Beyond the Old Playbook: Tanium on the Future of AI-Native Cybersecurity
Harman Kaur doesn't think enterprises have a visibility problem anymore. Tanium's Chief Technology Officer says most security teams already collect enough signals from enough tools. What they lack is the right data, feeding AI systems that can actually act on it.
Opening the Cybersecurity track at The Six Five Summit: AI Unleashed 2026, Patrick Moorhead and Daniel Newman get Kaur’s perspective on what that shift actually requires. Kaur points to Tanium Atlas as a product built around this core challenge: instead of navigating a UI, security teams can query any device across an organization in real time and get back what's running, what's vulnerable, and what to do about it. She frames governance the same way, built around consequences rather than risk. If a change can be reversed at low cost, Tanium gives AI more room to act autonomously. If it can't, a human has to approve it first.
Key Insights:
🔹 Kaur's thesis: security has moved from a visibility problem to a data problem. Enterprises don't need more tools to collect more signals; they need the right data feeding the AI systems already sitting on top of them.
🔹 Businesses should frame governance around consequences, not risk. For instance, if a change can be rolled back at low cost, Tanium gives AI more room to act on its own. If it can't be reversed, a human has to approve it first.
🔹 Tanium Atlas lets security teams query any device across an organization in real time, replacing UI navigation with direct answers about what's running, what's vulnerable, and how to fix it.
🔹 AI has compressed Tanium's own development cycle from months to weeks, enabling the company to ship new features daily as customer threats emerge.
🔹 Kaur's test for legacy security processes: revisit them from first principles. Alert triage exists because humans could only define so many detection signatures. AI removes that constraint entirely.
Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.
Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology audiences.
Harman Kaur:
The answer is no longer I need every single tool. I need the tools that give me the best data so that I can actually leverage these AI capabilities.
Patrick Moorhead:
Hey, everybody. Welcome to the Six Five Summit 2026. The theme is AI Unleashed. And if you have been keeping your scorecard, it is absolutely going bonkers out there. One of the key elements here, it's not just about more compute and more infrastructure. One of the biggest conversations out there is all about cybersecurity. And we're kicking off the cybersecurity track here with a conversation about one of the bigger shifts happening in the enterprise today. Daniel, you know, it's amazing. We can go every couple of days before there is some sort of AI security breach, some sort of outrage, some sort of governmental response. It is crazy. And I can't imagine being an enterprise trying to keep up out there.
Daniel Newman:
Yeah, it is pretty crazy out there. But it's also been really interesting to watch how AI has created these these kind of stirs in the market, right? We go from, you know, we have these new frontier models coming out, they're so disruptive, they're going to take over and be security. And then what we end up realizing is that these new models are actually creating this massive new attack surface. Every company now has a new challenge in that the cybersecurity and the key players in the industry are actually becoming exponentially more important. as AI continues to proliferate. So it's been a really interesting several months. I'm glad we're here at the Six Five Summit having this conversation because depending on the day of the week, the information flow has been so rapid that I think having the chance for people to hear from CTOs and CISOs and experts here at the Six Five Summit about what they're doing with their technology and also with the enterprises they serve, I think that's the right opportunity for people to really get their arms around what's going on.
Patrick Moorhead:
And joining us today to help unpack all of this space is Harman Karr, CTO of Tanium. Welcome to the show.
Harman Kaur:
Thank you. Thank you so much for having me.
Daniel Newman:
Yeah. So, you know, you heard us kind of talking, Harman, about everything that's going on. And look, We're just seeing this massive shift. It's happening so fast. And I'm watching this. I'm sure you're watching this. But AI capabilities, right? We've gone from lab to POC to the enterprise to broad and production deployment. You know, it feels like the old technology planning cycle has completely changed. It's gone from years to months to weeks to sometimes it feels like days. Just in your mind, like how does this compression redefine what modern cybersecurity organizations need to become?
Harman Kaur:
Yeah, it's actually really interesting. If I think back to when I was spending time in labs, evaluating technologies, generally you planned out your year, at least the next six months of saying, here's the technologies we're going to evaluate in lab, and then eventually obviously bring them into production. And you actually had time to plan, you had time to think about it and say, what are threats, what do we want to be doing, how do we want our organization Here's vectors that we can help improve, and it usually had a scorecard. And the other thing you had to account for in those lab environments was we have to train people, right? They need to be able to use this technology. If we're going to bring in a new security tool, a new patching tool, you actually had to spend the time and the money and say, okay, we actually need to buy the training that goes with it. And now all of that has really compressed, right? Like training for a security tool now is a chat prompt. Like as long as you can use chat GPT, right? You can use the new and latest and greatest security tool. And same thing with planning. I'm not sure if any CISO or CIO is looking 12 months or 24 months out. Everyone's thinking about the cycle, right? Vulnerability cycles, everything is sort of compressing so, so quickly. That's what we need to respond to. that doesn't really lend to really long cycles of keeping a technology in labs. And then eventually thinking about promoting that into production, you have to really compress that down very, very quickly. So I think a lot of those are forcing functions. Now, some of them are good, right? Like we don't have to spend three months training our staff to use a new tool.
Patrick Moorhead:
As Harmon, I'm glad you brought in kind of the historical perspective, right? A new type of security threat would come in and we would just add another tool, maybe another dashboard, another layer. And you had to integrate that. And by the way, enterprises had to integrate that with, you know, maybe five other security companies products, right? And that in itself, you know, exposed challenges there, but now, AI is really exposing the limitations of this. And you've talked a little bit about this idea of shared context as the real differentiator. Can you talk through that a little bit?
Harman Kaur:
I think there was a point where it was OK to continue to bring in more tools, layer in more tools. And then sometimes it was actually, now it sounds kind of funny, you would bring in a tool to make the other tool faster. We really can't do that anymore because we need context. The other thing is data really is important and you can't rely on one tool that pulls data every week. You can't rely on another tool that's pulling data every four hours, right? That mismatch actually has a difference on what these AI tools are going to do. And if your data is not complete and you have an agent and you have an AI tool that you're trying to use, it's only going to be that effective. So, you know, we went through the cycle of let's buy every single tool that's out there, every single tool that's harvesting as much data as possible because we need visibility. And I don't think we have really a visibility problem anymore. I think we have a data problem now, right? So what is the right set of data that I can give to these systems that they're going to actually help accelerate and protect my organization. And that's where everyone is now, is the answer is no longer I need every single tool, I need the tools that give me the best data so that I can actually leverage these AI capabilities. And then there's actually another side of this. As a vendor, as an organization that builds these tools, we can also build a lot faster using them as well. We are quite literally building alongside our customers as these threats emerge. They're stretching us in all of these different ways. And which I'm really grateful for, but we're able to say, oh, that's interesting. We can help you solve this problem. What may have taken us four months to do before, we can compress that development cycle into four weeks now and say, actually, we solved this problem for you. We ship new features and functionalities every single day, every single day. So think about that, like an organization of our size. We serve many, many, many large organizations. We ship features. and are solving problems and something new every single day. And that's what AI allows us to do.
Daniel Newman:
Yeah, it's interesting. And you sort of set me up pretty well here, Harman, for what I was about to ask you. First of all, I hear a lot in your answer about the industry's fragmentation, right? I mean, I think part of it is you're talking about lots of vendors, maybe some consolidation taking place as you try to like work across tools and then get contacts across tools. But you're also kind of dealing with a sea change, right? I mean, every security vendor is a, AI story, right? And obviously, AI is a continuum. You have some companies that I call sort of adding AI to their historical workflow and business. And there's other companies are sort of thinking and rebuilding from almost from scratch, like they're almost, how do we reimagine the entire capability or the tool in an AI native world, as CTO of Tanium and leading this, how are you looking at those things differently? Where do you add AI to the historically deployed, by the way, heavily utilized tools? You have all these enterprises going through stages where they want more AI, but they also don't necessarily want to have to completely relearn how to use everything. I think in the end, AI native is the way. How do you juggle all of that?
Harman Kaur:
The biggest thing that we talk about now is first principles, like why were we trying to solve this problem, even if the first time we solved this problem as an industry was 20 years ago? Why? What actually prompted us to solve this problem? And that seems like a quite daunting thing to do. And so when do you go back and say, let's go back to this 20 year old problem and rethink the way we need to solve it today now that we have access to AI, we have access to LLMs. Worse is to your point, which is like, just add AI. I think to the latter one, which is just add AI, we were doing that for a period to just build trust. You know, a very, very table stakes use case we hear about all the time is AI can help you triage alerts that come into your security tool. Initially, there was hesitation. It sounds insane to say this now, right? Not that long ago, a year and a half ago, we would show organizations and say, all your security alerts that come in, actually an agent can pick those up, triage them, and tell you what happened, give you details, it'll even tell you what it analyzed. you would think the reaction was like, oh my God, that is the greatest thing that's happened. The questions were, how do we know how we should trust that? Which weren't wrong questions at all, but people were really like, I don't know if we can trust that. Are you sure? Maybe we only have a triage these types of alerts. So there you actually had to keep the existing process and say, we're just adding AI to do these things faster for you. We're not breaking, we're not changing things. Now that that's the most table stakes feature and functionality that people look for in a security tool, now it's going back and saying, OK, well, why are alerts generated the way they are generated? Why did we put that process in place to begin with? Alerts are generated because generally you send down a, some people refer to as a signature, some sort of detection to the endpoint and say, look for this. And if this exists, then send me an alert so I can investigate. So, but that was a, those humans are saying, look for this badness on this machine. So that was also limited, right? There's a constraint there. Humans can only define so many signals and signatures to send. But with AI, like we can look at infinite number of signals off of these devices. Do we really need to wait to tell the device, here's what I define and deem as bad? So if you think about it, like we've missed actually a lot of signals because someone hasn't yet found a definition for this and to send down to the endpoint and then eventually get an alert for it. And so that's the way we've been sort of going is like, okay, we've built trust people, trust AI systems to be able to do this part of the equation now. Now let's sort of rewind and think about this problem from a first principles perspective. Why did we start this? Why did we solve this the way we did? OK, humans were trying to do X, Y and Z and humans obviously have limited amount of capacity. There's only so many humans in an organization. And I think another way I kind of say this to my team is you can't be doing the same job the same way that you today that you were doing three months ago, six months ago. You just can't. Right. We're missing a huge opportunity if we are doing it the same exact way.
Patrick Moorhead:
I think that's a great, great explanation that I think everybody can relate to. So I've been watching the security industry for probably 30 years, and it started off with perimeter defense, like, we're going to have security so good you can't get in. And then it evolved to, OK, you're probably going to get in. We're going to get you out really quickly, and you're going to do limited damage. And then the third evolution was, OK, we know you're going to get in. We can't keep you out. Let's recover the data. or the damage or the blast radius. And I think AI and security has gone through some multiple evolution as well. And let's be clear, AI use, aside from let's say AI ops, has been in security for a long time, right? a way to not only surface issues that come up, but also prioritize that. But now, we're moving even beyond, okay, something bad is going on. Here's a recommendation of what to do, and the human would do it, to the system actually taking the action on its own. What does an effective human in the loop governance look like in an environment like this.
Harman Kaur:
I kind of think about this from saying, what are the consequences? And I don't actually like to use the word risk. I think I use the word consequences more. So meaning humans can make mistakes, so can agents. But what are the consequences of this change being placed? And when I say consequences, there's other things. Can this change be easily rolled back? Is there actually a rollback that we can easily do? consequences, even if it seems really high, are actually quite low, because then you can just hit sort of recover and go back and redo this. Maybe it's a change that can't be reversed, right? So like, those are the things to like, think about. So we always kind of say, what are the consequences? And for things where the consequences are low, right, this system is not a critical server, this system, you know, it's an end user device in the middle of the night. And, you know, you can sort of build your trust and you can build your muscles and actually you can learn a lot of lessons from those experiments as well. So where can you allow, where do you actually have room to make mistakes and learn from the consequences right like I don't think consequences the negative word that's why I don't like using the word risk. where you want to actually have some sort of and then build a governance model around it and some of it is a little bit like let's just try let's try it on these machines even if there's a mistake that's made we can easily step this back or it's in the middle of the night no one's really going to be impacted and we can address that.
Patrick Moorhead:
It sounds like a really conservative approach. So it might be, okay, we've monitored something happening on a PC. It's in the middle of the night. We shut off access. The consequence is essentially, okay, somebody phones into tech support or messages somebody and says, hey, what the heck is going on here? It's really me, right? The consequence of that is, you know, maybe some inconvenience, but as you learn more about that trigger that set off the alarm, maybe multiple occurrences of that, you might not shut off that type of endpoint based on that signal you were getting before.
Harman Kaur:
Yeah, and that's where you may choose and say, actually, we want a human anytime we do this type of quarantine on the device. So yeah, it seems conservative, but I think it creates more of a balanced approach, because I want to make sure we're not reckless to say, you know what, these systems can be trusted. And the systems can be trusted, but the infrastructure we built over the last couple of decades for these systems to operate on, Like, right, like that's what we're all kind of working through and kind of trying to figure out how do we make it so these systems can run more safely and they're actually doing what we intended them to do.
Daniel Newman:
We're getting down the path here to autonomous security. Clearly, you know, it's one thing to sort of talk about the idea. You've sort of mentioned throughout this conversation, right, just that last example that Pat gave, like there's You say not necessarily risk, but consequences, doing anything autonomously, right? Agents are pretty cool. We do a lot of, in our own organizations, we like to build them. We like to deploy them. We don't put them all into production because as you know, like they do a lot of cool things, but there's a lot of work. I call it the rules and rails of business. And of course the rules and rails of security are even more complicated. Better safe than sorry, I think, but at some point you can also make it just constantly inconvenient to Pat's point. But like, this is your moment to talk a little bit of Tanium and what you are doing. But look, making autonomous security real, bringing it into a large complex enterprise and allowing it to be deployed at scale. Like, how are you doing that? How is it different at Tanium than the broad offerings that you're competing with?
Harman Kaur: I mean, it's a really good question. So what we're really focused on is we are trying to bring everyone closer to the data. That's what security is, effectively data. And what Tanium does at its core is we allow you to query every single device in a matter of seconds. Doesn't matter if your organization's 100,000 devices, or a million devices, or more. that you're able to interact with them in real time and say, what's running on this device currently? What's installed on them? And then what vulnerabilities open? Everything. If there is an alert, if there is a security issue, you're able to get that data off of that device in just a matter of seconds. Same thing if you need to actually make a change and say, I want to apply this patch, I want to update this application. All of that happens really quickly. And for years, we've made security quite complex, because you had to go through all these UIs to say, OK, I want to patch this machine. Think about how many people say, I am an admin, and they name the technology. Not, I am a vulnerability management person, or I'm a patching admin. They name the actual technology. Why? Because they've actually invested more time in learning the UI, which is probably the least important part of that. It's like, no, no, no, I need you to actually manage
Daniel Newman:
super tribal, right? It's very tribal, like I'm certified in this thing, as opposed to… Right, right.
Patrick Moorhead:
And I get invited to their show every year.
Harman Kaur:
Right, exactly. I got a shirt. Yeah, exactly. or a mug, but that doesn't really work anymore. If you think about it, you can't rely on that one guy. If there's an issue in the middle of the night, you could wake him up and say, this guy has the knowledge for this. Now, CIOs, CISOs, CEOs even are looking at vulnerabilities that they're on their phone, on their way to work, and saying, how am I exposed to this? What am I supposed to do about this? What devices do I have out there that are going to be impacted by Netflix? How do I need to get ready for those things? All of these things that I'm saying, all these questions, you can quite literally go into what is Tanium Atlas and ask those questions and say, what are my biggest threats right now across my organization? And we take that data that we're able to gather in just a matter of seconds, analyze that data, and say, here's the biggest threats in your organization right now, and here's how you can fix them. And it goes as far as analyzing it, right, putting, taking in context, as well as giving recommendations and drafting those actions for your approval. To say, do you want me to do something about these things right now? Even if you think about something as simple as what software is out there that hasn't been used, you can quite literally say, hey, I want to save a million dollars by removing software that hasn't been used in the last 30 days. It will go through, gather that data, and analyze it and say, here's the most expensive stuff out there that hasn't been used in the last 30 days, and you can save a million dollars this way, and quite literally even get you the dollar amounts. Or another really common one now is organizations want to be ready for MIPS, right? They want to be prepared; they want to have a way to respond, and not everything's going to have a patch. So how do you get ready when everything doesn't have an answer, everything doesn't have remediation? As soon as you hear about a vulnerability, you're able to type it into Atlas and say, tell me my exposure right now. And it can give you your exposure in real time, build you whatever dashboard visibility that you want to build in whatever format makes sense for your organization, and then ask it to help you remediate that, even if a patch isn't available. Maybe it's isolating those machines, right? Maybe it's making configuration changes change on those devices. So that's really what we've unlocked is this way. There's no UIs you're fumbling through. It's quite literally from a very simple prompt, just a click. You don't even have to type in these prompts. Recommended for you to getting this custom-built UI that you can navigate and then do something about it really quickly. And you don't have to bounce from tool to tool. Our single agent on the endpoint knows everything from provisioning a device to sensitive data that's on that machine. It records security data, everything in between as well.
Daniel Newman: Well, it sounds very exciting. Obviously, this type of innovation starts showing up in the growth, the numbers, as we mentioned before, sort of simplify and consolidating. I know from talking to many CISOs and CIOs that fragmentation is the hard part of security. Unlike many of the systems that businesses run- you know, a core ERP, a core CRM- they have 65 security tools. I mean, maybe I'm exaggerating in some cases; maybe I'm not, but to be able to contextualize, basically, right. I think we've all entered the era where it's like, look, we just want to talk to our systems the way we would talk to an employee. The agent is the employee. And like in many ways, the more ubiquitous and the more seamless that becomes, the more productive the business becomes, and the more secure you can actually build your environment. Thank you so much for kicking off our cybersecurity track here at the Six Five Summit 2026 Unleashing AI. Look forward to following the Tanium journey, and congratulations on the promotion to CTO.
Harman Kaur:
Awesome, thank you so much. I really appreciate it.
Daniel Newman:
All right, and thank you to everybody out there. For our viewers, don't forget to hit that subscribe button, follow us across our social channels and check out all of our Six Five Summit content at sixfivemedia.com slash summit. See you all for the next summit sessions; stay tuned.
Speaker
As chief technology officer, Harman Kaur leads Tanium's technology strategy, product management, AI and automation roadmap, and strategic technology partnerships.
Harman brings more than a decade of combined experience across the United States Air Force and Tanium. She continues to serve as a Cyber Officer in the U.S. Air Force. At Tanium, Harman has held senior roles across the customer organization, R&D, and most recently led the company's AI and Autonomous Endpoint Management strategy as head of AI before stepping into the CTO role.
Harman received an MBA from the University of Southern California and a BS in Information Systems from Hawaii Pacific University.


