Meet Our Guest

Dave Mareels

VP of Product Management at Sophos

Dave Mareels is VP of Product Management at Sophos, where he leads Managed Detection and Response (MDR) and Sophos Managed Risk services. Before joining Sophos in 2022, Dave co-founded SOC.OS and served as CEO, growing the company into a recognised player in threat detection and response ahead of its acquisition by Sophos. His earlier career at BAE Systems saw him working on complex, mission-critical projects across the Maritime, Air and Cyber divisions, building a strong foundation in technology and defence.

Dave is passionate about advancing managed security solutions that help organisations stay ahead of evolving threats through cutting-edge detection and response capabilities. He focuses on the practical realities of adopting agentic AI in the SOC, helping organisations balance speed, quality and trust as they modernise their security operations.

Dave Mareels with Adam Myers

ONE-PAGER

Agentic AI in Cyber Security Explained with Sophos

Best Practices & Lessons Learned

Agentic AI is reshaping what a modern SOC looks like, but the term is being used to describe everything from a simple copilot to a fully autonomous digital analyst. This one-pager distils Dave Mareels’ view on what a genuine agentic MDR service delivers, and how to tell it apart from AI-branded marketing.

It covers the shift from generative to agentic AI, why speed must be matched with quality and trust, and the questions every buyer should ask before choosing an MDR provider. Essential reading for CISOs, IT leaders and anyone responsible for evaluating security operations partners.

Download One-Pager

Episode Transcript

Adam Myers:

Hello and welcome to our podcast, Tales from the CyberLab. My name’s Adam Myers, I’m the Sales Director here at CyberLab, and I’ll be your host for today. Joining me is Dave Mareels from Sophos. Welcome!

Dave Mareels:

Thanks, Adam. Thanks for having me.

Adam Myers:

This is going to be a special one. Can you just tell us a little bit about your role and what you do on a day-to-day basis at Sophos, Dave?

Dave Mareels:

Sure. So I’m VP of Product Management here at Sophos in the security services business and looking after all things MDR. So Managed Detection and Response is my baby. Been at Sophos for four years, technical founder background. I was before then co-founder and CEO of a small tech startup here in the UK, XDR, SecOps space. I’ve very passionate about all things SecOps and MDR. Previously it was product focused, but now I’m very much managed services focused, which we’ll be discussing today, no doubt.

Adam Myers:

So Dave, AI is everywhere in cyber security marketing right now. In plain terms, what is agentic AI and how is it different from generative AI?

Dave Mareels:

Right. So the best mental model I have for GenAI versus agentic AI is GenAI is focused very much on making the human more productive. That’s how I think about it. So Adam becomes more productive. No doubt you use GenAI the way people use GenAI today, the way I use GenAI today, it makes me, Dave, it makes you, the audience member, more productive at achieving some sort of task. That task might be preparing for a podcast, Adam. That might be summarising an email. That might be any sort of goal you have in mind, but it’s all centred around the human still. So Adam becomes more productive. You can create an email in a specific tone that you want depending on your audience. So you’ve got a goal in mind. Gen AI for you is making you more effective, more productive. It’s the best mental model I have for GenAI and its use today. How does that compare to agentic AI is very different. Agentic AI, the best mental model I have for it is it’s not making Adam more effective. It’s Adam has hired a digital teammate. So think of that mental model, GenAI using it to make me more effective, more productive versus I now have a digital teammate. And that mental model, it’s subtle, but it’s very important. That distinction is very important in cyber security. We now have a digital teammate that can autonomously conduct tasks. Everything I just said about Adam being more productive, think of a teammate coming now, joining your team. You’ve hired someone new. The only difference with this teammate now is they don’t need to sleep. They don’t need to rest. They don’t need to take a break, but they can autonomously achieve a certain task fully end-to-end without Adam’s involvement. It’s the ultimate digital teammate. And that mental model I think helps me distinguish the difference between GenAI and agentic AI.

Adam Myers:

And a lot of people give agentic AI personas and names, don’t they? So it could be like you are almost like the team leader of all these agents so you are kind of like, this person is tasked to do this for me. And I guess that’s where the world is probably going to head is as a senior leader of a business, I’ve got to think of that I’m probably going to be looking after a team of agents at some point in the future where I need to manage them a bit like how you explained.

Dave Mareels:

Exactly right. And that’s bang on. So I always look at that mental model of a digital teammate, how you manage humans. You have to almost think of it in a similar way of managing a fleet of these digital workers. It’s the best way I can think about it. And it’s the best way we’ve actually applied that mental model in the SOC and in MDR, there’s a digital human now on the scene. That changes things a lot.

Adam Myers:

And I guess that poses risk. So if not done properly or there’s no guardrails in that world, what potentially can that do?

Dave Mareels:

Absolutely. So the same way there’s a human in the loop, there’s a human before an agent. There’s risk there in the system. So you have to have controls commiserate with that level of risk. If a human goes rogue, how do you think of that threat model? But that same thinking can be applied to an agent. You have a digital teammate. What happens if? You have to go through those models. It’s exactly the same thinking as you aply for a human, but there’s just a few nuances. The digital teammate can fail at a much faster rate, for example. If a human gets things wrong, they might get things wrong at a certain frequency, which is probably a lot more manageable than if a digital human does things wrong, a digital teammate does things wrong. The failure rate is potentially tenfold or definitely in order of magnitude greater. So it’s a slightly different problem, but the very same first principles thinking apply. Here’s a risk model. What if something goes wrong? And then how do you then put controls and auditing in place to mitigate that risk?

Adam Myers:

Yeah, because I guess we’re trained to spot humans doing the same thing, maybe not quite as we want it, and we can go learn and improve. We’re probably not trained at the moment to spot where that’s maybe just going down a different path we don’t like in today’s world because it’s still new, it’s still fresh. So I guess we’ve got to try and put some controls in place to spot that and security and what you do is doing that, isn’t it?

Dave Mareels:

Yeah. So how we tackle that is guardrails upfront, really designing the use case. What do you want this? And you said it perfectly, the persona. What is this persona? What is the objective of this digital teammate? And I think rather than having it super broad, the way we’ve approached this is find a use case, find a persona that is constrained and has some very specific use cases. Case in point could be a persona in the SOC, which is a threat hunter. Perfect example. We do not have a persona in the SOC yet for an agent, which is like the SOC full stop. The SOC full stop as an agent itself doesn’t exist. It’s the individual personas as agents that exist. So there is a threat hunter. And by defining that upfront, then you can put controls and you could put guardrails and you can basically guide it through its task. So it’s absolutely autonomous end-to-end workflows to achieve an objective, but that objective is constrained in such a way that you can control to your point that it’s not an unbounded problem.

Adam Myers:

And I guess in your world, it’s making threat hunters, the human threat hunter, more productive in a sense of it’s, I don’t know, it’s probably grouping threats together and it’s doing all the heavy lifting to present it to a human to say, “This is what we’ve found. Here’s some information. Make a decision off that in terms of how maybe you might approach it.”

Dave Mareels:

Yeah. So this is back to my first point on, so gen AI is used to make this you be more productive and then there’s an agent that is codified upfront to do a full task end-to-end. It’s your digital teammate. So those two models coexist today in the SOC. They have to coexist. So the human threat hunter is absolutely using tools, is absolutely using your copilot’s models. And it’s using the GenAI in the same way we said at the start of this podcast was they’re using it to research the threat landscape better. They’re using it to make their jobs more effective. Distil all these IOCs down. Helping them in every step of their process for threat hunting, it is augmenting them. It is making them more productive. That is GenAI augmented threat hunting, but it’s still the human executing the work.

The flip side, the agentic threat hunter doesn’t need Adam to talk to it. You’re not having Dave to say, now do this. It is upfront, fully autonomous. It completely changes the game when it comes to threat hunting. It is always on proactive. This agent gets triggered. It’s not triggered by Adam’s chat. It’s triggered by, oh, new threat research is available on Jira on WikiNow. Our threat research team has published something. And then the agent goes, remember your digital worker goes, oh, I’ve got some new threat intel. And it goes, it reads the report, extracts the report. It thinks about what queries it should write. It goes and crafts those queries and then it searches retrospectively on your data lake. It understands your data lake. It understands the structure of your data lake and it goes and hunts and then it understands the results and interprets those results and then it presents those results. That’s the difference. Fundamentally, it’s the digital worker that is executing the full end-to-end objective of start with a trigger of threat intel and present it what you’ve found and then everything in between fully autonomous. That’s really powerful stuff.

Adam Myers:

And the speed it can do that.

Dave Mareels:

The speed is phenomenal. So we’re just about to release the threat hunting agent, the next iteration of it, and it can basically do that very process, which I just spoke about, get a new indicator of compromise from a threat research report, PDF format, reading it, extracting it, grouping it, creating a query, conducting a query, and then presenting results in less than a second. That’s phenomenal. Wow. It’s phenomenal. So it’s a step function change in the outcome it’s providing to the customers. And that’s what makes this very exciting. And someone like us building those, partnering with you guys, bringing out MDR, what gets me really excited about this whole era, this agentic era, is it is now a step function change from an outcome point of view. And this is what I think the industry, we’ve sort of lost our way, but everyone, and if any of the viewers went to RSA or to Infosec, you’re probably rolling your eyes. And if you’re a buyer out there, I genuinely feel sorry for you because all of a sudden overnight, everyone has slapped on, I’m now an agentic MDR, I’m now an agentic SOC. And it’s really hard as a buyer to separate the chuff from the wheat because now all of a sudden every traditional MDR is now an agentic MDR. So what does actually agentic MDR mean? In my eyes, it means a complete step function change in the outcomes you can provide. Think about that threat hunting example I just gave. That is a fundamentally better customer outcome. And that’s what agentic MDR is all about. It’s not sprinkling AI. It’s not putting a marketing brand on there. It’s about redesigning your MDR with the context of a digital worker is now in the SOC being able to provide much greater, much better customer outcomes. And that’s what’s exciting about this.

Adam Myers:

Yeah, because I don’t know, I walked around Infosec and whatnot. It’s difficult. I work in the industry and it’s really difficult to understand the message and there’s so much going at all angles, you’re a bit overwhelmed, aren’t you? It’s an amazing experience to go there, but if I was a consumer or buyer or a business or a CTO, I’m probably thinking, “Where do I start?” That’s hard. It’s difficult to… So you need your suppliers, your trusted relationships to say, “Where should I be on this journey right now?” And I think things like this that we’re trying to do today is geared towards sharing knowledge and information of where to start that journey.

Dave Mareels:

Yes. And I think if I had to give advice to any buyer out there, and I always give this example, I’m a big basketball player, I love basketball, gruff with it. It’s like saying, “I play basketball. Dave plays basketball. And LeBron James also plays basketball.” And you say, “Well, they’re both basketball players.” And you conclude therefore they’re the same. That is a completely flawed logic as everyone you can imagine. Just a very quick test of Dave versus LeBron 1 on 1, and all of a sudden you’ll realise that they’re absolutely not the same players. And I feel like that’s the same thing that’s happening in the cyber industry. Everyone is an agentic SOC. Everyone is an agentic MDR. And if you abstract at the wrong level, and if you’re speaking to a vendor and they just keep it at the high level of, “We have agents. Yeah, we are agentic. We use AI.” And then you speak to your next provider who says exactly the same thing, you’re going to conclude they’re the same. And it’s a big variance in the market out there. So my advice is go that level deeper. Ask that next level of abstraction. The one level deeper in abstraction layer of, okay, what does it mean to be an agentic MDR? Define it for me. Are you just using GenAI? Are your analysts? And I think this is a maturity scale. A lot of different MDRs. And I think at a high level, everyone’s going to say, I will claim we’re an agentic MDR, absolutely. And then the next startup will claim they’re an agentic MDR, but they’re very different to my point. So you have to then say, well, talk to me about the journey. What is the workflow? What’s the operating model look like in your MDR as a provider? And if it sounds like I’m using GenAI, like we said at the start, to help me summarise a case, to use an assistant to copilot to say, sumarize this alert, what should I do next? Conduct a response action. That I would say is probably the first, it’s a good first step, but it’s a pretty immature outfit. An MDR that’s sort of sprinkling GenAI, probably the start of their journey for an agentic SOC. I wouldn’t say that’s a full agentic SOC. The agentic SOC is one that has those augmentation layers, the copilots that help my analyst summarise a case and respond quicker. But it’s also the one that has the digital teammate alongside where it’s human and it’s the digital human working together in unison and handovers are there. You have an agentic threat hunter, you have an agentic investigator. That I think is the next stage of maturity. And I think that’s where we are at Sophos MDR. We have the full autonomous agents with personas, full end-to-end autonomy in there. And I think that’s the next phase. And I think that’s where. Anyway, that’s the bar I hold myselves and our team is you’re not an agentic SOC until you have not just the augmentation layer from GenAI to make you more productive and better, but you also have the digital teammate working side by side with you.

Adam Myers:

Listen to this episode, one thing becomes really clear. The speed and complexity of modern threats are pushing security operation models to their limits. And that’s exactly why CyberLab are helping organisations take a more modern approach with next gen SOC and SIEM technology. And we speak to organisations every single day that need stronger threat detection, faster responses, and a service that can keep pace with modern emerging threats. Sophos Taegis MDR reflects the shift we’ve been discussing in today’s episode with Dave. CyberLab and Sophos have a history of over 20 years working together and we help organisations move forward with greater clarity, more confidence with our next gen SOC and SIEM technology. And you can find out more at cyberlab.co.uk. Now back to the episode with Dave.

So I guess Dave, why is change happening now? What’s broken about the way most SOCs or MDR services operate today?

Dave Mareels:

So I think the platform shift that we have, which is LLMs are here, GenAI is here, similar platform shifts we’ve had that I see it as comparable platform shifts. It’s like the internet is here. Mobile is here.

Cloud is here. These are distinct moments in time where there was a genuine platform shift. This technology that we have on our hand, I classify if not just as good as those three that I mentioned, if not better. It is a platform shift. So fundamentally we have a phenomenal technology on our hands here. Equally, the attackers have the same access to those tools. So there’s two things here. There’s the attackers using GenAI to be more effective. Now we’ve been saying this for years and every year, what’s a prediction we can make? It’s like the threats are going to keep evolving. The only thing that’s constant in this space is change. I love that quote. The only thing constant has changed in this space in particular. So threats will continue to evolve with LLM. It’s now LLM-powered threats that are going to continue to evolve. So you have this threat landscape, it’s always continuing to evolve, but it’s going to evolve at a much rapid pace now with the introduction of this technology.

Adam Myers:

And the volume, I guess.

Dave Mareels:

The volume, the effectiveness, the language barrier disappears. I can write perfect phishing emails in any language I want now. So it’s the reconnaissance phase for the attackers gets a hell of a lot more effective. But equally where we get excited, and I’m a raging optimist, but I believe that the marginal gains for the defenders is greater than the marginal gains of the attackers with the advent of this new technology. And so there’s a responsibility there for us to adopt this sensibly. And back to your question of why is this different? How is the old world broken? It’s not because the old world was bad in its own right. It’s because we have such a powerful technology in our hands today that therefore that means the outcome we can provide when we adopt that technology is going to be a step function change from a customer outcome point of view. Could you imagine a world where now my mean time to respond or my mean time to detect is now measured literally in seconds. So in our SOC, we’re seeing 90 second MTTRs, mean times response across such a global scale. Two, three years ago, we were talking in 40 minutes. So that is going to drive what? That is going to drive customers to have an expectation that is far greater than where it was last year. And the market dictates. Eventually the buyers will dictate. So if you do not adopt this technology to advance the customer outcome from a speed and quality, it can’t just be speed. I can give you speed. I can give everything done in a millisecond, but without quality, you fail. So you need speed and quality. And so I think with the introduction of GenAI into the SOC with these digital teammates now being able to provide a fundamentally different and far greater, far superior outcome from a customer point of view, if you do not adopt this, you will lose and you’re going to lose quickly. Your incumbency, I think, and how we are working internally is that’s the mindset is your incumbency is limited and you have six months. That’s how we are constantly operating. You have six months before you go out of business. That’s the urgency we need to adopt this because the outcome is so much greater that the customers is now going to demand seconds. They will demand quality. They’re going to demand a digital teammate. They will demand higher outcomes in the buying cycle. And just think of what a joke it would be if you’ve got three legit agentic MDR providers that you’re putting forward to the customers with phenomenal quality, with phenomenal speed. And then you chuck in a traditional SOC, which is like, well, we’ll do it in 50 minutes and we’ll look at only half of the stuff and the quality will be okay because we are fundamentally bottlenecked by humans. Sorry, you’ll be laughed at the room. So the technology is so great that means the customer outcome is going to be so much greater. Therefore, the market expectation is going to be much higher. So it’s not because the old model was bad, it’s because the customer baseline of expectation is going to shift.

Adam Myers:

And equally, there’s probably a lot of customers who are listening who are sat on traditional seam solutions of old. They’ve maybe done it from a compliance perspective, consumption model, paying a fortune. They’re not probably pulling all telemetry in. Those days are gone, aren’t they? No, that doesn’t happen surely now. And listen to what you are saying, it’s like it might be a small project to start with to make that transition, but what the benefit is huge.

Dave Mareels:

Massive, massive. I seriously see it as think of trying to sell a horse today. You go to a car? Yeah. Adam could sell a horse. I’ll try. Well, it depends on who. But if I was looking for a car and you try to sell your horse, it’s a fast. It’s an example. It’s a joke. But to tell an example, I think it’s exactly the same world we’re going to be entering in when we talk about the agentic MDR providers and you coming in with an old standard operating models with just humans that the old model is an alert fires, it sits in a queue, human picks it up, human does everything. And then human responds compared to the alert’s being picked up in a second, an agent’s completely investigated it. Only if it needs help. It’s going to go, “Hey, Adam.” Because accountability has to remain human. And then that agent carries on and it says, “Adam, can you take a response action?” And you have to be in control. You’re accountable for business decisions, for disruption, for response actions. That is a fundamentally different model. It’s a fundamentally different operating model. And again, it’s going to drive an expectation from the customer side that then is going to drive competition. If you do not adopt this, it’s going to be a competitive disadvantage and ASAP it’s going to happen.

Adam Myers:

And equally, if you are in role at the moment as, I don’t know, an IT leader, cyber leader, boards are going to want these things quicker. Other businesses are doing it, we want to keep up with the trends. It’s like it’s time to evolve and move that technology, isn’t it? It’s shifting so fast. You don’t want to get left behind.

Dave Mareels:

Absolutely. Yeah. Yeah. And it is driven fundamentally. The threat landscape’s evolving, so that’s a driver. Let’s not just say it’s pure competition and a great technology and you have to adopt it or you’ll lose. You also need to adopt it because the attackers are. So it’s all related. The landscape’s moving so fast. Every board member is now going, “Frontier AI is here. It’s going to find every exploit in seconds and I’m going to have to patch in seconds and I have to remediate in seconds.” That is fundamentally a different risk tolerance equation that businesses are going to have to grapple with. I think it’s one of the biggest challenges we have that I don’t think we’re fully prepared for yet as an industry where customers in a large enterprise especially, if you can get a critical patch, if you can get a critical VON patched within 30 days for a large enterprise, 10 days, that’s pretty good. It frightens me to think that we have to potentially go to zero, to go from exploitability found, patch immediately. And so that is a completely reframe of the problem. So how do we change our risk tolerance to adapt to that? And that’s also what’s going to be in the front of people’s minds is they’re reading the news about Frontier AI and they’re saying, “Wow, we need to adopt this. ” And that’s again, further going to drive customers to choose vendors that are adopting GenAI and maximising the potential of that technology.

Adam Myers:

I look at this next gen SOC and seam. It’s the glue. It knits everything together, isn’t it? It’s the core of what you should have at the hearty technology stack, how you work with Microsoft, how it pulls telemetry from investments you’ve made in the past with other vendors. It’s the heartbeat of what will pull all this together, how you knit all your tools and technologies together. Because historically in the past, it’s not been that way, is it? It’s been up to the human to try and do something there. I’ve had many calls with customers and they’re saying, look, this isn’t quite talking to this. You talk around backup, DR, all these other areas, firewalls, that all needs to be pulled in.

Dave Mareels:

Absolutely. And it is. And that’s why I think the open platform play, and you’ve heard about our recent launch, the native cyber defence system. If we’re calling it as a defence system now, that’s the language we’re using. And it very much is. It’s a platform, it’s open, it’s a system that can talk to each other. Gone are the days where an endpoint alert requires just an endpoint response action. It’s an endpoint alert that potentially needs an identity revoked or a session revoked in Google or in Microsoft. So it’s so important that those systems are all integrated into the platform and then the system’s there. And as you said, GenAI powered that can talk to everything, conduct response actions. That’s also the new benchmark. Could you imagine trying to sell a point solution and a point server? It’s laughable.

Adam Myers:

Yeah. It has evolved rapid though, has it? That has changed very quickly. And people like yourself who are at the heartbeat of doing that, the decisions you make are having a massive effect on the industry I think. And it’s going quick.

Dave Mareels:

And we have to evolve. It’s again, driven by the threat landscape and the need and that customer demand is increasing, is increasing, is increasing. Yeah, we have to, and we are. We’re working night and day with that mission in mind and the vision and the mission for us. The mission shouldn’t change. The mission should always be grounded in customer outcomes. We are here to protect and CyberLab and the Sophos partnership, that we embody that mission of we’re here to protect you against today’s threats and we’re here to further your resilience against tomorrow’s. And that mission statement’s powerful because it’s time independent. That mission statement remains true today and it remains true tomorrow. But what changes is the threat landscape today changes. And how do we prepare for tomorrow’s threats? How do we make you resilient for tomorrow’s threat is always changing as well. And now with the GenAI technology that the attackers are using, even more so that mission remains so true, so critical.

Adam Myers:

So Dave, for an organisation looking at MDR or considering switching providers, what should they be asking during that process?

Dave Mareels:

There’s a few fundamental questions. I think the scale of the operation behind the scenes. How wide is your threat? Your threat vantage point I think is a super crucial point. The attackers do not operate fundamentally within geographical constraints. So your provider should not be geographically constrained. So you need global scale. Do you have customers in every sector, in every shape, in every size, in every country? And why is that important? Is because you have a threat landscape view that you can then turn that into an advantage from a better detection outcome point of view. So I think scale of operation behind the scenes is absolutely fundamentally important. I’ll be asking that. I would be asking about the flexibility. We spoke about that. Can you integrate with my stack? How is it going to integrate? How is it going to maximise my ROI on my Microsoft investment? That’s crucial. Is it just a closed ecosystem or is it open? I think that’s fundamentally important. And then true to an app to this theme is GenAI, what are you doing? What are you doing with the Agentic technologies? How are you adopting this? And what’s your north star with it? Is it drink the AI Kool-Aid for the sake of drinking AI Kool-Aid, or is it fundamentally grounded in a better outcome for me as a customer? Are you getting faster? Are you getting higher quality? I think my advice to customers out there is don’t just focus on speed. Speed is one aspect. The other side of that coin very importantly is quality. It has to be together. I told you I could do everything. I can shut down every single case in the SOC that gets created and I can say I’ll resolve everything in a second. But if I’m not investigating and doing my due diligence and I’m not doing it with quality, no customer in the world in their right mind is going to like that outcome. It has to be speed and quality. So please advice is when you’re speaking to vendors, ask for speed, ask for quality and ask for metrics to back that up. And then lastly I would say is the agentic outcome. Again, how are you adopting that in the SOC? If I had to give one last piece of advice to any buyer out there around what sort of questions to ask, I think this is becoming increasingly more important, especially with the adoption of agentic technology and gen AI. We are using it a lot in our SOC and I absolutely, hand on heart, we are doing it with the right mission, the right North Star, a better customer outcome. But I think one crucial, crucial question that not many people ask, but it is becoming more top of mind for CISOs, is if I’m going to partner with you as my MDR provider of choice, how do you give me assurance that your message of I will reduce risk, this is what it’s about, by partnering with you to reduce my risk, you are claiming that, how are you going to give me assurance that whilst doing that, you don’t also introduce risk? And what I mean by that is what controls do you have in your own SOC with security in mind that is not going to introduce risk into my own environment? Because it’s a highly privileged relationship. MDR? I have access to their systems. I have access to their Microsoft environments. I can conduct response actions. I have admin level access to a lot of the endpoints and service. That comes with a risk that comes with risk. And so ask the question when you’re looking at MDR providers, when you’re looking at managed services, what are you doing internally? Don’t just waffle. Show me proof. Show me how you’re tracking that risk internally. What measures, what protective controls are you implementing in the SOC? An example could be, and this is what we do is before a response action takes place in Sophos MDR, there’s a step up FIDO2 authentication. Say who you say you are. And the fingerprint from Dave, the analyst, before I isolate the domain controller. So security controls in the MDR vendor itself is a question I don’t hear often enough. And I would employ any CISO, IT Director, any buyer in the MDR space to ask that question, how are you making sure you don’t introduce risk by partnering with me?

Adam Myers:

Because you just assume trust, don’t you?

Dave Mareels:

You do.

Adam Myers:

And really you should be benchmarking.

Dave Mareels:

Trust but verify. Trust but verify. And I think there’s been quite a lot of platform incidents over the last year and a half that’s making this more and more pertinent. So I think we’re going to see more secure by design almost be mandated as a sort of a baseline expectation from customers. What’s your secure by design policy? Question you never hear in the buying cycle, what’s your secure by design policy? What are you doing in your SOC to mitigate the risk of potentially one of your analysts? Real threat. Imagine that an analyst, an MDR provider’s analyst going rogue.

Adam Myers:

Insider threat risk.

Dave Mareels:

It’s the insider threat risk that is overlooked in the buying cycle. And I would strongly encourage every CISO, every buyer in this space to hold the vendor to account to say, “What are you doing to not introduce risk whilst claiming you’re reducing my risk?”

Adam Myers:

Yeah. I think, well, you’ve demonstrated what Sophos is doing, so I think I think that’s fantastic. And there’s a lot of trust there. We are at the heartbeat of that and I think it’s a really good tip to take away that. Yeah, really powerful. So if there’s one thing you could give as a top tip from this podcast, Dave, to our audience that they should be considering in their new year and what they should be doing around cybersecurity, what would it be?

Dave Mareels:

It’s back to my first point, don’t believe the hype, don’t believe the marketing message of the agentic SOC. Don’t compare Dave and LeBron James because they’re both basketball players. Go down that level of abstraction, ask questions, ask the what’s your mission, how are you implementing it with my outcome in mind and get the vendor to define what that outcome is, how they’re tracking it, how are they keeping it auditable? How is trust? I think my advice would be really rooted in my advice is the trust question. Not many people are talking about trust. We’re saying speed. Some of us are saying quality, but I want customers out there and buyers out there. The top tip is unpick the trust question, unpick the trust equation and say, what are you doing? How am I going to trust you? You are adopting these technologies faster than I am.

Give me trust in the way you’re doing it, your way you are adopting that. Aligned to my outcome is appropriate, measured, and not only going to give me brownie points for innovation, but it’s going to do it. We’re going to scale really quickly. It’s going to be fast. It’s going to be quality, but it’s done so in a very considered, thoughtful, risk sensible fashion. I think that’s my biggest tip to unpick the trust question in this day and age, especially in the agentic era. Yeah.

Adam Myers:

Amazing. Our first guest that’s joined us for a second time. I want to say thank you, Dave. That is an amazing episode and I’m sure our audience will really enjoy listening back. Thanks for having me. So that concludes this episode of Tales from the Cyber Lab. Join us next time for a brand new episode.

Until then, stay secure.