Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2026 Q&A: Brinqa’s Ron Dovich on Why AI Agents Are Only as Good as the Data Foundation Beneath Them

Share: 

David Marshall | Published: July 29, 2026
vmblog blackhat usa 2026 qa

As Black Hat USA 2026 approaches, the conversation across the security industry has shifted from which AI agent an organization has deployed to whether that agent’s output can actually be trusted. Few executives are better positioned to speak to that shift than Ron Dovich, Chief AI and Automation Officer at Brinqa, a company that has spent more than a decade building unified exposure management for large, complex enterprises. In this VMblog pre-show interview, Dovich explains why Brinqa’s differentiator isn’t another AI agent bolted onto a dashboard, but the CyberRisk Graph™, a governed data model unifying more than 260 data sources that every AI-driven prioritization and remediation decision is built upon.

Dovich also previews what attendees can expect at Brinqa’s Black Hat booth, from a hands-on CVE triage game called “Triage Tetris” to a confidential confession booth designed to connect with practitioners rather than generate leads. Beyond the show floor activities, he digs into the widening gap between AI-powered offensive capability and enterprise data hygiene, Brinqa’s recent BYOAI launch and Horizon3.ai partnership, and why he believes the industry’s next major reckoning will center on governing the AI agents organizations have already deployed. Read on for Dovich’s full take on ownership gaps, agentic AI risk, and what security leaders should be prioritizing for the rest of 2026.

++

VMblog: For readers who may not be familiar, give us the elevator pitch: who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.

Ron Dovich: Brinqa provides unified exposure management for large, complex enterprises. We unify data from 260+ connectors into Brinqa’s CyberRisk Graph™, one governed data model of vulnerabilities, assets, business context, and remediation history, so teams can prioritize real risk and route concerns to the right owner. What sets us apart isn’t another AI agent, it’s the trusted data foundation underneath it. Every AI recommendation, every prioritization call, and every remediation workflow above it is built on that foundation. Forrester named us a Notable Vendor, Gartner a Niche Player, and enterprises like Nestlé, SAP, Guidewire, PhonePe, and Cambia Health Solutions run on Brinqa.

VMblog: Black Hat attendees are a discerning crowd. What booth experiences, live demos, or hands-on activities are you bringing to Las Vegas that will cut through the noise and leave visitors with something they can’t stop thinking about?

Dovich: We’re skipping the demo pitch and running two activations instead. “Triage Tetris” will have attendees sift through real-world CVEs and decide in real time whether each one is genuinely exploitable or just noise, the same call security teams make every day, minus the spreadsheet. Our confession booth lets attendees step into a phone booth and record a confidential, off-the-record admission as a practitioner. It’s not a lead-gen gimmick, it’s a way to connect with people as practitioners first, and we think that’s what people remember after the carpet gets rolled up.

VMblog: What’s your Black Hat origin story? Longtime exhibitor or fresh face on the floor? What keeps your company coming back, or what made 2026 the year to finally plant your flag here?

Dovich: Brinqa has been building enterprise exposure management for more than a decade, long before it was an analyst category. We’ve been a steady Black Hat presence because our buyer, the security team, is stuck stitching together fragmented tools and has always been in that room. What’s different in 2026 is the shift from AI hype to AI accountability: the conversation moving from “which AI agent do you have” to “can you trust what it just told you.” We’re bringing that to the floor loudly, including co-hosting a party at the House of Blues with Horizon3.ai, a partner who shares that same high bar for proof over hype.

VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?

Dovich: The data foundation matters more than the agent. Any vendor can bolt AI onto a dashboard; few can prove the output traces back to a verified record instead of a guess. If a CISO remembers one thing: Brinqa is the trusted foundation that makes any AI strategy in exposure management safe to act on.

VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors, whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else, is your solution most directly built to address?

Dovich: The one we’re built most directly for is AI-powered, agentic attack speed: the collapsing exploitation window. Models like Claude Mythos Preview have already shown they can find thousands of zero-day vulnerabilities across every major OS and browser and move from discovery to working exploit in minutes. Brinqa’s CyberRisk Graph is built to close that gap. It maps vulnerabilities, assets, business services, identity, and remediation history together so exploitability and business impact get assessed continuously. We were accepted into Anthropic’s Cyber Verification Program to help operationalize this class of AI safely on the defensive side.

There’s a second, quieter vector: agentic AI amplifying bad data instead of catching it. Our own research confirms that ownership gaps run 60 to 80% in complex enterprise environments, and duplicate findings from overlapping scanners inflate risk metrics before an agent ever looks at them. Our AI Attribution and Deduplication Agents, and the BYOAI model that lets any agent query the CyberRisk Graph via API or MCP, make sure an AI agent is reasoning over verified, deduplicated data rather than noise.

VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for, and with, autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?

Dovich: We’re doing both. Brinqa’s own AI agents (Attribution, Deduplication, and Exploit) assign ownership, eliminate duplicate findings, and validate exploitability, all traceable to the CyberRisk Graph. Our BYOAI model lets enterprises connect their own agents to that same governed data via API or MCP, so they reason over verified facts instead of noise. We were accepted into Anthropic’s Cyber Verification Program as validation of that approach. What we think enterprises are underestimating: their own AI agents are becoming high-privilege identities that need an owner and an audit trail, and most aren’t tracking that yet.

VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?

Dovich: For Brinqa, it doesn’t mean generating more AI output. Tools like Mythos already do vulnerability discovery autonomously. Brinqa owns what comes after: our AI Deduplication Agent uses machine learning and LLM-based inference, not static CVE matching, to merge the findings as reported by Mythos-class tools, Qualys, Tenable, Wiz, and 260-plus other sources into one auditable record. Our scoring model layers in reachability, business criticality, and blast radius on top. Mythos is the most capable offensive tool ever built. Brinqa is the operational system that decides which of its findings represent real risk.

VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026? Can you tease it or give us a preview?

Dovich: Plenty to point to. In June we launched BYOAI, letting any AI agent or LLM connect to Brinqa’s CyberRisk Graph via BQL API or MCP, so teams can use the AI they’ve already invested in while grounding it in the same governed exposure intelligence. In the same month, we announced a partnership with Horizon3.ai, integrating NodeZero’s attack-path intelligence into the graph so prioritization reflects what attackers can actually exploit. And our 2026 H1 review reports that bookings more than doubled year over year, customers expanded deployments 4x, we became a Forrester Notable Vendor, and joined both Torq’s AMP Alliance and Google Cloud Marketplace.

VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?

Dovich: The ownership gap. As noted previously, our research shows that in complex environments, 60-80% of vulnerabilities have unknown internal ownership. Enterprises can usually find their vulnerabilities; what stalls remediation is not knowing who’s accountable for fixing them. Our AI Attribution Agent infers asset relationships, business hierarchy, and owners, so a finding lands with a name attached instead of sitting in a backlog.

VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?

Dovich: By consolidating instead of adding. Brinqa replaces stitching together dozens of scanners and spreadsheets with one governed platform, and our AI agents remove hours of manual triage: attribution and deduplication that used to take days now run continuously. Customers report 2 to 3x productivity gains and 75% faster incident response. The ROI conversation that CFOs understand: fewer headcount-hours on cleanup, faster remediation, and a solution with consumption-friendly procurement via Google Cloud Marketplace.

VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?

Dovich: Get your exposure data foundation in order before deploying more AI agents. An agent reasoning against bad data just produces bad decisions faster. Fix ownership, deduplication, and business context first, and the AI investment on top actually pays off.

VMblog: The conversation around software supply chain security has matured significantly, but has enterprise practice kept pace? What’s the current state, and where are the gaps that still keep you up at night?

Dovich: Supply chain security isn’t where we specialize; we’ll leave the assessment to vendors focused on code and SBOMs. What we see from the exposure management side: the conversation has matured faster than practice, and supply chain findings still live in their own silo. That risk should land in the same prioritization process as everything else, not a parallel one.

VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?

Dovich: What worries us most heading into 2027: enterprises plugging AI agents into their stack faster than they fix the data those agents reason over. Ownership gaps, duplicate findings, and inconsistent severity data show up in nearly every environment we onboard. Point an agent at that mess and ask it to remediate automatically, and it makes confident, wrong decisions at scale. The industry treats agentic AI adoption as a tooling decision; it’s really a data foundation problem.

VMblog: Does your team have any speaking sessions, sponsored research presentations, or Briefings appearances at Black Hat 2026 that attendees should put on their schedule?

Dovich: Check the Brinqa booth or our Black Hat event page for details.

VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?

Dovich: Ownership beats severity. A critical CVE with no owner never gets fixed; a medium finding with a clear owner and deadline does. Close the ownership gap before refining your scoring model. It’s the cheapest, fastest risk reduction move most programs can make.

VMblog: Are you hosting any exclusive networking events, hospitality suites, or invite-only dinners during Black Hat week? How should interested attendees get connected?

Dovich: Yes, we’re co-hosting a party at the House of Blues in Mandalay Bay with Horizon3.ai. Stop by the Brinqa booth to get connected to additional hospitality events during the week.

VMblog: What’s the most creative or unexpected giveaway your booth is bringing this year?

Dovich: We’re leaning into two activations instead of a trinket table. Inside, it’s “Triage Tetris,” our CVE triage game, and lucky players will walk away with a handheld Tetris console. Outside, it’s a real phone booth: the phone rings, attendees pick up and record an anonymous confession of their worst vulnerability management war story. Everyone can also grab a Brinqa challenge coin. It’s less about swag and more about giving people something to actually do.

VMblog: For the first-timer navigating Black Hat for the first time, what’s your best advice for getting maximum value out of the week without burning out by Wednesday?

Dovich: Pick three or four things you need to see each day and let go of the rest; trying to see everything means remembering nothing. Block real time for Briefings, not just the floor, that’s where you’ll hear what’s actually changing. And pace yourself: comfortable shoes, water, and a real lunch break beat any amount of caffeine.

VMblog: When the industry gathers again at Black Hat 2027, what do you think will be the defining cybersecurity conversation that dominated the year?

Dovich: Governing the AI agents enterprises have already deployed. By 2027 most will have adopted agentic AI in security operations. The defining conversation will be accountability, which agent did what, on whose authority, and can you prove it after the fact. That’s as much an identity and exposure management conversation as an AI one, and the industry is underprepared for it.

##