can do locally now. I mean, I wish that was possible five years ago. It just wasn’t. And so that’s what we’re really focused on, and that’s the biggest change, is the speed and just how much you can squeeze into a smaller compute memory footprint. I’ve seen the whole thing evolve, and it’s been one of the more rewarding parts of my career, to be able to work on this technology, which I think is a dream for so many who’ve been in cyber and been sci-fi fans and dreamed of seeing the robots. It’s finally happening, so fun time to be working.

Maggie 43:15

Lou, I saw you made a post the other day that AI agents are going to kill the browser. Could you just talk a little bit more about what you mean by that?

Lou 43:25

So when you think about the modern endpoint, there was this trend with SaaS that got everyone thinking that, like, the web browser, and maybe this was Google pushing this narrative, I’m not sure, that the web browser was the center of the universe. Like, everything was gonna happen in the web browser. And frankly, as somebody who built RiskIQ, I’d say a ton of what we did was web-related. It was all around websites. What’s just totally fascinating about AI is it’s broken this concept of the web browser being the center of the universe. Like, I do not immediately go to Google and type in a search query anymore or go try to find a web page for a company. I start with my AI tool that runs locally. I type my query into that system, and my objective, and I let it go do the thing that it does best, and it comes back with a good summary. And then from there, if I have to fetch the page, I go fetch it. But usually, the AI agent has done that for me. And I’m probably on the more bleeding edge, but more and more people I talk to, they’re like, “Yeah, that’s exactly what my day looks like.” A lot of the security that we’ve built the last 15, 20 years has been around this narrative of external threats coming through the web. And if that vector is shrinking, you look at where we spend money, we should be allocating money very differently than protecting a usage modality of web browsing that’s actually decreasing. It’s not that we’re not using HTTP. We are. It’s just that the agents are actually running it, which gives you... It really contains the blast radius within that application layer. So I have more desktop applications now than I’ve had in a long time. You mentioned earlier, everyone’s coding again. I’m coding again. I’m bringing down local packages. So my machine has a lot more going on than just a Chrome browser running on the desktop, and I think the future is gonna look a lot more like many applications and agents running locally, running in the cloud, all talking to each other. And so that just changes the gates that we traditionally protected. So yeah, thanks for that. Thanks for reading my post.

Maggie 46:09

Of course.

Akhil 46:10

Lou, I have so many follow-ups. Can I ask one on that? Okay. Then how do you decide what runs locally and what runs in the cloud?

Lou 46:17

I don’t think you decide at all. I think the AI’s seemingly deciding, right? You describe to the AI what you want, and it goes ahead and writes code. It fires up a container, whether it’s inside WSL or Ubuntu containers. A lot of these local agents then run programs, compile programs, and run them locally. You could see a future where the user experience is then generated by that program. So instead of it being generated by the website in a DOM object that comes across the browser, the local AI agent is just gonna develop an application for you that’s purpose-built based on your intent, and that’s why that stack is going to increase at the edge, at the... or whatever the modern endpoint ends up looking like. So this is a reality. Anyone who’s been using some of the latest Anthropic or OpenAI local capabilities, you’re living in this future right now.

Maggie 47:25

You know more about building security startups than almost anybody else. This is your fifth cybersecurity company, right?

Lou 47:33

Yeah, that’s right.

Maggie 47:34

What advice do you have for early-stage founders building technology for some of these critical industries?

Lou 47:41

I mean, choose a problem where there’s a real cost to... where failure has a real cost. It’s a loss of something that you care about deeply, and I think that that creates passion and conviction for you and your co-founders and for your team. And then you gotta spend a lot of time with customers who respect that. And when you’re solving problems that have major impact, working hand in hand with customers is just very, very rewarding. And I think in terms of mission-driven customers and mission-critical industries, these types of customers are amazing ‘cause they know that... It’s really the passionately curious that can solve any problem with them. Yeah, so they make some of the best customers, and I would encourage founders who listen to the podcast, lean in on that. You probably have a lot more in common with your customer than you realize. And then the last thing for me is it’s always important to be hands-on with the technology. I mean, I’m an engineer. That’s my natural way of thinking, and I’ve seen these problems firsthand, and I’ve seen how customers have to deal with the problem, and I know how difficult it is to solve the problem, and that gets your brain thinking in the right way, how to understand the technology and build essentially a better mousetrap. So there’s really no excuse to not get hands-on with AI today. You can learn almost anything, and I would encourage everyone who’s thinking about starting a company, you wanna be, as a leader in that company, you have to really understand not only the problem that you’re solving, but really understand underneath the hood, how this thing works so you can...

Maggie 49:46

You said you learned Rust for Ent.

Lou 49:49

Yeah.

Maggie 49:49

Is that right?

Lou 49:50

Yeah, exactly. I actually never... I mean, in my programming career, I’d stopped programming when Rust took off, and then when I went back to work on Ent, Brandon and I were talking about what the right way to build this was. So I’m like, “All right, I’ll write a little Rust program.” It’s amazing what you can do with the help of AI or with our Clanker friends. And then the other thing I’d say is, don’t build a company around the models, like whatever the frontier labs have because these things are gonna change. So these models are gonna come and go, but durable value will come from the insight that you have working with your customers, the data you have access to, the evals that you’re building, the distribution that you’ve built, and the customer trust, which was a big theme in this talk here. And with those things, you build the right team that can execute and deliver consistently, and that’s kinda how you get to the promised land and build something super special. And then the top talent in the industry will be attracted to that. You’ll be able to hire the best, and turns out that those people also care deeply about the mission.

Maggie 51:12

I know some people are worried that the frontier labs are going to eat all other software companies. Obviously you don’t believe that, otherwise you wouldn’t be here building Ent. But what’s your take on how the future of these models and these labs are going to play out?

Lou 51:27

I think, if you look at Microsoft and what they did with cybersecurity, just as an example, they got very serious about security and have a great security business. Like, I would not, just speaking for myself in cybersecurity, I do think, will OpenAI have a security business? Probably. Anthropic already has a security product inside Claude. So obviously the frontier labs are looking for markets where they can apply their models, and they’re gonna have fantastic distribution. So there’s no question that that will continue to be the case. I feel like the harness and understanding these applications is equally important now, and we’re seeing that play out in other industries. So I would not fear as much the frontier labs. I would just focus on the customers and the use case, and I think you’ll build a great business.

Akhil 52:40

That’s right. That’s right. Yeah. Was there anything... I mean, obviously you’ve seen where Microsoft has been going. You’ve got these big providers here that have been on the front. What to you is a sustaining advantage to some of these larger security providers? Like what’s one area that you’re like, “You know what? It makes sense that Microsoft or CrowdStrike or name your entity are doing relative to the types of things that Ent is doing”?

Lou 53:11

I think there’s a major advantage that Microsoft has in their ecosystem of, with Windows and the O365 productivity suite and Azure. It’s just so much easier to adopt technology. They’ve made it extremely valuable. There’s so much value in those products. The cost, because they run Azure, there’s no way to beat the cost on storage and compute. When you’re a hyperscaler, that’s a tough thing to beat. So for us, we deploy our technology directly in the customer’s data boundary. If that data boundary is Azure, then great. We’ll deploy it inside Azure, and we’ll deploy it on the endpoint within Windows. I think it’s very difficult for anyone to go toe-to-toe and say, “I’m gonna beat Microsoft, Google, Amazon at the inference game.” I mean, that makes no sense at all. Or, “I’m gonna beat on storage.” Those are things that I think you let the hyperscalers take and you work with your customers, where you can add value. Generally, when I look at the security incumbents, the value that they have is they’ve been collecting all of this data on the security events that the customer’s been seeing. That data has value. It’s just at a different level in the stack. It’s describing device failures more than what’s happening where modern work is occurring. So modern work is occurring really in the application stack. I’m running these co-work models. ChatGPT has one, Anthropic has one, Microsoft has one, and a lot of the security risk is happening in that application layer, which the security incumbents traditionally have stayed away from. So modern work is all about moving up that stack. But that doesn’t mean that that traditional device-level malware and the network attacks, they’re still real too. So our view is we’re not gonna go back and compete with Microsoft Defender or with CrowdStrike as an antivirus or an EDR provider. Companies are relatively happy with what they get from those capabilities. It’s where they’re lacking visibility and prevention is one layer up that stack, and then unifying all of the other applications that sit on that stack. So it’s very much a complementary thing, and I think, time will tell, if that remains durable for those incumbents. It probably is gonna change too, but for the time being, we coexist with them, and I think it’s very much a better together story.

Maggie 56:31

Great. Well, Lou, thank you so much for coming on the podcast and sharing all your insights.

Lou 56:35

Thank you, guys.

Discussion about this episode

User's avatar

Ready for more?