Cisco Security Targets AI-Scale Vulnerability Risk | Cisco Live 2026
Alan Shimel talks with Peter Bailey of Cisco at Cisco Live about why security can no longer be treated as a silo as enterprises build AI-era infrastructure. Bailey explains how Cisco is bringing security controls, Splunk data, Cloud Control and AI-driven analysis together to reduce tool sprawl, improve hygiene and help customers remediate vulnerabilities faster. The conversation also explores AI-assisted vulnerability discovery, patching at scale, shielding legacy systems, software quality and the need for industry-wide urgency as attackers gain access to more powerful AI tools.
Transcript
Hey everyone. Welcome back here to Techstrong TV. We are still at Cisco Live, having a great time, great conference, lot of news going on.
You can follow it on Techstrong TV or any of our Techstrong sites. But let me introduce you to our next guest. He's a security industry veteran who I haven't met before, so I'm excited to hear.
Let me introduce you to Peter Bailey. Peter, welcome. Thank you so much.
Thanks for having me. So, you came in here with the tag of the security industry veteran. Yeah.
That's like a nice way of saying you're getting older. I must not be that good at my job if we haven't met yet though, so I don't know. Oh, no, I keep a low profile.
But give people a sense, what have you been doing in the security industry? Yeah. So I've been in software most of my career on the, I won't say how many years, but it's getting up there.
It's a lot. But the last 10 years or so really focused on cybersecurity. And so before I joined Cisco, I joined Cisco about a year ago.
Okay. Before that I was with Google Cloud, and that was vis-a-vis the acquisition of Mandiant. And so I was with Mandiant.
Oh, sure. I was the chief operating officer of FireEye, that then became Mandiant. Before Mandiant.
Yep. Absolutely. And then Google Cloud, and now here.
And so, I'm now the GM for the security business at Cisco. And so I'm responsible for all the product and engineering for our security portfolio. And obviously that in this day and age means everything from AI to firewalls to identity.
And then we are closely partnered with Splunk, which is still sort of a separate entity, but we do a lot of work together with Splunk as well. Sure. Yeah.
It's interesting because when the Splunk acquisition first happened, I thought Splunk is security, because I've always thought of Splunk as security. Sure. But then they got the observability thing going on, and I knew that security had to go somewhere.
Yep. So it sounds like at least someone was smart enough to put that together, huh? Yeah, for sure.
So, they still own the security stuff, but what you're seeing us do is integrate products- Absolutely ... and capabilities and start drawing unified outcomes with customers. And that's really what customers want to see is that, can you actually just make this easy for me so I can help get to some outcomes, including a bunch of these different pieces that we have?
Absolutely. I'll tell you, Peter, I'm in security about 20, 25 years. I remember 25 years ago being amazed when someone told me that Cisco, by revenue, was actually the biggest security vendor in the world.
Mm-hmm. This is the days of the firewall. Yeah.
So no surprise in hindsight. For sure. But I think people out here would still be surprised to know that by revenue, Cisco probably still is, if not the biggest, top three certainly by revenue.
Yeah. We're definitely top three. It's a little less than 10 billion of revenue.
My portfolio's roughly four billion, and then Splunk's a little over four billion, four and a half or so. So it's a big business, right? It is.
We have north of 100,000 customers and obviously a lot of major enterprises and government and, so it is a big business, and it's a big portfolio. But it's also one that, if you've seen some of the announcements we've had this week, with cloud control, which is one of our big announcements- Yeah ... around our platform approach.
We are finally bringing the portfolio together, integrate these integrated outcomes and platform based outcomes. And that's really all about reducing the operational toil of managing lots of controls, but also creating a unified data plane. And if you have a unified data plane, you can start doing analysis a lot more easily.
Of course. And start asking different questions and of course also using AI to do that as well. I wrote an article on this this morning that really the theme for me from Cisco Live is that Cisco's creating a unified AI infrastructure play.
Yes. Right? Yes.
Built on the Silicon One CPU's hardware. Yeah. Layering on cloud control and all of that brings.
The other message I think people need to hear is that security is no longer, you can't silo it anymore. 100%. " 100%.
And yeah, we got a little Splunk here. Security now, east to west is, I guess what you'd call it, right? Yeah.
Is involved in that whole spectrum, and I think the cloud control piece is a great example of that. It's there. Yes, 100%.
One of the interesting things about cloud control is you launch with 50 something vendors, many of whom, some are observability, some are security. Identity, right? Identity is a big piece of it.
Sure. Yeah. Sure.
They all kind of roll in together. Yeah. And again, part of this, I think the way we've got to start thinking about security, about cyber, some people call it cyber.
Yeah. Going forward is, it runs that whole gamut. You can't just pigeonhole it anymore.
Yeah. And maybe another way to say it is we have to think in open platform terms. Yep.
It's too big of a problem set. Networks are too homogeneous. There's just tons of different infrastructure in there, and so there's never a perfect single vendor environment you're going to get into.
And so, we are thinking platform first, and by definition that means open. And you kind of said it before as well, is we're also thinking API first because we ultimately want to allow this to be like an agentic harness, if you will- Sure ... for managing infrastructure and security.
And that's really one of the other big announcements here is integrating in OpenAI and Codex, so you can build apps on the platform. And ultimately allowing our customers to build whatever they need to build to run their infrastructure and security and have the ability to do that directly on the platform. And so that's super exciting.
It's different. It's game changing. Yeah.
Just a question between you and I. Yeah. I was a little surprised to hear about the Codex being...
Look, everyone you talk to loves the other guy. I won't mention them. Sure.
I'm an OpenAI user myself, but wouldn't Cisco... You don't have to use that. You could use other tools.
So, we've started with OpenAI and Codex, but certainly we're going to be open and leverage and partner with other parties. You have to be, today. But we were super excited to engage with OpenAI because they are absolutely a leader in this space.
Yeah. They are excited to do this with us. We're creating a new capability and category with what we're doing.
And so, you start with a great partner, and then you can build out from there. Mm-hmm. And so I think we're just at the starting line of this, right?
Yeah. This is an innovation that we're just coming out with, and there's so much we can do with it, I think. And we're also excited to see what our customers do with it.
Yeah. And so then, yeah, but again, we have to think about an open approach, and our customers might have their own models themselves or vendors they want to work with, and ultimately we have to be able to incorporate that as well. Agreed.
Look, you can't have a discussion around security today, I guess, without discussing Mythos. And it's not just Mythos. OpenAI has their security scanners, too.
Sure. But Glasswing and this whole vulnerability apocalypse and everything that we're hearing about- Yeah ... from where you sit, you have a better perch than a lot of other people.
Sure. What do you see? Is it really an apocalyptic event, or hey, is it time now we've got to do something different?
So, I think if you go back a couple of years, we had research papers that came out predicting that AI would get good enough at some point that it would be able to basically behave as this very advanced attacker. Mm-hmm. Do the most sophisticated attacks.
And we knew that when it went from being a human AI doing it, that the cost of doing that would go down dramatically, and would open up the floodgates for the common cyber criminal to be able to do some very advanced techniques. And that is, in essence, what's happening. And we didn't know when it would happen or how soon it would happen, but what I would say is that Mythos announces the beginning of that era, where we are going to have much more sophisticated attacks that we're facing at much higher prevalence, and obviously machine speed.
And the reality is that our controls and our operational processes are not prepared for that. And on the front lines of that is the infrastructure and the vulnerabilities that humans could not find previously, and we've been able to find with these models. And then if you go inside the infrastructure, all the different security controls, to your point, it's a patchwork quilt.
You've got these vertical security controls that don't talk to each other. There's gaps in between them. And so you're going to need to get total visibility.
You need to have enforcement points everywhere, sensors everywhere, and enforcement points everywhere, and a holistic view of an environment that includes lots of other infrastructure and vendors in it. And so what I would say is this is a wake-up call for hygiene, security hygiene. We've all never gotten to full hygiene.
Two, that we have to build better software, and I think these tools can build better software. We're also using it to rewrite software, too, and refactor and modernize it. And so the scary part, and the part that I don't want to sound like a doomsday at all, but when this does get in the hands of threat actors- Bar the gate, bar the door ...
companies, state and local government, you can imagine a lot of these organizations that aren't strong security organizations. It's going to be wide open. These are very porous environments, and a lot of bad stuff can happen.
And so we are, I think rightly so, ringing the alarm bell because we have to hustle to close off these vulnerabilities and try to increase hygiene and solve these issues. I agree with you. Yeah.
A lot of my friends in cyber, so Jen Easter, for instance, tomorrow- Yeah, she's great. She's amazing ... Jen says this is a good thing because we're finally going to- Yeah ...
get people to get serious and develop secure software. Yeah. I'm always afraid this is a case where the operation was a success, but the patient died on the table.
Because we got to get to there. Yeah. And getting to there is going to be bumpy.
Yeah. Those who know, it's hard not to think the next year or two are going to be pretty tough. Yeah.
And maybe the government's got to get involved in some capacity. Maybe more funding needs to be put out there to help companies invest to solve these issues. And it's going to require a lot of new infrastructure, but also different ways to look at security, and I think the hygiene thing is the thing that we're probably going to be most focused on.
And again, that's people and process and technology. Technology. It's all, it's everything, right?
The same three, the triumvirate. That's right. It's cool.
That's right. Now, to me, and this is what I found heartening listening to the keynotes yesterday and today. This is a question of scale.
Yes. If we had unlimited human vulnerability researchers, we would find these vulnerabilities probably, but we didn't have unlimited- Yep ... vulnerability research.
You have, in essence, unlimited scanning now. We don't have unlimited remediation. And not just patching, but remediation, mitigation.
Totally. And that's where I think the scramble is. Until we get to the other side of this, it's kind of like crossing the Red Sea here.
Until we get to the other side of the Red Sea, where we're developing better software- Yes ... we have got to be able to scale. Yeah.
And that's what I really love about cloud control and about the Cisco messaging yesterday. Yeah. It is about helping that scale.
100%. You got to do this at AI scale. I think we've recognized that the next six months is going to be dominated, maybe more, by the patching of vulnerabilities, and then ultimately the shielding of things you can't patch through segmentation or actually building shields.
And so we are 100% focused on that window. And products are being developed in the background, but frankly, the products come later, as you said. Yeah.
We got to solve this, and this is primarily operationalization around some things we know how to do, and some new technology like Live Protect that'll protect systems going forward, or using Tetragon agents and shielding to protect legacy applications and what have you. But this is all about that operationalization, and we've got to help our customers scale to that moment. Obviously, we're going to harden everything we've got.
We're well down that path. Yeah. And so we're going to bring very hardened solutions to the market, and then we got to help our customers actually operationalize that.
Peter, I got a tough question for you, though. Yeah. Let's do it.
Look, you probably talk to as many CISOs, enterprise leaders as any security company in the industry. Are they taking this Mythos Glasswing stuff seriously? " Henny penny kind of, sky's falling.
Yeah. I think everyone I talk to is taking this seriously. And, in fact, even to kind of Jen Easterly's point, using it as a moment to go back to the board and say, "See?
" And so, I think everyone we talk to, it's more about, "Okay, got it. How do we operationalize? " Yeah.
"That's going to be very substantial. " And that's things like live protect, the things like that we're working on to help. Yeah.
Right? And then we've also open sourced a harness specifically that we built around these models to help find these vulnerabilities. We want to put that in people's hands, too, so they can also do this work themselves.
So that's an interesting piece, right? Because I've spoken to a lot of vendors who said, "We've applied to Glasswing. " Yes.
Yes. " So they just opened it up to another 100 plus companies. Oh, yeah.
Yep. Like 160 now companies. Obviously, OpenAI's got a much larger program, right?
bigger one. Yeah. And so it is now happening.
I think the thing that I'm worried about is, let's say you give this to an enterprise customer, and they're like, "Okay, let's just start pointing it at our internal infrastructure or our vendors and all of that," and it's going to create a lot of noise, right? And so, one of maybe the flip side of this is does that noise get in the way of getting hyper-focused on- It's signal to noise ... these specific things we got to address.
Yeah. Because the vendors are going to do their thing. They have to, and they're using these models to do that.
Internally, it's really about is my architecture somehow flawed? Is my configuration flawed? Is the reachability of this legacy application, and does that legacy of proprietary application then have connection points to my payroll system or things like that, right?
And so mapping those things is going to be really, really important. And I hope people keep their eye on that ball. As I said, I've been in security a long time.
The problem is, I remember going to Citi when it was Citigroup. It wasn't Citi. I remember.
They had three global CIOs. There was a guy named Peter Fisher. I don't know if you ever met Peter.
He's retired. But I remember, I was a security vendor then. We had a vulnerability product.
" Yeah. Sure. Obviously, that was 15 years ago.
The world's changed. But there's still too many companies that are slow on the draw when it comes to remediation, patching, mitigation. Yep.
And those, I think, are going to be the casualties of this. And that's where you really, as a company, you need to reach out to your partners. Yep.
Right? All of our largest partners have very robust ways to automate doing patching that's multi-vendor, not Cisco specific. And there are partners that can help.
Cisco has capabilities. We can help for the things we are able to impact. And so, like all things cyber, this has got to be a team effort, a community effort- Yep ...
where we're making these services available. And again, I don't know anything you don't know, but I got to believe at some point the government may say, "Here's funding. " Getting CISA more in the game because that operationalization is going to become the thing.
And to your point of we're not at that scale, a lot of companies can't do this, so we're going to have to provide those resources somehow. Got to lift them up. You got to lift them up.
Yeah. Unfortunately, I don't want to get into politics, but this CISA is not Jen Easterly or Chris's CISA. Yeah.
Listen, we've shown some family in this administration, in Sean Carancro and others. Mm-hmm. And there's some really good things happening there around policy and whatnot.
I wish there was a bigger alarm bell being rung right now. Yeah. Right.
And there was more things happening on the ground. And I think there's a lot of discussion about that that's happening. I hope so.
But we got to get going. We got to get going. Absolutely.
We got to get going. We got to get going here. Okay, cool.
So I apologize. Yeah. But hey, man- Hey ...
it was a pleasure meeting you. Great to meet you, too. Keep up the great work.
Thank you. Like I said, we're in for a rough ride. Yeah.
Bumpy ride a little bit, but- Not a lot of sleep these days. No, but we'll get to the other side. Okay.
And hopefully, it'll be better. Thanks for having me. Thank you.
Peter Bailey, GM of Cisco Security. You got it. There you go.
You got it. Live here on Techstrong TV. We're going to take a break.
We'll be back with a lot more people.