Vivek Kumar of Alter Domus and Mayank Upadhyay of Snowflake join hosts Gemma Allen, John Furrier and Dave Vellante for a conversation at theCUBE and NYSE Wired: Cyber Security Leaders. theCUBE Research frames the discussion on agentic artificial intelligence, abbreviated as AI, managed control plane, abbreviated as MCP, model selection, data protection, observability and identity controls that are reshaping security operations across capital markets and cloud environments.
Kumar emphasizes that agentic AI models can parallelize actions and therefore require an AI gateway for model protection and observability. They highlight the importance of model selection, continuous monitoring and robust controls to prevent unauthorized agentic activity and to preserve data security.
Upadhyay urges strict managed control plane governance, least-privilege non-human identities, sandboxing and proactive patching. They underscore the need to accelerate vulnerability remediation, adopt scoped agent identities and deploy detection and remediation at machine speed to manage emerging AI risks.
This discussion offers practical guidance for enterprise security leaders on governance, identity and access management, observability, and vulnerability management in the era of agentic AI.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Zero Trust Cyber Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Zero Trust Cyber Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Zero Trust Cyber Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Zero Trust Cyber Series. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Vivek Kumar, Alter Domus & Mayank Upadhyay, Snowflake
Vivek Kumar of Alter Domus and Mayank Upadhyay of Snowflake join hosts Gemma Allen, John Furrier and Dave Vellante for a conversation at theCUBE and NYSE Wired: Cyber Security Leaders. theCUBE Research frames the discussion on agentic artificial intelligence, abbreviated as AI, managed control plane, abbreviated as MCP, model selection, data protection, observability and identity controls that are reshaping security operations across capital markets and cloud environments.
Kumar emphasizes that agentic AI models can parallelize actions and therefore require an AI gateway for model protection and observability. They highlight the importance of model selection, continuous monitoring and robust controls to prevent unauthorized agentic activity and to preserve data security.
Upadhyay urges strict managed control plane governance, least-privilege non-human identities, sandboxing and proactive patching. They underscore the need to accelerate vulnerability remediation, adopt scoped agent identities and deploy detection and remediation at machine speed to manage emerging AI risks.
This discussion offers practical guidance for enterprise security leaders on governance, identity and access management, observability, and vulnerability management in the era of agentic AI.
Vivek Kumar, Alter Domus & Mayank Upadhyay, Snowflake
Vivek Kumar
Global Chief Information Security OfficerAlter Domus
Mayank Upadhyay
Chief Security & Trust OfficerSnowflake
search
(INTRO)
Gemma Allen
>> Welcome to theCUBE Studio here at the New York Stock Exchange. I'm Gemma Allen with NYSE Wired: Cyber Security Leaders, where we talk to the people shaping and securing the future of technology, business, and markets. For decades, enterprise cybersecurity has been built around one basic assumption, and that is that there is a human on the other end. But we know AI agents are changing that equation rapidly. They can operate autonomously, access multiple systems, call tools, and increasingly we hear call each other. And they've been given permissions that historically belong to humans. Which raises a very interesting question. Could the next major enterprise breach come not from a compromised employee, but an agent itself? Joining me are two security leaders looking at this from very different angles of enterprise. Mayank Upadhyay, Snowflake's Chief Security and Trust Officer, and Vivek Kumar, Global Chief Information Security Officer at Alter Domus. Welcome, folks.
Mayank Upadhyay
>> Thank you. Thank you. Really exciting to be here. What a great venue.
Gemma Allen
>> Two fascinating companies. we're no stranger to Alter Domus here on Wall Street, and we're also no stranger to Snowflake, right? You guys have had an interesting year on the street. There's a lot of enthusiasm for Snowflake and for Alter Domus, and the future we know is changing very, very quickly. So let's get straight into it. We're going to talk about trust, security, and what's happening faster than I think many of us predicted, perhaps even yourselves. Let's start just unpacking the world of 2026. We're halfway through, and I'm going to start with you, Vivek. You have built the backbone of capital markets, right? But it's essentially about giving clients and customers access to real-time data as efficiently as possible. We know AI is changing that. Talk me through how that changes your job from the perspective of security and trust. Break it down for me. What's changed in the last two years?
Vivek Kumar
>> I have more job security. I'm just kidding. It is changing a lot because the landscape has, for the last two years, three years, since the agentic AI adoption, the whole landscape has changed. Earlier, whenever the new tools and new products and new things used to come, we used to do like a yearly review or yearly new releases coming up and all those kind of things were very delayed. Then it moved to six months, then it went monthly, now weekly, now daily. So if you talk about anything happening in this world, especially in terms of security, in terms of technology, releases are happening every single day. So it has become very dynamic. And to cope up with that dynamic environment, as a chief security officer, it becomes a very, very difficult task and challenging task, though I'm loving it, to cope up with that. So that's, yeah, whole Dynamics paradigm has changed now.
Gemma Allen
>> So let's talk about Snowflake. Fascinating company. Everyone, I think, who's worth their salt in the industry knows exactly who Snowflake is and what you guys do. We know, though, that the world of data, the accessibility, the interoperability, who and how that data is accessed is changing at a scale that, like I said, no one expected, right? This year, a lot of enthusiasm around Cortex, the AI gateway that Snowflake has introduced. certainly did something interesting to your stock price talk me through it though from the perspective of the build out you're on the front lines behind this Mayank break it down for me yeah give me the lowdown
Mayank Upadhyay
>> look i think what'shappened in the last couple of years people went from simple chatbots to agents who can take actions and there's two things which have happened really in the last six months i'd say one the agents have got really good at parallelizing everything they do. And their job basically is to look under every rock, look at every nook and cranny, you give them a goal, and they try to get to that goal. And this means that if they're operating as you, they're going to have all the permissions you have. If there's any security issues in your enterprise, they're going to find those. That's a huge problem. The second thing that's going on is that these models have gotten really smart. these agents are different from traditional software in that they have their own brain, right? Which is these models. So with traditional software, you knew exactly it was going to call this next piece of software through an API. It was going to have very, very fixed deterministic behavior. But these agents, they have a brain of their own, and these brains are getting smarter and smarter. And the models have gotten so good these days at what's called long horizon reasoning without hallucinating, right? They're able to go deep and find issues as a result of that. So when you put all these things together, you're in this interesting scenario where, on the one hand, you've got this massive productivity boost, but when something goes wrong, it can go spectacularly wrong. So it's honestly a great time to be working in the security industry and trying to bring all of this chaos under control. So we started off on this journey. We've been in the agentic journey for a year and a half now. Earlier this year, we acquired a company called Natoma, which does bring some governance to MCP. We're building on the back of that. We've now got an AI gateway that is coming out in the market this month. And this AI gateway gives you everything from protecting the model, protecting the agents and integrating down to your data stack. So it's the full shebang. We've got our own experience for the last year and a half how we've modernized or further agentified our enterprise. And so we want to take that even further for our customers and we're super excited about that.
Gemma Allen
>> We hear a lot about MCP. It's become a real buzzword. We talk about it every day here on the show. It seems as though, again, every company is building towards this. If they're not already trying to execute on this strategy. We also know that it's a different kind of vector from the perspective of security. How do you think about it, Vivek, from the perspective of your footprint, your ecosystem and the interoperability elements? What does it mean from a governance perspective?
Vivek Kumar
>> First of all, we all are fighting the same enemy. So over here, the partnership is a big key thing. You know, the MCP adoption is happening faster and more rapidly than your security controls. So the problem what is happening is that there are a bunch of MCP gateways people are using, which you are not even aware of. And it's very hard to keep track of it and govern it and find it where it is. And it is creating a big issue in any industry from a security perspective. They should be going in through one governed MCP gateway so that security can watch it and do things. So as you said earlier, if an enterprise level attack coming in, it looks like a legitimate thing. But although it's an attack, it's no longer a traditional thing, what Mayank was talking about earlier. Because now, through the MCP gateway, all the things are going out, looks like a good thing, legit thing. one agent is talking to another agent, delegating it to a third agent, delegating it to a fourth agent, and that delegation is working in such a manner that it's very difficult to govern and audit that piece. So, MCP gateways and all this, although it's the best thing which has happened, if the governance is not in place, then you are going to lose visibility and get into some kind of a big problem. And there were a lot of things that happened with the GitHub and other things which you saw. And they were all because of these breaches that happened because of these chains of delegations and multi -agent functionalities and MCP gateways.
Gemma Allen
>> I mean, let's stay on MCP for a second, but let's talk a little bit about models because it's a very interesting evolution, right? We know that in some respects, MCP, it opens the floodgate to all sorts of different accessibility vectors, right? Models, we hear a lot about Anthropic. We hear a lot about OpenAI. We hear a lot about the security level of openweight models versus the models we're more familiar with here in the US. What are your thoughts, though, from the perspective of the kind of non -negotiables from a risk perspective, especially at a company like Snowflake, where there has to be some clear parameters around what can and can't happen, what can and can't engage?
Mayank Upadhyay
>> Yeah, look, first and foremost, we like both proprietary models as well as openweight models. So we can get that out of the way. We like to use them both. You get a lot of benefits from the open -weight models. As a security team, you don't have constraints when you're doing an investigation, when you're doing threat modeling. Also, from a cost governance perspective, they're so much better. The other thing which is a non -negotiable for us and for many of our customers is that they want their data to stay within their perimeter. So as you work with these models, you kind of have to make sure the data doesn't accidentally end up with the model provider in a way that might get used for training. And I know everybody has lots of different architectures for this, but it is the crown jewels that our customers have. And so that is a non -negotiable for us. So a lot of the ideas behind what we're rolling out right now with the AI Gateway are meant to give you that data separation, the visibility. You might use the word visibility, use the word trust. Trust comes from transparency and predictability, right? So with our AI Gateway, we want to give you that observability so you know exactly what's going on in the agent and the model. And we're watching it to make sure that nothing bad is happening for you.
Gemma Allen
>> And you have a complex network from some perspective, right? there are different folks who use many different technologies, many different APIs, many different tools. And that's probably only going to get even more diluted as this world of AI and inference expands. How do you think about it from the perspective of accessing the data and then securing the data once it's in the hands or in the presence of whatever actor you hope or deem it to be?
Vivek Kumar
>> So this is very critical because data is all very important. You can't build an AI layer without having a data security layer in place. Because the AI sits on top of data. The problem happening is these MCP gateways and the models and all, it's a new thing which is now turning into a shadow AI thing. Even the MCP gateways, people are using models, people are using MCP gateways, they are downloading things, and they are creating agents. Suddenly this is becoming a shadow AI kind of thing for us. It's a big problem. Agents, when they talk to a different agent or another agent, they have a capability of escalating their privileges. So all of these agents are doing a lot of different things. So you are really scared to see that your data, your critical data, your PII information, your financial information doesn't get pasted and it goes out of your boundaries. So the cross-border and cross-organizational boundaries should not be overlooked. And that's the main concern when this is happening. And it is very, very important that for that not to happen, you should know what kind of gateways you are using, what kind of models you are using. and all the agents, what actions they are doing. They should be least privileged actions. What I mean is that if an agent is supposed to do a task, he should only get the permission and escalation to only do that and then it dies down. You cannot have long-lasting controls given to them to perform the work. So definitely you have to build the governance, as Vivek was talking about it.
Gemma Allen
>> But how do you truly do that? there's obviously governance there's compliance it's sandboxing first what are you truly doing to ensure that whoever it is or whatever actor it is is trying to access data it's not just about verification it's abouteverything that comes after that also
Mayank Upadhyay
>> i'd probably mention four different things to you on the one hand you have sandboxing which makes sure you can do stuff least on your disk, steal secrets if you're going out to the network we know exactly where you're going. I would throw MCP governance as a perimeter control because you can see who's talking to what MCP tool. Are they allowed to talk to that MCP tool? The next layer I talk about is the identity layer. When you have an agent acting on your behalf, you don't want it to act with all your permissions. If you've been at a job for five years and changed different roles, you probably picked up a whole bunch of permissions along the way, right? You don't want to give all of them to your agent because an agent is going to try each and everything it can. Even look at paths you didn't think it might, right?
Mayank Upadhyay
>> Right.
Mayank Upadhyay
>> So the first and foremost thing you need to do with identity and where we're headed now is we're coming up with new standards. So when you kick off an agent, you can say, hey, here's a scoped set of things you can do on my behalf. It's a little bit like, say, you know, I like to think of agents as interns. They're untrained employees. Right. Now, let's say you're a company. you had an office manager intern who was supposed to go buy you a new printer and you send them off to get a printer. And they came back with this Wi -Fi controlled refrigerator. Right. So what do you do instead? You give them a gift card for Best Buy, which is set to $200. So you put those constraints in place and say, here's what you're allowed to do. So even if you veer off where you're supposed to be, it's not going to be catastrophic. It's going to be more or less within those guardrails I set for you. So those are the kinds of primitives that we're coming up with in the industry. And we have to make them easy for people to use. So again, you can use AI to say, hey, you're asking your agent to go research this topic for you. I think it's going to need to look at all these tables. So let me scope permissions to read -only permissions to just those tables. So that's a way of sort of making sure it doesn't go off and do something on its own. So that's the second big thing I think that's coming. And I just want to quickly mention, I think we also have to come and take care of more of the observability and detection techniques. And we can talk about that.
Vivek Kumar
>> That's what I was talking about. The agents have least privilege. because the number of non -human identities, which are the AI agents, is growing faster and more rapidly than the human identities. You can control human identities based on their birthrights and whatever permissions and access, privileged access they have, but in an agentic space for the AI agent, it's very difficult to do that. So with somebody coming up, Snowflake coming up with this kind of security control, identity becomes a very key, key factor for us.
Gemma Allen
>> And that non -human identity where there's multiple versions of a human based on a workflow or a task, right? That's a complex security system and ecosystem, too, to oversee. And you mentioned observability. That also changes the game fundamentally from managing someone on a domain level to managing somebody or an actor, I guess you can call it, in multiple proliferations. Yeah. How do you think about that? Is that when we really boil that down, does that come down to governance and compliance and very clear standards of execution? Or is it something more complex than that?
Vivek Kumar
>> It is complex because, as I said, it's changing very rapidly, very dynamically. The entire identity and access management system was based on human identities. It has a paradigm shift now and also it's growing. Plus, you don't even know what they are doing. So people are concentrating on the action, what the agent did, but you also need to see who authorized it, who gave them that permission to do it. So there are a lot of other complex pieces which were missing, which have to be incorporated in terms of this AI. Another thing you talked about, the sandboxing, just want to touch upon it. What I see as the problem with the agentic AI and the whole AI thing is, you are sending a kindergartner to college directly, right?
Gemma Allen
>> I love that.
Vivek Kumar
>> Yeah, you have to go through elementary school, middle school, high school, and then to college. So if you take anything which has just come out in the market and not sandboxing and not testing in your lab, suddenly implementing them in your production environment, you don't know what is going to happen, right? And it creates, one creates other issue, another issue and all. The scale goes so big that it will be difficult to control.
Gemma Allen
>> You mentioned something very interesting, which is observability, right? and the roadmap of a company like Snowflake. Because again, the expectation is also shifting. There was a time when we were so excited just to be able to access data, to be able to see the data in some sort of concrete and succinct way. But now, the role 10 years from now is going to be about observing the data. Who else is watching that data? How do you think about that from a company perspective? What does that roadmap look like? Who owns that problem?
Mayank Upadhyay
>> Yeah. Yeah. So, look, I think a lot of traditional security vendors are all moving very fast to try and fill this gap. At Snowflake, we just announced our Cortex AI Gateway, which is going to sit right between any agent from any company and the models you're using. So it just slides right into your architecture and it gives you that observability where it can see what these agents are doing. And there's actually two sides to the observability problem. Obviously, you want to make sure your agents are not misbehaving, right? So if it's a well-behaved agent that's going through this, you can look at what's called its traces, its trajectories, and you can see, is it doing something it shouldn't be? But there's a different side of observability, where what if there's an agent running in somebody else's environment that's now breaking through your perimeter and entering your enterprise? You have to catch those too. So while there's this whole new category of agent observability to make sure your agents are well-behaved, there's also the traditional security world of just building detections into your perimeter, fixing your security vulnerabilities so agents outside don't find ways to get inside your perimeter, right? And those have to be taken super seriously. And there's probably a limited amount of time for enterprises right now to go and patch these. So using AI to find these vulnerabilities, to patch these vulnerabilities, this is the time to be doing all of that.
Gemma Allen
>> I want to go back to something you said at the beginning, which is very relevant to your industry too, right? because financial services is very secure and we're hearing a lot about companies going back on -prem, sovereign AI, bringing actually AI to your data as opposed to bringing your data to AI. From the perspective of Snowflake, and I'm going to put this to both of you, what does that mean in terms of what you're building towards? How nuanced and different is that from a security perspective? Or is there kind of a universal security guideline around what it means to have data on -prem versus in the cloud, and how folks are going to go about, again, managing, monitoring, and continually observing what's happening with it?
Vivek Kumar
>> So it's a great question. And every day we are exploring new things. First of all, you need to know where your data is to secure it, to manage it, right? So as you said, bringing data to AI or bringing AI to your data. So that has become a big challenge. First is we need to know where your data is lying, or which data lake it's sitting in. It's always scattered all over the place. Agents, as you know, they have a very privileged access to go and talk to other agents and try to dig in and go everywhere. And the problem is that if there is an agent sitting outside who can come into your environment and can have access to the data through the agent which is inside, which is a legitimate agent, is a problem. So we have to secure our perimeters. We have to make sure where our data is and make sure that that is secure. The governance and the guardrails are the biggest things which we have to work on this thing. That how data needs to be treated and who can treat it and what kind of permission that person or agent has for that data. And it has become very important. The SIEMs of the world where they used to do the detection, like discovery and detection, all was based on very traditional environment. It was not based on the AI agentic environment. So you have to go and change. So you have to change from identity perspective, data security perspective, sensor perspective, governance perspective, policies perspective. Everywhere there is a change to see that how data can be accessed, who can access it, who authorizes it, what kind of identity and governance you have for them.
Mayank Upadhyay
>> So if I could add to that, Gemma, my take is that going back to on-prem is not the answer. The way the world is headed, everything is interconnected. Unless you're a three-letter government agency that is operating in complete secret, I think in general, you would expect people and companies want to have more trade, more commerce between them, right? And people are talking about agents going and doing shopping for you. So I think these are bringing more efficiencies into our life on a daily basis. So I think they, and even if, look, the moment you expose yourself to working with partners and interacting with systems outside, there's a threat surface there that you have to worry about that can be attacked. So I think you have to go back to the basics. And the basics don't mean going on-prem. It means finding and fixing your vulnerabilities, putting detections in place so that if you're compromised, you can detect that at machine speed and you can remediate at machine speed. There's also a super interesting and simple technology called deception. It's kind of like, okay, let's say you have a giant house and you've got lots of doors and windows and you can't put a burglar alarm everywhere. Well, guess what? You can get a big safe in the middle of your house. So if a burglar gets in, they zoom in on that safe. And the moment they open that safe, the alarm goes off. So there's lots of interesting tricks to deal with this. And I think we're headed to a world where the basic security practices about cleanup and vulnerability patching and management, as well as detections and remediations, have to be carried out at AI speed now.
Gemma Allen
>> So last question, and I love when somebody takes a position on something. we hear a lot about the move back on-prem though, right? And maybe that's built on a false assumption, or maybe there's a whole administrative layer that was never fully fixed in the era of cloud that is now suddenly coming home to roost somewhat from the perspective of security. And it feels like it's an easier solution when, in fact, maybe it's not the long term solution companies need. Right.
Mayank Upadhyay
>> That's right.
Gemma Allen
>> But how do you and I'm going to put this to both of you as you move forward, right? These are both fascinating companies, industry leaders. How do you think about the messaging around what's happening in this industry, conversations like that one and the role of companies like yours to in some way lead folks forward at a time where there is so much conflicting information and so much worry?
Vivek Kumar
>> So I would agree with Mayank. On-prem is not it, you can't move two steps backwards and one step forward, right? Because of all the SaaS platforms and everything coming up, you can't go back on-prem on a lot of things. Yes, there are certain things you can still go back, but again, are you going to increase your footprint, which again involves a lot of cost, right? So you may be focusing on the wrong thing if you want to go back to on-prem. Some people say that it could be safer than sorry, but that's not how it is, because the whole world is open to the SaaS platform. We are using a lot of these kind of tools and techniques and software now, bringing everything back to on-prem will not be a solution. It will be a very, very expensive solution, though. So what we need to look at is that whatever things we have, like Mayank was talking about vulnerability management and all that kind of thing. I was talking to one of the CEOs saying, it's no longer a zero day. It's all minus one day, minus two day, right? So fixing the vulnerability comes next, but patching process has to be very proactive. So in this environment, you have to be very proactive. You should know where everything is. If you have that observability, you have that visibility, then proactively go and face it and attack it and solve it rather than thinking backwards going to take the workload to an on-prem solution.
Gemma Allen
>> Let's stay on patching and I want to finish with this. If we just take meetings as an example, right? We know that there are huge vulnerabilities detected across operating systems at large banks, large enterprises. We also heard that the fix from a patching perspective, could take anywhere from six to nine months. In a minus two, minus one day scenario, that's an alarming reality. How do you think about that? What are your thoughts from the perspective of where we're at right now, the pace of where we're headed, and the gap?
Mayank Upadhyay
>> I think the way software patching has operated in the past is changing now. Right now, not only can AI find vulnerabilities, it can also suggest fixes. and some of the cutting -edge models have a very high acceptance rate when they suggest a fix the developers like it like you know people are talking about upwards of 85 percent acceptance rate right so we're getting to a world where traditionally when you found a vulnerability you would have a long argument about is it actually reachable does it matter do you have other mitigating controls in place right or if you had open source packages you would think about hey, how do you get this package to be upgraded? Is somebody even maintaining it? But in the new world, you can have software -generated fixes. It's like a three-line fix. Just roll it out. Don't even bother debating it, right? Or if it's a small open -source package of 300 lines or less, which is the bulk of them, and nobody's maintaining it, can you just get AI to rewrite it for you? So there's all these options which have opened up, and I think security teams have to think differently in this new world.
Gemma Allen
>> Wow.Well, we certainly hope that they will and that the world remains protected. So folks, fascinating companies, fascinating time, great conversation. Thanks for joining us on theCUBE and NYSE Wired.
Vivek Kumar
>> Thank you very much. Thank you for having us. It was great. Thank you.
Gemma Allen
>> I'm Gemma Allen here at theCUBE Studio at the New York Stock Exchange. This is Cyber Security Leaders, one of our programs with NYSE Wired. We connect Silicon Valley to Wall Street. Thanks for watching.
Vivek Kumar, Alter Domus & Mayank Upadhyay, Snowflake
search
(INTRO)
Gemma Allen
>> Welcome to theCUBE Studio here at the New York Stock Exchange. I'm Gemma Allen with NYSE Wired: Cyber Security Leaders, where we talk to the people shaping and securing the future of technology, business, and markets. For decades, enterprise cybersecurity has been built around one basic assumption, and that is that there is a human on the other end. But we know AI agents are changing that equation rapidly. They can operate autonomously, access multiple systems, call tools, and increasingly we hear call each other. And they've been given permissions that historically belong to humans. Which raises a very interesting question. Could the next major enterprise breach come not from a compromised employee, but an agent itself? Joining me are two security leaders looking at this from very different angles of enterprise. Mayank Upadhyay, Snowflake's Chief Security and Trust Officer, and Vivek Kumar, Global Chief Information Security Officer at Alter Domus. Welcome, folks.
Mayank Upadhyay
>> Thank you. Thank you. Really exciting to be here. What a great venue.
Gemma Allen
>> Two fascinating companies. we're no stranger to Alter Domus here on Wall Street, and we're also no stranger to Snowflake, right? You guys have had an interesting year on the street. There's a lot of enthusiasm for Snowflake and for Alter Domus, and the future we know is changing very, very quickly. So let's get straight into it. We're going to talk about trust, security, and what's happening faster than I think many of us predicted, perhaps even yourselves. Let's start just unpacking the world of 2026. We're halfway through, and I'm going to start with you, Vivek. You have built the backbone of capital markets, right? But it's essentially about giving clients and customers access to real-time data as efficiently as possible. We know AI is changing that. Talk me through how that changes your job from the perspective of security and trust. Break it down for me. What's changed in the last two years?
Vivek Kumar
>> I have more job security. I'm just kidding. It is changing a lot because the landscape has, for the last two years, three years, since the agentic AI adoption, the whole landscape has changed. Earlier, whenever the new tools and new products and new things used to come, we used to do like a yearly review or yearly new releases coming up and all those kind of things were very delayed. Then it moved to six months, then it went monthly, now weekly, now daily. So if you talk about anything happening in this world, especially in terms of security, in terms of technology, releases are happening every single day. So it has become very dynamic. And to cope up with that dynamic environment, as a chief security officer, it becomes a very, very difficult task and challenging task, though I'm loving it, to cope up with that. So that's, yeah, whole Dynamics paradigm has changed now.
Gemma Allen
>> So let's talk about Snowflake. Fascinating company. Everyone, I think, who's worth their salt in the industry knows exactly who Snowflake is and what you guys do. We know, though, that the world of data, the accessibility, the interoperability, who and how that data is accessed is changing at a scale that, like I said, no one expected, right? This year, a lot of enthusiasm around Cortex, the AI gateway that Snowflake has introduced. certainly did something interesting to your stock price talk me through it though from the perspective of the build out you're on the front lines behind this Mayank break it down for me yeah give me the lowdown
Mayank Upadhyay
>> look i think what'shappened in the last couple of years people went from simple chatbots to agents who can take actions and there's two things which have happened really in the last six months i'd say one the agents have got really good at parallelizing everything they do. And their job basically is to look under every rock, look at every nook and cranny, you give them a goal, and they try to get to that goal. And this means that if they're operating as you, they're going to have all the permissions you have. If there's any security issues in your enterprise, they're going to find those. That's a huge problem. The second thing that's going on is that these models have gotten really smart. these agents are different from traditional software in that they have their own brain, right? Which is these models. So with traditional software, you knew exactly it was going to call this next piece of software through an API. It was going to have very, very fixed deterministic behavior. But these agents, they have a brain of their own, and these brains are getting smarter and smarter. And the models have gotten so good these days at what's called long horizon reasoning without hallucinating, right? They're able to go deep and find issues as a result of that. So when you put all these things together, you're in this interesting scenario where, on the one hand, you've got this massive productivity boost, but when something goes wrong, it can go spectacularly wrong. So it's honestly a great time to be working in the security industry and trying to bring all of this chaos under control. So we started off on this journey. We've been in the agentic journey for a year and a half now. Earlier this year, we acquired a company called Natoma, which does bring some governance to MCP. We're building on the back of that. We've now got an AI gateway that is coming out in the market this month. And this AI gateway gives you everything from protecting the model, protecting the agents and integrating down to your data stack. So it's the full shebang. We've got our own experience for the last year and a half how we've modernized or further agentified our enterprise. And so we want to take that even further for our customers and we're super excited about that.
Gemma Allen
>> We hear a lot about MCP. It's become a real buzzword. We talk about it every day here on the show. It seems as though, again, every company is building towards this. If they're not already trying to execute on this strategy. We also know that it's a different kind of vector from the perspective of security. How do you think about it, Vivek, from the perspective of your footprint, your ecosystem and the interoperability elements? What does it mean from a governance perspective?
Vivek Kumar
>> First of all, we all are fighting the same enemy. So over here, the partnership is a big key thing. You know, the MCP adoption is happening faster and more rapidly than your security controls. So the problem what is happening is that there are a bunch of MCP gateways people are using, which you are not even aware of. And it's very hard to keep track of it and govern it and find it where it is. And it is creating a big issue in any industry from a security perspective. They should be going in through one governed MCP gateway so that security can watch it and do things. So as you said earlier, if an enterprise level attack coming in, it looks like a legitimate thing. But although it's an attack, it's no longer a traditional thing, what Mayank was talking about earlier. Because now, through the MCP gateway, all the things are going out, looks like a good thing, legit thing. one agent is talking to another agent, delegating it to a third agent, delegating it to a fourth agent, and that delegation is working in such a manner that it's very difficult to govern and audit that piece. So, MCP gateways and all this, although it's the best thing which has happened, if the governance is not in place, then you are going to lose visibility and get into some kind of a big problem. And there were a lot of things that happened with the GitHub and other things which you saw. And they were all because of these breaches that happened because of these chains of delegations and multi -agent functionalities and MCP gateways.
Gemma Allen
>> I mean, let's stay on MCP for a second, but let's talk a little bit about models because it's a very interesting evolution, right? We know that in some respects, MCP, it opens the floodgate to all sorts of different accessibility vectors, right? Models, we hear a lot about Anthropic. We hear a lot about OpenAI. We hear a lot about the security level of openweight models versus the models we're more familiar with here in the US. What are your thoughts, though, from the perspective of the kind of non -negotiables from a risk perspective, especially at a company like Snowflake, where there has to be some clear parameters around what can and can't happen, what can and can't engage?
Mayank Upadhyay
>> Yeah, look, first and foremost, we like both proprietary models as well as openweight models. So we can get that out of the way. We like to use them both. You get a lot of benefits from the open -weight models. As a security team, you don't have constraints when you're doing an investigation, when you're doing threat modeling. Also, from a cost governance perspective, they're so much better. The other thing which is a non -negotiable for us and for many of our customers is that they want their data to stay within their perimeter. So as you work with these models, you kind of have to make sure the data doesn't accidentally end up with the model provider in a way that might get used for training. And I know everybody has lots of different architectures for this, but it is the crown jewels that our customers have. And so that is a non -negotiable for us. So a lot of the ideas behind what we're rolling out right now with the AI Gateway are meant to give you that data separation, the visibility. You might use the word visibility, use the word trust. Trust comes from transparency and predictability, right? So with our AI Gateway, we want to give you that observability so you know exactly what's going on in the agent and the model. And we're watching it to make sure that nothing bad is happening for you.
Gemma Allen
>> And you have a complex network from some perspective, right? there are different folks who use many different technologies, many different APIs, many different tools. And that's probably only going to get even more diluted as this world of AI and inference expands. How do you think about it from the perspective of accessing the data and then securing the data once it's in the hands or in the presence of whatever actor you hope or deem it to be?
Vivek Kumar
>> So this is very critical because data is all very important. You can't build an AI layer without having a data security layer in place. Because the AI sits on top of data. The problem happening is these MCP gateways and the models and all, it's a new thing which is now turning into a shadow AI thing. Even the MCP gateways, people are using models, people are using MCP gateways, they are downloading things, and they are creating agents. Suddenly this is becoming a shadow AI kind of thing for us. It's a big problem. Agents, when they talk to a different agent or another agent, they have a capability of escalating their privileges. So all of these agents are doing a lot of different things. So you are really scared to see that your data, your critical data, your PII information, your financial information doesn't get pasted and it goes out of your boundaries. So the cross-border and cross-organizational boundaries should not be overlooked. And that's the main concern when this is happening. And it is very, very important that for that not to happen, you should know what kind of gateways you are using, what kind of models you are using. and all the agents, what actions they are doing. They should be least privileged actions. What I mean is that if an agent is supposed to do a task, he should only get the permission and escalation to only do that and then it dies down. You cannot have long-lasting controls given to them to perform the work. So definitely you have to build the governance, as Vivek was talking about it.
Gemma Allen
>> But how do you truly do that? there's obviously governance there's compliance it's sandboxing first what are you truly doing to ensure that whoever it is or whatever actor it is is trying to access data it's not just about verification it's abouteverything that comes after that also
Mayank Upadhyay
>> i'd probably mention four different things to you on the one hand you have sandboxing which makes sure you can do stuff least on your disk, steal secrets if you're going out to the network we know exactly where you're going. I would throw MCP governance as a perimeter control because you can see who's talking to what MCP tool. Are they allowed to talk to that MCP tool? The next layer I talk about is the identity layer. When you have an agent acting on your behalf, you don't want it to act with all your permissions. If you've been at a job for five years and changed different roles, you probably picked up a whole bunch of permissions along the way, right? You don't want to give all of them to your agent because an agent is going to try each and everything it can. Even look at paths you didn't think it might, right?
Mayank Upadhyay
>> Right.
Mayank Upadhyay
>> So the first and foremost thing you need to do with identity and where we're headed now is we're coming up with new standards. So when you kick off an agent, you can say, hey, here's a scoped set of things you can do on my behalf. It's a little bit like, say, you know, I like to think of agents as interns. They're untrained employees. Right. Now, let's say you're a company. you had an office manager intern who was supposed to go buy you a new printer and you send them off to get a printer. And they came back with this Wi -Fi controlled refrigerator. Right. So what do you do instead? You give them a gift card for Best Buy, which is set to $200. So you put those constraints in place and say, here's what you're allowed to do. So even if you veer off where you're supposed to be, it's not going to be catastrophic. It's going to be more or less within those guardrails I set for you. So those are the kinds of primitives that we're coming up with in the industry. And we have to make them easy for people to use. So again, you can use AI to say, hey, you're asking your agent to go research this topic for you. I think it's going to need to look at all these tables. So let me scope permissions to read -only permissions to just those tables. So that's a way of sort of making sure it doesn't go off and do something on its own. So that's the second big thing I think that's coming. And I just want to quickly mention, I think we also have to come and take care of more of the observability and detection techniques. And we can talk about that.
Vivek Kumar
>> That's what I was talking about. The agents have least privilege. because the number of non -human identities, which are the AI agents, is growing faster and more rapidly than the human identities. You can control human identities based on their birthrights and whatever permissions and access, privileged access they have, but in an agentic space for the AI agent, it's very difficult to do that. So with somebody coming up, Snowflake coming up with this kind of security control, identity becomes a very key, key factor for us.
Gemma Allen
>> And that non -human identity where there's multiple versions of a human based on a workflow or a task, right? That's a complex security system and ecosystem, too, to oversee. And you mentioned observability. That also changes the game fundamentally from managing someone on a domain level to managing somebody or an actor, I guess you can call it, in multiple proliferations. Yeah. How do you think about that? Is that when we really boil that down, does that come down to governance and compliance and very clear standards of execution? Or is it something more complex than that?
Vivek Kumar
>> It is complex because, as I said, it's changing very rapidly, very dynamically. The entire identity and access management system was based on human identities. It has a paradigm shift now and also it's growing. Plus, you don't even know what they are doing. So people are concentrating on the action, what the agent did, but you also need to see who authorized it, who gave them that permission to do it. So there are a lot of other complex pieces which were missing, which have to be incorporated in terms of this AI. Another thing you talked about, the sandboxing, just want to touch upon it. What I see as the problem with the agentic AI and the whole AI thing is, you are sending a kindergartner to college directly, right?
Gemma Allen
>> I love that.
Vivek Kumar
>> Yeah, you have to go through elementary school, middle school, high school, and then to college. So if you take anything which has just come out in the market and not sandboxing and not testing in your lab, suddenly implementing them in your production environment, you don't know what is going to happen, right? And it creates, one creates other issue, another issue and all. The scale goes so big that it will be difficult to control.
Gemma Allen
>> You mentioned something very interesting, which is observability, right? and the roadmap of a company like Snowflake. Because again, the expectation is also shifting. There was a time when we were so excited just to be able to access data, to be able to see the data in some sort of concrete and succinct way. But now, the role 10 years from now is going to be about observing the data. Who else is watching that data? How do you think about that from a company perspective? What does that roadmap look like? Who owns that problem?
Mayank Upadhyay
>> Yeah. Yeah. So, look, I think a lot of traditional security vendors are all moving very fast to try and fill this gap. At Snowflake, we just announced our Cortex AI Gateway, which is going to sit right between any agent from any company and the models you're using. So it just slides right into your architecture and it gives you that observability where it can see what these agents are doing. And there's actually two sides to the observability problem. Obviously, you want to make sure your agents are not misbehaving, right? So if it's a well-behaved agent that's going through this, you can look at what's called its traces, its trajectories, and you can see, is it doing something it shouldn't be? But there's a different side of observability, where what if there's an agent running in somebody else's environment that's now breaking through your perimeter and entering your enterprise? You have to catch those too. So while there's this whole new category of agent observability to make sure your agents are well-behaved, there's also the traditional security world of just building detections into your perimeter, fixing your security vulnerabilities so agents outside don't find ways to get inside your perimeter, right? And those have to be taken super seriously. And there's probably a limited amount of time for enterprises right now to go and patch these. So using AI to find these vulnerabilities, to patch these vulnerabilities, this is the time to be doing all of that.
Gemma Allen
>> I want to go back to something you said at the beginning, which is very relevant to your industry too, right? because financial services is very secure and we're hearing a lot about companies going back on -prem, sovereign AI, bringing actually AI to your data as opposed to bringing your data to AI. From the perspective of Snowflake, and I'm going to put this to both of you, what does that mean in terms of what you're building towards? How nuanced and different is that from a security perspective? Or is there kind of a universal security guideline around what it means to have data on -prem versus in the cloud, and how folks are going to go about, again, managing, monitoring, and continually observing what's happening with it?
Vivek Kumar
>> So it's a great question. And every day we are exploring new things. First of all, you need to know where your data is to secure it, to manage it, right? So as you said, bringing data to AI or bringing AI to your data. So that has become a big challenge. First is we need to know where your data is lying, or which data lake it's sitting in. It's always scattered all over the place. Agents, as you know, they have a very privileged access to go and talk to other agents and try to dig in and go everywhere. And the problem is that if there is an agent sitting outside who can come into your environment and can have access to the data through the agent which is inside, which is a legitimate agent, is a problem. So we have to secure our perimeters. We have to make sure where our data is and make sure that that is secure. The governance and the guardrails are the biggest things which we have to work on this thing. That how data needs to be treated and who can treat it and what kind of permission that person or agent has for that data. And it has become very important. The SIEMs of the world where they used to do the detection, like discovery and detection, all was based on very traditional environment. It was not based on the AI agentic environment. So you have to go and change. So you have to change from identity perspective, data security perspective, sensor perspective, governance perspective, policies perspective. Everywhere there is a change to see that how data can be accessed, who can access it, who authorizes it, what kind of identity and governance you have for them.
Mayank Upadhyay
>> So if I could add to that, Gemma, my take is that going back to on-prem is not the answer. The way the world is headed, everything is interconnected. Unless you're a three-letter government agency that is operating in complete secret, I think in general, you would expect people and companies want to have more trade, more commerce between them, right? And people are talking about agents going and doing shopping for you. So I think these are bringing more efficiencies into our life on a daily basis. So I think they, and even if, look, the moment you expose yourself to working with partners and interacting with systems outside, there's a threat surface there that you have to worry about that can be attacked. So I think you have to go back to the basics. And the basics don't mean going on-prem. It means finding and fixing your vulnerabilities, putting detections in place so that if you're compromised, you can detect that at machine speed and you can remediate at machine speed. There's also a super interesting and simple technology called deception. It's kind of like, okay, let's say you have a giant house and you've got lots of doors and windows and you can't put a burglar alarm everywhere. Well, guess what? You can get a big safe in the middle of your house. So if a burglar gets in, they zoom in on that safe. And the moment they open that safe, the alarm goes off. So there's lots of interesting tricks to deal with this. And I think we're headed to a world where the basic security practices about cleanup and vulnerability patching and management, as well as detections and remediations, have to be carried out at AI speed now.
Gemma Allen
>> So last question, and I love when somebody takes a position on something. we hear a lot about the move back on-prem though, right? And maybe that's built on a false assumption, or maybe there's a whole administrative layer that was never fully fixed in the era of cloud that is now suddenly coming home to roost somewhat from the perspective of security. And it feels like it's an easier solution when, in fact, maybe it's not the long term solution companies need. Right.
Mayank Upadhyay
>> That's right.
Gemma Allen
>> But how do you and I'm going to put this to both of you as you move forward, right? These are both fascinating companies, industry leaders. How do you think about the messaging around what's happening in this industry, conversations like that one and the role of companies like yours to in some way lead folks forward at a time where there is so much conflicting information and so much worry?
Vivek Kumar
>> So I would agree with Mayank. On-prem is not it, you can't move two steps backwards and one step forward, right? Because of all the SaaS platforms and everything coming up, you can't go back on-prem on a lot of things. Yes, there are certain things you can still go back, but again, are you going to increase your footprint, which again involves a lot of cost, right? So you may be focusing on the wrong thing if you want to go back to on-prem. Some people say that it could be safer than sorry, but that's not how it is, because the whole world is open to the SaaS platform. We are using a lot of these kind of tools and techniques and software now, bringing everything back to on-prem will not be a solution. It will be a very, very expensive solution, though. So what we need to look at is that whatever things we have, like Mayank was talking about vulnerability management and all that kind of thing. I was talking to one of the CEOs saying, it's no longer a zero day. It's all minus one day, minus two day, right? So fixing the vulnerability comes next, but patching process has to be very proactive. So in this environment, you have to be very proactive. You should know where everything is. If you have that observability, you have that visibility, then proactively go and face it and attack it and solve it rather than thinking backwards going to take the workload to an on-prem solution.
Gemma Allen
>> Let's stay on patching and I want to finish with this. If we just take meetings as an example, right? We know that there are huge vulnerabilities detected across operating systems at large banks, large enterprises. We also heard that the fix from a patching perspective, could take anywhere from six to nine months. In a minus two, minus one day scenario, that's an alarming reality. How do you think about that? What are your thoughts from the perspective of where we're at right now, the pace of where we're headed, and the gap?
Mayank Upadhyay
>> I think the way software patching has operated in the past is changing now. Right now, not only can AI find vulnerabilities, it can also suggest fixes. and some of the cutting -edge models have a very high acceptance rate when they suggest a fix the developers like it like you know people are talking about upwards of 85 percent acceptance rate right so we're getting to a world where traditionally when you found a vulnerability you would have a long argument about is it actually reachable does it matter do you have other mitigating controls in place right or if you had open source packages you would think about hey, how do you get this package to be upgraded? Is somebody even maintaining it? But in the new world, you can have software -generated fixes. It's like a three-line fix. Just roll it out. Don't even bother debating it, right? Or if it's a small open -source package of 300 lines or less, which is the bulk of them, and nobody's maintaining it, can you just get AI to rewrite it for you? So there's all these options which have opened up, and I think security teams have to think differently in this new world.
Gemma Allen
>> Wow.Well, we certainly hope that they will and that the world remains protected. So folks, fascinating companies, fascinating time, great conversation. Thanks for joining us on theCUBE and NYSE Wired.
Vivek Kumar
>> Thank you very much. Thank you for having us. It was great. Thank you.
Gemma Allen
>> I'm Gemma Allen here at theCUBE Studio at the New York Stock Exchange. This is Cyber Security Leaders, one of our programs with NYSE Wired. We connect Silicon Valley to Wall Street. Thanks for watching.