This Black Hat 2026 kickoff segment features Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, and Jon Oltsik of theCUBE Research, principal analyst in residence. The discussion focuses on practical guidance for chief information security officers navigating the show floor and the evolving threat landscape.
In this segment Case and Oltsik discuss how frontier artificial intelligence models accelerate attacker speed and compress defenders' response windows. They examine threat intelligence, virtual patching, identity security and the ways security stacks and processes must evolve to maintain cyber resilience.
According to Oltsik, organizations adopt threat intelligence, virtual patching and a strategic AI perspective to scale defenses when personnel cannot. They recommend prioritizing automation, security orchestration and measurable risk reduction to extend existing teams.
Case emphasizes resilience as the intersection of technology and business, urging chief information security officers to prioritize robust processes, minimum viable operations and human-plus-AI staffing models. They identify skill needs such as AI penetration testing, orchestration and governance to manage risk and guide investment decisions.
This segment provides concise, actionable insights on AI-driven threats, cyber resilience, identity security and security operations for security leaders and practitioners.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for Black Hat USA 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Black Hat USA 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Black Hat USA 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to Black Hat USA 2026
Please sign in with LinkedIn to continue to Black Hat USA 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Keynote Analysis
This Black Hat 2026 kickoff segment features Krista Case of theCUBE Research, principal analyst and practice lead for cyber resilience and security, and Jon Oltsik of theCUBE Research, principal analyst in residence. The discussion focuses on practical guidance for chief information security officers navigating the show floor and the evolving threat landscape.
In this segment Case and Oltsik discuss how frontier artificial intelligence models accelerate attacker speed and compress defenders' response windows. They examine threat intelligence, virtual patching, identity security and the ways security stacks and processes must evolve to maintain cyber resilience.
According to Oltsik, organizations adopt threat intelligence, virtual patching and a strategic AI perspective to scale defenses when personnel cannot. They recommend prioritizing automation, security orchestration and measurable risk reduction to extend existing teams.
Case emphasizes resilience as the intersection of technology and business, urging chief information security officers to prioritize robust processes, minimum viable operations and human-plus-AI staffing models. They identify skill needs such as AI penetration testing, orchestration and governance to manage risk and guide investment decisions.
This segment provides concise, actionable insights on AI-driven threats, cyber resilience, identity security and security operations for security leaders and practitioners.
Principal Analyst and Practice Lead for Cyber Resilience and SecuritytheCUBE Research
Jon Oltsik
Principal Analyst in ResidencetheCUBE Research
search
(INTRO)
Krista Case
>> Hello and welcome to theCUBE. This is our live coverage of Black Hat 2026 from sunny Las Vegas. We're here at the Mandalay Bay. I'm Krista Case, Principal Analyst and Practice Lead with theCUBE Research, and I'm joined here today with my colleague Jon Oltsik, Analyst in Residence with theCUBE. Jon, how's everything going this morning?
Jon Oltsik
>> Everything is great.
Krista Case
>> Everything is great, right? We were just having a discussion before we went on camera. We were, you and I both, running around yesterday, kind of a day zero before our coverage here at theCUBE, taking a number of briefings. And I know, Jon, one thing that came up a lot in our conversations is this concept that these frontier AI models, like Anthropic models, they're really accelerating the speed and the scale that attackers can move at, which is compressing the window for response for our defenders. That really seems to be the big headline here. And I know one of the big things that defenders need in order to be able to fight fire with fire a little bit is context. And they need intelligence in terms of how attackers are adapting their strategies and also context into, their business operations and how they can respond. I know we had an especially interesting conversation about threat intelligence. Why don't you maybe start us off, Jon, and talk through some of the things that you heard in that conversation in particular that you thought were interesting?
Jon Oltsik
>> Yes. Well, to start with on the frontier models, I think the hyperbole around this event is that the sky is falling. And so fear, uncertainty, and doubt is something that we've seen for two days now. But what you said is really what we have to do. And that is if we have a scaling problem and we can't scale our people, how do we approach this intelligently? And the threat intelligence discussion that we just had is one of the ways we do that. So what are the adversaries doing? How are the adversaries attacking us? What are their tactics, techniques, and procedures? And the more we understand that, the better we can arm ourselves. So that was the discussion that we had. There are also some things we can do that are intelligent. And you heard this in our meeting, and I'm just hitting myself on the head because they talked about virtual patching. So if we can discover vulnerabilities at AI speed, at scale, can AI also help us on the defense side with the right controls? And virtual patching is one of those things, IDS and IPS vendors have been doing this for years, and yet it's really not part of the discussion, and it really should be, because as we talked about in that meeting, it should be part of your cyber resilience strategy, and that gets back to the business context that you talked about.
Krista Case
>> Yes, absolutely, Jon. I love that you've brought up resilience because it really is the spectrum these days from security all the way through disaster recovery, business continuity. To your point, and this has come up in a few conversations already, we need to eat our metaphorical cybersecurity vegetables. We need to make sure that we have our defenses in place and our detection. But we also need to assume in this day and age that the attackers are going to penetrate the environment and that we need to be able to operate through that disruption. So it becomes, not to steal your line, Jon, in a conversation we were having, it becomes more about processes, right? And for a market that has been so much about point best of breed products, I think it's really interesting to see how it's really the people and processes, especially in this day and age that are ultimately going to make the difference in terms of being able to withstand these new types of attacks.
Jon Oltsik
>> Yes. And to me, cyber resilience is the intersection point between technology and the business. And of course, security has to play a role. But before we have resilience, we have to understand, well, what are our business processes? What's important to the business and who are the constituents that need to make that decision and do we need a hundred percent uptime can we scale down a little bit and if we do what are our compensating controls that's a business discussion and it's the new area not so much new but it's really where the CISO has to focus so resilience is a good thing in that it pushes security people to really get into the business.
Krista Case
>> It really, really does. And I'm glad you brought up the CISO role, Jon, because they're really the tip of the spear. I think in navigating this, throughout our coverage today and tomorrow, we're going to be having a handful of conversations around sort of that role, how it's evolving. Jon, you've been at many Black Hats.
Jon Oltsik
>> Many, many Black Hats.
Krista Case
>> You've been in the industry for quite some time, so I guess if you were a CISO, what would you be looking for as you're walking the show floor in terms of really navigating, okay, this vendor sort of has some AI marketing fluff, or they really actually are bringing some meat to bear in terms of actual capabilities that are going to help me where I'm at today?
Jon Oltsik
>> That's a great question. I wrote an article last week that was published in CSO Online about this. So the first thing is you have to come to Black Hat with an agenda. It's not a wing it type of show unless you're a marketer if you're looking for a job maybe but if you're a CISO you have to come with a list of requirements and then you have specific questions that you can ask the vendors. Do you integrate with these tools? What's your AI model? How are your developers trained and how are you guard railing against them? So that's what I would be looking for, but in terms of business resilience, again, you have to have that prepared. You have to know what systems you're trying to protect, what business processes you're trying to protect, and what the existing infrastructure looks like. And then you can make those or have those conversations. But they should be very specific in the areas that you need help.
Krista Case
>> I completely agree, Jon. And I think for CISOs, it's about, like you say, working with the business to understand what do those minimum viable operations look like? what can we withstand going down? It's almost a conversation about making tradeoffs with risk and uptime these days.
Krista Case
>> Exactly.
Krista Case
>> And so thinking on the technology front, because at the end of the day, this is Black Hat and still a very practitioner-led show. And we are looking still at what are the tools that we need to address these changes. I'm seeing the security stack is becoming closer together. I know for example, you and I were talking about how critical identity is these days and how it will be moving forward as we try to wrangle these AI agents. How we need to do things like correlate that with the threat intelligence you were referencing. But I'm wondering if you could talk through how you see the security stack maybe evolving to allow organizations to move faster in terms of allowing their organization to adopt AI, but at the same time better withstand these threats?
Jon Oltsik
>> How much time do we have?
Krista Case
>> Seven minutes? No.
Jon Oltsik
>> It's a great question. So the historical driver was we have too many tools, we have too many consoles or interfaces we need to consolidate, and that really drove the whole platform discussion. So the big vendors are building their platforms. To me, AI changes all this, because what is a product today may become an agent tomorrow, as agents gain cognitive ability, they're outcome driven, they have reasoning. So there's a strategic notion to how this will develop. The difficult part is that we don't really know how that will happen yet, because we're in the early stages of AI technology in general and AI in security. Therefore, we have to have an open mind. And to your point before about CISOs, a CISO should come in and look to where AI can help them address their pain points today, but with a strategic eye to the future in the 12, 18, 24 month timeframe on how that all builds. That's the weakness that I'm seeing. Now, that's a difficult thing to happen, and maybe that's not the CISO's job. Maybe that's a security engineer's job, but it has to happen, and organizations need to have that strategic perspective. That's why you come here, and that's what you should be focused on.
Krista Case
>> I completely agree, Jon, and I'll put you on the spot a little bit and say, okay, we're sitting down at Black Hat 12 months from now. In these early conversations that we've had so far and what you've been studying leading up to the show, what do you think maybe we'll have learned over the next 12 months? And I want to frame the question like that as opposed to what you think kind of the key trends will be because I think there will always be some of these marketing messages that every vendor latches on to. Again, this year seems to be AI governance, right? But tactically speaking, what do you think we'll have learned over the next 12 months and how do you think we'll have maybe matured in terms of some of these technology stacks?
Jon Oltsik
>> Great question. I think we will learn, so we're going to learn some hard lessons. AI is going to fail. There are vendors out there who are less than experienced at this but are putting product together because they're driven by financial motives. And that's scary. People will rely too much on AI. They call it AI complacency. And that is, oh, AI was right today, it's right tomorrow. Eh, it must be right all the time. Let's just let it make decisions. That's going to happen. So we'll learn those lessons, but I think a valuable lesson that you and I have talked about quite a bit is that our people are still really valuable. And AI won't replace the people, so we need to have AI smart people to enhance the technology and to enhance what they do. Not just accelerate it, but enhance it. And that's minimized, that discussion is minimized at the broader Black Hat show, but our individual conversations, everyone talks about that. So I think that's a lesson learned.
Krista Case
>> I think for the most part, at least the vendors that I've met with, they seem to agree that one plus one equals three in terms of, as you're alluding to, we're going to need these AI capabilities, but the human still needs to be in the loop, right? And so combined, human plus AI, we can do more than we could do with just AI or just the human. There are some exceptions to every statement? But I definitely, I would agree with that for sure.
Jon Oltsik
>> Yes, there'll be some displacement of jobs, but that's true of every technology evolution. But we also have to learn that it will create jobs, and that's true of every technology evolution. And I actually wrote about this a few weeks ago, that there'll be new jobs created. And if you are a security department and you are using AI, you will need someone who understands orchestration. You'll need someone who understands how agents cooperate with each other. You'll need someone who understands the data to a greater degree, and who can tune the data and tune the models accordingly. and those skill sets are developing great opportunities for practitioners.
Krista Case
>> So what are some of maybe the two or three key skill sets that you think we're going to need moving forward as we do start to have at least these AI augmented security practices?
Jon Oltsik
>> I just hinted at some, but I'll give you a couple of others. How about AI penetration testers and red teamers, right? So the business is creating all these AI applications. How safe are those? And so we need to beat them up and we need to make sure that we understand how they work, the vulnerabilities. And not just at a technical level, at a business process or even a business logic level. Are they doing the things that we want them to do or can they be manipulated to do other things? We will need specialists in AI governance. To your point, it's not, we understand our processes. Regulations are going to change all the time. And then AI is going to introduce new risks. And therefore, guardrails and governance is a living skill set. And so we'll need people who understand that all the time. So there's a couple of examples.
Krista Case
>> Yeah, I agree. I agree, and I'm really glad that you double clicked on governance, Jon, because I've had a couple of debates so far at the show about, okay, is it more about almost the posture end of things and uncovering where your vulnerabilities are, uncovering how your organization is using AI and turning the lights on, metaphorically speaking, or are we actually wrangling more today with an oversight and a governance problem? And I think most enterprises are in the former part of that camp, but I think we are going to quickly get to a point where we need those governance guardrails. So I would just be interested in your conversations if you're seeing that or if maybe I'm not giving organizations enough credit in terms of their maturity in terms of that posture versus governance conversation.
Jon Oltsik
>> Well, I think you're nailing it. Again, for the broader population, sure, there'll be large financial services companies, tech companies who are more on top of this than others. But you're absolutely right. And so the former example you gave is a technology play. The latter example you gave is a business play. And so when we talk about governance, it's really at the business level with some technology guardrails or processes we need to do. So if you're only thinking about the technology and what's vulnerable and things like AI firewalls and things like that, sure, you need those. But again, it's the executives. It's the board who has to say, this is our business objective, and here are the risks we need to protect against. This is fundamental, but now you've added the AI layer, which needs new skill sets.
Krista Case
>> Absolutely. Well Jon, I'm really looking forward to digging into these skill sets and a whole host of other conversations with you over the next couple days. Thank you so much for joining me to kick off our coverage of Black Hat this year.
Jon Oltsik
>> You're welcome. As we say in Boston, it's a marathon.
Krista Case
>> It is a marathon.
Jon Oltsik
>> It's a marathon, Krista.
Krista Case
>> The marathon, yep. It's the Boston Marathon.
Jon Oltsik
>> It's the Boston Marathon.
Krista Case
>> And we're approaching Heartbreak Hill, but we'll get over it, right?
Jon Oltsik
>> Hopefully we're approaching Heartbreak Hill. Exactly. Happy to be here. And this is great. Absolutely. Thank you for having me.
Krista Case
>> Thank you so much, Jon. And we'll be right back in just a few minutes with our continued coverage of Black Hat 2026. Again, this is Krista Case and Jon Oltsik with theCUBE. So stay tuned and we'll see you in just a couple minutes. Thank you.
>> Hello and welcome to theCUBE. This is our live coverage of Black Hat 2026 from sunny Las Vegas. We're here at the Mandalay Bay. I'm Krista Case, Principal Analyst and Practice Lead with theCUBE Research, and I'm joined here today with my colleague Jon Oltsik, Analyst in Residence with theCUBE. Jon, how's everything going this morning?
Jon Oltsik
>> Everything is great.
Krista Case
>> Everything is great, right? We were just having a discussion before we went on camera. We were, you and I both, running around yesterday, kind of a day zero before our coverage here at theCUBE, taking a number of briefings. And I know, Jon, one thing that came up a lot in our conversations is this concept that these frontier AI models, like Anthropic models, they're really accelerating the speed and the scale that attackers can move at, which is compressing the window for response for our defenders. That really seems to be the big headline here. And I know one of the big things that defenders need in order to be able to fight fire with fire a little bit is context. And they need intelligence in terms of how attackers are adapting their strategies and also context into, their business operations and how they can respond. I know we had an especially interesting conversation about threat intelligence. Why don't you maybe start us off, Jon, and talk through some of the things that you heard in that conversation in particular that you thought were interesting?
Jon Oltsik
>> Yes. Well, to start with on the frontier models, I think the hyperbole around this event is that the sky is falling. And so fear, uncertainty, and doubt is something that we've seen for two days now. But what you said is really what we have to do. And that is if we have a scaling problem and we can't scale our people, how do we approach this intelligently? And the threat intelligence discussion that we just had is one of the ways we do that. So what are the adversaries doing? How are the adversaries attacking us? What are their tactics, techniques, and procedures? And the more we understand that, the better we can arm ourselves. So that was the discussion that we had. There are also some things we can do that are intelligent. And you heard this in our meeting, and I'm just hitting myself on the head because they talked about virtual patching. So if we can discover vulnerabilities at AI speed, at scale, can AI also help us on the defense side with the right controls? And virtual patching is one of those things, IDS and IPS vendors have been doing this for years, and yet it's really not part of the discussion, and it really should be, because as we talked about in that meeting, it should be part of your cyber resilience strategy, and that gets back to the business context that you talked about.
Krista Case
>> Yes, absolutely, Jon. I love that you've brought up resilience because it really is the spectrum these days from security all the way through disaster recovery, business continuity. To your point, and this has come up in a few conversations already, we need to eat our metaphorical cybersecurity vegetables. We need to make sure that we have our defenses in place and our detection. But we also need to assume in this day and age that the attackers are going to penetrate the environment and that we need to be able to operate through that disruption. So it becomes, not to steal your line, Jon, in a conversation we were having, it becomes more about processes, right? And for a market that has been so much about point best of breed products, I think it's really interesting to see how it's really the people and processes, especially in this day and age that are ultimately going to make the difference in terms of being able to withstand these new types of attacks.
Jon Oltsik
>> Yes. And to me, cyber resilience is the intersection point between technology and the business. And of course, security has to play a role. But before we have resilience, we have to understand, well, what are our business processes? What's important to the business and who are the constituents that need to make that decision and do we need a hundred percent uptime can we scale down a little bit and if we do what are our compensating controls that's a business discussion and it's the new area not so much new but it's really where the CISO has to focus so resilience is a good thing in that it pushes security people to really get into the business.
Krista Case
>> It really, really does. And I'm glad you brought up the CISO role, Jon, because they're really the tip of the spear. I think in navigating this, throughout our coverage today and tomorrow, we're going to be having a handful of conversations around sort of that role, how it's evolving. Jon, you've been at many Black Hats.
Jon Oltsik
>> Many, many Black Hats.
Krista Case
>> You've been in the industry for quite some time, so I guess if you were a CISO, what would you be looking for as you're walking the show floor in terms of really navigating, okay, this vendor sort of has some AI marketing fluff, or they really actually are bringing some meat to bear in terms of actual capabilities that are going to help me where I'm at today?
Jon Oltsik
>> That's a great question. I wrote an article last week that was published in CSO Online about this. So the first thing is you have to come to Black Hat with an agenda. It's not a wing it type of show unless you're a marketer if you're looking for a job maybe but if you're a CISO you have to come with a list of requirements and then you have specific questions that you can ask the vendors. Do you integrate with these tools? What's your AI model? How are your developers trained and how are you guard railing against them? So that's what I would be looking for, but in terms of business resilience, again, you have to have that prepared. You have to know what systems you're trying to protect, what business processes you're trying to protect, and what the existing infrastructure looks like. And then you can make those or have those conversations. But they should be very specific in the areas that you need help.
Krista Case
>> I completely agree, Jon. And I think for CISOs, it's about, like you say, working with the business to understand what do those minimum viable operations look like? what can we withstand going down? It's almost a conversation about making tradeoffs with risk and uptime these days.
Krista Case
>> Exactly.
Krista Case
>> And so thinking on the technology front, because at the end of the day, this is Black Hat and still a very practitioner-led show. And we are looking still at what are the tools that we need to address these changes. I'm seeing the security stack is becoming closer together. I know for example, you and I were talking about how critical identity is these days and how it will be moving forward as we try to wrangle these AI agents. How we need to do things like correlate that with the threat intelligence you were referencing. But I'm wondering if you could talk through how you see the security stack maybe evolving to allow organizations to move faster in terms of allowing their organization to adopt AI, but at the same time better withstand these threats?
Jon Oltsik
>> How much time do we have?
Krista Case
>> Seven minutes? No.
Jon Oltsik
>> It's a great question. So the historical driver was we have too many tools, we have too many consoles or interfaces we need to consolidate, and that really drove the whole platform discussion. So the big vendors are building their platforms. To me, AI changes all this, because what is a product today may become an agent tomorrow, as agents gain cognitive ability, they're outcome driven, they have reasoning. So there's a strategic notion to how this will develop. The difficult part is that we don't really know how that will happen yet, because we're in the early stages of AI technology in general and AI in security. Therefore, we have to have an open mind. And to your point before about CISOs, a CISO should come in and look to where AI can help them address their pain points today, but with a strategic eye to the future in the 12, 18, 24 month timeframe on how that all builds. That's the weakness that I'm seeing. Now, that's a difficult thing to happen, and maybe that's not the CISO's job. Maybe that's a security engineer's job, but it has to happen, and organizations need to have that strategic perspective. That's why you come here, and that's what you should be focused on.
Krista Case
>> I completely agree, Jon, and I'll put you on the spot a little bit and say, okay, we're sitting down at Black Hat 12 months from now. In these early conversations that we've had so far and what you've been studying leading up to the show, what do you think maybe we'll have learned over the next 12 months? And I want to frame the question like that as opposed to what you think kind of the key trends will be because I think there will always be some of these marketing messages that every vendor latches on to. Again, this year seems to be AI governance, right? But tactically speaking, what do you think we'll have learned over the next 12 months and how do you think we'll have maybe matured in terms of some of these technology stacks?
Jon Oltsik
>> Great question. I think we will learn, so we're going to learn some hard lessons. AI is going to fail. There are vendors out there who are less than experienced at this but are putting product together because they're driven by financial motives. And that's scary. People will rely too much on AI. They call it AI complacency. And that is, oh, AI was right today, it's right tomorrow. Eh, it must be right all the time. Let's just let it make decisions. That's going to happen. So we'll learn those lessons, but I think a valuable lesson that you and I have talked about quite a bit is that our people are still really valuable. And AI won't replace the people, so we need to have AI smart people to enhance the technology and to enhance what they do. Not just accelerate it, but enhance it. And that's minimized, that discussion is minimized at the broader Black Hat show, but our individual conversations, everyone talks about that. So I think that's a lesson learned.
Krista Case
>> I think for the most part, at least the vendors that I've met with, they seem to agree that one plus one equals three in terms of, as you're alluding to, we're going to need these AI capabilities, but the human still needs to be in the loop, right? And so combined, human plus AI, we can do more than we could do with just AI or just the human. There are some exceptions to every statement? But I definitely, I would agree with that for sure.
Jon Oltsik
>> Yes, there'll be some displacement of jobs, but that's true of every technology evolution. But we also have to learn that it will create jobs, and that's true of every technology evolution. And I actually wrote about this a few weeks ago, that there'll be new jobs created. And if you are a security department and you are using AI, you will need someone who understands orchestration. You'll need someone who understands how agents cooperate with each other. You'll need someone who understands the data to a greater degree, and who can tune the data and tune the models accordingly. and those skill sets are developing great opportunities for practitioners.
Krista Case
>> So what are some of maybe the two or three key skill sets that you think we're going to need moving forward as we do start to have at least these AI augmented security practices?
Jon Oltsik
>> I just hinted at some, but I'll give you a couple of others. How about AI penetration testers and red teamers, right? So the business is creating all these AI applications. How safe are those? And so we need to beat them up and we need to make sure that we understand how they work, the vulnerabilities. And not just at a technical level, at a business process or even a business logic level. Are they doing the things that we want them to do or can they be manipulated to do other things? We will need specialists in AI governance. To your point, it's not, we understand our processes. Regulations are going to change all the time. And then AI is going to introduce new risks. And therefore, guardrails and governance is a living skill set. And so we'll need people who understand that all the time. So there's a couple of examples.
Krista Case
>> Yeah, I agree. I agree, and I'm really glad that you double clicked on governance, Jon, because I've had a couple of debates so far at the show about, okay, is it more about almost the posture end of things and uncovering where your vulnerabilities are, uncovering how your organization is using AI and turning the lights on, metaphorically speaking, or are we actually wrangling more today with an oversight and a governance problem? And I think most enterprises are in the former part of that camp, but I think we are going to quickly get to a point where we need those governance guardrails. So I would just be interested in your conversations if you're seeing that or if maybe I'm not giving organizations enough credit in terms of their maturity in terms of that posture versus governance conversation.
Jon Oltsik
>> Well, I think you're nailing it. Again, for the broader population, sure, there'll be large financial services companies, tech companies who are more on top of this than others. But you're absolutely right. And so the former example you gave is a technology play. The latter example you gave is a business play. And so when we talk about governance, it's really at the business level with some technology guardrails or processes we need to do. So if you're only thinking about the technology and what's vulnerable and things like AI firewalls and things like that, sure, you need those. But again, it's the executives. It's the board who has to say, this is our business objective, and here are the risks we need to protect against. This is fundamental, but now you've added the AI layer, which needs new skill sets.
Krista Case
>> Absolutely. Well Jon, I'm really looking forward to digging into these skill sets and a whole host of other conversations with you over the next couple days. Thank you so much for joining me to kick off our coverage of Black Hat this year.
Jon Oltsik
>> You're welcome. As we say in Boston, it's a marathon.
Krista Case
>> It is a marathon.
Jon Oltsik
>> It's a marathon, Krista.
Krista Case
>> The marathon, yep. It's the Boston Marathon.
Jon Oltsik
>> It's the Boston Marathon.
Krista Case
>> And we're approaching Heartbreak Hill, but we'll get over it, right?
Jon Oltsik
>> Hopefully we're approaching Heartbreak Hill. Exactly. Happy to be here. And this is great. Absolutely. Thank you for having me.
Krista Case
>> Thank you so much, Jon. And we'll be right back in just a few minutes with our continued coverage of Black Hat 2026. Again, this is Krista Case and Jon Oltsik with theCUBE. So stay tuned and we'll see you in just a couple minutes. Thank you.