Transcript
Manoj Tandon:
Hello everyone, I’m your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. We have another great guest with us today. Before I introduce him, please hit the like and subscribe button. It allows us to keep bringing you world-class guests and conversations like this one.
Today I’d like to introduce Filip Verloy, joining us from Europe. Filip is a technology leader with over 25 years of experience across enterprise IT, consulting, and global vendors. He’s an expert in agentic AI — a very timely topic. He has worked in large-scale, complex environments and served as Global Field CTO at the API security startup No Name Security. He has also held senior architecture and solution roles at Citrix, Dell, Riverbed, and VMware, among others. He’s known for his curiosity, his commitment to fundamentals, and his focus on building secure, resilient systems from first principles. Filip, thank you for being here — and for joining us so late in your time zone.
Filip Verloy:
My pleasure, Manoj. Happy to be here. Looking forward to the conversation.
Manoj Tandon:
Give us a bit of your background. What brought you into this field?
Filip Verloy:
I’ve been in IT for about 27 years now. I started in the late 90s. My background is actually in electrical engineering. I worked briefly at Sony Electronics before being convinced by one of their customers to join a startup electronics firm. That company eventually went bankrupt, which gave me an early lesson about the realities of business.
I’ve always been interested in IT — I started as a gamer like many of us. My first real IT role was as a Sun Solaris architect. From there, I worked across infrastructure, storage, and networking. I moved into vendor roles with Citrix, Riverbed, VMware, Dell, and I’ve been with Rubrik for almost 10 years now. Rubrik started in backup and data management, but we’ve expanded significantly into security and now agentic AI security. My broad background across infrastructure, networking, and security has been extremely useful in navigating this new AI-driven landscape.
Manoj Tandon:
You use the phrase “illusion of knowledge” and talk about building resilient systems from first principles. What do you mean by that?
Filip Verloy:
When building systems that need to scale and survive long term, you have to step back from hype. Social media and LinkedIn are full of excitement about new technologies. But instead of chasing the latest trend, organizations should ask: What are we building toward? What problem are we solving? How does this technology truly contribute to the business?
With agentic AI especially, there’s enormous excitement. But underneath that, you still need fundamental knowledge of infrastructure, APIs, data flows, identity, and security. Understanding how systems are built from the ground up helps you avoid being swept away by hype. That’s what I mean by challenging the illusion of knowledge — slowing down and truly understanding what’s happening under the hood.
Manoj Tandon:
People often say start with understanding risk. Is that still the right place to begin?
Filip Verloy:
Risk is a good starting point, but AI introduces unknown unknowns. In agentic AI, we’re experimenting with use cases where risks aren’t fully mapped yet. So yes, start with risk — understand what you’re willing to accept and what you can control — but you also need foundational understanding of the systems you’re deploying.
You’ll never eliminate all vulnerabilities. You must decide what risk is acceptable and what is not. But AI, especially agentic AI, makes this more complex before it gets easier.
Manoj Tandon:
Does agentic AI increase or decrease the attack surface?
Filip Verloy:
Initially, it absolutely increases the attack surface. Over time, AI can help shrink it — fighting AI with AI, for example, using LLMs to find vulnerabilities in code. But realistically, when you deploy AI agents, you are expanding your attack surface.
A traditional application tightly controls user input through a UI. A chatbot does not. Prompt injection attacks can push beyond intended boundaries. Additionally, LLMs are non-deterministic. You’re introducing a probabilistic system — effectively a black box — and giving it access to tools, APIs, and data. That expands risk.
Manoj Tandon:
How aligned are agent-based systems with human decision-making?
Filip Verloy:
An LLM predicts the next most reasonable token based on its training data. We fed it massive human-generated datasets, so in some sense it reflects human knowledge. But it’s still probabilistic and non-deterministic.
With agents, we go further. We take that “brain” and give it arms and legs — access to tools and APIs. At that point, you must build guardrails around it. You can tune behavior and add external controls, but fundamentally, you’re working with a system you cannot perfectly predict.
Manoj Tandon:
Can you truly secure something like that?
Filip Verloy:
You can improve security with guardrails, data filtering, and visibility. For example, PII should never be part of the training corpus. You can implement data masking and DLP controls. Agent memory — context windows — should be flushed between sessions.
But we are early in this journey. There are real-world examples of agents misinterpreting instructions. We can secure these systems better, but we’re still learning.
Manoj Tandon:
Let’s take a practical scenario. Suppose we create an AI travel agent for a company, and it accesses HR systems for employee data. Does the agent become an identity?
Filip Verloy:
This is one of the most interesting unsolved problems today. Yes, agents effectively become identities. Companies are starting to assign identities to agents — similar to service accounts. Microsoft, for example, is introducing agent identities.
But it gets complicated. In multi-agent workflows, one coordinating agent may call sub-agents. Those sub-agents may require temporary access to systems like HR databases. That access should be context-based and short-lived. Today, most access is static or token-based and long-lived.
We lack dynamic, context-aware identity management for agents. That’s a gap in current IAM models. We need better visibility, traceability, and observability. Longer-term solutions will require changes in how identity systems operate.
Manoj Tandon:
Where does API security fit into this?
Filip Verloy:
Agents operate through APIs. Modern applications are distributed and interconnected through APIs. If you don’t understand your API attack surface, you can’t secure agentic workflows.
APIs often leak abstractions. There are ways to extract more than intended. In an agentic world, that becomes a security risk. Understanding APIs from first principles is critical.
Manoj Tandon:
Convenience usually wins over security. Are we headed toward mass adoption first and security later?
Filip Verloy:
Probably, yes. We’ve already seen “YOLO” adoption patterns — turning systems on and figuring out security later.
But friction isn’t always bad. A little friction — like brakes on a race car — allows you to go faster safely. The key is minimizing friction while embedding security into rollout processes.
I’m seeing organizations form AI governance committees. That’s encouraging. They define acceptable use, data boundaries, and risk tolerance. With tools like LLM-as-a-judge, you can enforce governance policies dynamically with lower friction.
Manoj Tandon:
How does agentic AI change the internet economy, especially advertising?
Filip Verloy:
Interesting thought experiment. If agents bypass traditional UIs, advertising models change. I suspect monetization will shift. We may see tiered API models — fast paid access without ads, slower or free access with injected advertisements in chatbot interfaces.
Ultimately, providers will find ways to monetize.
Manoj Tandon:
What about governance — GDPR, EU AI regulations?
Filip Verloy:
There’s tension. In Europe, we see pushes toward sovereign AI models compliant with EU AI Act regulations. Some organizations prefer fully on-prem or sovereign stacks. Others want the power of frontier models like OpenAI or Anthropic.
Regulation will increase. But there’s always a gap between regulatory intent and practical implementation. We’ll likely see more regulatory pressure in the coming months.
Manoj Tandon:
Final thoughts?
Filip Verloy:
Start with basics: visibility. Know what agents exist in your environment. Know what tools they use, what identities they operate under, what data they access. Build visibility first. Then enable AI on top of that foundation.
That’s true regardless of organization size.
Manoj Tandon:
Filip, this was outstanding. Thank you for being here. When you’re able to share more about the identity work you’re exploring, please come back.
Filip Verloy:
Will do. Thanks again, Manoj. Really enjoyed it.
Manoj Tandon:
Likewise. Thank you so much.