While human hackers can only move so fast, the arrival of autonomous agents capable of attacking at unprecedented speeds should result in a ‘completely different calculus’ for identity and security teams, McClain says during the latest episode of CRN’s Security or Else! podcast.
While human hackers can only move so fast, the arrival of autonomous agents capable of attacking at unprecedented speeds should result in a “completely different calculus” for identity and security teams, according to SailPoint Founder and CEO Mark McClain.
McClain, a luminary of the cybersecurity industry and longtime leader of identity security powerhouse SailPoint, spoke with CRN for the latest episode of Security or Else!—a new video series hosted by senior editor Kyle Alspach.
[Related: Why The Cybersecurity Channel Is Essential As An AI Reality Check: Analysis]
Without a doubt, the “danger of agents” is the ability of an AI agent to move “thousands” of times more quickly than a human threat actor, McClain said.
“Humans can’t hit the keyboard a thousand times in a second,” he said. “So no matter what, if a human’s gone rogue, there’s only so much damage they can do in a limited amount of time.”
On the other hand, for agents that can attack with “automation and machine speed, [that’s a] completely different calculus on how rapidly bad things can unfold,” he said.
The implications are massive for defenders, who must now realize that discovering agents and monitoring their activity will only go so far, according to McClain.
Crucially, many organizations will need to put stronger controls around what agents can access and what actions they can take—and prepare to intervene rapidly when those controls are not enough, McClain said.
“It’s going to cause us to think differently about things like automated response [and] remediation. How fast can you respond? How fast can you remediate?” he said.
Ultimately, there will undoubtedly be situations when the danger is so clear that “we want an automated response that stops something bad or dangerous from happening,” McClain said.
For solution and service providers, the opportunity is to help customers connect their security efforts around AI agents with the fundamentals of identity security—while, likewise, developing a full set of controls needed to enable secure adoption of the technology, he said.
“There’s massive opportunity to walk into customers and say, ‘I’m here to help,’” McClain said. “Because I think they’re looking for help.”
Check out the video here, and please like and subscribe if you enjoyed (available on YouTube, Spotify and Apple). Security or Else! features conversations with security experts and top executives about what’s hype and what’s real—and what channel partners truly need to focus on next in security and AI.





