Matt Duren on AI Agents, Risk Score and Digital Workforce Security | KB4-CON 2026
Matt Duren, VP of AI and Data at KnowBe4, joins Techstrong TV at KB4-CON 2026 to discuss AI agents in the workforce, digital workforce security and how KnowBe4 is using risk scoring to help organizations respond to emerging threats.
The conversation explores how security can become a resilience-building win for the business, how Risk Score uses 316 unique indicators to measure digital workforce security health and how automated, individualized responses can help teams react as threats evolve.
Topics include AI agents in the workforce, digital workforce security, Risk Score, human risk management, automated threat response, security resilience, data-driven security and KnowBe4’s approach to workforce risk.
Transcript
Hi, everyone. Back here at KB Forticon in Orlando, wrapping up our day of interviews. If you haven't caught them, please do.
There's probably about a dozen, maybe more in the series. We've really discussed some very interesting things, and I think we're going to finish really strong. My next guest is Matt Durran.
Matt is the VP of AI and Data at KnowBe4. Matt, welcome to techstrong TV, man. Yeah, thank you.
Thank you for having me. So VP of AI and Data, that can cover up a lot of sins, but before we jump into your present role, Matt, let's talk about your prior roles, your prior history. Excuse me.
Give people a sense of your journey and how you got here. Yeah. Sure.
Well, I've been a cloud native engineer for a long time, and I built a career around Amazon Web Services and scaling systems. I've been at KnowBe4 just about eight years now. Oh, very cool.
And really got to see us grow from a young hypergrowth company to now a company that's been through multiple acquisitions of us, us of other companies, and then have kind of been helping to lead some of the transformations we're doing on agentic. If you know about KnowBe4, hopefully you've seen what we're doing with Ada and the Ada orchestration release we had in Q1, and then now, just yesterday we had a nice live launch at our keynote of a couple new features for our Agent Risk Manager, a new product that we're releasing right now, so excited to talk- Well, let's talk about that, Agent Risk Man. Look, most people know KnowBe4, they think training.
Yeah. Right? Security awareness.
This is kind of blazing a new trail. It's adjacent, as we spoke to Marco about, right? He described it as adjacent, but you're the person that I was looking to to kind of define what is this new product line.
What is the gist of it? How would you describe it? Yeah.
I think over the last two years or so, we've been making that pivot into more of a broader workplace, workspace security company, and we added in 2024 the acquisition of egress email security products, which are awesome, kind of that collaboration security umbrella, and then, just last month we had the official release, kind of early adopter program of Agent Risk Manager. So it's a product that's focused on, really to me, it's about getting confidence in deploying AI. It's in your workplace already, whether you know it or not.
So it's a matter of having the right governance in place, being able to do that securely, being able to do that in a way that's defensible, that's auditable, that really has a happy path and happy on the rails path for the approved tools, and then a solution for those tools that you maybe don't want to see for most folks. So I've been down this road before. Yeah.
Right? I saw it with wireless- Yeah ... believe it or not.
At the time, I had started a security company. The US Army was one of our biggest customers, and I was at an Army base, and I asked the DUUM, which is like a CISO of an Army base. They call them a DUUM.
Don't ask me what DUUM stands for. They have initials for everything. " Yeah.
And he was a real typical army guy. Wired only then, right? Yeah.
"We don't have a wireless security problem, son. " Yeah. And as he's saying that, I see people like reaching under their desk- ...
and throwing their WAPs underneath. The old link, the blue LinkSys. Yeah.
Remember the blue Link... Exactly. RT54G.
" Right? " Yeah. I saw it with cloud security and what we call shadow IT then.
Yeah. Well, now we've got this shadow AI problem. Shadow AI, exactly.
I don't know if it's a problem, because a lot of companies are encouraging it. " Yeah. But eventually, some of that's going to bite you in the butt at some point.
I think so, and what I've been encouraging our customers to do is let the exploration happen, but have a response to it, right? When you do have those tools, they're warn only. It's not approved, but we're not going to block it, and then after you get somebody that clicks Okay on that thing two days, two weeks, two months in a row, you've got to be having a conversation with them- You bet ...
about what is this thing you're using? What's happening with our data while you're using this tool? Or what kind of account have you decided to use all on your own?
And then is it something that we'd want to invest in and bring on the approved list of tools, or is it something where we need to approve it for a small subset of folks, or do we actually need to consider blocking that? And I think that's where a lot of companies are headed. They know that if they don't have approved tools, then somebody's going to use their own tool.
And again, I've seen this story before. I saw it with open source. Yeah.
A lot of big enterprises used to have sort of a no open source policy because who could we blame, and who knows- Mm ... how secure. No neck to choke, right?
No neck to choke, exactly. So from what I'm gathering, though, this is kind of monitoring and detecting agents on the network? Yeah, and it's not just on the network either.
So we've taken an approach where we have a browser extension, Chrome, Edge, that kind of a thing, where I think the browser is still the main means of getting- Ingress and egress. Yeah ... yeah, for new AI tools, right?
When you're exploring, that's your first exposure to it. com and find that first. And then once you do have that set of approved tools within the company, we're building out these direct API-based rich integrations that then no longer require a browser, right?
They're going to capture the browser stuff, but right now, we have Microsoft Copilot Studio. We're working on Gemini support and Claude support. They're coming along well.
Saw some demos last week, looking good. We can get things like agent-to-agent communication. We're capturing all of the agent tool calls, and that means if you're using Copilot Cowork, we can still capture those events, and we don't have to be on your machine.
We can still capture agent-to-agent stuff which are not running on your network at all. Yeah. And then we can avoid having to be inside your network stack or something like that as well.
So just listening to you talk, Matt, hey, look, a majority of the traffic on the internet today is API-to-API calls. Mm-hmm. And I've spoken to plenty of API security companies over the years.
Most people don't even know what APIs they have. Yeah. Right?
You ask them to give me a map or a listing of your APIs. Yeah. They don't know.
And agents aren't making that easier, right? No. And that's what I'm referring.
We're going to see a repeat of that, of, and you talk about agent-to-agent communication. Is it encrypted? Is it tunneled?
Right. It's the same way of trying to figure out our API communications. Yeah, and then we're asking questions like, what permissions does it have?
And you've got to remember a couple things about AI and agents. Number one, the I stands for intelligence, so this is a system that's making its own decisions. Then you also have to consider what identity's being used for the different MCP servers or the different tools that you have hooked up.
That's another. There was recently an MCP, the Linux Foundation- Mm-hmm ... or the daughter of the Linux, the AI Foundation, or whatever they're calling it- Yeah ...
had this MCP conference in New York City. Yeah. Look, that's a year, year and a couple months old, the whole MCP protocol.
Right. But it's the new API, if you will. Yeah.
Who knows what we're going to find lurking there? And I think who knows is such a great question because I think in the InfoSec and cybersecurity world, you have to be prepared for the unknown. And we- And that's hard, always- It is hard ...
you don't know what you don't know. Be prepared for it. Yeah.
And I think we've seen that with the surge of tools like Cursor and Claude Code- Yeah ... over the past really, what, 15 months? Claude Code came out early last year.
Look, to me, November was the inflection point. Mm. 5 model that came out.
Right. Yeah. It tipped the scale where, if human code security was like this, AI used to be up here.
It crossed- Mm-hmm ... around November and continues becoming, it's more secure than human-generated code. If you do X amount of lines to Y amount of vulnerabilities.
Sure. I think it took another leap forward in February or March with- Yeah ... Mythos- Yeah ...
and all of that. But clearly, we've crossed the Rubicon. There's no going back now.
Right. 5- There were two points there. Right.
Yeah. And as amazing as it was, it could only do 36 second human equivalent tasks. Yeah.
6, we're up to 12 hours. It's crazy. You set it up and I come back tomorrow, it's all done.
Yeah. And it only took maybe 30 minutes to knock that out. Absolutely.
I was talking, I think, with Sarah- Mm ... the CMO. Yeah.
We live in interesting, not even interesting, amazing- Yeah ... amazing times. I want to talk to you a little bit about something, this notion of a risk score.
Yeah. And look, we've all, in security, we've been dealing with scoring and CVEs and all of these things- Yeah ... for so long.
But what does risk score mean within this new know before kind of paradigm? Yeah. It's a good question.
I think our goal is to just put a number on your company's risk posture. So, you take and you look at what's the intrinsic risk of an individual, and that may be based on their title or what systems they have access to. And then how does that change over time with how they respond to a lot of what our products are showing them.
So are they a well-trained employee? Are they clicking phishing things? But also, how do they respond to emails that are marked by our email security products?
And then as you start to introduce Agent Risk Manager and the whole agent security pillar, what are their interactions with these AI agents look like? Yeah. Are they going to those unapproved but not blocked tools?
Are they doing that every day, and are they saying proceed anyway, a week, for a month? And how does that impact how risky they are to your business? So we want to take that and really give our customers a way to quantify the posture of their business over time.
Is that score going up and becoming riskier? Is it going down and becoming less risk? And then what can they do within our agentic products to drive that score down as much as possible?
So it takes some of the manual monotony of the security awareness training product that you mentioned we're well known for- Mm-hmm ... and makes it something that is a lot more hands-off for those admins, while also being more hyper-personalized, while also driving that risk score down. We've got some good early data from the past few months.
The risk score of ADA orchestration users is almost 10% lower than everybody else. Really? Even than customers that were already using some of the other ADA products.
That's impressive. It is, and it hasn't bottomed out yet, and I'm curious to see where it will, or maybe it'll just keep dropping. That'd be interesting.
We'll have to check back. We will, yeah. Could be season eight of the Insiders.
Hey, yeah. Don't give them any good ideas, you know? Don't think that they have enough ideas.
10% commission here. Yeah. Well, no, look, it's Karmen Ceasar.
Yeah, exactly. Matt, I want to end things off with, look, there's 2,000-plus people here. It's 44% more people than last year.
Mm. What's been your impression of KB4Con this year? There's an energy here that I haven't seen, just around everybody surrounding Nobafire, and like I said, I've been here just about eight years.
I think as a business, we're innovating more than we ever have, even compared to the early days. Mm-hmm. And I'm good friends with some of the founders and early engineers, and they're talking to me about being impressed with what we're doing.
We've got software guys that are volunteering to stay up overnight because they just can't stop. Right. They're excited about what they're building.
And then I've been spending most of my day yesterday and today sitting in the labs, talking to customers, hearing what their problems are, and they're excited, too. And that's what's really cool to me, is just to hear them say, "Wow. These new products, these are great.
They're helping us solve real problems. They're making us more secure. " And it's really just really energizing.
Cool, man. Yeah. It's what you want to hear.
Mm. Right? Hey, Matt, I know you've got to get back to the labs.
Thank you. Thank you for coming up here on Techstrong TV. Yeah.
That's going to wrap up our coverage here. I'm sorry to say, but the day's over.