Before Black Hat USA 2026 descends on Las Vegas, the conversation around agentic AI has shifted from novelty to necessity — and nowhere is that shift more urgent than in the security operations center. Ahead of the show, VMblog caught up with Jeremy Powell, CISO at Sumo Logic, to talk about what the company is bringing to booth #5641, including a production SOC Analyst Agent that triages real alerts end-to-end in about three minutes, an “agent-vs-agent” hands-on exhibit that invites attendees to try to poison its reasoning, and a look at the company’s “autonomy ladder,” where AI agents can be promoted — or demoted — based on real-world performance.
The discussion goes well beyond booth theatrics, though. Powell speaks candidly about the double-edged nature of agentic AI in security, pointing to reports of adversaries automating full ransomware operations in under 30 minutes as proof that the same capabilities reshaping defense are just as available to attackers. He also previews Sumo Logic’s Black Hat announcements, including expanded Dojo AI agents and new MCP support connecting tools like Claude Code and GitHub Copilot directly to Sumo Logic’s Cloud SIEM and Log Analytics. Along the way, Powell offers a CISO’s blunt take on governance, board-level accountability, and why “lights-out, self-healing SOC” remains more marketing than reality — at least for now.
++
VMblog: For readers who may not be familiar, give us the elevator pitch — who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.
Jeremy Powell: Sumo Logic helps make the digital world secure, fast, and reliable by unifying critical security and operational data through its intelligent platform. Built to address the increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness—combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges. Customers around the world rely on Sumo Logic for trusted insights to protect against security threats, ensure reliability, and gain powerful insights into their digital environments.
VMblog: Black Hat attendees are a discerning crowd. What booth experiences, live demos, or hands-on activities are you bringing to Las Vegas that will cut through the noise and leave visitors with something they can’t stop thinking about?
Powell: At Black Hat we’re keeping it hands-on rather than theatrical. The center of the booth is our production SOC analyst agent working real alerts end-to-end in about three minutes, with every tool call and verdict replayable in the SIEM — it runs on Sumo Logic because we use it ourselves. Alongside it, an agent-vs-agent setup where you can take the attacker’s side: craft a poisoned log line or hostname and see whether you can steer the agent’s reasoning past our injection evals and parsing.
There’s also Mobot, where a plain-language request turns into a working dashboard in under a minute, and a walkthrough of our autonomy ladder — including watching an agent get demoted a rung when an eval regresses, so you can see how autonomy is earned and pulled back. A metrics board covers what nine months in production actually looks like (98% of Tier-1 triaged by the agent, triage down from 28 to 3 minutes, ~25 hours a week back per analyst, no headcount cut), and you can take a one-page 90-day playbook on the way out. The idea is simple: less watching a demo, more poking at the thing yourself.
VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?
Powell: Agentic AI is a force multiplier on the analyst, not a replacement. It’s critical to have a human always kept in the loop and every recommendation traceable back to its reasoning.
VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors — whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else — is your solution most directly built to address?
Powell: Palo Alto’s Unit 42 reportedly ran an agentic tool through a full ransomware operation end-to-end in about 25 minutes. This is proof that AI is now a force multiplier for attackers too, not just defenders.
VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?
Powell: Agents are dangerous by nature because they need broad access to be useful. Sumo Logic’s SOC Analyst Agent, does autonomous triage, enrichment, and cross-signal correlation, but always shows its reasoning and keeps a human in the driver’s seat rather than “throwing another alert over the transom. My test is always “show me the model, show me how it explains its reasoning. The idea of a “lights-out, self-healing SOC” is still mostly marketing; human talent isn’t going away anytime soon.
VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?
Powell: AI for security (using agentic reasoning to improve detection) vs. security for AI (observability into AI tool usage itself/shadow AI). Can the AI model’s reasoning be followed back to a decision? If not, it’s essentially just noise without signal.
VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026? Can you tease it or give us a preview?
Powell: Sumo Logic is bringing our generally available agents in Dojo AI to Black Hat. This includes a smarter Mobot, our conversational interface, that goes beyond writing queries and now helps guide your investigations. Agents making Mobot better include Log Analysis Agent and Platform Optimization Agent.
SOC Analyst Agent automatically investigates alerts and delivers evidence-backed verdicts without having to manually triage each alert.
And of course MCP, which connects tools like Claude Code and GitHub Copilot to Sumo Logic’s Cloud SIEM and Log Analytics through a governed set of API tools. No custom integrations or raw data, just context, wherever teams work.
VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?
Powell: CISOs don’t buy features. They don’t buy technology. They buy outcomes.Three questions CISOs actually ask: How do I reduce risk? How do I get time back? How do I become defensible to a board or auditor?
VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?
Powell: Getting real governance/guardrails around agentic AI now rather than later. We also need to align accountability with authority and visibility, so a CISO isn’t held responsible for outcomes they don’t have real control or visibility over.
VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?
Powell: Get your mandate, authority, and the org’s risk tolerance in writing before taking the seat; stay technical enough to think adversarially, even if you’re not writing the scripts yourself; and speak the language of business risk, not just technical risk.
No one cares about security unless you’re a security practitioner.
Any motivated adversary with time and budget gets in, full stop. The goal is to be resilient.
VMblog: Are you hosting any exclusive networking events, hospitality suites, or invite-only dinners during Black Hat week? How should interested attendees get connected?
Powell: We are hosting an event on August 4th, Dojo after Dark. You’ll get hands on time with our latest releases, plus some fun interactive experiences. You can also reach out for executive dinners if you want to learn more. Visit our booth #5641 or reach out to us on social channels to land an invite.
##






