Skip to main content
a16z Podcast

Building Defense for the Agentic Era: Kevin Mandia

49 min episode · 2 min read
·
Kevin Mandia

Episode

49 min

Read time

2 min

Topics

Relationships, Startups, Fundraising & VC

AI-Generated Summary

Key Takeaways

  • ✓AI Attack Scale vs. Human Capacity: A single AI system accomplishes in one microsecond what 70 humans cannot replicate at all. Defenders must internalize this asymmetry: human-speed detection and response loops are already functionally obsolete. Security operations centers need fully autonomous detect-and-respond pipelines, because any human-in-the-loop architecture introduces fatal latency against machine-speed intrusions.
  • ✓Continuous Hyper-Attack Methodology: Armadin deploys 25,000 coordinated agents in a "hyper attack" that maps every service, route, and asset on a customer network, generating terabytes of metadata. The system then polls for changes—new apps, updated routes, new machines—and attacks only what changed, making continuous pressure cost-effective rather than prohibitively expensive for large enterprise networks.
  • ✓Zero-Day Discovery Benchmark: Armadin found over 90 zero-day vulnerabilities at Fortune 500 production environments in the first months of 2026, approaching targets exclusively from the external internet with no source code access. The final several zero days were found entirely by AI agents without human involvement, marking a measurable inflection point in autonomous offensive capability.
  • ✓Open vs. Closed Model Parity in Cyber Offense: When Armadin tested both open-weight and closed frontier models against 20 real-world kill chains, all models reached the same maximum of 8 completed chains. Differentiation was speed and cost, not capability ceiling. For security teams evaluating AI tooling, open models given more runtime match closed model effectiveness, compressing the perceived capability gap significantly.
  • ✓Armadin Blue — Autonomous Compensating Controls: Armadin's second product layer, built in partnership with CrowdStrike and Palo Alto Networks, translates discovered exploitable risk into automated compensating controls pushed directly to endpoint and firewall platforms. The goal is a sub-five-minute window from vulnerability discovery to active defense, before adversarial models can exploit the same finding independently.

What It Covers

Kevin Mandia, founder of Mandiant and CEO of Armadin, explains how AI transforms cyberattacks from human-speed intrusions to autonomous drone swarms, why traditional pen testing is obsolete, and how Armadin's continuous AI-on-offense model found over 90 zero-day vulnerabilities at Fortune 500 companies in 2026.

Key Questions Answered

  • •AI Attack Scale vs. Human Capacity: A single AI system accomplishes in one microsecond what 70 humans cannot replicate at all. Defenders must internalize this asymmetry: human-speed detection and response loops are already functionally obsolete. Security operations centers need fully autonomous detect-and-respond pipelines, because any human-in-the-loop architecture introduces fatal latency against machine-speed intrusions.
  • •Continuous Hyper-Attack Methodology: Armadin deploys 25,000 coordinated agents in a "hyper attack" that maps every service, route, and asset on a customer network, generating terabytes of metadata. The system then polls for changes—new apps, updated routes, new machines—and attacks only what changed, making continuous pressure cost-effective rather than prohibitively expensive for large enterprise networks.
  • •Zero-Day Discovery Benchmark: Armadin found over 90 zero-day vulnerabilities at Fortune 500 production environments in the first months of 2026, approaching targets exclusively from the external internet with no source code access. The final several zero days were found entirely by AI agents without human involvement, marking a measurable inflection point in autonomous offensive capability.
  • •Open vs. Closed Model Parity in Cyber Offense: When Armadin tested both open-weight and closed frontier models against 20 real-world kill chains, all models reached the same maximum of 8 completed chains. Differentiation was speed and cost, not capability ceiling. For security teams evaluating AI tooling, open models given more runtime match closed model effectiveness, compressing the perceived capability gap significantly.
  • •Armadin Blue — Autonomous Compensating Controls: Armadin's second product layer, built in partnership with CrowdStrike and Palo Alto Networks, translates discovered exploitable risk into automated compensating controls pushed directly to endpoint and firewall platforms. The goal is a sub-five-minute window from vulnerability discovery to active defense, before adversarial models can exploit the same finding independently.

Notable Moment

Mandia revealed that Armadin tested all major frontier AI models against 20 documented real-world attack kill chains and every model—open and closed—plateaued at exactly 8 completed chains. The differentiation was purely speed and cost, not intelligence, suggesting the capability ceiling is already commoditized.

Know someone who'd find this useful?

Episode Transcript

You don't have a defense unless you have a great offense to go up against. You wanna be the Baltimore Ravens defense at 2,000. You kinda wanna have your practice offense really push you. That's what Armenon's gonna do. We're gonna be the all star team on offense coming at you so you can train your defense with what we're doing. But you built Mandiant, a great success. Why did you decide to get back on the field? I don't wanna sit out the AI shift change when I've done thirty years in security and the whole damn thing's about the change. What AI does in a microsecond would take 70 humans. They can't even do it. It's apples to oranges. This is a tsunami like has never been seen before in security. The whole let's slow down the models. We don't want cyber risk too late. The open models are already good enough. Arm it in since January of this year. We have found over ninety zero days at customer sites, all in production. This is not like rinky dink companies. Like these are like fortune 500 The differences or similarities between nation state attacks compared to AI today and then where you think AI can be in a couple of years. On the defensive side, we're gonna say we're being attacked by these models, but we're not sure who's behind them. Yeah. Is it a nation? Is it a human? Is it Kevin Mandia has spent thirty years in cybersecurity. His view of the AI transition is simple. Everything I did is dead, and then everything else is new. In this episode, David George sits down with Kevin, founder and CEO of Armadin and the founder of Mandiant, to talk about what happens when cyberattacks move from human speed to machine speed. Kevin explains why AI gives attackers an immediate advantage, from probing thousands of paths simultaneously to making less sophisticated attackers dramatically more capable. And he makes the case that there's only one viable response: defense has to become autonomous too. We also get into how Amedin uses AI to continuously attack customer networks, what the team has learned from finding more than ninety zero days this year, and why Kevin believes the next two years could remake nearly every layer of the cybersecurity stack. Kevin, thanks for being here. No, thank you. Okay. So you built Mandiant. Yes. Obviously a great success, many different chapters, you know, it ended up inside of Google ultimately. Why did you decide to get back on the field? It's a good question. And I don't know if I decided it and that'll sound weird, but I met with David Slater and with Travis Lanham, the other founders and Evan Pena I knew, I could say they started this company. They are the founders. I met them. They had the idea. They pitched me on what they wanted to do. And I saw the talent in them. Travis is a generational …

Get the full transcript (9,255 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all a16z Podcast transcripts →

You just read a 3-minute summary of a 46-minute episode.

Get a16z Podcast summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from a16z Podcast

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Business Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's Startups & Product Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into a16z Podcast.

Every Monday, we deliver AI summaries of the latest episodes from a16z Podcast and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime