For Charlie Thomas, the question is no longer whether security teams should use AI. He believes defenders increasingly need it simply to keep pace with the scale and speed of attacks.
But access to AI does not solve the rest of the security problem.
Enterprises still need to know which agents are running across their environments, which human and non-human identities are involved, where sensitive data sits, and how quickly they can detect and contain an attack when preventive controls fail.
In this episode of Risk Grustlers, Charlie Thomas, CEO of Mitiga, joins Nicholas Muy, CISO and VP of Engineering at Scrut Automation, to talk about frontier and open-weight models, AI adoption in security, agent visibility, identity, SaaS exposure, incident response, and why many security programs may need to be reconsidered for the environments they now protect.
Charlie describes Mitiga as providing runtime detection across modern infrastructure, including cloud, SaaS, identity, and AI, with a focus on mid-to-large enterprises.
Listen to the full episode here.
Here are some key highlights from the episode
Nick: Just before we started the episode, you mentioned a question a lot of us are hearing today: frontier models versus open-weight models. What does that mean for defenders? Is this something you're hearing from customers and other security teams?
Charlie: It's certainly the topic du jour. I think it'll be a big discussion here at Black Hat this week.
At the end of the day, defenders and CISOs absolutely must use AI in order to defend against modern attacks. That's only accelerated over the last six to nine months and continues to accelerate.
Without the ability to freely use AI, whether it's frontier models, open-weight models, or some hybrid combination of the two, there's just no effective way to defend against modern attackers.
It's essential that the security community has access to those models in a fairly ubiquitous way to successfully defend and protect enterprises.
Nick: I didn't expect that this would be the problem we'd be dealing with in 2026. I thought the question would be whether security people wanted to use AI.
A lot of security people are fine using it like any other technology. But defenders are running into a problem where sometimes they can't use AI to do their jobs or defend against attacks.
The attacks themselves aren't always novel. They may simply be happening in more places, in more ways, and more frequently.
Charlie: If I look back to Black Hat last year, everyone was talking about AI, but I don't think it was as broadly adopted by the security community as it is now.
People recognize that it's a requirement. It's not something we're gradually working toward.
It has become cliché to say it, but humans can't keep pace with the volume of attacks. You're going to have to use AI.
Nick: But then we have to make sure the AI we're using doesn't stop us from using it. That's really inconvenient when you're in the middle of an investigation.
Charlie: Unquestionably, that's problematic, and it needs to be remedied.
I think there will ultimately be multiple models: internal models, open-weight models, and frontier models. I don't think there's going to be a single solution, given how quickly things are changing.
It's still to be determined what that looks like even six months from now.
Charlie: When you're defending in this new AI environment, you have to know your inventory and what you're defending.
In the agentic world we suddenly find ourselves in, CISOs have to move faster than they historically have, and faster than large enterprises have traditionally been able to acquire and adopt new technology.
Having an accurate census of the agents running across your enterprise is incredibly challenging. The CISO doesn't even own all those different agentic workflows and processes.
The way we look at the world is that everything starts with identities, both human and non-human. Without an accurate inventory of that, it's difficult to defend effectively.
Identity is still a foundational part of security, even with everything becoming more agentic.
Nick: What's the most common thing you advise customers on when they're getting started with this, especially when some may already be starting from behind?
Charlie: We start from a fundamental point of view that prevention ultimately fails.
That doesn't mean preventive tools aren't important. Posture tools matter. Layers of defense matter.
But in spite of the best security tools, processes, teams, and defenses, attackers still get through.
So we start by assuming that some attacks will get through. Then the question becomes: how do you identify that as quickly as possible, and how do you contain it as quickly as possible?
Mitiga's DNA is around incident response. That's how the company got its start. Our approach is not to say we're going to block and stop everything. There are going to be attacks that get through.
The goal is to detect anomalous activity around those human and non-human identities and stop the attack before it seriously affects the business.
Nick: Do you still do incident response, or help customers with that part?
Charlie: We don't offer incident response as a service the way we did in the company's founding years.
But we are involved in helping customers when there is a need for incident response. Inevitably, incidents will happen, and when those situations arise, customers do lean on Mitiga and count on us to support them through those incidents.
Nick: For your customers, have you seen anything in particular driving them to act? Historically, we'd always say the best time to take over a security team was right after an incident because suddenly there was urgency and budget.
Charlie: There's no question that right after an incident there's often a lot of urgency to make changes and take action.
What we've really seen over the last 12 months is a convergence.
Cloud is widely adopted now. What started driving urgency was the exposure around SaaS applications.
Many companies aren't even getting logs from some of those SaaS applications, yet highly sensitive data can reside in platforms such as Salesforce and Workday.
From a security practitioner's perspective, not having visibility into those platforms is a known and significant gap.
That was driving a lot of urgency. Now, I think AI has become another major source of urgency because organizations also need to protect how AI is being used within their environments.
Nick: What do you think will be some of the biggest things you and your customers will be dealing with over the next 12 months?
Charlie: We're seeing an acceleration in the use of AI across the enterprise.
There was this idea that CISOs were trying to slow down AI adoption. I never really saw or spoke to any CISO who thought they had the ability to do that.
Today's CISOs are broad, business-oriented leaders. They recognize that AI is important for their companies to remain competitive.
They want to support AI adoption, and they want to support it in a way that makes sense.
A lot of the customers we work with are in regulated industries, particularly financial institutions, so they also have compliance considerations that need to be factored in.
Nick: Have compliance requirements, customer requests, contractual agreements, or operating in regulated industries contributed to adoption or security improvements with the companies you speak to?
Charlie: For sure. We see compliance playing a role.
Banks, for example, are large, complex, and heavily regulated. Regulatory requirements are a real driver for the customers we work with, which is also one reason heavily regulated industries are an important area for us.
Nick: If there's one last thing you'd want to share, what do you think people should be paying attention to or spending their time on?
Charlie: Some of these attacks aren't necessarily sophisticated. Some are fairly novel in their approach. So the basics and the fundamentals remain extremely important, even in this agentic world.
Beyond that, think about the complexity of your environment today compared with what your security program was originally engineered for.
I think most organizations are at an inflection point where they need to rearchitect their overall security program.
I'm not talking about just tools. I'm talking about process, framework, and technology.
The bigger takeaway
AI adoption is moving faster than many of the systems security teams traditionally use to govern and protect technology.
Charlie keeps returning to a few fundamentals. Security teams need visibility into the agents and identities operating across the enterprise. Preventive controls still matter, but teams also have to assume that some attacks will get through and be prepared to detect and contain them quickly. SaaS and AI are creating new areas where organizations may have limited visibility, even while sensitive data and business processes increasingly sit inside them.
The answer, in Charlie's view, is not simply another security tool.
The harder question is whether the security program itself still matches the environment it was built to protect. As cloud, SaaS, identity, and AI become more interconnected, organizations may need to revisit the processes, frameworks, and technology behind the program, while keeping the security fundamentals intact.

Susmita Joseph is a cybersecurity and compliance writer specializing in governance, risk, and regulatory content. She focuses on making complex subjects such as AI governance, cybersecurity compliance, and risk management accessible to growing and mature organizations. With a particular interest in the intersection of AI and GRC, her work explores how emerging technologies are reshaping compliance expectations and security operations.

Barasha Medhi is a product marketer at Scrut Automation who focuses on making compliance easy to understand and easier to apply in the real world. She creates customer-facing guidance that explains not just what a feature does, but how it fits into the day-to-day work of getting audit-ready and staying that way. Her work connects the dots across frameworks, controls, evidence, and ownership, helping teams use the full breadth of Scrut’s platform with clarity and confidence.



%20(1).png)























