As Black Hat USA 2025 approaches, security leaders are grappling with a fundamental shift in how they approach AI in cybersecurity. What began as efforts to contain and limit AI exposure has evolved into a strategic imperative to operationalize artificial intelligence for reducing analyst burnout and improving security posture. Roland Palmer, VP of Security & Compliance at Sumo Logic, provides insights into this transformation, revealing that 90% of security leaders now prioritize AI in new solutions, with the conversation shifting from “can AI help?” to “why isn’t it helping MORE?”
In this VMblog Q&A, Palmer discusses the mounting complexity facing security teams as they navigate AI attacks, supply chain vulnerabilities, and cloud security challenges simultaneously. He emphasizes that the real challenge isn’t any single threat vector, but rather the complexity of tracking risk across all of them. Palmer advocates for a unified platform approach that enables true end-to-end visibility across cloud, hybrid, and on-premises environments, moving beyond the fragmented tools and partial integrations that plague many security operations centers. Sumo Logic will be demonstrating their integrated log analytics, SIEM, SOAR, and threat intelligence capabilities at booth #5812 during Black Hat USA 2025.
Don’t miss this pre-show Q&A to find out more. And make sure to add Sumo Logic to your MUST SEE list.
++
VMblog: What are your most security-conscious customers asking for today that they weren’t asking for just a year ago?
Roland Palmer: A year ago, the priority was securing rapidly expanding AI – understanding the risks, enforcing policy, and limiting exposure. This year, the question has shifted to, “How do I make AI truly work for my team to reduce burnout and improve security posture?”
Security leaders aren’t just trying to contain AI anymore; they’re trying to operationalize it. They want help triaging alerts, summarizing investigations, and accelerating decision-making. According to our recent 2025 Security Operations Insights report, 90% of leaders now prioritize AI in new solutions. The question isn’t “can AI help?” Now, the question is “why isn’t helping MORE?” The goal is to do more with less to keep up with a growing number of threats.
VMblog: If a CISO visits your booth and walks away remembering just one thing about your company, what should that key message be?
Palmer: Sumo Logic addresses some of the most persistent challenges in the industry: fragmented tools, overwhelming alert volumes, and the growing complexity of cloud security. We take a logs-first approach to integrate log and security analytics, Cloud SIEM, and SOAR to quickly ingest, normalize, and analyze terabytes of data, orchestrating automated responses to evolving threats. In a market flooded with siloed tools and partial integrations, we offer true end-to-end visibility across cloud, hybrid, and on-prem environments, so nothing critical gets missed.
Outside of our technology, Sumo Logic is really invested in the success of its own security team as well as our customers. We have a deep commitment to supporting our customers and thoughtful about the innovation we build to help them tackle the challenges they have today to make their jobs easier, faster, and more effective.
If you want to check out Sumo Logic in action, stop by booth #5812 at Black Hat!
VMblog: With AI attacks, supply chain vulnerabilities, and cloud security challenges dominating headlines in 2025, which of these threat vectors does your solution specifically address or focus on?
Palmer: All of them are critical, and they’re all intertwined now. What I see breaking most teams isn’t just one of these threat vectors. It’s the complexity of tracking risk across them all.
We need a system that can make sense of subtle signals across multiple layers. That’s where modern detection has to live. It has to help security teams own and operate in the gray space, both proactively and reactively.
VMblog: The ‘AI security arms race’ is a hot topic this year. How is your company leveraging AI defensively, and what’s your take on the AI-powered threats we’re seeing emerge?
Palmer: We continue to operate in an era where both defenders and attackers are scaling faster than humans can track.
Defensively, I’ve seen AI help analysts move faster in investigations by asking natural-language questions and pulling context together to reduce time to understanding. But the other side is evolving just as fast, if not faster. Threat actors are chaining actions together and mimicking behavior to blend in and gain access.
The real opportunity isn’t flashy AI. It’s explainable, assistive AI that holds up. That’s the kind of tooling I want in my own SOC.
VMblog: What’s your company’s most compelling differentiator in a market where everyone claims to have the ‘next-generation’ solution?
Palmer: I’ll say this from a practitioner’s view: our tools- log analytics, SIEM, SOAR, and threat intel-actually work together on one platform. You don’t need five tools stitched together or another console to swivel between. You need to go from detection to response without losing context.
Where a single platform really makes a difference, especially in real-world incidents, is in supporting cross-team collaboration. Nowadays, it’s not always security that finds the issue first. It might be a DevOps engineer who notices a misconfiguration or a spike in outbound traffic. With Sumo Logic, we’re all working from the same data, the same timelines, the same view of what’s happening. That shared visibility is critical when you’re trying to move fast and avoid confusion.
You can’t respond in isolation anymore. Whether it’s a new CVE or a misbehaving container, the teams who can investigate and act together are the ones who stay ahead.
It’s always “next-gen” until something actually happens. Then the dashboards freeze, tools don’t talk, support is nowhere to be found, and your analysts are stuck piecing together a story with duct tape and screenshots.
Sumo Logic’s differentiator is we are built to survive the chaos. One platform. One place to detect, investigate and respond without losing time or context.
We are tied to our customers and roadmapping what Security Teams actually need and care about.
VMblog: In 2025, the volume and noise of security alerts remains one of the greatest challenges for security teams. How can teams tackle this challenge once and for all?
Palmer: The teams putting a dent in the volume and noise are the ones who are ruthless about reducing irrelevant signals. That means smarter correlation, better prioritization, and automation that actually helps. AI’s a piece of that puzzle, but the foundation is strong telemetry and workflows that map to reality. This approach has significantly cut down time-to-triage in our SOC.
VMblog: Zero-trust architecture has evolved significantly since 2024. How has your approach to zero-trust implementation changed, and what practical advice do you have for organizations still in the planning stages?
Palmer: Zero-trust isn’t a product. It sounds good on paper, but if you can’t see what’s happening across users, infrastructure, workloads (the fundamentals), then you’re just guessing.
My advice: invest in visibility. Get your logging and analytics in shape so when it’s time to enforce controls, you’re making decisions based on real usage, not assumptions. That’s what will turn zero trust from a buzzword into a working strategy.
VMblog: What’s the biggest cybersecurity blind spot you’re seeing organizations struggle with in 2025, and how does your solution illuminate that gap?
Palmer: Most security teams can detect. Fewer can connect the dots between isolated alerts, behavior anomalies, and threat intelligence. Without correlation and real-time context, you end up with a pile of alerts and no story. That costs time, and in some cases, it costs teams the ability to act when they should. Sometimes, fixing that blind spot is about wiring together the tools you have and making them speak the same language.
VMblog: Looking toward 2026 and beyond, what emerging threat or technology trend keeps you up at night, and how is your company preparing for it?
Palmer: What keeps me up at night isn’t the headlines or technology per se. It’s understanding the fight that my SOC director, his team and every other security team are in every day and the fight they will inevitably be in in the future. It’s the subtle stuff. The low-and slow attacks, the behavioral drift, the signals that don’t trigger alarms but still mean something is off. We’re investing heavily in ways to understand normal behavior, surface the outliers, and build a real-time picture that makes sense before damage is done.
VMblog: If you had to predict the cybersecurity conversation we’ll all be having at Black Hat 2026, what topic or challenge do you think will dominate the discourse?
Palmer: AI will continue to dominate the conversation for the foreseeable future. There will be some creative “next-gen” threat or “next-gen” defensive capability that will likely be the next trend. But as the human gets further outside the loop in AI, we’ll be asking harder questions – “how do we verify what the model did?” “Who’s accountable if it’s wrong?” “How do we audit that?” Our next conversation will and should be focused on building trustworthy AI. And that will start to reshape everything from procurement to policy.
##






