On-demand session · 31 minutes Recorded live at HRMCon 2026

Looking ahead to 2030: autonomous prevention, human accountability

A future where prevention tunes itself — and accountability still has to be assigned to a person. What to prepare for now.

Matthew looks ahead at autonomous security — and what leaders should prepare for now to keep accountability clear.

Matthew Rosenquist speaking at HRMCon 2026
Matthew RosenquistCybersecurity Insights
Full session · 31 min
Why watch

Prevention is becoming autonomous. Accountability isn’t.

By 2030, more of prevention will tune itself. Someone still has to own the outcome.

Matthew looks ahead at autonomous security — and what leaders should prepare for now to keep accountability clear.

What you'll learn

In 31 minutes, you'll walk away knowing:

How security controls will increasingly tune themselves.

Keeping ownership clear as automation grows.

The decisions today that shape your program in 2030.

Speakers

A strategist on what the next five years hold

Matthew Rosenquist

Matthew Rosenquist

Cybersecurity Insights Follow on LinkedIn
Transcript

Read the full session

Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.

Show transcriptHide transcript

0:12 Right? We already struggle. With the challenges we face today. Right? It's complex, it's hard. doesn't matter what aspect you look at cybersecurity, it's tough. So, why would we even ask? What's out there? What's beyond that horizon? In fact, you should ask, what is beyond the horizon? Okay. Thank you! Thank you! Okay, so we are going to kind of talk about, and we've heard so many great things today from different leaders here about best practices, about challenges, about what they've learned. So we're going to pull some of that together as we take a journey in looking forward. Because it really matters. When we look forward, it gives us an advantage. Because we can start preparing now, instead of being surprised, instead of responding to what happens.

1:12 So, again, my background, you can look up the bio, online. I've been doing this 36 years, and I absolutely love it! I love the chaos, I love the ambiguity, I love dealing with that intelligent adversary. Okay? And that's what we need to start thinking about, and a lot of what we talked today is that adversary will also include AI, and various forms of AI. Right? So, we need to start baking that in, because, let me tell you right now. Right? It only gets harder. The only easy day was yesterday. It's… it's not gonna get any easier. I don't have good news in that space. I've got good news in other spaces. But we'll cover some of that. And at the end, we're gonna talk about what do we need to be thinking about now, and how do we need to start evolving now?

2:10 To get ahead of these risks, and not be just… Bulled over by them. Okay? And we're gonna cover it in a framework that we should all be familiar with. Alright, how many people, technology, people, process. Okay? We all know that. So, we're gonna kind of break it down into those different areas, and I'm gonna cherry-pick. And… help elaborate some of the risks that we're seeing now, and how they're going to evolve in the future. Okay. So, from a technology perspective, we know AI, it's here, it's being adopted rapidly, we know the attackers are using it. Right? To their benefit. So we've got this technology issue we're gonna get into, and from a people perspective, we have to worry about the people who are coding the next generation of product.

3:06 Right? That's on the front end. The technology that's being built today, yeah, they're using AI to do that. We also have to look at… the people that are gonna be victimized, because our attackers are going to use AI to victimize them in new, better, more efficient ways. And on the back end, we have to think about it, all organizations, and the critical infrastructures that we all depend on. They're also… integrating in AI, and there's processes. How do they vet it? How do they secure it? How do they attest to it? There's a lot of things in the processes that also can be undermined, can represent a threat, and can impact us at the end of the day. So, let's tear down a little bit at the technology side. And I want to focus on the mythos effect. Everybody familiar with Mythos? Anthropic's latest model. It was specifically designed to look for vulnerabilities. And as it turns out, it does 3 things really good.

4:14 One, it finds vulnerabilities in software, operating systems, firmware, and hardware. Does it really well, does it really fast? The second thing it does, which is kind of magical. Is it can create exploits for those vulnerabilities that it finds. Okay, that's… It's a lot harder than actually just finding the vulnerability. And the third thing is it can chain together vulnerabilities. So when you get a low or a moderate, you can't push that off, because mythos, and it's not just mythos, right? It's all the frontier models. They're really good at chaining together even low-level vulnerabilities to create something much greater. Alright? So… The result of all of this… Is the lowered confidence in the software, firmware, products, devices, services that we use And this little thing called patching, maybe some of you have heard it, Right? That… fundamentally breaks… It's already starting to break.

5:30 Alright, everybody familiar with Microsoft Patch Tuesday? It's our favorite second Tuesday of the month! For the last 3 cycles, Microsoft has put increasingly num- higher numbers of vulnerabilities that it's patching. This last Tuesday, over 600 vulnerabilities, and it's just going up. Okay? So, let's look at that. Oop. Let's look at that from a kind of process perspective. Alright? Now, I want you to put yourself in the mindset of your organization that has to deal with some of these vulnerabilities. Okay. So you have software, you have a product, you have a service, whatever it is. When you have to manage these vulnerabilities. First off, you have to discover the vulnerability yourself. And hopefully, it's an ethical cybersecurity researcher, or it's somebody from your team.

6:33 Right? If it's the bad guy, you're not gonna find out about it until your business partner says we were hacked because your software had a vulnerability. Right, that's bad. But let's just say, for the sake of argument, it's someone on your team. But they have to figure that out. Is there a vulnerability? And then they have to validate it. Is it a real vulnerability? Okay, let's grade it. Is it low, moderate, high, critical? There's lots of debate. That entire process. can take months, and in some cases, Microsoft, years to actually discover the vulnerability, grade it, and then start developing a patch. Now, here's where the problem comes in, because the people that know the code the best Those are your developers. You need their expertise. But… They're not just hanging around. You have them working on the next generation product. So you have to rip them away.

7:31 And go, guess what? We need you to work on the software you already finished. There's nothing a software developer hates worse. then finally coding something, and it works. They just step back. I don't want to touch it. It works! I'm moving on to the next thing. So you're gonna pull them back to their chagrin. Now they have to develop a patch. But we're not done. They then have to hand it off, and that patch has to be tested. Has to be tested on the current. product? But you know what? All your customers don't use the current product. You have to retro-test it to all the old versions your customers are using, to make sure it closes the patches on those, too. And you're still not done. Because remember that next generation product you have? you have to go validate that it's not gonna undermine that as well. Okay, so we're done with testing, and that can take weeks.

8:29 Depending on how many variants out there. Now it's time for rollout. And you could just hit the big red button and push it to everybody. But what if there's a flaw? Right? We've seen this. Microsoft, we've seen it with CrowdStrike, we've seen it with McAfee and so forth. You push a bad update! You may get a blue screen of death. You may fry components. You may end of life a device. So you have to rule it out slowly. Fair enough? Okay, so the chart you're seeing here is this whole life cycle that you have to do. And it typically takes… A long time, depending. So long, in fact, many organizations, if a vulnerability is low or moderate, they'll put it off and say, you know what, we'll just bundle all those together, and once every 6 months, or once a year, we'll address those.

9:24 And we'll only focus on the criticals and highs. Okay, this is where the window of opportunity of the attackers now using AI comes in. Because mythos, as we said, is REALLY good. And what I mean by really good? I mean an order of magnitude. better. Faster. More accurate. At identifying vulnerabilities, and even more so in being able to create the exploits. So, AI tooling… by the adversaries. Can do it in much shorter periods of time. And the whole idea with Microsoft Patch Tuesday, by the way, once a month, Microsoft figured this out years ago. As long as they get the patch out to their customers. before the attackers can exploit it and cause victimization, they're good, and they'll stay on that cycle. But they have to make sure they can get that patch out.

10:31 The reality is, it's flip-flopped. If you go out, and it's a great site to go out and take a look at, it's Zero Day, ZeroDayClock.com. I pulled this a few days ago. When we look at how long it takes for exploited vulnerabilities Right? For the attackers to come in and take advantage and harm people. we can see that, let's say 2018, right? It took about two and a half years. Those are the good old days, by the way, right? When we start getting into 2021, Right? It's 18 months. Alright, a little closer, but not too worrying. By the time we get to 2024, 2025, actually the last quarter of 2025, It was inside that 30-day window. That's why Microsoft has Patch Tuesday, and then they'll deploy a few more patches after that. Nobody noticed, don't worry, right, because the attackers are inside of that.

11:33 On the right here, if you can see it, it shows you the progression. In… it took 1 year for the attackers to exploit a vulnerability in 2021. Okay. By 2025, it was at one month. By 2026, it took them a week. And right now, where we stand. In some cases, we see it in a day. So, I want you to think about this for a second. Right? You're security, and you get notified, hey, there's a new vulnerability, so you're gonna go call your developers, and you're gonna say, okay, you have one day. 24 hours to validate the vulnerability, build a fix, test it, and roll it out. But it doesn't end there. By 2027, It'll be estimated to be an hour.

12:31 And then a minute. So these are some of the challenges that we have to deal with. It's not just the timing, it's also the numbers. I'll throw some stats out here. So, before Mythos came out, Mozilla, who creates a Firefox browser. You guys are familiar with that. They were going through their normal patch cycle, and they identified 22 vulnerabilities in their browser. Right? And they went off and they patched it. When Methos got limited release, they brought in Mozilla. Mozilla grabbed it. Within a couple of weeks, they started running it against there. Do you know how many they found? New ones! Right? In that short period of time, it was in under 2 weeks, Over 270 new vulnerabilities. Where the best and brightest only found 22.

13:29 The previous several weeks. This is an order of magnitude difference. Now, couple the fact with… it's not just finding the vulnerabilities, the vast number of vulnerabilities never get exploited, because it takes so much time and effort to develop exploits. Mythos and its peers out there can now develop the exploits at the same time it's finding the vulnerability. Typically, within days. Alright. So, that's the good news on the technical side, right? So, let's go with the people side. And when we think about the people side, we've got the accidental, the non-malicious. Right? And then we've got the malicious side. Well, again, you've got a lot of people out there that are using AI. Probably some of you right now, in fact. You're using AI.

14:25 We have developers that are using AI to write code and develop products, and it's amazing! Because they can give a short prompt, and the AI will come back. It'll pull the libraries it needs, and it'll write the code, and it'll put it on the screen. And that developer can see if it works. And if it works, number one rule in software development, by the way, if you write code and it works, you don't touch it. You don't add or remove a space, a comma, nothing! Right? And it works. So they just move on to the next piece. They don't go back and look at the libraries. They don't go back and look at the code. They don't have time for that. They're being pushed. What we see is AI, which has been trained on code. Its whole library is massive amounts of human-created code. Guess what? Those code was riddled With bugs and vulnerabilities. It's no surprise that the code that AI is generating today also has bugs and vulnerabilities. What did we teach it?

15:26 Right? But we're not doing those checks, unfortunately, so we're seeing a lot of code. It's not intentional. What is intentional are the attackers who are using AI to be able to do social engineering, and we've seen a couple of them here today. Right? You can impersonate, you can do phishing, you can do, all sorts of things, you can create synthetic deceptions. And with that, I want to introduce you. Well… to Celeste. Celeste is my favorite. When I say my favorite, you have to understand, she's not real. In my position, I get the pleasure and joy of every month going through and trying to find the latest scams in my inbox, or SMS, or on web pages, right? Most of them, I'm waiting for the ones directed at me. I've got some great little research stuff that I do.

16:27 Alright? Celeste is now my favorite. She is totally awesome! So, Celeste here, right, is a very carefully and crafted synthetic identity. The name itself actually comes from a Swedish investment family. She purports herself to be part of, I think it's TCG Finance, or something like that, which is a real company, by the way. Okay. So, she engaged me, Right? Started in email. And of course, I'm going to engage back. Right? She, in her first engagement with me in email, did OSINT, right? She researched me, looked at my recent posts and articles, crafted a message using cognitive vulnerabilities, appealing to topics that I'm interested in.

17:24 Right? Appealing to urgency, opportunity, all these things. So of course I engaged back. Right? Started doing research, and one of the things I typically ask is, hey, connect to me in LinkedIn. Right? Because if they give my… their LinkedIn profile, I've got a whole bunch of info… more information I can go dig into. And she gave a great response on why she's not in LinkedIn. Okay, no problem. We go back and forth, multiple times a day, and get to the point where she says, I have a webpage. Really awesome! So I go look up this webpage. The webpage was created less than 24 hours before, has full SSL certs, has the domain. She's already seeded it in Google and search engines, she has… A new email address, right? She's got all of this. In fact, I can look up all that information and see exactly when it was created. It's fantastic.

18:28 So now I'm trying to get her online. Hey, join me in a video. She was willing to do it, but not in something like Zoom, where you have a higher resolution. She wanted it on other platforms, where I had to give more information, she could put layers over it and do some other things, right? But the question is… Right? Would you be fooled? If somebody's approaching you or your workers, and they had web pages, they had social media accounts, they knew your interests, they were leveraging cognitive vulnerabilities. This is what we're seeing. I'm seeing, you know, intelligent threats create contracts on the fly. Job requisitions, on the fly, custom. Just for me, I'm very flattered. I was very flattered when she created a webpage for me. Right? So… That's what we have to worry about from the behavioral side. It's going to get worse. It's not just multimodal.

19:31 which was text, image, video, voice, video and voice. We now have to worry about The multi-provenance, because they're gonna back that up with social media accounts, web pages, job requisition, all this other material that is highly convincing. Fun stuff, huh? Okay, I'm gonna go through process real quick. We have to worry about shadow AI. Make shadow IT back in the day look like child's play. It's really tough to understand what AI is being used. And there are more and more challenges around this. The implementation of MCPs and APIs, which is the interface to allow Agentic systems to use your technology. It's fantastic. It also creates a tunnel through all your security tools and platforms and oversight and management To allow attackers to get to your most critical data, unfortunately.

20:36 MCPs were designed specifically for functional use. They even tell any opposing agent what access they have, what data… Get it. Right? It's a hacker's wet dream. And all of this happens at machine speed. A speed in which security operations… there's not a human in the world that can detect that and respond to it in time. Right? We're seeing orchestrated attacks by AI. Blowing through an organization, and they don't know until it's done. So what do we have to do? We either adapt or we get crushed. And this is where you're gonna hate me, right? Because the first thing here is probably the most important. Alright, and this is the I-told-you-so moment. You gotta do the basics. And when I sit and I consult and sit down with companies of all sizes, all over the world, this is the first one.

21:33 If you don't have good basics of cybersecurity, no matter what else you do, you could buy some fancy AI tool and tracking and whatever, it's not gonna make a difference. So if you're gonna do anything. Do this. Ignore the rest of what I say. Right? So this has to be in place. The second thing, and this is a change, Know your enemy. Our industry in cybersecurity has Since the beginning. Focused only within our walls, or firewalls. Right? We looked at, well, what vulnerabilities, what issues do I have, so on and so forth. And how many people watch World Cup? Anybody watch a World Cup? Oh, great games, great games. You're a coach in the World Cup! If you only focus on your players, what's your best defense play? What's your best offense play? What are the conditions of the field?

22:32 You're probably missing something in your next match. Because you should really be understanding what the other team brings to the table. And we haven't done that in cybersecurity. We have to start doing that, because it allows us to be more efficient, more effective, and we can allocate our resources better. We can't peanut butter across anymore. We have to focus. Military has learned this for decades, or hundreds of years, back to Sun Tzu, in fact. Third. We're trying to run a race with a Toyota Corolla, and the enemy has just jumped in an F1. Right? We have to change the tooling. We have to get the same tools or something comparable, which means we have to embrace AI. They have the advantage, by the way. They don't care if it works completely, if it breaks something, right? They can just jump in at its current state. We have to wait.

23:28 In security, we can do no harm. It undermines the trust that we bring to the organization. Therefore, we have to have trustworthy vendors before we can adapt to it. But we have to move into this and work with them. And lastly. And we've talked about this a little bit. As security professionals, AI's coming. Yeah, we don't get to stop it. We can't try and block it. We can't be the office of no. We have to be a welcomed partner. Otherwise, we'll be the last to know. So, we have to get over that. Governance requires cooperation. And the last thing I'm gonna go through here is really the accountability. Because out of all these things that are changing, the one thing that doesn't change Because our neck is still on the line. We're still accountable for all of this! Right? The customers, the business partners, the board, they don't care about all these other changes. You still own risk.

24:29 So we have to adapt to that. So we have to be that partner. Without a doubt. We have to build our tools, processes, people, and everything else to continually adapt. If you think you can build a static system and go, it's built, I'm done. You're lying to yourself. This is moving way too fast, and it will continue to move this fast. And lastly, and I'm gonna close on this. This is for all of us in the room. We have to embrace this ride. It does not get any easier, and it does not slow down. And there's a lot of people out there, they're at the end of their rope, they're stressed. Right? So, if you are not somebody That enjoys that ride. That is okay with ambiguity? Ambiguity? Right? That… doesn't like chaos, right? This may not be the role, because it doesn't get any easier.

25:29 But if you are that person. Oh, it's gonna be a good ride ahead. So, questions! I know I brought up a lot of stuff here. Question, right up here in front. I'm sorry, Stacy. It'd be safe to say that there is… Wouldn't it be safe to say that there's a lot of AI tools available to help prevent these, vulnerabilities from appearing to begin with? Absolutely. And by the way, we've had tools like that, we've been using them, SAS and DAST and all sorts of things, and yet still vulnerabilities get through. there is an inherent, race condition, if you will. We need to get the product out as fast as possible, do scans, but it needs to be done in 2 hours. Right. The same business limitations are there, and we have to reset those. But yes, we are seeing, and this is why Microsoft released over patches for over 600 vulnerabilities in the slash cycle, because they are using Mythos and other products to find more.

26:40 But every time they look, they're getting more, and these engines are getting better. Since Mythos first came out, it's already had two major revisions, and what it finds is even more every time, and it finds it faster. Do we have an online question, perhaps? Alright, they're asleep. Alright, we got more ques- the indomitable Edna Conway, yes! It's not so much a question as I want your opinion on something. So, you and I have talked about, at the end of the day. While we embrace the technology, we believe that the humans are the solution as well. So what I've been doing is I've been getting a lot of, Celeste-like folks in my life who know that You know, I sit on boards. And they found really great ways to do all kinds of cognitive research.

27:36 And set up just the perfect board seat that… it's amazing that they're looking for somebody with my bizarre background, right? So what I've been doing, and I've had a lot of success, and I want your opinion on this, and I'd love to encourage people to do this, when I realize what's going on, and, you know, you and I might be a little quicker at figuring out, but many in this room can do it, I actually contact the company that they have Claim that they are part of. Many of them boldly use the names of people in the particular field and or on the board. I contact them, and then I contact the local FBI agent. And I sick all three of them on… on them, and gleefully send them a message back that says, you will be hearing from the following three. communities, and I appreciate the fact that you gave me ample evidence to come after you Try not to do this with somebody who's as smart as me next time. Setting aside the glee that you experienced from this, it brings up a really important point.

28:48 Right? Our industry is already stressed. Just to achieve the deliverables we're on the hook for now. For us to move forward and be able to adapt to things like this. Sometimes it needs a gentle nudge. Sometimes it needs an Edna nudge. But… We're not… and it's really tough for organizations to be able to justify. We need to do this now. But we have to find a way. Because the people in this room and on the bridge, we are the experts. And what it's really gonna take, and what Edna does really, really well. is she translates that cyber risk and puts it in the context of business value. Because the moment you do that, now you have your C-suite attention. You now have your board attention, and it also travels downwards. You now have your product line management attention, and everybody else.

29:50 That is a skill that we're going to have to do and apply to make sure that we are moving our industry. We can't stay stagnant. Everything I've shown you today, It's gonna get worse. That's today! What's it gonna be like tomorrow? So we have to move and be in the mindset of moving and upgrading and adapting to the risks that present themselves. And if you can do it ahead of time. With foresight, you will have an advantage. Thank you, Matthew.

Watched the session. Ready to run the program?

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.