← All transcripts
EP. 09

Do AI or Be Replaced by AI w/ Craig Adams. AI-Native Future of Cyber Offense, Defense & Product Mgt

June 7, 2026 · 54 min ·Craig Adams
Watch episode on YouTube
~50 min read · 129 exchanges
Mehul 00:01.144

Craig Adam, it's so nice to have you on Noise to Signal channel. You are you are one of the most accomplished product leaders in cybersecurity. You've been building, scaling products for over 20 years. Recently, you're the chief product and engineering officer at Recorded Future. And most recently, you are the Chief Product Officer at Rapid 7. The thing I wanted to start with, the start the interview with is the the role of a product manager.

is changing in the age of AI. The reason I say that is historically, as product people, you would go talk to customers, you do the market research, you would talk and bring that into into requirements, talk to the UX team, refine it, iterate with the UX team, then go back to engineering, put that on a sprint plan and so on and so forth. And now what is happening is the product guy can build can actually build the prototype. The UX the UX guy can build the

the product and the engineer is sitting there. Why do I need the product and engineering people here? I can build the product completely end to end. So it's a game changing from a product perspective. As a product leader who's been building and scaling products, what's your point of view? What's the what's the role of a product manager in the age of AI?

Craig Adamns 01:15.574

first and foremost, I really appreciate the opportunity to be here with you. I'm a big fan of this series, so thanks for allowing me to join. So the second thing is first, the role of the product manager has fundamentally changed in the world of AI. Let me first start of the analogy of waterfall software development. It's debt. the notion of I write the long doc, which I hand off to someone else, who then hands off to someone else, it's just fundamentally over. And so we are now at a stage that agile

And and I mean agile from a total software development lifecycle is what we're going to be implementing, not just the engineering coding portion at the end of the day. And so, first, if we call waterfall dead, the product managers still, if some things stay the same and other things will change. The things that stay the same, the ability to come up with the right strategy to win, the ability to come up with differentiation, the ability to identify the moments that matter and the experiences that matter, which is more critical in the world we live in.

All of those things stay consistent. What is gonna change is the skill set and skill demonstration that product managers are gonna have to have. It's no longer gonna be primarily assessed by the comprehensiveness of documentation that you write or the insights. It's gonna be the ability to come up with rapid feedback loops of my ability to have an idea, prototype it, run it by customers all myself in a way that then will change my downstream software development partners. It also means the role of engineering has changed.

Mehul 02:37.762

Yeah.

Craig Adamns 02:38.044

Or the idea of getting a document and writing code, that's out the window. we're gonna be moving to a place where agentic you know, agents are gonna be prompting the engineer of the task that they need to do. But it's such an exciting time to be in tech. this truthfully is the opportunity of a lifetime, and I think there's no better role than product management to help.

Mehul 02:58.452

It it's funny because I've seen engineers who have written more code in the last year than they have written in their entire year entire career. But they they now they're saying they haven't even looked at the code sometimes. Like you know, sometimes they are not the it's getting to the point where the product the code is so good that they're not actually they're looking at it from an architectural point of view and so on, but not like, you know, doing like a real code review. The follow-up to that question I had for you, Craig, was

The does the product role change based on the type of industry you are, whether you're you know, w whether you're in a service type of a product leader or you're building enterprise software, does that change at all? Because you've been in all these different positions in your career at Recorded Future at Rapid Seven. The does the the role of the product change depending on the type of the industry?

Craig Adamns 03:43.925

So so direct answer is yes, but there's more in common that's different. So for example, if someone's in B2B product management versus B2C, it's a radical different skill set, it's a radical different approach, it's a radical different metric structure that you use in how you define success.

With the with those differences though, I still think there's a common core at the end of the day, which is fundamentally the ability to both set a strategy, vision, execution, go through then and define the areas that make sense to grow the business as well as the areas that we should not do, because a good PM spends more time saying no than yes at the end of the day. there's more of a common core than difference. What I will say though.

Mehul 04:17.697

Yeah. Yeah.

Craig Adamns 04:22.918

So if you go from B2B in different areas, I think if you go the difference between a intelligence product manager, so part of my career, or a network-based product management, or a services-based product manager, those have radical different lifestyle attributes of how you have to think design. So for example, if the end product is someone's gonna consume my technology, that's different than if my end product is a human or an ingenic agent is gonna consume my technology to do something for a human. So but it's still a big common core with a round out.

At the end.

Mehul 04:53.655

Do you think the product role takes more on the UX role?

Craig Adamns 04:57.364

done. so let me be let me be super clear. Th those two have merged. So if you talk about what's the skill profile in the future, user experience, I do think the ability to come up with design systems, libraries, standards is absolutely critical. So no one is trivializing it.

But if you do this the right way, your GENTEC code takes that into account at the end of the day. So in other words, you still have your user experience team creating, for lack of a better word, your libraries. But once those libraries are created, what you're end gonna have is the product manager is designing the capability. The user experience team probably is gonna own more of the end-to-end experience journey of the customer across the platform at the end of the day.

But but all the rules are changing in I think exciting ways. I can't emphasize that enough.

Mehul 05:47.358

And know, in our field, a lot of these roles changed in the previous era. Like we have the SecOps and then we had the DevSecOps. And I wonder if there is this new role that emerges from this where it like gen DevOps or something, or product engine ops or something. I don't know, maybe we should coin a new word and like, you know, and claim clear and and have that name to claim.

Craig Adamns 06:08.232

Register the domain now. it's a critical becoming trademark, just go all in. So I I think you're there, but but I think this is a a common thing we've always seen in technology evolution. And so remember with the role of a prompt engineer, which sounds almost quite quaint to total

Mehul 06:13.453

Mehul (06:24.277) Yeah. And apt at it. I I mean when I first saw it, the w what is a prompt engineer? That can't be a real role.

Craig Adamns 06:31.614

But but now that role, I would argue, has gone out of fashion. Like I argue there there's no such really distinct job or a skill of a prompt engineer. And so I think through all of time we've seen innovations come requiring new roles, and the new innovations come that evolve and change those roles in new ways. And so I absolutely think we're gonna see different roles come up, which means the people that are successful.

are gonna be those that are actually living the growth mindset. It's the lean in, authentically in every form of have they adopted the capabilities an organization has? Are they leaning in and how they're going to be relevant in contributing, as opposed to the reluctant laggards, they're screwed, just to hit it really directly, they're gonna have a tough, tough run at the end.

Mehul 06:58.635

Yeah. Yeah.

Mehul 07:16.277

And one other thing that happens is that you know as more people build software, as more more software comes to you know, comes to the comes to the top, it's one thing that becomes difficult is you differentiating yourself, you know, whether you're in product marketing, you know, I saw this firsthand at RSA and and this is one of the reasons I started noise to signal because there's just just way too much noise in in terms of differentiating yourself.

Right. And I was at RSA, I was looking at the booths and everything was agentic AI, cyber security. And I was recycling of the same words over and across every booth I was walking through. And I was like, How does an you know started startup like my s mine like differentiate himself? And it's very crazy. It's crazy, right? So I'm curious, what you what's your point of view in this world where everyone is claiming to be AI native, AI forward, or what's the what's the word that they're

forward deployed. Forward forward deployed and AI factories, whatever it is, whatever AI, AI native agent would they add to it. I'm curious what you think of that in the age of AI.

Craig Adamns 08:26.356

so first, I feel I feel both your pain of walking around at RSA, the the notion of everything sounds the same has made it truthfully for our buyers to have to be detectives to actually figure out what people do and what they do differently. And so that this has been the the the curse of the security industry is in f simply put, vendors making all promises that sound the same and then putting the onus on the customers to have to dig through. I think there's two parts that

Mehul 08:42.274

Yeah.

Craig Adamns 08:56.02

We're gonna as a trend. So, first, as sales cycles have changed, this notion of like I'm uncovering, identifying solutions, customers aren't walking anymore in the same volume around booths to learn of solutions to technologies at the end of the day. What they're actually doing is spending more and more time actually asking AI.

Mehul 09:14.871

Yeah.

Craig Adamns 09:20.328

With the problem I have, who should I be evaluating, compare and contrast across it? And so we're gonna see the world of like SEO from the past actually change into it's gonna be like AI SEO of like how do I optimize? So the text files that we put into pages so that we're giving the instructions to the scraping engines of what they should be paying attention to and telling them what to focus on and what's really important. that is gonna be a skill that of course will also evolve, like many of our engineering roles.

Mehul 09:45.868

Yeah, it's called it's called I think it's called AEO. I there is i there is a new term for it, is and first time I looked at it, what is AEO? It is AI yeah, AI engine in AI engine optimization, yeah.

Craig Adamns 09:50.291

So correct.

Craig Adamns 09:54.781

It's a thing. It's a thing. It's just how you optimize. That's exactly right. It's how you optimize your content so that you're giving AI agents instructions of how they should process read and what to pay attention to at the end of the day.

And so it's a fascinating field, but if we go up a level for a second, our question we're talking about is how do organizations differentiate? And and I think we're gonna enter phase of SaaS simplicity times 10, where organi buyers are gonna look at skepticism to every company they hear an amazing pitch from, and they're gonna want the ability to quickly see try in a safe way.

And so I think that's gonna mean in a certain world I have sandbox environments, I can play with things. I'm not gonna wanna speak to sales reps, I'm gonna wanna quickly go through, and I'll use the phrase quickly independently without the level of engagement. I think that we're gonna see the rise of I'll call it old forum content of the demo verti videos versus demo humans are coming back. Okay, it's cyclical on how it's operating, but the willingness of customers to speak to humans to learn everything they wanna learn.

Those days are just over. And so organizations are gonna have to face it. Now, who's gonna win are those that don't describe the feature function, but they focus on the outcome value that a customer gets at the end of day. Because truthfully, there's a lot of slop in cybersecurity of I have a capability that does X. No one wants a capability, no one wants another tool. They're actually looking to get an experience and outcome. And the organizations that talk that way, design products that way, and deliver that way, those

Mehul 11:37.024

And in some respects, I think in some respects the human led demo was already trending down because that was the rise of product led growth. You know, it was like let me try the product and once the you know once the user tries the product, they love the product, they share it with somebody else, you know, the links and the referrals that was already on that pad. You are already on that one. I I think AI just you know super supercharges that that journey that

Craig Adamns 11:42.484

Correct.

Mehul 12:02.903

Customers were already used to let me try it, let me use it, let me get the value. And once they are getting value, they like I have personally had this situation where I started with the twenty dollar cloud code subscription. I run out of my my usage. And then I'm like, dude, I need I need to do more work. And here I am flipping my credit card, you know, let's go to the hundred dollar version and then two hundred dollar version and so on and so forth. So I I never talked to a single sales guy at at Anthropic or Cloud.

Craig Adamns 12:31.69

But but I think this is if we multiply further on the product growth side. while everything is branded because AI is the buzzword of the century, an AI product looks like an AI product. You don't have to have someone tell you what AI is doing. And so I think the organizations that are gonna be successful are gonna be the ones that actually take the time to show work, show work product of what's actually being done. And so in an agentic world, one of the biggest fears many organizations have is the black box. It's when the

Robots go rogue, chatting in a chat room with each other about who's the best and how they can penetrate an organization. But I think people that embrace transparency to the tenth degree of how do they go through in and show work product actually will excuse me, show work product without detracting from customer experience. Those are gonna be the ones that have a real opportunity for exciting success. but if you're an AI product, you gotta look like an AI product, you have to feel like an AI product.

And that's gonna be a key part of both product management, product design and execution.

Mehul 13:35.566

Makes sense. Now let's let's switch to a topic that is near and dear to both our hearts, vulnerability management. let's talk about mythos. one of the narratives, this was like two or three months ago, is cybersecurity is dead, VM players are dead, there's all these AI players are going to take over the market share.

Craig Adamns 13:44.964

Litos. I haven't heard of such a thing.

Mehul 14:03.917

anthropic is going to do everything. and my when I read it, that doesn't make sense because obviously these new models are finding new vulnerabilities at expon at exponential scale. They're finding thousand, ten thousand vulnerabilities that is historically in like 10 standard deviations away from what's the normal standard.

Craig Adamns 14:13.288

Right.

Mehul 14:24.053

And my thinking on that was the exposure management players, the vulnerability management players, the defenders will be in more demand because somebody still needs to detect them, stun somebody still needs to help organizations remediate them. And they cannot obviously patch everything, but like they will provide recommendations for compensating controls and you know, because these are all the things that need to happen. And and the sur and now it is actually changing, but i the initial glass wing was we are only going to give access to NVIDIA.

Microsoft and Google. And I'm where is Callis, Tenable and Rapid Seven? Like these are the defenders. Where are where are the defenders? There are no defenders here in this glasswing program. You're creating all these findings and vulnerabilities. And the guys, the enterprises, like you know, I think if you collectively look at Tenable, Callis and Rapid Seven, there are sixty thousand customers across all all the you know key defenders that are out there, and they're not even part of the program. And I was like, what is going on here? so I'm curious, what was you know, you obviously saw the mythos.

hype roll out and then you obviously saw the your customers asking what do we do about me those and there is nothing to do because there is what do we do? There is nothing to do at that point apart from doing like a board level pitch deck. So I'm curious what you think of the old Meatles hype that has happened and the response from from your point of view.

Craig Adamns 15:37.204

Yeah.

Craig Adamns 15:41.195

At Rapid 7, we're excited about the announcements that are happening around Mythos and otherwise. And I'll tell you why, which is it's it's changing the problem statement of the industry. So to be very, very clear, I do think discovery and verdicting, discovery gaps, verdicting gaps, those two are things AI does really well. That that is an AI disruption. We should call out, identify, acknowledge that that's an incredible innovation. The problem is back to what you and I were talking about a little bit ago, like what's the problem of kind

Customer has to solve. The customer problem is not a just a raw discovery problem, or it's not a raw verdicting problem at the end the day. They have a fundamental exposure problem. And so what all of these innovations are going to do is it's going to put much more pressure on the response side. Response if it's a vulnerability, a cloud misconfiguration, response if there's something malicious inside of my environment, alert that fires at the end of the day. And so

In the spirit of harnessing the innovation, not fighting it, I actually love what it now does for discovery. The the challenge is the typical organization has discovered more things already than they can fix. So putting five X more things into their discovered bucket of things to fix is a non-sustainable cybersecurity model at the end of the day. And so where I think we're gonna see the evolution from.

Is absolutely the both number of vulnerabilities and using vulnerability exposure, pick pick your word, the identify risk inside environment. Those are going to multiply, which means organizations are going to have to have a different strategy because they're not going to be able to patch their way out of it. Combined with the time to exploitation that AI is driving from an attacker perspective. And so this is where I view the innovation as exciting because now it's going to move it to the actual outcome that a customer wants.

Mehul 17:09.835

Yeah, risks. Well yeah, it's yeah, risks in general.

Craig Adamns 17:32.715

So, where does it leave a customer thing? Hey, whoever they work with, they're gonna get the detection capabilities as part of it. But I'll tell you, people aren't buying something for detection. They're buying for the remediation, the response, the action side of things. That problem just got worse, which means the case for why an organization still needs a capability to address it is still as strong as ever.

Mehul 17:59.659

Yeah, w one of my biggest distaste about selling cybersecurity software, it it relies overly on fear mongering. The the and I have personally disliked that aspect of it, the fear mongering and scaring people in terms in terms of buying something. And I think mythos has in some ways mythos has been a has the has been a boon because they're generally scared out of their mind.

And a lot of l lot of the executives I talked to, they don't mean mythos came out. They didn't they said Mythos bad. Mythos coming out, mythos bad, right? So that is like the narrative that went out. And then and then there was no real good solution out there. Like, okay, what do we do? we don't we we are not going to disclose the vulnerabilities, we're not going to tell you anything about these. They're gonna come out sixty or ninety days later. But mythos bad, right? Mythos bad. And then the executives or the non technical executives, they're sitting on the boards and they're hey, Craig.

So what are you doing about mythos? And Craig is thinking like we don't have the details, but sure, here's a you know here's a step by step plan.

Craig Adamns 19:05.098

So so I actually so I have a view there. So like we're working with Enthropic, we're working in OpenAI and all those organizations of how to do that. I think the biggest statement I would make, and I and I and I believe this with every ounce of my body, which is in cybersecurity today as a fundamental perspective, we don't have an information problem. That's not the dominant problem we're having. so so if I view methos accelerated information,

Mehul 19:28.002

Yeah.

Craig Adamns 19:28.706

Which it does, and and mythos, open AI, like all all the different vectors of it, that is phenomenal. That just made the existing problem we had worse. And so the question now, and this is where we're gonna see you know different organizational profiles, is how excited organizations are gonna be, excited was in air quotes, about well, if I am using AI to gather more information, how much do I want to enable AI to make it actually implementing my compensated control?

Mehul 19:37.452

Yeah.

Craig Adamns 19:57.995

Which is net net, like can AI write to my organization, not just read, not just verdict, but actually change, lock the CEO's machine, things of the sort. And this is where you're gonna see a caution zone of, I believe the organizations that win are gonna have the most robust response options available for customers to leverage at the end of the day. But but this is a zone of well, sorry, there's one thing we haven't talked about as I'm bouncing around, forgive me, is wild increased.

information, it did also binarily decrease the time to exploitation when the vulnerability of risk exists in the environment. So so I do think the traditional cybersecurity model of identify a risk, prioritize it among a team, have a team go

Mehul 20:33.814

Yeah. Complaining.

Mehul 20:44.66

It really is. Yeah, it's all dead.

Craig Adamns 20:46.718

We don't have time for that anymore. And so it's gonna mean back to the response side of how do we implement compensating controls. That's gonna become more critical than ever before. And people are gonna need technology. I'm not sure people are gonna look at anthropic to to ride across their environment. I I don't see it yet.

Mehul 21:06.076

What's what's real and what's hype when you read about all these announcements around AI? Like one one thing I've seen consistently is fifty percent of our jobs are going to be replaced and these jobs are not going to be relevant anymore. And I mean I'm conflicted because I feel like if you have a team that is skilled, you essentially 10x every member of your team.

Craig Adamns 21:33.81

That's

Mehul 21:33.985

With AI, right? And you know, instead of cutting, you're essentially cutting yourself off. Like it like cut if you had a kick-ass team, had like great researchers, and you had great engineers, and you gave these tools to them, they in our my humble opinion become much more competent in what whatever they were doing. and I I mean, maybe maybe there is some jobs that get replaced because they were not.

valuable data. But but I feel like in net net net net the number of jobs will increase because we are now doing more coding, more managing of the software than before ever before. I'm curious what do you think of

Craig Adamns 22:14.494

Yeah, so so I have a few different thoughts. So so first, with every material technical innovation, there's always a displacement of what rules exist, what rules don't exist. So so I think this idea of churn, which is change will happen at the end of the day, absolutely is occurring. the second, if I look at the field of cybersecurity, I have religious level conviction that the number of defenders that work in cybersecurity will be more in the future than less, even in a post-AI world at the end of the day.

Mehul 22:40.896

But you know, when you say the defenders, do you think the instances of AI agent defenders or like human defenders?

Craig Adamns 22:46.95

In this specific case, human defenders. And by the way, I absolutely believe in every ounce of my body, the robots are going to do so many more tasks than humans. So it's going be clear. The robots are going to churn of what's done by a human and that's going to evolve across an organization. But if we just take a step back for a second, and maybe to make an analogy, if you look at the world of cybersecurity 20 years ago, I mean I'm hand-waving numbers. 20 years ago, everything's on-prem. So I understand, I understand what I'm trying to control, protect.

Mehul 23:12.084

Yeah.

Craig Adamns 23:14.44

Hey, then I move to the world where cloud's enough. Now I have things I'm trying to control, protect outside of my environment, but that's a step function of complexity. Then I go to the world of SASIFICACON where my crown jewels may not be inside of my environment and my cloud that I can control in any way. That's something I have to protect. Now you're going to an agentic world where I've got machines and robots running around. You're we're we're we're increasing this complexity of cybersecurity in nonlinear ways. Yes, we're gonna make house certain tasks way more efficient than I've ever been.

Done in the past, but no way, like zero percent scenario, are the number of defenders, the number of people in information security departments in aggregate going down across the horizon. Where I do think we'll see changes is when we look at an organization creating software development. So so I I think the the changes we're gonna see

That inside of technical organizations, you're gonna see an impact. And we're already seeing it if you look at the number of CS graduates coming out of universities. It's now in a decline from a peak in the past, and that's projected to continue. so you're gonna see disruption and churn. So I'm specifically focusing on the information security teams, the teams under CISOs and organizations. Those I have religious level conviction will be a size. Throughout society as a large, we're gonna we're gonna have a fair amount of churn where new jobs are being created.

old jobs are going away, but that happens with every technical innovation.

Mehul 24:40.662

But do you think like the there are any any roles that will get replaced, like the tier ones will get replaced with more tier twos?

Craig Adamns 24:48.753

Absolutely.

So so so if you ask my zone that like what what makes me up at night is entry-level positions are the center of the bullseye for tasks that AI can do in a more effective way, as a general statement. Having said that, let me look at Rabbit Seven's game. We're obviously using AI to do more and more things inside of our SOC. How do I have machines investigate alerts as opposed to humans? at the same time, we're not planning on reducing the size of our SOC.

We're actually going to use those people on higher value security tasks. Because if we look at the cybersecurity model, and maybe that's the punchline at the end of the day, there's always been change and evolution. And what was hard becomes commodized and what becomes more efficient with machines, you see this a churn is just the best word to use. At the same time, the problem hasn't been solved.

And so, even with more tools, more information, the number of organizations compromise continues to grow year over year. The dollar impact of compromise goes year over year. And so what we're to find is people moving up the security maturity journey in a more rapid clip than I believe we've seen in the past. Most organizations, if you corner the CISO over a glass of wine, don't say my security posture is perfect in how I operate. They know the zones that they need to.

Mature. It's a maturity journey. And I think what we're gonna find is AI is going to make certain tasks more efficient, allow more eff emphasis on other parts of the maturity journey. And I'm not convinced boards or C S or CEOs are gonna look at cybersecurity as the first area they wanna reduce their spend or reconfigure their workforce. I think they might look at a few other areas first.

Mehul 26:15.339

Yeah.

Mehul 26:36.6

talking about the you know, AI driving efficiencies, one of the things that are getting that is going to get efficient in the age of AI is the exploitation in the age of AI. The there is a rise of AI native exploitation. Craig, I started my career as a vulnerability researcher at Hannibal.

And I used to write exploits and it used to take time, a lot of time, days, weeks to get an exploit working safely so that we can push that into an SS plugin and then test it. And you probably know it from the Metasploit, the Metasploit project that is in Rapid 7 takes a while to get a functional exploit code working. Now, you know, writing an exploit essentially takes a prompt. Right? So I mean you can read not like as good as a Metasploit.

Craig Adamns 27:17.298

Yeah, it it's it's a few lines.

Mehul 27:21.224

Exploit but you can reasonably get to a point where you can prompt your way to an exploit. Right. what's the what's the future of EI native offense from your point of view? Like in this world.

Craig Adamns 27:32.471

so this is so this is where I look back where it's almost adorable to me when

security teams were nervous about using AI inside of an organization. Because every technical innovation starts with a fear inside of security teams of doesn't matter what the technical innovation is cloud. Like, how are you gonna secure the cloud? the the attackers are utilizing AI with such incredible efficiency, nonlinear impacts of how they're able to both identify exploit.

penetrate an organization that the the biggest risk is gonna be for defenders to not use AI versus any incremental AI risk that exists. Imagine the scenario in the past of the phishing emails where it was the Nigerian prints and you want to have $20,000, but it was almost like comical in proportions.

It doesn't matter the threat that you're seeing. if it's the ability to tackle fishing opportunities, if it's looking at how do we penetrate and identify an organization, find lateral movement across an environment, the time to exploitation is becoming your instant. And and so this is one zone where

Mehul 28:39.052

Yeah.

Craig Adamns 28:42.002

I believe you're gonna see a lot of focus on attack patching. You're gonna see a lot of focus on compensating controls. You're gonna be able to see a lot of focus of, I'm calling robustness of response actions. utilize the the old model used to be isolate the device, isolate the identity. Those are the two like go-tos when you'd see something go wrong. In a new world, things are gonna move so quickly that we're gonna have to immediately shut down access to sensitive data systems or otherwise as we go through the organization.

Mehul 28:52.204

Yeah.

Mehul 29:10.732

Yeah, there are I have two I have two follow-up questions on that. Do you think you know with the mythos and the AI native offense and exploitation, do you see do you see an explosion of vulnerabilities and then a plateauing of the vulnerabilities because of the low-hanging fruits have been found? Right? You know, or and the second question I have is if the vulnerabilities plateau, is it the chaining of vulnerabilities that is

The explosion that we see because historically you'd always needed one vulnerability to break in, get in, but now you can take chain like multiple medium and low and you know high severity vulnerabilities to act actually which is the end goal of vulnerabilities to compromise systems. Whether you do it with one vulnerability or five doesn't really matter. So I'm curious where where your head is. Like, do you see a plateau?

like there is a big explosion over the next two years, all these low hanging fruits are found and then there is like a steady state where you don't find as many because all the easy ones have been found and fixed and pushed into the internet critical software.

Craig Adamns 30:13.106

Although I I strongly disagree with that one. So let' let me let me let me jump in and make our our conversation spicy. So

the rise of AI generated code, it is a complete misnomer to think that that is high quality, secure, protected code at the end of the day. Have a conversation with Claude or pick a chat bot and ask it about software vulnerabilities and AI generated code. it covers everything else. So I I'm in this view that there's no spike in the plateau of vulnerabilities, exposures inside of an environment. That that is a a multiplying exponential piece. Second thing you said is 100% true. There is a lot of organizations

spent a lot of time on the critical stuff and kind of frankly got to the other stuff when they got to the other stuff. And so I think as you're gonna find as a new both terminology and a new defender approach.

Mehul 30:52.246

Yes.

Craig Adamns 31:01.246

Really focused on toxic combinations. And so it's gonna mean a different path. And this goes of not just how do I count the number of things, because to begin, to be clear, there are already more things than a company found that they could patch. So I'm starting out with patching is a necessary thing for stability and security of an organization.

And it will not be the way that organizations protect themselves against compromise. Like I the it's just the ground I'll hold. And so we're gonna find the robustness of response options, and that can be everything from virtual passing, maxing, masking, excuse me, changing attack path formation permissions that then guide you to how when a toxic combination occurs, I can be protected across my organization.

without this false thesis that I'm now gonna patch 50% more next year than I did in the previous year because it's not gonna happen.

Mehul 31:59.179

Yeah. And then if that is the case, how do defenders defend in the age of AI? Like what it because my my sense is like the only thing that changes in this new era is the speed of response. Like that is like go ahead.

Craig Adamns 32:12.744

Yeah. So

No, sorry, I apologize. I get excited about this conversation. And so so I think this becomes a defend with AI. So if I actually look at the SAS apocalypse that occurred a while ago, if I actually looked at

Mehul 32:24.912

Yeah. Yeah. Like two months ago, two or three months ago, every SA SAS software is dead. Like you know, it just give up, like give the money back to the shareholders. What are you guys doing?

Craig Adamns 32:32.286

But that's that's a little that's a little harsh. I I think what we're finding is a a redefinition of what SAS software is. And and so I have a thesis that and pardon my poor grammar,

That every software provider is a place that you either do AI or you'll be replaced by AI. So so I actually like passionately believe that most organizations aren't gonna find the majority of their AI use actually done from an AI provider directly. I believe the majority of their AI use is gonna be from applications, take something outside of cybersecurity, Salesforce, CRM management. Salesforce is gonna be place that you do AI at the end of the day. I don't go in to get my raw data and my dot feed.

Mehul 32:52.18

Okay.

Craig Adamns 33:16.492

I go in to get the analytics and the things that I need to be successful. It's going to be that provided by the vendor itself. And so the punchline of where I was going is I think the question is when you're being attacked by AI, you're going to defend with AI. But now we start hitting the inequality that exists inside of cybersecurity. There's a whole bunch of organizations, I'm looking at you, Goldman Sachs, that can afford every tool, person, capability on the planet, and they have the budgets to match that. There's a whole bunch of organizations, the regional bank, the water company,

The town, the school district, that aren't gonna be able to create and run all of these agentic applications themselves. And so that's gonna become the new role for SaaS software at the end of the day. It's gotta be a place where it gives defenders the capability to defend with AI through the tool suite that they give.

Mehul 34:04.598

D do you do you think that more and more soft SaaS software becomes much more customized to customers environment because now you can do these because a lot of times what I've seen is most ISVs they build the software is one size fits all, everyone gets the same version and then you you go with it and you then you have to hire like an army of professional services and solution engineers to get to get the job done.

And this is where this is the gap that the SOAR players kind of fixed, where they came in. We are going to automate the workflow, we're going to take all your products, and we're going to create these boxes, and then you can do this. If this and this happens, then do this. And it was like a glorified professional service. It was a glorified professional services engagement. Do you think more and more SaaS players will essentially help customers by agency? Like go deliver this out.

Craig Adamns 34:47.37

It was brittle. It was brittle. Yeah.

Mehul 34:59.82

I don't care how you do it. Here's the software. Here's the here's the data. Now go work on this data and deliver this outcome that I need.

Craig Adamns 35:08.808

I I think yes, and and your spirit of customization can be seen in it's a it's a simple example, but bear with me. every SaaS software product has reports. Reports imply that there's a fixed set of questions. I'm gonna go to a place to get a fixed set of answers, hence that's what the report does. If you look at what modern reporting typically looks like, there's AI-driven interfaces to it. So first, reporting still exists because you want to be prescriptive in your journey, of whatever journey you're taking a customer on and how they operate.

But modern reporting in the AI world's gonna be here's what you need to know, here's what's dynamic inside your environment, ask me the things. And it's guiding in a way that

Mehul 35:45.302

Here's the context and here's the context of whatever I'm recommending, which is personalized to your environment, rather than a cookie cutter report, here are here are the high, medium and lows you have.

Craig Adamns 35:55.657

And that's why I think your world of customizations is dead on, which is it's customized to the environment and how it operates a team.

Mehul 36:03.103

Makes sense. you know, when this AI journey started, Craig, there was a lot of hesitation in adopting AI in the organization. There were like a lot of i I remember in my previous jobs, there were there were people monitoring is anyone using chat GPD, is our sensitive information leaking, you know, we mean we need to limit the access of AI, AI bad. And so there was like a a strategy to contain AI using

Craig Adamns 36:26.986

It's adorable.

Mehul 36:32.873

enterprise. and now I think the shift is leveraging AI in the enterprise to do more. I'm curious where your thinking is. Whether you know, are we containing AI or leveraging AI? Where which phase are we in?

Craig Adamns 36:47.61

so so first, I think for I I kinda percent agree with the pattern you saw. And I'll say this is similar with other technical evolutions. No, not dissimilar to cloud. When cloud first came out, it became a very constrained thing of like who has permission access, and then we we hit a punchline or we dramatically accelerated. Then of course we figured out, well, how do we govern in the right way? I think with AI it's different. I I think we're to the point that the biggest risk of an organization will be not leveraging AI in an environment where your competitors and the market all turn.

Are. And so I'm I'm square on the side that the security team specifically that's not embracing AI use throughout their enterprise quite honestly will hinder that ability of the enterprise to be successful and accomplish its mission at the end of the day. So I think we're at the square adoption zone. The challenge we have in the square adoption zone is if I assume AI is more than a chat box.

So i if I start that that that's not actually the outcome that people want is I have a question, give me an answer. They're actually looking for

Mehul 37:49.919

Yeah. We are past that now. Yeah, we are past that. It is way twenty it's all twenty it's twenty twenty three. It's like so twenty twenty three.

Craig Adamns 37:55.839

Then then you're then you're in the zone where the typical organization is challenged with the AI maturity journey of how to identify what jobs to be done.

How do I set up those tasks? How do I set up the monitoring infrastructure so that I have oversight of the AI, just like I have oversight of what my humans do at the AI? And they'll go on a journey. The journey is hard though for the typical small and medium organization. That's something where we'll see them go. But I think back to your direct question, we're in the harness zone, and the biggest risk to an organization will be not adopting AI. That will be the thing that limits the trend line of a company.

Mehul 38:37.983

Yeah, and I remember I remember vividly the cloud journey when the t it was two thousand twelve, two thousand thirteen and I remember very vividly there were healthcare organizations, my data is so sacred, it can never go to the cloud. And my or you know, if it's a financial or bank, my data is so sacred, it can never go to the cloud. And now I see all the new infrastructure is getting deployed, is now getting deployed to the cloud. And I think the transformation in AI is essentially going to be the same because if you if you don't adopt AI, you risk

being left behind. You you risk being left behind completely. Your competitors will just leapfrog the capabilities and you'll be stuck with a chatbot or something, some silly thing that is irrelevant from a customer's point of view.

Craig Adamns 39:08.692

Great.

Craig Adamns 39:21.972

What I love about the leapfrog is the analogy I'll use is mail versus email. So it's that dramatic. and so your choice of using AI or not using is like you know sending the letter versus sending the the email message or the slack. yeah, that's the analogy, and I believe it with every part of my body.

Mehul 39:42.508

Awesome. what happens? what happens next? Do you so one one narrative I've heard is the AI frontier models are going to take over the world. it's only going to be five model, five companies that relevant that are relevant. OpenAI, Anthropic, Google, you know, XAI, add a bunch of open source tools, maybe Meta, I don't know, maybe Meta is maybe not relevant. I don't know. But

that is one way to think about it is there is vendor consolidation. That is one way to think about this problem. And the other way to think about this is there is vendor explosion. There is there are all these new startups that come up, new companies that spin up that solve this one niche, one problem, and then you know, they they solve it so well that no one else can do, and then there is an explosion of all these things from there.

And I personally saw this in the cloud journey. There was there was a lot of well Google is going to take over and all these things, but then eventually you saw like an explosion, right? So what's w what's your take? Do you see vendor consolidation or vendor explosion?

Craig Adamns 40:53.548

both at different life cycle stages. So let me be precise. with every technical innovation, you see vendor explosion as a way that we secure and protect it. So in the near horizon, I think you see a rise in the number of organizations that someone works with to defend and operate across their environment as a defender. no dissimilar to cloud at the end of the day. When cloud first came out, I had to have new tools, new acronyms that are gonna help me actually protect my cloud environment. So I think you see an increase. Then

Mehul 40:56.767

Interesting.

Craig Adamns 41:22.386

I think you'll see the consolidation journey come back in. So while you have a spike in the beginning, I think if you go a horizon out, horizon measured in two years, not ten, we're back to a consolidation phase. But you asked an important question, which is do I see organizations consolidating

all of their security apparatus with a particular friend hell no like like like like the the the one of the greatest myths of platformization is the the one platform to rule them all i have never seen that any customer environment i have ever met with any of the providers that exist today the typical no so so what what could be different is the number of different ones i see across an environment

Mehul 42:00.706

Do you think this time is different?

Craig Adamns 42:09.886

But do I believe Goldman Sachs is gonna say, Don't worry, we have anthropic, we don't need any of the nine hundred or one hundred and other eight security tools across my environment? No. Like I like hard no. And that's not trivializing the criticality, the value, the disruption that AI is bringing. And and so what we may see is like certain sectors take take the ability to scan codes and look for vulnerabilities inside of it or

You know, those spaces, you're you're gonna see disruption in sectors and consolidation. But do I actually l see that across the environment? No, the second thing that I'll say is in addition to consolidation, inside of security, the typical organization actually doesn't want a technology product. They want a services outcome at the end. And so the line between product and technology has long blurred.

In a space where is what I'm looking for raw information, or is what I'm looking for an assistance in managing an outcome that I'm trying to drive at the end, I think you're gonna see the rise of the services organization. In fact, there's some well-written research that says the next trillion-dollar software company is a services company. but this notion of software as the capability expands is gonna continue to be disrupted and changed, and AI is gonna have a big impact. That's actually

Most people don't want to buy software. That's not that's not actually what they're trying to do and solve in the market. They're trying to solve an outcome and they're gonna wrap people to multiply the impact of the technology they have.

Mehul 43:41.599

Do you so it do you then think that the value gets concentrated or the value gets realized in the service industry, then the software or the SaaS side of the business? Is that what you're implying?

Craig Adamns 43:54.683

I I am, but but I need to be I need to be careful because I don't think it's as one of a it's not a binary one and a zero. 'Cause if I go back to where we were talking about AI earlier.

Mehul 43:55.925

Yeah.

Craig Adamns 44:05.248

vulnerability uncovering and discovery for a moment. just because I now uncover 5x the vulnerabilities, I have a fundamental remediation problem that at the end of the day that I'm still gonna probably have software or services help me manage at the end. And so I don't believe I believe set software itself is fundamentally gonna change. So there's gonna be like a step function forward of like what is the software providing the platform of the future? and

I also think the services wrapper is something that the typical organization is gonna be expecting at the end. Because if we go back to the the skill sets that we're now talking about, I'm a regional bank in Minnesota. do I want to defend my apparatus, a you know, five software partners.

Or in the end, of like, do I want an organization to help me defend through software and AI use combined? I I believe the latter. I really do. and I think we see evidence of this. It's often just time blurred and how it operates. There's a whole lot of software companies that spend a lot of money on customer success that starts to smell a lot like services if you look at it closely. I think you're gonna see that multiplied over a horizon.

Mehul 45:22.805

Do you think there will be a renaissance of like margin expansion in the service industry? The traditional model is the the SaaS providers had like eighty percent margins and then the service providers had like a twenty percent margin or a maybe like a ten percent margin. Like do you think then like the service providers will have or at least have a line of sight for software like margins in the age of AI where they can do more with less, and then deliver the same outcome, or is that like a fantastical pro prediction?

Craig Adamns 45:53.043

No, so so direct answers, yes, I do. So to be clear, I think you'll see service organizations with software like margins and

I also believe markets have a way of being efficient. And so as more and more organizations have software like service have software like margins, you will see a new rise of services organizations that are looking or are willing to do a different margin profile, which will change the margin profile. So we'll we'll see a cyclical curve of more efficiency. But what makes it exciting for defenders is one of the fundamental problems of cybersecurity is cost effectiveness. My ability to actually afford everything I need to do.

Believed to be defended, that I think we'll see a compression across of what the typical product cost or the capability costs at the end of the day. Email monitoring, pick an example today. I think across the horizon, that's gonna cost less, which is then gonna give more and more organizations a chance to implement these security controls. Because again, to say it twice, the typical CISO knows there's areas in their maturity journey they wanna do next.

Mehul 46:51.881

Yeah.

Mehul 46:55.839

Mm.

Craig Adamns 46:55.976

And so how do you make that cost effective at scale? I think that's what gets really exciting for defenders.

Mehul 47:00.831

Do do you think then the the role like if there is I guess more expected for the human analyst to do with these services, then d does their role change in a meaningful way meaningful way? Like the f role of the security analyst or the security engineer?

Craig Adamns 47:18.11

Hundred percent. I I I think it's a there is there will more be different than is the same. because today the role of an animalist starts with let me process information, reach a conclusion, determine which action to take. I think those tasks are gonna be dominant automated in a way.

However, I stand by the statement I made earlier. I don't think the security size of organizations is going to decrease in aggregate. I think you're actually going to find rather a rise in security maturity. The cost to compromise is too significant. The ROI of spending on security is too high, or the cost of not doing it is too painful.

Mehul 47:57.846

The reputation damage is too high. Once you lose the reputation everything is done. Like if you once you shoot on what speech turn out, you're done.

Craig Adamns 48:01.948

And so this is this is gonna be one of those magical areas of efficiency will bring enhanced outcomes. and I think it will do it in a way that's gonna enable security defenders to focus on higher value tasks as opposed to lower value tasks, as well as organizations to have less security incidents across the horizon.

Mehul 48:24.583

Awesome. Awesome. Craig, last last topic for today. Now let's do let's do some predictions. given all that we have talked about, do you think first first question, do you do you think there will be more CVEs in 26, 20 2026 and 2027 compared to all the years combined before?

Craig Adamns 48:32.383

ya.

Craig Adamns 48:50.34

all the years combined. I thought you were gonna ask me if there's more. And I was like, this is a softball question. Of course it's yes. no, not all excuse me. There will be more in each of those years. those two years will not be more than all of total history. My prediction it doubles in number.

Mehul 48:54.547

Yeah.

Mehul 49:06.303

the Wolsen number. All right. Are we going to be secure by default or more of the same?

Craig Adamns 49:12.286

More of the same. the why behind it is the weakest link in an organization is still the processes, the people that execute it, not the the tool at the end of the day. That's the laggard and innovation that I think we're still need enhancement on.

Mehul 49:27.059

d do you think new new attack vectors emerge or do we see more of the same?

Craig Adamns 49:34.427

So so this is a bold one, which is there are new attack vectors. If you ask me the question of which attack vector is most likely to compromise, more of the same. We're still in a point where people clicking on links, compromise credentials, these still have a shocking percent of incidents occur. So the more the majority of compromises that occur are gonna be more of the same. Sure, there's gonna be new novel attack vectors that come out.

But it's more of the same. It's gonna be the typical risk an organization's gonna face.

Mehul 50:06.291

Next production, by the end of 2027, do we see more enterprise security tools or less in an enterprise?

Craig Adamns 50:14.602

more excuse me end of twenty twenty seven you're now you're right now in my inflection curve you less I think you see a spike between now and then so I think it starts going up and then I actually start to see the point of decline. So if you would have said 2028, I think there were screw tools provided right at the end of 2027, I think it's when the decline starts.

Mehul 50:36.751

Last prediction, that this is a fun one. Because of AI, do we see more good guys becoming criminals or do we see more criminals becoming good guys because they have nothing to do? Or n nowhere to hide?

Craig Adamns 50:51.74

More good guys becoming criminals. So my my my is simple, which is cybersecurity. We've always had our colorful characters of of attackers that become defenders and have well learned places. That's a well learned trough. I think when you make something easier to do and it's binarily easier to operate and implement a cyber attack than difficult, you will see a dramatic rise.

Mehul 50:54.589

Because it's easier to attack and come pretty.

Craig Adamns 51:21.481

Yeah.

Mehul 51:22.69

Dramatic rise of what, good guys becoming criminals?

Craig Adamns 51:25.748

Good guys becoming criminal.

Mehul 51:27.269

That is good point. That's a good point to end this interview. This is this Craig, this has been an epic interview. Thank you for your time. You're way too generous. maybe yeah maybe you come back again next year and then we revisit these predictions and see how accurate or inaccurate you were in terms of

Craig Adamns 51:32.37

It's not a good point to end the interview. it's not a good

Craig Adamns 51:44.106

I appreciate the offer.

Craig Adamns 51:53.379

and we'll have to have wine for that conversation, but count me in. Thanks so much.

Mehul 51:57.118

Awesome. I'm gonna stop recording I'm gonna stop recording.