How should security leaders respond when AI-powered attacks compress detection and response windows from minutes to seconds?
At Barracuda TechSummit 26 in Alpbach, Austria, I spoke with Rohit Ghai, Chief Executive Officer at Barracuda. The conversation took place exactly one year after Rohit joined the company, giving us an opportunity to discuss what brought him to Barracuda, what he inherited, and how his first year has influenced his plans for the business.

Rohit explains that Barracuda's focus on smaller and resource-constrained organizations was an important reason he accepted the role. A cyber incident can threaten the survival of a smaller company, particularly when it has a lean IT team and limited access to specialist security knowledge. For these businesses, Rohit argues that AI-supported and increasingly autonomous security is a practical requirement.
We discuss Barracuda's platform strategy and why genuine integration must extend beyond a shared interface. Rohit compares loosely connected product portfolios to supermarkets. Customers may find it easier to purchase several products from one supplier, but that commercial convenience does not mean the products share data or produce a coordinated response.
Traditional tool sprawl forced analysts to interpret information across several screens. Agent sprawl could introduce systems that act independently, disagree with one another, or take conflicting actions. Rohit believes security platforms must connect information across email, identity, applications, data, and infrastructure so they can reason across the complete attack sequence.
Identity is another major part of the discussion. Barracuda's acquisition of Evo Security addresses privileged access for managed service providers and smaller businesses. Rohit expects machine and non-human identities to greatly outnumber human users, raising questions about excessive privileges and how organizations grant temporary access to autonomous agents.
We also discuss the economics behind AI security. Rohit explains how Barracuda is adapting its value reports to account for token consumption as well as staffing, software, and security outcomes. Barracuda absorbs the direct token costs associated with its own AI capabilities and selects different models according to the task, an approach intended to keep its products affordable for smaller customers and MSPs.
Rohit is cautious about calls for the AI industry to slow development. Coordinating a worldwide slowdown between companies and countries would be extremely difficult. He also argues that cyber defenders cannot pause while attackers continue using widely available models to improve their campaigns.
The conversation ends with a wider leadership question. Rohit believes intelligence will become widely available, making empathy and trust more valuable. AI can generate an answer, but customers, partners, and security professionals must decide whether they trust the organization acting upon it.
Will connected AI security platforms reduce complexity, or could autonomous agents introduce a new form of operational risk? Please share your thoughts.
Useful Links
Rohit Ghai, Chief Executive Officer, Barracuda
Neil: [00:00:00] So today we're here recording at the Barracuda Tech Summit in Alpbach, Austria. And today I've got a very special guest. Got the CEO of Barracuda, uh, joining me. Can you tell everyone listening a little about who you are and what you do?
Rohit: Absolutely. Uh, thanks for having me, first of all. And, um, I'm Rohit Ghai.
As you noted, I'm CEO of Barracuda as of, uh, exactly one year. Wow. Uh, and, uh, you know, I've been in, been in cyber for, uh, several decades. Prior to running Barracuda, I ran, uh, a heritage cybersecurity company called RSA. So I was, um, you know, I was grateful to have the opportunity to curate, uh, the RSA Conference, which as you may know, is one of the largest congregation of cyber thinkers and s- and, and cyber people in general.
So, um, again, uh, you know, very passionate about cyber. Grateful to be here at Barracuda to, uh, you know, keep my journey going.
Neil: Love it. And I've got to ask, what was it that attracted you [00:01:00] to the role? What did you inherit, and what have you learned in your first year? And the reason I ask that is in this age of AI and age of exponential, it's like a l- a lifetime.
It's like five years in old money. So- Right ... what have you seen in that five years? Yeah. Tell, tell me about the last one year, should I say.
Rohit: Yeah. That's great. So let's start with, uh, kind of the, you know, my, uh, the reasons that brought me to Barracuda, right? Yeah. And, and I, I put those into three buckets.
The first is, um, you know, purpose/mission. Um, uh, you know, I've been in cyber, as I noted, for several decades.
Neil: Yeah.
Rohit: And in the past, I, much like many other enterprise cyber players, was guilty of saying cyber risk is existential, but it never was for the enterprise companies. Whereas the smaller organizations, resource-constrained with lean IT teams, cyber risk is indeed existential.
Yeah. One cyber incident can take a business to, uh, out, [00:02:00] and as such, the mission is much more fulfilling because it's much more impactful. So protecting this strata of the market, which is the backbone of the economy, it's the backbone of our community, uh, it feels ve- feels like a very powerful mission.
Yeah. So that was reason one. Reason two is promise of AI. These companies don't have human expertise and capacity, so AI is not an option, it's an imperative. Mm. You must have AI-infused solutions that are autonomous, that don't require a lot of human expertise to operate. And finally, the power of partnerships.
Barracuda, unlike other contexts I've been, we are unconflicted. We... 100% of our business gets touched with partners. Yeah. So partner first, partner only. So those are three reasons that got me here, and, uh, and it's been, uh, it's been a great, uh, one year in regular time and five years in AI time, like you noted.
Neil: Yeah. And when you mentioned your career there, your leadership roles, RSA, EMC, Symantec, CA Technologies. Yeah. [00:03:00] What experience would you say, looking back, have influenced the type of CEO you wanna be and how they're shaping your leadership role at Barracuda? And it's a bit like that Steve Jobs quote, "You can't join up the dots looking forwards."
But when you look back-
Rohit: Yeah ...
Neil: what, what kind of things did you learn that maybe made you the CEO that you are today?
Rohit: Absolutely. , One of the main kind of centerpieces of my leadership philosophy is something that I call level five leadership. And that's, uh, you know, this is, um, this is from the book, uh, "Good to Great," Jim Collins.
Yes. Uh, you know, one of my favorite authors. This talks about this idea of putting, uh, the business first, putting, uh, the people in the business second, and then yourself last. And that concept is what I've tried to pursue throughout my learning journey. Mm. Uh, and, and in that learning journey, um, you know, the, the other moments and the other, other noteworthy things that have influenced, uh, my leadership philosophy have been [00:04:00] Uh, you know, I am, I am naturally gravitated towards, uh, organizations that need, uh, you know, call them, um, call them turnarounds, call them, uh, call them companies where the reality and the potential, there's a big gap.
And I enjoy come-from-behind wins. Yeah. Surprising the market, surprising the different stakeholders in terms of, you know, what the outcomes can be. So that drives me and, uh, tugs on my soul to, uh, to, uh, to take things forward.
Neil: And that really comes across in our conversation today. And I also wanted to highlight that Tech Summit is celebrating its 20th anniversary.
When you look back at 20 years ago, we're gonna-- five years ago and so much has changed. Never mind 20. When you consider how much cybersecurity has changed during that time, which problems remain stubbornly familiar? There was a great slide- Yeah ... in the keynote which shows how much is the same as well.
Yeah. And what are business leaders maybe underestimating?
Rohit: Yeah. I would say the [00:05:00] thing that has remained true in, in, in the journey of cyber is cyber, um, in general is a very technical field.
Neil: Mm-hmm.
Rohit: Right? And you can, you can kind of look at that, you know, even the terminology we use, right? We call the, the, you know, the defenders, we call ourselves white hat hackers.
Neil: Yeah.
Rohit: Right? As opposed to black hat hackers. And so we think of ourselves as highly technically proficient people, and so there is a natural propensity to think about the problem from a technical lens. Um, and that has remained true, and that I believe is actually a challenge. Mm. And the reason being, um, you know, if you think about,, cyber incidents and what actually causes breaches, right?
It's the most basic things.
Neil: Yeah.
Rohit: You know, most of the breaches occur by hack-- you know, the, the threat actor logging in versus breaking in. Identity [00:06:00] is a big part of how, you know, uh, cyber incin-incidents occur. Um, vulnerabilities, bad patch management. So, so hygiene, I call it, right? It's not that the cyber threat actors are exploiting zero-day vulnerabilities, really, um, sort of obscure ways to break in.
They are finding You know, the easiest ways to get in.
Neil: Yeah.
Rohit: And often just logging in. And so our propensity to be highly technical, we have a natural tendency to go after the most difficult problems- Yeah ... as opposed to taking care of the very basic, mundane things that are actually how the bad guys are breaking in.
Neil: And another thing that stands out here at this year's summit is how Barracuda is arguing that AI era does not require an entirely new security strategy, but simply a more faster execution of the platform strategy that is already underway. So why is the right response and, uh, or why is this the right [00:07:00] response, and where do you think the industry risks overreacting to AI, trying to do- Yeah
everything from scratch, reinventing everything is-
Rohit: Yeah ... what do you- No, absolutely. Look, I, I, I think I would, I would qualify that statement by saying, in order to win s- the cyber battle, if you will, uh, in the AI era-
Neil: Yeah ...
Rohit: the platform approach is the correct strategy. Having said that, that platform approach needs to be, uh, pow-- you know, it needs to have an AI component It-- you need a AI-infused platform, right?
Because the threat actor is throwing and hurling AI-powered attacks at us. The reason platform approach is needed is because at this point, the response time, the window during which w- you must respond is getting compressed- Yeah. ... to seconds, and it will be sub-seconds very shortly based on the exponential curve that the AI technology is on.[00:08:00]
In that world, when you have such small windows to actually detect, respond, and recover, y- you must connect the dots across different facets of the attack surface. You cannot reason on just email or just data or just identity. You have to reason across all aspects of the threat surface to respond quickly enough.
So that's reason number one for a platform approach.
Neil: Yeah.
Rohit: Reason number two is actually, you know, if you think about why the platform approach made sense in the pre-AI era, it was to solve this problem of tool sprawl. It was the problem that I, as a cyber defender, had to stare at seven different screens to make sense of what was going on.
Yeah. Right? It was this user interface fragmentation. Fast-forward to the AI era, all of these tools are now infused with AI. Yeah. They [00:09:00] have their own agents. So you move from a world of y- tool sprawl to agent sprawl. And if you think about the problem of agent sprawl, all these agents, if they don't agree with each other, that's a massive, massive problem.
Yeah. Right? Because these agents are... by default have agency. They are actors on the, on the network. So when they're conflicted, what actions are, are they going to take? And it actually might be counterproductive. So- Platform approach is absolutely an imperative in the AI era, but that platform needs to be infused with AI in order to keep up with the AI-powered threats.
Neil: And that tool sprawl that you mentioned, I can hear people nodding around the world as they're listening to this. We've all experienced it, and many have probably been burned by vendors describing the collection of acquired products as a platform, even when those tools remain fragmented beneath the shared interface.
So what does genuine [00:10:00] integration mean at Barracuda? W- and what evidence would you say to people listening be- who may be suspicious of such a claim because of what's happened in the past at different vendors?
Rohit: You know, that your comment, uh, resonates, uh, your question really resonates. I actually have a term for these wannabe platforms.
Neil: Yeah.
Rohit: You know, I call them a supermarket, where you've acquired a bunch of technology, or you've built a bunch of siloed solutions that are under the same commercial umbrella. So the benefit to the customer is ease of commerce. I can buy multiple tools from the same vendor.
Neil: Yeah.
Rohit: Right? That makes the process of buying easier, but it does not move the cause of cybersecurity forward, because these tools are still disconnected, still siloed.
So true, a true platform, in my view, is an integrated set of tools, but it goes further. It cannot just be integrated at the user interface level. [00:11:00] Yeah. Back to that story, it's not enough to s- to have the cyber defender looking at one screen. You need to be connected and integrated at the data layer.
Neil: Yeah.
Rohit: Because like we said, the response window is getting compressed. You need to reason over all parts of the attack surface to make sense of what's going on.
Neil: Yeah.
Rohit: To use a physical analogy, think about, think about a war, which cyber is.
Neil: Mm.
Rohit: If your, uh, air force and your navy and your army aren't communicating to each other, you cannot beat the adversary on the other side.
So in that same vein, you know, your different tools need to be talking to each other at the data layer in order to-
Neil: Yeah ...
Rohit: beat the threat actor.
Neil: And it's been a few years since Barracuda acquired anyone, but of course, you have acquired EvoSecurity, which attempts to [00:12:00] address identity and privileged access gaps for MSPs and smaller businesses.
So what problems were those customers unable to solve before? And why were, were, uh, or why was existing platforms too expensive or too difficult for them to operate?
Rohit: No, great question, and very near and dear to my heart. Yeah. So I've been in the identity space for decades, and if you think about the problem of identity, it's getting exponentiated in the AI era because you will not just have human actors, you will have agentic actors on the network.
And, you know, there are different numbers being thrown around, but You know, the number of machine identities or non-human identities would at least be 100X factor compared to human identities. And when you have such a vast sprawl of identities to manage and the corresponding privileges associated with it, the biggest problem in cyber is often [00:13:00] over-privileged accounts.
Neil: Yeah.
Rohit: And these machine actors, they, if they're over-privileged, that's a big, big, uh, target for the, uh, for the threat actors. So what you need is a solution that can scale to handle, uh, a exponentially larger number of identities-
Neil: Yeah ...
Rohit: and cover the bases for the non-human side of the house. The other piece is for our customers, which is the lean IT organizations, s- resource-constrained organizations that often rely on managed service providers.
These managed pro- managed service providers need to manage thousands of customer relationships, so it requires a multi-tenant architecture- Mm ... so you can manage privilege not just for one end user, but multiple customers and the privilege domain that they, they have. So, so Evo [00:14:00] Security was built from the ground up for this MSP-first architecture, and it squarely addresses this problem of over-privilege, and it implements privileged access management and assigns just-in-time privilege for human and non-human identities, which is a very relevant problem, uh, for the AI era.
Yeah. And, and an important part of our Barracuda ONE platform at this point.
Neil: I think it really is, 'cause MSPs want fewer disconnected tools, but some are also concerned about platform log, uh, lock-in, which we've seen at some tech companies that will name, remain nameless. But how can Barracuda reduce operational complexity w- while also preserving choice and avoiding that very dependency that, that partners increasingly question?
Is it a balancing act or-
Rohit: It is, it is absolutely a balancing act. We also recognize that the jou- uh, the, the path to a platform is a journey where you, uh, you know, embrace, uh, perhaps one offer, one offering [00:15:00] from a vendor. And therefore, one of our core guiding principles in the way we've architected Barracuda ONE is the concept of being open Uh, which means we must, uh, be a well-behaved citizen, a well-behaved neighbor to other technologies that'll sit alongside us and will integrate with those other technologies, because we don't expect to be, on day one, be the entire platform, right?
It'll be a journey. Yeah. So openness is a key concept for us that allows us to navigate this balancing act. The other point I wanna make is that, you know, in terms of the platform lock-in or vendor lock-in, you know, what we wanna do is we wanna make sure that our customers have a very clear, transparent view into the value and the ROI that they're getting from the platform.
Mm. So a very important feature in our Barracuda ONE platform is what we call value reports, which enables either [00:16:00] MSPs or security teams to get a very data-driven rendition of the ROI of the investment they're making in our platform, and how that compares perhaps to other siloed, uh, approaches that they might have used in the past.
So we wanna be completely transparent. If we can't earn it, we don't want it. And, uh, so, so, uh, so the Barracuda ONE, uh, transparency of value is one of the core principles that- Mm ... we believe will allow us to do the right thing as it pertains to, you know, this vendor lock-in, uh, conundrum that customers have.
Neil: And I would imagine that is so important right now, especially over the last 18 months, where return on investment of every tech project, particularly AI, is right at the top of the agenda after many, uh, w- could say wasted money or, or struggle to get things over the line, didn't get the business value that they expected.
What kind of feedback have you had from these value reports that- Yeah ... that you've sent out?
Rohit: Yeah. You know, the, the, the, there's a, there's a, there's a bright line in [00:17:00] terms of the value report feedback that- Yeah ... we've had. Uh, you know, quite honestly, the Barracuda ONE journey started, um, y- you know, um, whatever, 12, 18 months ago.
Yeah. And the initial incarnation of the value reports were designed with a pre-AI mindset-
Neil: Mm ...
Rohit: where we looked at ROI from the lens of security outcomes and, um, you know, the cost of, um, the cost of the humans', uh, time in terms of, um, in terms of, uh, y- you know, getting to that value, as well as the cost of the CapEx or OpEx of the tools themselves.
Neil: Yes. In
Rohit: the post-AI world, as you, as you may have heard, there is a new term emerging called tokenomics.
Neil: Yes.
Rohit: So in addition to return on investment, we have to think about the return on tokens as we infuse our own solutions with AI. And, you know, what we have done is we [00:18:00] have, uh, made sure that we shield our customers from, uh, directly bearing the cost of tokens in, in the AI that we provide, uh, to them.
So, so we, we kinda incur the cost of the tokens behind the scenes, and it is-- We are very, uh, aware of the fact that our customer resource-constrained organizations are very cost-conscious, and therefore we use, uh, in our engineering, we use the right model, the right AI technology for the right use case. So we're not overextending-
Neil: Yeah
Rohit: or overspending because we have to provide these affordable, easy-to-use solution to our resource-constrained, uh, customers. So net-net, long story short You know, the, the, the value reports, uh, the feedback from customers is it's, it's highly valuable. It's highly valuable to our MSP, um, uh, partners as well [00:19:00] because they can showcase their value to their end customers.
And then the m-most recent incarnation of these value reports have started to think about the AI aspect- Mm ... of the return and the token aspect of the return.
Neil: And you spoke there about overextending, overspending, and avoiding doing these things. Of course, there's a lot of stories in the media at the moment around slowing down AI, especially around cybersecurity and the risks that we've seen this year.
What's your take on everything you've seen this year around attitudes around this?
Rohit: That's a fantastic question. Look, you know, um, there is, there is a cautionary tale playing out in the media- Mm-hmm ... where all the leading AI labs have messaged that, you know, the frontier AI is moving at an exponential pace, um, and as such that-- And, and the, and the safety explainability, um, aspects of that journey is lagging.
And therefore, they've [00:20:00] said, "Hey, we must slow down to make sure we, AI remains a force for the good and doesn't cause harm to humanity."
Neil: Yeah.
Rohit: Now that's a very noble concept. Having said that, I have two points of feedback to that, to that narrative. First of all, operationally, it's extremely difficult to have a synchronized slowdown across multiple AI labs, especially on a global basis, right?
Um, there, there, there will be different incentives and different motivations, uh, and different nations will have different agendas, so to synchronize a slowdown is operationally very, very difficult. It might be a noble-sounding idea- Yeah ... but may not be practical. But even if it were practical, even if the frontier AI velocity is able to be slowed down somehow, I believe that for us cyber defenders, slowing down is not an option.
Yeah. We don't have the luxury of doing that because, like I [00:21:00] noted before, most of the cyberattacks are not happening on the back of frontier AI models. The threat actor is rational, the threat actor is smart, the threat actor is constrained by the same things that we are: economics and tokenomics.
Neil: Yeah.
Rohit: So they're using widely available AI, not frontier AI, to launch highly sophisticated, highly insidious attacks that we are grappling with.
So even as the frontier of E-AI may slow down, the reality is, on the cyber frontier, we must be full speed ahead, keep up with the velocity, increased velocity, I might add, of the new AI-powered threats. So no slowdown in our world, even if somehow, magically, the frontier of AI slows down.
Neil: And for people listening, you know, what should security leaders be doing now to gain advantages of AI without introducing a new class of dependency or risk?
Any, any [00:22:00] takeaways or advice that you would offer to people?
Rohit: Absolutely. Uh, look, uh, I think, I think, um, you know, there are, there are three dimensions to, uh, to, uh, the, the topic of AI in cyber.
Neil: Yeah.
Rohit: You know, you have to think about securing against AI, because assume that all attacks are now AI infused, which means your response window is compressed, which means speed is the name of the game.
In order to, to cope with that, you have to secure with AI. Your solutions must be AI infused, so as you look at choices from vendors, you have to think about, you know, have they infused AI into their offerings so it can keep up with the, uh, with the velocity of AI-powered threats. In addition, the final component is securing AI itself.
AI introduces new risks There is risk of inadvertent data [00:23:00] leakage through the use of, you know, the chat type use cases. And as you now know, you have the era of agentic AI, where tasks and even complex workflows now are being automated. And as part of that, you're invoking multiple APIs, you're talking to different systems, and as such, the agents are, um, you know, have a lot of privilege that they're exercising.
So making sure that that is not introducing additional cyber risk is a very, very important dimension that you need to worry about. So net-net advise, think about securing against AI, secure with AI, and securing AI. All three things need to be cared for.
Neil: Awesome. And finally, on a personal level here, we started at the beginning of your origin story.
As we come full circle, when you leave the Tech Summit, think about all the conversations you've had, what are you gonna be taking away? What are you gonna be thinking about on that journey home?
Rohit: What I'm thinking about, you know, look, this is, [00:24:00] um, this is the 20th anniversary of the Tech Summit. It is the brightest manifestation of, um, you know, um, human collaboration, human empathy, which I think will be, uh, absolutely critical in the age of AI to make sure that we, um, you know, that the humans have a, have the right role to play in assuring cybersecurity.
Neil: Yeah.
Rohit: And my, my view is that, uh, you know, when intelligence is on tap, empathy is going to be how, you know, your organizations differentiate. Cybersecurity is a trust business. AI can provide answers, but it's us humans that provide trust. And, uh, investing in, in communities like this where humans come together, understand each other, listen to each other's challenges and problems, and collaborate to solve them, that's, you know, that's [00:25:00] the magic of this event, and that's gonna be top of mind for me.
And, and it's-- And I feel this immense responsibility on my shoulders to make sure this community thrives, grows, and, and, uh, continues to be a force for humanity and a celebration of humanity in the age of AI.
Neil: And I think that is a powerful and thought-provoking moment to end on. Just a big thank you for stopping by and speaking today.
Rohit: Absolutely. It was a great pleasure. Thank you for a wonderful conversation.

