
The old security math is broken. Teams used to get roughly 60 days between a vulnerability going public and attackers using it. Harman Kaur, Tanium’s CTO, explains why that number has flipped to negative, and what it means when the patch you need does not exist yet. This conversation is about the difference between automation and transformation. Running the same broken process faster is not progress. Harman makes the case for rebuilding security from first principles: changing org charts, retiring tools people have relied on for years, and moving humans out of triage and into judgment. She also gets specific about trust. In her view, trust now sits in the underlying data, because a confident AI acting on stale or incomplete data becomes dangerous at scale. Harman & KB get into the boardroom scramble around Mythos, why there is no single tool that solves it, and why the vendors closest to the data will be the ones left standing. About Harman: As Chief Technology Officer, Harman Kaur...
Loading summary
A
You had about 60 days from a vulnerability being discovered to it being exploited. Now the number is actually going towards the negatives. It's because as soon as it's discovered, before there's ever even a patch available, Right. What we used to sort of consider day zero, people are already exploiting it.
B
From KBI Media, I'm Carissa Breen and this is KBCast. My guest is Harmon Kaur, who leads AI and automation strategy as CTO at Tanium. We talk about how the time between a vulnerability surfacing and being exploited went negative. Why bolting AI onto legacy processes changes really nothing. And the question still hanging in the air is can organizations go back to the first principles fast enough to matter? If you found these conversations useful, hit follow. It's the single best way to make sure the next one lands right into your feed and it helps other execs find the show. Alrighty, let's get into it. Okay, so, Harman, I really want to start with. AI has now collapsed the time between discovering vulnerabilities and then also weaponizing them. Would you say we've reached a point where manual security operations is simply obsolete, or talk me through what's going on in your mind when I ask you that question.
A
Question, yeah. So is manual security operations obsolete? I think parts of it have to be obsolete because if you think about what is the kind of fundamental issue right now, it's honestly speed. Right. Like, AI is able to do a lot of things faster. So if you like distill that down. Do we still need humans? Yes, I think we still need humans, but their jobs have to move more towards judgment versus sitting there and triaging every single thing that comes in. And because you're never going to be able to catch up, you're never ever going to be a company that's sort of ahead of a lot of those threats if we're still managing those things manually. I don't think, you know, humans are completely out of the equation. And I think the manual does have to move to automation, but I think humans have to be inserted in that process still for judgment as well. I think that becomes really critical.
B
So speaking of the word critical, would you also say just the time between, as we know what's happening in the market, vulnerabilities coming out? Back in the day, we'd have a lot more time to patch them, to think through them more strategically. Now we don't. So what does that pressure look sort of downstream on a team, like coming from an executive like yourself?
A
Yeah. If you like think back, I Think we used to say about 60 days. You had about 60 days from a vulnerability being discovered to it being exploited. Now the number is actually going towards the negatives. It's because as soon as it's discovered before there's ever even a patch available, right. What we used to sort of consider day zero, people are already exploiting it. So like patch isn't an even available solution, isn't even available and there's already things and it's already being exploited. So how do you get ahead of that? Like the clock is completely changed. So if that the clock has changed, we have to adapt on the other side as well of how do we actually take that into account for every single thing that happens in an organization? I think a lot of it comes down to so a patch is unavailable for a vulnerability. The first thing is like are you going to even know where you're exposed? Right. So even if a patch isn't available, but like just having the confidence and awareness of like where does it actually exist and which machines across my organizations is impacting? Is it the machines that are the most critical? Are they the most critical assets in my organization or is it machines that aren't as critical and if someone was to get access into those machines, what other damage could they do? So that's where I think I was talking earlier about like the human judgment. Those are the things I think a lot of people have to start thinking about. And it's a lot less linear than what we're used to in security, which is alerts are coming in, we're triaging them and then we're eventually thinking about applying the remediation. Or even if you think about a patching cycle, right. Patch Tuesday would happen and then people would have their month long processes and hopefully get to some, some level of compliance which is generally 80 was celebrated, 80% was celebrated. I think those days are kind of going to be of the past. Pretty quickly.
B
Okay, so there's a couple of things in there that I want to talk to you about. Going back to your comment around the clock has changed, obviously it's a lot shorter time frame and then ultimately there may not be the right patch or solution. So what do you think sort of rattles companies more? Would you say it's oh my gosh, we've got less time or is that we don't actually have a solution to the problem or do you think it's both?
A
I think it's a couple of things. I think you're. So not only are we battling like we have to get faster, we have to introduce new tools to do these things. People are also battling their own culture, right? So, like, we've built these processes, we've built these tools, we've built these things in our organizations that also sort of culture has been created around them. So now not only people are having to go in and say, we need to change the process, we need to have different tools. They also have to go change a culture of an organization and say, like, we have to fundamentally think about these things differently. So I think that's one. The second thing is we've built processes in our organizations that were for humans effectively, right? Like, I'm a human that comes in and does triage and then I pass it along to another human. Now that's not happening, right? When an alert comes in and the triage happens, it's an agent generally now starting to pick it up, and there's a lot of tools that are doing that. Then an agent has to be able to pass it off to the next process, right? So these, like, processes that were handled by humans to make humans lives easier, you can't just say, like, let's make those faster. We have to rethink about them fundamentally. Why was that created in the first place? Why were we doing it that way? So I think having especially at a scale, think about scales of some of these organizations, imagine having to sort of hit the reset button and be like, holy crap, we've got to go back to first principles. Like, why do we even have this process to begin with? Like, that's a huge undertaking. Because now with Mythos and all of those things out there, people want to sell a single solution. People want to say, there's a single sort of magic wand you can wave. I don't think so. I think that's a quite reckless way to look at it. I think it's going to be much, much deeper. I think we fundamentally have to think about defense differently. The industry is going to change shape, and we're seeing it sort of evolve and change shape pretty quickly.
B
Okay, so before we move into that, I want to just go back for a moment. You said security teams, they're not thinking as linear as what we were traditionally. So even what was going to my mind as you were talking, Harmon, would be when we sort of shifted in project management away from waterfall into Agile, there was all these coaches and scrum masters trying to move people away from being more rigid in how we'd run a project, for obvious reasons. So that same approach culturally is happening now, but ultimately time is still against us. Like, we don't really perhaps have the luxury of doing it like we did 10, 15 years ago. So how does that sort of start to integrate that cultural thinking, moving away from being linear, making decisions faster, Perhaps that's making executives in very bureaucratic, rigid organizations a bit more nervous. What does that sort of look like in your eyes?
A
So one of the things I like framing that I use with my team is if you are doing the same job that you were doing in your roles six months ago, we are not keeping up with AI, we are not keeping up with industry. So like, that's sort of one framing to think about it. And really what that fundamentally means is if we're ending up with the same org structure, we have more things to do. We're not really like transforming anything. Maybe we made things faster by introducing an automation because we added Claude here, we added Claude there. That's not really thinking about transformation. So what I keep challenging my team and how I'm thinking about, even like product development is if we are thinking about things the same way and doing these things the same exact way we were three months ago, six months ago, we're actually not evolving with the industry and we are not keeping up and we're not fundamentally going to be able to serve our customers when they need us. So I think a lot of people are kind of talking about the automation and kind of stopping at automation. I think we've got to go deeper into transformation. That includes changing org charts, as uncomfortable as that sounds now. Right, right. It's changing tools, it's kind of changing fundamentally genetic makeup of your organization piece by piece. And I know that's sort of counter to, you know, what we were saying, which is like, we don't really have time to do this, but what's the alternative? Like, right. Do you hire a bunch of people to stand outside your door and like, hope for the best? But there's. You're going to run out of people to hire eventually. So I think the sooner, I think you kind of start that process, like on my teams, I've been very fortunate that my focus has been AI for the last couple of years and just really automation for organizations. I have literally changed the shape of my team every few months and even titles of people and what they were doing. And that's because that's what the industry needed. And I think we have to be okay with that. The other thing I've gotten really comfortable with and I'm evaluating people when I'm hiring is like failing fast as Cliche as that sounds, we're also in a world where we have to experiment and then we have to say, you know what? That's not going to work. Because previously it was. We would sort of say, we're going to do this project for the next six months, eight months, and implement this tool. By the time you're done with that implementation, that tool is going to be the most irrelevant thing that you've implemented. That's kind of when I say when, really foundational, really have to think really deep.
B
And would you say, because I know everyone's very focused on AI and the technology, but going back to your cultural piece, because even back in the day when. Because that whole adage, humans are creatures of habit. Like, no one really wants to change what they're doing, but we have to get past that. Even when we'd implement, like, a new tool, we'd have to run all of these, like, operational change managers and these whole project teams to train people. Like, obviously, like, those are more luxuries back when that was a thing, but now it's not because of time is against us. And how does that sort of sit with people that have been in the game? Like, people who say, I've been doing this for 20 years, are getting past. Like, we have to constantly be moving every three months. Like, maybe it's different for people who are the newer generation. They're used to constant change. But for people that have been like, hey, I've been in this tech space for a long time, and yes, I'm used to change, but not the volatility and the constant change. Like, how does that then look culturally as well?
A
So I think there's a couple of parts to it. First, I'm trying to embrace that there's something gratifying that we're all going through it together. So it's not unique to our organization, it's not unique to our team. We, like, have to look around and say, we're all literally as humanity in this, regardless, if you're a doctor, a lawyer in cybersecurity, we're all kind of going through it together. And I think we have to find some sort of solace and that everyone's experiencing this. The other is like, this is going to sound like really meta. We actually, the thing that's creating all this change, AI, that is also the thing that can help you get adjusted with the change. Right? So, like, I have my grandparents now using AI, and they're sort of evolving with it, you know, and it's so interesting to me Seeing like they're researching their exercise habits and like, should they exercise less or more? And they went on this walk that's kind of from a culture perspective, we're all in this together, not just as a my team that's impacting or my industry. Everyone is being impacted across every single industry. I don't know a single industry that is not being disrupted by AI. So you can really say if I run away and go do this, you know, I can sort of escape this. Unfortunately, I don't think any of us can. Even if you think you can find an industry that's not being impacted, if you have kids, your kids at school are going to be using AI and experiencing this. And then the other is like, how do you actually use this tool to help you kind of evolve? Like that's been a large, large part of what I've been doing with my own teams is like use the tool to teach you the thing that you need. You feel like the next skill that you actually need.
B
So on that point then as we know, everyone is sort of racing to add AI into their security stack. So what would you say is the main difference between organizations that are genuinely transforming with AI versus those who are just sort of automating, like inefficiency. Walk me through what's coming up there.
A
Yeah, I think for me, when I say, when people say, oh, automation, I think the first thing is are you doing the same thing faster? Like that's the first question I always ask is like, are you doing the same thing faster? If that's the case, is that really going to scale? Does that really make sense in this new world? I think that's my general frame of automation. If we're doing the same thing, the thing we're automating generally is we put that process in place because it was facilitated by humans. Now it's going to be facilitated by AI or agents. So like, shouldn't it fundamentally be transformed? Should we rethink about how we're implementing this? I think doing the same thing faster isn't really a transformation. I don't think you're really doing much. Maybe you gain a little bit of efficiency, but that's not the thing that actually is going to scale. And then if you think about it, adding, you know, every company right now is adding new tools and new things into place. Those tools aren't going to play as nice to those human driven processes that are just like patched over with some sort of automation either.
B
So would you say, given your role in your pedigree, people Are sort of just saying to you, hey, Harmon, we're sort of doing the same thing, but faster. Would you say most people are in that sort of camp or there's sort of a mix of people, customers that you're speaking to out in the market.
A
It's genuinely at this point a mix. So I'll give you the journey that we have been on. So if you think about cybersecurity, what are people generally afraid of when they're thinking about like security or managing enterprises? One, they're obviously afraid of being breached and you know, their organization being impacted. The second thing, they're afraid of disruption to their business. And the third thing is obviously losing productivity of their end users. Those are like the three meta big things that everyone, if you like want to distill security down to is like those are the three things every ciso, every cio, every organization is thinking about. So for that, when you think about automation across all of those, what we did is we actually started building tools and we started building things of how do we actually help build trust to say, when you do this thing that's good for you, whether it's applying a patch, it's updating things, you actually have confidence to make that change. Like that's like one way. So that is a different way to think about security, right. Previously it's like, I just need to be faster at patching. Now it's like, okay, can you build in like a trust layer that helps you go faster? Not just like, let me go faster and schedule my patches instead of going out weekly to go out every two days. Right. Does that make sense? Like, so that's like the fundamentally really thinking about it differently piece Same thing with when you think about security. Security is always like most security tools are generally the last line of defense is which is like if you really think about it, you're like, that's a really weird way to think about security is the fanciest tools we all pay for and employ are generally the last line of defense. Why, like, why is that? And part of it was like kind of constrained on the number of signals. Like you have to sort of absorb, right? To be able to say, is something bad happening in my organization? Because those were consumed by humans. Humans had to analyze, is something bad happening across my organization? Now you have like tools. It can absorb unlimited number of signals and be proactive. They can be predictive about behavior. So again, that's like thinking about that's just not going faster on an existing process. That's like rethinking about security and management in general. So that's kind of been the conversations that I've been having with a lot of organizations, a lot of customers is how do we rethink and like, where were the constraints in the existing kind of model? Kind of, how do we address those now from a first principles perspective?
B
And what's interesting, the operative word you say is trust. Because even a couple of years ago, people were like saying in my interviews, like, trust, trust. But I would say people would probably describe that word back then as like a fluffy word. But now to your point, trust is like perhaps that missing piece that companies to be like, what are we doing with these agents? Looking at human identities, non human identities, like all these sort of pieces that are trying to fit together. So this whole trust piece that I'm hearing a lot by interviewing folks like yourself is starting to almost have a bit of a resurgence in the definition, but also the meaning then behind it. So would you say companies are reevaluating what trust actually means in their company, which is a lot more than the fluffy, it feels good and it looks good sort of thing?
A
Yeah. For me, trust comes from the underlying data. Right? Do you trust the underlying data? Like, that's fundamentally what's going to drive the trust? Because that's what Dr. What is driving the. The rest of the systems and everything. I think that to me, especially when you think about it in the context of security, if decisions are being now made by autonomous systems, the decisions are being made by agents, like, what are they referencing? There is no human there in some of those processes. If the human's not inserted in those processes as a judgment, then what are they referencing? If that data doesn't make sense, if that data is stale, if that data is not complete, you're kind of setting yourself up, I think, a little bit for failure. So I think trust for me has kind of gone back to where, like the foundational data that you're using to drive all these systems. And I think that also can be a very daunting conversation. It's like, well, how do I get the right data? How do I get to a place where my organization has, you know, the right data or the most complete data, et cetera? I think some of it is. It's going to sound a little like, counterintuitive and maybe a little. I think it's got to come down to reducing the number of tools. If you're referencing a lot of tools and a lot of things, and stitching data together at itself is like a recipe for Disaster, especially in security. That's what we saw a lot when we were going in, helping organizations with automation. They were trying to congregate data from like 18 different sources, some included spreadsheets. And like, I want to automate this. Okay, we need to like reduce the source. Like, let's get as close to the source as possible for the automation. We don't need all these sources anymore because there's no. We're eliminating the humans consuming this or facilitating this.
B
Okay, so whilst we're on the topic of data, I want to then go into that a little bit more. So I've been interviewing people, President of like NetApp, for example, is all about modernizing data. Board members are saying, well, what do we need to do to be able to leverage AI? Well, obviously it's in the data. So. So would you say in cybersecurity, what are the consequences potentially of building AI on incomplete or poor quality data? So adding on a little bit more around even the interoperability piece, people talk a lot about that. But if it's coming from random spreadsheets that were 20 years old and bits of pieces here and there, it's not as efficient. So I'm keen to get into this a little bit more, so then people can start to understand by having proper data leads into leveraging AI more effectively.
A
So I think everyone has used the adage of like garbage and garbage out all of that stuff. I think for cybersecurity, it's bigger. AI is very confident. It is a very confident tool. Right. It doesn't know that the underlying data is wrong. So what it does is it actually empowers that tool to become dangerous. And that's a scary word to use, but it frankly becomes dangerous at scale. So if you have sort of poor quality data, you have incomplete data, what's happening at scale is going to be quite dangerous for organizations. And that's why, you know, I keep inserting the word trust into it. You're automating things potentially off of incorrect data or incomplete data. We're also seeing in systems where AI will try to fill in the blank, there's missing piece of data, it will try to fill in the blank, rightfully or wrong. And that goes back to data quality. So I think for me, the word I always come back to is like bad data equals bad dangerous at scale for AI. If we're going to employ AI systems to do this stuff for us, we'll
B
come back to that after a quick word from our sponsor. If you're in legal risk or compliance you know the stakes and the spreadsheet sprawl. Vanta makes life easier by automating key parts of your security frameworks. From evidence collection to audit readiness, ISO 27001, SOC 2, GDP, PR. It's all in one platform built to reduce manual work without cutting corners. Visit vanta.comkbcast that's V A N T A.com kbcast to learn more. And then Harmon, when you say poor quality, how do you define poor quality?
A
Yeah, that's a really good question. I think for me, the way I define poor quality is a couple of things. One is insecurity. You cannot rely on data that was from a couple of days ago or a couple weeks ago because the state of the machine, right, the state of the network is constantly changing. So the most recent state of that machine, if you're, especially if you're going to make a change on that, you need to have the most kind of current understanding of that machine. So that's one kind of. The other is the completeness of the data as well. So do you understand all the context that you possibly can about this device, about this network? So it kind of is a couple of layers depending on what's happening. But those are some of the things I use to kind of evaluate like data quality.
B
So then here's a question for you. If companies are going through this process of modernizing their data or however you want to frame it, would they leverage AI to then audit the data to then give you a score to say poor quality? Is it incomplete? Is that what companies are doing? Because I mean, I'm an ex boy banker and worked in security. There's like hundreds of thousands of records, millions of the stuff for something that's been operating for a hundred years in very old school data sources. How would you sort of do this to get a bit of barometer on? Oh, actually our stuff's pretty poor. We're going to need to do some work here.
A
I think there is a couple of like litmus tests there. Some of those, when you look at a process, if you want, if you take a process and say we're going to automate alerting, we're going to automate a triage. A lot of these models want to give you a confidence level one, not just the effort of it of you doing that well, how often can you actually make it happen? Is it like actually we're only able to triage 25% of our alerts coming in and we have to have a human engage in the rest of them. That's like a really, really kind of giveaway sign. Okay, something is wrong because something doesn't have enough information to actually triage these alerts. You know, I was talking to an organization, they have automated 80% of all of their help desk tickets coming in. And the way they did it is they went and kind of transformed and made sure there was documentation available every single time. You know, historically a ticket came in and how is remediated. And that's the data it was using. And that's the metric they sort of use for them is as that number climbs, right. Like, their data quality is obviously improving because the underlying data is getting better. And AI is able to leverage that data to actually help cloud close more and more help desk tickets. So that's usually like a pretty good indicator as well. You can apply your own kind of metrics to that however you want to view it. But that's generally a lot of organizations, if you can't do it, if you can't automate, it's generally because something's missing foundationally.
B
And that's the other thing I'm hearing as well from companies that I'm interviewing saying it's deterministic. So for example, an airline company, there's going to be the same style of questions that customers are going to ask me to change my flight, I missed my flight, something's happened. And then they'll start to see the same sort of responses coming in and then it will start to have more of a deterministic response to say, okay, we've seen that, but if it's something we haven't seen, then it'll be flagged by a human. Do you think it's just going to be a bit more of a process then? Because there could be something that perhaps there is a blank, or there's something crazy that someone hasn't seen before. What are your sort of thoughts here?
A
Yeah, absolutely. I mean, we have to like remember that we built all these systems for humans to consume this data. Right. We relied on humans to facilitate these systems as well in the past. So there is a bridge that we have to build. As companies that are building AI systems, they're still relying on experts to say. They're still relying on experts to say what is the right way to do this? Is this correct? So even if you take like an example, like in legal, so people feel like, you know, they're. Everyone feels like they're a lawyer, everyone feels empowered, which is great. But what are people still paying lawyers for? They're still paying lawyers to do the last mile, right, the last check. Is this correct? Is this right? So because the systems are built, they were built for humans. So there's still a human judgment layer that's going to exist, I think for a very long time until we close sort of those gaps.
B
And then going back to your comment before ran, fill in the blank. Would you say companies are flagging this as a risk? And what I mean by that question is if it's answering a question, it's filling in the blank, something that isn't desirable and then it's obviously synthesizing an answer or coming up with something that perhaps is maybe not true or is exaggerated. Are companies starting to think through that in terms of, hey, yes, we need to look at the quality, but also making sure if there's a gap, there's a blank. What do we do about it?
A
I think so. And like the way we're thinking about it and the way we actually started thinking about this couple of years ago, we created a role, initially we called it AI Interaction Engineers. And what we did is effectively that, that was effectively their job is like these, filling in the blanks because they were the experts in that domain to help fill in those blanks and to connect those dots for AI systems. And I think people are focusing on that more and more because that eventually is what serves the automations that are driven off of that as well. Even today we employ a lot of experts to do the validation too, until we get to a point that we are, you know, we are confident benchmarks that are a certain level that it's not needed. But for right now, that layer is definitely still very much needed.
B
And so then I want to ask you, why would you say companies perhaps are still applying yesterday's security models to tomorrow's threats? And I know it's hard because, you know, even in media, things change day to day, week to week. So I understand from an operations point of view people are trying to keep the lights on and run ops. And then something else happens and I got to change tact, talk me through what's happening from that mindset point of view.
A
We have to give people a little bit more grace. I think the reason I say that is there's so many layers to just saying, hey, adopt this new model. One of those layers is like compliance, right? Organizations are held to a certain, especially public organizations are held to a certain level of compliance regulations. So they still need to adhere to that as they're making changes. How do they not break that? How do they. And there's Also things like, you know, they have SLA requirements, contractual requirements that they're bound by. They have change management windows that they implemented 15 years ago that they have to redo, which impacts a lot of systems and a lot of people. So I think there's layers to this that people have to tease apart that have been built over so many decades. This is an interesting area. If you asked me about automation three years ago, I would say people are still resistant to automation. Now I would say people wish they could go faster, but these types of things are still kind of. People feel trapped by them. People still feel like speed bumps that they have to get over and have to tease apart before they can get to this sort of new world. Applying all of these like AI tools, applying the, all of the different practices to kind of for today's threats effectively. And I'm also seeing this trend, which is it's used to be we put all of this responsibility on CISOs and said, it's your job. I am seeing you know, more kind of executives lean in across CFOs, CEOs, and say, hey, we have a real threat here that we need to embrace and we've really got to have a change that happens. As well as boards, I've talked to a number of customers that have said we actually owe our board a response for how we're going to get ready for Mythos. Think about the last time that's really happened, right, where boards have mandated some sort of response from organizations to make sure they're ready.
B
And how are those responses going, would you say?
A
I think it's actually interesting you asked that. So I think originally, like, as soon as the announcement around that came out, originally, people were researching in the form of a tool and saying, we're looking for a tool that helps us with Mythos. And I think very quickly they realized it's not going to be a singular tool that sort of combats or helps with Mythos. And I think people are looking at it now is, oh man, we've got a lot of things and processes to change and a lot of different principles to apply. And the answer also isn't just patch faster. Like physics isn't going to allow us to patch faster. One, patches aren't being written faster, fast enough. Second is you still have. People still need to do their job. Like, I still need to be able to access my laptop. I can't be rebooting my machine multiple times a day just because the patch needs to be applied. So we can't patch our way out of this show, we need to automate and make patching much more efficient across organizations. But we have to also think about other things. How do we reduce potentially, you know, attack surface of my device? Right. Do you uninstall things I'm not using? Do you click close ports that aren't needed across an organization? So I think people are realizing that response is a little more comprehensive than, can I buy a tool that's going to help me? A singular tool that's going to help me with Mythos.
B
Yeah. And that's interesting because when I've been talking to people in the market and companies, that's pretty much been the response that I've heard so far. Would you say that now companies are sort of zooming out from just buy a tool and it'll solve our problems? I think companies are looking a little bit more holistically, a bit more operationally, a little bit more individually on, like, can we remove stuff? Perhaps that Harmon on a laptop she's not using. We have to be realistic in order to leverage to get effective productivity out of. You can't be rebooting your laptop like 12 times a day. So is it more People are thinking practically on that front?
A
I think people are. And I think there was the initial, which is like, adopt AI as quickly as possible at any expense. Doesn't matter. As, you know, people were putting up the leaderboards of how many tokens is someone consuming in an organization, and you are somehow the winner of it. Now people are actually like, okay, let's talk about productivity. What are we actually getting out of this? Does this mean we can actually reduce headcount? Does this mean we're actually shipping faster? Are we doing more? So I think people are just at a much broader level, thinking about AI in a much more, much more impactful way. Looking at roi, looking at productivity, worse is, let's go faster, let's adopt AI at every cost. And same thing with, you know, Mythos and vulnerabilities and new threats. I think people understand the transformation they're having to go through, but people have. This is where someone like, for our organization, it's been really interesting to watch. People are also, like, ready to let go of old, archaic tools. It's not so much like where previously used to be sort of a conversation like, what do you think about your existing tools? People are like, don't need them. They're not going to fit into this new world because we have to move much faster and these tools don't move with us. And people are embracing that for the first time more than I've ever seen it before.
B
Okay, that's interesting. So what do you mean by old archaic tools? So why would they be embracing that then if they originally thought there's no purpose, but now it serves a purpose. I'm keen to understand what you mean.
A
So I think historically people would say, hey, these, like, three admins love this tool that we implemented six years ago, so not sure if we want to move it, if we want to remove it. Now organizations are, you know, saying, you know what, I don't care if someone. These three people love this tool. It's not going to fit the way we're transforming the organization. So people are kind of are being much more aggressive in the implementation and the tool choices that they're making too. Does it actually fit into this, like, sort of new world as well? And also, like a lot of tools, why did people want to keep around some of these tools? Because they Learned these complex UIs for a long time, right? Like, I've spent my whole career learning this, like, just picking on Photoshop, right? Like, this tool that's really, like, hard to use. And, you know, I know all the bells and whistles. I know where this, like, tooltip lives. I know these shortcuts. Like, now everything is, like, transforming into a problem, right? Like, I want my picture edited this way and fix this and fix that. So, like, does it really matter? So I think people are also just saying, like, oh, okay, the next tool doesn't actually require me to go, and I got a PhD and all those little tools and bells and whistles work either.
B
Yeah, that's so true. Because even, like, it's like, I'm going to learn something else now, so used to the other way. And so therefore, that's interesting because that's probably what has kept potentially vendors with customers that may or may not needed to be there. But people were so used to it. And like, going back to the earlier point, people don't want to change. We want to just use the thing that we've been using because it's helpful, because we got other things that we need to do each day. So then what does that mean then for the industry? Because like you said, it doesn't really matter. The tool then underneath, if I can just ask it a question and I get the answer, becomes irrelevant. But then does that make perhaps the market very competitive then? Because perhaps people were being a little bit more like, well, we know that the renewal is fine because we don't need to change too much, but now that's a very different conversation because it's going to be like, does the thing work? We don't really care about understanding to your point. UI ux, because that's obsolete.
A
So irrelevant. Yeah, it does. So what we introduced was actually that interface for the endpoint management and security. For endpoint management, security, exposure management. That's what Tanium introduces. Sort of this chat prompt interface. You can do anything. Right. Because it's so interesting. I always thought it was really interesting that people identified their roles. Like, I'm sure you've heard this before given your background of like I'm an SCCM admin and you're like, no, you're a patching expert. So it's so interesting. And the reason why they identified with those tools was they learned their really complex UIs, they knew how everything worked and all of those pieces. So I think it's completely shifted. And so what do people care about now? It's honestly the data. Think about how many people are also consuming tools just through CLAUDE now through the connectors. And what do they care about through claude? Is the effectively the data from those tools. Like that's what the races really fundamentally come down to is the data, is it complete, is it accurate and can I use it to automate my processes and get my job done? It's the race is no longer about. Do you have this button? Is it purple, is it blue? That's what a lot of it used to be for a period of time. Do you have these shortcuts? That's.
B
That's so interesting. So then what does that mean? People just want the outcome. So it's like, I don't. I need to look underneath. If it's giving me what I need to do my job, then who cares? Whereas before you're right. If, even if you look back through history, people would go to the same bank that we bank with now. People don't doing that now you've got independent fintechs open up left, right and center. People will go somewhere faster, better, cheaper nowadays. And the same probably applies for the tech vendor landscape. So help me make sense. What do you think moving forward now? You've given a really good snapshot from your perspective, but how do you sort of see things unfolding now?
A
A couple of things. Switching costs is going to go down to some extent because people don't have these like, you know, think about how much training you would have to bring in if you're going to bring in a new tool. Right. I think that was that word used to be the word when there was a new tool being introduced as, like, training that's basically effectively gone, People are also going to be more keen to switching, which also increases. I'm actually happy. Like, you know, maybe this is weird to say from, like, when I'm building these tools, is the competitive pressure for these tools to sort of keep up and making sure they're actually, like, delivering what organizations need, humanity needs right now, as it sounds really, like, scary to say that we need to make sure these organizations, these really critical organizations that are serving our, you know, healthcare, that are serving our retailers, our banking systems, the Department of War, do they have the tools that they need to be able to operate and still do what they're doing for us in the world. And I'm glad that this kind of competitive pressure that it's creating for vendors, that they have to keep up and sort of evolve with it, and if they're not, they're not gonna make it.
B
And then just on that note, do you envision that customers will do that switching? Because sometimes it's been hard to, like, switch from, like, a vendor that's been in there for so long. And I've always been thinking about this because I've worked in enterprises before. It's like, how would we ever get away? Like, it's just so entrenched. So will we start to see more of that? Perhaps the loyalty just isn't there. Like I said before, if they can get it from. Maybe it's a tier four bender that we've never heard of, but they're really good at what they do, and it's faster, better, cheaper. Will we start to see that in customers in terms of a shift?
A
Think about how many AI companies we've seen in the last year pop up and, like, companies have embraced those tools. I think we're also going to go through a shedding phase. Like, I want to be like, I think we all kind of collected all these toys. We are going to go through a shedding phase. I do think that's going to happen, but I think people's ability to now move and embrace new tools and a lot of this pressure also comes from boards. Everyone has some sort of AI metric, AI initiative, right? AI officers, that's kind of become pretty standard regardless of what industry you're in.
B
And so final question on the shedding phase is this now when we're going to start to see the pressure on for the competition with the vendors. Because it's true, people think they can switch, get away faster, not as entrenched, then vendors are going to want to A, keep their customers and B, win others and perhaps win a customer that they thought was never possible before. It's really anyone's.
A
Oh yeah, I do think that's going to happen. And the other thing is, I think or the tools with the best data are going to be the stickiest tools because they're going to be the ones that are driving a lot of the business processes, not the humans as much. Humans are going to be there for like sort of a judgment and facilitating that. So the closer you are to the data, your source of the data, your facility, then you're going to be much more entrenched in a business. If you're sort of this like cosmetic layer into an organization, I'm not sure what that means for your future. I don't think it's good given that Claude and other tools can do.
B
Now that was Harman Kaur, everybody. The idea I keep turning over and over is her point that a confident AI running on bad data becomes dangerous at scale, which means the real race is a race to clean current, complete data. So if you're a board director listening to this, the question I'd leave you with isn't which AI tool you're buying, it's whether the data underneath it can actually be trusted. I read every reply. If you got some thoughts on this one, send me a message on LinkedIn, Kbcast cyber for the c suite.
Podcast: KBKAST
Host: Carissa Breen (KBI.Media)
Guest: Harman Kaur – CTO, Tanium
Release Date: July 29, 2026
In this episode, Carissa Breen sits down with Harman Kaur to explore the rapidly evolving intersection of AI, automation, and cybersecurity. Their discussion digs into the urgent reality: AI has completely compressed (even reversed) the time between vulnerability discovery and exploitation, pushing organizations to rethink not only their technology stack but also their core processes and organizational culture. Harman challenges the widely adopted, but surface-level, approach of "automating existing processes" and advocates instead for a true organizational transformation grounded in data trust, streamlined tooling, and ongoing adaptation.
The Exploit Clock Has Changed:
Manual Security Operations Are Obsolete—But Humans Aren’t:
The Importance of Awareness Over Available Solutions:
Cultural and Procedural Overhaul:
Embracing Nonlinearity and Fast Failure:
Universal Change Fatigue:
Using AI to Adapt to AI:
Doing the Same Thing Faster Isn’t Enough:
Rethinking Security Fundamentals:
Trust Now Means Data Integrity:
Fewer Tools, Better Data:
Garbage In, Danger Out:
Defining Data Quality:
Automating Data Audits:
Determinism and Human Backstops:
A Call for Grace and Realism:
Boards Are Finally Leaning In:
From “Tool Love” to Outcome-Driven Technology:
Switching Costs Plummet—Market Becomes Cutthroat:
On Speed and Human Oversight:
"Manual does have to move to automation, but I think humans have to be inserted… for judgment as well. I think that becomes really critical." (A/Harman, 01:27)
On Transformation vs. Automation:
"Maybe we made things faster by introducing an automation because we added Claude here, we added Claude there. That’s not really thinking about transformation." (A/Harman, 07:21)
On Data as the Foundation for Trust:
"Trust comes from the underlying data… If that data doesn’t make sense, if that data is stale, if that data is not complete, you’re kind of setting yourself up… for failure." (A/Harman, 16:58)
On AI Amplifying Bad Data:
"AI is very confident… it actually empowers that tool to become dangerous. And that's a scary word to use, but it frankly becomes dangerous at scale." (A/Harman, 19:24)
On Organizational Change:
"I've literally changed the shape of my team every few months… and that's because that's what the industry needed. And I think we have to be okay with that." (A/Harman, 07:21)
On the Death of Tool Loyalty:
"People are… ready to let go of old, archaic tools… For the first time more than I've ever seen it before." (A/Harman, 30:37)
"A confident AI running on bad data becomes dangerous at scale, which means the real race is a race to clean current, complete data."
— Carissa Breen, 38:46
Boards and executives should pivot their focus beyond AI tool selection and interrogate whether the data underpinning their systems is sufficiently trustworthy. Only then can automation deliver more than just speed—ushering in real, resilient transformation.