The a16z Podcast
The a16z Podcast

Building Defense for the Agentic Era: Kevin Mandia

a16z General Partner David George sits down with Armadin founder and CEO Kevin Mandia to discuss what happens to cybersecurity when attackers can operate at machine speed. After 30 years in security and building Mandiant, Kevin says AI convinced him to get back on the field. He explains how AI chang

Featured Speakers

a16z HostKevin Mandia Guest

Topics Discussed

Episode Summary

Executive Summary: Kevin Mandia argues AI is transforming cybersecurity from human-speed to machine-speed, giving attackers scale, speed, and broader reach while making attribution harder. He explains why he returned to the field to build Armadin, a company using AI on offense to find exploitable risk continuously and AI on defense to auto-remediate it. The conversation frames autonomous security as inevitable across the stack.

Main Topics: AI as a shift change in cybersecurity (Priority: 5/5): Mandia describes AI as a fundamental reset: offense and defense both change, and traditional human-led security workflows become too slow. Armadin's product model: AI offense and AI defense (Priority: 5/5): Armadin uses frontier models to attack customer networks in a controlled way ('Armadin Red') and then applies 'Armadin Blue' to create compensating controls and automated response. How AI attacks differ from human and nation-state attacks (Priority: 5/5): AI enables drone-swarm-like scale, rapid parallel probing, and more capable lower-skill attackers, while making attacks louder and attribution harder. Continuous testing through 'hyperattacks' (Priority: 4/5): The company maps a customer's environment with agent swarms, builds a metadata twin, and continuously polls for changes to re-test exposure as networks evolve. Red teaming, pen testing, and the future of security categories (Priority: 4/5): Mandia says pen testing is mostly hygiene and known-vulnerability scanning, while AI-driven red teaming verifies exploitability and will replace much of traditional pen testing. Operational lessons from 90+ zero days (Priority: 5/5): Armadin claims it has found over 90 zero days at Fortune 500 customer sites since January, mostly with human experts supported by automation, though the tech is increasingly finding them directly. Building and scaling a cyber company in the AI era (Priority: 4/5): Mandia contrasts Mandiant’s self-funded early growth with Armadin’s need for fast funding, stronger go-to-market, brand-building, and weekly process updates to keep pace with change.

Key Arguments: AI attackers gain an immediate advantage because one model can probe thousands of paths simultaneously and execute actions that would take many humans to match. Open-weight and closed models are already good enough for cyber offense; the main limiter is not capability but anonymity, cost, and access to compute. Nation-state tradecraft may shift from sniper-like targeted intrusions to noisier but more comprehensive AI-driven swarms. Defensive security must become autonomous too, because human-in-the-loop detection and response will be too slow in AI-speed incidents. Traditional pen testing is insufficient because it often finds known issues without proving exploitability; AI red teaming can validate real risk and reduce false positives. Continuous, change-based testing matters because networks, apps, and threat models evolve constantly; security should re-test whenever the environment changes. Security vendors and CISOs are already reorganizing around AI; over the next two years, major parts of the SOC, prevention, detection, and response stack will be rewritten. Winning as a startup now depends on speed, differentiation, customer happiness, and operational discipline, not just technical brilliance.

Data Points: Years in cybersecurity: 30 years - Mandia cites three decades in security as the basis for his views on the AI shift. Zero days found since January: 90+ - Armadin says it has found over 90 zero days at customer sites since January of this year. Customer type: Fortune 500 companies - He emphasizes that the zero days were found at major enterprise customers, not small companies. Kill chains tested: 24 - Armadin built 24 kill chains from real-world human attacks to evaluate model performance. Model progress through kill chains: No model exceeded 8 out of 24 - Both open and closed models reached diminishing returns at the same point in testing. Human effort equivalence: 70 humans - Mandia says a microsecond-scale AI action would take 70 humans and still be impossible to match. Timeframe for response: 48 hours - He says CISOs are typically contacted within 48 hours when Armadin finds a serious issue. Enterprise change speed: Every two weeks - Mandia says the product and market are changing so quickly that sales and operations must be updated continuously. Startup growth benchmark: $100M+ ARR in 18 months - He references Wiz as an example of the new speed expected in enterprise security. CrowdStrike-related keynote stat: 43% - A text message claimed 43% of RSA main-stage keynotes were Mandiant alumni.

Pivotal Quotes: "Everything I did is dead, and then everything else is new." — Kevin Mandia: His summary of how AI changes cybersecurity and why he returned to build in the space. "This is a tsunami like has never been seen before in security." — Kevin Mandia: He describes the scale and urgency of the AI-driven transformation in cyber. "You don't have a defense unless you have a great offense to go up against." — Kevin Mandia: His explanation for why Armadin uses offensive AI to train and harden defenses.

Implications: Cybersecurity is moving toward autonomous offense and defense. Teams that keep humans in the loop for too long will be too slow; vendors and CISOs must redesign products, SOCs, and response workflows around AI-speed attacks.

🔓 Sign Up for Unlimited Episode Search

About The a16z Podcast

The a16z Podcast discusses tech and culture trends, news, and the future – especially as ‘software eats the world’. It features industry experts, business leaders, and other interesting thinkers and voices from around the world. This podcast is produced by Andreessen Horowitz (aka “a16z”), a Silicon Valley-based venture capital firm. Multiple episodes are released every week; visit a16z.com for more details and to sign up for our newsletters and other content as well!

View all episodes from The a16z Podcast