00:00Weeks started with Jane Fraser, the Citigroup CEO, warning that everyone is racing to kind of
00:07plug these vulnerabilities. Is this a good thing for all of the companies that you cover?
00:13Well, so much has happened since March, right? When Anthropic came out and said,
00:18well, we can do vulnerability management and all the stocks tanked. And then they came back and,
00:23you know, after RSA, when Anthropic said, oh, we need some help. And then CrowdStrike and Pal Alto ran
00:30over. And then they raised again at the other inflection point has just been in the last since
00:36the Wall Street Journal article with, you know, the front-field models need to be paid. So things
00:41have really changed so rapidly in the last six months. And even within the enterprises, one example
00:46I could give you is they thought that one enterprise thought they had 300 agents and it turned out they
00:52had 18,000 agents across their network. So yes, right now we need, we went from AI that talks
01:00to AI, that acts, and now we have to act on it. So we need to identify and we need
01:06to know what the
01:07permissions are and we need to have runtime security is really important. You can't just delay this.
01:13And that's where I think you see some of the products that have just come out from both
01:17CrowdStrike and Pal Alto that address it. In fact, both of them made acquisitions at the end of
01:24Pal Alto bought Prompt AI for 600 and some million in February 25. That's now growing its fastest
01:33scaling product in the company. It's Prisma Airs and it tracks all these AI agents. And then you have
01:40Pangaea that was acquired by CrowdStrike that was procured last March, last December,
01:45that now has a whole product category called Falcon Guardian after it. And it's AIDR and
01:52that is over a hundred million in ARR in less than how many months. So yes, so these tracking these
02:00agents
02:00and protecting is a big thing. And that's exactly when we talk to, you know, every quarter we interview
02:0716 to 17 CISOs and over 20 resellers. And what we're hearing is the budgets are being really
02:14targeted toward how am I going to protect my infrastructure and what am I going to use?
02:21And these big platform players are getting an extra look because of that, because they already have
02:26some models in place like Falcon has Falcon Flex, which is their Trojan horse, which is an easy
02:33procurement model. You can easily add more modules on top.
02:38There's a lot of schools of thought, and I want to go through two of them in the time we
02:42have left.
02:43The first is the idea that, well, if the models are so capable, both on defense and the hypothetical
02:51of offense, do they just displace the legacy cybersecurity companies, similar with what happened
02:57in the SaaS apocalypse? No, no, no. In fact, at Feld.com, they had Anthropic on stage, Core Weave
03:05on stage. And basically the Anthropic, I believe he was the chief of marketing said, you know, we want
03:11to partner with them. We don't want to be in the business of doing cybersecurity. You know, we're
03:16leveraging CrowdStrike. We couldn't do this at the speed and scale they have. And what happens is you
03:22have these large companies in the cybersecurity space that have the telemetry and the data. And
03:28that's really what the key layer is. And that's the value added on top of the frontier models.
03:33When you go into an enterprise and say, I need to protect, I'll help you protect your infrastructure.
03:38What's critical is all the data that's been acquired. That is understand by these Palo Alto,
03:45CrowdStrike, Zscaler, Fortinet, you name it, whoever's in the infrastructure providing.
03:51So the second school of thought or idea is where is the threat? There is a distinction
03:58between models misbehaving. That's an alignment issue and presents a risk. And those very capable
04:06models falling into the wrong hands, the hands of bad actors. In your assessment, which is the
04:12greater risk that industry is confronting? I would say it's both. I don't think it's one
04:20or the other because we're running at speeds that we haven't seen before. I think the fact that the
04:26models, they're testing the models and you're seeing these is really important fact. And the
04:31fact that they might fall in hands is really not a good thing either. But the fact that you have
04:37companies like CrowdStrike that have, you know, have everything at runtime across all the infrastructure,
04:43across the endpoints, the cloud workflow, the identity, that is actually both a form of protection
04:50for anybody that deploys that. And so I would say both of them are not good to have, but having
05:00a
05:00defense mechanism is better. And there's got these companies have been preparing for that.
Comments