
The neXt Curve reThink Podcast · 2026-04-23 · 13 min
Key moments - from our scoring
Substance score
60 / 100
Five dimensions, 20 points each
The discussion centers on securing agentic AI deployments as enterprises accelerate adoption of agent-based systems. Raj Chopra outlines Cisco's multi-layered approach: first, gaining inventory visibility of agents across major hosting providers using LANs integrations and heuristic identification of agent behaviors (memory, context, reasoning); second, implementing algorithmic red teaming before agents interact with production environments; third, minting durable ephemeral identities for agents to enable categorization and policy expression; and fourth, deploying scope-attenuation frameworks (drawing from standards projects like Macaroon, Biscuits, and Wafers) to trim permissions as agents call downstream tools. Chopra emphasizes that agents require agency and broad access to be useful, but this creates risk - the core challenge is expressing simple policy intent while preventing scope creep and unauthorized permission reflection. He stresses the industry is in early days without established best practices, requiring humility and adaptation of existing security principles rather than prescriptive solutions.
Agents exhibit three distinguishing behaviors: memory (retaining information), context (understanding the environment to react appropriately), and reasoning (planning, thinking, and curating inputs before taking action). Scripts lack these capabilities and heuristic methods can identify these behavioral patterns.
Durable ephemeral identities allow categorization and classification of agents over time despite their short lifespans (ranging from seconds to days), enabling enterprises to reason about agent behavior patterns and express security policies against agent classes rather than managing billions of individual agents.
Agents lack judgment and are purely task-oriented; they don't know in advance which data or systems they'll need to accomplish a prompted task, so they request broad access. This requires semantic inspection to detect when requested permissions don't align with stated intent.
These are standards-based projects for self-attenuating tokens that automatically trim the scope of permissions as agents call downstream tools, preventing agents from reflecting their full permission set in every interaction and containing potential misuse.
Policy should allow simple intent expression with rich vocabulary - such as 'printers talk only to print servers' - while infrastructure handles implementation across network layers (wireless, wired, switches, firewalls), rather than managing individual agent permissions case-by-case.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a substantive framework for agentic AI security (identity minting, red teaming, scope attenuation via macaroon/biscuits) that is genuinely novel and operationally relevant. However, execution is hampered by repetitive circling, vague transitions, and host filler that dilutes the core ideas. A B2B operator would extract valuable mental models but would need to sit through considerable verbal padding to get there.
one is that it has memory. As in it remembers. the second is context. What's the world that it's working on so that it can react Appropriately. And the third is it reasons it plans.
These are actual name of projects like after cookies and browsers, right? Where we have these, self attenuating a scope scope so that the scope that you've given, when the agent calls the next tool over, it gets trimmed.
The three-element definition of agents (memory, context, reasoning) and the scope-attenuation framework via macaroon/biscuits tokens are reasonably fresh in the context of enterprise agentic security discourse circa 2026. However, the framing around 'shadow AI' and red-teaming borrows from established security playbooks; the originality is in application rather than fundamental thinking.
one is that it has memory. As in it remembers. the second is context. What's the world that it's working on so that it can react Appropriately. And the third is it reasons it plans.
We're taking elements that we know are that work and work well, and then. Adapt to the new things, that that were not there.
Raj Chopra as SVP and Chief Product Officer of Cisco Security is appropriately senior and directly responsible for the exact problem domain under discussion. He is clearly a practitioner building the solutions in real time, not a consultant or thought leader. This is credible operator-to-operator conversation, though the interview format prevents deep proof of hands-on execution.
Raj Chopra, who is SVP, and the Chief product Officer. Of Cisco security.
We have a LANs of integrations with all of the major. hosting provider.
The episode names specific technologies (macaroon, biscuits, wafers standards projects, MCP servers) and concrete implementation patterns (ephemeral identity lifecycle, algorithmic red teaming, scope trimming), but lacks real-world deployment metrics, customer examples, timelines, or quantified security outcomes. A B2B operator knows *what* Cisco is building but not *how well it works in practice* or *who has deployed it*.
These agents might run for five seconds. They might run for five minutes. Yes. They might run for five days. Right. But they're ephemeral and they will come and go.
Projects called macaroon and biscuits and wafers. These are actual name of projects like after cookies and browsers, right?
The host Leonard Lee asks directional questions that surface Chopra's framework, but fails to press on critical gaps: no deep follow-ups on false negatives in heuristic detection, no pushback on the scope-trimming mechanism's effectiveness, no interrogation of real-world deployment friction. The interview feels cordial but incurious; a stronger host would have challenged Chopra on unproven assumptions or demanded concrete evidence of the framework's success.
Maybe you can share with the next curve audience. Some of the things that you're announcing. at RSAC conference this year
The examples that you're providing, triggers even more questions. Yeah, right. Absolutely.
Computed from the transcript - who did the talking, and the words that came up most.
Send us Fan Mail It was a busy week at RSAC Conference 2026. The topic of agentic security was a very big one, whether you were contemplating it for securing agents you deploy in your enterprise or protecting it from malicious AI agents. neXt Curve's Leonard Lee had an enlightening conversation with Raj Chopra, SVP and CPO of Cisco Security, about what the company is discovering about the path to enabling safe and secure agentic AI. What impressed was the humility with which Raj approaches the task. We are dealing with unknown unknowns in the age of agentic AI. Yes, agentic AI is here, whether we like it or not, as a productivity tool or a threat. Check out this conversation. Raj highlights some priorities and approaches that we agree with based on neXt Curve research. He also introduces some additional angles that CISOs and security practitioners need to contemplate in approaching safe agentic AI for their organizations. AI security will require the cybersecurity community to think beyond its comfort zone. Yes, fundamentals matter more than ever, but the threats and the countermeasures are unknown. We hope you find part one of this conversation with Raj Chopra informative.
Transcribed and scored by The B2B Podcast Index.
Hey everyone, this is Leonard Lee, executive Analyst at ncur. welcome to this little vignette that I'm cutting here at RSAC conference, 2026. So I have Raj Chopra, who is SVP, and the Chief product Officer. Of Cisco security.
That's right. So this is basically your show, right? This is our show. I stand on the shoulders of an incredible team that is doing a lot of work.
It is an honor to represent their work. So it takes a team. One of the things that I'd like to start off our conversation with is, this, growing specter. Of shadow ai.
Yeah, Especially now that everyone's getting excited about agentic. Ai. they're looking at bringing that into their organizations in some form. G two was up on the keynote stage.
And one of the big themes that Cisco is going forth with this year is, the enablement of the ag agent workforce, but obviously. One of the things that we're hearing at the conference is this concern about threat actors using the same tools, right? Absolutely. And so that makes the concerns about security and the ability to, deliver, let's call it enterprise grade or enterprise safe, agentic AI or AG agentic workforces.
Probably more challenging. So I'd love to hear your thoughts on that. But then also Cisco bringing to the table Yeah. This year to make the agent workforce safe and secure.
Yeah. I think the pace of change, yeah. The compression of, how many things are happening in a very, very short period of time is what makes it, even more remarkable. It used to be purchased by companies and then the users would experience and then it became where users were bringing in technology into the organization.
Right. Yeah. and this is exactly what is happening. All of us individually found so much good use out of these tools.
People are like, why wouldn't I use this tool? Right. Because it was helpful. Anything before 2022 is.
By the way, dinosaur. Right, right, right. Any, the world only, is living in the technology unleashed since November, 2024. Sorry, 2022.
We are gaining so much of this productivity boost in our general lives, that not bringing it to our professional lives just seems like weird. We may call it shadow, but I'd much rather the industry came around to beneficial. AI and things that are not, as beneficial because AI is gonna be everywhere. There is no shadow.
Right. Right. It is, it is everywhere. Now, the effort that you have right now is to.
Get that visibility observability so that nothing is in the shadows. Correct? Correct. The first one is to go to the obvious sort of repositories where agents, the so-called beneficial ai The ones that are, meant to be used more broadly, that you can recruit those into your own full fledge sort of LANs of where these agents are.
We have a LANs of integrations with all of the major. hosting provider. It's never done, like there is always something new, but we can pull information together. From all of these, places.
in addition, there are other heuristic techniques that we used. Remember in the days of the botnet, you can't ask a botnet, are you a bot? Right. You can't say, okay, here's a capture or whatever.
Yeah. But there are heuristic methods that you apply To identify whether this is just a script that is being called or it is an agent. Right. And the key part of an agent are three elements in my mind.
one is that it has memory. As in it remembers. the second is context. What's the world that it's working on so that it can react Appropriately.
And the third is it reasons it plans. It thinks and then takes an input, curates it gets more further input, chisels it down. It is a reasoning. Those three elements make an agent..
And we lean on those kinds of behaviors to heuristically get to this is an agent versus just a script regarding identity, agent identity. Last year, that was an emerging topic. People were scratching their heads wondering, okay, how are we gonna do this? Yeah.
I've had some interactions with your duo team over the course of the year, some great stuff, but maybe you can share with the next curve audience. Some of the things that you're announcing. at RSAC conference this year that can, inform CISOs out there and enterprises and boards. Boards, okay.
You need to be educated on this stuff, that it can give them some confidence that, agentic AI can actually happen in a safe way within enterprise boundaries. So once you have a. Repository of these assets or inventory, I think is a more appropriate term. So now that you have these agents in your environment, you're not gonna just let them run amok.
Absolutely right. So you have to do a posture check of these agents. In the modern world that is called red teaming, we do algorithmically red teaming. For every agent that we have, I read before it can start interacting In the environment.
That's just good practices brought into the ENT world. It's, but doing it in a manner that is fluid. That is, natural. For it to be done.
The third part is a pass muster from the red teaming is then to give it a new identity mint, a new identity. These agents might run for five seconds. They might run for five minutes. Yes.
They might run for five days. Right. But they're ephemeral and they will come and go. One wants these identities to be durable.
So you can categorize them. You can classify what kinds of things that they're doing. Why if you ask an enterprise, they don't manage one URL at a time. In their environment.
It's too many. Yeah. We are not going to manage a hundred billion agents, one agent at a time. There needs to be categorization.
Yes. And that categorization. In due time is gonna come become very important. As a means for you to express your policy in your environment.
We're looking at a future of where security policy is be going to become much more complex than what we've dealt with before it would be simpler to express the intent. But the vocabulary will be rich. You should be able to specify the intent of your policy. I'm gonna give you a super simple example.
Okay? I have printers in the office. Printers should only directly talk to a print server. Period, you should be able to very simply express that intent.
And how it gets implemented in the capillaries of your network, wireless wired switch, firewall, et cetera, et cetera. That is plumbing. And so to be able to express that policy simply and ensure that it is effectively enforced on the infrastructure that you have. That's the combination.
That you're looking for, right? Right. That's where this authentication, where you're minting a new identity, keeping it around durably. So you can reason with it, you can categorize, you can classify over a period of time, build facets.
That can be expressed in the policy construct is how we are going to start to manage some of the basic policies around agents. going forward, the next step after that. is a very crucial, which is like, okay, I've given you an t I've made sure you're fit for purpose. I need to make sure that I can express what is it that you can do As an authorization, right.
And, this is, probably one of the most crucial things because agents only become useful. when they take on agency, they take on the responsibility of doing whatever is needed. Yeah. And what that means is that you have to have access to a lot of systems.
As an agent, I don't know what all data I'm gonna need to accomplish the task that I'm gonna be prompted to do. So this is the stuff that we are working with, standards bodies, working on these, Projects called macaroon and biscuits and wafers. These are actual name of projects like after cookies and browsers, right? Where we have these, self attenuating a scope scope so that the scope that you've given, when the agent calls the next tool over, it gets trimmed.
Yeah. Interesting. 'cause the craziness that happens is when an agent is using all of the permissions that it has. Mm-hmm.
To then reflect those in every interaction. That is where trouble starts. Yeah. And then you keep a track.
it is like, there is an audit, if you will, of all of the, attenuation, the scope trimming that has been done. Yeah. So that these things don't go off the rail, so to speak. Yeah.
The examples that you're providing, triggers even more questions. Yeah, right. Absolutely. About and some of the, challenges that enterprises and companies like, solution providers like Cisco will have in the journey going forward.
Yeah, in my view, this is still a very early phase. of agentic security and agentic safety. But it is encouraging to hear what Cisco was doing to actually create that foundation because it's. Without that foundation, you just simply can't, becomes, can't have safety around this.
Yeah. And we are learning this together, right? Yeah. That'll be well be, I have, it'll that level of humility know that there is no ivory tower.
Somebody can sit in and pontificate, this is how you're gonna do it. Right. Again, because it is all happening in such short time. There is not chain speed.
Yes. Because there is no time to really come up with the lived experience of best practices. Yeah. Right.
We're taking elements that we know are that work and work well, and then. Adapt to the new things that, that were not there. So, for example, you're probably sick of seeing as many people as you've seen over the last 74, 7, 2 hours. No, I, I, I, I love it.
I love it. I love all of you. For you. May I do seriously, hypothetically, let's pick on me Hypothe.
Let's pick on. The agents are coming to you. Every surface area that you are, you and I interact with today is going to be agent. It already is, but you prompt your browser.
Yeah. To book me a vacation within one hour travel someplace that has a biking trail and I can relax and not too hot and blah, blah, blah. You and I on a browser would go to Google and say, Hey, what's the weather here or there? The agent looks for that.
MCP server asks for the same thing. Right? Right. MCP server says Great.
Please gimme read access to your files. You're like, what? I am asking you for weather and you're asking me for file access? Like that's bananas.
But remember, these agents don't have any judgment, right? Yeah. They're all task oriented. Have you ever had an interaction with an agent or a LLM that said, I don't know.
No, but they all know. They all know apparently. Yeah, but see, this is what I call it. It's called the illusion of judgment, right?
This is where you then need semantic inspection. Not syntactical, but semantic. Semantic infection. Yeah, Would say, I'm asking you for a weather forecast.
And you are asking me for access to my files. Like this is not even in the same zip code like it needs to be, at least the prompt and the inference need to be in conjunction to accomplish a certain task. Hey everyone, I hope you enjoyed this conversation. I found it very enlightening.
He's probably sorry that he did this because now I have a thousand questions instead of just a hundred. But thank you so much. You got it. Reporting live from RSAC conference, 2026.
Leonard Lee, executive Analyst at Ncur with Raj Chopra, SVP, and, chief Product Officer of. Cisco Security. Yep. So thank you so much.
Thank you, Lauren.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.