a16z

Kevin Mandia on why defense needs a great AI offense

Kevin Mandia· Founder & CEO of Armadin at Armadin
·~48 min·English·a16z
AgentsAI SafetyAI CompanyBusiness StrategyOpen Source
TL;DR

Kevin Mandia argues open models already make machine-speed cyber offense real, and the only workable defense is an AI attacker that continuously trains an autonomous AI defense.

01Core Mental Model

No Defense Without a Great Offense

Mandia builds the attacker first: Armadin Red is an AI offense whose only job is to harden an AI defense, the way a championship team's practice offense forges its defense.

You don't have a defense unless you have a great offense to go up against.

— Kevin Mandia, a16z
Key Insight
Mandia is inverting the usual security budget — he sells the attacker, not the shield. A defense that was never stress-tested by a real-grade offense is unproven, so Red exists to make Blue trustworthy.

02Threat Landscape

The Great Equalizer

AI does not just make elite hackers better; it lets weak attackers strike like nation-states, at machine scale and speed, which also makes attribution harder.

less capable attackers, less technical, less successful are going to appear way more successful. It's the equalizer, right?

— Kevin Mandia, a16z
Key Insight
The real danger is not that elite attackers improve — it is that the floor rises. When a mediocre actor lands like a nation-state, defenders lose the signal that told them how worried to be, and attribution gets harder, so they can no longer lean on knowing who is behind an attack.

03Open vs Closed

The Open Models Are Already Good Enough

In Armadin's own 20-kill-chain test, open-weight and frontier closed models both completed eight — closed only got there faster and at a different cost, not with more capability.

the whole let's slow down the models. We don't want cyber risk too late. the open models are already good enough

— Kevin Mandia, a16z
Key Insight
If open weights already match closed models on the one task that matters here — finding exploitable code — then slowing or pausing model releases cannot hold back offense. Mandia's remaining gate is anonymous compute: once GPUs can be rented without a name, he expects far more criminal attacks.

04Product

Red Teaming Eats Pentesting

Red teaming that proves a real, exploitable path is replacing pentesting's list of theoretical findings, and it runs continuously instead of once a year.

pen testing to me is always just scanning for what's already known and it doesn't prove whether you're really exploitable or not.

— Kevin Mandia, a16z
Key Insight
Pentesting produced a backlog of vulnerabilities that do not matter; Armadin's bet is that proof-of-exploit, not a longer list, is what a CISO can act on. The map-once-then-poll design also quietly turns security from a periodic audit into an always-on service — the recurring-revenue shape investors pay for.

05Autonomous Defense

Humans in the Loop Are Too Slow

When attacks move at machine speed, a human in the detect-and-respond loop is too slow, so prevention, detection and response all collapse into autonomous defense.

if you have humans in the detect and respond loop, you're going to be too slow.

— Kevin Mandia, a16z
Key Insight
Once response must be autonomous, the three classic phases stop being distinct — fast-enough response is prevention. That collapses the whole SOC operating model, which is why Mandia says existing roles, headcount and processes are all being re-examined.

06AI Safety

Cage the Beast You Built

Armadin built a model that successfully attacks production networks, so its hardest engineering problem is caging that capability without strangling its creativity.

make no mistake Armadin has made the beast that we're all worried about. We've made a model that attacks. We've made many of them.

— Kevin Mandia, a16z
Key Insight
The telling detail is that most agent kills are for wasted spend, not safety — the same classifier layer that keeps the attack-AI safe is what keeps it from burning money, and only the genuinely unknown cases get escalated to a human. The other lesson from the public incidents is organizational: you cannot secure an attack agent without marrying AI builders to people who have actually run offense.

07Company Building

In the AI Age, You Build It Way Faster

Building a security company in the AI age changed on four axes — funding, speed, branding and go-to-market — because the product now changes every two weeks.

here's the four differences. The funding, the speed, the branding matters, the go to market buildup. You have to build it way faster today than you had two years ago.

— Kevin Mandia, a16z
Key Insight
Mandiant could be slow and self-funded because it had no competitors and a premise nobody believed; Armadin has the opposite problem — a validated, crowded market. Mandia says he does not know how long IP lasts, so he plans as though rivals reproduce today's product within six months. That makes execution speed the only durable moat, so the company itself must be industrialized, not just the product.