Security's new dilemma: Agents reason differently

•

Sep 25, 2026

•

10:04pm UTC

Copy link
Share on X
Share on LinkedIn
Share on Instagram
Share via Facebook

AI is accelerating familiar cybersecurity threats, but according to CrowdStrike's chief product officer AJ Shipley, speed and scale are only part of the story. AI agents can also assemble known tactics, techniques and procedures into unfamiliar attack chains, requiring existing security controls to adapt.

In a conversation with The Deep View at CrowdStrike's Fal.con event, Shipley discussed why organizations will need AI to defend against AI-enabled adversaries, how automation could change entry-level cybersecurity jobs, and why enterprises shouldn’t consider themselves outmatched. This interview has been edited for brevity and clarity.

Jason Hiner: How is AI changing cybersecurity?

AJ Shipley: I think, from my perspective, there's really two things that are interesting to think about from the perspective of the defender. One is something that we've been dealing with for the last several decades. It's just a matter of pace or how quickly things happen, and then the other one is net new, which is really interesting.

I think obviously AI-enabled adversaries are really just allowing those same bad actors to enumerate vulnerabilities and ultimately exploit vulnerabilities in order to further their means. Whether it's cyber warfare and advanced kinetic warfare, or whether it's stealing intellectual property, it's just allowing them to do that so much faster, and with so much more scale, as well as being able to find previously undiscovered vulnerabilities to then be able to exploit.

But for better or worse, the approaches to how you defend against that are the same approaches we've been using for the last 20 or 30 years. It's just a matter of pace on the defensive side. And so you have to use AI tooling in order to just be able to respond to the AI adversaries or the AI-enabled adversaries.

The other piece, though, which I think is really, really interesting, is the way these agents reason is fundamentally different than how people reason. And the last 10 or 20 or 30 years of security products have been built on this foundation of this intuitive understanding of how humans reason, either threat actors or adversaries or defenders, and how they're going to reason to try to respond to them.

What's different is that agents reason differently.... How these agents are putting together TTPs [tactics, techniques, and procedures] into attack chains that are fundamentally different than anything that we've ever seen before, and then how we have to be able to build defenses to those fundamentally different approaches to reasoning their way towards a problem, I think is something that we're very much focused on.

Jason Hiner: What makes AI agents so difficult for human defenders to handle?

AJ Shipley: These agents, I don't think, are inherently malicious or benign. I mean, I think you can probably build a malicious agent, but I think they are so task-oriented that they're going to try to find a way to accomplish their task, however they can.

Every TTP, every vector. I don't think that they're coming up with necessarily novel new techniques. Maybe they will in the future, but they're stringing TTPs together in a way, and then doing them at a pace and a scale that is impossible to respond to unless we are enabling the defenders with the same AI tooling.

I know that there's a zeitgeist out there around, "Hey, is AI and are agents going to replace security professionals?" I tend to be in the camp where I don't think that they will. And the reason for that is because there's two ways to increase productivity. You can do the same amount of work with fewer resources, or you can do more work with the same number of resources. Both of those are productivity gains.

I think in an AI-centric cyber world with an AI-enabled adversary, just the sheer scale means that we have to figure out a way to increase productivity. And one of the ways you can increase productivity is to do more work with the same number of resources. So those same number of resources are people. Which means, how are you going to enable those same number of people to do more work? With the AI tool.

That's what we're very much focused on: How do we use the agents or the tooling in order to make the defenders as productive as possible, not to replace the defenders? Because, again, I just think the data volumes are exploding, the way to chain together tactics and techniques in new, novel ways is exploding, and so you still need all of that expertise that people have. But we have to find a way to increase their productivity 10x or 100x.

Jason Hiner: How will AI change the work of cybersecurity analysts?

AJ Shipley: I definitely think that there are workflows, for lack of a better term, that AI will be able to fully automate away.

In the SOC [security operations center], we might say, "Hey, tier-one triage of just a whole bunch of alerts coming in." That's probably something that an agent's really good at. And then maybe some level of tier-one or tier-two investigation to figure out what's a true positive versus a false positive. That's probably something that an agent's really good at: doing that first gathering of evidence and synthesizing the evidence and coming up with a hypothesis, and then maybe testing some alternate hypotheses.

And I think that's where you still want a person in the role, stepping into that. And then the tier three, the incident response-type stuff: How am I going to take action now that I've confirmed that this is an incident?

I think this idea of what is an entry-level job probably moves up the stack from a tier one, tier two, tier three. Historically, entry-level was: You're going to be a tier-one analyst. You're going to start triaging a bunch of alerts. After a couple of years, we're going to let you start doing some investigation. And then when you get really good at it, we're going to let you do some incident response.

I think now we're going to start training humans and enabling them with tooling so that they don't have to do the tier-one menial-type work that they couldn't even keep up with anyways. Before, there was just this explosion of alerts, but now the whole idea of entry-level is just going to move up the stack, like a tier two or tier three.

That doesn't mean that this idea of entry-level jobs goes away. It means that what is the definition of entry level? It now becomes a higher-value skill set.

Jason Hiner: Will AI help organizations eliminate longstanding security weaknesses?

AJ Shipley: If you think about the cyber environment as a battle space, or a battlefield, there have always been advances in technology. Bronze Age, Iron Age, bow and arrow, gunpowder, naval warfare, atomic bombs. There have always been these advances in technology around quote-unquote warfare, where it felt like maybe at the time that the person who came up with the technology, or the side that came up with the technology, was like, "They're going to win". And then somebody else comes up with a way to defend against it. And then somebody else comes up with a clever way again to exploit it.

I tend to think that the AI tooling will expose where there's a lot of weaknesses where we didn't understand before. It will help us close a lot of those weaknesses. And if history is any guide, there will be something else that comes down the pipe in the future that exposes a whole bunch of new weaknesses that we're probably not even aware of.

I think that we will be a lot more informed on where there are vulnerabilities and where there are weaknesses, and then we will use the tooling to address those vulnerabilities and weaknesses. And in my experience, if history is any guide, there will be something else right around the corner in the future that we're then going to have to figure out: How do we respond and react to that as well?

I don't know what that thing is, but I tend to be an optimist. And just in general, I tend to think that when we figure that out, or when we encounter that thing, we'll figure out a way to defend against that as well.

Jason Hiner: What does the best-case outcome look like three to five years from now?

AJ Shipley: Five years is an eternity. If all goes well, I think we have built a fully redundant and resilient system, leveraging the tooling across all facets of the attack surface—endpoint, cloud, SaaS, network—to protect all of the assets that an organization cares about: their identities, human and non-human; the devices that those identities use to do their job; the applications that they use to do their job; the data that gets created.

Again, if all goes well, we've used really sophisticated and well-trained red models to identify vulnerabilities across all facets of that attack surface, and then we've used blue models to be able to remediate those vulnerabilities to the point where they're no longer exploitable. And then we can truly be able to take a vacation. That's the bull case, I think.

Jason Hiner: How can defenders account for the non-deterministic nature of AI models?

AJ Shipley: I think this idea of an ensemble of models, and having different models be able to vote on each other and weigh in, I think is ultimately what will address the non-deterministic nature, as well as harnesses.

I think there are mechanisms to be able to control the inputs such that you get a deterministic set of outputs. It's when little things change. For example, your input data set might be in a different schema. It might have a different timestamp. It might be asking the question slightly differently.

So I think a combination of harnesses, a combination of ensemble models, a combination of basically being able to get to weighted outcomes. And this is not all that much different, even from when I remember we were doing cloud-based sandboxing, malware analysis. You'd have a lot of different detection engines up there, and one detection engine might say that's malicious. One might say, "Not really sure." One might say benign.

And so how do the different detection engines, or the models at the time, the ML models, static or dynamic analysis, contribute to be able to make a determination of, "Hey, we think 80 or 90 percent of the way there that this is truly malicious."

Jason Hiner: What would you say to enterprises that fear they’re outmatched?

AJ Shipley: I would say they're not. They're not, at least in my opinion, they're not outmatched. Anytime there's been an inflection point in technology, technology has traditionally come along to significantly improve the productivity of civilization, and we've all benefited from it. AI is no different there. That technology obviously can be used for good, or it can be used for evil.

I would say embrace the technology, because it can be a productivity enhancer, and then make sure that you're partnering with somebody who's thinking about how to make sure that technology has the appropriate guardrails, that you have the appropriate visibility, that you can be able to detect when that technology is being used maliciously or inadvertently, and then you have all of the mechanisms and tools that you need to be able to respond to make sure that it doesn't happen again.

Some of what's old is new again. This is just an inflection point from a technology perspective. It's obviously driving a different pace that we have to be able to keep abreast of. But this technology doesn't use itself. It's not like there's an agent that just popped up out of the blue without somebody spinning up an agent and decided to go start acting rogue. There's people who are using this technology.

So partner with somebody who understands the adversary, who's always been focused on the adversary, is focused on understanding their tactics, their techniques and their procedures to partner with, so that you can then be an enabler of that technology in your organization in order to increase productivity.