TechChannels Expert Insights

Q&A: N-able Chief Innovation Officer Robert Johnston Business Tackles Resilience, AI, and the Mid-Market Security Challenge

Written by Teri Robinson | Aug 17, 2026, 7:22:29 PM

Organizations, particularly in the mid-market, are rethinking resilience as cyber risk accelerates. Business resilience is a combination of proactive protection, real-time detection and response, and recovery, rather than a single security capability.

Tech-Channels met up with N-able Chief Innovation Officer and Chief AI Officer Robert Johnson at Black Hat to continue a conversation that began a few short months at RSA about where SMB and mid-market organizations remain underprepared, how regional and community banks are changing their technology posture, and why AI is likely to compress attack timelines dramatically. Johnston argues that AI should ultimately be used to remove low-value work from security teams while enabling faster, more automated defense.

Q. What does business resilience mean in practical terms?

A. The business resilience [solution] we’re selling to our customers has got three fundamental components–a proactive component, a real-time component, and a reactive component.

The proactive component is unified endpoint management, the blocking and tackling of basic sectors, vulnerability, patching, management, secure endpoint management. You must do that component to stop breaches before they happen. The real-time component is MDR (Managed Detection and Response): security operations, detecting and stopping breaches while they occur. The reactive component is data protection and our co-product recovery.

Q. How do mid-market customers think about resilience differently?

A. If you are a mid-market bank, or you are an e-commerce company, or dentist office, or whatever it is, they don’t care about what product category is being sold. The dentist office wants to know that they’re protected and if something happens, you'll stop it. And if that fails, because this is a security business and it's hard, they can recover and get back to being in banking or being in e-commerce or cleaning teeth. That is the power of business resilience.

Q. Where are mid-market organizations most often underprepared?

A. The real time protection is distributed. So, the MDR category is still emerging and growing. There's heavy adoption, especially in the MSP space. In the midmarket, they have bought EDR security tools and they have backup. Oddly enough, you'd be surprised how many midmarket companies are unable or don't have a tool to do secure endpoint management. A lot of banks are still using GPO and Active Directory to do everything. It’s shocking. It never occurred to them that they can buy a tool that's not GPO and Active Directory to manage software, install software, do patching and scanning.

In the midmarket, like SMB and in the MSP space, of course, they're using RMM and secure endpoint management, but like in the midmarket, that part was forgotten about.

Q. Why are regional and community banks becoming more willing to adopt new technology?

A. There are two categories of banking—the big banks like JPMorgan and Bank of America, but everything beyond those top 15 banks gets categorized in community and regional banking. And, it's very much a story of David and Goliath. The majority of banks in the United States are regional and community banks, but 90% of deposits are in the big banks,.. So you have this constant effort by the region and community banking to come up with banking products to compete with the technology advancements of the big banks.

Banking is historically a slow industry to adopt technology, like Defense was. But now you see a scramble for survival in a lot of ways in community and regional banking where a lot of these guys are willing to take swings on just about anything when it comes to a fintech product or a banking product in order to provide a better experience for those customers, so they can compete with the big ones.

Q. Where does AI create the greatest productivity opportunity in security operations?

A. In every job, there's not just one thing you do. There are over 50 things you do. I really want you doing the one thing, but unfortunately, the other 49 things are cost of doing business that are just menial tasks that you must do.

It’s the great productivity leap in in security operations, especially to say, “ I'm paying this this security analyst that's that I really only want doing one job, but in order to do that one job historically he’s had to personally do the other 49 tasks, which were taking away from the one task, but it was cost of doing business.”

The answer is how do you take AI to offload as much of that as possible, so you can have the majority of his attention span focused on the one that you really want him doing, the one that's most meaningful.

Q. What is a practical example of AI improving security operations?

A. Security analysts deliver a SOP. One of the fundamental tasks is writing a summary, taking a complex, complicated series of events, and summarizing that event and sending it to the customer, where you can explain to them what happened, why it happened, and what you did about it.

Before AI, you would have a security analyst who's good at investigating, good at solving threats. He's not an editor. So, thinking critically, spell checking, all of these were very time-consuming. It would take 20-30 minutes pre-AI for an analyst to write up a good quality summary because you want it to sound professional, not have spelling errors, all the basic things. And that’s 20-30 minutes of tasks that we're not paying them to do.

Q. How could AI fundamentally change the speed of cyberattacks?

A. Before AI there would be two or three weeks in between intrusion and exploitation because at the other end of the computer there's a human. They don’t know where Active Directory is. He doesn't know where the sensitive data is. They don’t know where the credentials are. He had to figure that out, and it took him two or three weeks. So, defenders in general would get a nice, gracious period to interdict that activity and put an end to it before something very bad happened.

[But when bad actors use autonomous AI], the biggest fear should be now where is that going to compress. If humans are no longer at the other end of the computer, computers think a lot faster than humans do. You're not going to get two to three weeks to respond. You might get minutes. You might get hours. Defenses are not really configured to process telemetry and react at that speed. So we're going to have to get the defensive systems up to the ability to do that.

Q. What should organizations do now to prepare for AI-driven attacks?

A. They should be forward thinking, looking at how to transform their defensive systems to fight robots with robots.

Q. What should they do to build resilience?

A. You've got to have all three of the components mentioned earlier–proactive, real-time and reactive.

Resilience is an end-to-end business capability rather than a collection of individual security products, Johnston says. Organizations need the ability to prevent incidents where possible, identify and stop them as they occur, and recover quickly when prevention and detection fail.

AI changes the equation primarily through speed and productivity. Internally, it can remove repetitive tasks so security professionals spend more time on higher-value work. Externally, it can dramatically accelerate attacker activity, potentially shrinking the response window from weeks to hours or minutes. The strategic implication is clear: security defenses must become more automated, integrated, and capable of operating at machine speed if organizations are going to remain resilient.