As Black Hat USA 2026 descends on Las Vegas, the show floor will be crowded with vendors claiming “agentic” credentials, but few are willing to say exactly what happens when their AI gets something wrong. Arctic Wolf wants to be the exception. Ahead of the show, VMblog caught up with Will May, Chief Revenue Officer at Arctic Wolf, to talk about the company’s Aurora Superintelligence Platform and Aurora Agentic SOC — which the company describes as the largest commercial agentic SOC in the industry, processing more than 10 trillion security events and 200,000 investigations every week. May argues that adversaries have industrialized their attacks with automation, and that simply buying another point product no longer closes the resulting gap; what’s needed, he says, is an entirely different security operating model.
In this Q&A, May previews what attendees can expect at Arctic Wolf’s booth (#1564), including a live, unscripted demonstration of the Aurora Agentic SOC investigating a real case end to end — escalations and all. He also digs into the numbers behind the company’s Swarm of Experts™ architecture, which autonomously closes the majority of case volume while routing the rest to human analysts, and explains why Arctic Wolf believes the next frontier isn’t stopping every attack, but building the organizational resilience to keep operating when one inevitably gets through. From emerging threats like credential-based attacks and agentic AI showing up in live incidents, to the governance gap opening up as AI systems become a new class of digital identity inside the enterprise, May lays out where he thinks the industry’s attention needs to shift heading into the second half of 2026 and beyond.
++
VMblog: For readers who may not be familiar, give us the elevator pitch: who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.
Will May: Arctic Wolf is the cybersecurity and AI company that turns cyber risk into business resilience.
AI has changed the economics of attack. Adversaries move faster, automate more, and operate at a scale that used to require a team of skilled operators. Buying another tool does not close that gap. A different security operating model does, and that is what we deliver through the Aurora Superintelligence Platform and the Aurora Agentic SOC, the largest commercial agentic SOC in the industry.
The platform processes more than 10 trillion security events a week and runs more than 200,000 investigations in that same week. Specialized AI agents carry the volume. Human experts carry the judgment calls. That division of labor is deliberate, and it is the whole point.
Most security vendors sell products. We deliver an operational outcome: less risk this quarter than last quarter, and a business that keeps running when something gets through.
Black Hat attendees are a discerning crowd. What booth experiences, live demos, or hands-on activities are you bringing to Las Vegas?
May: Our booth is built around one question: can you trust AI to defend your organization?
You will see the Aurora Agentic SOC investigate live. Not a slideware walkthrough, an actual case moving through the pipeline: telemetry in, agents investigating, the AI Trust Engine™ validating the call, and then either a high-confidence closure or an escalation to a human analyst. We will show both paths, escalations included, because the escalation is the part most vendors edit out of the demo.
We are also going to argue with a piece of conventional wisdom: that security success is measured by attacks prevented. Prevention still matters. But when 63% of organizations had a significant incident last year, a strategy that only measures prevention is measuring half the problem. We will spend our time on the other half.
And take a pair of our shoes on the way out. Arguably the most stylish item on the floor, and a useful reminder that surviving Black Hat takes both trusted security outcomes and comfortable feet.
VMblog: What’s your Black Hat origin story? Longtime exhibitor or fresh face on the floor? What keeps your company coming back?
May: We have been part of this community for years, because Black Hat is one of the few places where the hard conversations happen in real time and in public.
What is different this year is urgency. AI changed both sides of the board at once. Attackers are faster. Environments are more complex. And most security leaders are still working out where AI creates value versus where it quietly creates new risk.
That last question is the one we come to have. Not the hype version of it. The practitioner version.
VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?
May: The future of cybersecurity is not human versus AI. It is human and AI, with a clear line between what each one is trusted to decide.
Every vendor at this show will tell you they have agents. The harder question is what happens when an agent is wrong. Our answer is specific: the Swarm of Experts™ autonomously resolves more than 60% of case volume as high-confidence closures, and everything else escalates to a human analyst. The AI Trust Engine™ validates decisions before they become action.
We would rather tell a CISO what that number actually is than imply it is 100%. A vendor claiming full autonomy is either not measuring or not saying.
VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors is your solution most directly built to address?
May: The biggest shift is that threats no longer arrive one at a time on a predictable timeline. They arrive concurrently, at machine speed, with attackers using automation across every stage from reconnaissance to exploitation to lateral movement.
That is the premise behind the Aurora Agentic SOC. Rather than building a bespoke defense for every emerging vector, we built an operational pipeline that takes all of them: identities, endpoints, cloud, networks, applications, attack surface. Stolen credential, exposed edge device, phishing lure, vulnerable internet-facing asset, AI-enabled attack. Same pipeline, same speed, same consistency.
What we are actually seeing in the field is worth being concrete about. Arctic Wolf Labs observed active exploitation of Palo Alto Networks GlobalProtect authentication bypass vulnerabilities used as an initial access vector for follow-on ransomware. We have seen the same pattern repeat across perimeter technologies as attackers concentrate on internet-facing systems.
Identity remains the most attractive target. Credential theft campaigns such as FortiBleed hit organizations across 194 countries. Infostealers keep harvesting credentials through GitHub repositories impersonating trusted brands, adversary-in-the-middle phishing built to bypass MFA, and QR-code phishing timed to high-profile events. These succeed because they target the seams between people, identities, devices, and controls, not because they defeat any single technology.
Agentic AI is also showing up in real incidents now. AI systems have moved past assisting humans and into executing multi-step actions on their own.
The category list matters less than the tempo, though. The defining challenge of 2026 is that attackers operate at machine speed and most security operations do not.
VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for, and with, autonomous AI systems, and what risks are enterprises underestimating?
May: Start with the number we get asked about most. The Swarm of Experts™, our patent-pending architecture for coordinating specialized AI agents, autonomously resolves more than 60% of case volume as high-confidence closures. The remaining cases escalate to human analysts with the context, expertise, and authority to make the call.
That ratio is the design, not a limitation of it. Rather than relying on a single model, specialized agents collaborate across the workflow: investigate, analyze, validate, resolve. The escalation path is a feature. It is what lets us put a number on the part AI handles alone and stand behind it.
On the other side of the equation, we are helping organizations secure the AI systems they are introducing into their own businesses. AI agents are becoming a new category of digital identity with access to sensitive data, applications, and workflows, and most organizations are moving faster on AI adoption than on AI governance.
That gap is the risk we see most underestimated. Companies are focused on what AI can do and not nearly enough on validating its decisions, governing its access, and understanding its behavior. Speed without validation is not an advantage. It is a new attack surface.
VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?
May: AI-native means AI is not a feature bolted onto a legacy platform. It is the substrate the whole operating model runs on.
But that phrase is doing a lot of marketing work across this industry right now, so here is how we would suggest testing anyone who uses it, ourselves included. Ask three questions. What percentage of your cases close without a human touching them? What happens to the ones that do not? And what is your process when the AI gets it wrong?
Our answers: more than 60%, they escalate to a named human analyst, and the AI Trust Engine™ validates decisions before they become action. Those are checkable claims. A lot of AI-native pitches are not.
VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026?
May: We are introducing a new metric for measuring detection and response effectiveness. Traditional metrics measure speed: how fast did you detect, how fast did you respond. We think that is the wrong finish line. What matters is how quickly a security team receives an outcome they can trust and act on.
Alongside that, the platform now processes more than 10 trillion security events and conducts more than 200,000 investigations every week, and we have resolved more than 3 million cases to date.
We are also pushing a broader conversation about cyber resilience. Preventing every attack is not a realistic goal, especially as AI lowers the cost and raises the scale of cybercrime. The organizations that win are the ones that reduce risk continuously, respond effectively, recover quickly, and keep operating through disruption.
VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?
May: The biggest blind spot is not a threat. It is the gap between visibility and action.
Most organizations have more security data than they have ever had. More tools, more telemetry, more alerts. And they still cannot reliably answer three basic questions: what poses the greatest business risk, where are we most exposed, and what do we do first.
AI is widening that gap rather than closing it. Faster, more automated attacks mean less time to prioritize and validate.
Security teams do not need more information. They need less of it, better sorted. That is what we are built for: surface the threats and exposures that actually matter, validate the finding, rank the action by real-world risk. Nobody buys cybersecurity to generate dashboards. They buy it to reduce risk.
VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden?
May: The biggest misconception in security is that better outcomes require more tools, more people, and more spend. For most organizations, the opposite is true. Complexity has become one of the largest drivers of cyber risk.
Security leaders do not want another platform to manage. They want outcomes. So we deliver the operating model itself: agent-led investigations with expert human oversight, as a service, instead of asking customers to build, train, govern, and staff an agentic SOC on their own.
The numbers we can point to: customers resolve cases 26% faster year over year, receive an average of one alert per day, get predictable pricing with unlimited data ingestion and investigations, and deploy in days rather than months.
As an example of our ROI, Arctic Wolf recently worked with a customer that is a major real estate investment organization, who had launched an initiative to understand exactly how many assets they had and identify any security coverage gaps. Their environment had tens of thousands of assets, including customer-facing systems, operational technology (OT) systems, and IT components.
By leveraging Aurora Attack Surface Management, Arctic Wolf provided the visibility and context (aggregated from across the customer’s toolset) to surface the true risk to the real estate organization and identify the most efficient way to remediate that risk.
The team saved hundreds of person-hours that would have been spent manually addressing the tens of thousands of vulnerabilities. And all of this was discovered with the Aurora Attack Surface Management assessment in a matter of days. The correlated data in Aurora Attack Surface Management showed the team that tens of thousands of vulnerabilities identified by the MDR actually belonged to only 3,000 devices, and they could resolve nearly all of those CVEs simply by upgrading the operating systems on those specific devices, relieving their team of the laborious and time- intensive manual process of reconciling asset inventories across tools.
The bigger ROI conversation, however, is resilience. Security investment should not be measured by tools deployed or alerts processed. It should be measured by risk reduced, recovery time, and business impact avoided when something does go wrong. That is the conversation CISOs are having with their boards now, and it is why we are seeing a shift toward operating models instead of more point products.
VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?
May: Building cyber resilience for the age of AI.
For years security was organized around prevention. That made sense when attacks were expensive to run. AI has made them cheap, fast, and scalable, and that changes the question.
It is no longer “can we stop every attack.” It is “can we keep operating when one lands.” 63% of organizations had a significant incident last year, and nearly half of those saw productivity disruptions lasting two weeks or longer. Two weeks is not a security problem. It is a revenue problem, a customer problem, and an employee problem.
So: an operating model built for machine-speed threats, visibility across the attack surface, and confidence that AI-driven outcomes can be trusted. Most importantly, security outcomes connected to business outcomes. Risk reduction, operational continuity, and recovery readiness are becoming board-level metrics.
The organizations that thrive will not be the ones that deploy the most AI. They will be the ones that use it to become harder to knock over.
VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?
May: The industry is underestimating what happens when AI agents become ordinary participants in business operations.
Today most organizations treat AI as a tool. Increasingly it behaves more like an employee: making decisions, accessing systems, touching data, acting on behalf of users. Except it does not have a manager, a badge, an access review, or an offboarding process.
That is the gap. AI agents are a new class of digital identity and the governance for them barely exists. Who provisions them. Who revokes them. What they are permitted to see. Who is accountable when one takes an action nobody sanctioned. Most organizations cannot answer those questions today about systems they deployed six months ago.
The next battleground is not protecting AI applications. It is governing autonomous AI operating inside the enterprise.
VMblog: Does your team have any speaking sessions, sponsored research presentations, or Briefings appearances at Black Hat 2026 that attendees should put on their schedule?
May: Arctic Wolf Labs is presenting research on LightSpy, a surveillance platform that has evolved well beyond mobile spyware. Researchers Dmitry Bestuzhev and Dmitry Melikov will walk through their investigation of its infrastructure: 72 servers, router implants, and the operational tradecraft that helped uncover how the platform is being used in the wild. It is a good representation of the threat intelligence and incident response work our team is focused on right now.
We are also running in-booth sessions throughout the event on agentic AI, security operations transformation, threat research, and how to use AI to accelerate detection and response while keeping humans on the decisions that matter.
VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?
May: Stop optimizing for alerts. Start optimizing for decisions.
And here is the part that costs us something to say. Before you evaluate a single vendor at this show, go count how many of the tools you already own are still configured the way they were the week you bought them. In most environments that answer is uncomfortable.
New capability is more satisfying to buy than existing capability is to finish deploying. Adversaries understand that. They are usually not beating your stack. They are beating the parts of it you never finished.
VMblog: Are you hosting any exclusive networking events, hospitality suites, or invite-only dinners during Black Hat week? How should interested attendees get connected?
May: Two, both at Hard Shake in the Waldorf Astoria on Tuesday, August 4.
The AI Defense: The New Threat Landscape threat briefing runs from 12:00 to 1:00 p.m., featuring Arctic Wolf President and CEO Nick Schneider, Dan Schiappa, President of Technology and Services, and Lisa Tetrault, SVP of Security Services. Attendees get the latest Arctic Wolf threat intelligence, a read on evolving cybercriminal activity and global threat trends, and a look at where we are taking security operations next.
Our CISO Happy Hour follows from 4:30 to 7:30 p.m. It is invitation-only and built for peer conversation rather than presentation: a chance for security leaders to step off the floor, compare notes on the threat environment, and talk candidly.
To attend either, connect with your Arctic Wolf representative, stop by booth #1564, or reach out through our event registration channels before the conference. Space is limited for the CISO event in particular, so reserve early.
VMblog: What’s the most creative or unexpected giveaway your booth is bringing this year?
May: Custom Arctic Wolf shoes, which we would argue is the most stylish giveaway at Black Hat.
They are an extension of our new brand campaign and a reminder that resilience is about being prepared to go the distance. Whether you are navigating the threat landscape or the expo floor, the right foundation matters.
VMblog: For the first-timer navigating Black Hat for the first time, what’s your best advice for getting maximum value out of the week without burning out by Wednesday?
May: Do not spend the whole week chasing sessions. Some of the most valuable conversations happen in hallways, at evening events, and on the expo floor.
Have a plan, leave room for spontaneity, and aim for a handful of meaningful conversations rather than trying to see everything. Black Hat is a marathon, not a sprint.
VMblog: When the industry gathers again at Black Hat 2027, what do you think will be the defining cybersecurity conversation that dominated the year?
May: Trust in autonomous AI, and specifically whether anyone can measure it.
We are already seeing where this goes. Advanced models can discover vulnerabilities, chain multi-step attack paths, adapt around obstacles, and pursue objectives in ways that resemble a capable human adversary.
What is striking is how they succeed. Not through novel technique, but by exploiting the same familiar weaknesses that have worked for a decade: exposed assets, excessive permissions, unpatched internet-facing systems, weak identity controls. The technology changed. The underlying hygiene problem did not. AI just made it findable at machine speed.
So the conversation moves from what AI can do to whether its output can be trusted, and then to how you would prove it. Right now, trust in AI security is mostly an adjective. By 2027 it has to be a measurement. That is the shift we think defines the year, and it is what our Human + Machine approach was built for.
##






