0:00
/
Transcript

AI Is Winning the Cyber Arms Race

A look at AI's impact on cyber and the case for orienting around limiting the blast radius

For twenty years the security playbook started in the same place, find a vulnerability, prioritize it, and patch it. Doug Merritt, CEO of Aviatrix and former CEO of Splunk, thinks that playbook is quietly breaking, and his explanation has nothing to do with anyone being careless.

The economics of offense changed underneath us, and most security programs are still funded as if they did not.


Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.


Why this conversation matters

Doug has sat in two seats that give this argument weight.

At Splunk he evangelized detect and respond, and now at Aviatrix he is arguing that detect and respond, while still important, is no longer enough on its own. That is not a vendor pivot so much as an honest reading of the incentives, and it lands differently coming from someone who built a business on the previous era.

If you are a practitioner watching AI rewrite the attacker’s cost curve, or a leader trying to defend a prevention-heavy budget to a board, this conversation reframes where the money should actually go.

Key takeaways

  • Offense became a compute problem, and that is permanent. Finding and exploiting a vulnerability is a search task, and the cost per token has been deflating faster than Moore’s Law. That is why this is a structural shift rather than a few headline demos, and why throwing compute at offense keeps getting cheaper and faster.

  • Patching has a ceiling that offense does not. Every patch carries the risk of breaking something, so testing, deployment, and organizational friction cap how fast defenders can move. When vulnerability discovery scales freely and patching cannot, “find more and patch faster” turns into a race you are structurally set up to lose.

  • The interesting question is not how they got in, it is where they went. Attackers increasingly arrive with valid credentials and move through the trust graph that runs across cloud services and CI/CD pipelines, including malware injected into trusted repositories. Once they look legitimate inside the environment, lateral movement and egress are where the real damage happens.

  • Cloud rewarded velocity, and security paid the bill. Cloud providers made identity default-deny because someone has to own and pay for a workload, but they left networking wide open because their economic engine is developer velocity and security reads as friction. New agentic frameworks inherit that same wide-open default, connected to the internet with little oversight.

  • A strong identity stance is necessary and not sufficient. Identity answers whether someone is allowed to act, not whether the action is an attack, which is why attackers log in rather than hack in. Human, agent, and workload identities are genuinely different, and workload identity in particular has been underserved.

  • Containment is about blast radius, not about keeping everyone out. The mindset shift is to accept that breaches will occur and to govern every path a workload can take, so an incident stays local and recoverable. Done well, containment holds firm whether or not anyone has detected the attack yet.

  • Blast radius has to become a boardroom metric. Doug’s argument is that CISOs, CIOs, CEOs, and boards should be able to answer how reachable anything is from anything else, and treat that number as something to drive down deliberately rather than discover after an incident.

  • AI is the reason containment is finally workable. The historic blocker to micro-segmentation was cognitive load across tens or hundreds of thousands of workloads. AI is strong at synthesis and pattern matching, which makes a staged path of observe, discover, monitor, and then enforce realistic, ideally starting with the internet-exposed workloads that have no filtering at all.

Notable quotes

developer velocity and security is friction

Doug, on why cloud networking is wide open by default.

It always is a lateral movement and egress problem.”

To say I’ve got a strong identity stance, therefore I’m good, is irresponsible.

Listen and Watch

Spotify

Apple Podcasts

Resources

Aviatrix Threat Research Center

Doug’s LinkedIn

Subscribe

If this kind of structural take on security is useful to you, subscribe to Resilient Cyber for more conversations and writing on cybersecurity, AI, and the incentives that shape both.

Discussion about this video

User's avatar

Ready for more?