Kevin Mandia on why defense needs a great AI offense
Kevin Mandia argues open models already make machine-speed cyber offense real, and the only workable defense is an AI attacker that continuously trains an autonomous AI defense.
No Defense Without a Great Offense
Mandia builds the attacker first: Armadin Red is an AI offense whose only job is to harden an AI defense, the way a championship team's practice offense forges its defense.
You don't have a defense unless you have a great offense to go up against.
The Great Equalizer
AI does not just make elite hackers better; it lets weak attackers strike like nation-states, at machine scale and speed, which also makes attribution harder.
less capable attackers, less technical, less successful are going to appear way more successful. It's the equalizer, right?
The Open Models Are Already Good Enough
In Armadin's own 20-kill-chain test, open-weight and frontier closed models both completed eight — closed only got there faster and at a different cost, not with more capability.
the whole let's slow down the models. We don't want cyber risk too late. the open models are already good enough
Red Teaming Eats Pentesting
Red teaming that proves a real, exploitable path is replacing pentesting's list of theoretical findings, and it runs continuously instead of once a year.
pen testing to me is always just scanning for what's already known and it doesn't prove whether you're really exploitable or not.
Humans in the Loop Are Too Slow
When attacks move at machine speed, a human in the detect-and-respond loop is too slow, so prevention, detection and response all collapse into autonomous defense.
if you have humans in the detect and respond loop, you're going to be too slow.
Cage the Beast You Built
Armadin built a model that successfully attacks production networks, so its hardest engineering problem is caging that capability without strangling its creativity.
make no mistake Armadin has made the beast that we're all worried about. We've made a model that attacks. We've made many of them.
In the AI Age, You Build It Way Faster
Building a security company in the AI age changed on four axes — funding, speed, branding and go-to-market — because the product now changes every two weeks.
here's the four differences. The funding, the speed, the branding matters, the go to market buildup. You have to build it way faster today than you had two years ago.