Recursive Security Brings Cisco and Splunk Together
Recursive Security Moves Cyber Up the Stack
Recursive security is becoming a larger part of the Cisco and Splunk conversation as AI changes how defenders build, test and improve security systems. In this Techstrong TV interview from SplunkConf 2026, Alan Shimel talks with Sunil Potti about bringing Cisco security and Splunk together around a shared mission.
Potti describes a shift in which cybersecurity is no longer just infrastructure plumbing. AI is pushing security higher in the technology stack. That creates an opportunity to connect security, observability, data and automation in ways that help organizations respond at machine speed.
Cisco and Splunk Converge Around AI
The discussion explores why Cisco is combining its security portfolio with Splunk’s observability and data strengths. Splunk already collects large amounts of operational and security telemetry. Cisco brings security controls, network context and a broad enterprise customer base.
That combination matters because AI systems need trustworthy data. Security teams also need evidence about what happened, why it happened and whether a response actually worked. Recursive security depends on that loop. Offensive agents test defenses. Defensive agents investigate and respond. Observability shows whether the system improved.
Self-Improving Cybersecurity Requires Better Data
Potti argues that cybersecurity products can no longer be built, tested and shipped as static systems. Attackers adapt quickly. AI can compress that cycle even further. Defenders need their own cycle of continuous testing, response, learning and improvement.
That is where Splunk can play a central role. Logs, traces and operational data can help customers understand whether security services are working in their environment. With the right data layer, teams can turn security operations into a flywheel that keeps learning from each test and response.
People Still Define the Mission
The interview also returns to leadership, people and culture. Potti says the work depends on building teams aligned around a higher ambition. Technology can accelerate the mission, but people still decide how the organization works and what problems matter most.
For technology leaders, the takeaway is clear. Recursive security is not just another AI feature. It is a model for continuously improving security through connected data, offensive testing, defensive response and human-led governance across Cisco and Splunk environments.
Transcript
Hey, everyone. Well, we're not live, but we are sort of live here at Splunk Conf '26. We're right outside the exhibit hall.
It's a little bit hectic, and hopefully you hear us well. I want to introduce you to Sunil Potti. Sunil, welcome first of all to Techstrong TV.
Thank you. Thank you, Alan. You know what?
I'm going to ask you to tell people your title. So, my title. Here, it's- It's just another title ...
Splunk. It's just another title. Just another title.
It's what I do that matters, probably. All right. Well, let's go there.
Should we get into that? Yeah. Well, before you tell me what you do now, tell us what you've done, how'd you get here.
So by a lot of luck and bribery. But, no. But in the past, so my journey began like many Indian immigrants here.
As an engineer in the database world, started my first startup doing the dotcom bust, then I actually was at Cisco, believe it or not, for three years, 20 years ago. Really? Yeah.
And then spent time at F5, like in the infrastructure game. With Netscaler. Sure.
And then with Nutanix from the beginning to the end, almost. Sure. When it became a big global brand.
And then I joined Google about seven years ago. I spent time leading their security portfolio at Google. Ah, okay.
And even though I didn't have a security background. No? So I didn't do too much more damage there.
And then I actually retired last year, and then was trying to spend a lot of time at my daughter's soccer games. Good for you. And there's a lot of action going on now, what can I say?
And then with my friend Jeetu, and a whole bunch of friends here at Cisco, when the opportunity came up to actually help them consolidate all of the Cisco security portfolio with the Splunk portfolio, it sounded like a great opportunity. So just when you thought you were out, they pulled you back in. Or at least, I pulled myself back in.
Absolutely. Why not? No, I have a similar background.
About 25-plus years in security, venture backs, and stuff. You've forgotten more about security than I've learned. No, because like you, look, I went to law school.
Oh. I fell into security- I got you ... because I love computers.
But I've learned my security lessons over the years. But I want to talk about this moment in time. I want people to appreciate where you came from to get where you are.
And I don't remember your exact specific title, but as you mentioned, you are charged with bringing Splunk, the observability business, the Cisco security business, together into one unit. Yep. And I think it's something they've spoken about and thought about, but nothing like now where there's such an impetus to get this done now because of the historic times.
Of course. We're here. You recognize it.
It brought you out of retirement. What do you think the opportunity is here? Yeah.
So obviously there was some calculus behind me getting back into the game. Mm-hmm. And I think the fundamental thing, Alan, is I feel like we're on the cusp of where cyber, in my humble opinion, can become as big as the frontier model, as an industry.
Here's why. So if you think about obviously where things have been in the last three years with AI, I think it's clearly obvious to the folks that there's real value in AI beyond just a cycle. Coding agents is a good example.
Everything that we've seen, right? But I think we are just embarking on the second act of it, which is about where can AI be democratized, just like internet got democratized. Yes.
Just like mobile got democratized. For it to be democratized, it needs to come in the form of open source models, needs to come in the form of lower cost. Yeah.
Sovereignty, various things, right? But with that choice comes a trade-off of control. And all the things that protected Philanthropic or DeepMind now becomes an obligation to the customer.
Yeah. And so it's a great opportunity for a platform company like Cisco, with Splunk, to emerge, to be that AI safety and security. I love it.
Right. So. " Right after my book.
Really? Right before mine. Okay.
Liberance. We are Hebrews, yeah. So the premise is we look at railroads, electricity, phone systems, fiber optics, the dotcom that you and I both kind of lived through, and it probably helped form our- Yeah, of course ...
view of the world. Something happened to this Jevons paradox, right? The more you use it, the more it gets used kind of thing.
But there's another thing. The people who do these models, the real value moves up the stack. Mm.
And to me, that's the opportunity you're looking at here at Cisco. And this whole security business. For the first time in our careers, cybersecurity's moving up the stack.
It's no longer at that plumbing level almost. Of course. It's front and center.
How do you capitalize on that, though? Yeah, I think that beyond a certain elevation in terms of the focus of cybersecurity, I think there's also another trend that's actually emerging in cyber, in my opinion. Which is, in the past, you would build a security product.
Mm-hmm. You would test it with certain considerations, ship it out. Yeah.
Somebody in some nation state wakes up one day and actively tries to break into it. Whether it be a firewall, whether it be a zero trust environment, whatever it is, right? I think in the world of AI, that cycle happens instantaneously.
Continuously as well. Right? Yeah.
Yeah. And so the only way to build a cybersecurity product going forward is to build that cycle yourself. Excellent.
And so therefore, I feel like there's a new architecture of self-improving cyber that needs to emerge, just like self-improving models. Models themselves, right? Yeah.
Exactly. Recursive, I think is the term. Exactly.
So there's recursive security, in my humble opinion- I love it ... is the next phase of cyber. And that's what we are going to do.
Recursive security. This is where you heard it first. I'm going to run with that.
You should. Recursive security. So how does that manifest itself here?
So I feel like in the case of, take Splunk. Splunk has been one of the bastions of, I just call it blue teamers, the defense. Mm-hmm.
And it's in our best interest to also keep the best offense agents, because that's the way that our defense agents can actually be continuously and instantaneous. Iron on iron, as they say, right? That's it.
And the same thing happens on the firewall side. Our detections and responses on the firewall groups. Somebody has to be constantly getting through them for the firewall policies to be better.
So the same thing can be applied at all of our security services. And by the way, the benefit is for our customer, most of the logs, most of the data points are captured in a system like Splunk- Yes ... already.
That's what we've been there for, tech. And so therefore, for a customer to know that any security services are working well in their environment, they have to still host train our stuff with their data. And Splunk exists there, so if you can make it easy for them to extract data- No brainer ...
then that cycle works on this. Becomes a flywheel. So the recursiveness happens not just in our development life cycle, it happens at a customer premise as well, all day long.
I feel obligated to ask you, the talk this week, of course, is around this whole AI and humanity issue. Basic. Yeah.
What do you think? I feel like, look, every week there's going to be a new topic. Mm-hmm.
That's this week's topic. That's it. There's going to be a new topic next week.
News cycles, they come and go. Yeah, that's all it is. That's all it is.
Yeah, that's all it is. Excellent. Last question.
Yes, sir. You've made it sound very simple. I've managed organizations nothing this size.
Of course. It's not easy bringing all of this together. It's like eating an elephant one spoonful at a time.
But what are the spoons here? What's the path? Yeah, I think one of the biggest levers is people, as you know.
Mm-hmm. So a lot of this comes down to people. Yeah.
And we just have to have a great set of people. Many folks already are there in the right positions. Some have to be added into the team.
So I feel that's one of the things that led me to also take this role was that inside knowledge of the people and their ambitions to be aligned on this mission that we are calling recursive security. Because that is a higher ambition. And if you can do it, and I always use the word clean ambition, is to have that higher bar, but to do it with people around you that you enjoy doing that with.
Amazing. That's it, yeah. Hey, man.
Good luck. Great seeing you. It's great meeting you.
Thanks for the opportunity. I look forward to speaking with you more. Of course.
We will talk more. Now that you've got a task on. Yeah.
We're at work. Okay. Awesome.
We are here live at Splunk Conf, although you're not watching this live. We'll have more on Techstrong TV. Stay tuned.