A Black Hat Recap: Cybersecurity Trends Reveal an AI Reality Check
Black Hat Cybersecurity Trends Meet Market Reality
Alan Shimel and Mitch Ashley return from Black Hat with a practical look at the cybersecurity market, AI hype and the pressure facing security vendors. Their discussion explores why cybersecurity is more visible than ever, while also questioning whether every company in the space can turn that attention into real customer value. The result is a grounded conversation about Black Hat cybersecurity trends and what they signal for security teams, startups and buyers.
The episode begins with the scale of the security industry itself. Alan points to research showing thousands of cybersecurity companies competing for attention. Mitch adds that the real question is not just who showed up at Black Hat, but who is solving meaningful problems. That distinction matters as AI messaging spreads across nearly every booth, product pitch and roadmap.
AI Security Hype Faces a Buyer Test
AI was everywhere at Black Hat, but Alan and Mitch separate useful innovation from marketing noise. They discuss how many vendors are adding agentic AI, autonomous SOC and AI-enabled security language to their positioning. Some of those efforts may create real value. Others may be little more than a new label on older tools.
The conversation highlights a key challenge for buyers. Security teams need to understand whether AI features improve detection, response and remediation. They also need to know whether those capabilities still require experienced humans in the loop. That makes Black Hat cybersecurity trends a useful signal, but not a final answer.
The SOC Moves Toward Automation
Alan and Mitch also examine the future of the security operations center. They expected agentic identity to be a major theme. Instead, they saw more activity around AI-enabled SOC workflows, automated remediation and early steps toward autonomous operations.
Mitch notes that security operations often takes longer to adopt major changes. Teams must trust new workflows before they rely on them during incidents. That slower pace does not mean the trend is weak. It suggests the industry is still moving from experimentation toward operational confidence.
Consolidation, Platforms and Real Value
The episode closes with a broader look at industry maturity. With so many cybersecurity companies competing for budget, consolidation feels inevitable. Alan and Mitch discuss the difference between point products, platforms and companies that can become durable businesses.
They also consider the role of customer outcomes. Buyers are not just looking for another tool. They want security investments that reduce risk, improve efficiency and help teams respond faster. For vendors, that means the next phase of cybersecurity will depend less on buzzwords and more on proof.
Transcript
Hey everyone, I'm Alan Shimel. And I'm Mitch Ashley. And you're watching...
Still Cyber. After all these years. After all these years.
Mitch, I got to tell you, coming back from Black Hat, it does feel like after all these years, man. I felt the years too. I felt a few of those years too.
Yeah. You're not kidding. I was doing 15,000, 17,000 steps a day.
Oh my God. Our friend, I don't know if you read this, Carolyn, our friend Carolyn Wong passed out from heat exhaustion, dehydration. No.
I didn't know that. Yes. She was doing a thing at the Bellagio, and she just didn't feel good, and she went down and- Oh my God ...
little IV and stuff. They had to take- Okay ... her in an ambulance.
That's dangerous stuff- But she's okay ... heat exhaustion. But it is.
It's- Mm ... all kidding aside, it's- Wow. I'm sure she's okay ...
and Carolyn's much younger than us. So- Yeah. By a few years ...
it can happen to anyone. Just saying. Well, 113 degrees, that can overtake you pretty quick.
Oh, but it's a dry heat. It's a dry heat. It's a dry heat.
Yeah, just chill. Feels like it's sucking the moisture out of your organs. Wow.
I'll tell you. Yes, it can be. I don't know about myself.
I feel myself drying up. Yeah, like a prune. Anyway.
Back in- But that's not why we're here to talk, Mitch. No. We went down...
We made the right turn there. Let's get back- Like usual ... on track.
There's a rabbit trail, we took it. Yep. Like, you know what?
But Mitch, I wrote a little piece, it's actually more than a little piece. I wrote a Tekstrong special report- Mm-hmm ... about my experience at Black Hat, and you experienced it with me.
We were together very... Really, from Tuesday morning breakfast, all the way through. Yeah.
It was. You did yours. We had several touch points there.
Yeah. It was in many ways, it was the best of times and the worst of times, as someone once wrote. I feel like I've read this chapter before.
Yeah. Very familiar. It really did.
Let's look at some positives first, though, Mitch. Sure. Has cybersecurity ever been this front and center?
AI has elevated so many things. We can curse it all we want, and data centers, and all that stuff. It has revitalized every part of our industry.
Every part of our industry, and even though the tech bros are still trying to recover from claiming we don't need human carbon units anymore, AI will do it for us. They finally figured out that's a stupid idea. We are selling lots of security.
At least there's a lot of security solutions in the market. I'm not sure they're all being sold. Well, so that brings up something that I wrote about in this report.
Our friend Richard Stiennon has been publishing the Security Yearbook now for four years or more. Yeah. IT-Harvest.
His most- Yeah. Yep, from IT-Harvest. Well, we knew Richard when he was at Gartner some time ago.
Oh, yes. Yeah. But the most recent edition of his book, I believe, has 4,100 security companies.
But I don't know if that's all... I know there's at least 4,100. There may be more.
Mm-hmm. Five hundred or so were exhibiting at Black Hat, so about 10% of the industry only was there. But the question is, are they all making money?
How can they be, Mitch? Well, how can they be, and are you seeing a sifting of who's slapping on agentic and AI onto company and product names? And who's doing something interesting, and then who's doing something interesting enough, customers are saying, "I want to go down this direction.
" That was a lot of where I was trying to get to, was sort of the wheat from the chaff, right? What's really substantive here, and what's happening. And you couldn't tell that by walking in the vendor area, because everybody, you'd think they had just gotten their D round of $80 million and spent half of it on their booth.
It was- It was like RSA, not in breadth- It was almost disorientating ... but in height. Yeah.
No, you took 10 pounds of RSA and put it in a five-pound bag of Black Hat. That's a good way of thinking about it. It was like, "Wow, this is Manhattan.
" Yeah, no. It was almost disorientating. Because it wasn't just that the booths were big.
The money spent on booth designs and the money spent on lights and videos and barkers, carnival barkers, and giveaways, and everything else. I really felt like I went down the rabbit hole. Yeah.
Right? Because at what- Well, that's- That was my first- ... a sign you and I know is sort of like, okay, wait a minute.
Have we sort of crossed over this peak of, are we spending too much on security companies and investments, and what's real and what's not? What's over-inflated in terms of investment in building security companies? Not saying they're all bad.
They aren't bad, but you can only have so much of a security market that's real. Well, so I did some back-of-napkin numbers based upon what I know, Mitch, right? Right.
And you and I, when we did Still Secure, we did RSA and Black Hat many, many years. We would. I know what we spent.
Absolutely. Yes. So I did a back of...
I'm not talking about the last row or two of 10 by 10 booths that were- No, no ... all the way in the back by the 8400. Though I interviewed Snowflake there, and the guy from Snowflake apologized to me that they had such a small booth.
I said, "Don't apologize. " But here's my take on it. They're the monster booths.
I'm not even talking about those, because those, you probably are measuring- Yeah ... millions of dollars. You expect those folks to do that, right?
The big Bosch people- Yeah. But do I expect them to spend a couple million? I don't know.
I know. But they're expecting to be front row, big, big. But the average 20 by 20.
The average 20 by 20 booth. Nice size. Mm-hmm.
Decent booth Not too big, but not too small. The Goldilocks size. That was always- Mm-hmm ...
a good size, 20 by 20. My estimate, Mitch, is that that has to be at least a quarter of a million dollars. The booth itself is 100 to 150.
You got to bring your team out there. You got booth design. There's 100 grand in booth right there.
Yeah, no, absolutely. Easily. I think it's a quarter of a million.
And here's the other thing. On the show floor, you're just seeing the visible half of the iceberg. Mm-hmm.
Most of these companies also then had suites where they were doing real business. Yeah. They were partnering up on buyouts at restaurants and bars- Restaurants ...
for the parties and everything else. I think a quarter of a million dollars is actually a conservative estimate about what the average- I would think so too ... Yeah.
What the average rent is. If I had a complaint, it's finding a place to go sit and do- Yeah, no, there weren't ... something other than meeting with people.
Well, if you sat down, they accosted you. "Hey, you here? " But- Security training.
That was my- Yeah ... on the way out to the Uber to the airport. " As I'm walking down the hall.
Yeah. " But let me do the other half of the equation for you, Mitch. I asked- Okay ...
" Mm-hmm. " Really? Now, you know security people, I know security people.
Look, if you're going to give them a nice hat that you could pick what patch you could put on, which I saw about 12 different vendors doing that, yeah, I'll let you scan my badge. I don't know if that makes me... You got one?
Oh, Mitchell. Oh. No.
Oh, I thought you were reaching for one. I have the new leads. These are the new leads.
Oh. Glenn Gary, Glenn Ross. The Glenn Gary, Glenn Ross leads.
I have the new leads. Hello. Gene Levine, I'm only going to be in your area a short time.
But- That's another great line in Florida ... I thought you actually got one of the hats that they put- No, I didn't ... patches on.
Anyway. No, I knew we were headwear. I refused.
But anyway, so 1,000 leads, so-called leads, for a quarter of a million dollars or better. Quarter of a million or better. Mm-hmm.
It's so pricey. Yeah. Doesn't that sound off to you?
Mm-hmm. And how many of that 1,000- And how many of that thousand- ... is real, maybe?
Yeah. If you're lucky. Yeah, because you're going to get people doing the black hat shuffle that are happy to let you scan their badge.
They may have registered with a dead-end email address so they don't get spammed. Mm-hmm. I don't know if the economics work, but Mitch, I don't think it's about economics.
I think the feeling is you got to be there or be square. That's just what I was going to say, is presence. Presence doesn't mean you've got the goods, but you do have to be present for people to think you got the goods.
Yep. So I did this special report, and I pulled some Futurum data for it, size of market. And look, today's cyber market is not the cyber market you and I were selling into at Still Secure, certainly.
Oh, that was early cyber. Yeah. It wasn't even cyber, it was InfoSec.
But- Mm ... that being said, 4,100 plus companies spending this kind of money. RSA, they spend at least that much as well.
Easily. So if you're a cyber company, you're putting a half a million dollars into two events. Mm-hmm.
Is the arithmetic off here, Mitch, or am I crazy? Is it not pay to play, but is it a cost of doing business? There's some credibility to that, that ultimately, it's got to turn into sales, right?
Some people know. How do people know about you because you were there, versus if you weren't there, they wouldn't have known about you. Because it's not going to be about the announcements, right?
There's a plethora of announcements- Many ... that get made. So, everybody that I talked to, many of them, most of them said, "Well, we actually announced last week," blah, blah, blah, blah their thing because it's just so crowded of a space.
Sure. But I will give people credit for is that it isn't just about the booth space and how much you spent, it's how many people attended, and were they engaged. That has to be one of the most engaged black hats.
Not from a research perspective, like you and I know from the old black hat days, the vulnerability disclosure- Right ... and research disclosure. The briefings.
But from a, "I'm here to figure out what we're doing with AI, what's happening. " Like we remembered in the old days. Well, I remember days where we got more resumes than sales inquiries- Oh, yes ...
in some of these shows. Usually on the last day at about 4:00. Yeah.
Yes. Well, when the economy was bad. But Mitch, let me explore that a little further with you.
It's a point I made in this special report I did, which is, for so long we've heard, "Where's the innovation in security? " Mm-hmm. Now, AI and agentics have given us a lot of new things, a lot of new toys to play with, a lot of new rabbit holes to run down, a lot of new ways of looking at problems maybe we couldn't have solved before, or problems- Yeah ...
that didn't exist before. Mm-hmm. So innovation's there.
Yeah The bar, the moat to enter the field, even if you are innovative. I've got a great new solution that's going to help the world. Mm-hmm.
In order for me to get heard and seen at Black Hat, at RSA, all year round as a cyber company, especially if I'm not from Israel, let's face it. Yeah. And I don't have an 8200 unit background or something.
I almost have to raise crazy money just to be heard, to be seen, to be noticed. And is that really what we saw there? I think we saw it there, and I think there's a bit of, I don't know if it's FOMO as much as you see the rounds that people are doing.
I saw an A round at 60 million for somebody I'd never heard of. And for what they were doing, okay, maybe that's worth 60. I'm not sure.
It's not 300 million, but it's a lot of money for an A round, to me. For an A round, it's crazy. That's a big chunk of money, right?
Yeah. So people are getting money thrown at them. They don't get that because they're nice people and really smart and have a good idea.
People have money they want to invest. They don't want to get left out, but they also, of course, want to win doing it, too, so they're making big bets. So I saw two buckets that this stuff falls in.
Mitch, one is me and my boys have done this before, right? Mm-hmm. We did this company, we exited, and we did well.
And maybe we did this twice even before or more. Yeah. And you know what?
Now with all the excitement around AI and all the new possibilities, we're back. We put the band back together and we're coming back. I probably saw four to six companies coming like this, that, and they raised huge amounts of money based upon their past success.
Then as I mockingly said, you've got the 8200 crowd from Israel. They have that pedigree, if you will. Mm-hmm.
And it seems like there are VCs waiting right outside the doors of the 8200 exit interview process, waiting to sign these people up. Mm-hmm. And then there are people who have genuinely new ways of looking at new ideas and new ways of looking at solving cybersecurity problems, both old and new.
And they're getting money. My question is, are they getting enough to be meaningful, to be noticed? I think, the proof point for me is if software is accelerating how fast we can do things, and it is, how fast do you have to prove your model in market?
So scale that up to your business now. If you truly can create the latest security innovation, the latest whatever innovation. We used to think a product market fit is a 12 to 18 month period.
Now it's sort of like if you're not doing that in 12 months- Six months ... I think you're doing six or less. So are you kind of tossed out after six, or have you pivoted five times by the time you get to six months to get to the right answer?
You have to move that fast. How much cash did you burn doing it? Exactly.
Because you know how that works. Cash is easy till it's not. Until you don't have it, yes.
Mm-hmm. Till you need it, then it's hard to get. And then the screws come in.
Yeah. But Mitch, let me ask you another question. In our pre-Black Hat show, we absolutely said agentic identity would be a huge thing.
Mm-hmm. I don't know if we saw the agentic SOC as... Everyone I spoke to at some level or another was playing the agentic SOC game, autonomous SOCs.
Mm-hmm. And I don't mean, of course, socks we're wearing on our feet, but security operations centers. I saw it more as not agentic yet, but still AI-enabled SOC, automated remediation, some more kind of still human in the loop of using AI to manage the SOC.
Early, let's start to do some agentic workflows, more than you did six months ago. So I think ops is always a little bit longer tail, a little bit slower to adopt, but not saying it's slow behind, it just takes longer for it to get to that stage. So it was there.
I just don't think it was in your face there, like it may be in six to 12 months. Certainly agentic AI, Mitch, was in full bloom. Mm-hmm.
Yeah. Agentic was. I did hear identity, not sort of like the identity identity, but it was there in new ways, not just talking about agent identity and human identity, but also identity of workflow and pipelines.
And people are thinking about sort of the non-deterministic of AI, that how do I assemble this, what happened, from an observability native standpoint, but I also have to know that it was authentic. That this actually was a workflow that was supposed to happen, and how can I validate that what I'm looking at has the provenance of it is actually the workflow that happening, not something got created or AI slopped or whatever along the way. So people thinking about identity, not just as objects, whether it's agents and people, but as work that's happening.
What's the identity of that work that occurred, and can I validate that it's actually true to what I think I'm looking at or AI is looking at? Agreed. What else did you see then that you thought was kind of prevalent, Mitch?
I think there's still emphasis on the discovery phase of what we have and where we're going, and that's sort of the traditional, we can't secure what we don't know about. Mm-hmm. But I think you have to think about not as just how do we discover what agents I have out there, I think you have to think about it as how do I discover while they're being created at the front end of the cycle.
And I think the industry's starting to realize that it's not shift left like we thought about it, of let's kind of think about the detection or the scanning earlier, but really some serious thought to at the point of creation, how is it secured? At the point of creation, how do I observe it? At the point of creation, how do I establish some kind of provenance for what is being created?
And I heard a lot of discussion around intent. Not just intent in prompts, but validating what the intent was when something got created or when an agent was instructed to do something, it got whatever its loop or command or marching orders were from, and trying to validate that. Because ultimately you can't validate an outcome if you don't really know what it was supposed to do, and if it's when you give an agent a prompt that it interprets a great deal of what that prompt means with context and memory and a lot of other stuff.
That's not the same as I can look at the code, and I can look at the data inputs and outputs, and I can determine what it was supposed to do. You have to be able to assemble not just intent with a prompt, but also memory and context, and as well as the tool selection, as well as the execution and the outcome. So it's a different cycle than we've thought about before, and I think people are starting to come to grips with the old way, current way of doing it, conceptually is the right set of things, but you've got to engineer it to a totally different level.
One of the things I was not necessarily surprised, but encouraged by, was the move to let's call it a post-Mythos world. Mm-hmm. It's a given.
Mythos- Yeah ... and if it's not Mythos, it's Chad or one of the other ones. They're going to find untold vulnerabilities.
What are we doing about it? When Mythos first came out, there were some people who were saying, "Ah, it's a nothing burger. It's not really finding real vulnerabilities.
" Mm-hmm. I think people are saying, "Oh, no, it's finding vulnerabilities. We knew they were out there, and now, of course, it's finding them.
" And I think that's probably a better reaction to the whole thing. Coupled with that, the other pattern is, I think we're barreling down the highway back towards the same experience with credit card and data theft with break-ins. The same thing is happening with models breaking out of their test environments, out of their harnesses, and getting access to the internet and HuggingFace.
The fact that that's happening and people are not freaking out about it, I'm not saying they should necessarily, but I think we're in the era already of, oh yeah, another model broke loose. Another model broke out of the lab. Another model broke out of here.
But what's missing with that, I think, for the enterprise customers is, all right, so those things happen. How do I prevent that from happening in my environment? And what are the disclosure requirements I'm going to impose or expect from the frontier model companies?
Because they're using these as marketing events, right? " But is there a CrowdStrike-like equivalent of a transparent disclosure for any of this? No.
It's not. " So I think that's a whole area we're going to see a lot of interest in or movement in is disclosure. Agreed.
I don't disagree there, for sure. I think you're right, Mitch. Let's turn to the social activities.
Okay. Of course, we can't say too much because you know what happens in Vegas. What's that?
What you catch in Vegas stays in Vegas? Is that what that... No, no, what happened- No, we did that on the one before.
Oh, that's the one before. But here's something. This is a pattern I see at RSA too, Mitch, which is you can't find a place to eat lunch because every- No ...
restaurant in the whole place is taken over. They're bought up. Yeah.
Yeah. And it's just, you want to know the truth, I get it. You want to make your party there.
But let's face it, most of these parties, Mitch, are over-attended- Yeah ... underserved in terms of it's not good food. If I want to go eat lunch, I want to sit down and eat lunch.
There was a time, Mitch, where you and I would love to go out at night until 2:00, 3:00 in the morning at these events and sample all the- It happened. Yeah. Yeah.
I'll fess up. It happened. We don't anymore, but still, to go out for dinner, you found yourself having to go all the way down the Strip to get out of the blast radius there.
We had to do that, yeah. Yeah. No, I know.
We had to do that to get to a restaurant. I'm talking from my-- I'm not making it up. Yeah.
This is my experience. And frankly, again, same thing at RSA. You can't find a restaurant or anything near Moscone that's not bought out.
Mm-hmm. What I was surprised to find is that RSA and Black Hat themselves evidently control a lot of the hotels and restaurants and meeting places within the blast radius as well. You got to kind of go through them, and they take their vig Pound of flesh.
Oh, yeah. Out of it. And I'll be honest with you, that sounds a little heavy-handed if you ask me.
Well, yeah. And what they want to prevent is, I don't know the right term for it, but the side event that becomes another main event. Well, no, RSA calls it the parasites.
Parasite, that's what the term is. Because I remember that from RSA, right? They don't want that to happen.
But on the other hand, hey, if I'm a vendor and I want to hold an event, a breakfast for customers, a bigger thing to invite people to, I don't want... I already paid you a lot of money just to be here. Right.
I'm already a quarter of a million in. You're going to hold me up for dinner? You know what I mean?
So, exactly. You're going to prevent me from going and setting up my side thing that I want to have. So, that means it all goes underground when that happens, when they play that game, I think.
Yeah. I got one other pet peeve. Okay.
You're in an environment where it's 115 degrees outside, it's sucking the moisture out of you. You're doing 15,000 steps a day moving around that show floor and doing your thing. They need more water stations.
They should be giving out bottled water. I agree with that. Hydration stations.
Yeah. Right? I agree with that.
And more Ubers, so you're not sitting there waiting for 20- More Ubers waiting out, baking in the sun. You go from medium-rare to medium-well by the time the car gets there. Yeah.
I think remembering that these are humans, not agentic folks, or agentic entities at this event. And just having the food court, for instance, where you can get your, what did we have? Three slices of pizza between us for $60.
That's crazy. I had to take out a HELOC on my house to pay for my- Yeah, to get a slice of pizza, it's crazy. Anyway, Mitch, I don't know.
I sound like, "Hey, go play in front of your own house. " Get off my lawn. Get the hose out.
I'm spraying those people. Get off my lawn. Oh, God.
Anyway, though, but it was an amazing Black Hat. I had a great time. I met- Yeah, me too ...
I talked with a lot of people. Caught up with- Very productive. Yeah.
A lot of old friends as usual, new friends. Looking forward to the next one. I guess the next bigger event we're doing is KubeCon, Mitch.
I've got a bunch- Mm-hmm ... of other events in the meantime, though. Yeah, there are a lot of them.
There definitely are. Yeah. KubeCon just came up.
And there's all the vendor ones, Microsoft Ignite. Of course, we have AWS re:Invent, and you name the names of anybody, and everybody has... It's the two seasons.
I feel like we have two football seasons- Yeah ... spring and fall- Right ... of the conferences that are happening.
We're preparing now- Fall conference season is coming ... to kick off the fall conference season. Yeah.
All right. Hey, Mitch, next episode, let's get a guest on here, and we'll do some cybering. We got a lot of people we could have on here, so I look forward to getting that happening.
Absolutely. All right. Until next time, I'm Alan Shimel.
I'm Mitch Ashley. And you're- Still cyber, after all- Take care, man ... these years.
Bye-bye. Yeah. Thanks everybody.
Bye-bye.
