Can a security team respond quickly enough when an AI-driven attack moves from initial access to lateral movement and data theft before a human analyst has finished opening their dashboards?
In this episode of The Business of Cybersecurity, I speak with Heath Mullins, Chief Evangelist at ExtraHop and former Forrester analyst, about why AI security has become an operational issue for organizations today.
ExtraHop’s 2026 Global Threat Landscape Report states that 85 percent of organizations have experienced an AI-driven attack. These incidents include AI-enhanced external attacks, compromised AI identities, and breaches involving third-party AI providers. The report also found that 55 percent view AI agents, agentic infrastructure, and GenAI applications as their biggest attack-surface risk.
Heath explains that many attacker tactics remain familiar. The difference is speed. An analyst who once had hours or days to compare endpoint alerts, network logs, threat intelligence, and security events may now find that the attack has completed before the investigation begins.
We also discuss how AI models can be influenced without anybody directly altering their code. Attackers can publish false information that enters future training data or introduce misleading content into internal repositories and development environments. An agent may then infer a connection, assign a high confidence score, and act on inaccurate information.
The risks grow when AI agents receive administrator privileges. Heath describes an agent as an entity capable of taking action across the network. His analogy is difficult to forget: AI can resemble a dangerous toddler carrying the keys to the house, car, and gun safe. It may be extremely helpful, but broad permissions combined with loosely defined instructions create the conditions for serious damage.
Third-party AI adds further dependencies. Security leaders need to understand how suppliers use models and reasoning tools, whether customer data is segregated, what remote access exists, and how a compromised supplier could create a path into the network.
Heath also challenges the assumption that endpoint controls and delayed logs provide enough visibility. Machine-speed attacks may exploit unknown vulnerabilities, evade endpoint detection, and move laterally using identities that appear legitimate. Behavioral and live network signals can reveal activity that does not match a published indicator or known signature.
Buying another security product may address an identified gap, but Heath argues that CISOs also need awareness across physical, virtual, cloud, and container environments. Network and security teams must share information when an identity, agent, or workload begins behaving differently.
His immediate advice is direct. Treat every new tool as potentially dangerous. Test AI agents inside properly isolated environments. Connect every agent to a known identity, restrict its permissions, and define a narrow task. Finally, train people to use AI responsibly and retain human authority over consequential actions.
Heath is also the kind of guest I could talk with over a cold beer for hours about technology and its consequences. After we finished the formal interview, our conversation moved naturally into AI data centers, energy costs, water consumption, surveillance, and humanity’s habit of adopting technology even when we understand the price.
If AI agents can act with administrator privileges at machine speed, are your security controls watching what those agents are doing or merely recording what happened afterward? Listen to the episode and share your thoughts with me.
[00:00:00] Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest.
[00:00:33] Welcome back to The Business of Cybersecurity. Where today I'm going to be speaking with Heath Mullins, Chief Evangelist at a company called ExtraHop. And he's also a former Forrester Analyst. And Heath is one of those guests I could happily talk technology and its impact with over a cold beer for hours. And our post-interview conversation proved the point.
[00:00:58] But today though, we will examine ExtraHop's finding that 85% of organisations have experienced an AI-driven attack. And that 55% see agents or agentic infrastructure and Gen.AI applications as their new biggest attack surface risk. So today, Heath will explain why familiar tactics become harder to contain when attacks move faster than people can investigate them.
[00:01:27] And how poisoned data can influence models. And why over-permissioned agents resemble almost dangerous toddlers with their keys to absolutely everything. What I am hoping now is today you will leave this episode with practical actions for securing AI as an operational reality. It's a big promise. But enough from me. Let me introduce you to my guest now. So thank you for joining me on the show today.
[00:01:56] Can you tell everyone listening a little about who you are and what you do? Yeah. So I'm Heath Mullins. I'm a former Forrester Analyst. And I'm also now the Chief Evangelist at ExtraHop Networks. I've been in the industry about 28-ish years. Got my start in the field. Worked my way up through wide area networking, fast packet data. And then jumped in with both feet right into security, and I've been here ever since. Love it. And, man, you must have seen so many changes, as have we both.
[00:02:24] But, of course, when you look back, I don't know, going from widespread usage of home internet to mobile, cloud, and now AI, what do you think when you look back there and try and join up the dots to the journey that we've been on? Because it is amazing what we've seen and been there from the beginning. But what do you take away when you look back at what we've done here? I think, my God, how did we survive?
[00:02:48] Just the sheer amount of information available today versus, you know, 20, 30 years ago is just staggering. It's just amazing. It blows me away when I have conversations with people and what they take for granted today versus what we used to fight for, you know, 20, 30 years ago. Yeah, 100% with you.
[00:03:07] And one of the reasons I was excited to get you on the podcast today, I was reading a little of ExtraHop's research that found that 85% of organizations today have already experienced some form of AI-driven attack. So what does an AI-driven cyber attack actually look like today? And how different is it from the security threats that teams were dealing with even a year or two ago? Because it seems to be getting more and more sophisticated. But what are you seeing here? What does it look like?
[00:03:37] Right. Yeah. So what's interesting is, you know, a lot of the tactics and techniques haven't changed to very much of a degree. What has changed is the speed at which the attack occurs. So as a human person, and I'm saying human person on purpose, as a human person, you cannot be relied upon anymore to be able to keep up with the speed of these attacks. You know, these attacks aren't happening over days or weeks or even months now where you have the luxury of responding. You know, I see something here.
[00:04:06] Let me go research. Here's my five screens that I'm going through. Let me Google this. Let me look up that. What does my SIM say? What does my endpoint say? Gathering all this information to build this case around what action should be taken. By the time the human is even activated, if you're still operating in that kind of what I would call old style SOC environment, you're already way behind. The attack may have already occurred as well as all the exfiltration or malware or ransomware implantation into your network.
[00:04:35] And you just have no idea. It's just happening at such a speed and through so many different vectors that it's almost it's next to impossible for just a human to keep up with this information. So much has changed here. I mean, for years, enterprise conversations around AI security focused on governance, acceptable use and preventing sensitive data from leaking into AI tools. We've had zero trust conversations.
[00:05:03] And now I'm reading that our own AI could be out to outers and be the hacker there. So tell me more about why you think this way of AI is actually part of the attack surface itself now. What are you seeing there? Right. So there have been some really interesting research articles published over the past six months where people are deliberately going out and poisoning AI models.
[00:05:26] And they're not doing so by accessing the code itself or breaching into this AI offering or anything like that. They're poisoning and posting false information on the Internet. These AI tools are being used to train on. You know, what's the best practice here? You know, what what's the top results on Google for, you know, X, Y, Z. And they're actually going out and creating false data that these agents are being trained upon.
[00:05:52] Another really interesting way that's poisoning is occurring does occur within the enterprise in and of itself. And what's being done is it's being fed false information and bias internally to that network. Now, that may have been a GitHub repository that they pulled down intentionally or not. Or it may be saying, hey, you know, here's go look at all this data to bring me back a clear picture of what my network looks like.
[00:06:18] But, you know, we're going to include some other things just to see if you're able to do it. Or we may include things on accident such as, you know, a cyber range or a firewall environment where we do our DevOps testing. So you're really giving it more and more keys to more and more information. And it's inferring information. It's not necessarily making a concrete, discrete decision on this is what I observed. So this is what I'm going to do.
[00:06:44] It's inferring based on this point in time or the last time I looked or this is what it should be because this is what I was told. These models are very, very powerful and articulate and able to take step by step instructions. But sometimes they make that leap just like a human was. A equals C because I can't find B. Therefore, this information is accurate. And I have a 99% confidence in the score.
[00:07:08] And I've been to so many conferences this year that it's taken me from real pyramids in Egypt to a fake one in Las Vegas. But everyone's talking at the moment about agentic AI. Hundreds, thousands of agents there that individuals and teams are all using.
[00:07:26] And the reason I bring this up is your research found that 55% of organizations see AI agents and agentic infrastructure and gen AI applications as their biggest attack surface risk. Now, I don't see that on the shiny keynotes and demos I see on stage. So what new vulnerabilities actually appear when AI moves from just generating answers to taking autonomous actions across enterprise system? Well, therein lies the problem, Neil. It comes down.
[00:07:56] You actually mentioned governance just a moment ago. And I really appreciate the fact that you did. People are putting 100% trust into these agents because they are buying into the FUD. You know, fear, uncertainty, death that's being offered to them by not only the vendor community, but the larger security community. You know, globally speaking, this makes your life easy. It helps you reduce cost. It helps you, you know, get to the results faster with, you know, more certainty, a greater degree of certainty. And that's all fantastic.
[00:08:26] But what they don't say is, hey, you really need to pay attention to what that agent is doing. In a lot of cases, these agents have admin powers. So what's an admin on your network? Well, it's an entity. You know, I'm not saying it's an identity. It's an entity. It's a thing that can take action upon your network. So what happens when these things are either poisoned by another model, intentionally misdirected by an internal or external threat, or they just believe that they're doing the right thing?
[00:08:55] And I'm using the term belief here because, you know, if you've been watching the news in the past week or so, a lot of the CEOs from the largest AI companies in the world are coming out and saying, you know, we may, we're either approaching the point of sentience or we're already there. So you have to take that into account as well. Would you give your child, you know, keys to the house, the car, the gun safe, you know, whatever, and then say, go on, just go find out what you can find out and then come back and let me know what happens. Of course you wouldn't.
[00:09:25] You know, AI is a dangerous toddler running around with permissions to do massive damage or be extremely helpful on your network. But without clearly defining and narrowly defining that scope of things that it's allowed to do, you're putting yourself in a position to fail and fail spectacularly. And for any leader that's listening, thinking, hey, we have our house in order already, thanks. I want to highlight as well, third party AI breaches also feature prominently in the findings.
[00:09:55] So with organizations increasingly embedding external models, agents, APIs and AI services all into their everyday workflows, how could a CISO listening understand dependencies that they might not even directly own or control? Right. Well, you know, this is this has been a problem for this is not a net new problem. This has been a problem that's been extant for quite a while. You need to assess your third party risk, just like you would assess a new tool that you bring in internally.
[00:10:25] When you're discussing these, when you're having these conversations with that third party, be it, you know, via the supply chain, via a managed detection and response organization, a managed SOC, managed NOC, whatever these things are. You need to be aware of the tools that they're deploying upon your network, not only deploying upon, but what those reasoning tools are doing internally to them. Is your data being segregated? Does it have its own tenant?
[00:10:49] What dependencies are created when you stand up, you know, this external environment for remote control or, you know, overnight support or whatever that thing is. It all comes down to, you know, what am I doing? Do I know what that S-bomb looks like? Is this acceptable risk?
[00:11:05] Have I consulted HR and legal as well as all the stakeholders within the organization to ensure that they're aware not only of what's there being planned to occur, but that proper controls are in place to prevent sprawl, to prevent additional lateral movement. That may not be nefarious on the surface, but could be used if that third party, that supply chain somewhere in there is breached. Now they have an open path into your network. So you need to apply.
[00:11:33] I would argue that you need to be, you know, I'm not going to say more stringent because then it sounds like you're not being as strong about your own network as you should be. But I would argue that you should apply that same level of scrutiny to anybody touching your network as you do your most trusted network administrators, security administrators, and so on and so forth.
[00:11:54] The Five Eyes Intelligence Alliance, they've also warned about advanced AI potentially bypassing traditional cyber defenses on a much shorter timeline than many expect. So what would you say are the security assumptions from our past that are most vulnerable when attackers can operate with so much greater speed, automation, and adaptability? Anything that we should be leaving in the past now and operating with a different mindset?
[00:12:23] What are the most dangerous security assumptions? Oh, wow. Most dangerous security assumptions are, I'm good. I know what I'm doing. I have this. You know, I've got this nailed down. Nobody, we haven't had a breach in three years. Therefore, we're doing something right. Well, no, you just haven't been targeted yet. And that's the reality. And, you know, this is a really interesting bit here in that, you know, back in, oh, what year was that?
[00:12:49] I'd say 2014, 2015 is when you really started to see these endpoints move from just antivirus and anti-malware into things like Symantex SEP, where it was a combination of tools that resided on the endpoint. And those are prevalent everywhere today. Every EDR, endpoint detection and response technology out there, has things around DLP and anti-malware and user verification, identity verification, and locking down ports.
[00:13:19] All those things exist. And it became very easy for enterprises to rest on their laurels and say, hey, if I've got my ingress point being my laptop, my server, anything I can put an agent on, if I've got that secured, then I don't really need to pay too much attention to my network. That's more of a knock job now. It's not necessarily a sock job. And then that is just a huge gap that has been exposed time and time again.
[00:13:43] They're not aware of lateral movement occurring on their network because they're more relying upon logs these days than they are around actual live network data from the wire in and of itself.
[00:13:54] So when you apply that mentality, your log roll up, even if it's every five minutes, today, today, as we speak, these AI attackers, these frontier models can bypass all of your traditional security controls, exploit vulnerabilities that you may not have any awareness of whatsoever, and just run rampant across your network. The EDR evasion kits are freely available online. You don't have to go to the dark web or anything.
[00:14:21] Just go in and type it in, go to Shannon AI, and for free use their model, and you can avoid just about anything that somebody has on a traditional network that is not looking at the network in and of itself as that single source of truth. So what I would say is that if you are not looking at your network and you're not applying AI-level technology, you've got to fight fire with fire. You know, these things are, it's offensive and defensive at this point, and the models are evolving in step, in lockstep.
[00:14:51] You know, this is better one day. My defense is better one day. The new vulnerability is discovered the next day. This is traditional security, traditional warfare, if you will. You have to stay one step ahead. And if you're starting out that far behind, it's going to be a lot harder to get up to a point to where you can confidently say, I think I'm okay, but let's continue to monitor and go beyond due diligence.
[00:15:13] And I suspect there will be some people listening who want a quick solution, and they will naturally jump to the obvious temptation of responding by buying, hey, another AI security product. But I suspect it's a little more complicated than that. And from your experience as both a former Forrester analyst and now at ExtraHop, what capabilities should maybe a CISO actually be prioritizing now?
[00:15:36] And how important are behavioral and network-level signals when an attack doesn't match an already known signature? Because that's something that we're very not so often prepared for. Sure. And that's another great, it's almost like you had these great questions in your mind already.
[00:15:55] So the temptation is always to buy something because there will be a vendor at your front door knocking away, sending you an email, taking you out to dinner, saying, this is how I'm going to make everything better for you. What those vendors tend to do is, you know, there's always going to be a place for a niche product that either addresses an adjacency or a security gap that's been identified. And I'm taking nothing away from them. They absolutely have their place.
[00:16:20] And in a lot of cases, these niche technologies are able to do things that simply nobody else can do. And that may be the difference between a complete takeover and being able to segregate something, right? And separate it and keep it from doing real damage upon your network. So when you're thinking about these things, the point that you brought up around behavioral network level signals when the attack doesn't match an unknown signature, this is very, very important, right?
[00:16:48] Because a lot of the vulnerabilities that are being discovered weren't necessarily published as an IOC or a CVE previously. So when you think about the network, you shouldn't just be thinking about, does this match a CVE? Does this match the MITRE ATT&CK framework? Does this match an IOC? Does this match something that we know about that is, you know, we've known about forever or is something that is net new that we're catching based on behavior?
[00:17:13] It's also about what is happening across your expanded network environment, not just what does my firewall say? What does the wire say? But what's happening over here in my VMs? What's happening in my cloud containers? Are there instances that are being spun up or expanded upon? And is that something I should be concerned about? Because the network team and the security team traditionally are pretty siloed. There's been, I've been pushing for years for more cross-training and collaboration.
[00:17:43] And that's to address a number of things, everything from, you know, not being able to find well-trained personnel to work in the SOC or the NOC to cross-training abilities to get that SOC person that may have a computer science degree but knows very little about networking. Well, you have to know about the network to apply security and vice versa, right? So I've been pushing this kind of concept for a long time. So this provides an opportunity for CISOs and other security leaders to combine resources and say, hey, you know what?
[00:18:11] Hey, security team, I see something spinning up in my environment. It looks innocuous, but this is a behavior that I haven't seen before. It's outside of our DevOps platform. We have been deploying new technologies within the network. But could you take a look at this? Because it's growing very rapidly and it's replicating itself. That is a huge cause for concern. It may just be a simple runaway stack or it may be, you know, this is what it was designed to do, especially when you're talking about installing AI agents.
[00:18:40] Maybe it's creating a set of agents behind it because that's part of its job. But if you're not watching for it, if you're not aware and cognizant of what's happening on the network all the way up into the cloud, into your virtual repositories, into your hardware, you could be allowing this massive attack to build and occur with what looks like credible identities and entities. They're allowed to do this because we gave them permissions.
[00:19:03] So if you're not watching the network in its entirety, not just thinking security mind, but also should this be doing this because it's not associated with anything else. But I think this is suspicious behavior based on how the identity or entity was used, what it's doing on the network, innocuous or not. I should be aware of that as a security leader because I'm responsible to go back to the board, to the CIO, the CTO, whomever, and say, this is what happened. And this was the blast radius. And this is how it occurred.
[00:19:33] I can't just sit there and say, we're not sure how it happened. We just don't know. We thought we saw something, but, you know, we weren't sure. So we didn't take any action. That is not defensible legally or otherwise. And looking at your research here and that figure of 85% of organizations already having encountered AI-driven attacks, combine that with everything that you've said today, none of this is something that security teams can just leave to a future roadmap.
[00:20:02] So I always try and give people listening a few actionable takeaways. So finally, what three actions should any CISO or security team take now to understand their AI exposure and try and improve their ability to detect, contain, and respond to those threats? And I appreciate that this is an hour-long podcast on its own, but any quick tips there? Yeah, absolutely.
[00:20:27] So first of all, treat every offering, everything that you put into your network, AI, security, anything, treat absolutely everything like it is dangerous. Because at the end of the day, regardless of the good intentions of the developers, of the model or anything, these things could be taken over. The information could be suppressed. The logs can be modified. There's just a ton of ways to do very bad things on the network.
[00:20:54] So be aware of your network, number one. Number two, any AI agent that you place in there, treat it just like any other piece of software. Run it through your actual sandboxed, air-gapped environment. Unlike what's happened in the news recently where models escaped and attacked other things, those were not truly air-gapped, sandboxed environments.
[00:21:17] So if you're playing around with these models and you're using them for offensive or defensive purposes or whatever you're using them for, watch everything that they do. Tie them strongly to an entity or identity and put very narrow guardrails. Limit that scope. You've heard the term. Everybody's heard the term in the industry. Don't boil the ocean. I cannot pound this into the ground any harder than I'm doing right now. Do not boil the ocean with your AI agent. You're going to run into problems.
[00:21:47] Whether it's bias, shift, hallucination, or malicious actions, something is going to go wrong if you're not very specific around the guardrails that you put around it. And the third thing is train your people. Train your people to use AI. Train them to use it effectively. Train them to understand what's good and bad. You know, it's not just using natural language prompts. That's fantastic.
[00:22:12] That's kind of the whole concept behind here is to make the job easier to remove the burden from that analyst and say, hey, now you can do more important things because we're going to automate these low-level actions. That's great. But that human still needs to make decisions. That human still needs to say, hey, you're not taking down this network segment at 10 a.m. on a banking day, Monday, or a payday, God forbid, payroll day, Thursday, Friday.
[00:22:39] You're not going to take down this network segment because you see something weird. You're going to require a human to come in and intervene and approve all of these actions. Train your people to use AI effectively and responsibly and be very particular around what AI agents you deploy on your network around that scope. And you will be in a much better position. Excellent advice.
[00:23:04] And for everybody listening, I will be including links to the Five Eyes Intelligence Alliance and that warning that advanced AI could begin bypassing traditional cyber defenses in month. I'll also include a link to ExtraHop's 2026 Global Threat Landscape Report. Some big stats in there for anyone wanting to connect with you or find out more about ExtraHop. Where would you like me to point them? Well, they can go to extrahop.com where I regularly have blogs posted.
[00:23:30] I'm also – I go out on LinkedIn quite a bit. I do a lot of reading around there and I post occasionally, probably not as much as I should. And I do have something coming up on my own, a podcast that's going to be around security beef where it's guaranteed no bull, which is, I know, very corny and cliche and I don't even care. It's the best I could come up with. But that will be forthcoming in the next six months or so. Oh, awesome. I'll be keeping a lookout for that. I'll post links to everything that you mentioned.
[00:23:59] And we did cover a lot in a short amount of time, but I'd love to – everybody listening to check out those links. Feedback, what kind of experiences are you having? What are you seeing? What are your problems right now? We'll keep this conversation going. But more than anything, a big, big thank you to you, Heath, for starting the conversation today. Thanks for your time. Absolutely. Thank you. I think Heath's warning today is memorable because it avoids treating AI as either magic or some kind of monster.
[00:24:27] An agent is an entity operating with the permissions that we give it. And those permissions can produce enormous value or spectacular damage. So security leaders should treat every new tool as potentially dangerous. Test agents inside properly isolated environments. Connect every agent to a known identity. Restrict its scope.
[00:24:54] And train people to recognise when automation should stop or where it's starting to drift. And network behaviour also matters in all of this too because machine speed attacks might not match a known signature. And logs arriving minutes later can leave defenders reconstructing damage after the event. So a big thank you to Heath for joining me in a candid conversation that could easily have continued over a cold beer for several hours. Maybe even a whiskey.
[00:25:24] But as we move from cyber defence to data centres and energy bills, surveillance, and the strange choices humanity keeps making with technology, a question for you. If an AI agent in your enterprise has admin access inside your business, who is watching what it does next? As always, techtalksnetwork.com if you've got anything for me at all.
[00:25:51] Other than that, I'll be back again real soon with another guest. So big thank you to Heath and an even bigger thank you to you for listening. Bye for now.

