Forward AI – Security Vulnerability Management with Forward Networks
The presentation highlighted a security vulnerability management use case that demonstrated a unique way to access Forward AI via Slack. In a common scenario, a CISO asked via Slack which devices were affected by a specific CVE. Forward AI, acting as an agent within the Slack channel, was prompted to investigate. It gathered vulnerability details and responded directly in Slack, identifying affected devices and providing a link to further evidence and details within the Forward Networks platform. The speaker addressed security concerns about Slack integration, emphasizing that specific integrations and channel restrictions are in place to ensure secure communication.
Beyond this demonstration, Forward AI aims to lower the barrier to network understanding by enabling users to ask questions in plain English rather than requiring them to learn complex, network-specific languages. It supercharges efficiency through an agentic architecture that can plan and execute dynamic, multi-step workflows, coordinating actions across multiple systems like ServiceNow and Slack. This capability instantly up-levels teams, enabling non-experts to solve complex network problems using state-of-the-art AI. The foundation of Forward AI’s effectiveness lies in combining the broad general capabilities of modern large language models with the deep, specific knowledge derived from Forward Networks’ mathematically accurate digital twin, which overcomes the challenge of applying AI directly to overwhelmingly complex raw network data.
Looking ahead, Forward AI, built on this robust digital twin, is designed to evolve into an agency system that can interact with other external systems via a general mechanism called MCP, fostering a thriving ecosystem of interacting agents. The core philosophy underpinning these agentic operations is trust, especially given the critical nature of network infrastructure. While striving for speed and efficiency, the current approach for Forward AI is to guide operators and provide deep insights, avoiding direct network changes to ensure safety and prevent unintended disruptions. The digital twin remains the essential foundation for enabling these trusted agentic operations, delivering measurable ROI.
Presented by Nikhil Handigol, Chief AI Officer, Forward Networks. Recorded live at AI Infrastructure Field Day in Santa Clara on January 29th, 2026. Watch the entire presentation at https://techfieldday.com/appearance/forward-networks-presents-at-ai-infrastructure-field-day/ or visit https://techfieldday.com/event/aiifd4/ or https://www.forwardnetworks.com/ for more information.
Transcript
Uh, yeah. So this one, uh, is related to vulnerability management. Again, a security use case.
And this time I wanna show you a very different way of accessing forward ai. So far, we, uh, we looked at, uh, the UI of, uh, of our platform, like this conversational interface. Uh, but let's, uh, let's go to Slack.
I have a Slack channel for my team, and the CISO just, uh, sent a message, said, Hey, I saw this crazy new CV come out, uh, this particular CVE number. Are there any devices affected by it? Like, again, like a very common scenario that you encounter.
Like there's a conversation, maybe they got, they got an alert or email, or they read about this somewhere. Now in response to this, I can, I can go ahead and say, uh, I can prompt forward and ask it to investigate, and I hit enter this kicks forward, ai, right? As a result of it, and, and gives it all of the conversational context that we've had so far before our AI kicks in.
The agent kicks in and starts doing its work. It's, uh, also given me a link here that I can follow and actually see its work happening live. I can follow the link to see what the agent is doing.
Uh, it's getting some vulnerability details for the CBE that was mentioned. Uh, this is the context that it had the original message about this, Hey, I saw this crazy CBE, and then it's, uh, it's getting all of this, uh, uh, results and it's gonna produce the result and, and come back with a response directly in Slack. It's gonna respond in Slack, It's gonna come back and, and respond here in Slack.
Mm-hmm. Based on, based on, based on the work that it did. Well, it's, uh, it's taking some time, but I want to show you maybe, uh, something as an example of what it did.
Uh, I had tried this, uh, a while ago. Uh, it's in the interest of time, this is what it produces. It comes back with a response directly in Slack on the CV affects one device.
Like that's the device that it affects. Like it's giving me like direct answer in Slack, but also with the link, the link that I can follow to go get more details, see the evidence, see the work that it did, everything. Mm-hmm.
Okay. It actually did complete here this time. And, uh, when, when I go back here, like, yeah, this is, this is a Slack message that it produced.
Uh, so this CV affects Cisco a SA and, and there are two devices that are vulnerable, and it's giving me all the details about, about the vulnerable devices. I can click on this link again. So I mean mm-hmm.
Critical question might be a security, you know, are you, are you authorized? Is a Slack user authorized to go out and access, you know, the configuration details to understand if it's vulnerable or not? You know, are you providing that information to some hacker out there that go in and actually hit it or something like that?
You know, I saw the, a security constraint here, is it? Yeah. So how is that mm-hmm.
Handled? Yeah. So this is, this is not accessing Slack nearly.
There is a, there is a particular integration that you have to enable between forward and Slack, and that is what authorizes the communication to go back and forth At a Slack channel basis. Or If you can restrict it to just a particular Slack channel, you can control it within Slack on where the access is, right? Yeah, definitely put that in a secure Slack channel.
A secure Slack. Yes. Don't put that in an open channel.
Okay. So I want to quickly recap what we saw today. Such a thing.
We saw four use cases. Uh, we did some troubleshooting. Uh, we saw how we can slash MT mttr by resolving customer impacting, uh, issues in seconds and not hours or days.
Uh, we did some proactive security, uh, uh, security work here. Uh, we saw how we can catch vulnerabilities proactively, uh, given a cv, like find out where it is or mitigate risk by blocking access to the internet, prevent command control with, uh, you know, uh, with that, uh, with that workflow. And we also saw how compliance can be sped up and automated by and, and accelerate audits, uh, in the process.
Uh, why does it matter? Why does forward AI matter? What, what we have accomplished with forward ai, it, it lowers barrier to understanding, it's a conversational interface.
So you don't have, as a user, you don't have to learn an interface and, and speak, speak the network's language. The network speaks your language. You can ask questions in plain English and get a response back in the same language.
It supercharges efficiency. It's an agentic architecture that can plan and execute dynamic multi-step workflows. And the agent system itself extends its reach beyond just the forward platform.
It can, it can coordinate actions across multiple systems. We saw two examples today, uh, ServiceNow and Slack integration, and third, IT instantly Uplevels team. We saw this example with that audit item, right?
Uh, I was not an expert in all of the vendors in Texas, but I was able to harness the power of state of the art AI to solve my problem in my network. I want to, uh, zoom out a little bit and talk a little bit about the technology. There's a, there's a, there's a perception in some circles that you can basically pull a bunch of data like raw configuration and state and slap AI on top and expect magic to happen, right?
That simply won't work because that in, in, especially in a complex environment like a network, uh, especially large scale networks, that simply can't work because that would be leaving too much for AI to figure out. Just to give you an example of the sheer complexity we are dealing with in one of our customer environments, we computed how many different path traffic could take through the network, and that number was more than the number of grains of sand on earth. Hmm.
Can you imagine AI being able to rock and comb through that level of data, that scale, and that complexity of data? Uh, ai uh, technology as it stands today is not simply not capable. It needs access to more refined and computed data.
We are not doing that. What makes our AI work is the foundation. It's this mathematically accurate digital twin that provides a comprehensive hierarchical data stack, and it's an agent architecture.
So it allows forward AI to extend beyond just the digital platform and reach out to adjacent systems like we saw with Slack and ServiceNow integration today, forward ai at a high level, what we have been able to achieve at a technological level is combining the best properties of modern large language models and the network digital chain. If you look at modern LLMs, they're trained on pretty much all of world's data. So they have very broad general capabilities, very broad general knowledge.
What the digital twin has is very deep and specific knowledge about your network. Mm-hmm. And we've been able to combine those two properties, and that's what makes forward AI works.
So today we saw forward ai, uh, it's an agentic system that's built on the foundation of a mathematically accurate digital twin. As forward AI evolves, uh, we will enable it to interact with other external systems. Uh, a general mechanism to enable that would be via MCP.
Mm-hmm. If you have an external system that is accessible via MCP forward, yeah, I will be able to connect to that system and bring it into its fold as it works through. Uh, and when forward AI goes GA in the next three months, uh, it'll also come with an MCP server so that, uh, it'll expose all of its underlying functionality to external agents, whether these agents are created by our customers or even third party agent builders.
And eventually we, uh, expect, uh, these agents all to interact with each other. Uh, so, and that's, that's the kind of thriving agent ecosystem that we envision that we want to enable, all built on the trusted foundation of a digital twin. But here's how we are thinking about agent take operations.
Our goal is to deliver real measurable ROI with agent take operations and not be limited to just hyper demos. And our strong conviction is that the right way to do it, the right foundation to build it on is a network digital twin. That's the essential foundation for trusted agent corporations.
Mm-hmm. And, and we plan to achieve this goal, uh, by both building our own agents, as you saw with forward ai, but we also want to enable third parties, our customers and other agent providers to build on top of this foundation of a trusted digital twin. Do you have a model or, uh, a strategy or philosophy for how you approach that cliff of executing functions versus guiding operators to execute functions?
Yeah, I think, I think the, the important philosophy here is trust. It all needs to come from trust. We, uh, and we are talking about critical infrastructure here mm-hmm.
Networks and, and, and, uh, the last thing we want to do is break the network. We don't want humans to break the network. We, so we want, we want to have both speed mm-hmm.
As well as safety. We want to have trusted, safe agent corporations and we want to execute with speed. Uh, so like, I think like that's, that's where like it comes down to.
So what you saw today, uh, everything that you saw today, the agent was not making changes to the network. Right. And that was a very intentional choice.
Yeah. So very intentional choice. We want to speed up all the things that are safe and easy to, like in a safe environment, and that can, uh, be sped up based on the behavioral knowledge that is present in the digital twin.
And that's a philosophy that, uh, I think everyone in the industry needs to, uh, needs to have if we want to really see, see agent operations real, uh, deliver real value in, in the networks. Okay. To, uh, wrap it up today, uh, we announced forward ai, it's a conversational agent system to simplify operations.
Mm-hmm. And the digital twin platform that we have been building for the last 12 plus years is the mathematically accurate foundation that enables both forward AI as well as general trusted corporations.