Transcript
And creating code way faster, with more volume of code. There's a lot of concerns of whether the code is actually secure. Pacific has total capabilities like jewel-based assistance where you can actually generate code. Based on our analysis, it's very, very important that organizations run those new AI-generated code capabilities through security controls. Otherwise, you're pushing insecure or potentially malicious code into production, which can be very dangerous. I think, again, for this, a lot of like kind of threats and pessimism in one perspective. I think, as we know, there's also a recognition, I think, from last practitioners that AI can be actually be used for good, right? So I'm curious about, Juergen, and I think you were touching a little bit on it, like where do you see that AI can actually be used by defenders to really protect themselves against this new reality? Yeah, before I respond to that, I just wanted to add to your previous comment, right, that exposure window. I think that's an important topic for enterprises to realize with this new wave of zero days and vulnerabilities being identified by AI. Already in our 2025 M-Trends reports, we saw that the average exposure window is now negative seven days. What this means is that attackers are using vulnerabilities before a patch is even realized. That means you, as a CISO, will have to accept that you're going to have vulnerabilities, you're not going to be able to patch fast enough. That is one reason. The other reason is just simply that we expect, of course, a very significant number of vulnerabilities to be identified. And as we've already seen in the past several years, we're going to also deal with vulnerabilities in systems that can no longer be patched. Maybe the manufacturer no longer exists, the devices are end of support, end of life. Most enterprises deal with challenges like that. And I think this is a critical moment for us, again, as cybersecurity professionals, to realize, to go back to a lot of the foundations that we've been talking about for so long. Defense in depth, zero trust architectures, improving cyber defense capabilities. All of these things are going to be critically important. Obviously, patching and changing and updating your vulnerability management program is absolutely critical. Reducing your attack surface is critical. But also, all of the additional security controls that we've been talking about for all these years are going to be critical because you have to assume breach. You have to assume you're going to have issues that you're not going to be able to fix fast enough before a threat actor potentially identifies that. But I agree with you. Let's leave the doom and gloom a little bit behind us. And let's also talk about how AI helps the defenders. And by the way, I do believe that AI will give a greater advantage to the defenders than to the threat actors, right? It may seem at times like things are not in perfect balance, but I think over time, AI is a huge advantage for us as defenders.