In a world where AI agents are rapidly becoming an integral part of various organizations, it's fascinating to witness how some companies are not only embracing this trend but also leveraging it to gain a competitive edge. Exabeam, a cybersecurity vendor, is a prime example of this strategic thinking. In an exclusive interview with CRN Australia, Pete Harteveld, the CEO of Exabeam, shared his insights on how they're navigating the rise of agentic AI and the so-called 'SaaSpocalypse.'
The Dual Approach to Agentic AI
Harteveld emphasizes that Exabeam takes a two-pronged approach to agentic AI. On one hand, they incorporate AI agents into their products to enhance the capabilities of security operation teams, making them more efficient and better equipped to handle sophisticated attacks. On the other hand, Exabeam also focuses on monitoring and understanding the behavior of these agents, ensuring that organizations can protect themselves against potential threats, such as compromised or malicious agents.
What makes this particularly fascinating is the analogy Harteveld draws between AI agents and humans. He highlights that agents, much like humans, operate based on credentials and exhibit specific behaviors. However, agents have the advantage of speed and continuous operation, which can be both a blessing and a curse.
Insider Threat Management and Agent Behavior
Exabeam's approach to agentic AI extends beyond just product integration. They view agents as non-human identities, employing a different set of detections to monitor and understand normal and abnormal behaviors. This is crucial, as agents, like humans, can be manipulated or compromised, and their actions can have significant implications for an organization's security.
Harteveld provides an insightful example: "If you're an insider threat team, you can see Pete Harteveld, but you can also see my agents. I have seven agents that operate on my behalf, and the team can establish a normal baseline of behavior for each of these agents. If one of my agents behaves abnormally, it triggers a detection, which then sends an alert." This level of monitoring and analysis is a powerful tool in managing insider threats, whether human or AI-based.
Opportunities for Channel Partners
Exabeam recognizes the potential for their channel partners to capitalize on this emerging field. By offering agent behavioral analytics as a value-added service, partners can package it with the agents they build for customers, creating a unique and highly valuable offering. Harteveld mentions a partner in Japan that is already doing this, building Microsoft Copilot agents and delivering a full capability to understand their behavior.
However, Harteveld also acknowledges that educating partners about agentic AI is a challenge. Only a small percentage of partners have the foresight to anticipate customer needs and build capabilities in this space. The majority tend to react to customer demands, which can limit their ability to offer innovative solutions.
The Challenges of Speed and Data
While agentic AI presents exciting opportunities, it also brings significant challenges, particularly in terms of speed and data. Harteveld explains that the amount of data generated by agents can be immense, and managing this data efficiently and cost-effectively is a major concern. Additionally, the speed at which agents operate places incredible pressure on security capabilities.
Exabeam is addressing these challenges by extending their detection capabilities closer to where agents exist, allowing for more efficient behavioral analytics. They're also building relationships with pipeline providers and adopting strategies to identify and manage the necessary data, leaving the rest in data lakes or other cost-effective storage solutions.
The Future of AI and Security
Harteveld is excited about Exabeam's role in supporting the proliferation of AI while ensuring necessary security measures. He believes that, much like with human employees, organizations should not lock down AI agents but rather monitor them for potential insider threats. This balanced approach allows companies to take advantage of AI's benefits while mitigating potential risks.
In conclusion, Exabeam's strategy towards agentic AI is a prime example of how forward-thinking companies can navigate emerging technologies. By embracing AI while also prioritizing security, they're not only staying relevant but also offering unique value to their customers and partners. As AI continues to evolve, it will be interesting to see how companies like Exabeam continue to adapt and innovate.