What happens when attackers can discover and exploit a weakness faster than your organization can patch it?
Recorded at Barracuda TechSummit 2026 in Alpbach, Austria, this conversation features Arve Kjoelen, CISO at Barracuda. Arve is responsible for protecting Barracuda's systems, environment, and code, which makes him the person answering the familiar question of who checks the checker.

Our conversation begins with the collapse in response time. Security teams once had hours or days to investigate suspicious activity. Arve explains why they may now have minutes or seconds, while vulnerabilities can move from disclosure to exploitation within days. Traditional weekly scans and handoffs to patching teams struggle when attackers operate at machine speed.
Arve offers a useful framework for understanding security posture through threats, exposures, assets, and controls. Technology changes constantly, but these categories give leaders a way to assess risk without chasing every new term. He also explains why reducing attack surface can begin with basic questions. Does a system need to be accessible from the internet? Does a web server also need remote management exposed? Does a midsize business benefit from spreading its workloads across every major cloud provider?
We examine the difficult balance surrounding AI adoption. Blocking every new tool can prevent employees from benefiting from useful technology, but allowing unrestricted adoption creates new exposure. Arve argues for deliberate choices and guidance that reduce risk without stopping progress.
The conversation also addresses AI-guided remediation. Barracuda uses AI internally to identify vulnerabilities, but Arve is cautious about fully automated fixes. An AI system may identify a problem and suggest a solution, while a human remains responsible for judging whether the proposed action could damage a production environment. Faster decisions are valuable only when organizations understand the consequences.
Arve also considers how entry-level technology roles may change as AI performs more coding and analysis. His view is that people will need to understand how to work with AI, evaluate its output, and carry an idea from design through secure implementation. The role changes, but the demand for human judgment remains.
We finish with model sovereignty, data trust, and provider dependency. If a security capability relies on one AI model, leaders need to know whether they can move to an alternative if access, performance, pricing, or policy changes. Arve also explains why Barracuda is preparing to support both open and closed models while the market develops. Where should your organization use AI to accelerate defense, and which security decisions should remain firmly under human control? Listen to the full conversation and share your thoughts with me.
Useful Links
Connect with Arve Kjoelen on LinkedIn

[00:00:00] - [Speaker 0]
Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data, and Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest. What happens when attackers, defenders, and employees all begin operating at machine speed?
[00:00:41] - [Speaker 0]
Well, reporting from Barracuda Tech Summit's twentieth anniversary in Outback, Austria this week, I've spoke with Rohit Guy, Neil Bradbury, Adam Khan. And today, I've got the CISO joining us, and we're gonna talk about the security problems that are hiding behind the AI headlines that we see in our news feeds. We've already discussed ShadowAI, agentic security operations, identity sprawl, managed XDR, model sovereignty, and why human judgment still matters when automated decisions arrive in seconds. And against one of the most spectacular conference backdrops I've ever seen, these conversations revealed what businesses must protect, what they can automate, and where people can remain firmly in control. But we've got one more conversation to go before I fly home, so let me officially introduce you to my final guest here at the Tech Summit.
[00:01:41] - [Speaker 0]
So a massive thank you for joining me on the show today. Can you tell everyone listening a little about who you are, what you do, what you're responsible for at Barracuda?
[00:01:50] - [Speaker 1]
Okay. Yes. My name is Arvik Kajolan. I am the CISO at Barracuda. So 80% of my responsibility is really around securing Barracuda, making sure that our environment, our systems are secure, that our code is secure, and so that we can provide, you know, secure products to our customers.
[00:02:09] - [Speaker 0]
So in the age old question of who checks the checker, it's you.
[00:02:12] - [Speaker 1]
Yes. Yes.
[00:02:14] - [Speaker 0]
Now in your keynote this week, you argued that the job of protecting an organization has not changed at all, but the time available to do it has. So what has accelerated most dramatically for security teams from all those conversations you're having with people?
[00:02:30] - [Speaker 1]
I think the time to react. So and the the two examples that come to mind now, one is in the SOX. When something happens and, let's say you see something that you don't like and you want to investigate it, attackers are moving so quickly now that you no longer have hours or even days to look at it. You have to be prepared. You have to be have automation in place, and then you just have minutes or sometimes just seconds to make sure that you look to see what's there and you resolve it right away.
[00:02:58] - [Speaker 1]
So that's that's one side, and then the other side is on the patching. So as these vulnerabilities just keep coming out, and that affects everyone, not just us, that you just you sometimes just have a few days before a vulnerability is from a vulnerability sake is issued until it's maybe exploited by attackers. So it's important to get the patching done right after the vulnerabilities come out.
[00:03:23] - [Speaker 0]
And I'm curious here at, the tech summit. What kind of conversations are you having? What kind of feedback are you getting on the back of that presentation?
[00:03:31] - [Speaker 1]
I had a conversation with a with a delegate who was, you know, not a Barracuda employee, but a And I ate with them before the presentation, and we discussed, you know, AI and does it need to be controlled or guardrailed or needle? Does it need to be available to defenders? Some of the things that I talked about. And afterwards, they came up and said, oh, I I think I can see your point, but I still don't agree with you completely. So I thought I thought it was a great great way of closing the loop with him afterwards.
[00:04:00] - [Speaker 0]
Yes. Slight progress made there. Love it. And you also describe security posture as the battlefield where threats, exposures, assets, and controls all collide together. So how can a business leader listening accurately understand its posture when its tech estate is continuously changing, in particular over the last eighteen months?
[00:04:19] - [Speaker 1]
It it is changing. It is changing. And those those of us who have to delve into the details, we are constantly dealing with kind of the foundation shifting underneath. But I wanted to put out a a framework like that because if if you think of them as categories, the categories are not changing. So the threats the threats are the threat actors in the ways that they try to get in.
[00:04:40] - [Speaker 1]
The the exposures are the weaknesses that you have and and, the vulnerabilities in the various areas where, you know, you need to strengthen things. Controls are still controls, and then your s your assets are assets even though they may be in the cloud today and they were, you know, on premise yesterday.
[00:04:56] - [Speaker 0]
Yeah. It feels like so much has changed and so much hasn't, right, at the same time?
[00:05:00] - [Speaker 1]
Yes. Yes. Yes. For those of us who have been around for a while, it seems like deja vu sometimes.
[00:05:05] - [Speaker 0]
Yeah. And, of course, now every new application tool and integration can all create another route for attackers. So how can organizations benefit from new technology without allowing that tech sprawl to create risks faster than their teams can identify them?
[00:05:21] - [Speaker 1]
You can try. I think for many for many organizations, it is difficult because these the tech becomes so attractive because it allows you to do new things. So you you go and you use it where it is available. But the more you have the ability to do at least some sort of planning, I think the better off you will be. So you might be if you're a mid sized organization and you're not providing software, maybe you don't want to be both in AWS, you know, and Azure and Google Cloud, and maybe play with Oracle Cloud as well.
[00:05:51] - [Speaker 1]
So I think trying to be more deliberate about, you know, where do I want to live and, you know, do I want data centers here? Do I want to be, you know, in these types of cloud environments? That's the way we can at least reduce the the surface a little bit.
[00:06:04] - [Speaker 0]
And it's so difficult, isn't it? Especially when so many employees want black kids in candy stores. They want their hands on all the latest AI tools, and a little bit from here and a little bit from there. It could be hard to visualize who's got what and who's using what.
[00:06:17] - [Speaker 1]
Yes. Yes. And for the security people, it can be a challenge as well because you don't if you just say no, then your company doesn't progress. It doesn't get to use the new technology. It doesn't get to benefit from it.
[00:06:29] - [Speaker 0]
Yeah.
[00:06:29] - [Speaker 1]
So you can't say no, but you can't you can't just let it be a free for all either.
[00:06:34] - [Speaker 0]
So Yeah. Providing
[00:06:36] - [Speaker 1]
guidance that that just reduces the attack surface is the way to do it.
[00:06:40] - [Speaker 0]
Absolutely. And, of course, vulnerabilities can now be discovered, weaponized, and exploited, not at human speed, but at machine speed. So where can traditional vulnerability management processes where are they failing to keep pace with this new speed?
[00:06:54] - [Speaker 1]
I think a couple of areas. So one is the traditional ways that we do vulnerabilities scanning is we let's just go back to just a couple years ago. You would maybe scan once a week. Yeah. And you would say, I'm gonna click a button.
[00:07:09] - [Speaker 1]
I'm gonna get a list of the things that I need to patch, then I'm going to hand it over to the patch team, and then the patch team will go find all those systems, install patches, and then we're all happy. And so that process doesn't work anymore. The tools are a little bit better. They're they run on the systems now, and they're agent based, so you get you get very frequent updates. But I think the the challenge is still in the remediation, and that you still need a human to go in to go in and patch.
[00:07:37] - [Speaker 1]
There are centralized patch tools. They work, but they also have gaps. You know, it's always the gaps that the finder the attackers find. So if you patch something, then then the attacker doesn't find that. So it's back to speed.
[00:07:49] - [Speaker 1]
Yeah. So you have to you have to do it more quickly. I do think that AI will enable us to do some of this more automatically than we do today. So I think that's where if we can have AI guided remediation, then I think we have a better chance of closing these holes more quickly.
[00:08:04] - [Speaker 0]
And as everyone listening and watching, we're all operating at machine speed now. But what does that look like for a defender? Which decisions should organizations automate first? I suspect this is a a question you get asked a lot because there's so much to do. Where do I start?
[00:08:18] - [Speaker 0]
Where's that low hanging fruit?
[00:08:20] - [Speaker 1]
Oh, I think it will vary from organization to organization. I think I think it definitely will. I think most organizations are getting pressured from the vulnerability pace, and so I think that's an area that you have to look at regardless of where you are. So that's probably the first one I would point out. And then perhaps the second one is the attack surface, which is related, you know, to the asset sprawl.
[00:08:42] - [Speaker 1]
Mhmm. So reducing that, and it's it's a little bit some of the things we talked about already being in, you know, being in fewer environments and so on. But it's also are you certain you need you know, any system that's on the Internet, does it really need to be accessible from the Internet or can you can you find a different way of doing it? Is it a web server, but also it can be managed from the Internet? That's not what you want.
[00:09:04] - [Speaker 1]
Yeah. So reducing just reducing the number of systems as well as the number of services on those systems that an attacker can even see in the first place.
[00:09:14] - [Speaker 0]
And do you think some enterprises get too obsessed with the over complicated and the newest, shiny, the tech, rather than that belts and braces stuff like the identity, somebody else logging in, somebody clicking on a link? Do you think that stuff gets neglected sometimes as with the obsession with all things AI?
[00:09:30] - [Speaker 1]
I don't know that it gets neglected because I and perhaps that means that I'm one of the people obsessed with AI. But I because it's it is providing a lot of benefit. The large organizations that I've seen that go really heavy into the new technologies and so on, they generally they generally don't neglect the basics either. So I think the larger ones are able to do both.
[00:09:50] - [Speaker 0]
Yeah. Yeah. And, of course, operating at greater speed can also produce bad decisions faster. I don't know if you've seen any of this, but how do defenders use AI to improve security without allowing false positives, incomplete data, fraud recommendations, and ultimately creating new problems? How do they avoid falling into that trap?
[00:10:09] - [Speaker 1]
Yeah. I think there are two answers to that. I think the first one is then AI is not as bad today as it was a year ago. So I think a year ago, we had a larger set of false positives, hallucinations. We still have them, but I think they're much less severe than they used to be.
[00:10:28] - [Speaker 1]
So I think that's one part of it. The second part is more around knowing where you need a human in the loop. So one of the things that we do internally is we find vulnerabilities using AI. So we have we point AI at something, and it'll find some vulnerabilities. But we have not mastered yet, and perhaps we don't want to master it right now, is completely automated remediation.
[00:10:50] - [Speaker 1]
So that is where you need a human in the loop because AI may say, here is where your problem is, and may even tell you that it thinks that there's a solution, but you need a human in the loop, at least for now Yeah. Because if you make a mistake there, then then you have issues.
[00:11:06] - [Speaker 0]
Do you ever worry about AI removing those entry level roles? Because it seems that critical thinking, that is the most important thing, that human expert, that critical thinking, and just keeping that pipeline of that that first line almost.
[00:11:20] - [Speaker 1]
I think I don't think AI will remove that, but I think those roles change. And so so for instance, I have a nephew who's going to school for computer science, and the nephew just during his courses has just realized then, I don't know how much I'm ever going to be actually coding, you know, like, these very specific things that I'm learning about how to do advanced things with code because I'll be asking AI to do it. But what that means is he has to get to a point where he uses the information that is there, where he uses AI productively in his job. So it's not that his job will
[00:11:56] - [Speaker 0]
go away. Yeah. Yeah.
[00:11:57] - [Speaker 1]
But he can no longer come into a company and say, oh, just give me a laptop, and I will write some code. He has to come in and say, oh, I know how to interface with AI. I know how to get it to produce good code. I know how to get it to, you know, secure that code and ask it to secure that code, and how to work with it from, much earlier, from kind of from idea and from design and all the way through through coding. So I think it changes.
[00:12:20] - [Speaker 0]
Awesome. And you also argue that AI advantage is very often too concentrated on the attacker side or kept away from frontline practitioners. So what is it that's preventing defenders from gaining equal access to to all of these capabilities?
[00:12:34] - [Speaker 1]
Oh, well, this I'll try not to make this a a political question, but I think I think what we're seeing is, and perhaps all of these things are tied together. So I think media coverage has often been negative about AI. So the stories that play and that's because that's what people want to read and see. Right? So the stories that play are, you know, an AI agent went rogue and broke into something and so on, and it it all sounds very scary, and there are too few, you know, conversations like this where we'll just talk about the pros and the cons of AI.
[00:13:04] - [Speaker 1]
And so I think so with that, we have seen some of the frontier companies like Anthropic, as well as some regulators really try to button down on saying this is a dangerous capability. We have to make sure that it doesn't fall into the wrong hands. And so some of the advanced things that some defenders won't be able to do today, they're just not available because you need to be part of a special program. Right? With whether that's with Anthropic or whether that is with with OpenAI.
[00:13:34] - [Speaker 1]
So it's really coming from the frontier models as well as the, as well as the government organizations there. I'll give you an example. Right before the last change in administrations in The United States, the Biden administration, so this would have been the end of twenty twenty four, put in place new regulations for AI, and they they set a threshold and said, you know, above this threshold, we want to want we greater scrutiny. They were not forbidding anything, but they wanted, you know, greater scrutiny on models because they're concerned about what would happen. So that was a year and a half ago.
[00:14:09] - [Speaker 1]
Grok three already has more computing capability than that 2024 ceiling that was set. Right?
[00:14:16] - [Speaker 0]
Yeah.
[00:14:17] - [Speaker 1]
And so we things are just moving so quickly that my concern will be if we are not very careful, we can put these limits in place. We will abide by the limits because we're generally law abiding, but we may have, you know, other nations where those limits are are not abided by, or we may just have open models or models not produced by the large model providers that will surpass where we are. So it's Yeah. It's a difficult position. It doesn't have an easy answer, but but right now, there are some some defense and tests that you can't do because of the limitations in place.
[00:14:47] - [Speaker 0]
And that takes me to sovereignty, which is a huge topic right now. There are concerns about durability and sovereignty at the moment. So if a sort of security capability relies on an AI model that its provider could change, restrict, or even withdraw. How should customers assess that kind of dependency?
[00:15:06] - [Speaker 1]
That will be customer dependent Yes. As well. So I would someone who is perhaps associated with the defense industry in The US, I think, will have a very different answer than a consumer company, whether it's in Europe or or in The US. So I think it will be a little bit industry based. But if you know that you are at least in a position to switch models, something happens to the model that you are currently using, I think that's a good starting point.
[00:15:35] - [Speaker 1]
Let's say today you're using only Anthropic or you're using only one model. If you just know when you're experimenting with an alternative and you you know how to switch if something should get withdrawn from you, that's that's probably enough as a starting point. But the bigger issues will be very different or very difficult to tackle because we will see a difference in how Europe approaches sovereignty as compared to how The US does it. Mhmm. I think Europe will maybe more open to use a wider variety of models than than The US will, and it may even play into some of the regulation Mhmm.
[00:16:13] - [Speaker 1]
Discussions that we had.
[00:16:14] - [Speaker 0]
And as organizations continue to build portfolios that contain both open way and closed models, what what should leaders examine when deciding which models can be trusted with their entire security ops operations? I know it's a big, big question, almost an episode on its own, but any advice there?
[00:16:32] - [Speaker 1]
Frontier models, it depends on what you're concerned about as a company. You might be a company that it's in at least in an industry that's adjacent to what some of the frontier models companies are looking at. And so if you are, you might be concerned with sharing any of your data with that company. You might think, I'm making queries about, you know, how do I create patents that are related to AI or the so you might think, oh, I don't I don't want, you know, these frontier companies to see that because who knows what they will do with it. So that that might be one risk or one way to think about the risk.
[00:17:09] - [Speaker 1]
But then I think for most, it will be more related to, can I really trust can I trust this model provider with the data with the data that is there? You know, where will that data eventually go? So if I don't have an immediate concern that the the model provider can use it for their own good, you know, are there other concerns there?
[00:17:28] - [Speaker 0]
Awesome. And I know you're an incredibly busy guy, and straight after this, you're going straight to a presentation. So for people that can't attend, what are talking about today?
[00:17:37] - [Speaker 1]
Today, we are talking about the Barracuda Trust Center. Yeah. We have done a lot of work at all companies like ours that operate in multiple countries. We have challenges around getting the right certifications, meeting the customer's needs. Right?
[00:17:53] - [Speaker 1]
One customer says I am because of the industry that I am in, I need to purchase, you know, systems that are that meet this certification level. And, that varies from country to country, from industry to industry. The The US has some specific certifications. Europe has some here. We are getting more and more European country specific certifications.
[00:18:15] - [Speaker 1]
There's ENS in in Spain. There's ACN two in Italy and so on. So we just want to tell our customers and our partners here that we know that this is a concern for them. We think that we are at a point where we where we can get to leading the market and and leading our competitors with really having the right certifications available. Sometimes it's a matter of being being more agile, looking for the right things, anticipating, customer needs.
[00:18:46] - [Speaker 1]
But also, want feedback today. So Mary from our, our legal and I, as we talk about this, if there are partners and customers out there that that think that their certification needs are not being met by what we're doing, we want to hear that because we want to start on those things now because certifications will take they take months, and sometimes they take even longer than months. But we want to know as soon as possible when a customer or partner feels that there's a need so that we can address that.
[00:19:12] - [Speaker 0]
It sounds like we need to get you back on in a few months, learn more about that feedback. But I will include links to everything we talked about in the show notes for everybody listening. But more than anything, thank you for stopping by today. I really appreciate your talk.
[00:19:23] - [Speaker 1]
Thank you for having me. It was great.
[00:19:25] - [Speaker 0]
So many big takeaways for my time here this week. And as I prepare to leave Outback, my biggest takeaway, I suppose, is that AI has changed the clock for cybersecurity. Attackers, they can discover and exploit weaknesses faster. Employees, they can send sensitive information into unapproved AI tools in seconds, and autonomous agents can create new identities, permissions, and actions that many businesses cannot yet see. And my guest today offered a useful framework for cutting through some of that complexity.
[00:20:02] - [Speaker 0]
Threats, exposures, assets, and controls, for example. And these categories remain relevant even when the technology changes because businesses ultimately still need to know what they own, reduce unnecessary exposure, patch vulnerabilities faster, and decide where human approval is required before an automated system can take action. And a few days ago, Neil Bradbury explained why the AI era is accelerating Barracuda's platform strategy. And when email, identity, endpoints, networks, applications, and cloud services all produce separate alerts, Security teams are left trying to assemble the story while an attack, well, that's already still moving. And managed XDR, that aims to connect those signals so teams can see the incident, understand its context, and respond sooner.
[00:20:58] - [Speaker 0]
And another reoccurring concern this week was ShadowAI. Of course, blocking AI outright, that risks driving its users just further underground. And a policy without monitoring offers very little protection too. And Barracuda says that its new AI data security product can monitor over 1,300 generative AI services, inspect prompts and uploads while protecting sensitive information and providing evidence for auditors and insurers alike. And Adam Khan's Formula One inspired agentic sock demonstration will always be a big memory for me.
[00:21:39] - [Speaker 0]
He showed what an AI assisted defense could look like in practice, agents handling investigation and response at speed, and human analysts retaining judgment, accountability, and control over some of those higher impact decisions. And, of course, the CEO. He connected all this to resilience, identity, and the needs of smaller businesses and MSPs. And Barracuda's Evo Security acquisition, I think, also adds privileged access capabilities at a time when human and machine identities are multiplying. And his message stayed with me.
[00:22:16] - [Speaker 0]
He said AI can provide the answers, but humans provide trust. So perhaps the real lesson from the Austrian Alps this week is technology might be moving at machine speed, but security still depends on people making responsible decisions together. And as AI begins acting on behalf of your employees and customers, do you know what it can see, what it can change, and who remains accountable when it gets the answers wrong? Let me know. Techtalksnetwork.com.
[00:22:51] - [Speaker 0]
I'd love to hear your thoughts on this. It's time for me to pack my bags, fly back to The UK now. I really appreciate you tuning in every day, but I will speak to you all again bright and early tomorrow with another guest. Thanks for listening. Bye for now.

