Can security teams defend an organization when attackers are using AI to research targets, personalize messages, identify weaknesses, and launch campaigns at a scale no human team can match?
I returned to Alpbach, Austria, for Barracuda TechSummit 26 and caught up with Neal Bradbury one year after our conversation about being secure today and ready tomorrow. A lot has happened since then. Agentic AI has become a boardroom subject, employee AI use has spread across businesses, and attackers have gained access to tools that lower the cost and expertise required to launch sophisticated campaigns.

Neal explains why Barracuda has continued with the unified platform strategy introduced at last year's event. In his view, AI creates additional exposure across identities, applications, email, and data, but it does not make every existing security control obsolete. The immediate requirement is to connect information across these areas and accelerate how quickly security teams can interpret and act upon it.
We discuss Barracuda ONE, its Barracuda IQ intelligence engine, the Bailey assistant, Integrated Email Protection, and the recently announced Barracuda AI Data Security offering. Neal also explains why the acquisition of Evo Security adds identity protection at a time when businesses must secure human users, service accounts, and AI agents.
One customer example shows why connected telemetry matters. According to Neal, Barracuda's team investigated an attempted wire fraud worth almost a quarter of a million dollars. No single product could see the complete attack. Information from email, network activity, and identity systems had to be combined before the team could understand what was happening.
Our conversation also examines shadow AI. Employees are already placing workplace information into chatbots and using tools outside approved systems. Neal argues that attempting to ban every tool will send that behavior further out of view. Organizations first need to understand which services are being used, educate employees about the information they can share, and guide them toward approved options.
Attackers may have gained the early advantage from AI, but Neal says defenders are catching up through automation. Work that previously took around 45 minutes can now be completed in under a minute inside Barracuda's agentic SOC. The aim is to correlate signals, remove repetitive analyst work, and present fewer alerts with better context. Human judgment remains part of the process when accountability and empathy matter.
Do you agree that AI favors the side that automates most, or could excessive automation create another security weakness? Share your thoughts.
Useful Links

[00:00:00] AI agents are only as strong as the data that they're given. When provided with an outdated data set, your agents could end up doing more harm than good. But not with Denodo. With an AI data layer built within your platform, your agents are provided with real-time data changes. So with Denodo, your agents can finally make the right business decisions. Simply visit denodo.com to learn more.
[00:00:27] How do organisations defend themselves when AI gives attackers the ability to research their targets, personalised phishing emails and launch campaigns at a speed that no human team can match? Well, last year at Barracuda Summit 25, Neil Bradbury joined me on the podcast to discuss
[00:00:51] being secure today and ready tomorrow. But fast forward 12 months later and once again I find myself back in Albach, Austria. And tomorrow appears to have arrived rather quickly. So today Neil is going to explain why Barracuda believes the AI era doesn't require businesses to abandon their existing security strategy, but requires them to accelerate the platform work that is already
[00:01:19] underway. Shadow AI, non-human identities, email attacks, managed XDR and Barracuda's recent acquisition of Evo Security. And Neil will also share why defenders can compete with machine speed attacks, provided that they connect their security data and automate enough of that initial investigation. And his conclusion is wonderfully direct. AI favours who automates the most.
[00:01:48] But enough spoilers from me. Let me introduce you to Neil right now. Today we're recording live at the Tech Summit in Alpbach, Austria with my good friend Neil C. Hughes again. And it was what, 12 months since we last spoke in this beautiful setting. Tell me what you've been up to since we last spoke. You know, it's always good to talk with another Neil. There's not a lot of us. This is kind of fun. So this is awesome. It's great to see you again. Look, in the last year we haven't been
[00:02:16] standing still. We've been executing and getting going. So for us, it's really been, in Tech Summit 25 last year we named Convergence as that theme, right? This year it's been all about how do we go and deliver Barracuda one and make sure that we apply some AI to it, right? And executing. So for us, integrated email protection, I don't know if you've been saying up, like June of this year was a really, really big release for us. And for us, why did we do that? We did it because in the
[00:02:44] agentic era with all this AI stuff happening, email is going to be one of those threat factors that gets totally taken advantage of. Because how do agents communicate? Email, right? And so we needed to make sure we doubled down on that. We haven't done an acquisition in a couple of years. So we acquired Evo Security in July of this year. So super excited to have the Evo team join us as we go down this path of, again, agents. How do we help businesses in the use of AI? Identity is going to be where it's at. I know you've got some questions coming up on that. So
[00:03:12] we're going to talk on that, right? How do you fight machines with machines, right? Because that's really how we're going to win this battle as we go forward. And so literally rebuilding the SOC. And then last, but certainly not least, today's a big day for us. We launched Barracuda AI data security to really help our customers and help our partners truly have a solution that can give visibility, governance, and controls to a business's use of AI. So probably a longer answer than you wanted, but we've been doing a few things. Yeah, you certainly have been busy. And before we
[00:03:42] talk about everything about the event and what you've been doing at Barracuda, you said at the beginning, it's great to speak with a fellow Neil. And I've got to ask you this because I'm asking every Neil I'll meet at this at the moment. Have you ever been called Ian or a different name? I was speaking to another Neil recently and he said he keeps getting called Ian. And I've had it as well. Are you part of that club? I am not. I am not. The only thing I've been asked is like, you go out for coffee and they try and write the name on a cup, right? And sometimes it'll be like, Niall? Is Niall there? And you're like, nope, there's no Niall. But it's like, oh, they're talking
[00:04:11] to me. I need to go get my coffee. That's the closest I've got. Oh, I love it. Well, if someone calls you Ian one day, you could join me there. But I mean, last year we met, the message here was secured today, secured tomorrow. Now, when you look back at the last year, what has changed most significantly in the threats organizations face and the way they defend themselves? And one of the reasons I asked that question is I went to 20 tech events last year. Nobody mentioned agents. Nobody mentioned authentic AI. Now this year, that's all everyone's talking. This will move pretty quick now, doesn't it?
[00:04:40] It's literally what you said. The AI adoption has accelerated faster than anyone expected. We were talking, you were on stage this morning presenting and like really coming into December, January. Everybody went home from the holidays and they started playing with the newer models from the frontier labs. And I think that was that moment where everyone realized, oh, this thing's real. Like there's some magical stuff. Now I know like you use AI to do the podcast and you've got all these tips and tricks, but even the tools you probably use over the past year have
[00:05:09] truly accelerated. And so as I think about like attacks, the attack surface has expanded across identity applications and data all at once. It's no longer just one threat vector. And so this AI effectively became almost a new surface with no established perimeter. Whereas we, you know, install a firewall, we'll protect the gate. It's going to be great, right? AI doesn't operate that way. And the other piece of it is if I think of it from the attackers, the economies
[00:05:37] have, the economics have really flipped. Launching a sophisticated attack has dropped substantially. You don't need a lot of skill anymore. You just need to go to the right dark web website, pick up the right AI tool. And as an attacker, you're going now, from my perspective, that doesn't mean that all is lost. The defensive side is still strengthening. We're using the exact same tools to strengthen the defensive and security teams can accumulate these tools faster than they can add
[00:06:06] people. And so with the right people, the right tools and agentic sock that we've been building will be okay. But this is kind of that last year, it's been this cat and mouse. And the tools are only making it more exciting. And in your keynote on stage today, you argued that the AI era doesn't require a new security strategy, but a faster progress with the platform strategy already underway. Why are you so convinced that existing plans almost remain, still remain fit for purpose? Totally. I'm still convinced the platform is the right strategy.
[00:06:36] For us, it's there's no one product category that we could invest in to control the AI opportunity or make AI usage safe for our customers, which is what it's all about. And so us effectively going and platforming and bringing our portfolio together is absolutely still the right strategy. The thing that changed is we got to go and we got to go faster. And so that's really what you're seeing is the speed of execution, not only because we're able to leverage these tools to implement it faster,
[00:07:02] but the speed under which changes are happening in the market is happening. So the platform in my mind is still the right way to go. Also, Barracuda is very, very unique. Barracuda IQ, our AI engine, it powers Bailey, it powers some of our other items. That is unique to us. It allows us to have all the threat intelligence and the telemetry coming from all of our various product groups. And when you put some AI on that, the things that we can correlate and the things that we can do, absolutely the right thing to do with the platform, absolutely the right thing to do to
[00:07:30] protect our customers. And the only reason I wanted to ask that is there might be some security leaders listening that could argue that AI is introducing risks so different that it demands a complete rethink. So where do you agree with that view and where do you think that maybe it goes too far by trying to reinvent the wheel? Look, the fundamentals are still the same. You know, when we heard from Klaus Gehry, our VP of network security this morning, right? Engineering, right? He's like, you've got a lot of great tools. You have a lot of great solutions deployed. Of course,
[00:07:56] they're all Barracuda. And this is us just adopting the current security strategies, not throwing them out for the AI era. It basically shows a new surface. We need to make sure that sensitive data never reaches outside of the perimeter, right? Like if you, you and I, like I imagine what you have access to at work, what I have access to at work, someone gets my identity. Oh my God, it's a podcast now. So we'll see where this goes. Don't do that. Right. Right. But like what you basically have access to,
[00:08:23] it just makes it so that you need to make sure that Neil, the virtual Neil, the non-human identity are effectively protected. And that's not a new strategy. That's a modification of the existing security strategies that are in place. Even our CISO this morning, Arve Kajolin was presenting, right? Like he's doubling down on that. So we feel that we've got the right strategy. We're built, we're building the right thing for us. You know, email is still, and I know I brought this up a few
[00:08:49] minutes ago, but email is still where the attack's going to land first. And it's Barracuda. There's nobody better in email. So we know that if we can protect email from these agentic type of attacks, we'll be in decent shape. One interesting thing and random note, like, and I don't know if you've had this, we interview people. It happens, right? We're hiring people leave. We've had employees effectively go and submit PDFs. And what they're doing is they're changing some of the text to white.
[00:09:17] And so what they're doing is they're proving like, I know how to do security because I know that you're still going to read this. So imagine like you get a PDF and you highlight it, it'll show up. But if you don't highlight it, you never see that text. And so even people that are interviewing with security companies are realizing now they got to show their security chops. They got to differentiate, but an agent would pick that up. You or I just reading it, we wouldn't pick it up. That is incredible. A big tip for PayPal applying for security.
[00:09:44] And it's interesting you say our email will always be the front attack point there because a few years ago, email was dead, right? All these productivity tools, Slack and everything, but we all remain in email. And not only that, we're now getting AI and agents to help with our email. So 100%, right? And still the accountability tool. Yeah. You need a paper trail. You need a paper trail. It's still a paper trail. And of course at Barracuda, you spent several years bringing email, data, applications,
[00:10:11] networks, and identities, and threat responses all together. It felt like it was slightly ahead of the curve in doing that. But what evidence shows that this platform approach is proving better security outcomes rather than simply giving customers another dashboard, which of course nobody wants? Look, I'm super fortunate that we have a Barracuda. We have a red team that operates at our security operation center and they showed, you know, there was an employee or a CEO compromise, right? It was a wire transfer fraud. It was worth almost a quarter of a million dollars.
[00:10:41] And they were able to do this or they were able to kind of help a customer. And there was very little effort for them to do that, but there was no single tool that would have seen that entire chain. The only thing was us having all of the connected telemetry from email, from network identity, you could actually then see what was effectively happening. And so this is really what AI is changing the game. It's basically turning all of these fragments that we get from all our telemetry into one story. And that's where the red team and that's where the SOC basically
[00:11:11] accelerates. For us, it's really, it's the number of outcomes and the incidents that we can resolve, less so all of this noise and all of these alerts coming in. And so it's more about less, more impactful alerts, more context. And again, being part of this platform, that is the evidence. Like we're not just saying, oh, look, we found an issue. We're only using email. We're able to use evidence from all of the different surfaces that we collect telemetry for whether by the way,
[00:11:37] that's a barracuda or not. I want everyone to use barracuda solutions, but we integrate with other third-party firewalls, other third-party solutions. And we're able to use that telemetry. And again, tell that entire story for what happened and hopefully, and prevent our customers from running into issues. And as employees begin using AI tools daily across workflows, I say begin, I know they're all doing it en masse, even in areas they're not supposed to be. So where are the blind spots starting to appear
[00:12:05] now? And which of those risks are organizations possibly most likely to underestimate? I feel like probably you've been doing podcasts a little while, maybe a month or two, right? Like, I feel like it's like what's old is new again, like shadow IT is now, it's now shadow AI. Yeah, yeah. B-Y-O-D. Correct. Yep. And so for us, it's like, how do we give visibility? It's like any executive, you can't prove what you don't measure. And in the case of security, you can't protect what you can't see. And so really,
[00:12:33] the blind spot is leaders, senior IT leaders, MSPs not actually understanding where their customers are using these tools today because they're in denial if they think they've blocked them all and they're not being used. And so now it's a matter of, as opposed to preventing it, it's understanding which ones and then putting a policy in place, guiding employees towards the right tools, the sanction tools. On top of that, we need to make sure that employees are trained to
[00:13:01] understand what to put into one of these tools or not. Like, I know we all probably have these family member stories, right? Like Brian said to someone this morning on stage, right? Chris had had one. I've had them where it's like, I had this file and I put it in a chat bot and it gave me the answer. It was great. And I'm like, use that for work? No, why? Is that a problem? I was just told to sign up and you're like, no, what are you doing? Right? And so this is kind of that blind spot. And I think it's partly visibility, partly education, and it'll go a long way.
[00:13:31] But the worst thing a business owner could do is say, don't use the tools because if you try and do a full stop, employees will do what employees do. They will circumvent and they will use their own device and they will find a way around it. Yeah. They always have an always will. And something else I wanted to highlight is I use AI, you use AI. Everyone listening, all your employees, everybody here does, but attackers are using AI as well to improve the speed, personalization, and scale of their campaigns. So are defenders gaining the same advantages? I mean,
[00:14:00] it's always been a game of cat and mouse or is AI currently favoring the attacker? What are you seeing here? I don't know. What day of the week is it? What hour, right? I think attackers got the early, I believe attackers got the early advantage, a flawless personalized phishing attack, better impersonation of an executive. You can just scrape a LinkedIn, make a flawless email, think vendors or brands, reconnaissance. How much faster can you do reconnaissance? We heard from Adam
[00:14:26] this morning. Like literally they were looking for one port to be open to go and hack and someone, they found something else was like, oh, that's interesting. And AI told them how to exploit it, right? Like it just, they just pivoted. And so what that's doing is the volume and is also scaled beyond human capacity. And so this is the challenge. So the attackers got the early kind of advantage. I would say now the defenders not catch up is the wrong word. The defenders like, oh, I know what you're up to now. Right. And so we're now seeing that we can go and take things that used
[00:14:56] to take us 45 minutes to detect are now taking sub minutes to be able to detect. And it's because of the tools and this fully agentic sock that we've had. And this is why we effectively went and rebuilt it. And so it's not the attackers get the advantage or the defenders get the advantage. Truthfully, it's AI favors whichever side automated the most. And so it truly is almost an automation game and removing as much manual fragmented information that you possibly can and automating as much as
[00:15:22] you can. However, putting humans in the loop where judgment is needed, that's where we can't lose kind of our humanity, the empathy. Like we've got to make sure we still put humans in the loop. And I don't know if the attackers are doing that, but we're doing that on the defender side in a good way. Love it. Another big message here is managed XDR promising to turn billions of these security signals we're talking about into faster detection and response. So how are you at Barracuda separating
[00:15:49] meaningful threats from background noise without overwhelming an already stretched IT team with alert fatigue? Yeah, totally. Totally. I like that you call it managed XDR. It's almost like you've read our website. Thank you so much. Kidding, Neil. Kidding, right? So for us, look, it's about correlation, not the volume. So yeah, of course you have to make sure your system scale. I'm not disputing that fact. The teams would be like, Neil, it's not easy. Yeah, it is. You just figure it out. But it's correlation. And so the signals coming from email, identity, network data and applications,
[00:16:15] they're all connected to tell a single story that can be judged. Right. And so that's effectively how we're separating this alerts and making sure that we're minimizing the amount of alerts. We're getting rid of the noise. And I'm going to say, it's going to be like repeating theme from the last question, right? It's automation. It's how do you put all of this automation in place? How do you take a lot of the repetitive work off the analyst so that the prioritization and some of this stuff is just easier? And so that the volume necessarily doesn't matter. We have spent a ton of time
[00:16:45] putting agents in place in the SOC so that we can go and add this context, reduce the amount of alerts. And so we're only giving the highest priority risks. We're only giving the highest things that need someone's attention and trying to get rid of as much of the noise as possible, as opposed to us, like something maybe is going on in your hope, never in your environment, as opposed to getting an alert from a network device, the email, the identity, the systems can correlate all of that. And you get one alert, you don't get three. And at scale, that's really how we're doing it. And that's what matters.
[00:17:15] And there'd be many people from SMBs listening and some of those smaller organizations, they lack the people, the time and budget available to some of the large enterprises. So how can they adopt AI safely while avoiding a collection of security products that they can't properly manage or don't have time to use them all? They should pick the right vendor, Barracuda. Yeah. Oh, was there... That was a mic drop, man. Did you want more information? No, no, look.
[00:17:41] I go back again to visibility. And so regardless of the size of the organization, sure, you might not be a Fortune 500 organization. Sure, you might not have an enterprise security team. But at the end of the day, you want to partner with a managed service provider, partner with a channel provider. Maybe you have a single IT person picking the right platform that can help. That matters. And so in our case, it's, look, give them visibility. We do that
[00:18:06] effortlessly within the platform. And then from there, it allows the less sophisticated, I think they're the amazing jack of all trades IT person that every one of these businesses has to properly put the right guardrails in place, whether it's the CEO. Of course, they want more permissions, but they should have less, right? Give them the guardrails that they need. And then for us, we're leveraging all of our technology. So Barracuda AI data security, which was released today, is a perfect fit. Yes, another mic drop moment for these resource
[00:18:35] constrained businesses and MSPs. And that's all sitting within Barracuda One. It's powered by Barracuda IQ, and it's supported by Bailey, our chat assistant. So if they need help setting it up, they just ask the question to Bailey and Bailey will tell them what to do. Love it. And if we try and give people listening a valuable takeaway here, if listeners were to take one action after hearing this conversation, who are serious about improving the resilience in an AI driven world, what should they be doing first? I'm sure you get this a lot, but what should they
[00:19:04] be doing first? I mean, I'm going to sound like a broken record. They need to go find out where AI is being used in the organization, whether, I mean, do a survey, ask people questions. Like if you don't want to buy a security tool immediately, but I think people would be surprised at how many security or AI tools are being used. Look, humans are humans. They're going to walk from the shortest path from A to B, right? And AI is making it so that they don't have to go in circles and that it's the shortest path. And so if I'm giving any of this to CEOs or businesses of all sizes, you got to find
[00:19:32] out where it's being used. On the flip side, I would say as a business owner, this is a massive opportunity. If you're not using any AI type tools in your organization, like all stop, call your service provider, call your MSP, do some research online. There's a ton of podcasts. I'm sure you've done some stuff by AI, right? Because this is one of those moments, like it's that it's the cloud moment. It's the iPhone moment. This allows a business with one employee, 10 employees to compete with those
[00:20:00] that have countless of thousands and number of, number of employees. And so this is for me, like I get excited about this. I know we're at a sec, we're doing a security thing as a security event, but just from a sheer execution automation, this gives a tool to businesses all sizes that allow them to compete at a level that they've never been able to compete on. Because I'm super excited for what's to come in the next few years. And I guess we will have people listening here, that they work in an organization and the leaders have given them, they say we're a Microsoft
[00:20:28] organization and we've got co-pilot in there and that is enough. We're locking everything else down. And we know that every person in that organization is off doing their own thing with their own tools. Do you think they will be open to sharing the tools that they're using through fear of it being locked down or is it another way of finding what they're using? So yes, you can install Barracuda and we'll tell you what they're using, right? Another mic drop moment. Yes. You know, Barracuda One is a platform, get it installed, we'll tell you what
[00:20:54] it's using. But then I go back to, I'll give you the human answer. Like AI is a hearts and mind exercise. Yeah. It really is. Like I have an entire massive, amazing, cool, not massive, any more budget, tell that, but like engineering team globally that is doing amazing things. And this is one of those moments where it's a change for how they do their job. It's no longer a slot count or the number of lines of code that they write. It's literally the outcome that they can drive every single day using these
[00:21:21] tools. And so any business listening, like, yes, buy Barracuda One as a platform. I'll tell you what AI tools are being used, but there's a cultural thing here where leaders in the business, you need to use it, start using it, start seeing what's capable, whether it's co-pilot, whether it's Claude, whether it's ChatGPT, I'm sure you're using it, right? But like get visibility, but there's a cultural thing here in business that they need to basically accept or figure out how they want to move forward. And finally, when I think of the Barracuda Tech Summit, I think immediately two things. First of all,
[00:21:51] the stunning setting here, and I will include some video footage of just how stunning it is. It's awesome. One of the things as an outsider that walks in here, everybody's talking, everyone's collaborating, and that passion and community atmosphere shines every year. And from all those conversations you're having, both with customers, clients, and the community, what are you taking away from this year's event?
[00:22:19] Yeah, so I usually get to direct the conversation, so that's good, right? And so I would say, for me, a lot of the questions I'm asking is, what are you doing with AI? Are you automating your business? Are you not using it? And truly, it's a varying set of answers that are coming back. A lot of service MSPs and partners that are here are looking for, hey, how are you doing this? What should I be thinking about? How should I build a service or a practice around this? Any of the businesses that are here are just looking to get visibility. They're looking to protect themselves.
[00:22:47] There is probably a little bit of like an unknown or a fear. I don't want to use that word in a security conversation, but there is this unknown. And what does it mean? I don't think that the model companies, the frontier model companies that are out there have done a great job at like helping the narrative, right? And you're in news like you know. So for this, those are a lot of the conversations that I'm hearing and that I'm seeing. And everyone just wants to protect their customers and figure out how to do it easier every day.
[00:23:15] Awesome. I think that's a perfect moment to end on. For people listening who just want to find any more information, anywhere you'd like me to point them to? I mean, barracuda.com is probably the best spot. You point to the website. I'll include a link there and to your personal LinkedIn. A massive pleasure as always. See you same time, same place next year. Sounds good, Neil. Thank you. I think Neil's argument there that AI favors whoever automates most offers a very useful way to think
[00:23:40] about the security race. Attackers gained an early advantage through faster research, convincing impersonation and campaigns that exceed human capacity. Defenders though, they're now using the same technology to reduce detection times from around 45 minutes to under just one minute. So automation alone, that cannot carry the responsibility. Instead, organizations need
[00:24:07] visibility into where employees are using AI policies, policies that guide them toward approved tools. And people who can apply judgment when the consequences demand it. Simply blocking every AI tool will probably encourage employees to find another route. So again, big thank you, Neil, for joining me here at the Barracuda Tech Summit. You can learn more at barracuda.com. But where should your security
[00:24:34] team automate without hesitation? And where should a human always remain responsible for that final decision? As always, let me know. TechTalksNetwork.com. I'd love to hear from you on this. But it's time for me to hit the show floor once again. So I'll be back again tomorrow with another guest. Thanks for listening. Bye for now.

