Sysdig is acknowledging the fact that CISOs don’t have time to click through a dashboard anymore. Conor Sherman, the company’s Global CISO, argues the next era of cloud security has to run at machine speed, headless, and outcome-first.
“I don’t care how the meal is made,” Sherman said. “I just need to make sure it’s made on time and it’s hot.” Outcomes first; everything else is plumbing.
The Problem
Security teams are drowning in data but starving for clarity. Modern cloud and AI workloads generate enormous volumes of telemetry, yet most security leaders still struggle to answer a basic question: which of these thousands of signals actually matters right now? Without that clarity, teams end up reactive, chasing noise instead of protecting the assets that genuinely put the business at risk.
Sysdig’s roots are in protecting the most valuable, fastest-moving workloads, first in the cloud, and now increasingly in agentic AI systems, wherever those workloads happen to live. For Sherman, solving that clarity problem starts with true telemetry: understanding what’s actually happening at the kernel level, inside the workloads that matter, rather than relying on surface-level alerts. But raw visibility alone doesn’t solve it either. The real fix comes from layering business context on top of that technical signal, so a security leader can point to a specific asset and say it needs attention most, rather than simply reporting what containers are doing at the system-call level.
How It’s Different
Sherman points to two things that set Sysdig apart. First, that combination of bottoms-up technical depth with top-down business prioritization, which he says unlocks the core ingredients AI needs to be genuinely useful to a security team: clear prioritization, meaningful remediation paths, and detection and response policies that actually matter for the workloads in question.
Second, and less expected, is Sysdig’s relationship to Falco, the open-source runtime security project the company maintains. Falco has been downloaded more than 200 million times, and roughly 60% of the Fortune 500 use it to protect production workloads. Because it’s open source, the detection logic Sysdig’s threat research team builds in response to bleeding-edge attacks gets pushed out to the broader community, meaning one team’s lesson becomes another team’s defense. Sherman calls it raising the floor for the entire industry.
The Shift to Headless


The most interesting thread in our conversation was Sherman’s read on where CISOs are being pushed, structurally, whether they like it or not. He calls it the move to headless: instead of a security team logging into a dashboard, the front door to a platform becomes a coding agent, Claude Code, Codex, Gemini, whatever the team has standardized on. The reasoning is blunt. When Sysdig’s own threat research team tracks something like a Jadepuffer-style attack, an end-to-end agentic campaign that breaks into an environment, exfiltrates a database, rewrites its own code, and drops ransom notes, a security team cannot respond by clicking through a console. They need the speed, data, and accuracy that only a headless, agent-driven workflow can provide. Making that work, according to Sherman, requires four ingredients: MCP connectors so a coding agent can actually talk to the platform, shared memory so context persists across a team, skills that codify expertise so an agent can act like a senior cloud security practitioner, and a harness that governs how much work actually gets done in a given environment.
The Proof
Sysdig’s internal analysis found that a vulnerability triage workflow that historically took three analysts 45 minutes each, roughly $135 in labor and time, can now be completed in under 15 minutes using agentic systems, for about $16 in total cost, with the AI token cost itself running around $3.63. That’s roughly a 10x reduction in the cost of vulnerability prioritization, and Sherman frames it as the kind of order-of-magnitude improvement the security community needs across the board, not incremental gains.
The One-Sentence Takeaway
Sherman said simply: “We can’t have more cowbell.”
His broader argument is that security teams can’t just do more of what they’ve always done, faster. They need something different. Patch cycles, whether two weeks, 30 days, or 60, are becoming close to irrelevant. He pointed to Sysdig’s own threat research on the “Marimo” vulnerability, where an attacker built and used an exploit before a patch even existed. He said that security teams need a barbell strategy, investing upfront in structural resilience and vulnerability remediation on one end, while building real, sub-two-second machine-speed detection and response on the other, because a threat actor isn’t going to wait for a project to finish. He also flagged a shift in scale: threat actors are now running the same attack harness against dozens of organizations simultaneously, and open-weight AI models are lowering the barrier to entry further. His view is that the frameworks the industry needs already exist, NIST’s secure software supply chain guidance, zero trust, etc. What’s been missing is the business case for actually operationalizing them, and AI has just supplied it.
About the Author

Arya Baviskar is a Women in Cyber scholarship winner and Reporter at Cyber Defense Magazine. She is an undergraduate student at Northeastern University studying cybersecurity. As she approaches her second year in university, she is training in Cyber Threat Intelligence as an intern at the Cyber Security Forum Initiative. Additionally, she is an AI Trainer at Handshake AI, evaluating LLMs for bias and safety. What ties her experiences together is a consistent focus on making complex technology more transparent and accessible to the people that it affects. Arya can be reached online at [email protected] or through her LinkedIn: www.linkedin.com/in/aryabaviskar.

