Building Defense for the Agentic Era: Kevin Mandia
Building Defense for the Agentic Era: Kevin Mandia
Podcast49 min 9 sec
Listen to Episode
Note: AI-generated summary based on third-party content. Not financial advice. Read more.
Quick Insights
  • Prioritize CrowdStrike (CRWD) and Palo Alto Networks (PANW) for monitoring: their potential integration with AI-driven testing and rapid defensive responses aligns with the cybersecurity shift expected over the next two years.
  • Treat this as a sector theme, not a buy recommendation: the discussion provides no valuation analysis, price targets, or company-specific forecasts for either stock.
  • Watch for demonstrated customer adoption, independently validated vulnerability discovery, and fast remediation; Armadin is private, and its performance claims are not independently verified.
Detailed Analysis

AI-Driven Cybersecurity (Investment Theme)

  • Mandia describes AI as giving attackers a major advantage in speed and scale: AI agents can test many paths at once, and less-skilled attackers may become more effective.
  • The proposed response is autonomous defense: continuously testing networks, prioritizing exploitable vulnerabilities, and rapidly applying protective controls.
  • Armadin says it has found more than 90 zero-day vulnerabilities at customer sites. The transcript presents this as evidence of demand for continuous, real-world testing, though it is a company claim rather than independently verified performance.
  • Mandia expects cybersecurity tools and workflows to change substantially over the next two years. He argues that traditional penetration testing may give way to more continuous, AI-enabled red teaming.
  • Actionable takeaway: Look for cybersecurity companies that can demonstrate real-world vulnerability discovery, fast remediation, strong integrations with existing defenses, and customer adoption—not just AI features or large vulnerability counts.
  • Risks mentioned: Attackers may gain an advantage in the near term; autonomous response must act quickly but can be imperfect; attribution may become harder; and large, frequently changing networks can make continuous testing costly.

Armadin (Private Company)

  • Armadin uses AI agents to test customer networks for exploitable weaknesses, then plans to use its “blue” product to help apply defensive controls.
  • The company describes a process of mapping network assets and checking for changes, then directing testing toward new or altered systems rather than repeatedly attacking the entire network.
  • Mandia says Armadin is working with CrowdStrike and Palo Alto Networks on connecting findings to defensive platforms.
  • He also says the company is raising capital and building sales and go-to-market capacity. He views rapid growth, customer satisfaction, and brand-building as important in a crowded market.
  • Actionable takeaway: Armadin is a private-company opportunity rather than a publicly traded stock. Its progress could be relevant to the broader cybersecurity investment theme, but the transcript gives no valuation, financial results, or independent validation of its claims.
  • Risks mentioned: The company needs to scale quickly, competition is intense, and Mandia says product advantages can be copied or eroded rapidly.

CrowdStrike (CRWD)

  • CrowdStrike is mentioned as a defensive platform Armadin is working with to support faster, more autonomous responses to identified vulnerabilities.
  • Mandia’s broader argument is that endpoint and other security tools may need to take protective action at machine speed, rather than waiting for a human to review and respond.
  • Actionable takeaway: The discussion points to the potential value of security platforms that can integrate external threat findings into rapid protective actions. It does not provide a specific assessment of CrowdStrike’s financial outlook or a stock recommendation.

Palo Alto Networks (PANW)

  • Palo Alto Networks is also mentioned as a potential integration partner for Armadin’s autonomous-defense capabilities.
  • The discussion frames security vendors as potentially evolving from detection and prevention tools toward systems that can automatically apply temporary controls when a threat is found.
  • Actionable takeaway: For investors tracking the sector, integration with AI-driven testing and response could be an important area to monitor. The transcript does not provide a specific price target or recommendation for Palo Alto Networks.

Fortinet (FTNT)

  • Fortinet is named among the defensive platforms that could use information from Armadin to help protect networks.
  • The discussion suggests that established security vendors may need to adapt their products to support autonomous, rapid responses.
  • Actionable takeaway: Monitor whether established vendors can incorporate AI-driven security workflows into their existing products. No specific view on Fortinet’s valuation or stock performance is given.

Tenable (TENB)

  • Tenable is cited as an example of traditional security tools focused on identifying known vulnerabilities and exposed services.
  • Mandia contrasts that approach with AI-enabled testing that, he says, can assess whether a vulnerability is actually exploitable and can find logic flaws in custom applications.
  • Actionable takeaway: The transcript raises a potential competitive challenge for traditional vulnerability-scanning products as customers seek more continuous, exploit-focused testing. It does not establish that Tenable’s products cannot adapt.

Rapid7 (RPD)

  • Rapid7 is mentioned alongside Tenable and Qualys as an example of conventional vulnerability scanning and security hygiene.
  • Mandia argues that AI-based testing could go beyond lists of known vulnerabilities by testing exploitability and application logic.
  • Actionable takeaway: Investors may want to watch how traditional scanning vendors respond to AI-driven red teaming and whether they can offer more continuous, validated testing. No company-specific forecast is provided.

Qualys (QLYS)

  • Qualys is also cited as an example of traditional vulnerability-management and scanning tools.
  • The discussion suggests that AI-enabled testing could challenge tools that mainly identify known issues, by checking whether weaknesses can be exploited in practice.
  • Actionable takeaway: The relevant investment question is whether established vulnerability-management vendors can evolve beyond scanning toward continuous validation and remediation. The transcript does not make a direct recommendation.

Google / Alphabet (GOOGL)

  • Mandia previously built Mandiant, which ultimately became part of Google. The conversation references that history but does not discuss Google’s financial performance or provide a new investment thesis for Alphabet.
  • Actionable takeaway: The discussion offers context on Mandiant’s cybersecurity expertise within Google, but it does not support a specific conclusion about Alphabet stock.

Wiz (Private Company)

  • Wiz is cited as an example of a cybersecurity startup that reportedly reached more than $100 million in annual recurring revenue within 18 months of its first release.
  • Mandia uses the example to illustrate the potential for rapid growth when a security product addresses an urgent customer need.
  • Actionable takeaway: The example supports watching for cybersecurity companies with strong customer adoption and clear evidence of urgency. Wiz is discussed as a growth benchmark, not as a publicly traded investment or a specific recommendation.

OpenAI and Anthropic (Private Companies)

  • The companies are discussed in the context of AI models used in cybersecurity and the need for better logging, audit trails, and safeguards when AI agents take actions.
  • Mandia argues that securing AI systems requires both model expertise and cybersecurity domain knowledge.
  • Actionable takeaway: The discussion highlights security and accountability as important considerations for AI providers, but it does not present an investment thesis or specific recommendation for either company.
Ask about this postAnswers are grounded in this post's content.
Episode Description
a16z General Partner David George sits down with Armadin founder and CEO Kevin Mandia to discuss what happens to cybersecurity when attackers can operate at machine speed. After 30 years in security and building Mandiant, Kevin says AI convinced him to get back on the field. He explains how AI changes the economics of cyberattacks, allowing attackers to probe thousands of paths simultaneously, and why that means defense will ultimately need to become autonomous too.  They also unpack Armadin’s approach: continuously attacking customers’ systems with AI to find exploitable vulnerabilities before adversaries do, then building toward autonomous defenses that can respond in real time. Kevin shares what Armadin has learned from finding more than 90 zero-days in production environments this year, why humans can’t remain in the detect-and-respond loop, and how the entire security stack could change over the next few years. Resources: Learn more about Kevin Mandia and Armadin: https://www.armadin.com/team-members/kevin-mandia Follow David George on X: https://x.com/DavidGeorge83 Learn more about Armadin: https://www.armadin.com/ Stay Updated: Find a16z on YouTube: YouTube Find a16z on X Find a16z on LinkedIn Listen to the a16z Show on Spotify Listen to the a16z Show on Apple Podcasts Follow our host: https://twitter.com/eriktorenberg Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
About The a16z Show
The a16z Show

The a16z Show

By Andreessen Horowitz

The a16z Podcast discusses tech and culture trends, news, and the future – especially as ‘software eats the world’. It features industry experts, business leaders, and other interesting thinkers and voices from around the world. This podcast is produced by Andreessen Horowitz (aka “a16z”), a Silicon Valley-based venture capital firm. Multiple episodes are released every week; visit a16z.com for more details and to sign up for our newsletters and other content as well!