Article

The Next Stack: The future of AI in cybersecurity

Thomas Krane, William Blackwell | July 28, 2026| 9 min. read
the next stack cybersecurity

As AI models continue to improve, the speed and scale of AI-based vulnerability identification and response are profoundly different. Previously, an organization may have had 30 days or more to remediate a known exploit or zero-day. Now, vulnerabilities are being exploited before disclosure. At the time of publishing, the mean time-to-exploit (TTE) is -9 hours according to the Zero Day Clock, and over 80% of vulnerabilities today are exploited as zero-days before disclosure, up from around 30% five years ago.

We believe cybersecurity will follow the broader AI trajectory as model capabilities reach the point where they can independently complete a full day of human work, and as the focus of AI advancement shifts from software to labor.

the next stack cybersecurity

The reality is that CISOs need to adopt an AI-native mindset, using AI to discover and prioritize remediation of attack paths and exposures, and to automate cybersecurity workflows and response procedures to move at ‘machine speed.’ We believe the benefits of this shift will not be evenly distributed across vendors. Deeply embedded control points — for example, for the endpoint, identity, certificate infrastructure — remain defensible. However, analytics, reporting, and workflow products face a greater risk of disruption as enterprises explore the opportunity to build their own.

As interfaces consolidate and shift toward headless architectures, we expect the management plane and domain-specific agents to offer the greatest opportunity for startups and ScaleUps — and where defensibility will stem from network effects, proprietary data, and brand rather than single features.

From one enterprise cybersecurity leader Insight Partners recently spoke to, the sentiment is echoed across the industry:

“The opportunity is to transform from a manager of a set of tools, to a manager of agents… you go from analyst to engineer. Otherwise you’re looking for another job.”

Significant AI trends impacting cybersecurity

We believe these three specific developments in AI have a significant impact on the future operating model for cybersecurity.

1. Agent and app building

Individuals can now build applications and agents themselves, which includes the security team. Insight Partners recently spoke to a Deputy CISO who has five agents working for them around the clock. This is a huge accelerator for cybersecurity teams and also may lead some CISOs to question the value delivered by certain features in vendor offerings. Why buy that product feature when you can easily build it yourself and tailor it to your use case?

Why buy that product feature when you can easily build it yourself and tailor it to your use case?

No one is likely to vibe code a CrowdStrike. There are network effects and data moats that mean that companies like CrowdStrike and SentinelOne* should continue to have an advantage over things you can build yourself today for that control point. But there are features and workflows that currently sit within code in vendor products that might be advantageous for enterprises to refactor themselves, highly customized to their individual operating models.

This raises three questions for security leaders and builders in the space.

  1. Which workflows will security teams delegate to agents? And therefore, how do the security team members’ roles evolve?
  2. Which product features will become more or less important in a world where AI is enabling the development of fully tailored software?
  3. Where will security teams build those agents and applications? And how much of it will be full build versus extending platform agent-builder capabilities, or simply buying into an agent-native vendor ecosystem?

To attempt to answer these questions, we first need to discuss the other trends driving change in the industry.

2. The shift to headless SaaS

As agent adoption accelerates, software is becoming increasingly headless. In April 2026, Marc Benioff announced a headless Salesforce, declaring “Our API is the UI.” Even before that, we’d heard from several founders whose teams haven’t logged into Salesforce for months. Everything is driven by automation and agents.

Cybersecurity is seeing a shift in that direction as well. Sysdig* can be used as a headless cloud security product. Trench has built a headless SecOps product. And others have built Model Context Protocol (MCP) servers to enable agents to pull data from their solutions.

Beyond the vendors, Notion’s security team built an agent called ‘Scruff’ that runs autonomous incident investigations. They no longer log in to Wiz*, CrowdStrike, or Scanner through a browser as part of those workflows. Instead, Scruff pulls the data via API and MCP for the security team to act on.

We’ve spoken with other CISOs in our network, including one who has built connectors from Claude to Wiz, Azure, and other security tools to surface data for analysis through the Claude interface. It’s clear that the days of multiple UIs are ending. We are heading toward a world where the API is the UI for most products. What remains is the single management interface that allows the security teams to visualize and interact with their increasingly headless security stack.

In a world where the API is the UI, what becomes the management interface?

3. Expanding cybersecurity capabilities of frontier models

Finally, we get to the frontier labs themselves, the most active in cybersecurity being Anthropic*, OpenAI*, and Google. What role will the frontier labs have in the future cybersecurity stack?

Many cybersecurity capabilities — both vendor-led and custom-built — will leverage models from the frontier labs to sift through increasing volumes of data and uncover novel trends and attack patterns. But there’s a more direct threat to many of the startups in the ecosystem today: frontier labs encroaching on their domain.

Frontier labs could compete directly by releasing security-specific capabilities — Claude Code Security and Codex Security from OpenAI are early examples — or indirectly, by lowering the bar for security teams to build their own custom tools or agentic workflows. Platform companies could accelerate both paths further by embedding these capabilities into their existing products. Most recently, at the time of writing, Cisco Cloud Control includes a marketplace for agents and applications built on the platform. The platform itself is using OpenAI Codex.

Going back to the theme of AI shifting from software to workforce, there is an opportunity for the frontier labs to become the center of work for cybersecurity teams. What remains are the solutions that provide the data, context, and initial correlation and analysis outside the reach of the frontier labs. Revisiting our examples from before — SentinelOne and CrowdStrike — these solutions are deeply embedded into the endpoint and provide rich telemetry and initial blocking and tackling of direct threats on the devices they protect.

Solutions like Keeper*, Delinea*, and Keyfactor* that provide identity, authentication, and certificate infrastructure are also likely to be at lower risk of disruption. These are companies with deep technical expertise that are the infrastructure and control points of the cybersecurity environment. However, anything that is essentially an analytics, reporting, or workflow product could be at greater risk of disruption.

As a side note, we should not ignore the potential role of small language models (SLMs) and open-source models in this future state. We have seen increasing interest in SLMs tailored for specific use cases owing to the fact that they are typically more efficient to run and can be tailored to produce above-par results for specific tasks, and trained on the context of the organization and use case. Open-source models also provide a potentially cheaper option (in terms of inference costs), but with the leading open-source models coming from China, this raises questions as to how secure those models might be and ultimately to what extent enterprises can effectively secure them if that is indeed a requirement.

The Next Stack for cybersecurity

The Next Stack is built for agents from the ground up. That means a strong data foundation, AI-first architecture, and technology that agents can actually access through open interfaces.

We’ve alluded to these already, but we can separate the Next Stack into three layers, as shown in the diagram below.

the next stack cybersecurity

The three planes can then be described as follows:

The data plane

The data substrate where all data relevant for the cybersecurity operating model is stored and analyzed. This will typically be implemented through a security data pipeline (e.g., Databahn) and a data lake (e.g., Databricks*).

The management plane

The orchestration and reporting layer of the environment. This is where the SecOps team operates, building and managing agents that orchestrate across the security control environment, and managing the centralized context layer for those agents. We anticipate the management interface for SecOps teams converging into a single interface. The management plane extends down to the control plane through the definition of domain-specific agents described below.

The control plane

The solutions on the front line that provide the control points in the environment across the typical security domains. Every domain itself is operated by domain-specific agents that are orchestrated by the management plane to enforce consistent policy across the enterprise. We also introduce defensive and offensive agents — essentially the red-team/blue-team members. The control points themselves will be implemented using the technologies we know well today – firewalls, Endpoint Detection & Response (EDR) capabilities, Identity Providers (IdPs), cloud-native application protection platforms (CNAPPs), email security solutions — but in an agent-native, headless architecture.

An example of what this could look like conceptually in an enterprise is shown in the diagram below.

the next stack cybersecurity

In the future cybersecurity operating model, the role of security operations will shift toward building, managing, and coordinating fleets of orchestration agents that ensure consistent implementation and operation of policy across the stack, while coordinating changes based on regulations and risk profile, almost like a governance, risk, and compliance (GRC) function, and domain-specific agents. Domain-specific agents require deep subject-matter expertise to ensure that the control points within that domain function effectively, and those same experts will be expected to step in to manually triage where things break down.

Questions for innovators in cybersecurity

So what does this mean for cybersecurity innovation? Let’s attempt to answer the questions presented earlier in this article.

Which workflows will security teams delegate to agents?

And, how does the role of those security team members evolve?

Our perspective is that, like all enterprise work, the first workflows to be automated will be those that are repetitive and analysis-heavy: alert triage, threat report summarization, and access reviews. That is already happening in many enterprises.

Beyond that, we expect to see more complex workflows shifting to agentic capabilities — architecture reviews, offensive security testing, threat hunting — capabilities which are already accessible through innovative startups today.

Ultimately, as more workflows are handed over to agents, the role of the security team is elevated as they become the in-house experts tasked with building and training those agents — along with agent skills — to be able to operate within the unique enterprise environment, and also to act as a manager of agents, ensuring that those agents are executing as they should. We also expect agents to continue to require human oversight and a human-in-the-loop, particularly for critical decisions where there is a potential risk of disruption or impact on security posture.

Which product features will become more or less important in a world where AI is enabling the development of fully tailored software?

As frontier labs enable the democratization of bespoke interfaces and agent workflows, we may see enterprises building their own human interfaces in place of the previously singular dashboards across multiple products. We may also see the development of bespoke analysis and workflow execution agents — and although not every organization will want to build their own, this does mean that the bar for what is considered a value-add workflow in a product is significantly higher.

What becomes more important are some of the product moats around network effects, proprietary data that cannot be sourced from within an enterprise, and brand (there is unlikely to be appetite to trust a home-grown solution to block highly sophisticated attacks at the perimeter of the network).

Where will security teams build those agents and applications?

And how much of it will be full build versus extending platform agent-builder capabilities, or simply buying into an agent-native vendor ecosystem?

We continue to see platform players releasing agent-builder capabilities, including Microsoft’s Security Copilot custom agents, Palo Alto Networks’ AgentiX, CrowdStrike’s Charlotte AI AgentWorks, and, most recently, Cisco’s Cloud Control Studio. These platforms have also developed marketplaces enabling customers to leverage third-party agents and applications.

Few enterprises are building full-suite capabilities on these platforms today, but that could change. Builder platforms make it easier to create applications and agents, and crucially, to integrate them into existing IT and security stacks. That integration advantage may ultimately make building within a platform more practical than using a third-party agent builder, in which teams would otherwise have to set up those connections manually.

As with previous technology shifts, we expect a balance of build versus buy. Some enterprises will lack the skills or resources to build the best-of-breed agent capabilities needed, or simply choose to buy products with agent-native capabilities and integrate them as part of an ecosystem. We also expect many vendors to refactor their solutions into agent marketplace offerings, ensuring their latest product capabilities are available across various platforms.

In a world where the API is the UI, what becomes the management interface?

One thing is clear: We do expect to see a consolidation of the many security interfaces available today into a singular interface. However, whether that management interface is custom-built or built on top of a technology platform remains to be seen. We expect to see a mixture of both formats.

What is the role of the frontier labs in the future operating model?

The frontier labs will have a critical role in the future cybersecurity operating model. That is, both as the models that will underpin the agentic infrastructure and, in some cases, as an interface to the security stack. We believe there will be a mixture of security teams that choose to leverage their core technology products as a control plane for agents in the security stack, whilst others will opt for end-user-developed agent applications built through frontier lab solutions, connecting the security stack back to those desktop applications using custom or pre-built connectors.

As noted earlier in the article, there is potential to adopt SLMs and open-source models that can be fine-tuned in the enterprise environment and operated at a much lower price point. However, we are early in adopting open-source models for cybersecurity. Today, most use cases are implemented with frontier models.

What this means for startups and ScaleUps

Startups and ScaleUps need to clearly understand where they fit within the Next Stack, and which features are truly defensible versus those that will be consumed through custom-built solutions. Where there is defensibility, the goal is then to determine how that capability should be integrated into the future agent-centric ecosystem, either as an independent product or as part of a platform-delivered marketplace.

Looking across the Next Stack in more detail:

  • If you’re in the control plane, you need to ensure your services are easily accessible and consumable by AI agents. We believe the companies that win here will not only have the best technology but also integrate seamlessly into the agent-native ecosystem.
  • In the data plane, the data lake itself is likely for the incumbents, but we’re seeing a range of innovative startups that provide quick data parsing and data search that may act as a shim to accelerate interactions between the data substrate itself and the agents accessing that — effectively the data pipeline between the agents and the data lake.
  • The management plane and the extension of this down to the control plane through domain-specific agents is where we’ll likely see the most disruption and opportunity for innovative startups. Focusing on being a best-of-breed agentic harness and orchestration solution that drives more consistent, accurate, and faster outcomes beyond what enterprises can develop themselves, either independently or with third-party service providers, will ensure ongoing relevance in this agent-native Next Stack.

We are seeing unprecedented technological change driven by advances in AI, which continues to impact every aspect of how work is done – including in cybersecurity – and we are excited to meet with founders building for this agent-native world.


*Editor’s note: This post contains forward-looking statements and predictions regarding the future of AI. These statements are based on our current expectations and assumptions, and actual results may differ materially from those expressed or implied in these statements. The information provided in this post is for informational purposes only and does not constitute financial, investment, or professional advice. This post should not be considered as a recommendation to buy, sell, or hold any particular investment or security. Investments in AI and related technologies involve inherent risks, and past performance is not indicative of future results.

Insight Partners has invested in Anthropic, Databricks, Delinea, Keeper, Keyfactor, OpenAI, SentinelOne, Sysdig, and Wiz.

Quotes in this article have been sourced from industry conversations and given with permission.