
The ITPro Podcast · 2026-08-05 · 40 min
Arctic Wolf, a security operations and AI organization, describes a fundamental shift in how managed detection and response operates at scale. Rather than scaling purely through hiring more SOC analysts to review alerts, the company has developed what they call agentic AI - specialized agents trained on 14+ years of incident response data and thousands of compromises - that handle discrete security functions like threat intelligence gathering, vulnerability assessment, detection rule creation, and forensic evidence collection. These agents work as a swarm, each with defined roles, continuously operating without fatigue or bias to augment human analysts. Nick Dyer and Carla Darcy distinguish this from consumer-grade LLMs like ChatGPT or Claude, which lack security-specific reasoning and knowledge of individual environments. The challenge for defenders is significant: threat actors already use AI for phishing, vulnerability scanning, and campaign creation with minimal accuracy requirements, while defenders must maintain near-perfect accuracy to avoid missing real threats. Arctic Wolf's approach relies on a "golden data set" - 14 years of normalized, tagged security data across 250+ vendor integrations - that enables training models that can be continuously refined by senior engineers. Despite automation potential, both executives emphasize the irreplaceable value of human judgment during actual incidents: relationship trust, critical thinking in ambiguous situations, and the ability to guide customers through crisis response at 3 AM remain distinctly human capabilities. The tension discussed is whether organizations build custom security AI over years or adopt turnkey agentic SOC solutions that plug into existing toolsets.
Agentic AI assigns specialized roles and personas to large language models trained on security-specific data (like Arctic Wolf's 14+ years of incident response data), creating autonomous agents that continuously perform discrete tasks like threat intelligence gathering, detection rule authoring, and forensic analysis. Unlike ChatGPT or Claude - which are general-purpose models trained on internet data without security context or knowledge of individual environments - agentic AI agents have defined functions, work as coordinated swarms, and are continuously refined by senior engineers for accuracy in security-critical decisions.
Arctic Wolf's detection engineering team uses agents to: discover the latest CVEs and threats from the internet, extract tactics and techniques (TTPs), automatically author detection rules based on that intelligence, test those rules against live environments through user acceptance testing workflows, and promote high-quality rules to production - a workflow that previously required multiple human analysts working sequentially.
General-purpose LLMs lack security-specific reasoning, governance knowledge about threat behaviors and actors, and context about an individual organization's environment. They're trained on historical internet data rather than security incident data, making them unreliable for security decisions that must be nearly perfect to avoid missing real threats, which is why security-specific agentic systems trained on curated incident data are necessary.
Arctic Wolf's golden data set is 14+ years of normalized, tagged security data collected across 250+ vendor integrations and thousands of incident response engagements. It provides a pre-sorted, enriched foundation for training AI models, giving the company a multi-year head start compared to organizations trying to build security AI from scratch or those with data from only a few vendors.
No - Arctic Wolf emphasizes human-in-the-loop as core to their model. Humans validate agent reasoning, make judgment calls during ambiguous investigations, provide empathy-based customer communication during 3 AM crises, and facilitate in-person incident response coordination. AI accelerates routine work and elevates analyst focus to high-judgment decisions, but human expertise remains irreplaceable for trust, critical thinking, and crisis management.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, brought to you in association with Arctic Wolf, Jane speaks with Nick Dyer and Carl Adasa about moving from traditional MDR to an agentic SOC.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign. Hello and welcome to this special edition of the IT Pro podcast brought to you in association with Arctic wolf. I'm Jay McCallion and joining me today are Carla Darcy, VP of Security Operations, and Nick Dyer, our Ah, VP of Systems Engineering. Carl and Nick, welcome to the show. Thank you. So first of all, can you give me an overview of Arctic Wolf and what you do?
Speaker B: Yeah, I'll jump in there. So, um, Arctic Wolf are a security and A.I. organization. Um, we're a global organization that are really focused more on kind of working with companies, uh, around the world on ending cyber risk. So we um, are ah, a security technology and also a service provider that allows us to deliver, uh, turnkey security operations capabilities. So it might be uh, detection and response, it might be vulnerability management, attack service management, um, it might be around security awareness and training. And we build all that on our own technology, on our own platform and then we wrap around our own, um, turnkey service delivery for our customers. Um, so it's not just delivering a suite of tools or technologies for organizations, it's actually helping them with operationalizing it, deploying it, and actually gaining value and business value out of those technologies as well as.
Speaker A: Carlos, you got anything?
Speaker B: Yeah.
Speaker C: So Arctic Wolf, we also have a security operations center. We have multiple uh, SOCs is what we call them around the world. We operate 247365. So every minute of every day we have uh, what we call triage security engineers. And these are the folks that are monitoring security alerts across all of our 11,000 plus customers. What we do every day, day in and day out, security investigations and really what we try to get to as soon as possible, uh, in the security world is to detect and respond to a security incident. There's a lot of cyber threats out there. There's a lot of cyber, what we call cyber criminals and cyber attacks. Uh, so for us to be 24, 7, 365, our customers can be rest assured that even when they're asleep they're being monitored. Uh, we have security professionals on call as well. So if it's 3 o' clock in the morning, they may give us a buzz, uh, because they may have heard, you know, some news, uh, about a cyber threat. And we're here to answer the call. But, but oftentimes we actually are the ones making the call at 3 in the morning with CISO or a CTO or a CFO. Unfortunately, those are the days that they dread, but those are the days that we are always prepared for.
Speaker B: Yeah. And uh, to really kind of go more Onto what Karl was explaining there. Um, the big part of what we do is we're a vendor neutral, uh, security operations capability in that customers can bring their own tech stack to our technology and our platform, the superintelligence platform. Um, we've built our own, um, ingestion engine, our own detection logic, our own data lake. Um, so we don't need customers to rip and replace and kind of use a, uh, bespoke suite of technologies or kind of a limited suite of vendors. Typically they can bring their own tools, their own investments to us and then operationalize and get a fully, fully manned 24 7, um, concierge service off, uh, out of the tools that they've already got today. So it limits the amount of investment they have to make up front. Operationalizes the tools they've already invested into, um, gaining more value out of those tools, but also then having a true security partner working with them, um, operationalizing and then getting value and actually helping them with the question of are we safe whilst using the technologies that are in play today.
Speaker A: Speaking of technologies that are in play today, it's been almost five years to the day since the release of ChatGPT onto the market. How has access to, or easy access to generative AI change the cybersecurity landscape?
Speaker C: I can rewind back to five years ago when ChatGPT was first released. It was pretty exciting working in a SoC. My career in cybersecurity started as actual SOC analyst and so I was the one working the alerts 247 on different shifts. But when ChatGPT arrived, it gave us a tool kind uh, of like Google, but a smarter Google. So we were able to ask questions and say, hey, if I see this type of cyber attack, what should I do? How should I investigate this? If I do find something, how should I respond to it? And so at the time it was really a conversational tool that we could use to really elevate and kind of, uh, expedite our security investigation workflow. And if you fast forward today, I mean, this thing is more than just a chat prompt. It's an actual tool built off intelligence and data that we've collected, especially at Arctic Wolf for the last 14 years. What we've been able to do now is take everything that we've known, um, all of our expertise partners pumped that into what we call a large language model. And then we've assigned it different roles and Personas. And so now we almost have what I would call digital humans. Right? And these are the forms of agentic AI, uh, that we call them, uh, we've created multiple swarm of experts. All of them have very discrete functions within security operations. You may have one that's a threat intelligence, uh, agent. You may have one that's a vulnerability agent, identity agent. And every time an analyst gets an alert, all of these different agents are now working to solve that one puzzle. Uh, everybody has their job. And the good thing about the AI world that we're in today, these things are continuous. They never stop and they don't get tired. They don't have biases. And one of the things that Nick and I discuss pretty heavily is how does the human get impacted in this world? One, we've been able to remove a lot of the mundane tasks. Sometimes you may have a bad day, as Nick likes to say. Uh, that may affect how you do your job, may affect how you look at security. Uh, alerts and investigations may also influence you in not the best way. The good thing with machines is they're quite predictable as long as we put the right guardrails and we code them in safely and properly.
Speaker A: Nick, have you got anything to add?
Speaker B: Yeah, um, so I think what's really interesting is you've got the use of artificial intelligence in security. So the capability of building out security capabilities, security workflows, agentic workflows in security for security operations. If we then generalize it more, you know, we've got the use of AI proliferating across the traditional user base. And that's not security or IT people. These are finance, uh, and they are, you know, kind of hr and they're the kind of work and their pr. These are all people now that are using AI technologies to augment their work or to, you know, kind of supplement their work or even to really help them with their digital assistants. What we're seeing is a real, um, kind of use of shadow AI across most organizations now. Um, it's not uncommon to see five to six different types of LLM model being deployed in every organization because you've got, um, kind of bespoke LLMs for certain use cases, or they might even now be part of maybe Google Chrome that you've adopted, or it might be part of Adobe that you use for kind of Photoshop or those kinds of things all the way through from Copilot for Microsoft and other things. Um, but what that really means is we're seeing a huge amount of kind, um, of confidentiality leaks and data breaches because users are now starting to use these technologies and trusting them more and using them for confidential or potentially, uh, maybe kind of use cases they shouldn't be using it for. So there was an interesting uh, Verizon data breach report uh, that came out fairly recently and that reported that over 40% of kind of use cases now are seeing data breaches across organizations. Not from actually kind of malicious insiders, but from people that just benign, that didn't mean to do it. And so you've got the rise of kind of data leakage really coming from uh, LLMs and chatbots. And then obviously we've then got the rise of using AI for attackers as well. And the wave that we're all facing here is um, know defenders. We're trying to work out how to use AI for good. It's already being implemented for red teamers, pen testers, but also for the, for the threat actors that exist out there in the world.
Speaker A: Yeah, because it does sound like that is something that could be really difficult for cyber defenders to face. This wave of people just not maliciously but just experimenting and in doing so opening up a whole bunch of windows and doors for either data to escape or for malicious uh, actors to get in.
Speaker B: Yeah, uh, it's one of the biggest worries that is on every ciso's mind right now. How do I protect my organization against non malicious insiders? How am I making sure that I've got my data governance and data compliance in place? Um, that's where education and making sure that users are using it in the correct way and in the right way. It's making sure that you've got the right LLMs in front of the right type of user so you don't have um, uh, unrestricted access to everything. Um, and then it's about data classification and data regulation that you're using inside as well. But it is a major challenge and it's on the minds of most IT leaders right now.
Speaker A: Carl?
Speaker C: Yeah, and we see this pattern essentially with every new technology that comes out. Cloud, uh, was a big thing. Once we went from standard on prem, uh data centers to now cloud. We had this huge transition. Uh and so we had really things tightened, lockdown within on prem. We had system administrators that had to provision you a server to put your data in. Now with all these different cloud infrastructures the developer can request a cloud container and uh, they'll get spun up the same day. Unknowingly put sensitive information in the cloud, forget to lock it down. Uh, and that's where the attackers are essentially getting freebies I would call it. With the rise of AI being used in business applications, if you're hr, if you're finance, if you're in marketing. What's interesting also is that unintentionally putting data there. And, uh, now instead of attackers having to steal this confidential information, we have folks willingly giving it, uh, to the cyber attackers at a whim. And so I don't think it's intentional in any way. I just do think it's part of this evolution, uh, of adopting new technologies. Sometimes some, uh, companies want to be very innovative. They adopt it really fast. And then after a while we start to have some lessons learned about it. We, we start to see user behavior patterns within the organization and then we can put specific policies in place. I think now it's pretty common to see HR organizations incorporate AI best practices as part of their new hire onboarding. We see GRC teams creating full compliance documents around AI usage, um, auditing, who has access, what do they access, what do they upload to AI and different chatbots. Because now every tool, um, that we have access to has their own version of AI. And so it's hard to really capture input, uh, controls in every little thing when everything is now embedded and integrated with AI. So it's very challenging for security folks, very challenging for IT folks. So organizations from the CISO to the cto, we're all kind of in the same battle. And we also want to make sure that we're not blocking the company from innovating. We always want to be business enablers as part of security, uh, and it also supports that. And so I think we're both kind of in this fight together. Um, I think that, uh, it's not going to slow down anytime soon. I can tell you. With just the rise of all these new AI bots and LLMs and features, it's almost impossible to use technology and it doesn't have AI component as some part of it.
Speaker A: You mentioned sort of LLMs and chatbots there. Those are typical examples of generative AI that a lot of people will be fairly familiar with. Let's move on to talking a little bit about agentic AI though, because I understand this is a bit of a specialty for Arctic Wolf.
Speaker C: Yes. For us, agentic allows, uh, us to be force multipliers. What we use agentic AI for really is capturing some of the expertise of maybe, let's say a threat hunter, an incident responder, and that expertise of over a decade of their experience and all their different compromises they've been involved in. And we basically say, let me take everything, you know, and everything you've ever experienced. Let me codify that and now train an agent. And so we have several agents in place that uh, have taken 14 plus years of experience and thousands of incident response engagements and we've taken the best practices out of that. And then we've created our first golden data set is what we call it. Um, the important factor here though is that once we've created this golden data set, it is a living, breathing LLM is what we call it, right? And so every day, every hour of every day, we have our senior level engineers and principal engineers, they are taking parts of this LLM. They're using it to spot check, to see is it accurate, is the reasoning correct, is the verdict correct. And then we tell them, don't have 100% trust. And I want you to treat it as if you have to validate this. And so we feed that directly back into the AI models. We work with data scientists on our team also to give them the feedback. They're able to retrain this, we call this, refining this as you go. Um, we have a very high quality mark, if you will. We want AI to be as close to 100% as possible in its accuracy. But obviously as anything else, it's not going to be perfect. And I don't want people to leave and say, well, AI has to be perfect for it to work. It has to be good enough and accurate enough for it to do its job. And then that's where the humans come in to really bring in that last mile and validate, take action. Um, but yeah, it's an interesting time in how we're using it.
Speaker B: It is. And if you, you know, if we take a step back in the AI race, I guess it is, um, threat actors are already using multiple type, different types of AI. You know, it's being used for, you know, phishing. Uh, it's really easy now to create a very good phishing campaign. Uh, it can be used to create malicious websites, you know, mimicking websites, duplicate websites, those kinds of things. Um, and also it's really, really easy to try and you know, scan for vulnerabilities and create AI technologies that can just breach vulnerabilities. And one of the biggest kind of rises that we've seen from attacks has been not from phishing and user kind of behavior based breaches, but it's now vulnerability based kind um, of breaches. And that just lowers the barrier to entry for attackers. Right. So AI, ah, is a force multiplier for attackers and it doesn't matter if they don't get it right. 100% of the time because they can just create a new campaign and you can just spin that out. It's really, really easy. When you're a defender and you're looking at ah, alerts and you're looking at false positives and true positives and you try and inject AI in the mix, it has to be correct 100% of the time because if it's not, that could be the worst day in your organization or combination of days if it is a serious attack. So with AI, you have to be able to trust it and it's got to have guardrails and it's got to be controlled. And a lot about what organizations are kind of figuring out now with AI is well, who do we use? Do we go for a frontier model? Do we think about uh, anthropic? Do we look at GPT? Do we look at claw? Uh, do we look at uh, copilot? Those models are not security models. They're typically, you know, kind of large language models built on historical data learned from the Internet and kind of other areas. It's not security specific. It doesn't have the reasoning and governance for, for threat behaviors and actors and kind of things that are going on. It also doesn't know your environment. So the context of how the organization works is not going to be inside that LLM. So it's really hard to implement something quickly without having to go and build your own LLM and build your own kind of. And that then is when it becomes a bit of a science project because you're investing a lot of money to try and build this, to make it work to how your organization needs to go. All the while you need to detect and respond to threats that the AI threat actors are already doing. So we're now at this crossroads of what are uh, organizations going to do to protect themselves against threats. Do they spend a multi year, you know, kind of multi million pound project to try and build this themselves? Or do they need something turnkey that can snap in to kind of give them that coverage and that capability within a matter of kind of weeks. And that's really the decision matrix that we're seeing. A lot of organizations go down right
Speaker A: now in addition to uh, sort of codifying institutional knowledge, people who've been at this for like you say, 14 plus years into an AI, ah, agent. Are there any other ways that Arctic Wolf is using AI agents?
Speaker C: Yeah. So even before attacks happen, you have to detect them, right? And so to detect them you have to have, you know, a pulse on the threat landscape and if you ever open up the Internet and you search for newest threat, today you probably have 50,000 articles, right? Uh, CVEs are being published every day. And actually the CVE organization said that the number of CVEs that are published this year has already increased by what it was last year at this time almost by 25 to 200%. And so the rate of new vulnerabilities being exploited, um, has skyrocketed, obviously because of AI and how easy it is to use. And so what we're seeing is agentic AI also being used for our detection engineering team. Um, this team, along with our threat intel and threat research, uh, put an agent and say, basically, can you go and find me the latest threats? From there I want you to take all that information, the tactics, techniques and procedures, what we call ttps. Now I need you to author me a detection rule. From there I have another agent that says, I'm going to go test this detection rule. Is it good, is it high quality? Um, do we have user acceptance, testing workflows that we can do to benchmark this rule? Once we do that, we promote that to production. All that done now almost entirely by agentic AI. What used to take humans to manually go on the Internet or set up rules to figure out what is the newest threat? Another human that's going to take that intelligence information, develop a rule manually by code. Another set of humans are going to test this against live environments and live events, uh, and then work with the SOC teams to sign off and say, this is a high quality alert. It's detecting the threat that we expect, um, and now it's in production. So this whole human workflow of intelligence to development, to production alerting is also where Arctic Wolf is using agentic AI. And it's not just within the SOC analyst team that are reviewing alerts. Um, it's really the beginning, the middle, and then once we get to incident response again, that time that everybody dreads, um, agentic AI is also being used there to help capture the specific forensics artifacts on a system. How do we speed up that collection? How do we then speed up the analysis of the evidence that we collect? And so agentic AI is starting to find its way across the entire spectrum end to end in security operations.
Speaker B: And, uh, just to add, uh, to Carl's point there, that all of this is not possible unless you have the data set to build upon, and we call it the golden data set. So the fact that we've been aggregating, collating and building services and um, Detection, logic and turnkey outcomes for customers. 14 years, these 250, 300 plus integrations of different vendors and tools and technologies that we've been working with. But we've been passing that information and enriching that information and tagging that information since we started. So when you start building a data lake for AI models to start aggregating and learning, the data's already sorted, it's already there, it's already kind of uh, so we've got a multi year head start on many organizations that are now trying to build this or historical organizations that are going right. You know, we've done it on maybe three vendors and now we want to go on 30 vendors. Well, we don't have that data to start with or to go with.
Speaker A: So does this mean moving to a fully automated system then?
Speaker B: Uh, I think we both have, uh, both have thoughts on this. Um, so I work in the world of sales and pre sales and sales engineering. Um, we're using, you know, AI LLMs to do wonderful things for us for kind of leveling up our quality of work and kind of what we're doing there. Um, but in our opinion, um, we still need good human beings. Uh, people really want to interact with humans like agentic work and AI work really kind of solves for a lot of the kind of BAU or the work that we have to do. Um, but when we're working with our customers and we're working with our partners, we, we're still the human gray matter people really want. If we're having a bad day at work, we want to pick up the phone and we want to speak to a human being. Similar, if I've got a problem with a hotel booking, I don't want to deal with a chat bot on the Internet that says, sorry, but you know, you have to answer these questions like no, I want to speak to someone real that understands me, that can take action on my behalf because it's really urgent. And um, it's exactly the same as security operations. Um, because if you're using a security operations provider context, relationship and um, being in the boat with you as a partner and not a vendor is so important, uh, to the outcome because it's all about trust and relationships at the end of the day. Yeah.
Speaker C: For me in Arctic Wolf, Human in the loop is something that we advertise, but it's something we truly believe in. Uh, we double down with the human in the loop as part of our story, as part of our solution. Um, AI, Yes, I do think that it can have its home in a fully autonomous way. But for maybe some parts of our investigation, some parts of detection engineering, some parts of response, um, that the human element of it, the gray matter that we call the critical thinking, that is what, uh, we really rely on to be the expertise in AI, to us, is a fantastic tool. It can really make things faster. But there's very critical moments in the day during an investigation that a human needs to validate things, needs to be able to respond, call a customer at 2, 3 o' clock in the morning and be able to, uh, explain what's going on in a very easy manner, uh, and then get inside a war room with the customer and their IT folks. And you have to be able to read the room and calm the room down and say, hey, I know this is a breach potentially. These are the specific actions we need to take together. You do this, I do that. Uh, and so it's a partnership, as Nick said. And that human element is really hard to replace with AI. And if I'm in, you know, if I'm a CTO or I'm an IT manager and my entire network is going down and I see systems getting shut down. I need a human to be able to talk to and interact with. Right. I need to be able to relay information of what I'm seeing that a chat may not be able to see or probably will never see. Right. So these AI Personas are great. AI technology is there. Um, but, you know, when an emergency actually happens, and trust me, it does happen all the time, there's nothing like picking up the phone and calling somebody and actually having that person to walk through the entire investigation. Because we may be a room full of 20, 30 people in this, what we call a war room. Right. And so, yeah, we'll probably leverage AI for the mundane tasks like, you know, hey, give me this information, parse it out, let's format it this way. It has its place. But, you know, the critical thinking, the human nature of how we do relationships and respond, I, um, think is going to be key. And no. So I don't foresee this being a fully, uh, autonomous world.
Speaker B: Yeah. And we are a destination employer for security practitioners. We want to continue to be that destination. We're very proudly the world's largest commercial SoC at this size, delivering this to tens of thousands of customers at this scale. Um, so we hear the news of AI is going to replace an awful lot of jobs. I don't believe that. I fundamentally don't. Primarily because you need the operators, you need the human in the loop. Right? And people don't want to be doing mundane tasks. They don't want to be doing the binary yes or no. That's the things that they get switched off by, they get bored by, and they will leave a job if all they're doing is eight hours of yes or no binary. What they really want to do is the really interesting things, and they want to level up and they want to then grow and educate and learn. And so that's really an opportunity for not just us, but every organization around the world is looking at the staff and going, right, how can we enable our staff now to do more, to do cool things, to innovate, maybe make money for the company or business value? It's not just having a load of people sat there looking at a dashboard saying yes or no, binary, or pressing a button. Because really, the gray matter is really the talent pool that we've got today, but also it's the next generation of the talent pool that we want to bring through.
Speaker A: I guess it really is then the, uh, classic piece of human creativity, the ability to interact socially with each other is why you still need human in the loop.
Speaker B: Yeah, without doubt.
Speaker A: Right.
Speaker B: And organizations and companies of every vertical around the world. It's still human to human. It's not AI agent to AI agent. A lot of the decision matrices and a lot of the things that we use to get to some of those decisions might be AI helped or assisted, but at the end of the day, business is done by working human to human. And I don't think that's going to change.
Speaker A: Well, that leads me quite neatly on to my next question, actually, which is what are the advantages of combining an AI and a human approach?
Speaker C: Yeah. So for me, if you have a. Let's go back to the fully autonomous. If you had AI doing everything, it can only learn so much, Right. It can only learn on itself. And so when you have human and AI working together, they're essentially building and evolving each other. AI can make humans much faster, and humans can make AI much smarter. So when you have speed and intelligence working together, uh, I like to say it's a force multiplier for us. We're also a force multiplier for AI. And so once you create this, what we call the golden data set in LLMs, they need constant training. It's like a human individual themselves, Right. It needs to learn new stuff, learn new tactics, new techniques. Uh, and the humans are part of that evolvement. Now, once we get into these new areas where maybe it's undiscovered principles or practices. In security operations, we rely on AI to say, hey, how can you help me do this much faster? How can you help me do this at scale?
Speaker B: Right.
Speaker C: I can do this task myself ten times a day. What if I am being asked to do this a thousand times a day? So small teams, typically when we see solutions, we create it, uh, at the time that we need it. And it may have been great for 10 tasks or 10 customers or 10 servers. What happens when that thing grows exponentially? Those same processes that we did 10 times for 10 servers is almost impossible to do for 1,000 servers or 1,000 users. And so for us, I think that augmentation of AI is helping humans become faster and scale better. Humans are helping AI become smarter and evolve because we have to constantly train. Um, and companies of all sizes are seeing a lot more data being ingested and produced. Uh, and humans are being asked to do more monitoring, um, these massive environments that constantly change.
Speaker B: Yeah. And it's why our technology stack and our platform is called the superintelligence platform. Um, superintelligence is a world known in AI circles which is the combination of human and machine allows you to continually refine, continually improve and iterate both the machine models that you have as well as the human beings and the expertise that you put in a single kind of outcome which is focused on a certain thing which is in our case, uh, security operations.
Speaker A: Building an AI native security capability sounds like a massive undertaking. Um, is this realistically something that IT departments can actually build themselves? And what kind of risk does this bring to organizations?
Speaker B: Yeah, so we've talked an awful lot about how we've done this and a lot of the work that we've done this is, ah, I can't state this enough. This is so hard to build, especially if you don't have the data set and the knowledge and the workflows to start with. We've seen this story before. We've seen waves of new security innovation that is the unicorn that's going to fix all the security problems for organizations. We've seen cloud and we've seen SIM and we've seen soar and all of these have just come with huge budgets, multi year projects with a lot of complexity because we've still got to keep the lights on. There's a lot of legacy we've got to keep on looking after. At the same time we haven't got enough people, we haven't got the process and all the while it typically becomes, I don't want to say half Baked. But it never becomes a solution that they were promised up front because BAU happens or other projects happen. Right. And where we are is you need to be able to show that you're adding value so budgets aren't being increased. And any AI project that's being implemented right now, if it can't show business value, it's not going to continue to get funded because it's so expensive. When you start thinking about tokenization and the workflows that we need to do. So for an organization overnight to go, I'm going to build an agentix security platform on top of my SIEM with my team of five or 10 security operators with not much data to really go about. That is a project that's going to be very hard to do and it's going to take multiple years to do so. Um, and so there's multiple ways to try and uh, boil the ocean in this way. You could look at the frontier models, you can try and look at a platform to build upon, or you can maybe look at a startup that might be able to give you some of these kind of little agents to deploy. But all of these are science projects. It's the start of the innovation curve. And what we're really proud of is we're bringing this turnkey solution to market. But it's already in use for uh, 10,000 plus customers today. So it's not a new next generation. Try it and adopt it and see what you think it's like. No, we've got this is delivering value to thousands of customers at scale right now that we can have you live on in 30 days or less.
Speaker C: Yeah. In terms of it, is it realistic? I would say yes. With an asterisk. Right. There's a caveat. You have to have the technology behind it, you have to have the budget behind that. Right. So the technology piece, you can get that. But now we talk about the people to make that all work and build it from scratch. Um, at Arctic Wolf, we have hundreds of security engineers and experts that are all kind of helping build these AI models. Um, now what we have is a security expertise because we're a security focused company. Most companies who may want to do this may not have the security expertise. I'm not saying they can't get that. And I don't think it's not realistic because there's a lack of desire there. But it is a long process, as Nick mentioned. And so if you think about, let's purchase a tool, let's find the right tool that fits our environment, the Right. Compliance and requirements and regulations. Let's find the people. Do we have the people internally that really know how things work, that can then turn that into code for AI to build agents and the infrastructure? Then do we have the right processes in place and compliance and security policies to make all that come together? Um, so, yes, I do think it can be realistic if, uh, you're a large organization, but unfortunately for a lot of small organizations, um, they just don't have the resources to do so. Um, and also I think, Nick, we spoke about this, but are you using synthetic data to build your and training your models, or are you using real life, uh, data that you have, uh, collected about your environment? What we find with AI also is that it needs good data to be trained. Well, you can't just create data out of nowhere or give it a lot of unstructured data from a lot of different places. And I've seen a lot of AI implementations that struggle there. Um, they'll hire an AI team. And, uh, again, the desire is there. The AI team says, I need good, structured data. So that is one of the big roadblocks upfront in the beginning is again, you may have funding. You have the right idea. We have a specific time we need to get this done by because of budgets and commitments we've already made. Oh, but we have to go back and fix all this data structure first. And, uh, you ask a lot of IT pros and architects and engineers. That's a tough one. And that's not even a security issue. Right. And so do you have the time, the resources, the desire? Except may be there, but it is a tough challenge.
Speaker A: Ultimately, boards really want to know answers to the questions, are we safe? And, um, what do we do if we're not? How does Arctic Wolf, um, prove operational and financial confidence beyond just the technology?
Speaker B: Yeah, so these are the conversations that we have every day. Um, because the advent of the agentic AI insecurity is headline news right now. And this is outside of the world of it. This is in the Financial Times. It's in. It's in, you know, the Telegraph is you reading about these things at the board level and at the non it, uh, buyer kind of level. So those are the questions that, the hard questions that are being asked of CISOs and IT leaders, which is, are we safe? And it's a very hard question to answer when they come into them with. I've read all about, about these agentic attacks and Mythos and five five for chatgpt and the wave of vulnerabilities that's coming at us. And some of it's hype, some of it's real and it's hard to cut through the noise. But it's even harder to justify that to a board when they need to be able to answer that question very quickly. And so that's one of the big things that we do, um, is helping the boards answer those questions. And like I said, the other thing you need to do is justify what the value of it is. If you're going to spend multi million pound investment, is that going to help us make money? Is it going to save us money? Is it going to help us grow? Like what, what is the tangible outcome? If it's just going to be, yeah, we're going to be safe. Some boards will go for that, others will go, yeah, but that doesn't, you know, that doesn't align to what our priorities are as a company. So you need to be able to have that conversation of we're reducing risk in the organization, but also we're improving the, the kind of scale, the spend or the, or the efficiency. So we can go and do X or Y. So it's about having those two conversations together and then the final one is what happens if we do have an incident? And that's the uncomfortable question, so do I have a plan? Who's on retainer, who do I call? How, what's the SLA to work with, uh, us and when, what do they do and what don't they do? So it's about having a knowledge of, well, these are the people I have on deck that I can bring in. This is how much it's going to cost, but this is the operational kind of value of what they're going to bring to us. And then finally you've got to start thinking about what do you do around insurance. In 2025 we saw the, the big attacks with JLR, Marks and Spencer, Harrods and the like. And we saw the, the major fallout of cyber insurance. You know, the cyber, the cyber insurance industry, you know, were hit by, you know, was it 450 million and above for uh, Marks and Spencer? And that was the business impact of the attack that they were claiming on pot on top of. So what are your carve outs? How are you understanding what are your limits of the financial kind of impact of what a breach could look like? You need to think about that. And then finally, what do your security vendors provide from a warranty perspective? So we provide our customers up to $3 million of financial aid in a warranty. It doesn't replace insurance, still need it. But if you need that financial coverage for additional carve outs or to help you with assistance for incident response or other things, we have our customers backs and customers are able to call on, um, that should a bad day happen in their organization. And that's the downside to security is you can never say never. There may always be something that happens.
Speaker C: Kong um, yeah, and for us, I mean my point of view is that there's a common language security, IT board and executives share. Uh, it's risk, risk and impact really. Right. So how does security teams and even it, uh, help paint that picture into something the board can really consume? And so if we can marry the risk of what we're see and the impact if we don't mitigate that risk via, uh, Security Technologies, a service provider and MDR like Arctic Wolf, um, this is going to be the impact. Now it's hard to calculate one for one, but then we'll use examples such as, well, this was a breach that happened. We're pretty identical to that company in the same vertical. We use essentially the same technology stack. So we can kind of predict what will happen if we don't address these things. And I see a lot of CISOs struggling, try to justify budget increases when really we're seeing a lot of them compress. Right. And so to stay ahead of technology and ahead of these attacks, budgets do need to be maintained or sometimes even grow. And so for us, we always try to marry the risk and the impact to help with that conversation. And I think what we also do well is because we have so many customers across so many different segments, uh, you as one of our customers, you can see how you rate against your peers within the same vertical or even broadly across all of our customer base. So for example, if you have an attack coverage map that we use and uh, out of all these different attack vectors that we know of, you have 80% coverage. Um, so we can detect 80% of the type of attacks, uh, based on what we're collecting from your environment, but your peers are averaging about 95%. These kinds of conversations as metrics help CISOs and the likes go to the board and say, hey, look, this is where we're currently at. We have this amount of coverage on our environment, uh, and this is kind of where we're stuck. Our peers across the way are at 95% on average. So they're in a much better security posture than us. Now the impact of that 15% could be huge, could be in the millions for Example. Right. And so it is a tough conversation. Security is seen as a cost, um, rather than a business maker or a money maker, let's be honest. Um, and usually the last time, the last, the moment you don't want to talk about security is when the breach occurs. And now we're wondering how did we get breach? How much money do we need to spend to patch this thing up in ransom notes and the likes? Uh, the conversation is hard. Risk, um, and impact typically. Is that common language I think we could all understand, um, that really help answer those questions.
Speaker A: If our uh, listeners, our viewers want to know more about Arctic, uh, wolf and its technology, what should they do?
Speaker B: Yeah, so the easiest thing to do is to hit up the website, which is arcticwolf.com um, there's a plethora of really good information there. We've got significant resources. We do on demand webinars there. We do industry based, uh, webinars in different verticals. So if organizations are in legal or kind of architecture, so you can go and find them there. Um, we've got a great amount of content also on YouTube. So Ark2wolf networks on YouTube, uh, there's demonstrations there, there's kind of use cases and kind of examples where you can see that as well as previous customer, uh, case studies discussions, webinars that we've also recorded too. And finally, um, we hit the trade show circuit an awful lot. So you might find us at a trade show near you, depending on where you're watching from.
Speaker A: Well, unfortunately that's all we have time for today, but Carl, Nick, thank you very much for joining me. You can find links to everything we've spoken about today in the show notes and even more on our website at, ah, itpro.com don't forget to subscribe to the IT Pro podcast where you're listening to podcasts and if you like what you hear, leave us a positive rating and review. I'll be back later in the week with more from the world of it, but until then, goodbye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.