Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2026 Q&A: Acalvio’s Ram Varadarajan on Why Cyber Deception Is the Key to Preempting AI-Accelerated Attacks

Share: 

David Marshall | Published: July 30, 2026
vmblog blackhat usa 2026 qa

As Black Hat USA 2026 approaches, the conversation across the security industry has shifted from whether attackers are using AI to whether defenders can keep pace with what that AI enables. Few executives are positioned to speak to that shift like Ram Varadarajan, Co-Founder and CEO of Acalvio Technologies. Ahead of the show, VMblog caught up with Varadarajan to discuss how agentic AI is compressing the time between reconnaissance and impact, why identity has become less of an access problem and more of a “graph problem” attackers exploit, and how Acalvio’s 360 Deception architecture is designed to make enterprise environments untrustworthy for both human adversaries and autonomous attack agents.

In this exclusive Q&A, Varadarajan previews Acalvio’s Black Hat 2026 booth experience at #8606 in the AI Zone, where the company will unveil Deception Guardrails, a new preemptive defense capability built to secure AI agents and the infrastructure they interact with. He also weighs in on the state of post-quantum cryptography migration, the software supply chain gaps that still keep him up at night, and what he believes will be the defining cybersecurity conversation heading into 2027. It’s a wide-ranging look at where preemptive, deception-based defense fits into an industry racing to keep up with machine-speed threats.

++

VMblog: For readers who may not be familiar, give us the elevator pitch: who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.

    Ram Varadarajan: Acalvio is a preemptive cybersecurity company built for the realities of AI-accelerated attacks. We use cyber deception to help organizations detect, disrupt, and contain adversaries earlier, before reconnaissance turns into lateral movement, ransomware, data theft, or operational impact.

    What sets us apart is our belief that the next phase of defense is not just about making reactive detection faster. Reactive defense was built for a world where defenders had more time to investigate, correlate, and respond. That time is disappearing. Attackers are using automation and agentic AI to enumerate environments, chain attack paths, test credentials, and move at machine speed. If defenders are waiting for post-compromise signals to become obvious, they are already giving the attacker too much time.

    Acalvio changes the attacker’s operating environment.

    Our 360 Deception architecture creates high-uncertainty environments across identity, cloud, endpoint, hybrid, virtualized, and OT infrastructure. We use high-fidelity decoys, honeytokens, deceptive credentials, and cloaking to make it much harder for attackers to tell what is real, what is false, and what is being watched.

    That is especially important as autonomous attack agents become more capable. These systems depend on ground truth. They need to know which systems are real, which credentials work, which identities matter, which services are exposed, and which paths are worth pursuing. Acalvio disrupts that confidence.

    The simple version is this: we make the environment untrustworthy for the attacker. That forces human adversaries and AI-driven agents to slow down, make mistakes, or reveal themselves much earlier in the attack chain.

    VMblog: Black Hat attendees are a discerning crowd. What booth experiences, live demos, or hands on activities are you bringing to Las Vegas that will cut through the noise and leave visitors with something they can’t stop thinking about?

    Varadarajan: Black Hat attendees expect to see more than another dashboard tour. They want to understand whether a security model changes the defender’s advantage.

    That is the experience we want to create. We will show what happens when an attacker, whether human-led or AI-driven, can no longer trust what they see inside the environment.

    The demo focus is on attacker behavior: reconnaissance, credential use, identity enumeration, lateral movement, and automated discovery. These are the moments where adversaries are trying to build a map of the enterprise. Acalvio changes that map. We insert high-fidelity decoys, honeytokens, deceptive credentials, and cloaked assets into the paths attackers are most likely to explore, then show how those interactions expose intent earlier than traditional post-compromise detection.

    The point is not that deception creates another alert. The point is that it changes the conditions of the attack. If an autonomous agent is probing the environment, testing credentials, or following a false path, it is no longer operating with clean ground truth. It is interacting with an environment designed to mislead it and expose it.

    What we want people to remember is simple: in an AI-accelerated attack environment, Acalvio helps defenders shift uncertainty back onto the attacker, forcing human adversaries and autonomous agents to slow down, make mistakes, or reveal themselves before they can cause real damage.

    VMblog: What’s your Black Hat origin story? Longtime exhibitor or fresh face on the floor? What keeps your company coming back, or what made 2026 the year to finally plant your flag here?

    Varadarajan: Acalvio has been a repeat supporter of Black Hat because this is one of the few industry events where you can have a serious technical conversation about how attacks actually unfold. The audience understands that attackers do not follow the defender’s workflow. They probe, enumerate, test assumptions, look for weak paths, and move through the environment before many traditional tools have enough signal to act.

    That has always been the problem Acalvio was built to address. But 2026 is a particularly important year because AI security has moved from an emerging discussion to an architectural priority. Agentic AI and automation are changing how quickly attackers can discover assets, validate credentials, chain exposures, and move laterally. The market has spent years trying to make detection and response faster. That still matters, but speed alone is no longer enough.

    This is also a clarifying moment for cyber deception. Deception is no longer about placing a few decoys in the network and waiting to see who touches them. It has evolved into a 360 Deception model that spans identity, endpoint, cloud, hybrid, virtualized, and OT environments. The goal is to change what the attacker believes to be true.

    In a well-instrumented deceptive environment, real can appear fake, fake can appear real, and every step an attacker takes to resolve that uncertainty creates an opportunity for exposure.

    That is why Black Hat matters to us. It is the right venue to reinforce the shift from reactive detection to preemptive defense, and to show why deception has become much more relevant in an AI-accelerated threat landscape. The companies that stay ahead will be the ones that make their environments harder for attackers and autonomous agents to trust.

    VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?

    Varadarajan: Acalvio helps defenders make the attacker’s world uncertain.

    That matters because attackers, whether human-led or AI-driven, need confidence to move quickly. They need to know which credentials are valid, which systems are real, which identities matter, which services are exposed, and which paths are worth pursuing. The more reliable the environment appears, the faster they can turn discovery into action.

    That confidence matters even more now because AI-driven attacks can test more paths, validate more assumptions, and move from discovery to execution faster than human teams can manually investigate.

    Acalvio disrupts that confidence. With 360 Deception, we create high-uncertainty environments where real can appear fake, fake can appear real, and attacker interactions with deceptive assets create early, high-confidence signals for the SOC.

    For a CISO, the value is very practical. You are not just adding another detection layer. You are changing the conditions of the attack so adversaries and autonomous agents are forced to slow down, make mistakes, or reveal themselves before they reach critical assets.

    If they remember one thing, it should be this: Acalvio gives defenders a way to take away the attacker’s confidence before the attacker takes control, at a time when AI-driven attacks are collapsing the window between reconnaissance and impact.

    VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors, whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else, is your solution most directly built to address?

    Varadarajan: Acalvio is built for the part of the attack where today’s fastest threat actors and autonomous agents still have to do real work: discovery, validation, path selection, and movement.

    That matters because agentic AI changes the scale and tempo of those steps. We are no longer talking only about scripted automation or faster vulnerability scanning. AI-enabled operators can use autonomous agents to reason across exposed services, identity relationships, misconfigurations, credentials, application behavior, and runtime signals. They can test hypotheses, discard dead ends, and adapt the attack path in near real time.

    The vectors we are most directly focused on are the ones where that capability creates the most leverage: identity-based intrusion, cloud and hybrid lateral movement, ransomware staging, critical infrastructure targeting, and living-off-the-land activity. In each case, the adversary needs trustworthy environmental feedback. Which credentials are valid? Which identities have reach? Which workloads are real? Which systems are monitored? Which paths create the least friction?

    Acalvio is designed to make those answers unreliable.

    With 360 Deception, we place deceptive credentials, decoy assets, honeytokens, cloaked resources, and false identity paths into the places attackers and autonomous agents naturally interrogate. The goal is not to wait for malware execution or late-stage behavioral correlation. It is to instrument the discovery layer itself, where agentic systems are forming their model of the environment.

    That is also why deception is becoming more relevant in AI-era security. Prompt poisoning, runtime manipulation, autonomous exploitation, and identity abuse may look like different categories, but they share one dependency: the attacker needs feedback they can trust. If the environment can feed back believable but deceptive signals, the attacker’s automation becomes easier to misdirect, measure, and expose.

    For critical infrastructure and OT, this is especially important. You often cannot rely on aggressive scanning, heavy endpoint agents, or noisy experimentation. Deception gives defenders a way to detect intent and movement without adding fragility to the environment.

    So, the shortest answer is this: Acalvio is built for attacks that rely on machine-speed discovery and trusted environmental feedback. In 2026, that increasingly means agentic AI, identity compromise, cloud and hybrid movement, ransomware preparation, and critical infrastructure reconnaissance.

    VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for and with autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?

    Varadarajan: The biggest risk enterprises are underestimating is not that AI will make attacks faster. Most security leaders already understand that. The more important issue is that agentic AI changes how attacks are assembled.

    An autonomous agent does not need to follow a fixed playbook. It can observe the environment, reason across signals, test paths, discard weak options, and adapt based on feedback. That makes the defender’s environment part of the attacker’s decision engine. Every exposed service, credential artifact, identity relationship, API response, runtime behavior, and configuration clue becomes data the agent can use.

    That is why Acalvio’s approach is focused on corrupting the feedback loop. If autonomous agents depend on reliable environmental signals, defenders need to make those signals deceptive, instrumented, and difficult to trust.

    We build for that through 360 Deception. Deceptive credentials, honeytokens, decoy assets, cloaked resources, and false identity paths are placed where an attacker or autonomous agent is likely to probe. When those assets are queried, touched, authenticated against, or followed, the SOC gets a high-confidence signal of adversary intent. Just as important, the attacker’s model of the environment becomes less reliable.

    On the defense side, we also believe AI should be used to reduce operational burden, not create another layer of noise. AI can help recommend where deception should be deployed, adjust coverage as environments change, and improve context around attacker behavior. But the goal should be better defensive leverage, not more alerts with better labels.

    Enterprises are making progress on runtime controls, model governance, prompt injection defenses, and data access policies. The bigger architectural gap is what happens when autonomous agents interact with identity systems, APIs, cloud control planes, developer environments, and operational infrastructure. The exposure is not only inside the model. It is in the feedback loops the agent can observe, trust, and act on.

    If attackers are using AI to build a more accurate model of the environment, defenders need to corrupt that model before it becomes an attack plan.

    VMblog: The post-quantum cryptography migration is well underway for some organizations and barely started for others. Where should companies realistically be in that transition today, and what’s your honest assessment of how complex the road ahead still is?

    Varadarajan: Companies do not need to have completed their post-quantum cryptography migration today. Very few have. But they should be well past the point of treating it as a theoretical future issue.

    The first step is crypto inventory. Organizations need to know which cryptographic algorithms they use, where they are used, which systems depend on them, which vendors control them, and which applications or infrastructure components will be difficult to migrate. Without that inventory, there is no realistic migration plan.

    The risk is often described as “harvest now, decrypt later,” and that is valid for long-lived sensitive data. But the larger architectural concern is broader key exposure. If quantum capabilities make it possible to derive private keys from public keys, the issue is not just old encrypted data. It is the trust foundation for authentication, encryption, signing, certificates, software integrity, and machine-to-machine communication.

    That is what should make enterprises stop and take notice.

    Many organizations still think of quantum risk as a 2030 problem. That is dangerous. State actors are expected to develop meaningful quantum capabilities before then, and advances such as networking multiple quantum computers in parallel could compress the timeline further. Whether an organization believes the aggressive forecasts or the conservative ones, the practical answer is the same: waiting is not a strategy.

    Finance, government, and manufacturing are likely to be among the first sectors forced into serious action. Government has policy pressure and national security exposure. Financial services has high-value transaction and identity infrastructure. Manufacturing has long-lived systems, supply chain dependencies, and OT environments that cannot be swapped out quickly.

    This is also where preemptive defense matters. PQC migration will take years, and during that time adversaries will continue to probe, collect, and quietly map trust relationships. Deception can help expose that activity earlier by instrumenting credentials, identity paths, and sensitive access patterns that attackers should not be touching.

    The operational reality is this: PQC migration is not a patch cycle. It is a multi-year architecture, governance, procurement, and testing program. Organizations should be inventorying crypto algorithms now, prioritizing systems that protect sensitive data or core trust functions and pushing cryptographic agility into every modernization and vendor decision.

    VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?

    Varadarajan: “AI-native security” only matters if it changes the security model, not just the interface.

    At Acalvio, we look at this through two lenses. First, how does AI change the attacker’s operating model? Second, how can defenders use AI to make preemptive defense more adaptive, scalable, and precise?

    The offensive side is the forcing function. Agentic AI can accelerate reconnaissance, test identity paths, correlate infrastructure signals, and adapt attack logic in near real time. That means security architectures have to assume the attacker is no longer moving through the environment at human speed or with a static playbook.

    For us, AI-native security means building defenses that can operate in that reality. Acalvio uses AI to help recommend, place, and adapt deception across complex environments, but the deeper differentiation is architectural. Our 360 Deception model is designed to disrupt the feedback loops autonomous agents depend on. If an attacker or AI system is trying to build an accurate model of the enterprise, we make that model less trustworthy.

    That is the proof point I care about. Does the technology change what the attacker can trust? Does it expose intent earlier? Does it reduce false positives for the SOC? Does it work across identity, cloud, endpoint, hybrid, virtualized, and OT environments without adding operational drag?

    If the answer is yes, then AI is doing something meaningful. If the answer is no, it is probably just the newest label on an old detection workflow.

    VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026? Can you tease it or give us a preview?

    Varadarajan: Yes. At Black Hat, Acalvio is unveiling Deception Guardrails, a new preemptive defense capability designed to secure AI agents and the infrastructure they interact with.

    This is an important step because most AI guardrails still focus heavily on inputs and outputs. That matters, but it does not fully address what happens after an agent is compromised, manipulated, or operating outside its intended boundaries. Once an agent can reason, call tools, access APIs, retrieve context, touch credentials, or interact with enterprise systems, the security problem expands beyond prompt filtering and policy enforcement.

    Deception Guardrails are designed for that moment. They introduce deceptive assets, honeytokens, honey skills, decoy MCP servers, decoy RAG systems, and decoy AI agents into the environments and workflows autonomous agents use. If an agent is manipulated, hijacked, or begins interacting with infrastructure in ways it should not, those interactions create early, high-confidence signals for the SOC.

    The larger point is that agentic AI security needs a preemptive layer. Enterprises need runtime controls, governance, access policies, and model protections, but they also need a way to detect misalignment and malicious activity before a compromised agent reaches real production assets.

    That is where Acalvio’s deception model becomes highly relevant. We are extending the same principle behind 360 Deception into agentic AI environments: create a deceptive reality where real appears fake, fake appears real, and attempts to resolve that uncertainty expose risk earlier.

    Attendees can see this live at Booth #8606 in the AI Zone, where we will be demonstrating Deception Guardrails against agentic attacks. The preview is simple: if AI agents are becoming part of the enterprise operating fabric, security teams need to protect not only the model, but the world the agent can observe, trust, and act on.

    VMblog: Identity has become the new perimeter, and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?

      Varadarajan: The identity conversation has matured, but the attacker’s use of identity has matured faster.

      Most enterprises have made real progress on MFA, PAM, conditional access, identity governance, and least privilege. The issue is that attackers are no longer treating identity as a login problem. They are treating it as a graph problem. They look for relationships, inherited privileges, sync paths, service accounts, cached credentials, token artifacts, cloud entitlements, and overlooked connections between human, machine, and application identities.

      That is where Acalvio has leaned forward. We are not trying to replace the identity control plane. We are instrumenting the identity attack plane.

      With identity deception, we create believable false paths inside AD, Entra ID, Okta, endpoint credential stores, and cloud-connected environments. Deceptive credentials, honeytokens, synthetic accounts, decoy privilege relationships, and dynamic HoneyPaths are placed where an attacker or autonomous agent would naturally enumerate. If they engage, defenders get a high-confidence signal that someone or something is exploring identity in a way legitimate users should not.

      This is becoming even more important with agentic AI. Autonomous agents can traverse identity context quickly, correlate identity relationships with infrastructure signals, and test possible paths at scale. The defender’s goal cannot be only to clean up every entitlement before the attacker finds it. That is important, but it is not sufficient. The goal is also to make identity discovery itself dangerous for the attacker.

      The gap we still see is between identity governance and identity reality. Access policy describes how the environment is supposed to work. Attack-path reality shows what an adversary can infer, test, and chain across the identity fabric. Acalvio is focused on that second problem, because that is where many modern intrusions take shape.

      VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?

        Varadarajan: The blind spot is not visibility in the traditional sense. Most mature organizations have more telemetry than they can operationalize.

        The issue is adversary-readable context.

        Attackers do not need a perfect map of the environment. They need enough signals to infer where trust exists, which identities matter, which systems are worth testing, where credentials may be exposed, and which paths create the least resistance. Agentic AI makes this more acute because it can reason across weak signals quickly: identity relationships, cloud permissions, endpoint artifacts, API responses, runtime behavior, exposed services, and configuration residue.

        That is where conventional visibility starts to fall short. It tells defenders what exists. It does not always show what an attacker can infer, trust, and chain.

        Acalvio addresses that blind spot by instrumenting the discovery layer. We place deceptive credentials, honeytokens, decoy assets, cloaked resources, and false identity paths into the areas attackers and autonomous agents naturally interrogate. When they engage, defenders get high-confidence signal earlier in the attack path.

        The value is not simply that deception detects activity. It changes the quality of the environment the attacker is reading. The attacker sees believable signals, but those signals are designed to mislead, measure, and expose them.

        So the blind spot is not “we don’t know what we have.” It is “we don’t know what the attacker can learn from what we expose.” That is the gap preemptive defense is built to close.

        VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?

          Varadarajan: The ROI case starts with signal quality.

          Most security teams are not struggling because they lack alerts. They are struggling because too many alerts require human interpretation before anyone knows whether they matter. That becomes expensive very quickly, especially when teams are lean and attack timelines are compressing.

          Deception changes that equation because interaction with a deceptive asset is already meaningful. A real user should not authenticate with a deceptive credential. A normal workflow should not query a decoy service. A legitimate process should not follow a false identity path. When those things happen, the SOC is not starting from a vague anomaly. It is starting from a high-confidence signal of adversary behavior.

          That reduces operational burden in two ways. First, it shortens the investigation path. Teams can see what was touched, which deceptive path was followed, and what behavior triggered the alert. Second, it reduces wasted cycles because deception is designed to fire when something interacts with an asset that should not be part of normal business activity.

          For a CISO, the ROI is also strategic. Earlier detection lowers the cost of response. Higher-fidelity alerts reduce analyst fatigue. Deception across identity, cloud, endpoint, hybrid, virtualized, and OT environments helps extend coverage without requiring teams to manually chase every weak signal.

          The broader point is that security leaders do not need another tool that promises visibility and then hands the SOC more work. They need controls that change attacker behavior and produce cleaner, earlier signals. That is where Acalvio creates measurable value.

          VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?

            Varadarajan: Security leaders should be prioritizing preemptive defense against AI-accelerated attack paths.

            The issue is not whether organizations have detection. Most do. The issue is whether detection happens early enough to matter when attackers and autonomous agents can enumerate assets, validate credentials, correlate signals, and move through the environment at machine speed.

            In the second half of 2026, the priority should be reducing the attacker’s confidence before they establish control. That means looking hard at the discovery layer: identity paths, cloud exposure, unmanaged assets, privileged access, lateral movement opportunities, exposed APIs, and operational systems that could become part of a chained attack.

            It also means recognizing that several trust foundations are under pressure at the same time. AI is compressing attack timelines. Identity is being exploited as an attack graph. PQC is forcing organizations to inventory cryptography and rethink long-term trust in keys, certificates, signing, and machine-to-machine communication.

            Patching and reactive response, while necessary, cannot carry that burden alone. The growth of AI-assisted vulnerability discovery, agentic attack automation, and cryptographic transition risk is making patch-only and alert-only strategies harder to sustain.

            The organizations that will be better positioned are the ones that make their environments harder to read, harder to trust, and more dangerous for attackers to explore. That is where deception, cloaking, honeytokens, and preemptive controls deserve a higher place in the architecture.

            VMblog: The conversation around software supply chain security has matured significantly, but has enterprise practice kept pace? What’s the current state, and where are the gaps that still keep you up at night?

              Varadarajan: Enterprise practice has improved, but it has not caught up to how attackers think about the software supply chain.

              We have seen real progress around SBOMs, dependency scanning, code signing, artifact integrity, CI/CD hardening, and vendor risk reviews. Those are all necessary. But the software supply chain is not just a list of packages. It is a set of trust relationships that spans developers, build systems, secrets, APIs, identity permissions, cloud services, open-source components, third-party tools, and production deployment paths.

              That is where the gap remains.

              Attackers do not need to compromise every part of the supply chain. They need one trusted path that lets them move from a developer environment, build pipeline, package registry, service account, or API connection into something more valuable. Agentic AI only increases the concern because it can reason across those trust relationships more quickly and test combinations that would take human operators much longer to evaluate.

              From Acalvio’s perspective, this is another case where preemptive defense must move closer to the attacker’s discovery process. If someone is probing developer credentials, accessing deceptive package registries, querying honey APIs, touching decoy services, or following false paths in cloud and identity systems, defenders should know before the activity becomes a supply chain compromise.

              The current state is better than it was, but still too inventory centric. The next step is understanding exploitability and attacker pathing: not just what components exist, but what trust they create, what access they imply, and what an adversary or autonomous agent could chain from there.

              VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?

                Varadarajan: The industry is still underestimating how quickly foundational trust assumptions are being challenged.

                The first is autonomous attack orchestration. We are paying attention to AI-generated phishing, AI-written malware, prompt injection, model abuse, and runtime risk. Those are legitimate concerns. But the larger shift is that autonomous systems can increasingly connect the pieces of an attack: reconnaissance, identity mapping, vulnerability selection, credential testing, tool use, lateral movement, and objective pursuit.

                That changes the economics of intrusion. More attack paths can be explored faster, with fewer humans involved and more adaptive decision-making along the way. It also means weak signals that might previously have sat below the threshold of human attention can become useful inputs for machine-speed attack planning.

                The second is post-quantum cryptography. Too many organizations still treat PQC as a distant migration issue, when the real concern is the trust layer itself: keys, certificates, signing, authentication, encryption, and machine-to-machine communication. If state actors develop meaningful quantum capability before 2030, and the industry is still inventorying algorithms in 2027, the timing gets uncomfortable very quickly.

                These two issues may look unrelated, but they share a common problem. Attackers are getting better at exploiting what defenders assume to be stable: identity relationships, environmental signals, cryptographic trust, and control-plane integrity.

                That is where I think the 2027 conversation will move. Security leaders will focus less on whether AI is being used in attacks and more on how to protect the trust foundations that AI-driven and quantum-capable adversaries will target. Deception, cloaking, high-fidelity signals, crypto agility, and preemptive controls will become more central because they address the systems attackers depend on before impact.

                VMblog: Does your team have any speaking sessions, sponsored research presentations, or Briefings appearances at Black Hat 2026 that attendees should put on their schedule?

                  Varadarajan: The main place attendees should engage with us is Booth #8606 in the AI Zone, where we will be demonstrating Acalvio Deception Guardrails against agentic attacks.

                  That will be the most direct way to see the announcement in action. We will show how deception can be applied to AI agent workflows and surrounding AI infrastructure, including honeytokens, honey skills, decoy MCP servers, decoy RAG systems, and decoy AI agents.

                  The conversation we want to have at Black Hat is very specific: how do you detect and disrupt a manipulated or compromised AI agent before it reaches real enterprise systems?

                  That is where we believe preemptive defense belongs in the AI security architecture. Runtime controls, prompt injection defenses, governance, and access policies all matter. But security teams also need early signals when an agent begins interacting with context, tools, credentials, APIs, or infrastructure in ways it should not.

                  If attendees are working on agentic AI security, identity deception, cloud and hybrid attack paths, or how to reduce attacker confidence in machine-speed intrusions, Booth #8606 is worth putting on the schedule.

                  VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?

                    Varadarajan: Stop validating your security program only from the defender’s side of the console.

                    Most teams know what their tools are supposed to detect, what their policies are supposed to prevent, and what their dashboards are supposed to show. The harder and more useful exercise is to ask what an attacker can learn in the first ten minutes of discovery.

                    What identity paths become visible? Which credentials can be found or tested? Which APIs respond in useful ways? Which cloud permissions imply reach? Which systems look valuable? Which controls are obvious enough to route around?

                    That exercise becomes much more important as agentic AI enters the equation. Autonomous agents do not need perfect access to cause trouble. They need enough trustworthy feedback to build a path.

                    So, my advice is simple: instrument what the attacker is likely to explore, not only what the defender already knows how to monitor. If you can make discovery itself risky for the adversary, you change the balance of the attack before it becomes a full incident.

                    VMblog: For the first-timer navigating Black Hat for the first time, what’s your best advice for getting maximum value out of the week without burning out by Wednesday?

                    Varadarajan: Go in with three questions you want answered, not thirty booths you feel obligated to visit.

                    Black Hat is valuable precisely because it is dense. The problem is that density can turn into noise quickly. Every category will claim urgency. Every vendor will have an AI story. Every session will sound relevant if your filter is too broad.

                    The best way to get value is to anchor the week around the decisions you need to make when you get home. Are you trying to understand how agentic AI changes your security architecture? Are you evaluating identity risk? Are you trying to reduce SOC burden? Are you preparing for PQC migration? Are you pressure-testing cloud or OT exposure?

                    Use those questions to choose sessions, meetings, and booth visits. Leave room for unplanned conversations, because some of the best insight at Black Hat comes from practitioners comparing what they are actually seeing in the field.

                    And protect your energy. The goal is not to collect the most swag or attend the most sessions. The goal is to leave with sharper judgment than you arrived with.

                    VMblog: When the industry gathers again at Black Hat 2027, what do you think will be the defining cybersecurity conversation that dominated the year?

                    Varadarajan: I think the defining conversation will be the breakdown of trust assumptions across the enterprise.

                    AI will be a major part of that. By Black Hat 2027, the debate will have moved well beyond whether attackers are using AI. The more important question will be whether defenders can protect environments where autonomous systems can discover, decide, and act faster than traditional security workflows were designed to handle.

                    That will force a harder conversation about defensive architecture. If attackers are using AI to build a more accurate model of the enterprise, defenders will need to make that model less trustworthy. Deception, cloaking, high-fidelity tripwires, and preemptive controls will move from “interesting” to operationally necessary.

                    PQC will also be part of that trust conversation. Organizations will be under more pressure to understand where cryptography lives, which systems rely on brittle algorithms, and how exposed their keys, certificates, signing infrastructure, and machine-to-machine communication really are.

                    The other major thread will be non-human identity. Service accounts, workload identities, API keys, automation accounts, AI agents, MCP servers, SaaS connectors, and CI/CD identities are becoming the enterprise operating fabric. Many of them are powerful. Many are under-governed. And many can be chained in ways security teams do not fully see today.

                    So if I had to put a frame around 2027, it would be this: security leaders will spend less time asking how to detect attacks faster and more time asking how to defend the trust fabric itself. Identity trust, AI agent trust, cryptographic trust, machine-to-machine trust, infrastructure trust, and environmental trust are all coming under pressure at the same time. That is the conversation that will define the next phase of cybersecurity.

                    ##