How prepared is your organization for threats that move faster than people can respond?
At Cisco Live, I sat down with Bhaskar Jayakrishnan, Senior Vice President of Engineering for Cisco Customer Experience, to discuss a reality facing technology leaders everywhere: attackers are increasingly operating at machine speed while many organizations are still relying on processes designed for a very different era.
Our conversation explores what Cisco describes as the defense velocity gap and why traditional approaches to patching, remediation, and risk management are becoming harder to sustain as environments grow more complex. Bhaskar explains how organizations are shifting from reactive security practices toward more continuous approaches that focus on visibility, resilience, and operational readiness.

We also discuss one of the biggest long-term challenges facing the industry: quantum computing. While many organizations still view quantum threats as a future problem, Bhaskar explains why preparations need to begin now, particularly when it comes to crypto agility and the risks associated with "harvest now, decrypt later" attacks.
Another major theme throughout our discussion is AI. Bhaskar shares lessons learned from Cisco's own experience deploying AI across a workforce of more than 20,000 employees and explains why successful adoption often depends less on the technology itself and more on data quality, workflow design, and organizational trust.
Along the way, we explore resilience, modernization, automation, and what it takes to prepare an organization for a future where both opportunities and threats are arriving faster than ever before.
If you're trying to understand how cybersecurity, AI, and quantum computing are reshaping the responsibilities of today's technology leaders, this conversation offers practical insights from someone helping organizations tackle those challenges every day.
Are today's security and operational models ready for a world moving at machine speed, or is it time for a completely different approach?
Useful Links
Connect with Bhaskar Jayakrishnan

[00:00:04] - [Speaker 0]
Welcome back to the Tech Talks Daily Podcast, where once again, I'm reporting from Cisco Live in Las Vegas, where I expected to hear a lot about AI and agentic AI, etcetera. But what I didn't expect was just how much of the conversation would focus on security, resilience, the evolution of zero trust, and preparing for threats that are evolving faster than ever before. And my guest today is the senior vice president of engineering for Cisco customer experience. And during our conversation, we explored what Cisco calls the defense velocity gap, where attackers are increasingly using AI to identify and exploit vulnerabilities at machine speed. And this comes at a time that many organizations are still operating with processes that were designed for a very different era.
[00:01:01] - [Speaker 0]
And as we continue looking forward, I also wanna talk about why quantum readiness is becoming a boardroom conversation And what Cisco has learned from deploying AgenTik AI across a workforce of more than 20,000 people and why the biggest challenge in AI may have less to do with the models and more to do with data. You But don't wanna be listening to me waffling on. Let me beam your ears directly to the show floor here in Vegas where you could sit down and join us in a conversation. So thank you for joining me here at Cisco Live. Can you tell everyone listening a little about who you are and what you do?
[00:01:39] - [Speaker 1]
Hey, Neil. I'm glad to be here. I'm Bhaskar Jayakrishnan. I've been with Cisco for seventeen years. And in the last two years, I lead engineering for Cisco customer experience.
[00:01:51] - [Speaker 0]
Fantastic. And there's a phrase here that's caught my attention, and that is the defense velocity gap. Immediately caught my attention because attackers are increasingly using AI to identify vulnerabilities and launch attacks at machine speed. So how has this changed the way Cisco thinks about cybersecurity, and where are organizations still relying on processes that just simply cannot keep up with the pace of today's environment?
[00:02:16] - [Speaker 1]
Oh, that's a spot on relevant question. Yes. So if you think about threats, customers have to deal with a lot. Anybody that's managing infrastructure, they are dealing with what we call yesterday's debt, which is aging infrastructure with its own set of issues. Today's reality, where you have models like my thoughts, and there are gonna be many models after that, which are gonna attack infrastructure at machine speed.
[00:02:42] - [Speaker 1]
They are mapping infrastructure at machine speed and they are gonna exploit any vulnerabilities. And while we are paying attention to all of this, you have quantum computing around the corner, which is what we call tomorrow's fight, where you have to start preparing for defense against things like harvest now, decrypt later attacks. So we kind of take a look at it as these three things. But these three things, much as they are three potentially distinct things, the way we respond to that is common. So as we think about how somebody who's managing infrastructure can prepare, we think of it in terms of true resilience.
[00:03:21] - [Speaker 1]
True resilience is not a reaction. It's an architecture. So it's not about patching. People instinctively think that, hey, if I patch my entire environment, I would be safe. But it is more than that.
[00:03:33] - [Speaker 1]
So what we do is we work with our customers through the combination of our products and services to make sure that they are prepared. So, one of the things that you would see as part of Cisco Live is from Cisco services, We are announcing something called resilient infrastructure services where we are gonna help our customers reach that true resilience. When we think about true resilience, we think of it in three phases. One, exposure assessment. You need to know where you stand.
[00:04:02] - [Speaker 1]
You need to map every single piece of asset in your organization. And when I say asset, I use that word pretty broadly. This includes a hardware asset, a software asset, cryptographic assets because you need to know about all these three for you to protect yourself. Phase two is infrastructure modernization. Infrastructure modernization is where you've taken a comprehensive look at your infrastructure to make sure that it is based on zero trust principles, things like MFA, network segmentation.
[00:04:34] - [Speaker 1]
And, of course, you need to have the operating procedures to make sure that you are keeping the environment up to date. And the reality is, thanks to all these frontier models, that are mapping environments at machine speed, the next two years is gonna see as many upgrade events as possibly the last ten years. So people have to patch their environment within minutes, not like the six months it takes today or perhaps a year. So we work with our customers to make sure that their procedures, whether they have the right pipelines where they can push changes with confidence. And as part of this, we also take a look at the kind of things that they do.
[00:05:14] - [Speaker 1]
At Cisco Live, you would hear a lot about LiveProtect, which is an element of embedded defense. Right? So as part of that, we work with our customers to make sure that they have embedded defense options across their network. Phase three is what we call defense resiliency, where you want to ensure that the customer has a SOC which has all the best practices. It it has a comprehensive view of the network And they are not just relying on reacting to alerts with human effort.
[00:05:46] - [Speaker 1]
This is where the element of agentic ops comes into picture. Right? And how do you keep these playbooks up to date and refined? With Splunk and with capabilities, you get all these alerts, but then you have to react to that as well. So from Cisco, the first element is you need to have the right products.
[00:06:06] - [Speaker 1]
Right? That's why you would see a lot of announcements in in terms of quantum readiness as well. Right? I mean, are looking at all of these comprehensively, and then we support them through services, which is a combination of support services and professional services, and the professional services are delivered either by Cisco or through our extensive partner network so that we can get our customers across the world to get to true resiliency at scale.
[00:06:31] - [Speaker 0]
And I'm glad you mentioned Zero Trust there because I've been to, what, 20 plus tech conferences this year. Predictably, Agentic AI is covered everywhere, but this is the the first one I've been to this year where there's a big focus on securing AgenTik AI, and one of the big slides or one of the big parts of the presentation in the keynote today was all about the evolution of Zero Trust and bringing it into AgenciKi and those millions of agents. A massive deal, isn't it? And and kudos to you guys for bringing it up and addressing it because I think there's a lot of concern, isn't there, in the world at the moment?
[00:07:04] - [Speaker 1]
There is. But now if you think about what's happening with all these frontier models and attacks at machine speed, right, the first principles don't change. What has changed is these models has weaponized the speed. It has weaponized the comprehensiveness. One of the data points that I would like to point to is something that was announced by Cisco Talos, the security arm at Cisco, which analyzed the vulnerabilities that were exploited in the year 2025, and what we found was about 40% of the top 100 vulnerabilities which were exploited in 2025 were on devices that were past the last day of support.
[00:07:48] - [Speaker 1]
And it's probably about 23%, I think, of the defects. They were like around for a decade. So it kind of gives you this view in terms of the amount of technical debt out there. But then, with these models, they can process a lot of information, and therefore, when they map your network, they can exploit it, they can chain it. So that's why we have to think in terms of the defense, the posture, and keep this continuous improvement so that you are not letting go of first principles.
[00:08:26] - [Speaker 0]
And one of the other biggest concerns I hear from business leaders is security teams are overwhelmed by alerts, dashboards, and compete in priorities, the dreaded alert fatigue that we hear a lot. But how can AI help reduce the burden without introducing new risks or or creating more layers of complexity into the mix?
[00:08:45] - [Speaker 1]
So when it comes to prioritization and when it comes to reaction, what you're gonna see is with agent take ops, right, you now finally have the ability to process a much larger volume. When people were doing it manually, people were paying attention probably to the high critical severities, and then you had like this large body of alerts which languished without action. So now with agents, you would be able to process them, prioritize them, and if you were to take into consideration active threats, threats that are being exploited, then you can prioritize the alerts which are correlated with the current threats that are actively being exploited. So there are possibilities in terms of how you can prioritize. For instance, you can prioritize elements in the edge before you address things at the core, Alright?
[00:09:41] - [Speaker 1]
So that you're you're protecting the periphery. Of course, if you want defense in-depth, you want to make sure that your entire estate is protected. But when it comes to priorities, there are different ways of looking at it. The other thing is you can prioritize according to the active threats, as an example. So there are different ways of doing it.
[00:10:00] - [Speaker 1]
Earlier, doing it just with automation was hard, but with agentic ops, it opens up the possibilities. Now, you've also seen people talking about autonomous operations. I mean, I've seen different words being used, a dark knock, things like that. Right? So as you get to autonomous operations, then now you can bridge it all the way from seeing an alert to an agentic response that results in potentially a configuration change that is pushed through a pipeline which is tested so that you can push it with high confidence and you can close the loop by actually addressing it.
[00:10:38] - [Speaker 1]
So with agentic ops, you can finally see light at the end of the tunnel.
[00:10:45] - [Speaker 0]
And also here, I think unlike other tech conferences, it's not just all about agentic. Quantum is entering the conversation here. You mentioned it earlier in our conversation, and it really just seemed to have shifted dramatically over the last year. But for those that still see Q Day as a distant problem that Harvest Now, Decrypt Later, for example, what are are they potentially underestimating, and and why should organizations be thinking about crypto agility today rather than waiting for that that problem that may or may not appear in the future?
[00:11:18] - [Speaker 1]
So, I don't think anybody can say for sure when Q Day is coming. Yeah. But what everybody knows is Q Day is getting closer every single day. In the last one year, I think Q Day has been pulled in by three years.
[00:11:35] - [Speaker 0]
Yes. Right?
[00:11:36] - [Speaker 1]
There has been a lot of advancements in quantum computing. Right. So you can think in terms of vertical scaling. There are more computers more quantum computers with more qubits Then you can think in terms of horizontal scaling where you you see something like a quantum switch from Cisco. You can think about other protocols which are gonna be available where you will be able to harness the power of multiple quantum computers.
[00:12:05] - [Speaker 1]
Then you have advances in algorithms. So not a single day goes by without you hearing about some research where now you are able to break an algorithm with fewer qubits. Yeah. So if you take all of these into consideration, Q Day is coming in. That's why you see announcements from pretty large companies which have more aggressive mandates than the regional mandates and the country mandates where we they want to patch everything by 2029.
[00:12:33] - [Speaker 1]
2029 is barely three years away. It's not like three decades away. And the other part of it is state actors are already copying petabytes of data with the the harvest now so that Yeah. They can decrypt it later. Right?
[00:12:50] - [Speaker 1]
So we need to prepare. So as we want to help our customers through this, we think in terms of three dimensions. Dimension one is secure communications. Everything that comes in and goes out of the box, whether it is for the manage plane, management plane, data plane, control plane needs to be safe. Second is secure platform.
[00:13:17] - [Speaker 1]
Even if the traffic coming in and going out is secure, but the platform is compromised, you have a problem. Right? So you have to evaluate the secure platform. Third is crypto agility. Crypto agility is the ability where the cryptographic configuration is decoupled from the implementation, so you can actually change it with speed.
[00:13:40] - [Speaker 1]
Right? So in the past, when algorithms changed or something like encryption algorithm went from 512 bits to 24 bits or whatever the number is, people got like five years, seven years to do it. But now, you might have to react pretty fast. So as much as we've been talking about patching Yeah. In the previous case, you are here, you're talking about potentially up updating the encryption algorithm as well.
[00:14:09] - [Speaker 1]
So one of the things that we are doing is we are announcing something called quantum readiness assessments as through Cisco IQ. Cisco IQ is the delivery vehicle, as I said, for Cisco support and professional services. As part of quantum readiness, we give our customers a bottom up view, which is essentially, is this device ready? So we analyze it on the basis of these three dimensions and we give them one of the four outcomes. Your device is ready.
[00:14:34] - [Speaker 1]
You're good. Two, the device is not ready. You need a hardware refresh. Or the device is capable of it, you need a software update, or you need a feature activation or a configuration change for you to be ready. And similarly, we also give a top down view where we give our customers the ability to look at their infrastructure estate as a whole.
[00:14:54] - [Speaker 1]
And not just that, they need to also know whether they are gonna meet the deadline according to the regional mandates. So we allow a selection of the mandate so that they can take stock of where they are with respect to the timelines which have been set out. Right? The one thing, none of us know exactly when queue days arrive, but what is certain is we need to prepare now.
[00:15:25] - [Speaker 0]
100% with you. And I'd also like to give everyone listening a peek behind the curtain at Cisco because the system of customer experience has been through its own AI transformation, deploying Agenic AI across a workforce of roughly 20,000 plus people. So what surprised you most during that journey? What assumptions about AI adoption maybe turned out to be wrong? Any any surprises there?
[00:15:50] - [Speaker 1]
So it has been an interesting journey over the last couple of years. To start with, the technology itself is moving pretty fast. Yeah. So something that you think is not capable today, not capable of solving today, by tomorrow, you're gonna see a new model, a new technique, a new framework which makes it possible. So there is a lot of action going
[00:16:13] - [Speaker 0]
on.
[00:16:13] - [Speaker 1]
The other thing is, how do we approach it? So as we went through this journey, one of the first things that we did was we tried to use AI to immediately get efficiency. So as we started doing that, we started seeing efficiencies, but those efficiencies were not groundbreaking. And that's when we had the first moment, where we realized that we are trying to solve through AI. 2026 technologies being applied to workflows which were developed in 2016.
[00:16:45] - [Speaker 0]
Yeah.
[00:16:45] - [Speaker 1]
So that's when we started thinking in terms of AI native workflows. What are AI native workflows in terms of based on the technology available today, how do we fundamentally deconstruct the problem and reassemble it in a way where you can use these technologies? And when we did that, suddenly we started seeing enormous adoption and results which are actually meaningful. Right? When you look at multiple organizations, there's no dearth of pilots, but the number of agents which actually get to production and show enough results to justify the ROI is pretty hard.
[00:17:29] - [Speaker 1]
So as we talk to our customers, we talk about thinking about it in terms of AI native workflows. And the one other element I always call out is it's not just about models. It's also about data. At the end of the day, AI, only as good as the data that you give it. So the universal truth is this, enterprise data is messy.
[00:17:55] - [Speaker 1]
Enterprise data is fragmented. Enterprise data is siloed. Enterprise data is sitting in people's heads in terms of institutional knowledge. And say, for instance, I use an acronym, I use a phrase, maybe a product has been renamed as a human being, you automatically give that cognitive bridge, but then in a system, you need it. So one of the first things that we had to do was do a data audit to figure out where is the data, how many systems it's sitting in, how do we bring it together with a data fabric, how do you collect it, correlate it so that you can make it available to an AI agent?
[00:18:36] - [Speaker 1]
And once we started doing it and giving the flexibility to our users in terms of how they use it, then we started seeing adoption go up and the results being meaningful.
[00:18:47] - [Speaker 0]
And I think Cisco has a front row seat to how customers are adopting AI AI, and I'm sure you would agree with me there. But what is the biggest mistake that organizations might be making when they think about AI transformation? Are there any myths or misconceptions that they bring to the table when you're having these conversations?
[00:19:07] - [Speaker 1]
Well, a lot of the organizations fall under the trap of using AI for AI's sake. Yes. Right? So you have to wet the use cases. There's no escape from the data audit.
[00:19:20] - [Speaker 1]
You have to bring the data together. You need to have the right skill set. You need to be able to challenge the status quo. And the most important of all, be willing to take that chance when you are not going to have something that is accurate. Right?
[00:19:39] - [Speaker 1]
So you need the skill set for the leaders and the engineers to lean in where they become part of building an agent or a system which can solve the problem for them. The other thing which I find very fascinating is our minds are wired for deterministic outcomes. Yep. When we use applications, when we use workflows, we expect it to work exactly the same way. Right?
[00:20:08] - [Speaker 1]
But with agents, there's a range of possible probabilities. Right? So how do we wrap our mind around it? How do we give it guardrails? How do we come up with layered autonomy so that you for low risk use cases, you can give an agent a lot more autonomy.
[00:20:28] - [Speaker 1]
But then for high impact use cases, you either want a human in the loop or you want a human in the loop when your confidence score is not high enough.
[00:20:37] - [Speaker 0]
Yeah. And on stage today, I think Chuck Robbins perfectly highlighted the speed of technological change. Think he said three months ago, all we cared about was RAM and where that was coming from, and then it was mythos. Now, of course, everyone's talking about. If we dare to look into the future a little bit, where do you see AI having the biggest impact inside organizations over the next, what, eighteen months to three years?
[00:20:59] - [Speaker 0]
How do you see that impact growing?
[00:21:01] - [Speaker 1]
I remember a phrase from a few years ago where it said, like, every organization is a software organization, right, irrespective of which industry you are in, whether you are in fast food, whether you're in airlines, whether you are a software company. I think it's gonna be the same thing for AI. Every company is gonna be an AI company. It's about how do you harness this technology. Of course, there is an operational challenge from the perspective of if you move too soon before the technology is ready or you are able to show enough results, you might trip up because you're spending a lot of money without results.
[00:21:37] - [Speaker 1]
If you move too late, your competition is gonna outclass. It's about how you find the right balance so that you still experiment, you move, so that as this technology matures, you're gonna be there. Liz Santoni uses this phrase about what you are seeing today is the floor. We don't know how high the ceiling is, and technology is rapidly improving, and the floor is gonna raise.
[00:22:05] - [Speaker 0]
Love that. And before I we met today, I was also reading a great story about the importance of creativity in technology now and in business and and far and beyond. I'm curious, what is a creative way that you've used AI or your teams have used AI or another tool to improve your own work? Any examples spring to mind there?
[00:22:26] - [Speaker 1]
So one of the interesting parts about having coding agents available to you is you can solve these problems which are nagging you, but then it never bubbled up enough for you to like put enough resources on it. So one of the things is I run a global organization. So I wanted a visualization of my team's time zone spread, and I wanted a mathematical model to evaluate team fragmentation so that I can evaluate it on the basis of the number of time zone legs for a piece of information to bubble up or bubble or or or be disseminated. Right? So using Cloud Code, one of the things I did is I developed a visualization and a fragmentation computation model, and that gave me a mathematical construct to actually evaluate it and act on it.
[00:23:34] - [Speaker 1]
So that was fascinating. And this is something that I could get done in probably about six to eight hours. And this would have traditionally required a whole bunch of requests to a whole bunch of people for it to be developed.
[00:23:47] - [Speaker 0]
Wow. And I think that is a powerful moment to end on. So many great takeaways from getting a chance to sit down with you and talk about this stuff today, but I'll include links to everything that we talked about there and links to Cisco Live and some of the keynotes there and some of the insights coming out, but just thank you for sitting down with today. Really appreciate your time.
[00:24:06] - [Speaker 1]
Hey. Glad to be here, and thanks for taking the time to talk to me and Cisco.
[00:24:10] - [Speaker 0]
There were a few big moments in today's conversation that really stood out to me. The first was my guest point that resilience is not a reaction. It's an architecture. And in a world where threats are moving at machine speed, simply patching systems after the fact is becoming increasingly difficult. And another good point now was his perspective on AI adoption.
[00:24:34] - [Speaker 0]
Rather than applying AI to existing workflows and just hoping for dramatic improvements. He refreshingly argued that organizations need to rethink workflows from the ground up and design them for an AI native future. And it's this questioning of the way things used to be done and the way things have always been done. Legacy ideas, thinking, technical debt, and ways of working that are just no longer fit for an age of AI workflows. And finally, I think his reminder that while nobody knows exactly when q day will arrive, every day brings it closer.
[00:25:13] - [Speaker 0]
And that simple observation makes quantum readiness feel far less like a future problem and much more like a present day planning exercise. But as always, love to hear your thoughts on this. What challenge concerns you most right now? Is it AI driven cyber threats, quantum readiness or preparing your organization for AI native ways of thinking and working? Let me know.
[00:25:39] - [Speaker 0]
Drop by techtalksnetwork.com. Make sure you're subscribed. I've got 11 or 12 interviews coming your way from the event. So if you enjoyed this one and you're hearing me for the first time, please, I'd love to hear from you and I'd love to speak with you again tomorrow.
[00:25:55] - [Speaker 2]
So a big thank you to Denotto for supporting the Tech Talks Network and helping us share these conversations because AI is only ever as powerful as the data behind it. And Denodo gives your business trusted real time AI ready data from across the enterprise, and they do that securely and without duplication. So power smarter AI with Denodo. And you can find out more by simply visiting denodo.com. But that's it for today.
[00:26:25] - [Speaker 2]
So thank you
[00:26:25] - [Speaker 0]
for listening. Bye for now.

