Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2026 Q&A: Coalfire’s Charles Henderson on Machine-Speed Attacks, Agentic AI Risk, and Closing the Visibility Gap

Share: 

David Marshall | Published: July 30, 2026
vmblog blackhat usa 2026 qa

As Black Hat USA 2026 approaches, the conversation across the security industry has shifted from whether AI will reshape the threat landscape to how fast that transformation is already happening. Few executives are positioned to speak to that shift like Charles Henderson, executive vice president and head of DivisionHex at Coalfire, the global cyber advisory, assessment, and security firm whose team of expert hackers and defenders is built to break and defend enterprise environments against advanced threats. Ahead of this year’s show, VMblog sat down with Henderson to discuss what’s driving the accelerating pace of compromise, why open-source models are closing the gap with frontier AI, and why “unrestricted” AI hype shouldn’t distract defenders from unresolved fundamentals.

In this exclusive pre-show interview, Henderson previews Coalfire’s Black Hat presence — including a live demonstration of a machine-speed agentic offensive platform, an Agentic SOC session examining what makes AI-driven security operations trustworthy, and an inside look at the Black Hat NOC from longtime organizer Neil “Grifter” Wyler. Henderson also unpacks Coalfire’s new Managed and Transformation Services business unit, shares research on the rise of unauthorized “Shadow AI” activity, and explains why he believes 2027’s defining conversation will center on keeping human judgment in the loop as autonomous response systems take on more of the workload.

++

VMblog: For readers who may not be familiar, give us the elevator pitch — who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.

Charles Henderson: Coalfire is a global services and solutions company that specializes in cyber advisory, assessment, and security. Coalfire’s DivisionHex employs a team of expert hackers and defenders to build, break, and defend your company from advanced cyber threats.

VMblog: Black Hat attendees are a discerning crowd. What booth experiences, live demos, or hands-on activities are you bringing to Las Vegas that will cut through the noise and leave visitors with something they can’t stop thinking about?

Henderson: At Black Hat, we’ll be based at the Kumi Lounge at Mandalay Bay on Wednesday. There, we will showcase two major technical breakthroughs. First, John Hendley and Justin Podzunas will demonstrate a machine-speed agentic offensive platform that shows how threats in the near future will be collapsing defender timelines. Using open source models that can run on a laptop, attackers can compress time to network takeover; attacks that once took days can now be accomplished in less time than it takes a defender to make a cup of coffee.

Additionally, John Dwyer and DivisionHex will highlight this business unit during an Agentic SOC Demo at Black Hat. This session examines what makes AI SOC trustworthy and explores questions buyers and builders should have before trusting agentic security.

Neil “Grifter” Wyler, a mainstay at Black Hat for two plus decades will also be providing a behind-the-scenes look at the “one of the most  hostile networks in the world” – the Black Hat Network Operations Center (NOC) which his team has been responsible for building from the ground up.

VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?

Henderson: We believe that effective security is more than just compliance. Coalfire brings together elite offensive security, defensive operations, cloud transformation, AI expertise, and compliance under one modern cybersecurity strategy. We are partners for our clients to build resilient environments, not simply validate compliance after the fact.

VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors — whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else — is your solution most directly built to address?

Henderson: Attackers are taking their same playbook and starting to execute them both faster and more effectively.  Attackers keep getting faster, and the signals say that trend isn’t slowing down. Our solutions are built for the timeline that speed leaves behind, the one where defenders have less and less time to respond. While the playbook remains familiar, automation and AI act as an accelerant, compressing a kill chain that once took days or weeks into mere minutes.

Most security programs are designed for human-speed threats. Crucially, while there are increasing government calls to regulate or slow the release of frontier models from labs like OpenAI or Anthropic, open-source models are rapidly closing the capability gap to those frontier models, sometimes in as little as a few weeks. This is a double-edged sword. While attackers can certainly use open-source or open-weight models, defenders can too. And helping train and prepare defenders, especially around the threat of increased attacker speed, is something we’re very focused on.

VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?

Henderson: Because of the collapsed timelines, defense needs to adapt at similar machine speeds. If a response plan requires manual triage or executive-level approval to isolate a server, the organization has built a defense for a world that no longer exists; at machine speed, the window to notice and act on a major incident shrinks to something unmanageable for most organizations.

However, it is critical not to get distracted by the “unrestricted” hype alone. In the real world, attackers—even those using AI—still prioritize the path of least resistance, which remains stolen credentials or phishing, rather than complex zero-day chains. We’re helping our clients to view this moment as a starting gun to close visibility gaps and fix foundational architectural flaws, as you cannot defend against an autonomous adversary if you haven’t solved the security fundamentals.

We are most concerned that the risk of hidden automation is being underestimated. There is a layer of human in-the-loop oversight needed for all AI systems. Without a human overseeing AI activity, agents may go rogue and perform unauthorized actions, which is something we’re already seeing in the wild with Hugging Face. Recent research shows that 20% of AI-related incidents now involve these unseen agents performing unauthorized actions. This is another cry to focus on visibility gaps – you cannot protect what you can’t see.

VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026? Can you tease it or give us a preview?

Henderson: We will be highlighting out new business unit, Managed and Transformation Services. The unit will be led by John Dwyer, a cybersecurity executive, researcher and practitioner with more than two decades of experience.

The unit aligns service development, engineering, operations and go-to-market execution around a single strategy: help clients address compliance requirements, strengthen security outcomes and establish longer-term security outcomes. The unit is built to meet clients where they are, whether they need implementation support, a focused assessment or a longer-term managed service relationship. The goal is to build on Coalfire’s existing strengths with a more modern service and operations model.

Managed and Transformation Services also gives Coalfire a clearer platform for partner-led growth. Strategic partnerships are a key way that Coalfire will expand delivery capacity, formalize platform-enabled assessments, and create managed follow-on services across posture management, remediation governance, vulnerability management and operational reporting.

VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?

Henderson: The most significant blind spot is still the visibility gap. 50% of monitoring capabilities are currently lagging in AI adoption. Organizations are rushing to adopt AI for efficiency but leaving much of it unmonitored. We address this issue through our agentic AI threat hunting service by monitoring Shadow AI and identifying agents behaving outside expected parameters.

VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?

Henderson: Our solution helps security leaders navigate the “AI Efficiency Paradox:” 63% of teams have a primary mandate to reduce costs through AI, yet 90% report AI-related security incidents that create an unbudgeted “efficiency tax.” We justify ROI by preventing high-remediation costs—which exceed $500,000 for 24% of organizations—through closing the critical visibility gap. Rather than adding to the operational burden, we reduce it by automating the discovery of Shadow AI encountered by 80% of organizations weekly, shifting lean teams from reactive triage to purpose-driven, active threat hunting. This approach allows leaders to operationalize AI securely, transforming cybersecurity into a business enabler that provides measurable outcomes and long-term resilience without increasing breach exposure.

VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?

Henderson: Speed of detection and defense. Your enterprise needs a response system that is fast moving to detect and combat threats in real-time. Agentic attacks will execute in a matter of minutes, not hours. We’re bringing proof to Black Hat that demonstrates that reality. Companies need to move their response windows to counter these attacks appropriately.

VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?

Henderson: The industry continues to be distracted by shiny objects while overlooking the fundamental legacy issues around visibility, vulnerability management, and architecture, especially regarding identity. As we define in our research, organizations cannot successfully implement autonomous defense unless they first master the basics: being maniacal about visibility, turbocharging vulnerability management, and building a hostile architecture. For example, many enterprises currently suffer from incomplete EDR coverage and stale service accounts with excessive privileges—gaps that an AI-augmented attacker can identify and exploit in minutes. You cannot automate your defenses if you haven’t sorted out the foundational security gaps that have been ignored for years.

VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?

Henderson: The rapid decrease in time needed by threats post-compromise is a reality, not a projection; we’ve proven this through our own internal R&D, which has compressed attack speeds from minutes down to seconds. Organizations must move with urgency to get the basics of their security program sorted before they can realistically move toward automating their defenses. The reality is that attackers aren’t fundamentally changing their techniques—they are simply getting much faster. You don’t need to solve for wildly novel attacks; you just need to execute on the security fundamentals you already know to close visibility gaps and adopt hostile architectures.

VMblog: When the industry gathers again at Black Hat 2027, what do you think will be the defining cybersecurity conversation that dominated the year?

Henderson: 2027 is a long way out and security is changing faster than ever. While the industry is currently in a fully autonomous hype cycle, by 2027, I believe we will see a shift toward plugging humans back into the loop. Our recent research showed that 46% of agentic AI incidents involved autonomous systems performing actions that got away from the original human prompt. While large language models and agents can deliver results at machine speed, human judgment remains essential for making final decisions tied to financial, operational, or reputational outcomes. The defining conversation will be about defender-in-the-loop autonomous response, where AI-driven security agents provide the correlation and recommendations, but human practitioners provide the critical judgment call for when and how to act.

##