Making Endpoints Sexy Again: AI in the SOC and the Future of the CISO
Techstrong Group’s Alan Shimel sits down with Sophos CTO John Peterson live from Broadcast Alley at RSAC to discuss how the relentless speed of agentic AI is making endpoint security sexy all over again. Peterson shares his incredible nine-year journey scaling Sophos Central, diving deep into how their massive MDR operation is leveraging AI to automate tedious SOC tasks and tackle the newest bottlenecks in the software development lifecycle. Ultimately, they explore the burning question on everyone’s mind: will AI replace the CISO, or simply free security leaders to focus on high-level strategy as the volume of machine-speed vulnerabilities explodes?
Transcript
Hey everyone, we're back here live at RSA. We're in Moscone on what they call Broadcast Alley, and I'm really happy to introduce you to my next guest. It's his first time on Techstrong TV, so it's a pleasure to welcome him, John Peterson of Sophos.
Nice to be with you, Alan. Nice to be with you. Thanks for joining us.
So John, what's your position with Sophos? I'm chief technology officer at Sophos. CTO?
Yes. So I'm responsible for all the folks that build our products and support them out in the wild for our customers. Excellent.
Yep. So I always like to let people know who they're listening to. Mm.
You don't just walk in one day and become CTO of a company like Sophos. John, tell us a little bit about your journey. Absolutely.
So I've been with Sophos now for almost nine years, believe it or not, and it feels like I joined yesterday. But when I first joined, I was responsible for the cloud security group, so the group of engineers that's responsible for the Sophos Central platform. Mm.
And at the time that I joined, Sophos was going through this transition because we were one of the first endpoint security companies in the world, actually. And like many of the original endpoint security products that were out there, our original endpoint products were all kind of on-premise managed, and we were going through this transition to the cloud, right, and cloud-based management. And so there was a huge inflection point that the business was going through at the time, and I was able to help them through that and get Sophos Central to the point where today it supports over 600,000 customers, 28 million devices- Wow ...
globally. So, we're processing petabytes of data every day. So, the platform itself has really grown, our business has grown, and I've been fortunate enough to be in a position where my role has grown with the company.
Love it. Yeah. You know, it's an interesting thing, John.
The wheel of karma goes round and round. Mm. So Sophos was in one of the original endpoint- Mm ...
then went to the perimeter, then went to the cloud. Mm. And now with the advent of AI- Mm ...
AI on the edge, AI on your devices, you're an endpoint company again, right? Yes. Yeah.
All of a sudden, endpoints are sexy again. Or endpoint security is sexy again. We think that endpoint has always been sexy.
Okay. Beauty is in the eye of the beholder. But, that's a great story.
And you know what? We touched on it a little. So there's still the cloud security- Yep ...
aspect of Sophos. There is this big endpoint push. Yep.
What's the three-letter acronym for endpoint security now? ER. Yeah.
EDR. Yep. Do you still make ETMs and sort of perimeter boxes, or?
We still have a large and growing firewall business. Really? It's less of a UTM business, but more just like a business enterprise edge, SMB, mid-market focused firewall product.
Really? So we see Fortinet all the time out there. Yeah.
In the market. They were here earlier, actually. Okay.
Yeah. But yeah, we still have a large firewall business. And people have been talking about the death of the firewall for a long time.
From 2001- Yeah ... when I started, they were talking about it. And the reality is that business for us continues to grow.
We continue to invest in it. But we of course also are investing heavily in our MDR business, which is, actually, we believe the largest MDR operation in the world. We have 35,000 customers.
Really? And actually that's one of the things that's allowed us to do some pretty innovative things with AI agents for our MDR operation. Because we have, I think, probably more data about customer behavior and the active threat landscape, and also how to deal with that threat landscape and those active threats, than any other vendor.
So as we're building agent-driven solutions for that SOC to help us with efficiencies and also with better customer outcomes, we're in a position that we think is just very competitive because we have this corpus of runbooks and standard protocols and procedures that our SOC uses every day to protect customers that we can use as context to make the agents better and drive better outcomes for our customers. I love it. Yeah.
It's a great story. Mm. So, we're one day in...
Well, we started yesterday, so maybe there's two days in- Yeah ... to RSA, and there's clearly no mistake. This is the year of agentic AI at RSA.
Yes. I got a confession. I've been using AI for a while, but the last three weeks or so, month, I really dug in on agentics.
It's a drug. I'm telling you, this is like crack. Because it's not only me, the people in my office who are on it- Mm ...
it's very hard for them to disengage. They're coming in on weekends. I haven't had people in the office on weekends in- Right ...
I don't know when. Mm. They're staying late.
They're coming in with stuff they did at home. Mm. Because people are just like, "Holy, I can't believe I could do this," right?
Right. It's that kind of effect. Are you seeing this similarly within Sophos, in the people you're managing?
And more importantly- Yeah ... we got to help secure these people because they're running as fast as they can. Oh, 100%.
Yeah. And I think the answer is absolutely to that question. It's been remarkable, even just in the last six months, to see how fast the technology has- Six weeks.
Yeah. How fast the technology has progressed. 6 has- Game changing ...
such a leap forward. Yeah. And then one of the things that I spend a lot of my time thinking about is AI-driven engineering, and how can I enable the development workforce at Sophos to build our products more efficiently and-The AI coding tools are going to be a big part of that for us.
Sure is. And like you said, it's sort of like a drug when you get going with it and you start seeing something that used to take you days or weeks being at your fingertips in- Moments ... a matter of moments.
Yeah. Yeah. And so we're definitely seeing that in the engineering side, but also, as I mentioned, in our security operations center for MDR, there's a huge amount of efficiency and just better outcomes that we've been able to drive with the agents that we're building.
But also, I would say that the same tools that are great for us as defenders are being exploited by attackers absolutely mercilessly. And so the amount of time that it takes to actually take a vulnerability, or even discover a vulnerability, that used to be a very specialized niche thing, and that still is. Security researchers out there every day submitting issues to our bug bounty program and every bug bounty program out there.
Well, but this is a problem now. Right. The volume of bug submissions.
Right. A lot of people are shutting down their bug bounty programs. Yeah.
The Curl, for example, was one of the- Yes ... ones that I saw, yeah. And so that's troubling in a sense, because we have this explosion of vulnerabilities.
We also have the amount of time that it takes to exploit one of those vulnerabilities successfully and then scale it massively, that used to be contained to a very small set of- Players ... specialized operators. Mm-hmm.
Now, it's available with kind of a master- Well, yeah ... any 18-year-old with an- With an LLM ... LLM, yeah.
And so, setting ourselves up and our company up and our customers up to deal with that new reality is a big part of what I spend my time thinking about. And the solutions that we're building into our MDR operation will help, but we also need to be thinking about, as we build our products, how do we engineer better code reviews into our release pipelines- Sure ... and our CIC infrastructure.
Well, just to do that quickly, but- Right ... to me, I don't know if you ever read the book "The Goal" by Goldratt. Mm.
" Yeah. "The Goal" is about manufacturing, but it's the theory of constraints and bottlenecks, and part and parcel with that is as soon as you break through one bottleneck, you discover the next bottleneck, and then the next bottleneck. So we're moving from a world where code was the bottleneck.
Right. There's only so much code we could turn out, how many developers do you have? Yeah.
How much lines of code did they do a day? Right. To sky's the limit, right?
Yeah. You can turn out as much code as you want with these things. Yeah.
Well, the next bottleneck then is, oh my God, how the hell are we going to govern? We need governance here. Exactly.
How are we going to put quality control in? Yep. How are we going to security test?
Yeah. Well, we tackle those things, but then the next bottleneck will come out. Yep.
Right? Which is, okay, I've got to deploy this now. Yeah, exactly.
And I've got to run it. I've got to make sure it stays, and I've got to update. Right.
So there's always the next one and the next one, and it's just the theory of constraint. How do you at Sophos, where you're talking scale- Yep ... at scale, these problems become a billion here, a billion there.
Before you know it, you're talking real money, right? Oh, for sure. It's the same thing.
You mean in terms of the expense of the LLMs and... Yeah. So I think the- Just keeping up.
Yeah. Well, I think the interesting thing is there's a whole series of cultural things that we're trying to do to enable our engineering staff to really lean in safely on these technologies. But one of the first things that we saw when we started introducing AI coding assistance was the amount of code being created was going like this.
But when you look at some of the more traditional productivity metrics, like do you have more PRs moving through the system? Are they moving through more quickly? Do you have more issues being resolved?
Are your cycle times reducing? Those metrics didn't initially improve because you had this top of the funnel being loaded, but the rest of the funnel wasn't set up to actually- Uh-huh ... take that input and then process it more quickly.
And so one of our large focuses now is getting beyond just this AI-driven coding to true agent-driven workflow across the whole development stack, right? So that when a PR comes in, it's being reviewed for defects by an agent, it's being scanned for vulnerabilities by an agent, and then when a human actually reviews it, they're reviewing something that's got a much larger chance of just working its way quickly through the system. And so that all, yeah, we're on a journey.
I think many companies are on that journey right now. Absolutely. Yeah.
There are going to be a lot of business school case studies- Absolutely ... coming out of the next year and a half, two years here. Yeah.
No doubt about it. Let me ask, wrap things up with a little bit about RSA. Sure.
Any specific Sophos news around RSA or observations from you about this year? Yeah. I think one of the big things that we're focusing on as a company right now is this idea of kind of making CISO level expertise available to the masses, right?
And so we like to cite a statistic that there's only about 35,000 CISOs in the world, but there's over 359 million companies in the world. 009% of businesses- Has a CISO ... have access to CISO level expertise, right?
And so per our previous conversation, as agents get better and better at finding and exploiting vulnerabilities, having that access for small and medium businesses is absolutely critical. And so, major focus for us right now is trying to build services that serve that market and- Let me ask you a question on that one. Please.
Because I had this conversation with someone not on camera. Okay. We be clear.
But I'm going to ask you on camera. Okay. If you don't want to answer, don't answer.
Okay. But we talk about AI making certain jobs obsolete or harder. Not harder, butSuperfluous- Sure ...
is the word. Yeah. What about the CISO?
Well, I think that in many cases, I look at it less as automation of or elimination of jobs, more as elimination of tasks, right? Okay. So if you think about, to the SOC, for example, which is another example that I'll keep referring back to.
The typical SOC functionality is like you get a case, and then you open the case, you triage it, and then if you determine it needs to be investigated, then you go through the process of investigating it. And that's often a relatively procedural thing that you go through in a SOC. So what we're focusing on there is trying to automate as many of those steps- Absolutely ...
as possible so that when the human actually gets involved to review the case, you're reviewing the output of that agent's analysis. It's further along. Yep.
Yeah. And so I think with virtual CISO or the CISO role in general, I think that there's always going to be a need for a human-level component, the human judgment element. But I think a lot of the tasks that are associated with being a CISO are going to ultimately get easier, and they're going to be, hopefully, you'll be able to conduct them more thoroughly.
But at the same time that I'm saying that, the threat landscape is also changing so- Well, that's the other thing ... so quickly that- It may free them up from doing that mundane- Right ... reporting stuff.
Yep. And focusing on strategy- Absolutely ... and keeping up to date with what the latest threat vectors look like.
Yeah. And I do think that as we get more and more vulnerabilities being discovered by better and better LLMs, you're going to have to be positioned to respond to those as we, as software manufacturers, need to be ready for that. And CISOs need to be ready to put programs and processes in place to ensure that that happens and manage it.
And I think that that role's not going away anytime soon. Yeah. Agreed.
Yeah. John, we're out of time, man. Great.
Thank you so much. Yeah, sure. I appreciate you coming in.
I hope you enjoyed it. Yep. John Peterson, CTO at Sophos, here on TechstrongTV.
We're going to take a break. I've got my friend Chensy coming in here, so don't go anywhere.