AI is changing what cybersecurity companies can build, how quickly they can build it, and how the market reacts when a new capability appears. That does not mean the underlying security problems are changing at the same speed.
In this episode of Risk Grustlers, Nicholas Muy, VP of Engineering, Platform & Security, and CISO at Scrut Automation, sits down with Mike Privette, Founder and Cybersecurity Economist at Return on Security, to separate meaningful change from market noise.
Mike tracks cybersecurity companies, investment activity, and market patterns. That perspective shapes a conversation that moves between what investors notice, what customers still need, and what security teams can realistically put into practice.
Nick and Mike discuss the reaction to AI in application security, the growing difficulty of distinguishing one security company from another, and the difference between building something quickly and building something worth maintaining. They also explore what hands-on AI adoption means for security teams, hiring, and the long list of operational work that rarely receives much attention.
Underneath the conversation is a question that applies to both products and security programs: when producing more becomes easy, how do you decide what is actually valuable?
Listen to the full episode here.
Here are some key highlights from the episode.
Nick: You spend a lot of time following cybersecurity companies and investors. What has stood out to you at RSA?
Mike: I have been focusing on application security and trying to understand how the market is responding to the AI security capabilities entering that space. Public markets reacted immediately, but what I really wanted to understand was whether customers felt the same way.
From the conversations I had with CEOs, customers appeared much less concerned. They still wanted outside validation and different layers of security. These new capabilities are important, but they address only one part of a much larger security market.
Nick: Independent validation becomes especially important when AI is involved. If one model generates something, testing it with the same model can reinforce the same assumptions. How should teams approach that?
Mike: I agree. I have heard more discussion about using one model to judge another, reaching consensus across multiple models, and comparing their results.
That kind of comparison can help keep teams from validating their own assumptions. These models are extremely helpful, but if you ask one to find a problem, it will find something. Teams still need a way to test what the model produces.
The conversation then turns to the crowded cybersecurity vendor landscape.
Mike: Another thing I have struggled with at RSA is how hard it is to look through the hundreds of exhibitors, along with the many early-stage companies around the event, and understand what people are actually solving outside the core problems.
Security categories used to map more cleanly to the teams buying the products. Now everything can sound the same and sound like nothing at the same time. Much of the work still comes back to controlling access to data and protecting the data itself.
Nick: The boundaries between security categories also seem to be disappearing. A company can present itself as several different things depending on who is asking.
Mike: Exactly. AI security receives a great deal of attention, but it is a very small part of the entire industry. Most of the market still comes back to data, identity, and the same fundamental problems we have been trying to solve for years.
Nick: Setting the noise aside, what cybersecurity work has genuinely caught your attention?
Mike: I am interested in people using AI to build small, repeatable pieces of software that connect systems or improve existing processes. They are not trying to recreate an entire commercial security platform. There is much more to the total cost of ownership than building the thing, so they are focusing on the scaffolding between tools and workflows.
That is especially useful in application security. Many companies do not have enough specialized application security engineers, so people outside those roles have to learn quickly and compete for developers' time. If they can prototype something that shows an application team where a meaningful issue exists, such as an authentication problem, they can focus the conversation on work that matters.
This is an exciting moment because it has become much easier to make an idea visible and get people aligned around it. But easier production creates its own challenge. It is now simple to produce a large amount of material or software. Producing something that delivers real value remains difficult.
Nick: There is also a difference between a personal utility and a project expected to operate reliably at scale. Something can be useful to its creator without being ready to support a business. Building was never an end in itself.
Mike: That distinction is only going to matter more. Teams will have to filter through more projects and be more deliberate about what they adopt. Just because something can be built does not mean it should be built. The question is what actually matters.
Nick: Security teams learned during cloud adoption that simply saying no does not stop the business from moving. Now many security operators are being pulled into AI enablement because the business wants to move quickly and needs security involved. What cultural change are you seeing around AI?
Mike: More security teams are leaning in. They understand that if development or operations teams are using AI, security needs hands-on experience with the same technology. Otherwise, it is difficult to provide useful direction.
Blocking adoption is no longer a realistic strategy. AI moves easily between people's personal and professional lives, so organizations need to give people a responsible path forward. That is part of why AI governance is emerging. The goal should be to show people sensible ways to use the technology and then manage the exceptional cases, rather than trying to prevent all use.
Nick: Do you think some security professionals will quietly avoid using AI even as their organizations move ahead with it?
Mike: Hiring expectations are already beginning to change. I spoke with a recruiter who said this is happening across security roles, including at the CISO level. Leaders may be asked how they would motivate a team that is resistant to AI or not using it effectively.
The same shift is reaching individual contributors. Candidates may be given a security problem and asked to show how they would use AI as part of their approach in a technical interview. These expectations are starting at the high-tech end of the market, and I expect them to spread through the rest of the industry.
Nick: I am seeing that in interviews too. I ask candidates for a specific example of how they have used AI in the previous two weeks. That is the question: give me a specific example.
Mike: That is a good way to see how they approach it and think about it.
Nick: Looking toward Black Hat, what less glamorous security problems would you like to see receive more attention?
Mike: Much of day-to-day security work is unglamorous. I would like to see better ways to connect the systems, APIs, and risk information that teams already have so they can answer basic questions more quickly.
Even reporting on security coverage can be difficult. A team may be asked to tell the board how well the organization is covered, but agreeing on the denominator and producing a precise answer can take substantial effort. Better connections between systems could make those answers easier to produce.
The same opportunity exists in managing risk continuously and improving the third-party vendor process. For example, being able to consume a current risk score for third parties through an API could be useful. Those are the kinds of challenges that could affect real security.
Nick: Third-party risk is important, but many security teams do not have enough time or resources to investigate even their critical vendors as deeply as they would like. They understand the problem, but another urgent issue often takes priority. How do we help teams reach the rest of their roadmap?
Mike: Clearing the backlog could create a major change. Teams rarely reach the important work when urgent requests keep winning. As soon as one urgent task is finished, another takes its place, while the important work remains.
I spoke with a founder in the observability space whose team could finally work through infrastructure and architecture tasks that had repeatedly been postponed.
Once the backlog was clear, the team had new headspace to ask what it could do now instead of focusing only on what had to be done. If security teams can reach that point, they can start doing new work rather than continually postponing it.
The bigger takeaway
This episode is not an argument that AI will solve cybersecurity, nor is it a case for dismissing the technology as hype. It is a conversation about judgment at a time when markets, products, and working practices are changing quickly.
Mike's market perspective highlights an important distinction: investor reactions, vendor positioning, and customer demand do not always move together. AI may reshape parts of application security, but customers still need validation, and security teams still spend much of their time on data, identity, access, and risk.
For practitioners, the shift requires participation rather than distance. Security teams need enough hands-on experience to guide adoption, test outputs, and explain where the risks actually sit. That experience is also becoming relevant to hiring and leadership because organizations increasingly expect security to help them move responsibly, not simply tell them to stop.
The most meaningful opportunity may be operational. If AI can reduce the effort required to connect systems, produce reliable answers, and work through accumulated tasks, teams may finally create room for the important work that urgent requests keep displacing. The technology can accelerate the work, but people still have to decide which problems are worth solving.

Susmita Joseph is a cybersecurity and compliance writer specializing in governance, risk, and regulatory content. She focuses on making complex subjects such as AI governance, cybersecurity compliance, and risk management accessible to growing and mature organizations. With a particular interest in the intersection of AI and GRC, her work explores how emerging technologies are reshaping compliance expectations and security operations.

Barasha Medhi is a product marketer at Scrut Automation who focuses on making compliance easy to understand and easier to apply in the real world. She creates customer-facing guidance that explains not just what a feature does, but how it fits into the day-to-day work of getting audit-ready and staying that way. Her work connects the dots across frameworks, controls, evidence, and ownership, helping teams use the full breadth of Scrut’s platform with clarity and confidence.











.png)












