Outpace Cyber Threats with Agentic AI + Human Ingenuity

Tomer Weingarten (CEO & Co-Founder · SentinelOne)

RSA Conference 2025 · Day 3 · West Stage · Keynote

Overview

SentinelOne CEO Tomer Weingarten delivered a candid assessment of an industry he believes has failed to solve its most fundamental problems, even as it races to deploy AI. His prescription: stop pursuing checkbox security and "magic promises," accept collective accountability, and embrace a human-plus-AI model in which autonomous systems handle detection and response at machine speed while human operators shift from incident-chasers to strategic supervisors. The vehicle for that vision is SentinelOne's unified, open AI cybersecurity platform — what Weingarten calls a "meta layer" connecting every security product, data source, and enforcement point in a single reasoning system. ---

Watch on YouTube

Visual summary for Outpace Cyber Threats with Agentic AI + Human Ingenuity by Tomer Weingarten
Visual summary for Outpace Cyber Threats with Agentic AI + Human Ingenuity by Tomer Weingarten

Key moments

  1. 1:13 Every conflict zone has a parallel digital war zone
  2. 3:20 Software industry prioritizes speed over quality and safety
  3. 5:40 MCP gives attackers direct keys to kingdom — urgent risk
  4. 7:01 2024: worst cybersecurity year ever; healthcare genome data stolen
  5. 8:25 Most exploited security product globally in 2024 named
  6. 9:48 Shift to humans plus AI: intuition plus machine precision
  7. 13:05 SentinelOne unveils open AI platform unifying all security products
  8. 14:02 Autonomous AI detects and resolves misconfigurations at machine speed

Outpace Cyber Threats with Agentic AI + Human Ingenuity

Speaker: Tomer Weingarten (CEO & Co-Founder, SentinelOne)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch on YouTube: https://www.youtube.com/watch?v=YiIvCs4beA4

Reading time: ~6 minutes

TL;DR

SentinelOne CEO Tomer Weingarten delivered a candid assessment of an industry he believes has failed to solve its most fundamental problems, even as it races to deploy AI. His prescription: stop pursuing checkbox security and "magic promises," accept collective accountability, and embrace a human-plus-AI model in which autonomous systems handle detection and response at machine speed while human operators shift from incident-chasers to strategic supervisors. The vehicle for that vision is SentinelOne's unified, open AI cybersecurity platform — what Weingarten calls a "meta layer" connecting every security product, data source, and enforcement point in a single reasoning system.

Introduction

For Tomer Weingarten, making his first appearance on the RSA Conference main stage was not an occasion for a product announcement or a tour of technical capabilities. It was an occasion for an industry reckoning. In a keynote that blended sharp self-criticism of the security sector with an ambitious architectural vision, the SentinelOne co-founder argued that the cybersecurity industry has spent two decades chasing threats without fixing the brittle infrastructure that lets those threats flourish. As AI accelerates both the sophistication of attacks and the scale of the systems defenders must protect, that foundational fragility has become untenable — and the answer, Weingarten argued, is neither more tools nor bolder vendor promises, but a structural reimagining of how security operates.

The State of the Industry: A Reckoning

Weingarten opened with an unusually frank diagnosis: the cybersecurity industry has not made the world safer in any meaningful sense. The attack surface expands with every new product deployment. Software is built with speed and revenue prioritized over stability. Security remains an afterthought. And despite decades of investment, 2024 was, in his view, "the worst year for cybersecurity ever in history."

▶ Watch: The industry's fundamental failures (2:00)

The consequences are no longer abstract: personal healthcare data, genomic records, call logs, and location data have passed into the hands of adversaries in bulk. "We as consumers, as humans, are all impacted by these cyber breaches, not the enterprises that suffered them," Weingarten told the audience. "This is a frightening reality, yet somehow we've grown numb to it. We read about the breaches, they linger for a couple of days, we move on to the next one. Business as usual."

The failure is systemic. Vendors make claims with "little proof of delivery." Platform strategies sometimes introduce new vulnerabilities rather than closing existing ones. Weingarten showed a slide listing security vendors responsible for the most frequently exploited vulnerabilities in 2024 — a pointed rebuke to an industry that sells protection while sometimes generating new attack surface. The conclusion: accountability is not optional, and the current posture of conformity and complacency is a mandate to rebuild.

The Threat Landscape Is Not Waiting

Before turning to solutions, Weingarten catalogued the scope of what defenders face. Exploits continue to reign as the dominant attack vector after two decades — a damning signal that the vulnerability management problem remains unsolved. But the attack surface extends well beyond traditional software flaws.

▶ Watch: Global threats accelerating (4:00)

Ransomware, malware-less attacks, deep phishing, deep fakes, AI poisoning, AI exfiltration, AI takeover, and what Weingarten termed "robo hacking" — security vulnerabilities in the physical robots increasingly connected to enterprise networks — all represent vectors that defenders must account for simultaneously. The newly popular Model Context Protocol (MCP), Weingarten observed, hands attackers powerful capabilities the moment it is connected to a compromised system: "It gives the keys to the kingdom directly to the attackers to abuse that powerful tool that we just put inside of our infrastructure."

The broader geopolitical context amplifies these risks. Cyberspace, Weingarten argued, has become a theater of warfare, espionage, and disinformation with no guardrails and no watchdog. Adversaries are not merely stealing data — they are manipulating the information environment to alter perception and erode trust in institutions.

The Case for Human + AI: Not Competition, but Amplification

The turn in Weingarten's argument came at the midpoint of the keynote: the question is not whether to deploy AI in security, but how to frame the relationship between human judgment and machine capability.

▶ Watch: The age of humans plus AI (10:00)

Weingarten rejected the framing of AI as a replacement for human defenders. Instead, he described a symbiotic model: the irreplaceable intuition and ingenuity of experienced security professionals, combined with the relentless scale, precision, and speed of AI systems. Under this model, human operators do not chase every alert. They supervise a system that handles detection, triage, and initial response autonomously — shifting from hands-on defenders to strategic supervisors of a broader security apparatus. "Think about the human brain amplified and extended," he said.

SentinelOne's claim to authority in this space rests on its origin story: the company was built on AI and autonomous protection from the beginning, before it was fashionable. "We ushered real-time security, autonomous protection, when people thought it was a complete crazy idea," Weingarten said. Today, he argued, the rest of the industry is catching up to an architecture SentinelOne has been executing for a decade.

The Open AI Cybersecurity Platform: One Meta Layer

The practical expression of Weingarten's vision is SentinelOne's open AI cybersecurity platform — a system designed not to replace existing tools but to unify them under a single layer of intelligence.

▶ Watch: Introducing the autonomous cybersecurity platform (12:01)

The architecture addresses what Weingarten described as the defining problem of enterprise security: fragmentation. Today's networks are collections of disconnected products — endpoint agents, cloud controls, network gateways, identity systems — each operating in isolation, producing telemetry that never converges into a coherent picture. The platform aims to eliminate those silos by connecting all data, all products, and all enforcement points under a unified reasoning layer that can see across the entire environment in real time.

Key capabilities include: automated discovery and mapping of the environment, dynamic onboarding of new data sources, compliance monitoring, vulnerability detection, and coordinated response across connected vectors — all driven by multiple AI models orchestrated through an agentic framework. The system is designed to evolve through reinforcement learning, adapting faster than human operators alone could drive it.

▶ Watch: Live data and proactive AI (14:00)

"Live data is the key," Weingarten said. "This is when AI stops being reactive and starts being proactive." The distinction matters: a system that reasons over real-time telemetry can prevent incidents rather than merely respond to them, shifting the calculus from cost-of-breach to cost-avoidance.

A Call for Industry Accountability

Weingarten closed with an argument that transcended any single product or company. The problems of cybersecurity are collective problems, and they require collective solutions — not just better technology, but better behavior from vendors, investors, and practitioners alike.

▶ Watch: Accountability and the path forward (8:01)

"Let's strip down these claims. Let's focus on what's real. There are no magic solutions. There's only magic promises." The obligation, in Weingarten's framing, falls on everyone in the industry: to stop shipping insecure software, to stop making unverifiable claims, to stop treating security as a compliance checkbox. Collaboration and deep partnership — not vendor lock-in or territorial siloes — are the path to a digital environment that is genuinely resilient.

Notable Quotes

"Twenty twenty-four was, in my view, the worst year for cybersecurity ever in history. All of our personal healthcare data is in the hands of adversaries. All of our genome data is in the hands of adversaries." — Tomer Weingarten

"There are no magic solutions. There's only magic promises." — Tomer Weingarten

"Live data is the key. This is when AI stops being reactive and starts being proactive." — Tomer Weingarten

"The irreplaceable intuition and ingenuity of humans, plus the relentless scale, precision, and speed of AI — these are the capabilities that we need to bring to bear through every layer of security." — Tomer Weingarten

Key Takeaways

  • The industry's foundational problems remain unsolved. Speed-over-quality software development, security as an afterthought, and fragmented architectures have not been fixed — and deploying AI on top of broken infrastructure compounds, rather than corrects, the underlying fragility.
  • 2024 was a landmark year for the wrong reasons. The breach of personal health, genomic, and communications data at scale represents a systemic failure that demands accountability from the entire industry, not just the affected organizations.
  • Emerging technologies like MCP introduce new risk vectors that must be secured before deployment, not after adversaries have learned to exploit them.
  • Human + AI is the operative model, with AI handling detection and response at machine speed and human operators serving as supervisors who set strategy, validate judgment, and handle edge cases requiring intuition.
  • Platform unification over point-product proliferation is the architectural principle — a single reasoning layer that connects all data, all products, and all enforcement points is more defensible than a collection of disconnected tools.
  • Accountability is a precondition for progress. Vendor marketing claims, insecure software practices, and checkbox compliance must all give way to verifiable delivery and genuine resilience before the industry can make meaningful progress.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Weingarten's RSA debut is better than most CEO keynotes because he actually calls out the industry's failure, including his own sector's vendor marketing problem, before pivoting to the product story. The accountability argument lands. The 'meta layer' platform vision is ambitious, but the candor about 2024 being catastrophic is the kind of honesty RSA stages rarely see from a sitting CEO.

Heather Calloway (CISO) — WEAK

SentinelOne CEO Tomer Weingarten opens by calling 2024 the worst year in cybersecurity history and naming the industry's own accountability problem. Then proposes an open AI platform as the answer. The candor is rare; the landing is familiar.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025