In a podcast published on October 6, 2026, cybersecurity veteran Kevin Mandia, founder of Mandiant, discussed his return to the field with Arminen, driven by the profound "AI shift change" he believes will redefine security. Having spent 30 years in the industry, Mandia felt compelled to engage with this "tsunami like has never been seen before," stating he didn't want to "sit out the AI shift change." He was particularly impressed by Arminen's founders, David Slater, Travis Lanham, and Evan Pena, recognizing their generational talent and the critical need for their solution.
Arminen leverages frontier AI models for offensive cybersecurity, a service they call Arminen Red. The core idea is that a strong defense requires an equally strong offense to train against, akin to a football team needing a robust practice offense. Arminen aims to be the "all-star team on offense," continuously pushing defenses. Mandia emphasizes the unparalleled scale and speed of AI attacks, noting that "what AI does in a microsecond would take 70 humans." AI excels at finding exploitable risk in structured languages like code, making it highly effective for vulnerability discovery. Mandia warns that open models are already capable, and the main barrier to widespread criminal AI attacks is currently the anonymous availability of GPUs.
Comparing nation-state attacks to AI, Mandia describes a shift from "sniper rounds" (targeted, surreptitious attacks) to "drone swarms" (broader, potentially sloppier but more comprehensive attacks). AI democratizes attack capabilities, allowing less skilled attackers to achieve greater success, which will complicate attribution, blurring the lines between nation-state, human, and AI origins.
Arminen's approach involves "hyperattacks" that use a swarm of agents to map a network, creating a "metadata twin." This allows for continuous, cost-effective polling for changes and targeted attacks on new vulnerabilities. Mandia differentiates this from traditional pen testing, which he views as mere "hygiene" scanning for known issues. Arminen, by contrast, carries out actual exploits to verify risk, achieving remote code execution and finding logic flaws in custom applications. Since January 2026, Arminen has found over 90 zero days at Fortune 500 customer sites, all in production, without source code access. Mandia highlights that their models, post-trained by real red teamers, are now finding zero days autonomously.
Looking ahead, Arminen plans to introduce Arminen Blue, a defensive capability designed to use offensive intelligence to create autonomous, rapid compensating controls. Mandia asserts that human involvement in the detect and respond loop will be too slow in the AI age, necessitating autonomous defense. The future SOC will see significant automation, with prevention, detection, and response increasingly handled by AI, narrowing the window for human intervention.
Mandia acknowledges that enterprises are currently in a "window of exposure," with both attackers and defenders operating with desperation. He notes that the "Mythos moment" accelerated awareness of AI's offensive capabilities. Reflecting on incidents like Hugging Face, he stresses the importance of combining AI expertise with deep security domain knowledge to safely develop and deploy AI models, as security teams often underestimate model capabilities.
In terms of company building, Mandia contrasts Mandiant's self-funded, slower growth with Arminen's need for rapid, venture-backed expansion. The current market demands immediate scale, a robust go-to-market strategy, and continuous innovation. He emphasizes that in this "tsunami" of change, differentiation comes from customer satisfaction and becoming the "best in the world" at what they do.