The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Shift AI Podcast
Shift AI Podcast artwork

Rethinking Security Analytics with In-Place Intelligence, CEO of Vega, Shay Sandler

Shift AI Podcast · 2026-08-08 · 41 min

0:00--:--

Key moments - from our scoring

Substance score

62 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality13 / 20
Guest Caliber14 / 20
Specificity & Evidence11 / 20
Conversational Craft12 / 20

Vega represents a fundamental departure from legacy SIEM architecture that has dominated security operations for two decades. Traditional SIEMs centralize data by duplicating logs from endpoints, firewalls, EDRs, and cloud sources into a single repository - an approach that became increasingly expensive and operationally complex as cloud adoption exploded and security tool fragmentation multiplied. Shay Sandler and co-founder Ellie recognized this inefficiency while reflecting on their military intelligence and Granulate backgrounds, realizing that attempting to aggregate siloed data sources from AWS, Azure, Google Cloud, Kubernetes, various EDRs, and SaaS applications created an impossible data engineering burden. Instead, Vega pioneered in-place intelligence - enabling security teams to write detections and run AI-powered analytics directly against data where it lives: S3 buckets, cloud storage, data lakes, and endpoint tools. This approach eliminates egress costs, reduces transformation complexity, and critically, preserves the full fidelity of context that frontier AI models require to effectively hunt threats. The shift became urgent as frontier models entered the threat landscape: defenders now compete against AI-driven attackers with infinite reasoning capacity, making comprehensive data coverage non-negotiable. Vega's model aligns incentives: security teams get better detection quality and lower cloud bills simultaneously.

Key takeaways

  • →Legacy SIEMs duplicate and centralize data from multiple sources, creating unsustainable egress costs and forcing teams to filter out valuable context just to manage cloud expenses.
  • →In-place intelligence allows security analytics and detection writing to happen where data already lives - in cloud storage, EDRs, and SaaS platforms - eliminating the need for data movement and transformation.
  • →Frontier AI models used by both attackers and defenders require full, high-fidelity data context to function effectively; partial or filtered datasets produce mediocre results regardless of model sophistication.
  • →Security operations need comprehensive data coverage (HR, IT, cloud, endpoint, application logs) to defend against AI-driven attackers who only need one successful attack path, making the old 'filter to minimum necessary' approach obsolete.
  • →Cost reduction and security effectiveness are now aligned: avoiding egress fees and transformation complexity while maintaining data completeness simultaneously improves detection quality and reduces cloud bills.

Guests

Shay Sandler

Topics in this episode

EDR (Endpoint Detection and Response)Frontier AI modelsS3 bucketsZero-Day VulnerabilitiesCloud cost optimizationsecurity operations center (SOC)SIEM (Security Information and Event Management)NDR (Network Detection and Response)Data egress costsAgentic security operations

Questions this episode answers

Why can't traditional SIEMs handle modern cloud security data efficiently?

Traditional SIEMs were built in the pre-cloud era and still operate on the principle of centralizing all data into a single repository. Modern environments generate siloed data across multiple clouds, regions, EDRs, and data lakes; duplicating and transforming this data for SIEM ingestion creates unsustainable egress costs, complex data engineering work, and forces teams to filter out valuable context just to manage expenses.

How does in-place intelligence differ from SIEM-based security analytics?

In-place intelligence enables security teams to write detections and run analytics directly where data lives - in S3 buckets, cloud storage, EDRs, and other native tools - without copying or transforming it. This eliminates egress costs, preserves full data fidelity, and allows teams to maintain comprehensive context needed for effective threat detection.

Why do frontier AI models require complete, unfiltered security data?

Frontier AI models are garbage-in, garbage-out technologies; if fed partial or low-quality data, they produce mediocre results regardless of their reasoning capabilities. Complete context helps models estimate all possible attack vectors and opportunities, which is critical since defenders must defend against an attacker who only needs one successful path in.

What was Vega's original motivation for solving this problem?

Cost was a primary driver - two years ago, customers' main pain point with security operations was SIEM expense, not efficiency. Coming from Granulate (a cloud cost optimization company), Shay and Ellie recognized that traditional centralized architectures were economically unsustainable as data volumes and cloud complexity grew.

How did the shift toward agentic security operations influence Vega's vision?

When frontier models and agentic systems entered the threat landscape, the market's approach to filtering and minimizing data became untenable. Threat actors could now leverage AI with infinite reasoning capacity, forcing defenders to maintain comprehensive data coverage and leverage their own frontier models - which requires the full context that in-place intelligence preserves.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains solid technical insights about the shift from legacy SIEM to federated, in-place security analytics, and the role of frontier models in forcing architectural change. However, much time is spent on personal background (military service, first job in meat factory, Granulate exit story) that doesn't directly inform B2B operators about security operations. The core product/architecture explanations are substantive but somewhat repetitive, and the host doesn't push for deeper specifics on implementation challenges.

The SIEM approach for it like didn't really change. It's like, okay, duplicate all this data from all those different sources and move it to the siem. You also need to transform it to a particular format.
frontier models with amazing reasoning capabilities that can generate zero day vulnerabilities very quickly... the teams are, you know, Nobody will bet his career that one attack path that seems to you like it's probably redundant or probably nobody will attack us from that vector, nobody will do it anymore

Originality

13 / 20

The federated, in-place querying architecture is genuinely differentiated from legacy SIEM vendors, and the framing of AI adoption through a transparency/auditability lens (NL-to-KQL translation) is thoughtful. However, the core narrative about AI-native tools, threat actor models, and the speed/velocity imperative are now widespread in security discourse by May 2025. The positioning of AI as 'scalable engineering capability' is interesting but not deeply explored.

we enable the customers to index the data in place, meaning that you don't need to egress data, you don't need uh, to transform it anything it just in bucket
it creates actually like an abstraction layer which is very powerful because like agents, how they interact in natural language and then you have a deterministic layer that it's completely exposable to an agentic layer

Guest Caliber

14 / 20

Sandler is a credible practitioner: 6 years in an elite Israeli military intelligence unit (Unit 8200), early employee #1-10 at Granulate (exited to Intel for $650M), and now CEO of a funded security startup actively selling to Fortune 500 banks. He has lived the problem space across defensive/offensive and cloud cost optimization. However, his primary operating experience predates the agentic era he's now building for, and much of the episode is devoted to background rather than demonstrating deep ongoing customer/operational insights.

Spent there six years in a very high intensity environment in the military... really leaving that thrill
being one of the first 10 employees in such an amazing company... acquired by intel for $650 million

Specificity & Evidence

11 / 20

The episode lacks concrete customer examples, specific metrics on cost/performance improvements, exact timelines for feature rollouts, or data on adoption rates. Sandler mentions 'Fortune hundreds' and 'huge banks' but never names a single customer or provides a case study. The technical description of in-place indexing is conceptually clear but devoid of benchmarks (e.g., query speed improvements, egress cost savings %). The '140 employees' headcount is mentioned, but no data on revenue, traction, or deployment scope.

we're seeing this amount of energy in the highest point I ever seen it
we sold to Fortune hundreds and to huge uh, banks and this was like our first customers

Conversational Craft

12 / 20

The host asks reasonable setup questions and some intelligent probes (e.g., about egress costs, the timing of agentic talk), but rarely pushes back or challenges claims. When Sandler makes broad assertions ('nobody can stay in place,' 'the biggest thing is post-Mythos'), the host mostly affirms rather than interrogate. The host also allows long personal tangents (meat factory job, military service) without redirecting to business substance. A few good moments of follow-up (about Mythos/Daybreak and small teams, about velocity), but overall conversational energy is polite rather than probing.

Got it.
Yeah, absolutely.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C78%
  • Speaker B17%
  • Speaker A5%

Most-used words

data58security34vega19different18cloud17first14part14today13shift12high12started12problem11organizations11organization11cost10israel10

Episode notes

In this episode of Shift AI, Shay Sandler, CEO and co-founder of Vega, joins host Boaz Ashkenazy for a wide-ranging conversation on why the legacy SIEM is breaking down just as security teams need their data the most. Shay grew up in Israel studying math and physics in a famously competitive class of gifted kids, then spent six years in one of the country's most elite military intelligence units before joining Granulate, a cloud cost optimization company, as one of its first ten employees. Granulate was acquired by Intel for $650 million, and after a year inside Intel, Shay left with his former Granulate colleague Ellie to found Vega - a decision he says was pushed forward by a month of reserve duty after October 7th that reminded him how much he missed solving hard problems with his old team. The two dig into why traditional SIEMs, built for a pre-cloud world of centralized data, are collapsing under multi-cloud, multi-region, siloed telemetry - and why teams that once filtered data down to save on SIEM costs now need all of it to keep up with threat actors wielding frontier models.

Full transcript

41 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Today on UM SHIFT AI, we're talking to Shai Sandler, CEO and co founder of Vega. Vega is an AI native security analytics platform that lets enterprises query their security data directly where it already lives without the cost and complexity of duplicating or moving it. Shai spent six years in one of Israel's most elite military intelligence units, was one of the first 10 employees at Granulate before its exit to intel, and co founded Vega with his former Granulate colleague Ellie. SHIFT AI is a weekly podcast and video series about the shift happening inside enterprises and how they're approaching AI in the agentic era. We cover the strategy, infrastructure, data and security necessary to move quickly at scale. Every week we sit down with the leaders, navigating this transformation in real time. A few quick announcements before we dive into the episode. Thank you to our sponsors for their support. If you want to learn more about sponsoring the show or an event or about the Shift AI ecosystem, send us a note to SponsorshipAI FM. With that, let's dive into the episode with Shai Sandler from Vega.

Speaker B: All right, Shai, welcome to the SHIFT AI podcast. Super super excited to have you today.

Speaker C: Excited to be here.

Speaker B: So, you know, I always like to get the audience set and to understand your background a little bit. And you were, uh, born and raised in Israel. You were part of a pretty elite unit, uh, in the army, and you made your way to Granulate and then eventually to Vega. Now you're the CEO of Vega. Will you walk the audience through a little bit the path that got you to be the CEO and uh, founder of Vega?

Speaker C: I guess, uh, you know, grown, like in Israel, in like a regular family, nothing fancy, not rich, not poor, you know, studied math, physics. You know, it was like a big, uh, area of focus, uh, for me, you know, as a child. Some music as well was also part of it. It's like a family thing. And yeah, I guess, like I was in a very competitive class of like, I guess it's kind of cringe to say that, but like gifted kids in mathematics and physics. Yeah, and more like 22 boys out of 24 people in the class. And like, all very competitive and a lot of hormones, I guess, or something like this. And it kind of was directed final, like, towards, uh, for some reason, like, we found that love, like in cybersecurity and computer science. Something about the pace of it, you know, because, like, we love like mathematics and physics, like in theory, but something about, you know, initially it was, you know, building our own websites, then games and hacking to each other. Was very stimulating and I guess uh, you know when we were in high school it was already the path, uh, you know, started thinking about the army and uh, you know I thought I'm going to be you know, some Navy SEAL or something like this because I thought it would be cool. And uh, you know, I'll attract the girls in high school and uh, uh, very soon, you know, I met a friend who I knew before, was a few years older than me who wasn't one of these elite units and he told me like dude, this is science fiction. If you have the chance, you have to go there. And it kind of shifted my whole perception and it led uh, me to I guess to go to the army. Spent there like almost six years, did some incredible projects. Like I can't believe they're letting you know 18 years old take part of. It's insane. And yeah, afterwards, you know, it's kind of um, led the snowball effect that afterwards, you know, when I finished the service, one of my friends from the army offered me to join. His company called Granulate. Spent there four amazing years in which we were acquired by intel for $650 million. It was obviously like amazing outcome and you know, like right now in Israel it's almost obvious like hey, everybody's doing startups back then it felt for me like the riskiest move I ever did. And it felt like a huge privilege for me to take part of, you know, being one of the first 10 employees in such an amazing company. And the exit was something I even didn't consider like I didn't thought of it as like okay, there is like a financial upside beyond salary. So yeah it quite amazing. And spending one year in intel, you know it was enough for me to kind of miss the thrill, the adrenaline, the fighting, uh, uh, instinct that you have. Like in a startup, you know there is some levels of adrenaline and dopamine that you don't get and like a very steady job like in intel with all the benefits of being in intel especially today with the stock price and uh, yeah, I guess it's kind of motivated me to start something of my own. I had a lot of stakes there after the exit so it was like a huge move to leave it and I knew that I need to do something incredible on the other side. And this just you know motivated me to start Vega and I was fortunate enough to have ah, my co founder apartment who was working granulated and intel with me. And he is a very assertive guy. So like when I asked him you know, very I Guess, um, in an explorational way, like, do you want to start, uh, something. Maybe it's the right, uh, thing to do is like, yeah, let's do it. And since then, you know, it's just execution. Execution.

Speaker B: That's awesome. Going back to the time in the army, and I know you can't share everything, but did some of the work that you were doing because it was an intelligence unit, right, unit 8200.

Speaker C: Yeah.

Speaker B: So when you were in that position, what did you learn that kind of carries through till today that kind of impacted you during that time?

Speaker C: Yeah, I guess the most important thing, and I took it to many, uh, places in my life, is that, you know, you assume everything is solvable, uh, unless, uh, you prove otherwise. So oftentimes I saw it so much in my life and some of my friends in college or whatever, they get the problems like, ah, we cannot do it. It's too tough for me. Or, uh, I don't know, someone else will do it. In the uni, there was some mild arrogance. Even you can say that there is like, unsolvable problem. Like, nobody managed to do it before. Like, give, uh, it to me. We'll figure. And there is something about it that you have like a group, uh, talented, unique individuals who get, uh, a very tough problem to solve and they truly believe, genuinely believe they'll figure it out in one way or another. And I think this is unique and I think this is something that really drives, uh, the startup industry in Israel. Because even when we started Vega, what we were afraid of is not finding an interesting enough problem to solve that that will drive a true impact and a true business. As a result, we never had even an hesitation. The problem that we'll find won't be solvable. You know, we knew, like, we have the right, uh, team, the right talent, the right everyone, like to be the best in the world in this, uh, it just find the right problem. And I think this is, uh, incredible.

Speaker B: It gives you the confidence to be able to attack things in a way that it's required when you have a startup like that.

Speaker C: Absolutely.

Speaker B: So I always like, you know, this show started as a show about the future of work, you know, which is why it's called Shift AI. I always like to ask this question. It helps the audience kind of understand you a little bit better. What was the first job that you had that you actually got paid? Someone gave you money for doing the work?

Speaker C: Yeah.

Speaker B: And how old were you?

Speaker C: And you know, so my dad is a vet and not many people know that, but Vets are not only, you know, giving vaccines for uh, dogs and cats and whatnot, they also take part in the meat industry. Okay, not a slaughterhouse, but, uh, you know, like frozen meat. Making sure that, you know, it's kept in the right way not to develop disease in the meanwhile. Like this is part of the responsibility of a vet. So my dad did both sides, ah, and he m. Had uh, you know, a lot of friends in the, you know, in the meat industry. And when I was 14, like I uh, looked for like I wanted to start earning my own money. And it was like summer vacation in like middle school or high school, I don't recall. And my dad got me to work, uh, in a meat factory. Again, not the slaughterhouse, but carrying boxes of meat and afterwards also distributing them. I was on a truck with a driver and we were uh, driving, uh, through the southern part of Israel. So every day it was two hours commute and then going over a course and ah, distributing the boxes. And I was kind of like, it was after my initial, uh, you know, growth spike.

Speaker B: Yeah.

Speaker C: So like I was quite big and I was like training. So like for me carrying heavy weight, uh, was good thing to do back in the day. A lot of energy and yeah, it was like very tough job. You know, it was like 4am every morning to start the commute. Uh, but it paid pretty well uh, for that period of time. And you know, I felt that I experienced like a lot of uh, uh, dimensions in life I never did. New type of people. Also like in Israel, high variety of different, uh, demographics I never met or encountered in my life before. So. Yeah, it was eye opening. Yeah. Oh, for sure, for sure.

Speaker B: Well, I want to like, uh, the

Speaker C: manager from that job, by the way, was in my wedding like two years ago. Yeah. Yeah.

Speaker B: So you stayed close. That's cool. Yeah, that's really cool. Um, well, it's always amazing. First jobs have impacts on people, even if they seem kind of mundane at the time.

Speaker A: I love that.

Speaker B: Um, well, let's get into Vega. I want the audience to understand what you guys are doing, the problem that you're trying to solve. And let's go back to the early days, kind of in the founding when you and your founders were trying to figure this thing out. So I want to get it in your head during that time that kind of led you to want to attack this problem.

Speaker C: Yeah, fantastic question. So, uh, you know, we spent four, uh, years thinking Granulate. Granulate was a cloud cost optimization company. And one of the reasons I was quite compelled to Go to Granulate is because it wasn't in cybersecurity. I did like six years in a very high intensity environment in the military, like just doing you know, offensive cyber, really leaving that thrill. And like after six years it's not that we wanted to rest, we wanted to do something else. We wanted to do something that we felt is like uh, at the time felt for us like uh, building something and not just you know, destroying or defending, you know, trying to contribute in different ways. And, and at the time it was great and very fascinating and the technology we developed there was amazing. Uh, but after four years we kind of missed the thrill, we missed the high adrenaline of the cybersecurity market. And also uh, right after we left Granulate and started the ideation process, like what the hell are we going to do in our company? Unfortunately, October 7th happened in Israel and um, I was called for reserve duty and uh, you know, spent uh, one month there. And you know it was a very chaotic time but in a way it was also um, you know it's kind of hard to say that but in a way even a little bit like exciting because you were back in your team with like the best uh, uh, you know All Stars OG is like from the units ever and you're just you know, solving hard problems together and having like a very meaningful, impactful uh, job for uh, uh, you know, for Israel and doing that. I realized like wow, this cyber thing is like actually super cool. Like I missed that. Yeah. And uh, that was like an Ellie and I, we were serving different units in the reserve uh, duty back then. But I recall I called him like one night like it was 1am or 2am on my way to go to sleep after like a long hours work. And I told him like cyber is very cool, it's very fun. It's like oh, I feel the same way. And like we knew we had like the synergy of like okay, we are back to cyber. Like this is what we do, this is what we love. And when we, you know, some of the criticism on the cyber security industry internally in Israel, from the talent perspective, the people that you hire, the first engineers is that oftentimes you just spread fear. But the technology is not innovative or interesting. It's just another way to present data uh, so that the buyer will see some value out of it. But there is no real innovation. And you know like Ellie and I are both like engineers in heart and you know we really wanted to solve real problems but also to attract the right talent and for them not to be wasted or like to be excited. You know, every second company that started back then is like, we do aix, we do AI identity, AI Security Operations, AI compliance, whatever. So like, AI was, was absolutely a big part of it. And I recall, like, we had a lot of, you know, conversations, exploratory conversations with, uh, CISOs, with directors of Security Operations. And we asked them, like, about the pains and also about how AI adoption will help them. And at the time, it was very hard for people to kind of pin it down because they were really looking. Yeah. You know, it's actually kind of wild. Today everyone is talking about Agentix Security Operations. Two years ago, two and a half years ago, you were having this conversation. People didn't necessarily, uh, understood the pain so much because for them it was like an efficiency play. Uh, it was like, okay, I have these people, obviously you need to, um, hire, maintain them, train them. It's quite hard. There's a lot of churn in that market. Ah, people are not necessarily as focused as you want, uh, them to be in the job. But, uh, it's, it's working. It's enough. It's like checking the right box.

Speaker B: Yeah.

Speaker C: And I think it's only what we saw is we kind of took a leap of faith in this in a way because, like, we didn't get a crazy validation that, like, people want a gentic security operation. Like.

Speaker B: Right.

Speaker C: We just knew, okay, this is a very important vertical technology. And if you assume that this vertical will be also utilized by, uh, the offensive side, something has to change. There is like too much vectors here that, you know, contradicting each other and creating a lot of mass. I want to be in the center of the scales.

Speaker B: Yeah. It's interesting you did that in 24. The beginning of 24, by 25, by January 25th, the word agentic started coming up.

Speaker C: Yes.

Speaker B: Uh, but a year before that, it just wasn't part of the conversation. Maybe people were worried about people putting context in the context.

Speaker C: Exactly.

Speaker B: But that was basically it.

Speaker C: Ah, exactly.

Speaker A: Yeah.

Speaker C: Exactly.

Speaker B: Yeah. That's interesting. So maybe describe to the audience a little bit like, I think about the legacy SIEM and all these folks that have been in security for a really long time who have thought about how to deal with data and how to deal with being able to kind of view all the logs and the data in a very particular way. That legacy idea of how to do that is very different than what you guys came up with. So talk a little bit about that and let's provide context around what Vega is Doing that's different than the legacy systems.

Speaker C: Yeah. So let's break it down. Uh, effectively the first question needs to be asked is like why do you have security analytics? Or as a result like security operations in the first place? It's not for decoration or it's not just because it's cool, it's uh, because perfect prevention is impossible. You can get all the preventative tools, sensors, whatnot, like to your environment secured by design. Nobody eventually will bet their career that it will be 100% perfect. There is always like a insider risk, zero days, whatever ways to get in. And when something gets in, you want to react as soon as possible, to discover it as soon as possible and to contain it as soon as possible. And this is like what security operation it's all about. And obviously um, you know, when you're doing like this diagnostic type of work, the more data you have, the more context you have, the better results you will deliver. Now if we go back like I guess uh, two decades ago, there started to be a shift between people manually going through different solutions like okay, one av, the other av, maybe some server that connected some of the AV telemetries, firewalls and trying to do triaging work manually, uh, to the SIEM approach. And the SIEM approach was you have a solution that collects data from all this, uh, endpoints or firewalls in the environment. It's before cloud, ah, get them to one data repository and enables you um, this single pane of glass, one ability to interact with this data, ah, write detections, build dashboards with this data. And this was kind of the reality, the biggest shift started to happen with the cloud because not only cloud introduced a whole new way of, uh, a whole new landscape of generated telemetries from like Cloud Applications, SaaS, application on its own. Uh, the way that these telemetries are being generated and stored is different because it's not just stored in different endpoints in the cloud. There is S3 buckets, cold storage, data lakes start to emerge like this is one part of it and the second part of it. That cloud also changed the landscape of security tools. So suddenly you have EDRs, NDRs, ITDRs, whatever. And what the tools are actually doing is that they are in essential as well like collecting the relevant telemetries for their domain. Like let's take an edr, you don't need to have like an agent that collect all the telemetries from the av, the ADR does it and store it in the adr, maybe like for seven days of retention but this is actually its job and obviously building content on top of it and some detection mechanisms and control mechanisms. And then the reality is that the SIM is still operating as if it's like uh, 2001 or something like this. And the reality is much different. You know, you have multi cloud, every cloud has multiple regions. You have some data lakes, uh, you have edr, you have other solutions that every solution introduces some sort of like a data lake of its own. It starts to be like very, very complex to utilize all this data. And the SIEM approach for it like didn't really change. It's like, okay, duplicate all this data from all those different sources and, and move it to the siem. You also need to transform it to a, uh, particular format and then you'll be able to interact with this data in the siem. This is where it's kind of started to break right? Because like you couldn't really leverage it. Duplication was very complex. Transforming the data was complex and like a high data engineering burden on the team. And as a result, um, security operations started to see data as a pain. Like they started to leverage solutions like Kribble, uh, to filter out data. Maybe I don't need this data, maybe we'll put this data like in a cold storage, um, filter out unnecessary fields. The approach on data is like let's get the minimum things that we need to get to the SIEM to operate this thing. But then in a way it's kind of broken the first value proposition of the siem. Now this is kind of the landscape that was true, I don't know, until like a year ago basically. And the conversation is like, how will you enable a high coverage detection response program or ability to write high fidelity detections, uh, on top of a very siloed data environment in security. One point also to add is that beyond, you know, the cloud generating a lot of siloed data sources. Also in today's landscape is security, almost every data source is relevant for security. So HR data, uh, IT data, um,

Speaker B: they want it all, they want it all. They don't want to filter stuff out. Yeah.

Speaker C: And what happened recently, and by recently I can even say the post mitos era, if you will, is that

Speaker A: we

Speaker C: finally acknowledged as an industry there was like big enough of a marketing event if you ask me, that uh, frontier models can and will be utilized and are utilized by threat actors. Frontier models with amazing reasoning capabilities that can generate zero day vulnerabilities very quickly. And why is it stressful? Because suddenly the teams are, you know, Nobody will bet his career that one attack path that seems to you like it's probably redundant or probably nobody will uh, attack us from uh, that vector, nobody will do it anymore because there is infinite amount, like infinite scale for high intelligence reasoning that is solely trying to hack into your systems. So as a result you want to leverage these frontier models to your own benefit for the defense perspective. The problem is that from a defense perspective those models need context because uh, attacker, he needs just one way in. You need to estimate all the metrics of opportunities to get into your environment. Right? And then suddenly all the approaches of let's filter out data, we probably don't need it anymore are kind of breaking everything is important. Like a uh, frontier model, as sophisticated as it can be, it's a garbage in, garbage outcount technology. Give the most amazing frontier model, very partial set of data in low quality. The results will be very mediocre. So it really forced the market to rethink uh, the approach of how do you leverage the full potential of the data to feed those agents basically to help the teams keep up with the threat landscape.

Speaker B: Early on, you know, now a lot of people are talking about how to deal with finops for tokens.

Speaker C: Mhm.

Speaker B: But were you thinking about the egress coming out of these systems and how to deal with it, uh, for all this data? Because that was a big part of it too. I mean being able to kind of bring it all into one place is expensive. And now people are looking at their cloud bills and they're thinking wow, how do I deal with this? And so at that time, early on, were cost an issue that you guys were thinking about too and how to deal with what was happening in the cloud, pulling it down?

Speaker C: So maybe it's not popular to say that, but cost was like initially one of the first, uh, one of the first motivations like for us to really even pursue it. Because uh, you know, as you said like two years ago, nobody talked about agentic, uh, frontier models, uh, utilized by threat actors. It was mostly about efficiency. If you ask, uh, you did a survey two years ago and asked customers like what is your pain with security operations? People will say uh, the SIEM is expensive and the partial partially functioning SIM part is expensive. This is there is improving. It was like a nice to have. But the pain was mostly the cost. The fact that you know, year over year you get more and more. So like, and obviously coming from a cloud cost optimization company that you know, my job was to deliver cost reduction to very sophisticated organizations as uh, Leading the research in granulate and really um, you know, created this kind of instinct in my eyes to look for like optimization. And the people that we hired are people that, you know, no data, love data, no performance. And it was obviously, you know, a very important uh, optics like in Vega always like look for like the most performant, fast and effective way to do things.

Speaker B: Yeah. Well I think it's interesting, you know, the way that you guys do it. I want to kind of talk through just the process you go through, how you leave those things in place.

Speaker C: Yeah.

Speaker B: And it still allow for that telemetry because I think that is the thing that's really exciting about what you're doing. So maybe kind of lay that out for the audience a little bit.

Speaker C: Just connecting the dots. Right. Like we talked about the problem space and we talked about the need right now in organizations to fully leverage the full potential of the data. Now our approach in Vega is that we're a security vendor. Right. I think it's not fair as a security vendor to ask a customer with a very complex environment, as we said, like multi cloud on prem, multi region, different data lakes. Hey, if you want to see the full potential of Vega and help us help you in detection response, please perform a spinal surgery very promptly because otherwise you won't get any value. So our job is to help them achieve this value in a way that actually makes sense to the big enterprise. So we kind of broke this down. So the first thing, the first primitive of the Vega uh, architecture is enabling organizations to leverage uh, the data in a very performant and cost effective way, uh, in commodity storage. And when I say commodity storage is like the AWS S3 of the world, the GCP storage, the Azure Blob. Why? Because in cloud native environments, but not only cloud native environments, it will surprise you how much data organizations have in these buckets. They have naturally like a lot of telemetries there that are very important, whether it's the VPC flow logs of the world, but it also can be uh, CrowdStrike FDR logs that are saved there for retention or whatnot. So naturally they have a lot of data there. Also the data pipelines of the world, the creables of the world, created a lot of retention knowledge there. So first objective was take this data and make it queryable like in a very fast performance. And the way we do it in Vega is that we enable the customers to index the data in place, meaning that you don't need to egress data, you don't need uh, to transform it anything it just in bucket in the commodity storage. The data is there and Vega can query it in a very fast pace. Now the problem was I cannot uh, come to a top four bank and tell him hey, meet AWS S3 in one region. This will be your data lake from now on. Because this is the same problem I was talking about. So this is a good primitive. But in order to make adoption easy and to enable organization to leverage the full potential of the data, we introduced federation. And federation is very important because organizations today, as I said they have data in so many different places. Even organizations that you think is centralized, oh we have all the data in aws. They can have four different regions. So you don't want the egress cost, you don't want the duplication of the data. So introducing federation, it's not necessarily me forcing organizations to never save anything in a centralized location, but it's giving them the flexibility to have security analytics capability. Wherever the data will ever be. It can be today in four different places. You'll hire a chief data officer and he will consolidate the data under one data lake for the enterprise. Great, let's utilize it for security. A big shift in the market. You decide to move to three different clouds for whatever reason, fine. The security organization keeps up. And because it's data storage agnostic, the content that you build on top of it is also agnostic and also scales with the organization. So this is very important component that we invested dramatically in to deliver this value and, and positions us as a company oftentimes as the only company that can deliver uh, this value for certain companies that are very complex. Uh, the third aspect of it is uh, enabling everything to be AI native from day one, the AI native interface. So the way it's operated is that everything from a security analytics standpoint we have um, basically a very deterministic uh, very um, deterministic uh interface meaning that you write query old school like in KQL and it will federate, um, push down to the data repositories and provide you an answer. Deterministic classic. Uh, there is obviously AI in the midst of it, but the interface is not necessarily like looks like AI.

Speaker B: Yeah, it's not a chat interface. Yeah.

Speaker C: The reason by the way why it's important is about the economic standpoint like uh, to your work. Industry is already realizing that you cannot just to burn tokens on uh, uh one plus one or whatever you want to really have from a control perspective and transparency perspective like everything that you can make optimized and deterministic and you need it even should be. But on top of that we developed a very strong state of the art natural uh language to KQL capability and why it's important. Initially we developed it because we had one of our early design partners told us uh, KQL cool, but I don't know kql. I know spl, like okay, it's the AI age, let's write in like a natural uh language to kql, uh wrapper. And they loved it. But suddenly like the full potential of it kind of unveiled to us. It creates actually like an abstraction layer which is very powerful because like agents, how they interact in natural language and then you have a deterministic layer that it's completely exposable to an agentic layer and it creates like uh, the interaction between those are completely uh, transparent and completely controllable by the customer. So if an agent today is doing threat hunt in Vega, it receives like piece of threat intelligence, let's say PDF from FSIS, extract IOCs and TCP, uh TTPS, runs the hunt, builds the detection, all the steps along the way eventually being translated to queries that the user could have written and the user could audit these queries. It's 100% like, it's non elucidation. Like he can see what the queries were, he can edit those, he can do whatever he wants with it. And it creates a lot of trust for the adoption of AI.

Speaker B: Yeah, yeah, it's really interesting and I see this a lot with databases too like Supabase and others. They're providing that abstraction layer. So you know, when you think about your customers, they are using natural language to ask the questions that they want to get after. The agent will abstract it and kind of build the uh, queries. But uh, that is the key thing is that they get to use English or their natural language to ask those questions.

Speaker C: The customers and the agents that they deploy and the agents. Because the cool thing about it, and this is something that I can shut up about it like for the last couple of weeks is that um, and I guess we'll talk about it also later. But I see the biggest utilization in AI regardless for security in general, in enterprises, in software and whatever, as beyond everything, uh, scalable engineering capability. Because what is happening is that in verticals in the past that you cannot afford to build like a huge R and D for the purpose of it. It's classic for security because beyond maybe J.P. morgan and Chase, you don't see a lot of uh, security organizations with like a whole Dedicated R and D of hundred people building whatever they want. So people started to go to like no code automation or to buy a lot of vendors to do a lot of things. But today with some creativity and the engineering boldness, one individual can build like magnificent things.

Speaker B: Oh yeah.

Speaker C: And I think this is kind of the huge potential, uh, like, of AI because like this one person can create 10 different agents to do workflows that you know, no vendor will uh, ever think about because it's like right to the context of the organization and these vendors, what this, sorry, these agents, what they need is a high quality data access. And this is exactly where we come to the picture because those agents are interacting with our interface in natural language. And, and when this engineer wants to see, okay, what are those agents doing? Eventually beyond seeing a chat interface, it can also see what's actually happening under the hood, what queries are being run, can you optimize it and whatnot. And then it's full stack engineering. Think about as a software developer, you build a software and then it compiles to an intermediate language and then it compiles to a uh, binary code. So there is all those levels.

Speaker B: Yeah, that's amazing. Well, let's get into it, uh, about the customers, because these are security customers tend to be pretty conservative, relatively speaking. But not only have you guys raised a lot of money and a, ah, very high valuation, but these customers are leaning in. These are Fortune 500 customers that are saying yes and are leaning in. Talk about what you're seeing out there when you are interfacing with these folks and what's kind of generating that energy.

Speaker C: Yeah, I think today as we speak, I think we're seeing this amount of energy in the highest point I ever seen it in my short career. It's incredible. And I think the biggest thing about it is that especially in the post mitos era, if I can call it this way, people now are more afraid of staying with their existing stack. That didn't change for a while. That is not keeping up with the technology than to bet on a startup and have few hiccups along the way.

Speaker B: Got it.

Speaker C: I think.

Speaker B: Yeah.

Speaker C: You know, like even I, what is kind of cool about this, all AI wave, is that, you know, I'm running a company of 140 employees. It's not so big, but I already have a lot of empathy for organizations like uh, a bank or something. And because I sometimes, you know, when I hear from my customers about uh, pressures that they receive from the board or from peers, I feel that sometimes I give the same pressure in my organization. So like I push my teams to leverage AI and BAI native all across the board. Hr, go to market, finance, everything. Same thing happening in the organization. So who has the biggest uh, risk to get fired? It's not even about the threat actors and threat actors are very important, but just from a market dynamic, who has the bigger risk? Probably the, the one who will not evolve, the one who will not bet and one who will not change. So for at least it opens the years, everyone wants to learn, everyone wants to challenge what they have. And this market dynamics, especially in security operations where like there were so much uh, so many companies that did fantastic technologies that tried to disrupt that market and failed because of wrong timing. This was kind of the gap, the unwillingness to change because the things are working enough now. I think in no vertical in the industry and especially not in cybersecurity because also the pressure from the threat actors with the frontier models, nobody can stay in its place. And this creates a lot of fascinating conversations for us. And also accelerated velocity. And the reason why I believe Vega is so unique in this space because very early in our game we sold to Fortune hundreds and to huge uh, banks and this was like our first customers. This is something I very insisted on from a strategy standpoint, like we have to deliver to those value immediately. The reason why they trusted us is exactly the point that we touched earlier. Because the transparency model, because the control model, because eventually when an organization wants to leverage AI, uh, in every vertical, not only in security, usually you have two different options. One is the forward deployed engineer model, which is effectively, you know, consultancy or service. You basically pay for a vendor that will provide you some outcome and you don't really care about the bits and bytes. You get like a service, you get a people that will help you deploy that and show you that the value is actually working. But if you're replacing an existing solution or like a um, driving existing vendor or driving like internal teams. Internal teams need control, internal teams need transparency in order to act. Especially those big enterprises are not changing services, they're changing software and they want to have the same amount of control even if it's AI native through and through. And I think this approach really makes it easy for them to adopt.

Speaker B: Yeah, absolutely. And I think too that when you look at Daybreak and you look at Mythos and you see who is on the list for uh, preview, small banks and regional banks aren't on that list. JP's M on that list, Citibank's on that list. But there's a ton of people and usually those small organizations are small teams. They don't have the resources. So to be able to kind of leverage these tools and make those teams feel bigger is a massive, massive, um, momentum. So I totally see where you're coming from there.

Speaker C: And I think that the engineering aspect of AI that we discussed before, I think in a way it's kind of the big equalizer. Because if I was today a CISO of an organization with, uh, I don't know, 5,000 employees or 100,000 employees, I don't think I will build my cyber defense organization any differently. I think it's just a matter of, ah, number of people. But the profile I would hire, the core will be those cyber defense engineers, those people who can hook to data with cloud code or cursor or whatever works for their environment and be agile enough to infuse an organizational context and their engineering creativity, uh, to deliver those outcomes.

Speaker B: Can you talk a little bit about that though? Because in the past, I mean, taking a week to patch something was usually fine. In a world where you have bad, um, actors with a mythos like model, I mean, you have to patch these things in seconds or in hours. Right? I mean, talk about what the new world for AI security looks like compared with the old and where this is evolving a little bit.

Speaker C: I think it's all about velocity. I think velocity is the key. I think sometimes, you know, uh, as part of velocity, we talk about cost and complexity because those things are kind of interfering, uh, with our ability to reach velocity. But I think the journey all cybersecurity organizations are focusing right now is like speed, Speed. Because it's the same threat landscape, it's the same procedures effectively, but just the clock sped up. Everything needs to be faster from a vulnerability management standpoint and from a security operations standpoint, like all across the board. And if you try to kind of deconstruct a lot of the narratives that you hear in the market, eventually it comes down to speed.

Speaker B: Yeah. Always. Always. Well, um, I always like to end the episode with the same question. And that question is, when you think about the future of work and in this case the future of security as AI evolves, let's imagine that there's going to be another mythos out there and there's going to be another daybreak, and these models are just going to evolve in a world that looks like that, where we hope the good guys have the best models. How would you describe that future in two words? And then you can elaborate

Speaker C: so I think it's, um. The two words I'll choose is creativity and engineering. Okay. Yeah. Because I think that eventually, and I touched a lot on this in this episode, but I think effectively the biggest perk of this AI wave is that every one of us, without going four years in MIT and knowing a lot of programming languages and knowing the bits and bytes of some compilers can create a very powerful software. And what will make him great is not necessarily, again, knowing, uh, the best APIs or best, uh, ways to build, I guess, effective software, but to be creative with it and to be bold with it and to dare to innovate. And I think eventually in cybersecurity, but also beyond cybersecurity. Any individual that has ideas that learning his organization is curious in cybersecurity, learning about the threat actors, learning about the risk in this organization, and having creative ideas that he wants to implement in order to solve them in creative ways, uh, he has all the means in the world. Just as an individual. It doesn't need to hire a team, it doesn't need to do anything fancy. Just access data and build your creativity. I think this is the most magnificent way to drive outcomes, and I see it in many different verticals. And I think this is definitely the way to go for cybersecurity.

Speaker B: Yeah, absolutely. I mean, it's just such an interesting time that we're occupying. We're doing this episode in May of 2026. We still haven't released Meet those to the public yet.

Speaker C: Yeah.

Speaker B: You know, and so there's just this opportunity to kind of deal with cybersecurity in a very interesting way in the next six months, in the next year. That I think is really exciting. So I really appreciate having you on the show. It was super interesting. I think the audience is going to get a ton out of it. I'd love to have you back at some point. We can revisit this stuff. So, Shai, thank you for being on the Shift AI podcast.

Speaker C: Thank you so much.

Speaker A: That's a wrap. Thanks for tuning in. It was such a pleasure to have Shai Sandler as our guest on today's episode. If you want to stay connected to Shai, you can find him on LinkedIn. If you are interested in how he thinks about building AI native security architecture for the agentic era, connect with him and keep up with his posts and activities online. I continue to be amazed by the guests we've had on the show, and I'm excited about the ones joining us in the near future. I truly appreciate you spending your time with us. Thank you for listening to this episode. Don't forget to subscribe to Shift AI on ShiftAI FM, Apple Podcasts, Spotify, YouTube, or wherever you listen. And please rate the show with a five star review. You can also check out our substack@shiftai.substack.com we're always adding new content, so please go take a look. Shift AI is syndicated by Geekwire, and our show's theme music was created by Dave Angel.

Speaker C: Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • If Your MSP Says ‘All Good’, Can They Prove It?The Small Business Cyber Security Guy · on EDR (Endpoint Detection and Response)89 / 100
  • Weathering the AI Vulnerability Storm with Gadi Evron, Rob Lee and Ed SkoudisCyber Leaders · on Zero-Day Vulnerabilities89 / 100
  • How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200MThe SaaS Podcast · on EDR (Endpoint Detection and Response)87 / 100
  • Episode 121: New Open Group Security Standards DocumentationThe Azure Security Podcast · on security operations center (SOC)86 / 100
  • Everybody Wants AI. Who's Paying for It?AI Proving Ground Podcast · on Frontier AI models85 / 100
  • AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy MerzaSecure & Simple · on security operations center (SOC)85 / 100

More from Shift AI Podcast

All episodes →
  • AI, Security, and the Courage to Reinvent with Smartsheet CTO Cynthia Tee66 / 100
  • Governing Agent-to-Agent Trust at Scale with MuleSoft from Salesforce SVP and GM Andrew Comstock
  • Teaching Discernment in the Age of AI and Higher Education with UW Vice Provost for AI Noah Smith
  • The End of DevOps and the Rise of Autonomous Cloud with Hyphen AI CEO Jared Wray
  • The Case for Deterministic AI with Logical Intelligence CSO Patrick Hillmann
All Shift AI Podcast episodes →