In short
How AI is accelerating cyberattacks (finding vulnerabilities and weaponizing them faster), and why defenders must shift from human-paced, UI-driven security to “headless,” API-first, agent-driven cloud security.
Guest backgrounds
Loris DeGioanni is CTO and founder of Sysdig (second company). His first company, Case Technologies, created the open-source network analyzer Wireshark; acquired in 2010. He focuses on securing modern cloud infrastructures and Sysdig’s AI initiatives.
Key claims
AI-enabled attackers compress the timeline from vulnerability disclosure to exploit/attack from weeks to hours, increasing volume, speed, and “democratizing” sophisticated attacks. Cloud security is harder than on-prem because there are “many entry/exit points” (city vs medieval castle). Current defenses are too human-speed; defenders need AI-speed workflows.
Notable examples
Publicly exposed S3 buckets (e.g., reading sensitive documents). Falco as a “security camera” collecting runtime signals and cloud trail/logs to detect suspicious activity. “Headless cloud security” for agent consumption; dashboards/reporting replaced by agent-generated outputs.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUnderstanding Sysdig and Cloud Security
0:45 to 4:00
An overview of Sysdig and its role in cloud and container security.
“So I'm going to ask you, from what I understand, Sysdig is a cloud and container security platform that gives users visibility into what's running in their Kubernetes container and cloud environments.”
Loris DeGioanni's Background
4:00 to 6:15
Loris shares his journey in the cybersecurity field and Sysdig's mission.
“So can you, I mean, I'm sorry, I didn't ask you to introduce yourself before that.”
The Evolving Threat Landscape
6:15 to 7:11
Insights into how AI is changing the dynamics of cybersecurity threats.
“You know, AI has done a lot of wonderful things, but it's done a lot of scary things.”
Speed and Scale of Cyber Attacks
7:11 to 10:13
Discussion on the rapid acceleration of cyber attacks due to AI.
“Yeah, and we are in a new era for humanity, in my opinion.”
Main Attack Vectors in Cybersecurity
10:13 to 14:12
An exploration of the main methods attackers use, including phishing and misconfigurations.
“and in general what we're seeing is that these attacks are also impersonating humans better and better, right?”
Human Vulnerabilities in Cybersecurity
14:12 to 17:37
Discusses how social engineering exploits human weaknesses in cybersecurity.
“So a lot of these attacks are like being able to impersonate maybe contractors, you know, in your organization.”
On-Premise vs Cloud Security
17:38 to 19:34
Compares security approaches for on-premise data centers and cloud infrastructures.
“You, your team, your developers are sort of accessing this environment from all over the world.”
The Evolution of Cybersecurity Strategies
19:35 to 22:39
Explores the shift from human-centered to machine-driven cybersecurity.
“I mean, cybersecurity has developed very quickly when you look in terms of technological history.”
Introduction to Falco and Its Role
22:40 to 26:11
Describes the functionality of Falco in monitoring and securing cloud environments.
“but everything, you know, in general in cybersecurity.”
Transition to Headless Cloud Security
26:12 to 28:00
Discusses the paradigm shift towards agent-based cloud security solutions.
“And how do you know, I mean, that requires a tremendous amount of trust in the agents.”
Show all 18 chapters
Importance of Data and API in Cybersecurity
28:00 to 29:50
Learn how data quality and API integration enhance cybersecurity outcomes.
“The model that can be trained on the best data is the model that produces the best results.”
Human Reliability and Team Dynamics
29:50 to 31:50
Understand the role of teamwork and processes in minimizing human errors.
“It's a work, you know, players like Sysdig, what they bring is they bring deep expertise in areas of security, right?”
Hyper-Personalization in Cybersecurity
31:50 to 36:10
Explore how hyper-personalized AI can revolutionize data reporting in enterprises.
“So the question is, how do you create something similar, but for the world of agents?”
The Evolution of User Interfaces
36:10 to 39:50
Discover how user interfaces are evolving towards coding agents and conversational interactions.
“So all of these together makes us believe at CISD that, as I was saying, the UI is a thing of the past and that the future is exposing the data, the right data in the right way so that you can enable this workflow.”
Role of AI in Cybersecurity Workflows
39:50 to 42:00
Learn how AI can automate and streamline cybersecurity tasks traditionally done by humans.
“rather than providing any kind of user interface.”
Addressing Cybersecurity Vulnerabilities with AI
42:00 to 44:35
Learn how AI can automate the process of identifying and fixing software vulnerabilities.
“And by the way, it's running in production for me.”
The Future Role of Humans in Software Development
44:35 to 47:53
Explore the evolving role of humans as orchestrators in software development due to AI advancements.
“and by therefore accelerating the detection and the resolution of these problems.”
The Imperative for AI in Cyber Defense
47:53 to 51:08
Understand why companies must adopt AI to combat increasingly sophisticated cyber threats.
“is that the same would just translate everywhere, you know?”
Transcript
Automatic transcript. May contain errors.0:00AI has done a lot of wonderful things, but it's done a lot of scary things. Attacks can be scaled much faster through the use of AI. It makes it easier for cyber criminals to attack systems. So every time there's something new that is being discussed, first of all, these tools can find new vulnerabilities in software. But then once something is found, the speed at which this can be leveraged to perpetrate attacks is, you know, used to be weeks. Now it's hours. Okay, so I usually start by having you introduce yourself, give your background so far as it's relevant, and how you got to Sysdig. But I wanted, because Sysdig is sort of deep tech, and a lot of the listeners are not necessarily familiar with that.
0:54So I'm going to ask you, from what I understand, Sysdig is a cloud and container security platform that gives users visibility into what's running in their Kubernetes container and cloud environments. Can you just explain in very brief terms to listeners who don't know what a container is, what Kubernetes is, and how that relates to security? And then we'll start asking questions. Yeah, in a nutshell, Sysdig is an AI-powered real-time cloud defense platform. What does it mean? Let's start from cloud. Cloud is where all of the software that you, I, our listeners are using on a daily basis, right?
1:57You do a checkout at the supermarket, you do your banking, you do your Uber. It doesn't matter. Anything that you do, you know, nowadays is powered in the cloud and is powered by software that is running in the cloud. AI is running in the cloud. So we are talking about AI here, you know, and all of the AI infrastructure is definitely working on cloud-based and cloud-native infrastructures. So cloud is where software runs nowadays, and 6D protects and defends the software that is running in the cloud. Software running in the cloud normally is based on stacks, on ways to, you know, organize and run the software.
2:47which are based on some of the terminology that you mentioned before, containers, Kubernetes. These are the same way you run your software on your Mac or macOS. Typically, software in the cloud runs on distributed software infrastructure that is based on so-called containers, which are little... It's a way to partition your software in little independent pieces that can be deployed easily and they can run everywhere and can scale up and down. And Kubernetes is essentially the operating system for the cloud, right? So it's what takes the software and runs it and makes sure that the software, you know, like the software that you're running is able to grow when there's more demand and shrink when there's less demand and use the appropriate resources and so on and so forth.
3:40Sysdig is a company that specializes and leads essentially, you know, the ability to protect all this kind of stuff. So CISD also protects most, you know, most of the environments where AI runs. Okay, thanks. That's very concise. So can you, I mean, I'm sorry, I didn't ask you to introduce yourself before that. Introduce yourself and give a little bit of your background. I know that you've navigated a few major cybersecurity transitions in your career. So can you talk about that? Sure. And thanks for having me. My name is Loris DeGioanni. I'm a CTO and founder at Sysdig. Sysdig is my second company.
4:34My first company was called Case Technologies, was the company behind a very well-known open-source network analyzer called Warshark. This is a tool that pretty much everybody that has to do with the computer network in the world uses, you know, to observe, troubleshoot, optimize computer networks. Still going strong now. The company was acquired in 2010. And then after a few years of taking a break, I started this big essentially with the goal of securing modern cloud infrastructures and bringing all of my expertise in visibility and security and open source to the world of cloud. And cloud is, you know, where all the software in the world runs.
5:25whatever you do in the cloud whatever you do in your life, sorry checking in your bank account paying at the supermarket chatting with friends getting a cab it's all, you know, run by software that runs in the cloud so Sysdig you know, originally set out to solve the problem of securing these infrastructures that are running in the cloud, which is also incidentally where most of the AI, not most, all of the AI runs nowadays. Today at CSDig, I'm a CTO. I run product and engineering, and also I focus on all of the initiatives that we have at CSDig related to AI, including some of the stuff that we're going to talk about today.
6:16Yeah. You know, AI has done a lot of wonderful things, but it's done a lot of scary things. And one of the scary things is it makes it easier for cyber criminals to attack systems, to increase their speed and scale. So there's this, as there always has been in cybersecurity, this sort of arms race between the attackers and the defenders. The defenders generally catch up to a new attack vector fairly quickly and fortunately are staying ahead, it seems. But we're in a new era of cybersecurity with the implementation of AI. Can you talk about the current threat landscape for me, break it down somewhat?
7:20Yeah, and we are in a new era for humanity, in my opinion. And therefore, cybersecurity is no exception yet. And first of all, my first comment is this is evolving so quickly that the moment you make a comment on this, it's already outdated. And this is particularly interesting because it feels like, you know, with stuff like Mythos and Project Glasswing, for example, from Anthropic, it really feels like we've reached the point where AI is becoming very, very relevant for cybersecurity. In general, in terms of a thread landscape, I feel that the thread landscape remains similar to what we've seen historically in cybersecurity, but with incredible acceleration, right?
8:28An incredible increase in volume and speed in terms of what we're seeing in terms of attacks. Attacks can be scaled much faster through the use of AI. You know, the same coding tools that make developers so productive and are sort of revolutioning the software development arena are leverageable very effectively by attackers. So, you know, stuff like, I don't know, producing, going from vulnerabilities to exploits of this vulnerability, which required, you know, advanced programming and development skills now can be largely done through the help of NAI, which means that, for example, our trade research team a couple of weeks ago released an article where they were showing that between the disclosure of a vulnerability, so essentially a fault in a piece of software that can be exploited for security attack purposes, and being able to see the attacks, the exploits based on the vulnerability now it's a matter of hours, you know, just a few hours.
9:50So every time there's something new that has been disclosed, first of all these tools can find new vulnerabilities in software but then once something is found the speed at which this can be leveraged to perpetrate attacks is, you know, used to be weeks, now it's hours. In general things that used to be complex to attack and leverage and used to be the domains of sophisticated attackers that could invest, like state actors or stuff like that that could invest heavily in maintaining this list of vulnerabilities and creating the attacks and using them at the right time and so on. we can say it's been democratized, you know, so many, many more people and many more entities are in a position to do stuff at levels of speed and sophistication that was first earlier in the domain of people that had much bigger budget.
11:02and in general what we're seeing is that these attacks are also impersonating humans better and better, right? So when we're talking about stuff like fishing like, you know
11:22fake videos and all this kind of stuff it's becoming easier and easier essentially to be fooled even people that are very well prepared to this It's easier and easier to be fooled because these technologies are becoming more and more credible. Yeah. You know, again, for listeners who aren't that familiar, can you break down what are the main attack vectors? I mean, certainly phishing is one. And it's amazing that it's so effective because it's relatively crude. But I know that there are... It's still one of the main entry points. I would say, you know, typically there's the entry points to do attacks on software.
12:15Typically there's mistakes and misconfigurations. Right. Bugs and people taking advantage of people like phishing and so on, right? So mistakes and misconfiguration, at least in the cloud, which is a domain where Sysdig operates and where I have the most expertise, still tend to be, you know, like the prevalent ones. It's like you just human mistakes, you know, you forget your data on a storage that is open to the Internet and not protected by a password. You know, this is how and then somebody can easily discover it or your firewall is not configured to block certain specific traffic, maybe to certain specific targets.
13:09And you didn't realize that, you know, and so very, very often this is basic, you know, like we call it posture. So the attack surface is essentially a function of you being able to figure out this kind of stuff and realize where these issues are. And then, you know, the other one is bugs. So you can have the best possible posture and you cover your bases, but then people are able to come and find, you know, a disclosed or undisclosed bug in your software that can be leveraged to, you know, create a buffer overflow or remote execution or stuff like that. So this is stuff that sometimes you're actually most of the times you're not even aware of, you know, and this is the kind of sophisticated ones that I was mentioning before.
14:11And the third one is, yeah, people. So a lot of these attacks are like being able to impersonate maybe contractors, you know, in your organization. And through that, you know, escalate the privileges or phishing. So having to do with email, with instant messaging, by, you know, essentially, you know, social engineering. and being able to take advantage of the natural weaknesses that we have as human beings and the natural, you know, maybe lack of attention that we have with human beings, even if we are, you know, very trained and sophisticated in this. Yeah, and on the misconfigurations, a few years ago, I had a guy showing me that there is a website, I think, or he had a tool that could scan the internet for public S3 buckets or exposed S3 buckets, you know, these data stores.
15:20And, you know, he could go in and, you know, read the documents. There was during COVID, he could look at people's lung x-rays and it was really remarkable. Is there a difference between securing servers that are on-premise and servers that are in the cloud? Yeah, for sure. And yeah, the S3 example that you made is a classic one in cloud, you know? And yeah, that's why I was saying, still based on what we're seeing, probably, you know, this kind of attacks, this kind of issues are still the most common ones.
16:17And when comparing traditional data centers with the cloud, I often use a metaphor, which is the medieval castle versus the modern city. Right? Typically, on-prem data centers used to contain, you know, all of your hardware and software. You were managing it. You were controlling it. The solution, essentially, to secure them was put firewalls at the edge. make sure that you control everything that enters and exits this data center and make sure that you're as tight as possible at you know blocking or killing what what enters and comparing this to a medieval castle because it's like you know big walls the important stuff inside these big walls a little bridge uh and everybody has to go through that little bridge that's the firewall you know And you do careful thorough checking at the bridge and you make sure that only the people that you select enter and exit, you know?
17:24And that's the way you protect it. Modern cloud infrastructure are designed, are running on hardware that is provided by the cloud provider, right? Amazon, Microsoft, Google, you mentioned it, right? There's many of them. You, your team, your developers are sort of accessing this environment from all over the world. Your users are accessing the software that you're building and you're providing them from all over the world. There's a million entry and exit points. There's a million different people and personas that are entering and exiting, you know, with different scopes, with different goals, with different tasks that they have to perform.
18:16It's like a city, you know, there are many highways going in and out. And there's it's not only useless, but it's counterproductive to try to block these people from from going in and out. Right. You actually want to do the opposite. In a city, you are productive if you have all of these people that can move and can interact with each other and so on. So the solution is not anymore just the firewall at the edge. There's no edge anymore. And the solution has to do much more with being able to police, being able to detect. So, for example, one thing that Sysdig does that we are very strong at doing is what they call a security camera for software infrastructures.
18:59We have an open source tool called Falco. for this, which is a very popular open source tool. And this is something that you can place in different places of your cloud infrastructure, collects the data, brings it to a centralized point so that you can then understand what's happening the same way the police does by putting, you know, like security cameras in different parts of the city. And then you can, first of all, detect when something happens and you can also react very quickly. And the better this data is, the more granular, The more real-time this data is, the more you can react. So there's the difference between on-prem and cloud.
19:37It's like city versus medieval castle. Yeah, that's a good analogy. That's interesting. I mean, cybersecurity has developed very quickly when you look in terms of technological history. and you know originally it was professionals that were looking at code or looking at at systems as humans but as the attacks become increasingly automated security is now machine-driven. So how do we stay ahead? What's broken or not working about our current approach to cybersecurity? Yeah, what's broken, what's not working. Let's talk about the problem. And this mirrors what we were talking about earlier when we were mentioning essentially how security is changing now that the threat landscape is changing as the attackers become more and more empowered by AI.
20:57So we have a situation where attackers are at this point leveraging AI effectively and aggressively with all of the implications that we discussed before. And on the other hand, we have a defense landscape, in particular when we're talking about approaches, tooling, that is still in the early stages of evolving. And, you know, security traditionally has been human-centered, tool-supported, but human-centered, right? And the goal, I've been part of this industry now for quite a bit, and trying to provide tools that make the good guys as effective as possible. But the purpose has always been build tools that empower humans to be as best as possible at defending from the bad guys.
21:58right this is quickly becoming not good enough when the attackers move at ai speed uh this just doesn't work if the defenders work at human speed right so the what's you were asking what's the issue? The issue is that either we find a new paradigm that allows the defenders to do the same and to move at AI speed, or there's going to be a huge imbalance and it's going to be very, very hard to protect not only cloud software, but everything, you know, in general in cybersecurity. Yeah. I mean, you mentioned, did you say Falco? Was that the camera product that you put into a system? Do the attackers at this point, because we're now into the age of agentic AI, Do they have, are there agents that crawl through publicly facing software looking for vulnerabilities autonomously?
23:25Is that what's happening? And something like Falco, what exactly does it see? because this is all happening at the level of bits and transistors. Yes. Stuff like Falco is essentially, it works by having a set of agents, sensors that you deploy across your infrastructure, and this collects essentially data coming from multiple sources, data coming from, you know, running software. So which network connections are done, which files are open, you know, which commands are executed, all of this kind of stuff. It also collects signals that are coming from cloud trails and logs. So, you know, what AWS actions you are executing.
24:31AWS, you know, is the Amazon Cloud. So what are you doing there? You know, are you starting something? Are you changing configurations? Are you opening, are you putting data in some place? You know, this kind of stuff. So it collects all of these signals and then it's able to tell you, you know, by analyzing the signals if something either is an attack or is it something that is suspicious, essentially. And Falco traditionally... And here, when we're talking about what's changing in security, data is becoming more and more important. So Falco provides the best data that can be consumed for this purpose.
25:16What's changing now is that this data traditionally goes to humans in the end, you know, under the form of alerts, logs and so on, for judgment, for prioritization, and then for taking action. the way I describe it is the traditional software stack is B2H business to human and what is changing and in particular what Sysdig is changing in the way we're doing it and what we're changing in cloud security is that we're moving toward the model that I define more like B2A right business to agent so uh since they this week is uh introducing uh headless cloud security which means that uh it's security is cloud security but but built for agents so assume that you know we provide a software that still needs to be you know like the best software for for cloud security but now assume that it's not designed anymore for consumption by humans So we're abandoning, you know, like the traditional UIs and we're making it headless.
26:36We're making it essentially, you know, agent first, API first, so that it's designed essentially, you know, not to be consumed by humans as at least, you know, the main users of this, but it's designed to be consumed by agents so that workflows can be accelerated and automated by essentially basing them on agents first. And how do you know, I mean, that requires a tremendous amount of trust in the agents. So is it simply through testing that you develop that trust, that you know these agents are not going to block legitimate activity or that they're not going to miss illegitimate activity? How do you develop the trust in those agents?
27:32Yeah, let's talk a little bit about what we mean when we talk about headless cloud security. In my opinion, there are some really important paradigms here. First one is data is everything, right? This is, in general, being made very clear in the world of AI. Even when we're looking at all of these companies that are providing, you know, like the best, incredibly powerful AI models, in the end, data is the mod, right? The model that can be trained on the best data is the model that produces the best results. This is also very true in cloud security. So these agents operate on data and the better, the more granular, the more valuable this data is, the better outcome you will get from these agents and the less mistakes they will make.
28:41Paradigm number two, core concept number two is everything needs to be API based, right? so that is designed for consumption by agents so the ui this is quite radical but the ui you know the dashboards the point and click and so on is uh something of of the past because if you need you know like a dashboard you just point your agent to the data coming from the security tool and the agent will create the visualization that you need we call this hyper personalization so The security experience, the security product at this point is hyper personalized for every single use, for every single outcome, for every single individual that points the agents to the security product.
29:33The third important element is this becomes outcome and workflow oriented. So you need to infuse these agents. And this speaks to your question. How do you make them reliable and accurate? It's a work, you know, players like Sysdig, what they bring is they bring deep expertise in areas of security, right? So the question is, how do you infuse the agents with the workflows, with the expertise, with the ability to reach the outcomes that become goals, you know, when you need to detect in real time what's happening, prevent it, block it, take action, remove vulnerabilities, understand the attack surface, understand, you know, when sensitive data is exposed to the internet and remediate it automatically, right?
30:30So it's all about outcomes and it's all about making sure that these outcomes are converted in skills that are heavily validated. And then there's the how do you make the last part to answer your question is think about humans. How do you make humans more reliable at performing tasks? Because humans fail too, right? Humans can make mistakes as well. What we do in companies is we assemble them in teams and then we put together processes and give them tools that allow them to work productively and constructively in teams and minimize mistakes because there's proper workflows and proper, you know, checking of what everybody else is doing, right?
31:24There are whole industries in software. Git is essentially, if you look at the core of what it is, or Jira, these are just tools that are designed to essentially make humans cooperate in solving issues and do that with less mistakes. And these are tools, for example, that are used heavily in cybersecurity. So the question is, how do you create something similar, but for the world of agents? How do you make sure that, for example, there's a common shared memory for these agents in terms of, you know, security and protecting so that a learning from one agent can be taken, the other agents can be taken advantage and it's coordinated.
32:14You know, there's not, there's less guesswork because the decision is taken together and agreed, you know. So the other thing that CZig is working on when working on headless cloud security is these constructs, you know, to make sure that not only agents can operate well independently, but we heavily believe that agents make less mistake if they are properly trained and they're properly aligned with each other with the proper support and tooling that is coming from products and tools like ours. Yeah. And you talked about personalization. Can you explain a little more what that means? Personalization, personalizing data for enterprises and the era of the dashboard is over, you know, cybersecurity, the cybersecurity industry for decades, you know, like if you look at these products and And it's, you know, data collection and then a bunch of data visualization on top of it, you know.
33:26And every product is a way, you know, to assemble, you know, like the views and get the reports and generate them as PDFs. Because, again, that supports very much the human workflows, right? When I do some kind of work in cybersecurity, for example, in Posture, I then need to share my results with the CISO, and the CISO takes my results and the results from the other teams and creates essentially a report. So it's like humans that are working together in securing infrastructure. Now, there's two things that are happening here. Number one is data is the important thing at this point. And if you need a specific view on the data, gone are the days where you go in the product and the product is hyper customizable because what you do is you just point an AI to this data and it's like, I need this report for my CISO next week.
34:20The CISO is going to talk to the board and needs this for me. Let's build it. And let's build it in a way that is compatible with the look and feel of what our organization presents to the board, you know? And the AI becomes, that's why I say hyper-personalized, you know? Because the AI builds exactly what you need, exactly what the data you need. And it's the goal, it's the purpose of the AI to go and find the right data, slice and dice it, organize it, present it, and then you can iterate with the AI. But this becomes like conversation, the same way you would do with a teammate, with an assistant, rather than pointing and clicking on a user interface.
35:12So that's number one. Number two is more and more we'll automate and delegate this kind of stuff to agents that will do it for us. Does the CISO really need to invest the valuable time of a skilled analyst in just creating a report with the right look and feel? No, probably you can do it once or twice and that gets converted at a certain point into a skill for an AI, which will also be connected to your calendar and know when the presentation for the board meeting needs to be delivered and the prior night will put in your folder or in your email the report. And maybe the first time it's not exactly what you need, you will provide feedback.
36:04And the second time it will be much better. And the third time it's ready to go and you don't have to worry about it anymore. And you can just give it to the board and it's prepared like that. So all of these together makes us believe at CISD that, as I was saying, the UI is a thing of the past and that the future is exposing the data, the right data in the right way so that you can enable this workflow. Yeah. And the interface for the user then, is it conversational? I mean, text-based, natural language? So the user interface for the user, so this is interesting as well, because if we look at the evolution of how cybersecurity and not cybersecurity, software in general, has been embracing AI, I would say we are at step number three.
37:10Step number one is, okay, wow, there's these models that can speak and reason like a human. Let's include a chatbot in our software that can be an assistant, you know, inside the user interface of our software and brings, you know, like our user interface to be conversational. Since it has done that very early on, years ago, big results, you know, very nice. And you see this in many cybersecurity products. And all of the first wave of announcement was all about that. Then there's been wave two, where we're currently part of the wave two, which is agentic. You know, so more and more, this kind of AI that is embedded in cybersecurity products goes from being single step and question and answer into becoming more and more independent and being able to perform tasks independently, you know?
38:11And this is like the inclusion of a Gentic inside cybersecurity products. Sysdig, especially with our launch, with the launch of Headless, has a different point of view. Our point of view is that the user interface of the future for cybersecurity tools for any kind of software is the coding agent. It's cloud code, you know, in practice, to give you an example. Or equivalent. Codex, you know, you name it. One of these.
Read the full transcript
38:45People will... These coding agents, let's put it this way, will become the operating system of the future. Will become the Windows or the macOS of the future. They will be the place where we, people, sit when we integrate with software. This integration will be conversational, probably voice in the future, probably other ways to do this. But we believe that software will escape just the user interface of software. So when we talk about headless, we don't mean only, you know, like there's a genetic functionality and the AI is able to do stuff. but we really embrace SSD, the fact that workflows will run in the coding agent.
39:32And when you do cybersecurity, no matter if it's vulnerability management, posture, threat detection, and so on, you will do it from inside cloud code or equivalent. So then the question becomes, okay, what is the best way for a cybersecurity product to be cloud code first, rather than providing any kind of user interface. That's the concept of headless, essentially. The place where users live is cloud code. Let's make our software integrate and provide as much value as possible there. And let's make people get the best out of it in those environments. Yeah. So the user, as it asks the software to do something, it'll code a solution on the fly instead of it being a static piece of software.
40:33Is that what you mean? It's coding, yes, but it's also performing tasks. I see. Let's take an example. And again, let's go back to nowadays software. Typically, there's a bunch of constructs in nowadays cybersecurity software that has designed essentially to surface to the user the best data so that the user, the human, can take decisions. Right?
41:12but then the final decision is still taken by the human. In vulnerability management, for example, vulnerability management is the area in cybersecurity where you go and look at all of your software components one by one and all of the software that you've written, you know, line of code by line of code and you try to identify vulnerabilities. And then, of course, you try to fix them. And doing these like software tools, security products, what they do is they analyze your software. There's many ways to do that. And they look essentially where are your vulnerabilities? They tell you what are your vulnerabilities and where they are running, you know?
41:54And then the human decides, okay, this vulnerability is pretty bad. It was disclosed yesterday. The whole world is talking about it. It's a serious one. It's a very bad one. And by the way, it's running in production for me. so what I need to do is I need to go and upgrade my software to fix this vulnerability and then I need to push a new version of my software actually I'm not the person in charge of this software so what I need to do is I need to go identify the owner of this vulnerability and open a ticket for this person and tell them hey there's this urgent please take a look because we have this vulnerability now you need to make a new release with a fix for this vulnerability and you need to push the software in production as soon as you can.
42:40This is not necessarily writing code in the classic sense, but it's performing all of these actions that are done by humans today, you know? So from within cloud code, you will be able to do most of these, you know, through agents and through AI assistants. So it's like these AI assistants will be able to take a look, receive the data, you know, in terms of vulnerabilities, express judgment calls, like this one is bad and it's running in an environment that is very sensitive for me. So let's focus on this one. And then the AI can talk to you and tell you, okay, when you wake up in the morning and you talk to the AI, the AI will tell you, while you were sleeping, I analyzed this data.
43:24There's this one that is urgent. Should we go ahead? And you say maybe yes. What do you propose? And the AI will be like, okay, I see where this is. and I see that there's a new version I searched online, there's a new version of the software, I can make a patch for you, I can open a PR for you for this piece of software, and then I can communicate with the developer and let the developer know. This is step number one. In the even successive future, the AI could make the fix, decide that the fix is sane, and push the software in production for you. All of these from your coding agent, where you will discuss with your coding agents.
44:08And in some cases, this will actually produce artifacts that are software. In some other cases, this will produce actions on your software, on your code, on your infrastructure that are what today the practitioners do. And it will become more and more automatic. That's how you solve the problem of the attackers being so aggressive and so quick at doing stuff. You can compensate by automating on the good guy's side as well, and by therefore accelerating the detection and the resolution of these problems. And this starts from the environments where the users live. So this is not point and click, and you try to figure out what you should do first, but it's by in your operating system of the future, in your coding agent, by talking to agents and AIs that have been properly instructed and trained to perform these workflows together with you.
45:12Wow, that's fascinating. So how should organizations start thinking about this shift? And what will separate companies that succeed in this new model from those who don't. Again, I'm putting this in the micro trend of adopting AI, right? I think that we will see, we are already starting seeing major adoption of AI from organizations of any kind, any size, in any industry. And this is unescapable. It's a matter of competition and survival for every single enterprise on this planet. And it will require adapting to these workflows and embracing them as quickly as possible. What we are seeing in software right now, I mean, you read the news and especially, you know, like software news, like news that are special in software and every other day there's an article about this particular person is claiming that they have not written a line of code since last December.
46:33Well-known developers and so on and so forth. And it's pretty clear that in software development specifically, the future role of humans will be coordinator. right uh and enablers uh in my personal you know daily workflow essentially what i try to set as a goal is block ai's as as least as possible you know keep having the ai working for you uh because uh you are the one that uh especially with the current state of technology enables these agents, directs them, prevents them from making mistakes. They still very much make mistakes, right? So the human will become more and more an orchestrator and a provider of vision and a provider of strategy and oversight, right?
47:41So that's what we do as humans. that's pretty clear in code already, and we can all see how it looks in code already. My thesis, SysDix's thesis, is that the same would just translate everywhere, you know? So no matter what our field is, product management, sales, logistics, I have no idea, you know, we'll become orchestrators of little teams that we control to perform what we're doing and we'll get our hands less dirty with the immediate, you know, stuff and like the single line of code. But we'll be empowered to accomplish a lot by having essentially each of us a team of skilled and efficient individuals that can go after our goals and our guidance.
48:43That is very much, in my opinion, what will happen in cybersecurity. So I gave you some examples before, but the practitioners that right now have to worry about the single vulnerability inside a single piece of software will be more like, you know, will guide initiatives, will define and guide initiatives inside the organization, and then they will leverage their tools to perform these initiatives and to make them successful. Since Dig is designing today, what is the cybersecurity software that empowers people to do exactly this? Yeah. Yeah, that's a new world. There are a lot of times. The companies that aren't employing AI solutions to defend their software infrastructure.
49:43Is the threat going to overwhelm them? I mean, if companies aren't using things like Sysdig? I think the problem will become your ability to just sustain the volume, the pace, the quality, the sophistication of these attacks. So no matter how many humans you employ and how skilled they are, I believe that if we don't accelerate them and we don't support them through these technologies, and that's why CISD is embracing them so aggressively, they will become the bottleneck, you know? And it's, you know, it's like fighting a tank with a baseball bat, you know, or something like that. We won't just be equipped to the volume and strength of what comes to us.
50:51So we need to, you know, superpower the defenders so that they can, you know, contrast a tank with a cannon and not a baseball bat. Yeah. And that will be very important.
From the publisher
AI has fundamentally changed the cybersecurity threat landscape, not by inventing new attack types, but by collapsing the timeline. The same tools that make software developers more productive are now being used by attackers to move from vulnerability disclosure to active exploit in a matter of hours. That shift, argues Loris Degioanni, CTO and founder of Sysdig, changes everything about how defense needs to work.
In this episode, Craig Smith talks with Loris Degioanni about why human-centered security is becoming a structural liability, what "headless cloud security" means in practice, and why the coding agent (tools like Claude Code or Codex) may become the new operating system through which all enterprise security workflows run. It's a conversation about architecture, urgency, and what it actually means to fight a tank when you've been trained to use a baseball bat.
If this conversation made you think differently about AI and security, subscribe to Eye on A.I. for weekly conversations with the people building and defending the future.




