Sevii Brings Autonomous Remediation to Cyber Defense
Autonomous Remediation Moves Into the Security Spotlight
Alan Shimel speaks with Curt Aubley, CEO and co-founder of Sevii, during Techstrong TV’s Black Hat 2026 coverage. The discussion focuses on autonomous cyber remediation and why security teams need faster ways to respond to modern attacks. Aubley explains that defenders are facing adversaries that can move at machine speed. Traditional security operations often cannot keep up with that pace.
Sevii is building technology designed to help close that gap. The company’s approach uses agentic AI to support cyber defense, investigation and remediation across enterprise environments. Aubley describes a future where security teams do not only detect problems. They also act quickly, contain threats and reduce risk with greater consistency.
From Military Service to Cybersecurity Leadership
Aubley also shares the career path that shaped his view of cybersecurity. His background includes service as an Army officer, work in federal cybersecurity and leadership roles at major technology and security companies. Those experiences gave him a long view of how cyber operations have evolved. They also shaped his belief that defenders need a new operating model.
The conversation touches on his time at organizations such as Lockheed Martin, Intel, CrowdStrike and Deloitte. Each role added a different perspective on security, infrastructure, scale and execution. Aubley connects those lessons to Sevii’s mission. The goal is to give security teams tools that can act with speed while still supporting governance and contr
Agentic AI Changes the SOC Conversation
Autonomous cyber remediation is not just another layer of automation. Aubley makes a distinction between tools that create more alerts and systems that help complete the work. Security teams already manage complex stacks, rising alert volumes and limited resources. Adding more noise does not solve the problem.
Sevii’s model is built around AI agents that can support detection, hunting, reasoning and remediation. The goal is to help organizations respond faster without forcing analysts to manually drive every step. Aubley says this can help security teams improve response times, reduce operational load and focus people on higher-value work.
Security Teams Need Speed, Trust and Control
Alan and Aubley also discuss the trust challenge around autonomous action. Many organizations want the speed of AI-driven security, but they also need confidence in how decisions are made. That means policy, oversight and governance must be part of the design. Autonomous systems need to support security goals without creating new uncertainty.
For enterprises, the takeaway is clear. AI-powered attacks are changing the pace of cyber defense. Autonomous cyber remediation gives security teams a way to respond with more speed and scale. Sevii’s approach is aimed at helping defenders move from alert overload toward faster, more complete cyber execution.
Transcript
Hey everyone, we're back here on our continuing coverage of Black Hat 2026. We usually do most of our work down on the show floor, but this year we seem to be in a lot of suites, and it's actually a lot easier, more comfortable, and I think more conducive to a good interview. Let me introduce you to our next guest here.
His name is Curt Aubley, and he's with Sevy. Kurt, welcome. How are you, man?
Outstanding. Thank you for having me on today. Great.
Kurt, we're going to talk about Sevy, but before we get to Sevy, let's hear... You and I, well, we were talking a long time about everything under the sun. But give people a sense of your kind of journey of how you came to be here at Sevy.
So I was fortunate enough to be an Army officer, and then a friend of mine and I actually created a cybersecurity company, and we were part of an acquisition for Lockheed Martin. Really? Yeah.
So we were able to- Into the federal space ... the federal space, and was lucky enough to be the vice president and CTO of NextGen there. And for 14 years, did offense and defense of cybersecurity, amongst many other different technologies.
And then eventually found myself in Silicon Valley as a vice president and CTO at Intel Corporation, the chip people. Sure. And then- Well, they did more than chips, though, to be fair to them, right?
Oh, we do a lot more and it's silicon. Yeah. Yeah.
We used to say it's solutions, it's systems, it's silicon, and it is the whole stack. Amazing company. You know what?
So our newest site that we just launched about less than six months ago is Techstrong Semi. Because for most of my career, look, silicon was only Intel. Right?
Yeah. That gives x86. And there were people who did other x86, but it was Intel.
And now, of course, with AI and everything else, silicon is sexy again, right? And- Oh, I've always thought silicon was sexy. Well, you always thought it was sexy anyway.
In a past life, I actually did a lot of work with the US Army and also information assurance. Spent a lot of time down in Fort Huachuca. I was stationed in Fort Huachuca.
Were you? I was. Yeah, we were not at Techstrong, we're just a media company, but I've been in security a long time.
And so we had a network access control product that was like the standard Army NAC for a while, and we got certified in Huachuca and did that whole thing, and then I did a tour of all. But you've probably done more Army bases than I have. But I've done my share of Army bases, for sure.
So then you're at Intel. And then some of my friends that I worked with at Lockheed Martin had started a new company in California, so I joined a little company called CrowdStrike. Really?
Yeah. So George, was George and, George Kurtz is there, really? Well, George, Dmitri, Mike Carpenter, the whole crew there.
I knew Mike Carpenter, actually. Just amazing. Very lucky to be- Small world ...
part of that team for about four years as a vice president there. And then, it was time to move to Maryland for a variety of good reasons, and I joined another little company called Deloitte. Geez.
So I was lucky enough to be a managing director there and was a solution leader for detect and respond business, which I had three security operations centers in the US. Mm-hmm. One in Madrid, a sister SOC.
Mm-hmm. Hyderabad, India. Okay.
About 1,000 people on the team. Amazing IR team, intel team. Sure.
We went from the number 86 MDR provider to the number one MDR provider, was very proud of the team for everything they were able to accomplish. Uh-huh. And that's when we realized, even with 1,000 people on our team- Not enough ...
and we had great partnerships with CrowdStrike and Google and many other great partnerships and technologies, and wonderfully trained people, we still didn't move fast enough. And when you look at how fast things are moving today, especially with Frontier labs now releasing autonomous agents out there, either planned for marketing or not planned, the speed is just amazing. No, I don't know if it was...
Well, the timing was- Very interesting ... interesting. So I wrote a thing recently.
Don't blame the agents. They're not malicious. They're just doing their job.
Right? You can't set up a containment with guardrails not to let these things out. I blame the people.
But you're right, it makes for very interesting times. But that's being at Deloitte is where Arnishima and I had our initial idea for an autonomous defense and remediation platform that could move faster than adversaries- At AI speed ... at AI speed, at machine speed, at machine scale.
Yeah. And we were very lucky to meet two other co-founders, Steven Collins and Caleb Cross, who were also thinking the same way, and together we started Sevy. Love it.
What a great story. So look, I think it's probably been a dirty little secret for, I'm in security 25, 30 years. It's been a secret for all 30 years.
It's a losing prop with SOCs, right? Even before the AI came into it. In addition to working with US Army, we worked with another network called NMCI.
Probably heard of it. I'm very familiar with NMCI. Well, yeah, because if you know Mike Carpenter, you probably know NMCI.
Well, at Lockheed, we didn't do NMCI, but we did NASA ODIN and- Yes ... other massive- It's another one. Deals, yeah.
So you know the deal there, though. But that's where my eyes got opened to just really what the mission was, and how Under-resourced, undermanned we were. And that was before AI, as I said.
At NMCI, you were getting, back then, hundreds of thousands of intrusion attempts a day from some of our friends in the world. And- I'm not sure they're friends, but okay Well, I say friends. Some of them we thought were friends, too, but it doesn't stop them from probing.
But anyway, and that's when I realized just how undermanned our SOCs were. And I think it's only gotten worse, unfortunately. Yeah.
Mathematically, even with the most amazing people, well-trained, hardworking, we have put all these different architectures. Our architecture for our security operations centers haven't fundamentally changed since the early 2000s. No.
We have these great sensors. Now we have EDR and next-generation AV, and then you bring that into special data management tools, and then you get it into a central SIEM. Then maybe you put a SOAR on it.
SOARs came out in 2014, right? Mm-hmm. Maybe you throw some cyber intel in there, then it gets a case management system.
The time it takes from the edge, all the way through to a case management system to a human, that can be anywhere from five minutes, 15, 30 minutes before a human looks at it. And do you really want to have an adversary get a, "Hey- It's over. It's over by then ...
take 30 minutes of our day. " It's over. But they're onto their fifth one after that.
That has always been the issue. But now, of course, AI has just blown it up, because if you're not moving at AI scale, you're stuck in cement, right? And I think that's been a major, major issue.
The question is, and I'm sure people watching this, is this guy saying AI's going to take your job at the SOC? Probably not, I'm thinking. Right?
You're going to need SOC people, but these are now SOC people on steroids, right? SOC people empowered. Absolutely empowered.
So when you think about how our industry's changed over time, because people couldn't hire enough people, it's really budget challenges we have. Right? If people had unlimited budget, hey, no problem, I can just go hire as many people I want.
Yep. Give them wonderful salaries, train them, it'll be wonderful. It doesn't exactly work like that.
We have budgets, and a lot of people outsourced. We might have called it MSS, MSSP, MDRs. And I think now, with where our technology is and others, we're giving cybersecurity products back in the hands of the operators so they don't have to outsource anymore the traditional level one, level two, level three- Yeah ...
hunters, things like that, because now they can leverage AI to do that. Absolutely. In many different ways, right?
Now we're really talking autonomous AI at this point. So first of all, I don't disagree with the premise. Right?
Quite frankly, it's the reason I left my last security company, is I realized security was too hard for all. The only people who had those kind of budgets were like the Fortune 50. Maybe there was a handful of companies in the world.
Yeah, the really large companies or large government agencies. Right, that could do that. The rest of the world was SOL kind of thing, right?
I think it's depressing. It depresses a lot of security people to know we deal with this. But right now, Kurt, we also deal with people hear autonomous AI, and you're right, you mentioned it before.
They think of breaking containment, these rogue agents, and they weren't rogue agents. They were agents doing their job, but agents breaking out. Right?
How do you think we're ready for autonomous SOC? So there's a couple thinkings here. One, I don't think we have a choice.
There is that. Really, you don't have a choice. What other options, right?
There's some trade-offs here, right? Right. And unless, if you're a public company and you're compromised and you could've stopped it, and you have to go in front of Congress or do an SEC filing, those aren't enjoyable experiences.
Not at all. Right? But if you design your autonomous platform with governance in mind from day one- Mm-hmm ...
then it absolutely is possible. The problem we solve is that adversaries move so fast. And if you look at, whether it's Gartner data or personal experience, it takes hours or days to detect, fully remediate, maybe even recover from a cyber attack.
And if you look at reports from, say, CrowdStrike, they generally say it's in 26 seconds if the fastest adversaries break out. Once they're in and out. Maybe it's 28 minutes if it's an e-crime actor.
We'll call it 15 minutes on average. So you really have around 15 minutes to stop an adversary before you're at a lot of risk for your environment. Mm-hmm.
So that's why we've developed our autonomous defense remediation platform, has agentic AI agents. Since we happen to be an American cyber company, we do all of our development in the United States. We kind of joke we're designed in California, we build in North Carolina.
Just like the other guys. Except we build in North Carolina. Exactly.
And about half our company is former Army and Navy and other combat veterans- Federal. Mm-hmm ... which is fantastic.
So our agentic cyber warriors are able to stop adversaries at machine speed and scale without the need for humans in the loop. Now, when I say that, immediately people get scared. " What's going on?
It doesn't scare me. I'm going to explain to you why when we're done, but go ahead. But if you build the right Governance in from the beginning, so that you have multiple layers of governance where you can control exactly what your cyber warriors are doing.
Because the cyber warriors become extension of your team. Yep. And we measure the results.
Usually, we see a 90% improvement in meantime detection, meantime to hunt, isolate, remediate, remove the isolation, write your report. It's like two to 12 minutes depending on the attack. Right?
But you control what they do. Do you want a human in the loop or at certain stages? Do you only want autonomous processing of every detection?
Because traditionally, you don't look at every detection because not enough people and it costs too much money. Yeah. Autonomously looking at every detection, autonomously hunting everything.
Normally, you don't hunt everything because- Yeah ... you only have a few hunters on the team. You might stop right there and be really happy that, hey, all this work was done and I can hand it to my team.
Or you might want to go all the way through to autonomous remediation- Mm ... depending on the asset classes and what's happening out there. So if you design your platform so you can build trust over time and you're very transparent, we do now have partners and customers in autonomous mode.
6 million assets- Really? identities, enterprise, laptop, desktop, servers, all that kind of good stuff, under separate protection. Beautiful.
There's a couple things there I'd like to unpack. Number one, this is why I call it AI scale, not AI speed. It's not necessarily just about the speed.
It's about the scale. It's about the ability to handle 1,000 different things, 10,000 different things, 100,000 different things that you couldn't handle with humans. Now, you mentioned the whole human in the loop thing, and you're right, that does scare the heck out of people out here.
Right? Because they want a human in the loop. But when we're talking about things- That's okay.
Years ago, that cloud computing thing seemed really scary- It's the same thing too ... because I had to have my own data center. Remember those days?
Yeah. Yes. Although data center seems to be coming back again, but you know.
$8 trillion worth. But there's a whole another story. I wrote a whole book I'm coming out with on that.
But anyway, but here's the thing about the human in the loop. If you insist on putting that human in the loop, like when you're running a race, you're as slow as teammate. Yeah.
That human becomes the slowest teammate. I prefer another way of looking at it. I call it human at the helm.
Right? So you're not in the loop per se, but you do have some oversight. Absolutely.
You're supervising it. You can provide advice. You're guiding.
You're setting the policy. I feel like a captain at the helm. Yeah.
Right? Not down in the weeds, but at the helm. And I think that's the model.
I think human in the loop is a way station on the way to human at the helm. So, that makes perfect sense to me. What about money?
Do we save money doing this? Because am I saving headcount? Am I saving...
Or is it, hey, it's not a question of money, it's a question of better protection. Or am I getting both? Because I like to be greedy like that.
Absolutely. Why not do both? Uh-huh.
Right? We're very fortunate. We have no legacy platform products or anything else, so we could be autonomous AI native from day one.
Mm-hmm. So we designed in both cyber return on investment and total cost of ownership return on investment. Because fundamentally, we have a speed problem, adversaries come in fast.
We have a scale problem, the number of attacks. And thanks to the mythos, AI era now, which I think is actually the best marketing campaign ever for cybersecurity. Because now it's back on top of every board's mind, right?
Mm-hmm. But it's real and it condenses- It is real ... the time from vulnerability to exploit, and you get more volume of intel.
But the fundamental problem we have is actually economic. If every security team had an unlimited budget, they'd solve the problem. They'd hire the people they want, they'd hire as much tech as they want, it'd be great.
" That'll help. Until AI co-pilots start charging for AI token use. Mm-hmm.
I'm not sure why people were doing that, but they were. So now, I still have a budget problem. I don't have enough budget to get all the people I want, and now I don't have enough budget to pay for all the tokens.
In fact, I actually have some customers where they were burning through like a whole year's of budget after like one month of cyber attacks. So we economically have a problem. So one of the things, and this is for us, we have a very strong silicon strategy, and the architecture of our product is such that we do not charge our customers tokens.
We believe that's our job. Really? Absolutely.
You ever use Expensify or any of those SaaS applications for- All of them. Yeah ... expenses and stuff like that?
Yeah. Did you ever see the little box that says, "We're charging you for CPU time, disk time," and stuff like that? No, they don't charge you, you just use the app, right?
Absolutely, yeah. Guess what? We believe that handling AI tokens and that architecture and your silicon strategy and using AI models when they're needed, not doing, say, like AI SOC technology's pretty old already, right?
Yeah. That's like wrapping an LLM around the SIM. Mm-hmm.
Too slow, costs lots of money. And it didn't really help, right? So if you have the right architecture, then your cyber ROI, you can spin up as many cyber warriors as you want and stop adversaries at speed and scale without worrying about being charged.
We license per asset protected, per endpoint, per identity. It's good. So I think this is where the world has to go.
Right. I think we got to get away from the token thing, because you're never going to get AI to reach the scale you want it to reach when you got to watch a token out of the corner of your eye. But how are you doing that?
Are you using open weight models, your own models? I'm assuming you've got to be hosting this yourself. So we do a mix.
So first, I just want to tell you the TCO side, what we're finding is we track all the time we save our customers. Yeah. So if they have 100,000 detections this month, we look at all of them.
So we autonomously process all of them. We autonomously hunt everything, leave no little detection behind. Then we autonomously remediate.
So we track all the time, so you actually get a dollar amount in our dashboards that show you how much money you save. Each time. But really, it's not really cost savings as much as cost avoidance.
Right. Because you really want to keep your security teams because you trained them up. They're amazing.
Yep. Right? You might not outsource as much.
So that's a different business model. Now, for AI tokens, specifically asked about our architecture. So fundamentally, when you have a platform that's what we refer to as well-architected, you're only using AI when you need it.
Right. And that could be in the form of machine learning models. It could be frontier models.
We're partners with a number of frontier providers. They're fantastic to work with. We leverage some open source, open weight models.
Mm-hmm. Today, we're an US AWS commercial cloud. We're also an AWS GovCloud.
Okay. We'll be FedRAMP this September. Very excited about that.
Very cool. We're working with a couple of different countries to put our sovereign clouds into different locations- Mm-hmm ... because of the data requirements for those countries.
So, we do a little bit of hosting on our own. You do. But we also leverage our AWS partnership significantly.
Excellent. Kurt, we're running low on time, but I wanted to mention, you guys, so we recorded this Tuesday of Black Hat, kind of first day Black Hat. You guys put out your release, a release today, right?
Oh, super excited about this. Let's hear it. There's so much great intelligence reports.
Our partners like CrowdStrike has great reports, and Google has great reports. DHS has great reports. Yep.
You know how many people actually read all those reports and take real action? Large companies with intel teams, absolutely. I had about 100 people when I was fortunate to be working at Deloitte.
I had, like, 100 people on my intelligence team. Sure. Most people don't have that.
No. So we've developed first autonomous preemptive security module. It goes on our autonomous defense remediation platform.
And what we do is we continuously and autonomously process all new intelligence every 15 minutes. We then autonomously determine, hey, is this intel even relevant to me? And if it is, we create a hypothesis hunt.
Really? And then we hunt the customer's complete environment and determine, hey, are you already compromised? Because this is brand new intel, just came out probably 15 minutes ago.
Or maybe you have some vulnerabilities that were exposed. So this is, again, AI scale. AI scale, and then we'll do the automated remediation for cleaning up- The clean phase ...
compromised systems. And if a patch is available, we'll actually go ahead and do the patching. Now, sometimes, as you know with Mythos, that isn't available.
But if you think about it, from pretty much the time a new intel report is published, 15 minutes later, it's autonomously processed, autonomously- And that's the AI scale we need ... hypothesis hunted, and autonomously remediated. Right.
That's- So we're very excited about this. Yeah. I'm excited about it because that is, again, AI scale.
Right? Because with Mythos, the time from vulnerability, discovery let's call it, to exploit is probably- Well, condensed ... it's not 15 minutes though.
That's the good news. I think it's 28 minutes or maybe a couple hours. So 15 minutes gets you.
But that's what's needed here, right? That's what we need. And it was announced today.
Is it available today? It is available today. In fact, we have a couple customers where we're operational.
Very cool. And it is new, so we work really closely with our customers. Oh, look.
And wow, it's so much fun to keep building quickly. Absolutely, because that's the... Look, you've been in business a long time.
I've been in business a long time. This is a new era we're in right now. It's so damn exciting.
We're solving problems we've had for 25 years because the tech just didn't exist back then. Exist to do what you can. So this is another thing I caution people all the time.
" Yeah, so does everyone else and everything else. Is it a hell of a lot better than anything we've had before? You bet.
Well, here's the good news. We have something called self-correcting AI. Well, look at then, that's the beautiful- And so we'll talk about that another episode.
Another time. Hey, but we got to run. Kurt, first of all, congratulations.
Thank you. You know what we didn't mention? Hey, what's the website?
com. com. There, you heard it.
All right. Hey, we're at Black Hat. We've got more coming.
Stay tuned.