Why Defenders Still Win in the AI vs AI Era
Cybersecurity has officially entered the AI vs AI era. Nadir Izrael, Co-Founder and CTO of Armis — now part of ServiceNow — joins Alan Shimel on Techstrong TV to talk about what changes when attackers run at machine speed and defenders have to keep up. Nadir explains why pre-breach response windows have collapsed from weeks-to-months down to days, and why post-breach response has gone from hours-to-days down to seconds-to-minutes. He argues defenders still hold two powerful advantages: home court advantage — deep, real-time context on every asset, identity, privilege, vulnerability, and control inside the environment — and the advantage of time, which can be used to run continuous simulations and prep for whatever attackers throw at them. With Armis joining ServiceNow’s workflow backbone, Nadir lays out why the combination is uniquely positioned to operationalize AI-driven defense across the full attack surface — IT, OT, IoT, medical devices, and now AI agents themselves.
Transcript
Hi, everyone. Welcome back here to Techstrong TV. Let me introduce our next guest.
His name is Nadir Israel. Now, Nadir is Group VP from Armis, from ServiceNow. And that should clue you guys in that Armis is now part of ServiceNow, but we'll discuss it in a second.
Let's first say hello to Nadir. Nadir, welcome. Thanks for coming on Techstrong TV.
Thank you very much for having me, Alan. So Nadir, before we get into Armis, ServiceNow, and the benefits of AI-powered vulnerability detection, let's talk a little bit about Nadir. You're a group VP there.
Give us a sense of how you got to be group VP. What group are you VP of? All of these things.
We're still navigating the corporate structure within ServiceNow, but I'll give you the brief. I am one of the founders of Armis, over a decade ago. I'm the chief technology officer there, and as part of the acquisition, Evgeniy, my co-founder and my better half, our CEO, and myself, basically both report into Amit Zavery, the president and COO and CPO at ServiceNow.
So, we got fancy titles with it. But fundamentally, I'm actually doing the exact same role from before, which is product and engineering and generally kind of the vision behind Armis, and proud to do so. Absolutely.
Nadir, look, in past lives, during the dot-com, I sold my company to what was a roll-up, in that we were the second acquisition. We then went on to do 30 acquisitions in 36 months. Right?
Wow. Well, I was VP Biz Dev Corp Dev, so I was heavily involved in all that. And, yeah, I know what it's like.
We had directors reporting to vice presidents, vice presidents reporting to directors, SVPs, EVPs. We were making up titles just to, it was a crazy- Yes ... it was a crazy org chart.
But that being said, it is. The fact is, you're going to wind up doing a lot of what you were doing before, at least for the first six to eight months. Right?
Then sometime around a year, they start trying to figure out, and what I've always seen is some people rise up, some people stay where they are, some people leave for greener pastures, right? I don't know. It's kind of the natural way of things.
But for people who aren't familiar, let's say maybe they didn't hear of Armis originally, right? I first became aware of Armis, I was at an Insight Ignite in Iceland, and I think I met Evgeniy. He was speaking there.
Yes. I think I remember the event. I think he got stuck there because I think the Icelandic airline went bankrupt or something while he was there, or somewhere- Something crazy happened.
Yeah, I remember ... some weird, crazy thing happened. I made it out, thank God.
But anyway, back then, look, I knew Armis as one of the leading security companies in the IoT space, right? And that's kind of where you started. But of course, the mission expanded over the years a lot.
And prior to the ServiceNow acquisition, Armis was just a leading company in the whole security space, but in many different, not just IoT anymore, because identity and everything else had gone mainstream. Bring us from there through the ServiceNow piece of it. Of course.
I think for us, very early on, we heard a decade ago, the problem that we heard from CISOs, from CIOs, from IT managers, were the same thing. We're seeing an explosion of connected devices and connected assets. The attack surface is expanding greatly.
We have no idea what we have, and we don't know how insecure or what the vulnerabilities or risks that are incurring are. So when we started off, to your point, we started off from the world of IoT, OT security because we thought, "Okay, the endpoints, there's a ton of companies that got those. " That's kind of how our brain basically worked.
But as we grew, to your point, the mission broadened because as we sort of peeled back different layers of that original question, we started finding out that there's more problems. Yeah, you got endpoint security, but what brings the complete picture together? We started realizing that we're almost like the Google Maps of an organization, putting together a complete picture of everything.
But as we grew from that, we started really understanding over the last few years that the mission actually doesn't end with just telling you what you have. It's also helping you prioritize and understand context around what's important within that environment and what to do about things, and ultimately, to help you to actually fix things, to help you actually move the needle towards success. Now, the market sort of met us as well with the whole notion of exposure management and other elements, kind of theories that basically kind of put everything together.
And a few months ago, the deal with ServiceNow came to be. I don't think that there are two companies in this space who are more aligned with each other. I think that ServiceNow had a lot of the same contact points and a lot of the same elements that sort of they brought together as well, but Armis really fit like a glove.
We had a very very good partnership even before that happened. And as a result, I think that eventually ServiceNow said, "Okay, this is an interesting bit of technology, but more interesting even, there's a very thriving business here that can do a lot for our mutual customers," and here we are I love it. And as we were talking off camera, look, as big as Armis was, ServiceNow's a really big company in the tech world.
And there will be ups, downs as this whole thing plays out. It'll be interesting to watch. And it's interesting, sometimes the acquiring company has an outsized influence on the bigger company, right?
Almost like a reverse kind of thing that you wouldn't expect. So, and ServiceNow, quite frankly, security's important to them. It is.
But I don't think they've had security the likes of Armis. So I do agree, it was a great fit. If you don't mind, though, Nadir, I'd like to turn over to our topic of discussion today.
For those of us who've been in security, and I've been in security 25-plus years, finding vulnerabilities was always a huge piece of the puzzle, right? We wanted to find those vulnerabilities before the bad guys did. And then, of course, we would worry about fixing them, remediation, mitigation.
With AI and Mythos and Glasswing and everything else, it's almost rocked the foundation of the principle, find vulnerability, mediate, remediate vulnerability, find the next vulnerability. That's been going on for as long as I'm in security. Now, all of a sudden, finding vulnerabilities isn't so hard anymore, it seems.
But how do we keep pace with fixing those vulnerabilities, preventing cyber attacks? Because the bad guys are using the same tools. Yeah.
So there's a bunch of things to unpack in what you said. First of all, I'll start with the fact that Mythos shouldn't have been as big of a deal as it is from a perspective of we knew this was coming. Yes.
I think that the industry has been talking about it for a long time, but sometimes you got to sort of see it in front of you for people to really shake the foundation of cybersecurity, to your point. But I'm glad it did, because it opened everyone's eyes to the fact that, to your point, AI attack platforms or proto AI attack platforms are out there. Absolutely.
And I can tell you that we can back that up with data as well, because part of the system that Armis operates, Early Warning is what we call it, it's basically the system that tracks different threat actors, different exploits, things that are kind of happening. We're seeing how many AI agents are doing the attacking now, how much they're rattling the fences for real, and testing out different techniques, different mechanics, different things. So that threat is absolutely very real.
It's not something that's sort of made up by anyone. Now, to your point, it changes the game quite significantly because from a human versus human type of ordeal, it turns into an AI versus AI ordeal. And the main thing that this changes outside of the sheer scale of attacks is the speed.
The speed of response has drastically reduced. So if I look at post-breach, for instance, we used to look at it as a perspective of we have hours to days, right? Hours to days is usually a typical sort of operation within an environment that you'd have to deal with.
Now, we're talking seconds to minutes. If we're talking about a capable AI model that is able to morph, write exploits on the fly, do whatever it needs to do to move around, seconds to minutes. On the pre-breach side, on the exposure management that we talked about before, it used to be a matter, to your point, of a backlog of vulnerabilities where it could take you weeks to months to solve things, and it would've been totally fine.
But now we're talking about things that move into the range of hours at most. And the reason is quite simple. If you don't go after and solve for different vulnerabilities within your environment, some roaming AI agent out there is going to end up leveraging it and exposing that breach within your organization.
Now, all of this changes the game fundamentally. I've never seen, in my entire career in security, a change so foundational in how we view security and what's required of us as an industry and as vendors of security to change in order to allow for a successful defense against that. I agree.
But the answer can't be, it's just, "Oh, this is a new world. " I agree. We got to do something.
I agree. Well, let's talk about- What do we do? So let's talk about what the advantages of defenders are and kind of work back from first principles.
I love first principles. It makes a lot of things very clear. So there's actually two advantages that defenders can leverage, and one of them is absolutely huge, and that is home court advantage.
At the end of the day, no matter how fast and sophisticated an AI attack model would be, it would still be learning basically from scratch. And a defender AI, if that was existing and operational within an environment, would have a huge advantage when it comes to understanding where all the assets, all the identities, all the privileges, all the business context, all the vulnerabilities, all the security controls. Basically, if you did your prep work, you have a huge advantage over any kind of attacking AI, but you have to make it accessible, leverageable, and actually build a model that takes advantage of it, which is, we can talk about this, exactly where the Armis ServiceNow part comes in.
But the second advantage that you have is actually, ironically, the advantage of time. At the end of the day, let's say I told you that a big test is coming up, something you really need to pass. And I told you, "I don't know when it's going to be.
"But it's critical that you pass that test. So what you're going to do is you're going to put all of your homework and all the material and everything together, just like we talked about just now. But the second thing you're going to do is you're going to start running simulation after simulation after simulation.
You're going to use every spare cycle you have to prepare for whatever's coming. And I think that that methodology can absolutely be leveraged and will be leveraged in security. And what I mean by that is that you have an all-knowing AI that has access to everything within your environment and knows exactly where everything is.
You're constantly evaluating all the different attack vectors that exist within the environment, and you're constantly popping up different mitigations, different things that are coming up. You take those, you apply them within the environment, and then you run the simulation again. You run again what are all the attack vectors.
And you keep on doing this iteratively, and you keep on making the environment more and more resilient over time. That kind of approach, which is exactly I think where both the industry is going, as well as where we're going, is an approach that maximizes on what the advantages of a defender are. But it does require putting all the bits and pieces in place.
If you don't do that, you're essentially leaving the gates and fences wide open to attack from something way more vicious and way more fast than what we've ever seen before. Agreed. I don't disagree there at all.
So here's my issue, right? So what you've just described here is the AI scale issue and then how we need to respond. I'm not blaming security people, but as you said, we've been crying wolf over this problem for a long time.
People get sick of hearing from us. We're just the people who say no. We're negative, we're panicked.
I have serious doubts about the ability of most organizations to really harness the troops, so to speak, to really make the kind of effort we're going to need to do that. And I think this is part of your mission now, right? At ServiceNow, you're playing to a much bigger audience.
I think- You've got a louder microphone, if you will. And to your point- Got to get people on board. No, and to your point, a broader mission statement, too.
Part of the advantage that we have as part of being of ServiceNow, ServiceNow runs today all of the workflows of pretty much every large organization on the planet. I like to look at it as almost like they're the nervous system of organizations. Everything flows through those workflows, through all of the different infrastructure and systems that they provide organizations.
This is exactly where the work needs to start, where agentifying, or at the very least making them agent-ready is a key piece of being able to solve the problem that you're describing. Now, I will say that the one really, really good thing that happened with Mythos and with everything around the Anthropic release at the time is that the reason it shook the foundation is because it didn't just shake CISOs. It shook CEOs, it shook boards.
It was so in your face. It was so big. It took on so much media attention, that every large organization, someone at upper management started asking, "What are we doing about that?
" And that is a huge tailwind to leverage in order for security to do exactly what you're describing right now. Now, they won't be able to do this if there's not something very intelligent that we can provide. They can take advantage of all of these things we mentioned before, as well as be able to morph and transform some of those workflows, some of that nervous system into being what it needs to be.
But my take is that ServiceNow, in particular, has a huge role to play in this future and has a huge role to play in being able to bring organizations to a point where they can trust using AI at scale within organizations to solve problems, security being a key piece of them, but also going hand-in-hand with how to secure AI in the first place. Those two things are inherently two sides of the same coin, and being able to be part of an organization like ServiceNow provides us a lot of leverage, but also a lot of responsibility. At the end of the day, we need to get this right, not just for the sake of security, but for the sake of organizations operating AI at scale in general, if that makes sense.
It does. Makes perfect sense to me. Nadir, we're running low on time, but I know you guys, well, in years past, Armis had a huge presence like at Black Hat and stuff, but I assume you will be there in another, well, it's only another month and a half or so, right?
Yes. No, we will be there with a huge presence. I think that part of ServiceNow being on the acquisition spree that it was means that there is a lot of sponsorships with Black Hat that were combined.
So I think you're going to see a huge presence of ServiceNow and Armis at Black Hat. I think that we're also planning to make several different debuts and announcements of some of the things we even just referenced here. I think that ultimately- Oh, really?
Okay ... there's a lot of stuff. Will that be at Black Hat or before?
I don't want to get you in trouble. Don't say nothing you're not supposed to, but it'll be Black Hat- I will say that- ... before?
By Black Hat, there's going to be a ton of stuff out there that I think are leveraging everything we just mentioned in the best of ways to really protect a lot of the different foundational elements of society, in a world that otherwise is truly scary. I think that the advent of some of these threats is very real, and as I mentioned before, we're seeing those types of threats rattling the fences as it is right now. So we don't have any time to waste, and we plan to come out with as much of this as we possibly can, as fast as we can.
I love it. " Hopefully, I'll see you maybe in person out in Vegas, somewhere with air conditioning. Somewhere where there's AC.
Thank you. Yeah. Thank you for having me.
And congratulations on the ServiceNow- Thank you very much ... deal. It's a great thing for the...
I think it's a great thing for Armis. It's a great thing for the industry as well. Really appreciate it.
Thank you. Thank you. " We'll be back.
Stay tuned.