The rapid adoption of AI is reshaping enterprise security. While organizations are racing to adopt agentic AI and new development methodologies, the biggest challenges are not entirely new. Instead, AI is exposing long-standing weaknesses in cyber hygiene, asset management, and security processes while dramatically accelerating the speed at which organizations must respond.
Tech Channels sat down with Infoblox CISO Henrick Smith during Black Hat to examine how AI is changing software development, cost management, security operations, executive decision-making, and even the role of cybersecurity vendors. Smith emphasized that AI should be viewed as an accelerator that augments human expertise rather than replacing it.
Q. What is the biggest security challenge organizations face as AI adoption accelerates?
A. I think the balance that we're like facing right now, and every CISO and every company is facing the same balance, is that everything is moving so incredibly fast. Agentic security, agentic use in general, like agentic developers, agentic designers is moving at lightning speed."
What it's highlighting is not that everything is moving faster. What is highlighting is that you don't have control of your basic hygiene. Because if you had control of your basic hygiene, it wouldn't be an issue because you would just fall into the same pipeline as everything else.
Q. Is AI creating entirely new security problems, or exposing existing ones?
A. Mythos is a good example where it's highlighting two things. It’s highlighting there is a new frontier of security that we weren't aware of before, things that we did not know were exploitable or could be a risk. But a major portion of it is because people alone couldn't do before. It augments you as a power tool versus being replacing you as a human. We're still going to need humans. The developer has already stepped away. The only time they have to step in is if we still can't fix it. It augments us. Did it go away? Not in the way that people think.
A lot of it is highlighting that there's a backlog you knew about. You just hadn't prioritized it. And in many cases, not prioritizing it was valid because it could have been low or medium risk. Perhaps you have code you’re not using. But suddenly, you have something that is calling it out visibly and loud into the world. That's where the challenge is now. Is that not that everything is new, not that we didn't know about it, it's just being called out in a different way then highlighting the gaps we had in our processes before.
Q. How is AI changing the way security teams work?
A. AI models are incredibly powerful. They're really good at finding things they might not have found before. In many cases they're really good at finding things that we would have found, they just find it so much faster. It doesn't replace the humans; it augments them. Once we have the information AI models provide, we can really dive into it to see what's happening. We're still going to need humans. The developer has already stepped away. The only time he has to step in is if it still can't be fixed.
Q. How will organizations manage the growing cost of enterprise AI?
A. There will always be an extra cost. We have to understand where we're offsetting it. I don't think we offset it by getting rid of humans. We offset it by enabling humans to do a lot, lot more. We also have to train the people in how to use AI models. Start with a model that is cheaper. If you run into problems then use this model. You have to learn how to use the right thing for the right job. Or it will cost you.
Q. Will attackers face the same AI cost pressures as enterprises?
A. They are going to run into the same cost model. It's just that they're not going to be paying for it. It’s going to be like bitcoin mining, using someone else’s account to support it. We’re going to see a mix of people misusing and hijacking other people’s accounts. A lot of the attackers are using the open weight models. They are incredibly capable. You have less capacity, but you don't have any cost constraints.
Q. How is the conversation with customers changing?
A. We are a cyber company. We're still traditionally seen as a network company. We are talking more to the CISOs than we're talking to the network teams."
That information is invaluable for security. If you're not paying attention to what's happening on the network, you're losing out on a ton of information. The first thing you're going to see is the DNS. If you can catch it there, you catch it way before it goes anywhere else.
Q. Are more business executives becoming involved in cybersecurity investments?
A. Yes, I think that's actually really good. We've had a long period of time where security has bought a ton of different agents. There's a lot of overlapping technology. You bring in a different awareness. You bring in a different intentionality. Why are we buying this? What is the value we're getting from it? I think it's good. It teaches people to motivate why they need something.
Q. How does involving finance improve cybersecurity decision-making?
A. That awareness brings a different light to the products. Intentionality is amazing, being able to say why you want it. If you have to say that to your CFO, it raises the bar. It helps to tell the story.
AI is not changing the principles of cybersecurity as much as it is accelerating the pace at which organizations must execute them. While agentic AI, frontier models, and autonomous development introduce new capabilities and new attack paths, they also expose longstanding gaps in cyber hygiene, asset visibility, and operational discipline. Organizations that have invested in strong security fundamentals will be better positioned to absorb these changes, while those with unresolved technical debt will find AI amplifying existing weaknesses rather than creating entirely new ones.
Smith’s pragmatic view of AI's impact on the workforce has AI is emerging as a force multiplier that automates repetitive work, accelerates analysis, and allows skilled practitioners to focus on higher-value activities, rather than replacing security professionals and developers. At the same time, to realize these productivity gains organizations must develop new competencies—from selecting the right models for the right tasks to managing AI costs and integrating AI responsibly into development and security workflows.
.png?width=1816&height=566&name=brandmark-design%20(83).png)