The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/The neXt Curve reThink Podcast
The neXt Curve reThink Podcast artwork

The Blueprint for Agentic Security (with Raj Chopra)

The neXt Curve reThink Podcast · 2026-04-27 · 12 min

0:00--:--

Key moments - from our scoring

Substance score

55 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality11 / 20
Guest Caliber13 / 20
Specificity & Evidence14 / 20
Conversational Craft8 / 20

At RSAC 2026, Cisco Security's Raj Chopra outlines the emerging framework for securing AI agents across their entire lifecycle. Trust emerges as the most constrained resource in agentic systems, requiring adherence to stated capabilities and comprehensive observability. Chopra details Cisco's multi-layered approach: contributing security taxonomies to the community via MITRE, vetting all 1.5M+ models on Hugging Face through CLM AV scoring, and scanning MCP servers and skill files that developers download. The centerpiece is Code Guard, an IDE extension that validates code against organizational security policies in real-time as agents are built, checking for exposed credentials, publicly routable IPs, and policy violations without forcing developers - enabling secure-by-default behavior. This package, bundled into Defense Claw, represents Cisco's effort to restore security best practices to a rapidly evolving ecosystem where agents can spawn in seconds and require continuous runtime monitoring. Chopra acknowledges that enterprise-grade open agentic frameworks remain immature, requiring governance frameworks spanning instantiation, deployment, visibility, and feedback loops.

Key takeaways

  • →Trust is the most constrained element in agentic systems and must be built through observability and adherence to stated capabilities.
  • →Code Guard, Cisco's IDE extension, validates agent code against organizational security policies in real-time during development without friction.
  • →Cisco has vetted all 1.5M+ models on Hugging Face through CLM AV scoring and scans MCP servers and skills files at the point developers download them.
  • →Enterprise-grade agentic frameworks require comprehensive governance spanning instantiation, deployment, runtime monitoring, and feedback loops across different timescales.
  • →Cisco contributes security taxonomies, TTPs classification frameworks, and open-source tools like Defense Claw to the broader community rather than creating proprietary standards.

Guests

Raj Chopra

Topics in this episode

SplunkHugging FaceMCP ServerMitreOpen TelemetryCiliumCode GuardDefense ClawCLM AVECMP

Questions this episode answers

How is Cisco securing AI models downloaded from Hugging Face?

Cisco vets and validates every model on Hugging Face using CLM AV scoring, with results posted publicly so developers can see security validation before downloading.

What is Code Guard and how does it work during agent development?

Code Guard is an IDE extension that checks code against organizational security policies in real-time as agents are built, preventing exposed credentials and policy violations without forcing developers to manually review every decision.

What are the key security scanning points in the agent development lifecycle?

Cisco scans models on Hugging Face, MCP servers at download, skill files when added to agents, and validates code generation against policy manifests embedded in agent files.

Why is trust the most critical challenge for enterprise agentic systems?

Trust is the most constrained element because agents must demonstrate adherence to stated capabilities and behaviors through continuous observability, which lacks standardized taxonomy today.

Is enterprise-grade open-source AI agent security mature today?

No - it's too early to claim enterprise-grade maturity; organizations still need to assemble governance frameworks across instantiation, deployment, runtime visibility, and feedback loops.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode packs concrete technical details about Cisco's security tooling (Code Guard, MCP Scanner, Defense Claw) and the mechanics of securing agentic systems, but buries them under substantial filler (conference pleasantries, crediting G2, naming researchers, extended throat-clearing about frameworks). The substance that exists - policy manifests in agent code, continuous scanning of model and skill downloads, runtime observability - is valuable but takes up perhaps 5 minutes of a 12-minute segment.

Every single model that is hosted on hugging face has been vetted, validated by Cisco. And the results, they're off posted.
As the code is being written It is checking for whether it adheres to the policies. Of the organization, literally, as the agent is being built, the code there is a manifest on top in that agent file in which we specify.

Originality

11 / 20

The specific implementation details - Code Guard policies embedded in agent manifests, continuous MCP server scanning, integration into IDEs as developer-friendly guardrails - are differentiated and concrete. However, the broader framing (trust as constrained element, need for taxonomy, observability in agentic systems) rehashes conference consensus. The practical tooling is fresher than the conceptual scaffolding.

You cannot have a publicly routable address. In IP address. In the code. You cannot have username, password, you cannot have blah, blah, blah, whatever. Yeah. The distillation of the security policy set by the security team is presented in the manifest of every code.
So as you're working without you having to spend more cognition cycles on, like, should I do this? Shouldn't I do this? Da, da, da. It is doing it with you, along with you as the code is being built.

Guest Caliber

13 / 20

Raj Chopra is SVP and Chief Product Officer at Cisco Security - a credible practitioner at scale with direct accountability for shipping security products. However, this is a 12-minute hallway/booth interview at a conference, not a deep-dive with a founder or operator who built something from zero or weathered real operational crisis. The guest's seniority is real but the format and depth limit impact.

Raj Chopra, who is SVP, and the Chief product Officer. Of Cisco security.
Everything that I'm seeing, and we develop a lot with AI at Cisco, IT and AI, forward development cycle, et cetera. It's very, very exciting. Also scary at times, but very exciting.

Specificity & Evidence

14 / 20

Strong specificity on implementation: Hugging Face model vetting at scale (~1.2-1.5M models), Defense Claw as the integration point, Code Guard policies in manifests, MCP server scanning, skill file validation, and open-source contributions (Cilium, Open Telemetry, VPP). Weak on numbers: no specific attack data, no quantified risk reduction, no customer case studies, no timeline for enterprise-grade deployment. Evidence is architectural and example-heavy but not outcomes-heavy.

Every single model that is hosted on hugging face has been vetted, validated by Cisco. And the results, they're off posted. Yeah. So if you go to hugging face.co, look up a bottle, it will have a score under CLM av.
Between Code Guard, which is this Yeah. MCP Scanner Skills Center. Moral, validation, et cetera, et cetera.

Conversational Craft

8 / 20

Leonard Lee asks soft, summarizing questions rather than pressing for depth, edge cases, or disagreement. He affirms repeatedly ("you hit the nail on the head," "that's exactly what") and allows Raj to make uncontested claims about trust being the most constrained element without asking for evidence or counterargument. No real follow-ups on risk, no productization timeline specifics, no pushback on whether these tools actually reduce breach likelihood. The host is a gracious interviewer but not a rigorous one.

You hit the nail on the head. Everything that I'm seeing, and we develop a lot with AI at Cisco, IT and AI, forward development cycle, et cetera.
Yeah. You heard it, you just heard it. Yeah. From Raj. Yeah. This is very, very important.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cisco12code12open7thank7security6blah6brought6team6agent6conference5together5trust5claw5server5grade4forward4

Episode notes

Send us Fan Mail The topic of agentic security was a very big one at RSAC Conference this year. The conversation was split between safe and secure agentic AI enablement for the enterprise (and consumers), and the agentic enablement of threat actors armed with a new generation of AI tools. The second part of our conversation with Rajneesh Chopra, SVP and CPO of Cisco Security, touched on the crisis of trust that we face, and the framework that Cisco is contributing openly to help foster safe, enterprise grade GenAI and agentic AI applications. Raj does a great job of outlining a holistic blueprint that Cisco is working off for safe agentic AI and enterprise GenAI. Bottom line, Getting to safe agentic AI is a journey with many twists and chasms along the way. We are in the early rounds facing a threat environment that is highly fluid and moving at machine speed. It will take a mindset of safe AI innovation that preemptively injects what Raj calls "common sense" in lieu of lagging best practices to meet the challenges and threats of fast-evolving AI-assisted cyberattacks. Please

Full transcript

12 min

Transcribed and scored by The B2B Podcast Index.

Hey everyone, this is Leonard Lee, executive Analyst at ncur. And welcome to this little vignette that I'm cutting here at RSAC conference, 2026. So I have Raj Chopra, who is SVP, and the Chief product Officer. Of Cisco security.

That's right. One of the things I, posted in response to, or in reaction to G two's keynote, was that there is this quality aspect, and this is like probably gonna be an important element as you look at, the value that agents can deliver. It fundamentally has to be secure. Yeah.

Has to be fundamentally safe. Yeah. Which this is what G two talked about on stage. Yeah.

But then there's this emerging element of quality. Does. Is it accurate, right? Yeah.

is it, reliable? Yes. Is it trustworthy? And these things all come together to fundamentally determine whether or not something is actually consumer grade, industrial grade, or enterprise grade.

Right? You hit the nail on the head. Everything that I'm seeing, and we develop a lot with AI at Cisco, IT and AI, forward development cycle, et cetera. It's very, very exciting.

Also scary at times, but very exciting. Yeah. I would tell you from where I, stand That trust is going to be the most constrained element in this agenda world. Right.

It is going to be trust or lack thereof. Right. Yeah. You heard it, you just heard it.

Yeah. From Raj. Yeah. This is very, very important.

Yes. And part of that also comes from how do you formulate trust, how you build trust, and trust gets built, by adherence to what you say you're gonna do. Yeah. So that observability in this entire interaction.

That is very, very expansive, is very important. Yeah. And I don't think that taxonomy of thinking exists today. I think it's in bits and pieces, it's not well-formed.

Yes. Right. you have like ethical ai, trustworthy ai, blah, blah, blah ai, but they're not, arranged and layered in a way where. You can have the essential conversation.

And this is what I'm gle what I've gleaned, through the course of this conference, but also through some of the messaging that you guys have brought together. Cisco, yeah. Security in particular and G two. Of you always have to give credit to G two, right?

I mean, he brought the conference. Yeah. But this is where, credit is genuinely, due to G two and the team, the very large team that, he, I, or many of us represent, now our contribution Into this whole aspect of AI coming from a, again, a practitioner's perspective. Yeah.

is that we have, as Cisco, we've not just built these frameworks. AI frameworks like taxonomy and how you think about it. The classes of attacks and because the, yeah. In, security we call about TTPs tactics.

Technology and processes, they are gonna be distinct. So Cisco has contributed, not just came up with a framework, we have contributed Back into,, the community. Working with Mitre and other agencies. So we're not like overshadowing Sure.

somebody that is not the spirit of it, but adding to that. Dialogue. Adding to that community understanding where there is a very rich source of that taxonomy that we have brought into the market. There are phenomenal researchers, in the team, one who has worked very hard at it.

I'm gonna call her out, Amy Chang. If Amy, you're listening to this, you're amazing. but again, she is also part of a larger team that does phenomenal work. We have foundation ai, which is another, really forward thinking, AI specific sort of people.

These are researchers from the best, the top universities, tenured professors from Harvard and yeah, yone and his team, others who have done phenomenal work. and then there is this. heritage that Cisco has had of bringing things to open source. Yeah.

Right. Whether that is open telemetry through Splunk, whether that is cilium with is surveillance, whether way back when. there are many technologies. ECMP, VPP, there are lots of them that we brought in the market.

But one of the other things that we are rather brought it to open source. We have one with the, that has a claw in it. Yes. So that is exactly what, right.

I was gonna say that Defense Claw has, defense Claw has sort of tied a bow around many of these quote unquote projects that we have, that we've that we have contributed to. Open source. Yeah. Key word hooks.

Yes. Hooks. Hooks. So the way developers now, we're shifting personas to developers building these agents, or building applications.

with ai, nobody sits and say, I'm gonna write a model. Most of them download. You're gonna go here. Oh, okay.

Come on, let's do that. So, I mean, most people will start that journey by going to hugging face. Yeah. Every single model.

I think last that I checked, they were a little shy of 1.5 million, but, definitely more than 1.2, 1.3.

Every single model that is hosted on hugging face has been vetted, validated by Cisco. And the results, they're off posted. Yeah. So if you go to hugging face.

co, look up a bottle, it will have a score under CLM av. It doesn't say Cisco, it says CLM av. That has been done by Cisco and we continually do this. Yeah.

Okay. so you download the model. Now you're working maybe in an id, maybe off CLI or what have you. But then for this thing, this entity that you're building, co-developing with an with.

With something Ag agent, whether it's cloud or Codex or what have you, it needs to talk and it's gonna talk through an MCP server. Guess what? Nobody builds an MCP server either. Right.

This is stack overflow on steroids. Nobody builds an CP server. They download one. They give it a personality.

Bad guys are gonna go where people spend most of the time. Yeah. Hugging face. Yeah.

MCP server downloads. Absolutely. So we scan the MCP server. Okay.

How does functionally get added to these agents? They add skills. We scan the scale file. Well, agent to agent, so on, so forth.

In fact, when it is writing code We also open sourced a thing that Cisco it developed, which is called code guard. So as the code is being written It is checking for whether it adheres to the policies. Of the organization, literally, as the agent is being built, the code there is a manifest on top in that agent file in which we specify. Okay?

Right. You cannot have a publicly routable address. In IP address. In the code.

You cannot have username, password, you cannot have blah, blah, blah, whatever. Yeah. The distillation of the security policy set by the security team is presented in the manifest of every code. That is being generated in that IDE as you're building the agent.

Hmm. That is code guard. I did not know that. Yeah.

So that package of things that we've had brought together Into an extension Is now available with defense. If you are a developer, your organization or you yourself, yeah. Could just literally have that as an extension in your id. So as you're working without you having to spend more cognition cycles on, like, should I do this?

Shouldn't I do this? Da, da, da. It is doing it with you, along with you as the code is being built. There is a lot of other code that has been written that is not great.

I'm not talking about that yet, but all of the new code that is being written, it is going to be more secure than we've ever had, in the past. And it's because of things like this. Yeah. So between Code Guard, which is this Yeah.

MCP Scanner Skills Center. Moral, validation, et cetera, et cetera. We are bringing common sense. We talked about best practices.

Nobody knows best practice because it's happening so quickly. But we are restoring sort of common sense back into the stack. Yeah. By enabling the developer to do the right things Yeah.

Rather than forcing them to do the right thing. Yeah. And that's something that we're hearing a lot about here. At the conferences, foundations.

Yes. And, in a rapidly shifting environment, being able to make that foundation extensible and then extending it, like what you're talking about here with, defense Claw, right? Yep. Because, one of the things that I've published recently is that we're too early to claim that we have enterprise grade.

open claw of any sort. Yes. Right. So all these artifacts need to come together in order to provide the tools and the practices.

As well as the governance around the entire life cycle of these things. You can't just think of it in terms of instantiation deployment. It's like how do you monitor, have visibility to these things in runtime? And then close the loop.

Because, and you have all these different timescales, like one of the things you pointed out is one of these things can be spawn in like a second. Yes. And so these are new dynamics, as organizations, developers are looking at, the agentic future that they have to deal with. Mm-hmm.

arriving at safe. It just got a little bit more complicated in my view. And so, we can go on forever because we're only supposed to do 15. Oh, geez.

Wow. Okay. See we're having way too much fun and I think this is just the tip of the iceberg of our conversations. I have to be honest, I have a ton more questions.

I think there's many explorations that we should do together. Sure. Because it certainly looks like Cisco has its, head around, where. Things need to go in terms of enterprise enablement for AgTech as well as ai.

'cause to be honest with you, I don't think we've even cracked a code on a lot of the, previous, iterations of generative ai, whether it's the LLM or RAG or what have you there, there's still a lot of open challenges. Yep. I'm looking forward to continuing to explore Absolutely. The problems with you guys.

Absolutely. And also discussing the solutions and how you guys are, bringing them to your customers. So yeah, it was, look forward to it. Really, really great conversation.

Thank you. Thank you very much. But thank you so much. You got it for this opportunity to, chat with you.

Yeah. Reporting live from RSAC conference, 2026. Leonard Lee, executive Analyst at Ncur with Raj Chopra, SVP, and, chief Product Officer of, Cisco Security. Yep.

So thank you so much. Thank you, Leonard. All right. Enjoyed the rest of the conference.

Thank you. Thank you very much.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Doing AI Is Easy. Doing It Well Is Hard.AI Proving Ground Podcast · features Raj Chopra70 / 100
  • How Kubernetes Audit Logging Causes etcd Performance DegradationDevOps Daily with Fexingo · on Splunk91 / 100
  • Lewis Tunstall: Hugging Face, SetFit and Reinforcement Learning | Learning from Machine Learning #6Learning from Machine Learning · on Hugging Face89 / 100
  • Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee RosseySecure & Simple · on Splunk86 / 100
  • Modernizing your threat huntTalos Takes · on Splunk86 / 100
  • Mirko Novakovic on Waves of Innovation and Observability Product ManagementCaSE: Conversations about Software Engineering · on Open Telemetry86 / 100

More from The neXt Curve reThink Podcast

All episodes →
  • Silicon Futures for May 2026 - Qualcomm hyperscale AI, Cerebras IPO, Huawei 1.4 nm68 / 100
  • Edge Continuum: Where AI belongs from sensors to cloud (with Azita Arvani)86 / 100
  • Edge AI Foundation at Sensors Converge 2026 (with Pete Bernard)55 / 100
  • Silicon Futures for April 2026 - The AI CPU craze, Qualcomm's custom AI, Google TPU 8 explained80 / 100
  • The Unknown Unknowns of Agentic Security (with Raj Chopra)80 / 100
Explore the best B2B AI & Data podcasts →
All The neXt Curve reThink Podcast episodes →