Securing the Agentic Era with Snyk’s AI Security Fabric
We’ve moved past the era of just putting “walls around the code,” and as Snyk’s Chief Innovation Officer Manoj Nair joins us from Lisbon, it’s clear that securing the AI-driven enterprise requires a fundamental shift from gatekeeping to building a pervasive security fabric. With the release of Snyk’s 2026 State of Agentic AI Adoption report, Manoj reveals the startling reality of “Shadow AI” where nearly half of the code generated by foundational models remains insecure or incorrect. Snyk is doubling down on this new frontier with their AI Security Fabric and a free Agentic Skill Inspector, ensuring that as you unleash your builders to move at wire speed, they aren’t accidentally inviting autonomous attackers through the back door.
Transcript
Hey everyone. Welcome back here, the Textron tv. My next guest is Manoj Nyer.
Manoj is the Chief Innovation Officer at Snyk. That's a cool title. I can't wait to hear more about it, but, um, let's welcome Manoj.
Manoj. Good to see you again. I hope all's well, It's awesome.
I'm live from, uh, Lisbon this time, Alan, and it's always good to be back, uh, on your show. It's always good to have you on and Lisbon's a great town. I've been to Lisbon a few times, and what a nice place.
Um, Minaj, before we talk about Lisbon and, and everything I mentioned, you're the Chief Innovation Officer, but let's talk about your path to becoming the Chief Innovation Officer. What, what, what have you done that prepared you for this? Wow.
Uh, so I'm a, I'm an engineer by training a kernel engineer. I call myself an accidental product manager, you know, along the way. So like, build it and they'll come.
No one came. So that took me onto a product and engineering side, general management. Um, security also accidentally was one of these things.
I was at RSA seven years. I learned security the difficult way through like, through a nation state breach and like, okay, there's a difference between security and compliance. Um, you know, fast forward I really wanted to do a, you know, did a lot of scale things that big companies like R-S-A-M-C, VMware, hp, and, uh, I did my own startup.
Um, you know, went through, probably write a book someday about all the mistakes I made that all the books talk about and then my own mistakes. Uh, and, uh, it was, you know, after I took it to an exit and it was a fun ride in terms of scaling the post exit metallic. And we've talked about that in the past too.
And I was there sure. Um, I was thinking about what to do next, and that brought me to sneak, you know, um, security has been a passion, but I'm also an engineer. Uh, and this company was getting ready to, you know, scale into the enterprise.
So my first few years was really, you know, came in as a chief product officer at some point. Also ran all of engineering, um, few years in, uh, and, you know, 18 months ago, uh, really, so I'm almost four years at sny. Uh, there was an opportunity to bring all my startup roots to bear as AI was, you know, starting to appear in the horizon as a another business opportunity.
And me and a bunch of founders went and created, uh, a whole bunch of interesting things that we can talk about around, you know, not just securing, uh, you know, AI for security, but really securing generative AI and genetic ai. So, uh, that's the path, um, pretty, uh, hard to plot out. Um, but, you know, feels like it, it all, all of those life experiences have prepared me to be here at this moment.
Uh, it, it usually works like that, right? You know, things happen for a reason as we go through this. What we think is random kind of, you know, path that life life takes us in Manoj.
We, we mentioned NY a few times, and I, I think most of our audiences heard of ny familiar with ny. I don't know if they're very familiar with sny. And, but for those maybe who don't even know, you know much about NY at all, how would, how would you know?
The sneak we see today is not the sneak I first saw. I think it was at a CloudBees event in Nice France in about 2018 or something like that. Um, right.
And they, with the dog kind of, uh, logo and everything, and I, I remember meaning with Guy pni. Yes, right, Geico. But, um, of course today's sneak is a, a much bigger dog.
Tell us, tell us about it. Uh, 10 years in. Uh, but I'll tell you like, you know, the origin story is very interesting.
When you hear from Geico, it's a lot more interesting. But think about the hard bleed moment, right? When the world figured out that they're using open source software and that software is potentially compromised and like core of all of internet.
And this is a company that was formed around that moment. Um, and you know, there's like these different moments in companies history with a very simple premise. All of security is, you know, like very human nature about security.
I'm gonna put, you know, deep modes and walls and, you know, maybe put some spies in, right? So you got network security and endpoint security and, and, uh, and you know, NDR and, uh, you know, uh, EDR all XDR, it's really like detection response. Try to prevent at the firewall and lots of different patterns of the same for different eras, cloud being CA and cloud security, which is similar, right?
Like I want to try and prevent, and then I'm gonna put a parameter I'm trying to detect, I'm gonna try and investigate. SNYs premise was very simple. The root cause of these issues starts in software and who writes software?
The developers write software. Why do those issues ever, you know, end up in production? Because devs are not educated about security.
Like you go to computer science, as a computer scientist can say, we focus on innovation, not in training safety, unlike a civil engineer. Secondly, it's hard. So if you're not educated, you know, this is not the thing that you're being compensated for and it's hard to fix these things so they end up in backlogs.
So can you solve that? Can you make it easy to give it up or context and learning right in the moment? And automation to take care of the mundane work.
And so one of SNYs first innovations was don't test after the fact. Like all of this AppSec industry and all these tools were there to basically have the auditor compliance check a gatekeeper right at the end of the whole software process. We said, no, we'll give you the context right in the id and they'll tell you what happens if you use the wrong open source software and that same, and they'll give you a, a auto pr, you know, we'll create a PR to fix the issue.
And so all the, like the top GitHub stars started seeing this automatic PR being created. And, you know, we have a free, even today we have free forever tier. And, um, that was the start of the company.
And it's gone from there to open source software, first party code, uh, and, you know, infrastructure as code containers to now dynamically testing software because AI is generating a lot of code, um, being built into not just the id, but into the AI coding assistance and the agent coders themselves and now starting to secure the AI software itself, right? And so we've gone from those roots, but we have stayed true to those roots of we're gonna enable builders to move fast and stay secure. So we've gone from that, you know, do fast, stay secure to really unleash innovators everywhere to move, you know, faster and safer in the AI era.
Love it. com. SNYK or is it ai?
I don't remember. io Io. I forgot IO there for a while.
Everybody's AI now or this, but io um, Reno, thank you for all that. Let's pivot if we can, and talk about SNYs 2026 state of AG agentic AI adoption. Yeah.
And, and the launch of something you guys are calling the, uh, SNYs AI security fabric. But let's do the, the, uh, the survey report research first. Yeah.
So, you know, I talked about snyk, again, 10 years in now we have, you know, 4,800 customers including, you know, the biggest companies in the world in every category. Uh, I talked about a little bit about my journey of, you know, starting this, uh, AI innovation, um, you know, which has now become a business unit at snyk. Um, and we really signed up a bunch of these customers, some of the most forward-leaning AI native companies in every industry to be our design partners.
And so what we were able to do, and slowly, and you know, last year we launched EVO as an open preview for all our customers. And what what it is really focused on is giving customers visibility. So the state of agent AI report is really from enterprise customers.
You know, they're probably, you know, at least 200, two $50, um, or build up or much bigger, right? Like sometimes tens of thousands. And they are, you know, it's an anonymized report that just shows where are we, A lot of people talk about ai.
Some people are, you know, gung-ho, some people are not believers. And, um, you know, what we are able to show is what is the real state? You know, are people using models?
Are they using one model, two models? Are they using agents? Which industries going forward?
And so, you know, it was, uh, surprising. It's been surprising to all of our customers. We have now 500 plus, you know, what I call early adopters of evo, trying to get visibility into what is the state of agent ai.
The way we built it is very magical. Like we can go to the largest companies and just at a turn of a switch, get them to see their shadow AI just happening. Same thing that happened with Shadow Cloud.
You know, CTOs and, uh, are getting told by CEOs and the boards to move fast. They're building stuff, security is catching up. They don't even know how to get visibility into the complexity of ai.
Um, the parameter based, cloud-based tools can't see a lot of this because AI is code. You know, you can download a model from hugging face, you can download deep see and run it on your laptop, and you will not see it anywhere else because it's basically code running. So yeah, you can go try and find a pattern and try to match it, but there's almost, you know, two to 3 million AI open source models.
You can build agents, you can build MCP servers, you're running these tools on de or laptops. And that shadow AI is being penetrate used as an entry point into companies. So it was an interesting, uh, intelligence report by a company called, uh, um, Ray Noise, uh, their ex NSA guys.
And they showed, like last December, you know, after Christmas there was like three to four days where attackers just were scanning the internet for who has, you know, vulnerable AI components that they can attack and be able to penetrate. And they found that open lama, for example, was being, you know, exploited. And so there's a lot of detail about this, that they were public.
So this is real. You are, you know, and we're highlighting we're helping these customers, as I said, you know, almost fired, you know, folks using this now. And this is an anonymized report that highlights to the industry, if you are a security professional, use this report.
You know, go, go to your leadership team and say, this is reality in like hundreds of these companies. We should try this out and we should know start security starts with visibility. And, um, and there's some very interesting facts.
I'm happy to share. Absolutely. So, you know, in those, I I, I did an interview maybe 15 years ago now with the CEO then of, of, uh, MongoDB and the CEO of Couchbase.
And I said to them, guys, a lot of people say, no, sequel stands for no security. When are you gonna get serious about security? And they both said to me, Alan, we'll get serious about security when our customers demand that we get serious about security.
That was 15 years ago. Nothing's changed. Well, no, sequel security has changed.
Yeah. But that attitude of we'll build security in when the customer demands it. Right now we, we've got a gold rush going on here, right?
Yeah. And as you mentioned, I forget, there's like 2 million models on hugging face or something, but the big guys, you know, they're talking trillion dollar valuations for companies that are a few years old. Yeah.
Expecting them to like, be serious about security or have a security first posture, probably naive. I mean, I, I'll give, I'll give philanthropic credit. They talk a good game about it, right?
The constitution and everything else. But I, I just think that we are in a bit of this wild, wild west as everyone's selling picks and shovels, but there aren't a hell of a lot of sheriffs in town. Yep.
And, and now we're talking about agents. You've seen what's happened in the last month with the open claw, mobo, all these things. I, I think in, in times of turbulence, in, in innovation and in, I mean, what we're living through right now, it's almost like pity the poor fool who has to sit down in the town square and say, what about security?
Yeah. What about security? Right?
People are too busy rushing to go pen gold. Yeah. And unfortunately, my experience is until someone gets burned, right, until something bad happens, then all of a sudden people say, well, why didn't we do something about security?
And I, I, um, you know, I I, I don't mean to be flippant, but we're a little bit in that stage of this thing right now, right? Yeah. I think we need the sneaks of the world.
We need people like you saying, what about the security? What, you know, we need, we need to be thinking about it. And I, I think ultimately we do, people will, and ultimately it'll catch up.
It's just a tough one right now. Talk about security fabric. Yeah.
So let me just address that. I a hundred percent agree. It's unfortunate, it's human, human nature.
The good news I feel in the leading companies is the security leaders are not wanting to be behind. Like I felt in cloud, it took them many years. So I would say about 15% of the companies, the leaders I talked to, are very much in the trenches with the technology teams.
And they're using AI and they're trying to make sure they do the kinds of things. Otherwise, we wouldn't have had these, this level of customers in less than six months using this, right? That's good news.
The attacks have started happening too. So people are starting to take attention. So there was this, uh, what was this?
Uh, you know, the, I think the press called it the most severe AI vulnerability. Like it was not even like, I think three weeks ago, ServiceNow had, uh, you know, a agent that they built using an API, the API was untested. So you didn't do good old API security testing.
So authorized authorization was broken. So you could exploit the API, but you would've had to do one at a time. They built an agent on top of it.
The agent was compromised with a good old prompt injection and agency. And now you tell the agent to compromise the API and now it is like widespread. So the compounding effects of this is really like starting to happen.
And there are many leaders who, you know, once we publish the details of, of that kind of a vulnerability, people are like, this is, this is real. Or we knew this was coming. This is real entropic, you know, OpenAI, Google all have disclosed that nation states have used their models to run autonomous attacks.
What does an autonomous attacker do? They're not waiting for new vulnerabilities or old vulnerabilities. You know, if you're in a bad neighborhood, you're not gonna put just a camera in front of your front door.
You are gonna have security all around. So they're probing, they're probing every part of high value assets for any kind of vulnerability 'cause it's cheap to do. So now you're able to use AI to do it.
And that was the genesis of the fabric. And we go, you know, Jensen talked about at, you know, the uh, Davos summit about the five layers of ai and it start with the GPUs and the compute and you got the model layer and you know, so on the agenda layer, the top, the apps that use all that, what was missing was stark. There's no security layer, you know, so we need to get to a point where security is a fabric that covers all of the existing attacks and the new attacks.
And that is what we set out to do. And that's the vision. That's what we launched.
We've been trying, working on this for 18 months now. The pieces have finally come together and it's very simple. We're like, look, basically no old vulnerability left behind.
No more excuses. We have customers who have taken care of two years of vulnerabilities in matter of two weeks. 'cause we can now genetically remediate your entire security debt and backlog.
So that's like AI is accelerating DevSecOps and ensuring that continuously you are making sure that you're have a very stable baseline so you don't have that low hanging entry point for this autonomous attacker. com. com is my favorite site because it's independent researchers from Berkeley and ETH one of the top universities in Europe.
And they constantly benchmark all these coding models. This 48% of the code is incorrect or insecure for the latest foundational models. And so what happens, you know, like we, we all see AI swap in our LinkedIn feeds and all this.
There's real AI swap creating new vulnerabilities for these attackers to come after in the code that people are rushing to production. And that was our secured inception. We're now integrated into every major agent coding with deterministic checks on supply chain.
Are they using the wrong library? Are they done uploading some malware library? Are they, you know, is the code being generated with a SQL injection?
And we can do it at wire speed much faster than throwing the code at some models who might say, oh, we can also find issues. Now how many tokens are you gonna spend? And we have customers who have millions of billions of lines of code.
Are you really gonna like toss it all in a model and say, tell me what's wrong. Basically the fox guarding the henhouse situation as you we're, we're saying, well, the independent check were built in so that the dev never sees all this friction and it auto generates correct code. This is amazing.
Like that 48% goes to the high nineties and then really now you are able to move fast and build a agent code. And you talked about open claw and you talked about all these things. Agents are everywhere.
They're on the, you know, I have multiple, a lot running on my desktop. I used our products to make sure that I don't have things like skills issues, which is by the way, the research we found with open Claw. So we disclosed first these almost, you know, 4,000 plus issues and what are skills, skills are the tools given to agents so they can actually do stuff?
And so these skills had real malware embedded in them. People were downloading that. So this is like, okay, how do we quickly not just tell people something is wrong?
We built a tool that was a agentic skill scanner and we made it available for free. io, you can look at our agent skill inspector before you download any skill or build it in your pipeline. So next, you know, that's the next frontier visibility of AI components that we talked about, like the state of agent AI report, but then continuously making sure that you are building it securely.
And that's why we built Evo, right? And I think you and I talked about evo. So it's going from no vulnerability left behind, no new vulnerabilities into, so take away the low hanging fruit and then go after that high priority new attack surface for a gentech applications.
io. If they go to the front page, they can find out about this report and about the AI security fabric A hundred percent. And uh, we have our, we have our AI agent running on the website.
You can ask uh, her for any help to find anything. So There you go, man. Hey, enjoy.
Enjoy Portugal. Enjoy Lisbon or, or traditional or something for good for dinner, I'm sure. Right?
Uh, It is, absolutely. It's uh, you know, we work hard all day with the team and we celebrate. So Lisbon's one of my centers of, you know, where we're building all these AI software, sneak API and web evo all the dynamic capabilities that I mentioned.
So yeah. Good, good time with the team. Good.
Enjoy. Hey, I hope to see you soon. Maybe, I don't know, are you R-S-A-R-S-A?
Yeah, absolutely. We'll make it happen. I'll be there.
I'm on broadcast alley all week. Stop by, say hello. Sounds good Alan.
See you then. Thank you for all taking the time. Alright, Manoj Nir, chief Innovation Officer at S Sneak here on Tech Trunk tv.
We're gonna take a break. We're back. We got more text drunk TV coming at you.