Kapish Vanvaria & Dan Mellen, EY
In this interview from RSAC 2026, Kapish Vanvaria, global Americas risk consulting leader at EY, joins Dan Mellen, global chief technology officer for cyber at EY, to talk with theCUBE's Dave Vellante and Christophe Bertrand about how the rapid deployment of agentic AI is outpacing governance and widening the trust gap that security leaders must close. Mellen anchors the challenge in EY survey data: 96% of organizations have AI in their cyber defense strategy, while 95% are deploying AI broadly across the business — yet controls, training, and governance are consistently lagging behind. Vanvaria introduces "trust by design," a model that embeds cyber, legal, and compliance stakeholders into product development from the start rather than applying governance after the fact. He also flips the conventional framing, arguing that the most capable organizations will position humans at the center and let AI operate in the loop around them. The conversation also explores how agentic AI is reshaping security operations in practice — from AI-augmented SOCs and automated third-party risk management to the traceability challenges that emerge when autonomous agents inherit and act on human entitlements. Mellen references EY's joint announcement with CrowdStrike and NVIDIA to deploy an AI agentic SOC as a concrete model for embedding responsible AI principles natively into security workflows. Vanvaria argues that the profession must make a fundamental shift from a defensive posture to an offensive one, using AI to hunt threats at machine speed. From a projected 5X increase in cybersecurity investment to the reimagining of roles like pen tester and threat hunter, the guests outline a roadmap for how organizations can move at the speed of trust without repeating the governance failures of the cloud era.