Home

The Main Scoop Ep. 45: Attackers Only Need to Be Right Once. AI Just Made That Easier.

The Main Scoop Ep. 45: Attackers Only Need to Be Right Once. AI Just Made That Easier.

Chad Rikansrud, R&D Software Security Engineer at Broadcom, explains how frontier AI models are finding decades-old mainframe vulnerabilities in seconds, collapsing the complexity advantage that once protected legacy platforms. He outlines why enterprises need faster Security Intelligence (SECINT) ingestion and disciplined human oversight to keep pace with adversaries wielding the same tools.

Frontier AI models can now find decades-old vulnerabilities in mainframe operating systems and open-source codebases in seconds, a capability that once took skilled security researchers years to develop and now runs on demand for anyone who has access to the model.

On this episode of The Main Scoop, Daniel Newman, CEO and Chief Analyst at The Futurum Group, and Greg Lotko, SVP and GM of Broadcom's Mainframe Software Division, sit down with Chad Rikansrud, R&D Software Security Engineer at Broadcom, to unpack what frontier AI's new discovery speed means for mainframe security and Security Intelligence (SECINT) operations.

For enterprises running mission-critical mainframe workloads, that shift changes the calculus on patching, threat monitoring, and staffing. Security and infrastructure teams that once had months to respond to a disclosed flaw now face adversaries who can weaponize the same discovery in a fraction of the time, which puts a premium on faster SECINT ingestion and disciplined human oversight of AI-assisted defense.

Key Takeaways:

AI has erased the complexity advantage that once protected mainframes. Inherent complexity and decades of technical debt once served as a natural security barrier, but frontier AI can now read and understand that same complex code as easily as a human expert.

Frontier AI models are surfacing decades-old vulnerabilities in seconds. The same discovery tools are available to defenders and adversaries alike, so organizations can no longer assume obscurity or complexity buys them time.

Security Intelligence (SECINT) feeds are expanding faster than most teams can act on them. Mainframe and security operations teams must work in sync to turn that growing volume of intelligence into actionable defense rather than a backlog.

The patch calculus has flipped: the risk of not patching now outweighs the risk of the patch itself. Organizations that once weighed availability against stability now have to treat rapid, disciplined patch application as the default, not the exception.

Human oversight remains the deciding factor in how effectively AI tools are used. Frontier models are confident even when wrong, so practitioners who know how to guide, question, and correct them get dramatically better results than an unchecked model left to run on its own.

Rikansrud advises enterprises to pair frontier AI's discovery speed with fast, disciplined patch execution and experienced security judgment in order to close the exposure gap before adversaries do.

Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.


Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology audiences.

Transcript

Chad Rikansrud:
Being the attacker is the easiest job in the world, right? Because you only have to be right once. And the defenders have to be right every time. And there's a million different little knobs and wheels and buttons to push, and they have to get every one of them right.

Greg Lotko: 
Hey folks, welcome to our next episode of The Main Scoop. I'm here with my co-host, Daniel Newman. Good to see you. Greg, it's good to be back. It's good to be together. A little foot. There we go. So why don't we get to our topic for the day? Today we're here to talk about AI, which is a topic I know you enjoy, but specifically the impact around security, thinking about all that's been going on with the frontier models, the capabilities that are out there. We all know that the first thing we were talking about was AI doing code generation or code understanding so that you could rewrite, refactor, or tie things together. But now we're hearing a lot of talk in the security space.

Daniel Newman: 
So by the way, we've been doing this for a while now, right? You've got this great audience, we've done this show. Now I really lean pretty hard into AI, right? And somebody that I used to and continue to co-host with was a little hard on me about that. How did I do? How did I do?

Greg Lotko: 
I just think everybody should hear a report card on all those early calls about, you know… Wait, I got to think because you've told me as an analyst, we don't ever talk about the things we get wrong. We only talk about the things we got right, which helps our win percentage. A plus or just a solid A? You know, I'd give you a B. I know it so so you and I have talked a lot about AI and at some point you felt like I was Against AI and it wasn't that I thought you were conservative. It wasn't even that it was just AI was a buzz. We had a lot of topics to cover and you were bringing AI into just about every conversation. Now, that said, AI is in a lot of conversations and is in a lot of places. I still don't look at what's going on with AI as the panacea that some people think it is. I see it as the next great tool. I don't think it's the be-all end-all that it's going to replace everything, but I do think there are a lot of places to apply it that can bring efficiency and value and productivity and all that. So, I do believe in the pervasiveness of it. I don't believe it's a one-for-one replacement of. It's an and, not an or.

Daniel Newman: 
It's the center of the next industrial revolution and the current economic revolution, though.

Greg Lotko: 
So our guest for today is Chad Rickensrud. He's been a security practitioner and expert. I mean, he's been somebody who's helped businesses become more secure, shown them where they have issues. And most recently, we had the honor of having him join our team, but he's got over 30 years of experience in this space. And in that context, That's what we're bringing them on here to talk about, is to really talk about these frontier AI models, what we're seeing, and how it's helping shape and change the industry, and in some instances, waking us up to things we maybe should have been more urgent about for a long time. And by that, when I say we, I mean the whole IT industry ecosystem. I don't mean Broadcom. So Chad, with that intro, you're a legend. What do you want to share about yourself and where do you want to take us to start this conversation?

Chad Rikansrud: 
Thanks. Thanks, Greg. Daniel, I'm delighted to be here. Well, I'll tell you what. So you guys obviously have some history in how you have talked about AI in the past and how you think about it or have discussed what the relevance of it is. I was definitely a late adopter. And by late adopter, I mean like March, April-ish of 2026. I have lived through in my career a whole bunch of technology booms and fads and things that were generally just renaming of other stuff. And where I've landed now is kind of more pragmatic about AI. I think it's a tremendous tool. I think it's going to do a lot of things that people can do, but faster and maybe more innovatively in some cases. But I don't need it on my toaster or in my fridge or in my everyday. I'm so sick and over-inundated and deluged by it. Relevant to where we're at today, my background initially in tech was for a large financial services corporation running operations, data center operations. And so for a good chunk of my career, production, job one, keep the lights on, get the money out, all that kind of stuff. And I've lived through some outages and I know what it's like when it's in the ditch at three o'clock in the morning and nothing, nothing, and I mean nothing. really was of greater importance than production, meaning the availability.

Greg Lotko: 
And that's why your perspective is so valuable to the customers and the businesses in the ecosystem, right? Having lived their side of the equation and understood, understanding what it means to be up and on, available, secure, you know, you can flip to the other side and say, hey, I've walked in those shoes.

Chad Rikansrud: 
Yeah, that's exactly right. That job, other than the getting tired of being woken up at three o'clock in the morning, is what led me into the security side of things. I wanted to get back into a hands-on role. I wasn't a mainframe person. I came from a decidedly x86, Linux, that side of the house, networking. And I really understand the power and the importance of this platform now that I'm in operations, right? And I start thinking about, it's about the time ransomware became in vogue. And I started thinking about, you know, what somebody asked me when I was at the bank. We had one of these kind of closed door meetings that nobody will ever admit happened and said, you know, do you think we could ever get ransomware on a mainframe? Because I was at the time the kind of like in-house person who knew about these things. And I said, for a minute, I thought to myself and I said, yeah, yeah. And it would work really well. Right. Cause what's a mainframe, if not like an encryption machine and an IO machine and what's ransomware. I mean, it's, you know, once you've launched it, it's all about encryption and IO, right. It's going to work.

Greg Lotko: 
And the reality is anything is hackable if you haven't taken the steps to implement the protections and the securities. Somebody, if there's a little door left open or a crack, they'll find the way. And by the way, so that brings us to talking about the new capability that's being applied, the Frontier AI models. And I know you've been, I was going to say playing, but that's not the right word. I know you've been interacting and using these technologies. You know, what do you think the big thing is? What is it, you know, what is it discovering? Is it discovering different things? Is it just discovering them faster? Is it easy? Is it smart? You just say, hey, find all the bugs and it goes? Or how much does it have to be guided?

Chad Rikansrud: 
Yeah, that was a lot of questions. I'll tell you what. You can have a lot of answers. I mentioned ransomware. That was a turning point in the good versus bad guy world of technology, right? It used to be the case that if you parked your car in the wrong spot, they had to come and tow your car, and then you had to go pick it up, right? That's expensive, right? That's the old version of getting a virus. It's got to find all the good stuff. It's got to exfiltrate it. That's complicated. Ransomware is like the boot, right? Ransomware is basically when they throw the boot on your car, they don't have to deal with towing it. They can just put it on and you can't use it, right? That was a huge inflection point in terms of good versus bad in technology. So, this frontier AI models and what's coming from here on makes that look like just a brief footnote. And I'm not prone to exaggeration, but they are I will say that I don't think they're finding anything that people can't find. People can find these bugs. I've been finding them for years. It's not just software bugs, though, either. It's configuration issues on the platform. It's hacking things A to Z. It's stringing together all kinds of lesser issues. So it's not like just trying to break into your house and finding the front doors open. It's finding that like you're gone on Thursdays between, we'll be seeing six and seven o'clock. And there's a window that doesn't lock just right upstairs. And this light switch over here can be turned on without the neighbor seeing it, right? And all kinds of things that you wouldn't think about as being home security issues. But if you put that whole picture together, I can get you into the safe and get the jewels and get them out of there. And you don't have to necessarily go through, I mean, you'll find the front door open too. How much guiding does it take? It takes more than you might think. One of the pitfalls I've run across is the models are really confident, so confirmation bias is big. When they're convinced, they're convinced they're right. And sometimes it takes a while to prove to them that they're not correct about something because of inferences.

Greg Lotko: 
This is kind of the point that it is not the tool in and of itself. The tool used by a practitioner who understands how to drive it, correct it, point it, decipher it, will be way more successful than just the novice. It's the same tool, it's the same technology, but how you interact or drive it makes a huge difference, right?

Chad Rikansrud: 
Think about it like this, Greg. I look at it a little bit like a neurosurgeon. Science could break us all down to cells and atoms and how things go together, and we know that. But you know anytime that surgeon opens up somebody's brain, like it's a little bit different every time, right? It doesn't matter how well we've documented the genome, the DNA, the cells, the organs, how they work together, every one of those adventures is a little different and you want somebody who knows what they're doing on all parts of that exercise, right?

Greg Lotko: 
So what you're saying is human intelligence makes a huge difference in how you use artificial intelligence.

Chad Rikansrud: 
Yeah, it has a body of knowledge. It is all the tools, but you want someone guiding it in some way, shape, or form. Because as we've seen, as of late, unchecked, they can go off the rails pretty quickly. My experiences have been little off the rails. You're wrong about A versus B, but unchecked, None of those stories surprise me at all, because it's much more like having a bunch of really arrogant experts at your disposal who all might have slightly different opinions, but groupthink is a thing, right? And so you really want someone who knows what's going on when you're using these things surgically. That said, and then if you're the bad guy, you don't give a crap, right? If your job is just to hack it up, if you're a mad scientist doing brain exploration, you don't care if the patient dies, right? So when you're the bad guy, you don't have to get it right. You just have to keep trying. And in that case, I mean, it's a force multiplier for them because they don't have to be good, right? They just have to get it right once somewhere along the line.

Daniel Newman: 
So you kind of are speaking a bit to determinism. Deterministic model is non-deterministic. You know, mostly the models themselves are non. Of course, where we connect APIs and MCPs and data sets, we make them more deterministic by connecting business systems and rules and data sitting on mainframes. But like, but what we, what you did identify is in the end, the models are now very, very capable of discovery. Let's just call it that. So they're able to go out there and kind of find the vulnerability. And then they're also very good at finding any and all information out on the open web and not necessarily the dark web too, but they would say, okay, now that I know this vulnerability is here, let's go figure out how to hack it, right? And that's what you were sort of leaning into was the jailbreaking that was going on, right? It became like a bit of a, a bragging competition between the different model companies to say who had the worst antagonist.

Greg Lotko: 
No, no, seriously, they were competing to say who- I'll tell you my reaction to that. You really look into, whether or not it's PR, you look into what's going on and you look at how the AIs or agents are interacting with each other. And I think we've had it wrong. We are not right now, today, dealing with artificial intelligence. We are the closest we have ever been. But what we're dealing with is artificial adolescence. I mean, think about it. You're defining rules and a framework and an agent let go autonomously is saying, well, hey, all the other agents are doing it. I should be able to do it. Or you gave me a task that's impossible, so I should be able to cheat or break this rule. And that loops right back to. It really depends on who's guiding, interacting, setting up the framework and the result.

Daniel Newman: 
Well, I mean, a sandbox should never be connected, right? Like the fact that they escaped a sandbox, you have to actually ask, how was it ever given the capacity to connect to the external world?

Chad Rikansrud: 
I mean, they took the guardrails off, which makes me kind of think it was maybe some publicity-ish stuff behind it as well.

Daniel Newman: 
All of this is to be said that there is a significant new surface area for these tools to be used. What are the implications now that you can basically send a tool loose? And you started to talk about this, especially for the bad guys. And then how did the good guys get around this? Because the bad guys can kind of scatter. They can sort of shotgun it and go after everything. The good guys need to actually know what the heck they're trying to attack.

Chad Rikansrud: 
It isn't good, right? I mean, here's the thing. I teach hacking. I teach offensive computer techniques. And I'll tell people in the class that one of the things that you have to understand is being an offensive person, being the attacker is the easiest job in the world, right? Because you only have to be right once. And the defenders have to be right every time. And there's a million different little knobs and wheels and buttons to push, and they have to get every one of them right. So it's basically, it comes down to being, it's like the joke about the bear in the woods, right? You run across the bear in the woods with your buddy, you stop and put your shoes on, and he's like, you're not gonna outrun that bear. He's like, I just gotta stay ahead of you. And that's basically what it boils down to, is that a lot of attacks are attacks of opportunity, but a lot of the world, especially in the mainframe world, has been lucky, and they need to be good. There's been some barriers to entry to that that are gone now.

Greg Lotko: 
Levels of complexity and all that kind of stuff. I'd say the part about the mainframe world being lucky, and I want to make sure folks listening to this, You hear that and it makes people think maybe the mainframe is less secure than other platforms or environments. I patently don't believe that. I know you don't believe it. The part that where they've been lucky is while the mainframe is way more secureable than other platforms. Unfortunately, and not unique to just this platform, some people have gotten lazy. They take longer to apply patches. They maybe inherently think it's more secure than it actually is without having done the work to apply the patches or use the technologies that'll make it more secureable. and that's why they've gotten lucky. This is a huge wake-up call across the industry to say, hey, there's a lot of technology and capabilities out there that can help you secure your environment. Don't just be talking about them. Don't just be investigating. Don't just purchase them. Do the work. Not only install it, but apply it. Configure it unique to your environment to make sure you're fixing that window lock that doesn't latch. Work the whole system all the way through and look at all the angles and paths.

Daniel Newman: 
And maybe the right follow on for that, Chad, is, you know, with all this additional security intelligence demand and updates that are now being required from teams, how do you, whether it's a mainframe team, security teams, broadly, like, how do you recommend they keep up?

Chad Rikansrud: 
Yeah, I mean, so, you know, it pains me to say it, but at this point, The operations guy in me is kind of crying and dying right now, but it's more important at this point to be secure and on top of these patches than it is to necessarily… the risk of applying a patch is basically now less than the risk of it having to back it out, right? Like you don't want to not have that patch applied.

Greg Lotko: 
You don't want to be exposed to the next thing. Well, because the risk of a breach is higher, right? Yeah, the cost, the impact. Right, so when we used to be thinking about IT, we were thinking about we have to have the latest and greatest features function. And by the way, we have to be secure and we'll apply these security patches. One, everybody's rotated away and saying, hey, security and securability is job one. That's way more important than applying some functional feature or capability. But then two, the risk of having an outage because of a defect in a patch is way lower than now the risk of not applying it and the risk of breach.

Chad Rikansrud: 
Yeah, and I think it'll be a shift, right? It's going to be a shift in, it's going to start with the large organizations that have to patch at a rate that they've not seen before. They're going to have to use these tools. I mean, we hadn't talked about that, right? But these tools are really good at generating patches, fixing, suggesting secure configurations. And so you can use these same frontier AI tools, you know, to speed that up. And to some degree, they're going to have to. But the origin is going to start with these and it's going to go outward to where people are going to look for organizations to do their banking with, for instance, that they know is secure, that they trust from a security perspective. And yes, they're going to still want that level of availability and access to it. But like a lot of things in your life, if you think about it, you already put security above availability in certain areas in your life, right? You have to stop and unlock your door. You have to like, you know, there's all these different places in your life where you are inconvenienced by security, but you need to think about it. And I think that's where we'll get to, right? I mean, we'll get to that point where that's going to be the most important thing you're shopping for.

Greg Lotko: 
It's funny, I hadn't thought about it before, but you're right. It's inconveniences that you put up with. And I have something happen almost every day, right? So you have the remote. to unlock your car. Well, the car I drive the most has this feature that if you don't unlock it and open the door within a certain timer, the car then automatically locks itself. I cannot tell you how many times I walk out to the parking lot, and as soon as I see the car, I unlock it, put the key back in my pocket, figuring, oh, I'm getting the stuff ready that I'm gonna load into it, and just as I walk up to the car, it locks again. And it's an inconvenience, but I'm like, you know what? That's better than wondering if the car was left open. Much better.

Chad Rikansrud: 
But it's going to take all of us. It's going to be a Herculean effort. I don't want to make it, I mean, from the enterprise, at the enterprise level, from the outside in. everybody's going to have to be on board with this. And it's going to also require vendors to make patches easier to consume, to make them seamless in and out if they have to be backed out. Because the entire playing field and the entire set of rules have changed now dramatically. And we all have to get on board with it. There's no There's no way around it.

Daniel Newman: 
So in summation, the AI boom has created exponentially more surface and better tooling, but it's made the job of the good guy harder. But having said that, these tools also can complement. And if I don't want to put words in your mouth, but since we have to wrap this up, what I heard you say today is it's going to be an AI plus human Herculean effort, right? AI, humans with great knowledge, experience, Systems, you know, obviously hopefully providing real telemetry to the AI, because like I said, the AIs are non-deterministic in most cases, and all kind of working harmoniously to drive a future where hopefully mainframes, of course, but really all systems are secure where we feel comfortable continuing to build because again, you know, that's the scariest side of this all is these tools give us great productivity. But they also just, you know, like the last era where we traded our privacy for endless free social media tools. Now we're, you know, we are, we're always trading something for these revolutions in technology.

Greg Lotko: 
You know, it's funny if I, if I think about the arc of the conversations you've and I've had when AI has been brought up, The thing I think I was reacting the most to was the theory that AI was gonna replace humans or humans in certain spaces. I always saw the ability for AI to make things better, faster, do more, all that kind of stuff. I think the real turning point for me, or the aha, is as much as AI is able to understand human tasks and technology, and it's a powerful tool, What I've come to realize is for AI to be its most effective, it's when a human has a great understanding of the AI capability, how to interact with and drive it the most. So it really is not just about AI understanding the human and the technology, but the human understanding the technology and the AI to get the most out of both.

Daniel Newman: 
Yeah, it's exponential. I mean, there's certainly, just like every industrial revolution of the past, there will be certain things that will, we will upskill humanity, right? You know, no one's running around town lighting the lamps at night anymore, but like, that became something bigger. Nobody's standing on an assembly line building those cars, except maybe in Maranello most places. They're not though, right we built, you know, and and the point though is is it created more jobs Not less and I it's starting to look more evident where it felt like at one time maybe it wouldn't this in this revolution wouldn't create more and it's looking like abundance is Well, I never believed that but okay, we'll see we'll see but I actually I tend to be coming to that conclusion as well Chad Thank you so much for joining us. It's been a lot of fun Yeah, my pleasure. Next time you come on mustache. We could we could be real we could look really I'm in twin I'm in I didn't get the memo, but I got it.

Chad Rikansrud: 
I'm in I got it.

Daniel Newman: 
Maybe I'll shave my head but That would be even more fun

Chad Rikansrud: 
Yep, you heard it here folks.

Daniel Newman: 
Definitely want to hear from you again. A lot of fun. Love that you have your hands on the tools and congratulations on the role here at Broadcom and we'll see you all again soon.

Greg Lotko: 
Thanks for joining us. Thank you.

Daniel Newman: 
And thanks everybody for being part of this Main Scoop. Hit subscribe. We appreciate the whole community. Stick with us for more content on the Main Scoop.

MORE VIDEOS

Fleet-Scale Deployment Is the Physical AI Benchmark

Physical AI is shifting from lab prototypes to fleets of machines operating reliably in the real world, and Ambarella's Muneyb Minhazuddin joins Six Five On The Road at AI Infra 2026 to explain what that shift demands of silicon, memory and developer workflows. Minhazuddin traces the case back to a 22-year-old chip architecture and forward to a developer cloud built to compress model porting time from months to days, and he identifies enterprise ROI proof points as the biggest hurdle left before physical AI scales into millions of deployed units.

AI Safety Alarms, China's Distillation Reckoning, and Qualcomm's AWS Breakthrough: A Pivotal Week for Enterprise AI

A viral AI extinction claim, a federal advisory naming six Chinese AI labs for industrial-scale distillation, and a $60 billion Qualcomm-AWS silicon pact define a week when enterprise AI risk and opportunity collided head-on. Patrick Moorhead and Daniel Newman weigh in on what's signal and what's noise across AI safety, chip supply deals, and a market rally still betting big on compute.

The 15-Cent AI Query: Broadcom's Paul Turner on Rebuilding Enterprise AI Economics

A Six Five study found an eight-to-one cost gap between running an AI agent through a leading frontier model and running it on modest on-prem hardware. Paul Turner, Chief Product Officer of the VMware Cloud Foundation Division at Broadcom, joins Daniel Newman and Patrick Moorhead at VMware Explore 2026 to explain how VMware's AI Factory turns GPU provisioning, model management, and security into a repeatable path from infrastructure to production AI.

See more

Other Categories

CYBERSECURITY

QUANTUM