Chi: AI cybersecurity risks are primarily in infrastructure, not code
“But actually a lot of the biggest concern or risk is in the infrastructure level. And so these are not things that are expressed in code, but take simulating larger environments of enterprise cloud infrastructure, or even grid infrastructure, for us to be able…”
Chamath: Defensive and offensive AI capabilities will produce cybersecurity stalemate
“There will be adversarial AIs that are battling each other. So for every bad actor trying to hack a system with some leading edge AI, the defender is going to have a leading edge AI defending itself. And I think that's going to cause roughly a stalemate.”
Isenberg: Modular AI Workflows Make Security a Founder Problem
“So most people use one chatbot today, but builders are already assembling their own AI work environments, like a coding agent, a research skill, a design skill, maybe a browser tool, a video workflow, and at some point, your setup starts to look like a little …”
Ehrlich says non-human identity is now a top-two enterprise cybersecurity issue
“How many cybersecurity companies you see in, in NHI, in non-human identity right now, an infinite amount. And there's a reason for that. It became a number one, number two problem right now.”
Bostrom: Advanced AI could eventually make cybersecurity defense-dominant
“I think for cybersecurity right now we're in a regime where attackers often win but it might be that in the limit if you have sort of An AI trying to find vulnerabilities and also patch vulnerabilities and you keep making the AI stronger, like eventually maybe…”
Bostrom: Biological Risks Exceed Cyber Threats Due To Slow Countermeasure Deployment
“And patches are a lot easier to roll out in the digital space. So, so maybe there's like some cyber thing. We figure out what the vulnerabilities we can release the patch. And then in, in principle, like almost immediately around the world, all the relevant sy…”
AI Handles Mainstream Tasks But Fails on Cybersecurity Edge Cases
“AI can be great at 80% use cases. We live in the .1% use case. We're looking for the needle in the haystack. AI is not good at looking at the, for every needle in the haystack.”
Palo Alto Networks Declared the Cybersecurity SaaS Downturn Over
“So, we declared the Sasacalypse for cybersecurity was over. We did not believe that we were going to get impacted, and you can see now that was six months ago, and we seem to be having a moment.”
Sharp: Cybersecurity faces a severe 12-month crisis before AI defense rebounds
“We're gonna have a really bad year. In terms of security, ah, and hacking in general, and people, ah, you know, being exploited. It's gonna be a bad year. But we only really have to go through it once. As the cost of this intelligence comes down, we will event…”
Dave Morin: US frontier AI models hobble cybersecurity and biological research capabilities
“Both the frontier models from the American companies have specific changes that have been made in their harnesses that hobble the model's ability to respond to certain types of tasks. And in particular, the two types of tasks that are the most on alert on watc…”
AI attack agents will operate 1,000 times faster than humans
“The day where a human would break in, and if you were 10 minutes behind the human on defense, you could stop the impact of a breach, is going to end. There's going to be an agent that breaks in, then another agent uploaded because it had remote code access, Re…”
Stamos: Cybersecurity Is Currently the Top Societal-Level Risk From AI Models
“You know, there, there's all kinds of risks from AI and, you know, there are all kinds of bad things that happen to consumers. But when you talk about the models themselves, it seems that cyber is the thing that's hitting right now, for sure, from a societal l…”
Stamos: Cybersecurity Faces Years of Total Chaos From Autonomous AI Attackers
“I think we're gonna go through a couple of years of craziness. Like, we have 20, we're all living using twenty-something years of really important software that was written mostly in non-type-safe, non-memory-safe languages. We're using, you know, for the soft…”
Herjavec: AI Is a Bigger Opportunity for Young People Than Cybersecurity Was
“If you're in your twenties, just the fact that you're in your twenties, you're a perceived expert on AI because you're young. So I think it's a bigger opportunity today than when I started.”
Coogan: AI That Hacks Software Can Patch Exploits Within an Hour
“So if you have a model that can hack a system, it can usually patch that system for that hack in far less than six months, like probably in like an hour, like it can see, oh, there's a exploit here and we ship the code, merged it in, and now that exploit is cl…”
Kolter: Security and science will explode as AI agents automate tedious verification
“So I think this is really sort of an underappreciated point that we're reaching this point, this sort of phase where a lot of security, a lot of science has this potential to kind of explode. Not because we're going to get better at it, but because agents can …”
Nikesh Arora: Palo Alto Networks market share grew from <2% to 8-9%
“When I started at Palo Alto, we were less than two percent market share in the entire revenue of cybersecurity. We're closing in on eight or nine percent right now, right?”
Arora: Cybersecurity will produce new multi-ten-billion dollar companies in 10-25 years
“There is room to build companies which have tens of billions of dollars of market cap in the next 10 to 25 years.”
Saxena: Enterprise data operations will adopt cybersecurity-level rigor
“We feel that data is going to start running with that same amount of rigor because that one incident puts you In bad light on the front page of a publication and it's not a good look for the company.”
Lemkin: Cybersecurity will worsen during a transitional phase as AI accelerates hacking
“As most databases are now built by AI, as more and more apps are built by AI the number of issues is going to explode, and if Mythos and Friends lets bad actors find every site the second it launches with any PAI and steal it, I think we may enter an era later…”
Anthropic's unreleased Claude Mythos model shows outsized cybersecurity capabilities
“Mythos is a unreleased frontier model. It's a general purpose model that was trained not specifically for cybersecurity or specifically for coding or specifically for software, but we have discovered what we believe to be outsized capabilities specifically in …”
1,300 cloud cyber platforms launched in five years, while SMBs got zero
“We just happened to ask the question, how many cybersecurity platforms have been created for the cloud in the last five years? And the answer is like, 1300. And then we said, how many have been created for the SMB in the last five years? And the answer was zer…”
Morin: Full-stack AI code generation breaks traditional internet cybersecurity
“A lot of the way that we built software, which was like, we're going to build all these little shims in between, and there's going to be all this open source software and I'm going to use yours and you're going to use mine and it's going to make my life easier…”
Raanan: 350 to 400 cybersecurity startups funded annually for 20 years
“The flow of new players into cyber security is quite steady for the past, I would say, 20 years. You know, you're looking at around, ah, 354 hundred new, ah, teams that get funded every year.”
Sidana: The x86 computing architecture is effectively dead
“These days I'm primarily focused on AI. Cybersecurity, data, and then I have a small practice in an area that I'm calling the depth of the x-ray six. So because the x-ray six architecture is now effectively dead that's going to create some opportunities, and I…”
Raanan: Cybersecurity is always a derivative of underlying technology shifts
“Cyber security is always a derivative
Of something else.
So if, you know, Windows operating system is new, then you need Windows operating security.
And if mobile is new, then you need mobile security.
If cloud is new, you need cloud security.
If AI is new, yo…”
Raanan: The cybersecurity industry will face its darkest period this coming decade
“I hope I'm wrong, but I think I'm, we are going to face the darkest, darkest period in cyber security in the next.
10 years.”
Padval: Cyber defense is an asymmetric problem ensuring endless market demand
“Cybersecurity is an asymmetric problem. The hackers, all they need is one IP address to get into a enterprise and then spread from there and disrupt the company. Whereas the enterprises have to be protecting it a hundred percent and no one's going to protect i…”
Hays: AI increases data value and makes operationally intense businesses defensible
“Proprietary data sets. AI makes your data more valuable, not less. Marketplaces and businesses with network effects. Operationally intense businesses, the bad businesses become the best ones, and cybersecurity and physical security. More AI equals more attacks…”
George: Push businesses get harder to scale as they grow bigger
“One of the things that I say about push businesses, which is, you know, you gotta go sell it. Like sometimes those are really successful and there's industries where this is the case, like cybersecurity and things like that. They don't tend to get easier over …”
Foster: Cybercrime Emerged Directly from Online Payments and Financial Transactions
“Cybersecurity, the whole thing exists because that's where the money was. It's the same, that old Willie Horton quote of like, you know, why did you rob banks? Well, that's because that's where the money was. It was the same thing in cybersecurity. The moment …”
Foster: Autonomous driving is a much easier problem space than cybersecurity
“One, I would tell you, like, self-driving cars is actually a much easier problem space than cybersecurity.”
Zuora CIO: AI markets in go-to-market and cybersecurity are super crowded
“So this one is putting a lot of pressure on the AI companies, the startup companies, then they have to keep up. Because it's very crowded, it's becoming very crowded, especially in the go-to marketing space and cybersecurity. It's super crowded, and so the ven…”
AI model capabilities on cybersecurity tasks double every six months
“The capabilities on cyber tasks of models are doubling every six months.”
IT and cybersecurity teams lack complete visibility into connected devices
“The more I talked to them, the more I kept talking to other security teams and IT teams, actually, everybody kept telling me sort of the same thing. We don't really know everything that's connected to our environment. We don't really have a good understanding.”
Axonius maintains an industry-leading Net Promoter Score near 80
“And we have one of the highest NPS scores that we know of in cybersecurity. It's like high seventies, low eighties.”
Cybersecurity products are binary: buyers will not accept partial functionality
“In cybersecurity, products are really black or white. It's not like the product Works 50% and somebody will buy it for 50% the cost. It's either it works or it doesn't.”
Founders must not sell risk-reducing security products to compliance-only buyers
“Never sell security to people that don't care. If you're trying to position a product that's genuinely going to reduce risk, don't try to sell that thing to people that only care about compliance or only care about checking the box.”
Steinman: Almost no industrial facilities worldwide have basic cybersecurity protection
“Most data moves over industrial networks unencrypted. Most industrial equipment simply receives any instruction sent to it with the proper protocol and just starts executing it. And so this is a huge problem. There's no security on industrial facilities on alm…”
Arora: Cybersecurity must consolidate into single platforms like CRM and ERP
“Nobody has two sales forces deployed in an enterprise. Nobody has two workdays deployed in an enterprise. Nobody has two SAPs deployed in an enterprise. Why? Because you need end to end visibility, a singular workflow, a singular set of analytics to solve the …”
A VC offered BuildDots a $4M seed round to pivot to cybersecurity
“There was another meeting in which we explained, and then this VC guy, he looks at us and says, look, guys, I'm not going to invest in construction. Okay, what the hell? What you are about. Now you guys with your background, say that you're gonna start a cyber…”
Dimon: JPMorgan spends around $800M annually on cybersecurity
“We spend eight hundred million dollars a year or something on it. We educate people on it.”
Rubin: Firewalls remain one of the largest cybersecurity spending categories
“The device is called the firewall. It's literally. 30 or 40 years into its life. Still one of the biggest categories in TAMs in cybersecurity spend on the planet.”
Arora: Outsized cyber returns come from startups securing new attack vectors
“The most likely categories which will see outsized returns are categories where a new attack vector is being born. And there are many ideas about how to secure the attack vector, and many people are experimenting.”
Song: Persona learns more from cybersecurity than identity verification peers
“A lot of our learnings these days is not from like, you know, just like identity verification companies from cybersecurity, like cybersecurity has a long, long history of threat detection. And like, it's fundamentally in this bad actor kind of, you know, detec…”
Dhillon: LLMs allow grandmothers to become cyber scammers
“It's not only that grandmothers are the ones being scammed, it's actually grandmothers can become scammers now, and it's because, right, because it's like, it's just easier than ever and that's actually the real issue. It's like, sometimes people talk about la…”
Arvatz: Governments are rarely on the cybersecurity cutting edge due to air-gapping
“It's not that governments are in the cutting edge of doing cybersecurity. They typically aren't. Why? They don't need to, because they're not connected to the internet. So the risks are very different than the risks of the average company.”
Arvatz: Cybersecurity startup seed rounds today are no less than $6 million
“Today, seed round for a cybersecurity company is no less than six million dollars.”
Zhang: Enterprise adoption of cybersecurity AI agents will be slower than expected
“And so because the models are inherently non-deterministic, It's very hard for buyers like really trust a gen AI solution there. And so, especially agentic solution. So like, I think that option there is going to be really, really, really slow, a lot slower th…”
Cybersecurity startup CMOs cannot succeed without a deep security background
“I really don't know how somebody that does not come from a
From a security background could kind of be successful deeply in this type of a role for a company like Wiz, because it is really about understanding your customers and it is really about understanding…”
Liwer: Companies pay $50/user on CRM but resist $15/month for cyber
“Everybody in this room will spend easily 50 bucks a user on CRM, but they won't spend 15 dollars a month on cybersecurity.”
Lorenc: Cybersecurity issues get ignored until attackers actively exploit them
“You know, you can talk about stuff all day long, and until attackers actually start looking at it, ah, nobody cares.”
Nikesh Arora Had Zero Cybersecurity Knowledge When Becoming Palo Alto Networks CEO
“The hardest part was being stupid. Like, you know, I don't understand. I did not understand anything about cybersecurity.”
Arora: Top cybersecurity market leaders change completely every ten years
“The stars of 10 years ago are no longer the stars of today. So that's kind of very unique in cybersecurity.”
Sasi: Learning cybersecurity from books is ineffective without hands-on lab practice
“Cybersecurity isn't a topic you can read and learn from books. That's like the most bullshit way of Learning cybersecurity. It has to be practiced. So for that, you need the lab facility, or you have to look at real world scenarios.”
Sim: Cybersecurity will be exempt from the tech antitrust M&A freeze
“Very few, huge M and A's because of antitrust, maybe save cybersecurity, which has national security interests and those things tend to go a little bit faster.”
Hoffman: AI cybersecurity and workforce transition tools are underdone startup areas
“There's areas that I think are underdone that I would really like to see. Cybersecurity with AI. You know, I think it would be very good to have that relative to society. I think that the notion of you know, how do we make these transitions for the white colla…”
Ed Sim: JPMorgan Chase spends $1 billion annually on cybersecurity
“And JP Morgan, for example, spent a billion dollars a year in cybersecurity.”
Noon: LLMs excel at filtering noise in raw cybersecurity operations
“There's a lot of just raw operational work that happens in security of just like, we need to, you know, rarefy this signal, filter out the noise, and then honestly feed it through a human being who has some experience as to what the bad guys are trying to do. …”
Noon: Using LLMs just for phishing spell checks materially increases attack success
“Like, if all they could do was, like, spell check the bad guys, and that's all you were using, like, whatever off the shelf, you know, open source LLM for, like, even that would make a difference materially on, you know, cybersecurity policy returns.”