Endpoint Security Moves Back to the Front Line
Endpoint Security Faces a New AI Reality
Alan Shimel speaks with Nati Hazut, founder and CEO of Bold Security, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on endpoint security and why the endpoint is becoming more important again. Hazut argues that the industry has accepted weak endpoint controls for too long. AI is now forcing teams to rethink that approach.
Hazut explains that Bold Security grew out of lessons from his previous work in data security and cloud security. While working with customers, he saw a basic problem. A user could still move sensitive data from a production system, zip it and send it through a SaaS app. Legacy data loss prevention tools often failed to stop that risk. That gap helped shape Bold Security’s focus.
AI Brings Workflows Back to the Endpoint
The discussion highlights a major shift in enterprise computing. For years, security teams moved toward consolidation, cloud services and browser-based workflows. Now AI is changing that pattern. Users are running AI tools locally and handling sensitive data on their devices. That makes endpoint security a front-line concern again.
Hazut says this creates new risk. The problem is not only malicious employees. It can also be accidental exposure caused by new AI tools. If sensitive data reaches a local model or unapproved workflow, the organization may lose control without realizing it. Bold Security is designed to help teams see and manage that activity in real time.
Local AI Models Can Improve Control
Bold Security uses local AI models on the endpoint to classify data and analyze user actions. Hazut says this helps address two old problems in a new way. First, many tools still rely on pattern matching and regex. Second, traditional systems often struggle to understand user intent.
By running AI locally, Bold Security aims to reduce privacy, cost and third-party risk concerns. The platform can look across apps, data, users, actions and AI workflows. Hazut says the goal is not to add another narrow agent. The goal is to give teams one control point for endpoint security and data protection.
Endpoint Risk Needs a Broader Platform
Alan and Hazut also discuss how endpoint tools have evolved since the antivirus era. Older tools were often heavy, limited or focused on one type of threat. Today’s endpoint risk includes data movement, AI use, SaaS workflows and user behavior. That requires a broader model.
For security leaders, the takeaway is clear. Endpoint security is no longer just about malware or device protection. It is about understanding how people, data and AI interact on the device. Bold Security is betting that this shift will make the endpoint central to enterprise security again.
Transcript
Hey everyone. Welcome back here to our continuing coverage of Black Hat. This year's Black Hat, we are going where the people are, it seems.
We have been in the W, the Four Seasons, everywhere. Elevator alcoves, it seems. We're now near the media room and book room here, and I'm happy to introduce you to Nati Hazut, who is with Bold Security, and you may not know Bold Security, but you will after this.
Nati, welcome to Techstrong TV. It's great to have you on here. Thank you.
Thank you for having me. So let's start with basics. Who are you?
Right? Yeah. Tell our audience, if you don't mind, a little bit about yourself.
Yeah, sure. So, I'm Nati, founder and CEO of Bold. Bold is my third company.
So first startup, I had an agent-based security solution for a service provider. This company got acquired by Qualcomm. Mm-hmm.
And then my second and previous journey was in the DSPM space, a company called Polyrise. I sold it to Varonis in 2020, and then, for three years led their cloud initiative for Varonis. Okay.
And I thought that after this company, I'm going to take some time off. It ended up with three months. Never works out.
Because we saw a huge opportunity in the endpoint space, a space that we as an industry kind of neglected for the past 20 years, I believe. Longer than that. Yeah.
And, excited to be here today and share more about what we built. Absolutely. So you're what we call a serial entrepreneur.
That's how they call it. Welcome. My name's Alan.
I'm one, too. I've done about four or five startups. Amazing.
And after every one, I always say, "I'm going to take some time off. I'm going to hang out with the kids. " Yeah.
I hope my wife doesn't listen to this. Look, I'm married 36 years. Okay.
And she put up with me the whole time, so- Okay. I'm married two years- You'll be okay ... so I don't know enough, you know.
It'll be fine. At some level, as long as you're doing what makes you happy, that makes them happy because it's not like you're trudging off to work every day, right? Okay.
You're doing things that you're passionate about. Okay. So endpoint security, right?
You're right. Look, I gave up on endpoint security about 25 years ago when the Semantics and the McAfees of the world, they were so heavy that it used to kill my system, and I had to make a choice. Right?
And then Microsoft, this is before your time, Microsoft went free. Mm. Right?
With Defender. Yep. And that kind of crushed it.
But really, back then, endpoint security meant antivirus anyway. Yep. And it never really worked well.
Of course, we've seen endpoint security evolve. Other companies have done well in the endpoint space. What made you think the time is right, that what we have today is not doing the job?
So honestly, for me, the aha moment was when I was working with clients on a big DSPM project, and after spending so much efforts, right, client is asking those basic questions that make you reevaluate everything you thought was right. And the question was very simple. It was like, "Okay, now that we're done with this project, what if a user will take data from my production environment, zip it, and share it through whatever SaaS?
" And then I realized that as an industry, we kind of like the endpoint, it's such a huge gap, but for years, we've got used to the fact that it's not that good, but for some reason, we're sort of okay with that. But then I thought about how things are moving right now with AI, and I think it's funny to see how trends are shifting back and forth. So 20 years ago, 10 years ago, we were all about consolidation, cloud compute, VDIs.
This is where it's going. Browsers, right? And then suddenly, we see AI, and we see how the vendors create those GPUs and MPUs.
We see how users are leveraging those AI models locally on their devices. And I think what is interesting here is to see how the endpoint, what used to be the last mile of the enterprise or the backyard of the enterprise, however you want to call it, now it's becoming the front. Because if you have now sensitive data on your endpoint, it's no longer you trusting your employees.
It's just an unintentional exposure by a new AI tool. " Because the old solutions are still struggling with the old problems, and now we have much more complex challenges to face, and we're not ready. Right?
We don't have the pace of improvement with the existing tools. We don't have the offering there in place. And as I said, we're still struggling with the fundamentals.
You're struggling with the old stuff- Yeah ... when it's a new era. Yep.
It's kind of like the French and the Maginot Line. Yeah. Right?
They're still trying to figure out how to win the last war. Mm-hmm. When they don't realize there's a new war.
Absolutely. Yeah. So I call a lot of this, what you're describing, this is sort of Apple's moment, right?
" They didn't miss anything. I think what we're seeing, and we're seeing this play out with the open weight models and everything else, we are going to move to a point where the AI is running on our endpoint, right? Not in the cloud, not at these $8 trillion worth of data centers we're building.
It's going to run on our endpoint. Right. And if we're not prepared, it's going to be a disaster.
A disaster. So this is Bold's moment then. Yep.
Yeah. And you're right. In fact, I think when we talk today with IT and managers and CISOs, one of the things that tremendously changed was the way we adopt new technologies.
In the past, it would go through the IT architecture team, security team, then you provide access to this SaaS, to this new tool. Now, with AI, innovation starts on the endpoint, and we're not ready. And we hear it across the board.
We all want to be AI first, but we all want to make sure that nothing breaks. And obviously, it's hard because we don't have the right tools for it. Nope.
And as said, the vendors, the manufacturer of the hardware, they already provide our employees the NPUs and the GPUs. We understand the token's going to be a problem. We understand that we need to run it locally.
But as said, we don't have the tools to control it yet. No. And I think the question, Nadi, is, do we try to build, bolt on these newer tools to the old tools?
Or do we say, "Look, it's a new time. " Period, right? You can't turn a horse into a cow, and you can't turn a cow into a giraffe.
Yeah. Absolutely. And we may need a giraffe, right?
Yeah. We don't need a faster horse- Exactly ... to run on the gym.
I agree. That's exactly what it is. I agree.
It's a faster horse isn't going to win this for us. I agree. So- So now, how does that translate to what you're doing at Bold?
So our approach is actually not to just close a very specific gap, let's say just AI, because as said, we're still struggling with the old problems. Let's talk about why we're struggling with the old problems. It's because of accuracy.
We're still classifying data with regex. Yes, in 2026, we're still using regex. And we don't have the tools to analyze intentions.
So on the bright side, AI is great. It's a natural talent with these two aspects that we didn't have these capabilities in the past. On the other hand, we have the drawbacks of AI, scale, cost, privacy, third-party risk, after the fact versus real time.
And the way we did it with Bold, we basically create local AI model running on the endpoint. And with that, we can analyze all the actions of the users. We can classify the data with AI.
And here's the thing, we're not just going after the shiny new gaps of- Right ... AI, agentic, all these buzzwords. It's important.
You need to close it. But you definitely don't want to have yet another agent. Right.
So the way we see it, you should have one agent to control how endpoints are being used across apps, data, users, actions, and AI. " But, and we already did it with our existing customers, we replaced the legacy DLPs as well. Really?
So it's really a platform then. Yep. Today it's DLP and the AI, but when you look at the spectrum of what endpoint security can do, there's more meat on that bone.
Absolutely. And I think that's kind of our approach. In general, when you think about innovation, and entrepreneurs really like the next gen thing.
But sometimes, because reality changed that dramatically as we have now with AI, next gen is not enough. Because when you think about it, DLP is very siloed to data. But if you want to control effectively AI, let's say very basic example, cloud code accessing your passwords, encrypting it, and sending it through an unmanaged MCP outside of the enterprise.
For me, in order to see and control it, I need to have the visibility to the application layer, to the data, to the actions, and even to the posture of how this endpoint is configured. Mm-hmm. And then to control it.
So DLP is not enough. So the way we look at it, it's not just DLP, it's a modern approach to something that is much broader that will give you this control, and to your point, as a platform, and not just as a solution. Absolutely.
So security, you got to love it, right? Yeah. I'm doing this 25, 30 years.
You look at what's going on with Mythos now, with the vulnerabilities, not just all of the Mythos-like scanners and all. The fact is, we never fixed our vulnerabilities before Mythos. Right?
Yeah. We were always behind. Yeah.
What we were finding versus what we were remediating. Now we're just further behind. This is a very similar thing here.
There's a reason why no DLP company ever just killed it, because none of them did it- Right ... right. Perfect.
I agree. Or even very good. But I do think you're right.
In the AI here, there's two aspects of it. Number one, it allows you to do it right after all this time. And number two, it also, because this is how the AI god works, it takes and gives away, right?
Right. It also opens up this whole other can of worms- Right ... about how we defend against AI.
Yeah. And that really is what Bold covers both of those. Yeah.
And I think that one Other new aspect that now we have with AI is the fact that we can do what we call soft enforcement or soft prevention, and I'll give an example. Until today, if you were not sure, you'll escalate it to a human. Right?
And the human in the loop, it's a big problem. We see it also with mitigation of vulnerabilities. The fact that things are happening in such a fast pace, you don't have the time or capacity to have someone to actually review it.
With AI, you could actually check intention and decide which exceptions you want to streamline, you want to auto-approve. So I think on the bright side, these are good things that will allow to scale these type of solutions. I don't disagree at all.
I think sometimes problems are just waiting for the right moment, right? And this could very well be that moment. Now, you guys recently released a new version.
Mm-hmm. Tell us what's new and what's that about. Yeah.
So, we talked a lot about the platform piece of Bold, right? So when we have all these layers of context and control, the natural next step for us was to provide an advanced model for AI interaction. Because basically what we see, the traditional tools are very focused on, let's say, web-based security or some desktop app security.
And the problem with AI, and the agents, it's hard to predict which tools they're going to leverage. Whether it's the MCP tools, whether it's CLI commands, whether it's desktop apps. And with Bold, what we did is basically we provide visibility into the data that these agents are accessing, the intention of them, where they're communicating outside of the enterprise, the session itself, the data that is involved.
So basically, we provide an end-to-end solution to secure AI adoption. And it's important to mention, AI security is such a broad term, right? And it will take time until we understand where everything fits in.
But with Bold, we know one thing for sure. You can't start protecting AI before you have good control over which tools users are using and how they're using them, and what data is exposed to these agents. That's kind of the first fundamental piece you should figure out before you go to the advanced MCP gateways and all these type of things.
So what we're releasing basically is a model that help the enterprises securely adopt AI, be AI first without the risk of users experimenting tool in an irresponsible way that can put your organization at risk. I love it. You know what we didn't mention in all of this?
What's the website? What's the website? security?
security, right there. Nadi, this is the first time. I hope to continue our conversation- Yeah, same here ...
maybe not in Vegas, but- Yeah ... virtually, whenever. You could always come to Florida.
security. Go check it out. We're here at Black Hat.
We're going to have a lot more for you in a minute.