SentinelOne, Inc. (S) Earnings Call Transcript & Summary

November 5, 2025

NYSE US Information Technology Software conference_presentation 295 min

Earnings Call Speaker Segments

Eran Ashkenazi

executive
#1

Please welcome our CEO and Co-Founder, Tomer Weingarten.

Tomer Weingarten

executive
#2

It's always so incredibly exciting to see everybody here and do this every year. I actually want to start by welcoming everybody to OneCon, but I also want to start with thank yous. I want to thank our customers, obviously, I want to thank our partners. I want to thank our teams. There have been so many dedicated Sentinels working day and night to make this possible, the people that build the products, the people that support the products, the people that sell the products, everybody is putting their heart and soul to make this event happen and also, obviously, to fuel the innovation that protects all of us collectively. So let's give all of you and them a nice round of applause, please. Okay. And yes, this is always a very exciting event. But I don't know, for some reason, it kind of feels even more exciting this year. Maybe it's the smell of GPUs in the air, maybe it's the fresh sound of data center compute cycles. I don't know what it is, but it seems like the future is upon us. It's very clear that this year, with the advancements in AI, we are looking at a whole new landscape. We're looking at a whole new future of possibilities, not only for cybersecurity, but for all of humanity. And sometimes it's exciting, sometimes it's a little bit scary. I mean, the unknown, the uncertain, it's definitely very interesting to see it where you're on the front row, defending from the bleeding edge use cases of how people leverage AI, both for good and for bad. So there's not like a really great way for me to ease into it. But at the end of the day, cybersecurity has become the single most important factor in the survival of humankind. It's no joke. It's no longer a technical discipline. It's a survival imperative. Humanity's dependence on intelligence and on infrastructure, on systems and on data makes the protection of these systems fundamental to civilization itself. The digital, biological, geopolitical, all of these worlds are merging together, making the security of intelligence and of systems synonymous with the security of life itself. I'm not exaggerating. This is the meaning of cybersecurity. The question is no longer whether cybersecurity matters, should we do it more? Should we do it less? Is it working? Is it not working? It's really becoming a very simple question. Can we sustain existence without cybersecurity, without mastering the discipline of cybersecurity? And given that the balance of power, the stability of this world will depend on how we govern AI, how we control AI, how we harness AI for our own benefit, for humanity's benefit, it's important for us to always remember that AI's potential mirrors its destructive potential as well. Nation states and individuals alike can easily wield AI for disinformation, for disruption, for creating havoc and mayhem complete digital warfare. We're starting to see that already. You'll hear about it in some of the sessions that you listen to today. This new arms race is not about weapons. It's about control. It's about control of autonomous intelligence. It's about control of compute, and it's about control of energy. A secure AI future requires global cooperation. It requires all of us bending together and working together to create a different reality. It's about ethical design and it's about resilient architecture. What does the world need most from cybersecurity? We've all been doing cybersecurity for quite a long time now, but it doesn't seem like we're giving all of us that use cybersecurity, both as enterprises and as end consumers, what they need. So let's try and figure out like what are these things that cybersecurity needs to deliver to make the world a more secure place. Well, the first one might be an easy one, but it's not. Trust, security must be intelligent. It must be autonomous. It should be anticipatory. It cannot be reactive. All of cybersecurity today is entirely reactive. That is a huge problem. It also has to be fully auditable, steerable and transparent, which again, is not the case today. We have a hard time trusting our cybersecurity. Continuity. We all look at cybersecurity today as this force that is there to block the badness and rein us back in, make sure we're not doing things that could eventually lead to a breach or to a compromise. But in essence, cybersecurity should empower progress, should not restrict it, should not limit it. It should enhance the flow of information and not stop it. And lastly, confidence. The world needs confidence in the systems it uses and the systems it depends on, the ability to move fast, safely and with agility. But there's many, many, many challenges with cybersecurity today. We here wake up every day trying to solve some of the most monumental challenges in cybersecurity. And to get to where we believe the promise of cybersecurity needs to be, we have to overcome these challenges. And the first one, and I'm sure none of these are going to be very surprising to you, is complexity. Too much data, too little understanding. The volume and diversity of data today is beyond any human comprehension. We got no way to decipher all the data alone. We got no way to make sense of it. We got no way to do it in a manner that actually provides the outcome that we want. The second thing is fragmentation, probably one of the most deeply rooted issues of cybersecurity. Fragmented defenses, where defenses remain siloed. They don't talk to one another. They don't know one another, no idea what each one of these surfaces are doing. Endpoint, cloud, identity, network, all of them are disconnected. You can put all the data in one nice place. It doesn't mean these surfaces are connected or that they know how to exchange data and exchange insights between them. And lastly, speed, which is one of the most critical ingredients to ever be able to protect any asset in this world. Attackers weaponize AI faster than defenders can adapt. I think this is very, very clear and true to today. Without being able to monitor what's happening right now in this instant and act instantaneously, we will become irrelevant. Cybersecurity will become irrelevant. If cybersecurity continues to be after the fact, it will become completely irrelevant. Okay. As we think about all these different ingredients and components, I think it's also important to ask what do we need to secure even? I mean, are we securing servers? Are we securing the cloud? So when we kind of wake up in the morning and we think, okay, how do we design our systems? How do we design the systems that we give you, we really try and focus on what are the biggest things that we want to make sure are going to be safe. And the first one is us, people, human identity, protecting who we are and what we do in digital form. And it's no secret that our digital identity is becoming as important, I guess, for some people, even more important than our physical identity. Think about all these influencers. Their identity online is greater than their identity in the physical world. Eventually, and it's happening today, both identities are going to merge together. We will not have a separate identity. It will be one of the same. So we have to protect that. And then obviously, data, but not data itself, but data integrity. If we can trust that the information that we're consuming is authentic, that it's uncorrupted, that it's not painted, we cannot trust anything that's built on top of that data. So we have to go back to our foundations to make sure that this world is secure. And lastly, intelligence, artificial intelligence, system intelligence, as our dependence grow, we have to make sure that artificial intelligence itself is not being manipulated by any type of bad actor. Truth itself is under attack in the world of today, synthetic identities, deep fakes, misinformation, you name it. It's all happening. And that algorithmic manipulation sometimes blur what's actually real. Okay. How do we get there? I mean enough with the doom and gloom. Let's do something about it. Let's make sure we can actually live in a safe world for all of us. But we need an entire change of approach, an evolution of approach, if you may. And it's really about the architecture of the future and what we need to build right now, autonomous architectures, streaming architectures, contextual and accountable from reacting to preventing, from this concept of detection and response to, let's say, proactive and predictive from complex to simple and ideally from simple to invisible. This is where security will go. And we're putting some tangible foundations. You're going to hear a lot today through our innovation sessions of what's coming to the platform that you all use. And that's really important. Why we work on this vision? And I'm actually going to show you a quick sneak peek video on what's coming next, what we've been working on and what we're going to continue to work on. What's going to be important to remember is that we're taking a gradual approach that doesn't only end with a spectacular mode for cybersecurity, but also that infuses capabilities every single day to the console that you use today to the Singularity platform. There's no one big bang where security gets solved. It's all going to be gradual. It's what we need to make sure that we move from this reactive mode of today and into an autonomous mode in the future. But again, it's not going to happen in one fell swoop. Streaming data, high-frequency ultra-scalable data lakes. What took hours with legacy systems processing data is now taking seconds in high-frequency data lakes like the Singularity data lake. That's a step function change in what you can now do and what you can now create with these types of technologies. And it's very, very meaningful because when data lives within the platform, it really means that artificial security intelligence like Purple can now act immediately, instantly and across all that data, all these entities and all the time. When you can query up to 7 years of history of data and you put all that context into AI, you get a very, very different outcome than just the bolt-on AI, let's query, let's do some NLP type stuff that you're seeing from a lot of others in our space. To get AI actionable for cybersecurity, it's not enough just to put the data into it. You have to build contextual augmentation, you have to reduce the noise, and you have to enhance the signal. It's not as easy as taking data and putting it into an LLM. It's about building a whole system that creates that outcome, an outcome that is autonomous, but that is also incredibly accurate and is fully auditable. We don't want any system out there that has something that we cannot explain or that we cannot audit or that we cannot trace back. That's a huge imperative to how we build AI systems. So let me show you a quick video. And when I say quick, it's going to be really quick. If you blink, you might miss the interesting bit. We've been trying to balance between exposing what we're working on, but also giving you some understanding of how we're thinking about the problem. And again, I think you'll find it really, really interesting. [Presentation]

Tomer Weingarten

executive
#3

Okay. Yes, I know. I know. I know. It's fast. I know. I know. Look, it was either this or not showing anything. So we opted to give you something. But really, I think when you look at what we're building today and that fusion between humans and AI, I think that's the most interesting bit of all of cybersecurity right now. How do we bring these disciplines together so we can actually create a safe mode of operation for AI without taking away any of the speed. And you'll see some of the components that go into the system are being actually now introduced in the Singularity platform, but I'm not going to steal their thunder. There's going to be a great innovation session later on, and you're going to see what investigations are looking like. So all of this comes with a pretty significant ethical imperative as well. We have to harness AI responsibly. We can't just put AI and hope for the best or just enjoy the benefits without thinking about the guardrails needed in place. So we have to do it with accountability and supervision. Every AI decision must be explainable, governed and aligned with human intent. So AI is not just this force that goes through tasks, it's actually something that is aligned with what we want to achieve. It's an autonomous system that can act at machine speed, but is always in service of human purpose. And that's hard. Aligning these models to what we want is hard because sometimes we don't even know exactly what we want them to do. Connecting all these endpoints, these clouds, users, everything together, that's the goal with AI, deciphering through the masses of data and putting it together in one context. That's the adaptive ecosystem that we want to create. And that's why you've seen us go and acquire. You've seen us go and build. You've seen us go and partner to create that adaptive ecosystem. And all of it is for one purpose that you are a part of, securing the human future. The mission of cybersecurity is freedom. It's freedom to innovate, it's freedom to build, it's freedom to thrive. Cybersecurity should protect human potential, not limited. And the measure of success will be a world where humans and machines collaborate safely. That's what we all want, creatively, ethically. The mission of cybersecurity is not control. It's freedom to ensure that technology remains humanity's greatest ally. And that's our commitment. That's what we're here to do. That's what we have been doing for the past decade. We are here to champion humans. We're here to empower. The world needs security that is invisible yet omnipresent. The world needs security that is intelligent enough to protect without friction. And it has to understand purpose, which is probably the most difficult thing about this entire problem. But we are here, and we're committed to innovation. We're committed to creating this future with you and for you. This is why we wake up every single day. Every single Sentinel knows that this is the mission that we have today, that the technology that we built and are building is doing one of the most critical and important things one can ever do. So with that, thank you so much. I'll see you through the innovation sessions as well, which will be much more interesting than this one. So thank you so much. Really great to see you all.

Steve Stone

executive
#4

All right, folks. Thanks, everyone, for being here. I really want to start with that. Time is our most valuable commodity. You've chosen to spend that with us today. So we just want to say thank you for us here at SentinelOne. So as Eran mentioned, I work inside an organization where we focus exclusively on threat. All we do is bad guys and breaches. No other topic hits our portfolio. And so we really get to spend our time on what are we seeing today and what are we expecting tomorrow. I was initially asked to do kind of the fairly typical conference talk. Let's stand up, let's talk about a year-end review, let's tell you what we saw, pretty safe. So we wanted to be a little bit riskier actually. We wanted to provide 2 different things. First, we wanted to talk to you about what we think is coming. That's risky because we are often wrong when we do assessments in the Intel business, most folks just call that guessing, but it's Tradecraft and Intel. And the second, we want to give some visibility into how we see the world. We want to be transparent with our customers and partners, so you can make your own assessments based on our world view. So we're going to really focus on 4 major needle movers that we think are going to radically reshape the threat landscape in the next 3 to 5 years. I'll cut to the ending here and tell you what those are going to be. Those are going to be Russia, China, North Korea and AI, but we'll dive into all 4 of those more as we go through. As we kind of kick off, though, I really want to kind of start with this. This is what intelligence is. I've spent 25 years doing threat intelligence in the military, in the intelligence community and in the private sector. We love to overcomplicate this topic. We love to explain Tradecraft. Don't even get us started on classification markings and sharing. But ultimately, intelligence is really straightforward. Our job is inform decision-makers by providing the right data at the right time in the right format so it can be actioned. That's it. That's all we do when the [ day ] is done for intelligence. So in that spirit, what we will do today is we're going to give you the same thing that we give our executives and our Board. How do we think the world is going to change? For us, we use that to forecast what capabilities we need. For you, it's no different. How do you secure your businesses not from yesterday, but from what's coming tomorrow. This is really hard, though. I made that sound really, really easy. Where do you focus really comes down to 2 core challenges. And the first is just signal-to-noise ratio. Both of these are going up dramatically. I'll kind of start with the noise first. I won't waste anyone's time. All of our news feeds are full of cyber threat stories. You can see them everywhere you go. It's almost -- it never ends. It just keeps going. But we're also seeing just as much signal, actual real things. Every single measure in the threat landscape is up and to the right. We see more actors than ever. We see more malware than ever. We see more vulnerabilities than ever. Like there's a trend here, right? Like I could just keep going. Not one trend is going down in the threat landscape. So we see both the increase in signal and noise. And I'll talk a lot this morning about context. I think context really helps us make good decisions. Cybercrime, according to the FBI, has gone up 144% in the last 6 years. Let's compare that with traditional crime. Burglaries are down almost 50%. Drug crimes are down 27%. Homicides are down 15%. Imagine if I stood on this stage and said, we think in the next 6 years, there will be 144% more murders. That's the comparison we have when it comes to cyber threat. We're not saying that to scare. We're not saying that to spook. We're really saying that as a call to action and how to use this time to prepare for those things. So ultimately, when it comes down to intelligence, we make guesses. We make assessments. This is kind of a typical one. I'm not the first person to stand on a stage and give an example of an assessment gone wrong. But I want to flag this not because it's funny, not because Robert Metcalfe got this wrong, but to show how challenging this business is. For those who might not know Robert Metcalfe, he was the co-creator of the Ethernet. This person knew technology. He's a Turing Award recipient, the highest honor in his field. He has an actual law named after him. Metcalfe's law dictates the way that modern telecoms work to this day. And this is what he thought the Internet was going to do in 1996. It's easy to get this wrong. It's also easy to stand on stage and kick rocks at other people. I've been doing this business for 25 years. I have been wrong more times than I can count, but that's the job. The job is not to tell you history, it's to tell you what we think is going to happen. In one of my more and more infamous papers, when ransomware was starting to flip over from targeting individuals to corporations, I was asked to author a paper that went to multiple governments, multiple Fortune 500 companies where my assessment was relax. This ransomware thing is not a big deal. It's going to be like DDoS, we'll figure it out and it will just be background noise. So I don't want to tell you not to listen to me, but let's also add some context. Some of this is going to be us saying what we think and some of that's going to be incorrect. So as we move forward, how do we do that? How do we predict the next 3 to 5 years, knowing we're going to make mistakes. The way that we approach this at SentinelOne is we really do it very similar to the futures market. I'm not a finance person. I'm not a quant. I won't dive really into how this market works. But the model that we use is let's look for the major trends and then let's assume variance, just like the futures market does. So this is why we're going to talk today about what we think the 4 major trends are going to be, what is going to fundamentally shift the threat landscape versus describe to you what the threat landscape looked like yesterday. As we go through that, there's going to be of the 4, 3 of them that require geopolitical context. I think one of the things that is different at SentinelOne, and we take quite a bit of pride in, we don't just do cyber intelligence. We also do geopolitical intelligence. This is part of what we do. So the 3 events that we think require some scene setting before we dive into the landscape starts with Russia. Multiple governments are assessing that Russia is going to invade a second European country no later than 2030. This is one of these assessments that's actually not that hard to make. You can actually literally see it from space. We're watching Russia rebuild multiple military bases. At the same time, they are an active armed conflict with Ukraine, and some of these bases are different. Some have more context. This one you see here, this is a Russian military hospital that they're building right on their border. You only build military hospitals on borders when you expect casualties. There is no other purpose for these institutions. So we could talk all day long about why we think Russia is going to invade another country in 2030, but we think this will be the scene setter for 1 of the 4 needle movers that we're going to see, and we'll come back to this. The other part we see is we're watching them do this today. Literally yesterday in the news, Russian military aircraft were probing European airspace. They've been doing this all year long. This is a typical Russian playbook that they run in advance of intrusions -- sorry, invasions, I should say. The second major needle mover we see is going to be China, Taiwan. I've spent most of my career as a China watcher. I love, love, love China from an intelligence perspective because it's the easiest thing in the world. They do this crazy thing in China where they write down what they're going to do and then they go and do it. They literally follow their plans. They tell you 5 years ahead of time what is going to happen. And then they write another paper that says, here's what we need to adjust, and then they do it again. Forecasting China is like the simplest thing in all of threat intelligence. Number one on their list is reunification with Taiwan. We've been talking about this as long as I've been doing this. This was here before I showed up. However, we think this is changing right now. We think the China-Taiwan situation is potentially the single most important thing we will deal with from a cyber threat perspective by the end of this decade. And it's based on a few things. Ultimately, it's based on one person. Xi, who runs China, when 2022 was appointed to his third term in the Chinese Communist Party. I won't spend too much time getting deep into Chinese politics. This is a big deal. A big deal there is a third term senior leader. And immediately upon him taking office, he starts going through and making actions for Taiwan. Within a week of taking over, he officially tasks the Chinese military to have the capability and war plans to invade Taiwan no later than 2027. We're going to come back to that date. That data is really important. We then start to see other things happening. We start to see things like China building up its maritime fleet, not its Navy, it's actual commercial shipping. Why in the world are we talking commercial shipping at SentinelOne's OneCon event. This is how invasions work. There's a great quote that's hundreds of years old now where Napoleon talks about amateurs talk tactics, professionals talk logistics. This is how invasions are fed. This is how invasions are equipped, and we're seeing it in real time. Again, I would love to say we're really smart, but you can see it from space. Like this is not hard to find and ascertain why this is happening. We also look at other things that are happening that they are forecasting. And in 2027, there are 2 major events that will concur at the same time. First, the Chinese Communist Party will celebrate its 100th year anniversary. They are already planning this being their largest event for 2027. This is going to be a huge deal in China. And Xi is laser-focused on his place in history. He is adamant in carving his name into the rock that is Chinese history. He wants to be viewed on the same page as Mao, and he looks at this 100-year anniversary as his window to do that. Also, he has already declared he has every intention of taking over a fourth term. No Chinese senior leader has ever taken over a fourth term. And all reporting indicates that he wants to do this because in his fourth term, he can unify China and Taiwan. We are seeing multiple indicators, this long-term topic is likely to come to fruition in the next 2 to 3 years. So this is going to be our second needle mover that requires some geopolitical context. And the third is North Korea. North Korea is the opposite of China. This is the wildcard. They routinely do things both in cyberspace and also in the real world that just surprise us. And the world changes very quickly in North Korea. One of the major events we've seen over the last 10 years is in 2017, North Korea underwent significant international sanctions based on their testing of nuclear weapons and ballistic missiles. That led to what the world thought was going to be an economic suffocation of North Korea that would force them to move off of their aggressive geopolitical situation. And that's not really what happened. Let's pin 2017 in our minds. I'm going to come back to 2017 here in a few minutes. That's going to be a very important date. So as we fast forward a few years, what we saw was the opposite. North Korea actually became more aggressive. Something happened between 2017 and 2021 that allowed them to not only survive sanctions, but become more emboldened, become more aggressive, and that has been accelerating in the last 8 years. The largest acceleration occurred in 2024. North Korea, for all of its aggression in this world, had always stated publicly they intended to unify with South Korea peacefully, no longer. In 2024, they said that is not an option, and they believe absolute kinetic warfare is the only way to unify the peninsula, and that is their #1 goal is North Korean regime. We then see this pick up even more speed as 2024 plays out. We see North Korea send tens of thousands of troops to fight in Ukraine along with Russia. This is the first time in decades, North Korea has sent troops abroad. They are able to pay for this. They are able to pull this off, and they are willing to go to a higher level of aggression geopolitically on an international stage. And as we look at that, we also see this recently. In the last 2 months, for the first time in years, North Korea sends representative to the UN and their entire message is we are going to become more aggressive. They are not going to give up nuclear weapons. They are not going to give up ballistic missiles. They are not going to give up sending their troops somewhere else. So as an international community, we're kind of stuck to say, why are they able to do this? Why are the sanctions not working? And we think that will be the scene setter for our third major needle mover. Before I dive into how we think all of this is going to manifest on the actual cyber threat landscape, I think we owe all of you an explanation on how SentinelOne sees the world. It's great being up on stage talking about politics, but I can't load doctrine into a firewall. I can't take a public statement from the UN and make that go find something on EDR. That's not the way this works. So let's walk through how SentinelOne converts this and how we see this playing out across the world, and then we'll dive into what we think are going to be the really large landscape shifts in the coming years. The first thing that we talk about is we see the world through you. Our clients are our visibility. This is how we interpret everything that we talk about when we look forward. We have about 14,000 clients in about 80% of the world's countries. We're not in North Korea. They're not a big fan of ours. We don't have a lot of agents deployed in Russia. I don't think anyone would be surprised at the 155 countries that we're in, but this is the space we're at. This is ultimately the highest level view that we have is through your organizations. That manifests one layer down by our access to about 40 million endpoints and about 2.5 exabytes that we can hunt and move across. In essence, this is where we test our theories. This is how we say, we think the world works this way. Let's go look and verify. I'm not a math guy. My undergrad is an Anthropologie. So millions and trillions and billions confuse me pretty easily. But just to give some context here, if every one of you was a SentinelOne EDR agent, it would take 73,000 rooms to equate how many endpoints we have access to right now. All I know about exabytes is it has 18 zeros. That sounds like a lot. If I converted that to my Spotify playlist, that playlist would be 2.5 billion years long. I'm not saying we know everything. I'm saying we believe we have enough data to make qualified assessments on where the threat landscape is going. If we take that down one level, it's a difference what we can see versus what we know. How do we test these ideas? And there's our detection engines, there's our hunts. In this case, we just took indicators, it's tangible. We can openly talk about how many things we see, how many groups we are tracking. This is what we apply across the visibility you as our clients provide to us as an organization. But all of this ultimately comes down to outcomes. Outcomes are where we actually get to assess how the landscape is changing and where we are going. And if we look at just some examples here, ransomware, I'll come back to ransomware. It turned out I was super wrong in 2016. We did not solve the ransomware problem in 2016. In the first 9 months of this year, we have stopped over 1,000 attempts to deploy ransomware actively inside of client environments from more than 65 distinct threat groups. This is now where we start making our assessments. This is really where the rubber meets the road, and we synthesize down that combination of what we can see, what we're testing and then what we know. And that synthesis is really where intelligence comes in. I'll just take one example from our MDR organization. The first 9 months of this year, they triaged about 26 million alerts. Nobody cares. Absolutely, nobody cares how many alerts we looked at. There is no inherent meaning in that. What happens is we synthesize that and crush that down to about 15,000 incidents. Incidents are where we can make decisions. This is actually what matters. That synthesis is how we talk about intelligence and how we create our world view. So now that we've given a little bit of geopolitical context, we've given a little bit of synthesis and how we see the world, let's dive into what we think these 4 major shifts are going to be across the threat landscape. Number one, let's go back to Russia. We started with Russia. I think it's the first place for us to start. What we look at is if Russia invades a second country inside of Europe, what's that going to look like? We know what happened with Ukraine. So let's start with that. We got to see in 2022 when Russia invaded Ukraine, the first real cyber war. We've debated this for decades. We've talked about it. We've got papers written. We actually got to see it with our own eyes in 2022. And what Russia did that I think are important for takeaways are 4 things. First, they synchronized their military operations with their cyber operations. They did not view cyber as a silver bullet. They did not view it as stand-alone. They viewed it as part of their overall warfighting capability. Second, they did not just use their nation state programs. They did not just use APT28 and APT29. They leveraged their own inherent organic programs. They leveraged all of the cyber criminals that they have allowed to operate [indiscernible] inside of Russia, they had expectations for them. Those bills came due in Ukraine. So we saw cybercrime as an active component of Russia's push against Ukraine. And then we saw the exact same thing with hacktivist communities. Russia applied a full spectrum of their overall capabilities against Ukraine. Third thing we saw, and this is one that if you would have been in a conference with us 4 years ago, this is all we would have talked about. We have never really seen destructive cyber, actual destruction on the ground. Any intelligence analyst as recent as 4 years ago could have told you exactly every single time we saw destructive events because there was like 2 of them. Like there just was not that many, so they matter greatly. In the first 6 months of the Ukrainian invasion, we saw 9 distinct destructive tools. And then it became so prevalent, we kind of lost count. And I would love to tell you we have all these absolute answers. But as an intelligence community, we don't even agree. We kind of threw our hands up at dozens. So the reality of will nation states use destructive cyber? Russia will. They absolutely will. And then the last part, for the first time ever with any country and any conflict, we got to see the endurance of a country. We can talk about intrusions in isolation, but that's what it is. It's a one-off. We actually got to see in Ukraine how long and how deep and how persistent could the Russian cyber efforts be? And the short answer is, yes. Short answer is all of those things. They did not have to stop running intrusions in other parts of the world. They did not stop innovating, and they were basically daily drivers going after Ukraine day after day after day for 3-plus years in counting. They have the endurance to execute these programs on multiple fronts. We expect all of this will happen when Russia invades a second country in the next 3 to 5 years across Europe. Here's what we think will be different. We have a list across the international community of like the most 2 to 3 likely countries Russia will invade. All of those countries are either part of the EU or are a member of NATO. Those will make the next conflict inherently more complicated. And that will start with Article 5. Article 5 inside of NATO is, in essence, a call for common defense. You attack one NATO country, you attack all NATO countries. So now this will not be Russia versus Ukraine. This will be Russia versus a country and then all of NATO, EU involvement. This battle space will get incredibly complicated very, very quickly. That's difference number one. Difference number two, Russia has a much broader target surface. Ukraine is not that big. It just really isn't. They will have the ability to go after entire swath of the globe to produce their impacts. That will impact our business. Third, Russia is deeply integrated with the European economy and also Russia struggles with sanctions, both that interdependence will produce impacts and sanctions will produce impacts. We think that will drive a more immediate extreme reaction from Russia. They will need to have an incredibly severe kickoff versus a 3-year prolonged event. We expect to see a much more widowmaker-like type initial event because they're racing the economic clock. And then fourth, before the Ukraine invasion, no one would have assessed Ukraine as a very cyber-resilient place. That wasn't what any of us had on the scorecard. Ukraine turns out as incredibly cyber resilient. They've impressed whole swaths of the cybersecurity industry. We then compare that with the European countries, on paper, they're far more resilient. They are far more secure. That is likely to be stress tested. Our entire way we think about resilience is likely going to be stress tested when Russia invades the second country. Ultimately, for our businesses, we think these are what you need to pay attention to. We should expect everything we saw in Ukraine, except it will be applied at, at least, a regional scale, if not a global scale. What is happening to Ukraine now is what we should prepare our businesses to, especially if we work inside of Europe. Second, we should expect an extreme event very early, and then we have to find a way to survive through that. And then these last ones really all kind of go together. It's going to be complicated. There's going to be multiple countries with their own competing priorities, their own assessments, all having to come together to figure out how to work against this threat. I've been lucky enough in my own time, I've spent some time working with NATO. It's complicated. For any folks that have had to work with allies, the only thing worse than going to war without allies is working with them every single day. Allies are hard, like that's just the reality. Ukraine is simple. It's Russia and Ukraine. And our cybersecurity entire industry is largely supporting Ukraine. That is highly likely to be very different when we have this first needle mover with Russia. The second needle mover is going to be China. I mentioned how China is the easiest thing in the world. China as an intelligence analyst is also the hardest thing in the world. And here's why. It is almost impossible to talk about the scope and scale of China's cyber program without sounding like a crazy person. Like you just sound like you're making stuff up. You sound like you're saying just crazy stuff that no one can believe. So let's just baseline with one thing. In the last year, we've seen significant media, government and industry reporting on only 2 Chinese cyber groups going after telecoms. Let's quick refresh. China has dozens of cyber programs that we're aware of. These 2 alone have compromised more than 80 telecoms with access going back at least 12 months. The U.S. government assesses every single U.S. citizen has been impacted in that effort from these 2 groups. And oh, by the way, most of those intrusions go back at least 3 years. This is just a baseline. And the telecom piece is not unique. This is what they do in every industry and have been doing for at least 20 years. This is not a one-off. So when we think about that long-term access, that espionage event, all of a sudden becoming an invasion. Guess what happened? China told us exactly what they're going to do. They have every intention of using cyber specifically to infect and influence multiple global populations, so countries stay out of the war. They do not want the U.S. involved. They do not want NATO involved. They do not want Japan involved. They do not want Australia involved. So their intention is to use cyber to make the home population so uncomfortable that governments have to stay out of this conflict. We think on our best assessments, this will go on for 18 to 24 months globally. That's how long we think it will take them to accomplish their invasion. That will be a mix of highly targeted attacks against specific places, widespread espionage, just like they're doing now. And then the third bucket, information warfare. We really haven't dealt with this. Outside of Taiwan and some dissidents and some other areas, we have never really encountered China's information warfare apparatus. We assess it to be significant, and we will now have that problem to deal with along with everything else. If we look at this, what are these likely outcomes going to be? These are the things that we think companies need to be prepared about. You have to assume they already have access. They are spending years and years preparing for this scenario. They are telling us they're preparing for this scenario. They are telling us they will go after water supplies. They will go after trade routes. They will go after ports. They intend to shut down communication. Let's talk about the comms piece alone. Every time there's an AWS outage, I find out because like Roblox is down, my kids can't get on their programs. And oh, by the way, all of our stuff goes down. That happens for a 2-hour AWS outage. That happens when Azure goes down. Imagine when the intention is to put down massive communication capabilities for weeks to months. We will have to operate our defenses without having all of our capabilities in that. And then also the last couple here, China wants to influence the population. Of all the access China has had and all their intrusions, they have never leaked secrets. Russia has, Iran has, North Korea has, ransomware has. China has access to material that will undoubtedly change the way people look at their governments. They have access to data that will undoubtedly reveal things that we do not know about our own governments, and they have every intention of using that. So not only will be dealing with intrusions and impacts and information warfare, we will also have to navigate this through. This goes from being a CISO job to like your CMO is now part of this. Your CMO is now going to have to answer questions. Your comms people are going to be involved. So we think about what these mean. We think these are the things that we're looking at. And ultimately -- and this is where Russia -- or this is where China makes it sound inflammatory a little bit. We think this has the potential to be the single most important cyber event we've ever seen. That sounds dramatic, but we think it will be that important. We think if China invades Taiwan, it will be unparalleled across the cyber threat landscape. Third one is North Korea. I can talk North Korea all day long. I promise I won't. If you've read anything North Korea in the last year, it's been about IT workers. I want to use this as just a quick baseline. We know as an international community, North Korea has 10,000 North Koreans that log in every day and get paid by IT companies to do an actual IT job, like they're actually working and they're actually getting paid because it generates between $400 million to $600 million for the regime. If they're willing to put 10,000 people every day on generating $500 million because they need it, that's important, and we'll come back to why that's important. Just for some examples here at SentinelOne, we put some research out from our Sentinel Labs team. The first 6 months of this year, we were successful in stopping more than 360 personas apply for more than 1,000 jobs against SentinelOne. They're not interested in SentinelOne. International reporting has this happening at about 6,000 companies where they've actually been hired and their actual employees. I'll kind of point to another session. Tom Hegel is going to give a great talk on how we've gone about this, highly, highly recommended. But this is pennies compared to crypto theft. We have become snowblind to crypto theft from North Korea because it's been happening nonstop since 2017. Can I tell you definitively, North Korea started stealing cryptocurrency at wholesale because of sanctions? I cannot. I can tell you it started happening 60 days after sanctions went into place. I can tell you they've doubled down on it every single year, and it's gone up 28x since they started in 2017. To rotate the problem a little bit, 2/3 of every cryptocurrency stolen was stolen by the North Koreans. This is how important this is. And if they're willing to put 10,000 people on $500 million, what do we think they're going to put on $2 billion and counting for this year alone. This matters as a needle mover because it just provides huge returns for them. We compare it against traditional crime. You can see it's not like a 2x, a 4x, it's 1,000x. It's 100x return on their investment. And the bottom line here is the most important part. We know they're doing it. We absolutely know they're doing it. They're being attributed, and it does not impact them at all. So they're just going to keep doing this more. So I mentioned earlier, MetCalfe's law. I'm going to take a swing here at Steve Stone's Law. I'm going to try my own little math formula here. So this is patent pending. No one steal this. It's a $100 bill plus EUR 100 times [ fakeair ] is greater than Bitcoin. That's Steve Stone's law. And what this really means, when we talk about why North Korea matters and why it will shift the landscape, this has always been a criminal regime. They are so good at crime, the U.S. government and the EU had to completely rebuild the $100 bill and the EUR 100 because they were the top counterfeiters in the world. Oh, by the way, both organizations had to do it twice. This is how persistent they are at generating criminal money for their organization. [ fakeair ], I hope this is the only [ fakeair ] presentation you've ever been in. This is their #1 export. The #1 export out of North Korea is [ fakeair ] at $170 million a year. Their entire GDP is $15 billion a year. They're generating at least $7 billion in stolen cryptocurrency alone, more than $2 billion this year. They've made more money still in cryptocurrency than 12x their top export of [ fakeair ] and 5x more than their total export list. Oh, by the way, if we just look at their GDP, we assess that their cryptocurrency theft is about 15% of their total GDP. This is how they are funding their regime. This is how they are able to be as aggressive as they are, and this is going to produce 3 major things that we look at. First, they are sinking those gains right back in. They are investing their returns and they're making it work. That is then allowing them to be very aggressive geopolitically. That will have consequences on a geopolitical stage. Third, at some point, we will likely get to a point, just like it did with counterfeit money, where they are injecting so much doubt into this system that we start questioning the actual system itself. And cryptocurrency is already under doubt. That has the potential to have profound ramifications across the globe. We don't know what that will be. The last part, these guys are really innovative. Like they're using AI to become valid workers. No one saw that coming. The methods they're using is still cryptocurrency are really innovative, and they're just sinking more and more resources back into that. We really actually don't know what they're going to do next. They are the actual wildcard out there. And then the fourth needle mover that will hit, there's no way we're not going to talk about AI-facilitated malware. I want to kind of level set real quick on where we're actually at today. Let's just talk about 4 quick things. We have LLM created malware, technically feasible. Like it's happening a little bit, but it's not meaningful. We are having LLLM embedded and post-runtime cases. It's real. Mal Terminal's example. Ely will talk about that a little bit later on. We're seeing LLM invocation at a local level, it kind of works a little bit. And then we're seeing prompt injection and data exfil using AI. This kind of went from 0 to where it's at, say, in about 12 to 18 months, but it's brittle, it takes humans and it's pretty unstable. We don't think that's the forever answer, though. That's where it's at today. If we look forward, we think all 4 of these areas are going to change demonstrably. The first, we think will be the operationalized LLM-assisted payloads. We're probably a year away from that being really common. The offline LLM malware, the only thing keeping that back right now is the packages are too big. Technology always shrinks the packages. We think that, that will be there. The third one, AI augmented social engineering at scale. The only reason we probably really haven't seen this, we haven't been in the right geopolitical situation yet. This is almost undoubtedly a matter of time. And then the fourth one, the real bogeyman that we all talk about is autonomous chained attacks. This is limited by a couple of things: cost, compute and just more experience. This is not happening today. Although we are seeing multiple governments research it, we are seeing cyber criminals try it. This is inevitable. It will happen. Our assessments are we're probably 3 to 4 years away from that happening. But we've been talking about the future. This is all heady stuff. It's hard to get our brains around. I want to kind of go back to how we see the world. I want to give you one specific example. How are we actually seeing the world shift on the wire? And I can't think of a better person to walk us through that than Drea London, our Head of Incident Response -- sorry, we've got some slides missing there. I apologize. Drea will come out and walk us through how we're actually seeing Evil AI operate inside of these environments.

Drea London

executive
#5

Wow, you guys know you're going to wake up and be terrified. First day. That's what we're doing. So I'm going to tell you a story today about a threat that we're seeing, and it's not going to create global cyber warfare, but it might be a little more accessible. It's something that we see rampant right now running around and a lot of customers of ours. So Evil AI is a -- it's a malware family that's basically using AI and efficiency tooling to disguise itself and using the human interest in AI to basically create lures, right? So we know that in the world that we live in today, AI makes us more efficient. It makes us, frankly, not have to work sometimes, right? It makes everything so much easier. And so that creates an element of trust. So looking at the question of how is AI being used by threat actors today. If you look back to Black Hat last August, I was on stage in our beautiful booth basking in the fact that I have one of those gorgeous booths at Black Hat, all the lights, and I've got Benji and our marketing team asking me all these questions about how are threat actors using AI today? And I get that question a lot, pretty much all the time. And I gave the same answer that I always give to him, which is like, we're really not. Okay? We're really not, not so much. We see them using natural language models in phishing and things like that, making malicious code seem more relevant or reasonable or trusting, but we're really not seeing it day to day. There's no polymorphic malware running around the universe that we've all been afraid of from publications and things like that. But little did I know that at that exact moment that I was speaking, we were, in fact, experiencing or several customers of ours were experiencing AI being used in a very novel way that we had not seen before. And it's -- again, it's not polymorphic malware, but it is new and interesting and really capitalizes on the human element of AI technology. So how does the story start? Mid-September, we get a phone call from a customer of ours, a very large customer, one of my favorite customers. I'm sure they're in here somewhere. I can't see any of you with this light. But we get a call. And usually, unless I'm on the phone call trying to sell you something, if I'm on a call or in a room, it's probably not your best day, okay? So I'm on this call. We're evaluating the incident with a customer. And this is a large customer. They have a very sophisticated security team of their own. So they've already been sort of performing their analysis. They're providing us with the information that they've gotten to date. And we recognize that this is something that's quite prolific in their environment. Again, mid-September, we get engaged, DFIR team is on the phone, scoping an incident. And there were several files that we knew were likely bad. The first one that we reviewed is file -- an installer for an application called JustAskJacky. Now JustAskJacky is an AI assistant. And if you were to install JustAskJacky on your computer, you will be presented with this beautiful little cartoon character [ bluntly ]. I kind of picture here like 1950s, like she can be vacuuming and with her Martini glass at the same time, she can do anything you want. She's here for you. Andrea, I'm here for you. What do you need? What can I do for you? And she does it. And this is the difference from other trojanized malware that we have seen in history is that she is actually completely capable. She does what she's supposed to do and so then she solicits trust in you. You believe that she is a legitimate application because she is doing what she said she's doing, right? She's answering all your questions. Oh, you want this recipe. Oh, you want me to fix your picture for you, make this more clear. I'm here for you, Andrea. I can do whatever you want. And I can also drink a Martini and vacuum at the same time. She's doing all these things. But in the background, Jacky, is kind of naughty. She's not actually just doing good things. She's running some auto runs and registry key and setting up what will be a large scale global account information stealing campaign. So JustAskJacky is the first piece of software that we start to look at. We then identify another piece of software appsuite.msi. Okay. This is actually very similar to Jacky, but she's he, she, whoever is written a little bit different, different type of code. appsuite.msi purports that it is a PDF editor. Have you guys ever tried to edit a PDF? Not real fun, but how you want to spend your time, okay? We have evolved, but it's not a good use of your time. So it is not surprising that the population when presented with a beautiful Google ad or a phishing lure that's like, I can help you edit your PDF. You're like, yes, please. Oh, I meant it actually does. It does what it says it's going to do, and therefore, even now you trust it. So appsuite.msi, again, another loader, very similar to Jacky, different purpose, fully effective. This is what is different than trojanized malware that we remember from history, right? Like we look back at Trojan and we think, oh, I remember Excel spreadsheets that were meant to help me be more efficient, it's a Trojan. This is the same type of mentality and purpose that we have seen in history, but using AI and productivity because that is the place that our minds are in today. That's what interests us today. Interestingly enough on appsuite.msi, so just as Jacky got a clean bill of health from VirusTotal, appsuite did not. Viruses were like, [indiscernible], I don't think so. I think you're a [ pub ]. I don't really like you. I'm going to go ahead and classify you. And the threat actor that created appsuite.msi, frankly, same threat actor that created Jacky, submitted a ticket to VirusTotal. They said, no, no, no, that's a false positive. [ Mine hour ] is safe. That's a bold move. That's not something we see very often. And I don't know if VirusTotal just didn't look at the ticket or didn't care, but they have continued to persist that yes, just kidding. You are, in fact, not good. But all of this is spread via malvertising campaigns, SEO poisoning, Google ads, phishing lures, very typical strategies that we see in cyber crime today. It is not focused on any industry or segment or geography. It is anyone -- anyone and everyone. So moving right along. What we've determined after reviewing these 2 pieces of malware is that their actual intention was to deliver TamperedChef, which is an information stealing module within these applications. And it's whole purpose is basically steal cookies, credentials, secrets, whatever it can from the endpoint that it's living upon. What's super interesting is its life cycle was exactly 56 days. Now I did not know this. I learned this as a part of this research. That 56 days is the exact amount of time that a Google ad is active. So what it's essentially doing and intentionally and purposely is collecting every single amount of information it possibly can over the exact amount of time and then detonating itself 56 days later. And this is interesting because when we start to look at the time line of how this all manifested this last summer/fall, you can see that execution on that time line in effect. Okay. So OneStart.exe, this is another file that we looked at, and I'm not trying to just give you guys follow names, IOCs. Honestly, there's like hundreds of them. But just to kind of give you a picture of how all this comes together. OneStart.exe is a piece of the puzzle. It's one of the files that the loaders, Jacky or Appsuite install on your computer that essentially perpetuate, right? It launches TamperedChef, it perpetuates the collection of the malware. It really is kind of just like one piece in the middle of the puzzle. What's interesting in OneStart.exe is it's one of the first things that we see when we start to go back in time being tested. And it also kind of connects all these pieces together because we can use that executable as the connective tissue between different pieces of malware that might be written in different types of code but have this exact same [ C2 ] or command and control language within them. And so it allows us to kind of put all of these things together. This is, again, end of August, is when we see this in this one specific victim environment. Okay. So mid-September, September 11, we see the first publication of EvilAI. And this is written by Trend Micro, it was actually very good write. I definitely recommend reading it. And it's the first time that we see the industry really putting all of these pieces of the puzzle together. We've been seeing them kind of independent. But this really provided an understanding of how everything worked together and create this entire life cycle. And it goes forward and really explains to us as researchers and industry professionals, how the threat actor is exploiting AI, branding to deliver this persistent backdoor and steal credentials. It's really using the concept of AI and how -- what it means to individuals to essentially lure them and be effective. So as one does, whenever you have a cybersecurity incident, well, in this case, one where we know we need to introduce detection. At SentinelOne, we take all the research we have from our breach responders within my team, within the other customers and partners that are sharing information with us and we built a bunch of platform detections. We were already detecting this from a behavioral aspect early, early, early on. But I think that we didn't exactly know what it was that we were detecting. And so we -- this is me telling you, don't be scared, we did good things. We're here to help you. We did. We did. We immediately deployed these protections and sent them out to all of the end points that SentinelOne was protecting. And then we started to look back in time. In breach response, I mean, I would never give you in this life cycle presentation, but we all know what the missed life cycle is, right, and part of that is our postmortem analysis. And so looking at our postmortem, we said here, we're really skeptical of this timeline, we weren't really sure. And like ma'am this seems like only been going on a couple of months, but it's super prolific. And so, fortunately, this victim, again, one of my favorite customers if you're in here, please, had really, really good data retention. We had to like a lot of time that we can search through. And we started looking, and we found evidence dating all the way back to February of 2025 of parts of this campaign. And at that point, it was very low noise. The threat actor was in a testing phase. But it just shows you that conceptually, they had a plan, and this is a multi-month plan. A lot of times in cyber crime, you're kind of in and out in a hurry, right? This was very thoughtful. It was very broad, and it obviously impacted hundreds of thousands of people all over the world. But so we find our first evidence, dating all the way back to February and then continuing our research between March and August. So we had like our first detection in February, next detection kind of mid-March. Between March and August, we have 36 independent versions of AI -- or EvilAI-related malware in this one single victim, which -- that's not good, right? But what it allowed us to do was really get an idea of the entire life cycle of how this malware evolved and developed and what it did. And so what we started to see is January -- sorry, February, March, very low noise. We're just testing stuff. We were purchasing domains. We're creating our trojanized installers. We're refining our infrastructure. But then by late June is when we really started seeing the campaigns on Google ads, this is one that's getting a large global rollout. And then you have your 56 days, right. We were dormant for 56 days. So by late August, that malware that had been laying dormant for 56 days at TamperedChef, completely executes and start sending secrets back to its control server. That's when larger-scale compromise is assumed. That's when we can start seeing -- the utilization of those credentials are secrets. We can start to see them being sold, et cetera, massive data exfiltration, et cetera. So at the end of the day, again, not here to just try to scare you. You have a whole conference full of like AI-related conversations and information and all the reasons why we can protect and secure you. And we can. And we did all the way back to February, these detections were detecting and that's great. But the point is, I was wrong the first week in August, when I sat on stage at Black Hat and I was like, no, no, no, we're not really seeing AI being used by threat actors in breaches. And I didn't think that this is how we would start there, okay? We are all afraid of -- you saw it o Steve timeline, what is it, 2029 and 2030 when we start to see completely autonomous delivery of malware. What we're seeing is the human element, the same exact human element that we've seen in trojanized malware forever, which is simply between the keyboard and the chair, how do we make your life easier? How do I make you more effective and efficient but now I can do it easily and in a way that actually works. So I solicit trust. So we're not seeing polymorphic malware, but we are seeing malware being used by AI. By the way, all of these installers, we believe, are written in AI. You can tell by the obfuscation techniques that were used that not only did AI likely create these installers, but they're also again soliciting the human element of AI interest. And that is it for me. I bring Steve back.

Steve Stone

executive
#6

All right, folks. We talked a lot here. We covered the globe literally and figuratively. Our real hope here, we're not trying to scare anybody. We're trying to give 3 things. One, we want to give visibility into how we interpret the world. Two, we want to give context for the things that we are looking forward to. And then three, our real hope is to be a scene setter for everything else that comes to OneCon so we can set the stage for why we are building what we are building, why we are pushing the way that we are. So you can see our goals and ideally how we can help to secure your environment. Thank you very much for your time, everyone.

Tomer Weingarten

executive
#7

So the next 30 minutes are going to be all about what we've been building, what we've been doing and how we actually make tangible progress towards that vision that we set out to build into usher into this world. So I'm going to be joined by quite a few leaders and we're going to talk about how we're taking all of these different components that we have in the platform today and those that we've just added either through acquisition or building or partnerships. We're going to show you how these innovations come together to create the autonomous SOC vision. Now what's important to understand is that a lot of what you're going to see in this session is actually either already available on the platform or coming in the next, let's call it, 90 days. So these are all tangible real things that you're going to be able to do with our platform, some you can also already do today. So that showcased some of these pivotal steps that we've been taking to solidify SentinelOne as the leading AI security platform. I want to first open with data. As we talked about, when we think about creating that innovation entire fabric of cybersecurity, it has to start with bringing the data in, which is why I'm incredibly excited to invite to the stage Gurjeet Arora to tell us more about how Observo AI and the Singularity platform are coming together to put data into one place and action it. Gurjeet?

Gurjeet Arora

executive
#8

Thank you, Tomer. It's a profound privilege to be part of the SentinelOne team. One month in, and I can already feel it, this team runs on innovation. Together, our shared passion for customer impact and innovation will define the future of cybersecurity. At Observo from day 0, we are focused on one clear mission, empower security teams with the right data at the right place at the right time. This chart from Gartner shows the exponential growth in machine data we have seen in the last 2 decades. What used to be terabytes just a decade ago, it's petabytes today. That's 1,000x growth in the last decade. In practice, most teams can't even capture all this data and even if they do, the signal gets lost in the volume that is [ noise] . The net result is exponential increase in costs, while the overall security stance of the enterprise deteriorate rapidly. This problem of noisy data impacts every single security team out there. This is the problem we are solving. Let's see how we solve this problem. To solve this problem, we have built the industry's most advanced data pipeline. This data pipeline uses [ 4 ] specific machine learning models to deeply classify and denoise data. Further, to make data operations easier, we have created Orion, our agentic data engineer. Today, Orion has become a go-to tool for security teams. They are automating day-to-day time-consuming operations like data enrichment and data classification using Orion. In terms of scalability, today, large organizations like Bill.com, Alteryx and Harbor Freight are using our platform at petabyte scale. What's the most clarifying to me is the value that customers are getting from our platform. So on an average, our customers are getting more than 50% in cost savings while improving productivity by more than 40%. Let's see how easy it is to adopt the Observo platform. We basically ship in 2 configurations, 2 very simple configurations for our customers. The first configuration is applicable if a customer is currently not using the Singularity AI-SIEM. In this configuration, Observo becomes the central vendor-agnostic data engine that crowds data from any source to any destination. Further, all features of the Observo platform are available in this configuration. The second configuration is applicable if a customer is currently using Singularity AI-SIEM. In that configuration, the enriched data from the pipeline turbocharges the Singularity AI-SIEM, further features like Purple AI and Singularity hyperautomation work exponentially better. To wrap up, our teams have worked relentlessly to create the industry's most advanced security platform. This platform seamlessly combines the power of streaming analytics with deep agentic analysis in a single system. What this means for you is, we can deeply classify and transform your data, your noisy security data into actionable insights. That's really how we accelerate the path from manual threat hunting to autonomous defense. Finally, I'd like to invite you all to visit us at our booth to experience the platform in action and to see how it can turbocharge your security dreams. Thank you.

Tomer Weingarten

executive
#9

Thank you, Gurjeet. So simple, easy, complete, getting data into the Singularity platform has never been easier. And with AI native pipelines, you can take any source and put it ideally into our Singularity platform data lake or routed into any other destination that you want. That is the power of this unity. That is the power in data pipelines. That is the ingredient that allows us to start seeing everything that you have in your enterprise environment, collect, classify, enrich data, optimize, filter it, make sure you're taking what you need and putting it to action. And as Gurjeet mentioned, this is actually a substantial cost saver for all of you. A lot of the data that's beaming between systems today is actually not optimized. A lot of it is redundant. We're building AI capabilities to immediately introspect your data sources to give you an immediate analysis of what you need, the cardinality of data and how distinct is the data source you're interrogating. These are all incredible capabilities to help you gain better control over all of your data sources no matter where they come from, network, e-mail, identity, it doesn't really matter. With Observo, we opened up the gates to put data into the Singularity platform. So what's next for us? We're going to now talk about how we extend the Singularity platform to secure AI, which obviously is a complete new attack surface for all of us. And to talk about that, I want to invite to the stage Itamar Golan, the co-founder of Prompt Security.

Itamar Golan

executive
#10

Thank you, Tomer. Pleasure to be here. Guys, we are living through one of the most exciting times in history. Organizations everywhere are adopting AI at the pace we've never seen before. Every team, and I mean every team, is already adopting AI, marketing, finance, legal, everybody is using it. And if not yet, they are experimenting, testing, learning, but with this incredible wave of innovation comes the all new set of challenges, security teams, well, you guys, you find yourself at the center of it all, facing threats. We could not even imagine a few years ago, prompt injection, jailbreaks, data leaks. The rules have changed and we are all trying to figure out how to stay secure in a world that is moving faster than ever. So the main question is that, how do you enable AI innovation, but safely, securely and at scale? Well, that's exactly why we build Prompt Security, a comprehensive AI security platform that weaves together security, governance and privacy for every AI interaction. From day one, our mission has been simple but powerful. We would like to help organizations like yourself adopt the incredible power of AI without compromising data privacy, security or governance. That mission, by the way, extends to everyone, to the employee using ChatGPT, Gemini or Claude, to the developer using GitHub Copilot or Cursor and to the innovation and R&D teams building AI agents from the ground up, Prompt Security is what makes that possible. We make sure that the AI revolution doesn't just move fast. It moves safely. The Prompt Security platform, as you can see now in the demo behind me, can show you the entire AI footprint of the organization, which AI applications are being used, who is using them, which data is being shared. You can also configure specific granular policies to your business contextual needs and you can even apply them as you wish, on a combination of specific AI users, AI applications and content. The screen behind me is probably familiar to most of you. Imagine one of your employees going to some random AI and revising an e-mail, but unfortunately, sharing sensitive information. Prompt automatically detects this sensitive information, alerts the user about his violation, educating him, making him better for the next time and behind the scene sanitizing all the sensitive information. But there's the magic. We're not blocking him. We are enabling to use it safely and responsibly, and that's our mission at Prompt to find the sweet spot between governance, security and privacy and employee enablement.

Tomer Weingarten

executive
#11

Thank you. What you just saw on the screen, guys, this is only one example, pretty simplistic one, of Prompt stopping sensitive data from leaking into an AI application. But the platform we've built, it's much more comprehensive. It protects the entire AI ecosystem, AI sites, AI components, enterprise tools, copilots, code assistants, MPP servers, you name it, we protect it all. And if you are interested to learn more, please join me afterwards to my product session, I'll dive into any one of our Prompt Security offerings. Guys, SentinelOne has been the most powerful platform to harness the power of data and AI to protect every attack surface. And now with Prompt Security, we take it to the next frontier, securing AI itself. Thank you.

Unknown Executive

executive
#12

Okay. So securing AI, this is, as you've seen one of the most complete platforms on the market today. It doesn't stop with securing only employees from the usage and data acceleration that may happen when they're leveraging AI at work, either for sanctioned usage or unsanctioned usage, but it also helps you protect AI agents, all these building studios that you have out there, all the new workflows you're putting into work and in MCP environments as well. Obviously, AI adoption is accelerating across every team and across every facet of your organization. Security has to keep pace, Prompt is how you do it. It gives you immediate visibility into every AI bound action you have in your enterprise. Deployment is incredibly easy. Again, emphasis on simplicity, completeness of visibility and completeness of control. Find AI, see what it does, put a policy, done. That's how AI should be managed in the enterprise. That's how you facilitate your workforce to work securely and to adopt AI at the pace that they need. Okay. So earlier, I talked about how agentic AI needs to actually work, how we can harness it to potentially accelerate what we do in cybersecurity. Well, it isn't an empty promise. We're well on our way to create that reality for every customer out there. No more bolt-on AI, no more workflows, no more specific agents to tweak and to configure and to test and to have no idea what the outcome would be. We're moving into a complete integrated AI, agentic AI into the existing security operation fabric that you all use today, which means full context, fully tailored actions and complete human oversight which is one of the keys to actually be able to use agentic AI in mission-critical environments. So to share more I'm really excited to introduce Rachel Park and Heather Phipps to the stage.

Rachel Park

executive
#13

Hi, everyone, welcome. We are so excited to be here today to discuss the topic we feel very deeply about and has real-world consequences. So 2 months ago, researchers discovered PromptLock, a malware prototype that can generate new ransomware code in real time. No command and control server, no script kitty. Just an LLM that could write and immediately implement unique Lua scripts, so every infection looks different. In less than a year, we've gone from early AI malware prototypes to credible demos of fully autonomous attack chains. One example, Ransomware 3.0, showed an LLM executing every stage of an attack for reconnaissance to payload creation to even ransom negotiation. When attackers can automate at this pace, when the code itself can adapt, we defenders cannot afford to stay manual. At this point, autonomous security isn't really optional now. It is how we stay protected. So how do we shift the advantage back and equip our analysts with agentic AI to unleash what we believe is our greatest weapon, human ingenuity.

Heather Phipps

executive
#14

Rachel, we're here to answer exactly that. Life in a SOC is intense. Endless alerts, too few people, newer enough time. Triaging, investigating, responding at scale is tougher than ever. Proactively improving security posture fields nearly impossible. Our mission is to flip the script to place AI directly in your hands so you can stay ahead of the most sophisticated attackers. This is why Purple AI exists. It's your proactive partner for true autonomous security.

Rachel Park

executive
#15

Exactly. Look, Purple AI is the brain of the Singularity platform, unifying intelligence, proprietary models and threat data into a single adaptive system for modern security teams. It shifts the paradigm from human work assisted by AI to AI work approved by humans, so you can focus on the actual critical high state incidents requiring creative expertise. To us, humans are the mission commanders. You lead a strategy, let AI handle the chaos. But Heather, can you help us make this concrete? And can you show us how Purple helps at every stage of the SOC analyst workflow?

Heather Phipps

executive
#16

Let's dive in. In the console, my infinite queue alerts me to a potential identity compromise. With one click, I launched the investigation. But Purple AI has already been working in the background, surfacing alerts, correlating data and investigating for you. Normally, this sort of alert sparks chaos. Is it an identity compromise or an insider attack? How widespread is the threat? Analysts spend hours digging through logs, connecting dots, tracing the attack path. But with Purple AI, this looks completely different. When I took on the incident, I get a complete summary of the agentic investigation from the initial discovery and alert correlation to impact analysis and recommended actions. Purple AI dynamically planned and executed this investigation tailored to the specifics of the incident. It formed hypothesis, tested them and adapted instantly as new contexts emerge. This is Purple AI agentic auto investigation with dynamic context-based reasoning across any alert any data. And Rachel, I would like to share this is coming next quarter.

Rachel Park

executive
#17

Okay, this is important. Purple's AI agents figure on what to do when novel info comes in, but the playbook isn't obvious. Where other vendors really love to count their numbers of agents, at SentinelOne, we are focused on orchestration and outcomes for you. Now earlier, I called Purple the brain, and that is because it reasons, it learns. And it clearly demonstrates its logic for the human analysts approval. So our end-to-end agentic investigations give you scale, automate across every alert free from the limits of static playbooks. Adaptability. Purple learns and pivots dynamically with high accuracy; and transparency, that means full explainability with you in the commander seat. Let's take us in action. Purple AI kicks off the investigation from an Okta in possible travel alert. It asks, Who is the user? Where do they log in from? It identifies James Sabalo with a suspicious login from an unknown location. From this, Purple hypothesizes that we may have a compromised identity. It queries often Workday from our background on James. Purple AI's seamless integration with singularity hyperautomation, lets it act quickly and safely. It instantly reaches out to James on Slack and confirms the log-in was unauthorized. This is Purple AI integration with Singularity hyperautomation, also coming soon. Next, Purple AI investigates how James' identity was compromised. It pulls in proof point data to confirm evidence of phishing and it identify suspicious [ SCC ] overwrite linked with his credentials. Finally, Purple AI assesses the blast radius. It queries, EDR, Zscaler and cloud trail logs confirming that this attack is isolated with no evidence of lateral movement. In seconds, Purple AI has traced the complete attack chain from the original phishing e-mail to identity compromise to data encryption, all agentically without any human configuration, giving you clear evidence for decisive action. Look, our AI doesn't stop at investigation. Of course, it also drives response. Purple AI agentically surfaces preapproved recommended actions via Singularity hyperautomation, rotate AWS credentials, block the attacker IPs, restrict S3 access and immediately suspend the user in Okta. Done, just like that. This is how Purple AI delivers you an agentic SOC. It is thinking through the problem, crafting its hypothesis. It is investigating, trying to validate that hypotheses and then only taps into preapproved workflows to execute approved response actions. And then finally, it documents everything in one clear auditable view.

Heather Phipps

executive
#18

But, Rachel, Purple AI doesn't rest even once the threat is contained. With one click, you can close the loop, instantly creating a detection to identify and stop similar threats before they spread. No more manual rule writing, no more missed chances to incorporate what you've learned. Every investigation instantly strengthens your defenses. Remember, the original overwhelming SOC workload that we started with, imagine no endless alerts, no brittle playbooks and fewer but far more targeted manual investigations. At every phase of the SOC workload, Purple AI and hyperautomation deliver true autonomous security, working tirelessly and accurately while keeping you firmly in control. Rachel, this is a transformation that every SOC needs from reacting to threats to anticipating them from barely keeping up to staying ahead.

Rachel Park

executive
#19

Okay. So speaking of staying ahead. We do have one more exciting announcement for you. We've just shown you turnkey agentic workflows inside the platform but we know many of you are also experimenting with your own LLM and custom models. So today, we are extremely excited to announce the Purple AI MCP server, a secure bridge between SentinelOne's live intelligence and real-time context and your AI ecosystem. Now you can create your own custom agents, rooted in S1 data and able to reason using your security context. Whether you're using OpenAI, Anthropic, Gemini or other internal models, you now have the freedom to innovate securely and at scale. And look, this isn't just another integration. This is about the future of autonomous security. It's giving you the power to extend the Singularity platform truly as far as your imagination will go. And the best part is the Purple AI MCP server is open source. You can actually get started today on GitHub. We cannot wait to see what you build.

Tomer Weingarten

executive
#20

Okay. I'm very excited about this. I mean we just saw a complete cycle from alert to immunization and prevention happen within a few seconds, minutes with a human in the loop. But how do we scale it now? How do we do it across thousands of alerts? And I'm not just talking about SentinelOne's alerts, I'm talking about any alert that comes from any connected product, be it Okta, Microsoft Defender, Splunk, whatever it is. How do we take what we've just seen for one alert and we do it across the board, asynchronously for everything that's happening? That's the goal with the next release of Purple. But to do that, you also need to scale the human control. You also need to scale the ability to make sure there's somebody monitoring the system at any given moment. And that is exactly why we are launching Wayfinder services. Not only we're launching Wayfinder services, we're also teaming up with Google Threat Intelligence to make sure that we can funnel real-time threat intelligence, best-of-breed threat intelligence directly into the Singularity platform and action it with Wayfinder's AI-powered human services. So this is how you scale AI. This is even when you don't have enough workforce, enough analysts to go after any alert or every alert, we have that supplemental force. So before I invite Steve and Vijay to the stage, let's quickly recap. Agentic auto investigations, Singularity hyperautomation, automatic actions, custom detection rules and the Purple AI MCP server, which is obviously an insane bridge to everything you want to build, this is the world's first fully agentic AI SOC. You have all the components, all the ingredients to basically unleash the power of AI to make your SOC infinitely faster and more productive and you don't need to code it. You don't need to configure it, you don't need to build it. You don't need to invent it, you don't need to grapple with it. It's there, turnkey, click and it happens. That is the future that we envision for cybersecurity. So let's jump to Wayfinder. I'm really, really excited with this partnership. It's taking the world's best threat intelligence and fuses it with elite defenders 24/7. I want to welcome to the stage Steve Stone and Vijay Ganti.

Steve Stone

executive
#21

All right. Thank you, Tomer. I appreciate it. Vijay, thank you for joining us here.

Unknown Attendee

attendee
#22

Thank you.

Steve Stone

executive
#23

So we've spent several hours here talking to you about tomorrow. Let's take a step back. Let's talk about today and some ground truth. I live and die in the services world. We have to solve problems now. We work with clients every single day who are struggling with legacy technology. It's often just jointed, complicated workflows and ultimately, blind spots. When we go back and look at what has made us successful at SentinelOne in our almost 8 years of delivering services, it's when we are connected and it's when we are coordinated not just with our clients, but other organizations in our industry that our clients also rely on. Based on this, as Tomer mentioned, as of today, and you can get it this month, this is not coming in 6 months, this is now. We are relaunching our services with a real focus on 3 things: how do we combine artificial intelligence with our human expertise and world-class threat intelligence from both SentinelOne and Google Threat Intelligence. As we look at how we expect this to operate, our ethos remains the same. We are not changing the spirit and intent of what we've done so far. We are here to work with clients preventing intrusions, reducing risk and being there in that critical moment in that breach moment, we will still do that. The difference with Wayfinder is we will provide more capabilities around that, and that will be the next evolution of our services. We will take our existing managed detection and response, our incident readiness and response and our threat hunting and combine them into a seamless client experience. Additionally, we are combining what you see upfront with what's happening behind the scenes are detection engineering to ensure that as seamless as well. And then we're going to provide outcomes across whatever data you put in front of us. You apply the surface, we will apply the expertise. And the point I want to just really kind of drill down on here, why we have Vijay with us is the threat intelligence piece. I mean -- you heard me talk about this earlier. I won't go back and recap all that 45 minutes. But this is foundational to us. That threat intelligence is what allows us to move its scope and scale. It allows us to provide the right outcomes, and this is ultimately where Google Threat Intelligence comes in.

Unknown Attendee

attendee
#24

Thank you, Steve. And you had mentioned this morning that attackers are innovating, attackers are collaborating. We as defenders must do the same, it's time. What's unique about today is that 2 reputed top cybersecurity companies are coming together to deliver intelligence to our customers. But this is not just about shared intelligence, it is about actually delivering actionable outcomes to our customers, which is what you talked about. The visibility that we have together, the capabilities that we have together, actually will eliminate the blind spots for our customers. So let's talk a little bit about what Google Threat Intelligence is. It's actually a combination of Mandiant, VirusTotal, and Google Insights. Let me just elaborate on that a little bit. With Mandiant, what you get is frontline threat intelligence that we get from responding to thousands of security incidents every year. With Mandiant, you get curated threat intelligence from 600-plus researchers who are looking at threat landscape. With VirusTotal, you're getting the best cloud source and open source threat intel out there. And with Google Insight, you're getting visibility into threat landscape that Google has as it protects billions of consumers and thousands and thousands of businesses. But it's not just about sharing data here. We don't just collect threat data. What Google does, it has the analytical infrastructure to curate, enrich and contextualize all of this to deliver actionable threat intelligence. And what happens because of that is that you will actually get active security. Now let's look at MDR, managed [ detection ] and response. And that essentially starts to deliver these outcomes to our customers.

Steve Stone

executive
#25

I appreciate it. Thank you for that rundown. I think as we look at this, I think this is where we really at SentinelOne see, this is where our unified platform shines. And we combine our services with that, which was delivered across our platform. Every single services client will benefit from the combination of Google Threat Intelligence and SentinelOne automatically. Let me give just a little bit of context on how important we're taking this. You will not be able to engage Wayfinder services and not receive the benefit of GTI. We are bringing this into the core of what we are doing, combining it with our intelligence, our findings and then applying that across our clients, all at the benefit of speed and scale. Bringing these 2 organizations together, I'll be honest, I still don't know how we got the bosses to sign off on it, but it's too late, patent-pending, legal paperwork all signed. So what I would leave with is this, this is how we are going to approach this on behalf of our clients. We're not here to sell intelligence. We're not here to send you a PDF of what to think about. We're going to take this intelligence, combine it with ours and then move it through our artificial intelligence and then present that in front of our human expertise that allow us to work at scale. We will be applying that. We will be taking the actions, and we will be responsible for ensuring the right parts of intelligence are applied across their environment all while we will provide rapid onboarding and near immediate outcomes as soon as we are enabled. This is how important we think this combination of SentinelOne and Google Threat Intelligence will be. Not just when we find more threats and find them sooner, we can respond faster and more precisely. And you've heard us talk a lot about AI today. I know AI can get real [indiscernible] real quick. We talk about human expertise much the same way. But this is how we think about it here at SentinelOne. We think about it in this concept of a flywheel. And this is why this is so important to us on the services side. We use artificial intelligence to drive that human expertise. It allows us to see more, move faster, it makes our people better and then in return, this is what makes our AI better. It is being trained 24/7, 365 by human experts and the combined intelligence of our 2 organizations and every single incident, both SentinelOne and Google Threat Intelligence experience.

Unknown Attendee

attendee
#26

Yes. I was going to say AI, what is that [indiscernible] just kidding. I think this human AI collaboration that you talked about is probably the most exciting part. It creates this virtuous cycle that creates a learning system, which is so important for us. Imagine this Google Threat Intelligence provides context to Purple AI. Purple AI drives actions and decisions for security analysts. Security analysts provide feedback into Purple AI. And that's the virtuous cycle we're talking about. It is a learning adaptive system that we're delivering, which is absolutely world-class.

Steve Stone

executive
#27

I completely agree. I really appreciate it coming out and join us with this. I know you've got a lot going on. And just what I would say to all of you in the audience, if you want to know more about Wayfinder, we have multiple sessions throughout today and tomorrow. We'll be talking about this for the foreseeable future. We are incredibly excited to build on top of years of experience serving you, thousands and thousands of incidents and now also the added benefit of Google Threat Intelligence. Thank you so much. We appreciate your time.

Unknown Executive

executive
#28

Thank you. Hi, everyone. I think I have the best job in the company because I get to see how our solutions are helping customers solve real-world problems. In this industry, when we talk about cybersecurity, it's often about the technology. We talk about the platforms, automation, AI and all the things that, that technology can do but it's really never about the tech. It's always about how the tech is empowering the people behind it. And that's what today's session is about. You're going to hear from some of our customers that talk about how they're using our solutions to solve problems that they couldn't before. So without further ado, please join me in welcoming our panelists to the stage. Okay. Let's start with some intros. [ Angel ], why don't you kick us off?

Unknown Attendee

attendee
#29

Sure. Hello, everyone. Very excited to be here. My name is [ Angel ], Director of Software Engineering at DirecTV. For those who are not really familiar with us, DirecTV is about delivering that premium content with unforgettable customer experiences to millions of homes across the country, and we're especially proud of our superior sports packages that's really put our fans in the front of the game, they care about the most. So in a world where media technology and AI has been evolved so fast, our challenges are really clear. How do we deliver secure and scale that digital experience without miss a beat? And that's exactly where my team has come in. We're sitting right in the intersection of cybersecurity, observability and automation. And I'm really fortunate enough to lead a group of very talented individuals and who are always looking forward and asking how do we prepare for what's next, not just reacting to what's happening now. So that's why I'm very excited to be here, share some stories and pick up the new ideas. And just have a great conversation about where our security operation is going to head in next.

Jörn Graf

attendee
#30

Absolutely. Thanks, Angel. My name is Jörn Graf, I'm Team Lead of Endpoint and Application Security Team at Schwarz Group. So for those who don't know Schwarz, Schwarz is 1 of the top 3 retailers in the world. Besides retail, which is our core business, of course, we also operate our own production facilities. We operate a recycling facility, shipping line, cargo line. That makes our infrastructure-wide a bit complex. Currently, we are talking about 600,000 employees all over the world. And yes, I'm really enjoying to share some stories out of our daily business. I think a lot of you in the audience also can identify with.

Unknown Attendee

attendee
#31

Hi, everyone. I'm [ Shrishti Chatterjee ]. Thanks for having us here. Actually, I'm a global lead for security architecture and cyber defense at Thoughtworks. Thoughtworks is actually a global technology consultancy. We are located in multiple locations in the Asia Pacific, India, Middle East, Europe, in the Americas, LATAM and North America. We actually work more on the providing -- delivering software to our clients and making sure we are delivering with AI because AI is now top of everyone's mind right now. So providing modern design with AI and engineering, keeping in mind and security all the time. So for us, security isn't just an internal function where my role sits between engineering, having some strategic roles for continuing to improve our architecture in security and at the same time also working as an incident commander in the cyber defense team helping and understanding how we can continue to improve our security structure. A lot of the work is not just internal function, like I mentioned. We do have a bunch of things that we have to do for our clients. So keeping security in mind for our clients actually having that implemented into our development design and also continuing to improve our business with security as well.

Unknown Attendee

attendee
#32

And good morning, [ Mike Francis ], Director of Cybersecurity Advanced Threat Wyndham Hotels & Resorts. We are the world's largest hotel franchise here. We have over 9,500 hotels across 22 brands worldwide. In my role, I'm responsible for all things cyber threat intelligence, digital forensics, incident response and detection engineering. So my day-to-day role consists of very closely aligned to all the stuff that Steve was talking about, keeping on top of our adversaries, keeping on top of the threat landscape, informing our stakeholders, influencing strategic business and tech decisions and when something does arrive, running that into response kind of similar to [ Chatterjee ].

Unknown Attendee

attendee
#33

Wonderful. I'm going to do a complete icebreaker, right? I'm going to throw you guys off. I've got a little question. I'd like for you to describe your job by using a movie title. And then just explain quickly why and bonus points, if you don't say the Titanic. I'm going to start with you, Michael. We'll just come back down this way.

Unknown Attendee

attendee
#34

Sure. I'm going to go with my favorite movie so far this year, which is One Battle After Another. So kind of what I just spoke about, right? We have a very complicated threat landscape involving both cybercrime and nation state actors. So it literally is day-to-day one battle after another with adversaries varying TTPs and keeping on top of that evolving threat landscape is complex. And then as part of that movie, the resistance network, I think about. And I think about how we as defenders just all need to have solidarity for each other, share that information, defend as one. So that's what comes to mind with that.

Unknown Executive

executive
#35

Okay. That's really good. Very thoughtful. I hadn't even heard of that movie. Let alone the movie of the year. I guess I'm behind on my culture. Tristy, what about you?

Unknown Attendee

attendee
#36

I'm thinking the Avengers, kind of thinking of like you're kind of -- there are a lot of movies, obviously. You're kind of an elite team always looking at things that you have not seen. Anything will be there on top of your screen right there. So there are new threats every day, which we don't know about. So yeah...

Unknown Executive

executive
#37

Yes. Very good there, you got to like it.

Unknown Attendee

attendee
#38

So literally, the Avengers was the first thing which came into my mind also, but more thinking about we have all those individuals in our cybersecurity landscape in our teams, and I think also here in the audience. And everybody has a very specific skill set at the end, which overall comes together as a team to defend our world. In our case, it's our infrastructure, our customers, whatever. And I think that wraps it up. So we just need to protect everybody, and that's -- that's what I think.

Unknown Executive

executive
#39

All right. I got a couple of movies I need to watch on the plane ride home. What about you, Angel?

Unknown Attendee

attendee
#40

I'm sitting between Top Gun and the Hidden Figures.

Unknown Executive

executive
#41

Hidden Figures and Top Gun.

Unknown Attendee

attendee
#42

I think our team is always challenging the status quo and always thinking about what's next and very inclusive about the idea. Now we talk about things, we discuss and we're always thinking what can we do better right? How can we step one -- how can we stay one step ahead, right? There's a lot of things going on right now with the AI and the cybersecurity as well.

Unknown Executive

executive
#43

Yes, especially that Top Gun, you definitely need to have like speed and precision and all of those things.

Unknown Attendee

attendee
#44

Yes.

Unknown Executive

executive
#45

Well, good. Well, I -- we're all anxious to hear about your SentinelOne deployments and how you're using us today to solve problems. [ Yaron ], you've been a customer the longest. Why don't you tell us a little bit about what you have deployed, how your journey started?

Unknown Attendee

attendee
#46

Sure. So yes, we are customers since 2020, so late 2020. We did the evaluation during the year. And in the meantime, we protect around about 450,000 endpoints.

Unknown Executive

executive
#47

450,000 endpoints.

Unknown Attendee

attendee
#48

It also includes like cloud workloads and the likes. So when did we start? We analyzed the entire market. So we ended up having a short list. I think most of the audience here can identify with 3 vendors, Microsoft, CrowdStrike and [ on ]. And at the end, we did our technical analysis because even if our company is that big, we are still -- the technical teams are still kind of taking decisions. And so we had a very great cooperation with the account team, so shout out to everybody of our account team back then. So yes, at the end, that's the phrase a lot of companies throw out, which means customer focused. But I can totally agree that SentinelOne is living customer focus. That's a thing -- I'm in the company for 17 years now. I saw a lot of -- did some projects globally with a lot of tech companies. And well, that's outstanding for me, at least. Yes. And well, our first broad deployment started when there was with our old antivirus solution. We had a breach in some of our remote locations and somebody was like, "can we just deploy SandinOne?" Yes, sure, we can. So we provided the installer. So they provided the site token and they went ahead. And somehow, our management was like, so we did that now for branch office, I think 100 to 500 endpoints or something. And we were like, yes, sure, why not? So we went ahead, and it was close about Christmas that year. And during the holidays, there were a lot of people offline, but we decided to go ahead and install immediately on the first wave of our clients, which replicates like 20,000 endpoints. So -- and after 3 months, we reached 40,000 endpoints.

Unknown Executive

executive
#49

40,000 in 3 months. What took you so long.

Unknown Attendee

attendee
#50

Yes. Well, obviously, our testing and change requirements. But at the end, we forced it. And within 6 months, we reached the 100,000 endpoints.

Unknown Executive

executive
#51

That's fantastic. And quadruple from there. That's amazing. Thank you. Tristy.

Unknown Attendee

attendee
#52

I need a question back. I can think I forget.

Unknown Executive

executive
#53

Your S1 deployment. Tell us how you're using it.

Unknown Attendee

attendee
#54

Yes. I think we're a heavy Mac shop. So we have like at least about 11,000 endpoints. So it was a clear win.

Unknown Executive

executive
#55

That's great. We're super strong in Mac.

Unknown Attendee

attendee
#56

I know, I know. This was -- it was giving us -- we get like full-on deep visibility on anything we want in Mac. And we do have Windows machines, too, but Mac was our thing we're looking for. In addition to all the EDR functionalities that we get, we also had more visibility with what's happening, plus all of the auto remediation and the user-friendly interface that you get. Everything is farle, but we love it. It's really -- it's more like you don't have to spend a lot of time trying to understand what you're trying to figure out. It's much easier for anyone was learning first time also to pick up on the work. Obviously, you do need to do some little bit of groundwork before that was done to make sure a lot of the automations are done. The open API that's there, which allows us with a lot of the integration for our SIEM and other tools that we want to integrate with, collect some of the data that we need to and send it over wherever we need. I'm also looking at the browser extension now. I didn't know it's all there, but that's another thing that's getting me excited now moving forward.

Unknown Executive

executive
#57

Wonderful. That's see. We're moving pipeline at the same time that we're working. I love it. Angel, why don't you tell us about how DirecTV is using SentinelOne?

Unknown Attendee

attendee
#58

Yes. There's obviously many things you're looking for where you're trying to pick as security partners. At the time when we look into SentinelOne, our biggest challenge is how do we have that clear unified view across our super hybrid environment. And at DirecTV, we have data come from everywhere from cloud, application, EDR and our legacy environment. And they're kind of leaving the silo, didn't really talk to each other. And that made it really difficult to detect the things earlier and for the security team have to see the whole picture. At the time, we're also evaluating a few other vendors. We're evaluating [ Strong ] SIEM, Google SIEM and some open source tools as well. But it all come with very heavy teaming and load operational work that we are not really need to go for and/or it doesn't really integrate very well with our existing ecosystem. So SentinelOne really stood up at that time is it's not just another data lake to us, is it integrates really well with our existing system and the AI-driven insight and the hyper automation that's really the game changer to us is we're able to using the natural language, create the security data and trigger the automation, really made the process so much faster and make that visible to the teams that beyond just the security. So -- and also, I think really important, like I think -- and [ Yaron ], you touched that point is that what's really set SentinelOne apart is a partnership. Your team has been incredibly transparent and responsive to our need and really invest and believe the success of DRTV. And the result is really clear. We are able to reduce our data onboarding by 30% and cutting our automation development time by almost 50%. So in the end, for us, choosing SentinelOne is not just about what's solving our problem today, but more building that intelligent security operations that we wanted to really operate on for DRTV. So that's one of...

Unknown Executive

executive
#59

That sounds fantastic. I love it. You guys are really making us all happy here, hearing how great our teams are. Michael, how about you?

Unknown Attendee

attendee
#60

Yes. So our journey with SentinelOne actually goes back to 2017. We did an EDR bake-off back then, and SentinelOne was one of our finalists, just didn't have everything that we were looking for at the time, to be honest. There was some core functionality that was missing. I think the company overall is a little bit different than they are today. I should say a lot different than they are today. So we selected a partner in cyber reason. They served us well for 6 years. Let's didn't really innovate. I don't think cyber reason even exists anymore. And we had to do another bake-off in 2 years ago. And as Jorn said, it was the same top 3, CrowdStrike, SentinelOne or sticking with Cyberason and seeing what happened. And really, it was the team and a big shout out to Victoria, who really just directly became an extension of our team almost immediately even during the presales phase. It was just a wonderful partnership. You guys were incredibly humble about Wyndham. You fit so well into our company culture, what we wanted to do. The way you guys viewed threat intelligence and how we viewed hunting, how we viewed remediating threats and tackling these problems was huge for us. The efficacy testing also blew us away as well. I mean my team is highly technical. I specialize in malware analysis and reverse engineering. We threw a ton of malware at it, stuff that we were pulling live, live off our endpoints are live from our sandbox and it proved out really, really well. The biggest differentiator for us, though, compared against your competitors was just the simplicity of the UI, the consistency of it, we have a fairly junior SOC team. And I think that, that really proved out in the testing that the team, even though they're not super technical, was just so comfortable within SentinelOne, and that really went a long way. And then adding on top of that was the Purple AI functionality, which really sealed the deal for us, just being able to translate needs and asks and wants in human readable format, bouncing that off Purple AI, getting those results back, even adding tweaks and to those results, that really was a for us, and we've been extremely happy. And as of last week, we closed AI SIEM. So we are now an AI SIEM customer. as well.

Unknown Executive

executive
#61

Thank you. Thank you for that.

Unknown Attendee

attendee
#62

Yes, absolutely. We're super thrilled. We're coming off of a Splunk Cloud deployment that, as I mentioned, the team that's kind of running that today, not as technical. We are considered a small enterprise. So there's not a lot of hands to go around. And those of you that know Splunk know it's -- there's a lot of carrying and cheating that needs to go into it. And we just wanted to get out of that. It just wasn't serving our needs. And SentinelOne came in during the POC, blew us away, everything is production, and we're carrying that right through. So it's been terrific.

Unknown Executive

executive
#63

That's awesome. Thank you for that. You talked a little bit about when you rolled out our data, our AI SIEM in your environment. What were the challenges that you were trying to solve when you were looking at our solution for that?

Unknown Attendee

attendee
#64

Yes. Definitely, I was -- like we mentioned earlier that, that unified view of all the data come in, right? We want to make sure we have visibility into the application security login to the network, to the infrastructure, our legacy environment, cloud environment, all that needs to be combined together as one comprehensive view for our security team. Not only that in the extension is we want to make sure that information can be useful for other team beyond just the security as well. And I think that's where the SentinelOne really come in. And give us that capability and able to using the like AI, Purple AI and hyper automation, the team is going to be so excited about it and we reduced our pretty much automation development time by half.

Unknown Executive

executive
#65

That's impressive. That's absolutely impressive. One of the things that I always love to see is when by the adoption of our solutions, there's a culture or technology shift that occurs within your company. Do you have any examples of how using SentinelOne may have broken down barriers or changed your team's day-to-day productivity?

Unknown Attendee

attendee
#66

Yes. I can take that to start. I think with us, the biggest thing at Wyndham is definitely our culture. We have a no-silos cybersecurity team. And with that, we have a terrific relationship with our IT team and being able to onboard our IT team directly into SentinelOne. So they're working the problems with us or troubleshooting the agents with us. I think that's just been terrific for the partnership because they're getting much more comfortable with what SentinelOne is doing, right? A lot of these EDRs, sometimes to these technical teams are just black boxes. Sometimes they don't understand why they do the things that they're doing and why they're making the decisions that they make. So for us, we decided to bring them in on this go around just with the flexibility of the role-based access control that's allowed us to do that. We didn't have that in our prior product. And I think that's really helped to just get folks comfortable with SentinelOne as we've started this journey.

Unknown Executive

executive
#67

Fantastic. [ Yaron ], anything to add from your perspective?

Unknown Attendee

attendee
#68

Well, we kind of did it the other way around because our old antivirus solution was like very decentralized. We had around about 140 whatever servers to deploy the pattern updates and the like. And our countries around about 35 countries overall. We had a lot of administrators, which were doing something, exclusions, whatever else. we totally busted it. So rolling out SentinelOne, we -- currently, my team contains 4 full-time people taking care of the operation of SentinelOne for that scale. And we just limited our permission. So we are the only ones who can set up any exclusions besides the SOC. Our SOC team, yes, is asking us or is forwarding us requesting exclusion to be set based on their analysis. And it was tough to get all the administrators in the countries convinced that, that's the right way. But well, we did it in 2020. And until now, there's the ISOs and the SOC team and us having role-based permissions and it works. So it was quite the other way around, but it was a huge shift for everybody. But as they always complain about too much work to do for the countries. Well, we took work away. And I don't have any numbers to give you statistics, but yes, they don't have to do that much anymore.

Unknown Executive

executive
#69

That's fantastic. Fantastic. [ Srishi ], what's top of mind for you these days?

Unknown Attendee

attendee
#70

There are a lot of things. Right now, I think we can say AI is definitely on top of our mind. There's an AI battlefield going on. What's happening now? What's the next malware that's coming out. That's definitely on top of everyone's mind. We actually focus more on like, I would say, like I could divide them into like 2 or 3 things. One of those AIs and the other one would be more like focus on human risk. Even if AI is doing something, unless someone clicks a button, nothing is going to happen. So how do we continue to improve our human risk, like that could include insider threats, it could include data leakage prevention from that and protection from that in general. And then the other one is like how can we quickly remediate and recover from what has happened. So we are -- that's actually going to be more of our focus also, but we look into if something -- if there is a problem, if there is a virus, it shouldn't happen to anyone. If there is a malware, it has done whatever damage it has to do, how quickly can we come back? And that's one of the things we want to be good at. There's no way of saying it won't happen.

Unknown Executive

executive
#71

Yes. That's true. It's what happens when it happens.

Unknown Attendee

attendee
#72

And how quick can we get back to it?

Unknown Executive

executive
#73

Yes, what's top of mind for you these days?

Unknown Attendee

attendee
#74

Yes, I'm sure everyone is going to have AI is there part of their answer, right? I mean for us, we have several business practices -- business projects in place right now involving both generative and Agentic AI. So it's just wrapping our hands around that, getting in front of the project team and making sure that we build a secure foundation before the business comes in and starts building these products out. We're also going through a major website replatforming. So we're completely rebuilding our whole website and mobile app right now, and that's gotten a lot of attention, obviously, a lot of cybersecurity focus.

Unknown Executive

executive
#75

I want to bring it back to deployment. Yaron, you talked about how quickly you could get us deployed on the endpoint. Angel, what was it like when you guys made the move from Splunk to AI SIEM? Can you tell us what that deployment was like?

Unknown Attendee

attendee
#76

Yes. Our environment is very super hybrid environment. So we have data from our legacy data center to the cloud and to some hybrid cloud environment as well. So when we look at the data onboarding, we're like, wait a minute, how can we get all this data in so fast. And your team is right there, providing the right solution there, give us, hey, you know what, for these applications, we can using the existing EDR bring the data in, and we can also using the Scalar agent bring the data in that we're able to deploy within our system and collect the data really, really, really fast for us. So that -- and your team is right there with us not only provide the right solution, but also make sure that validating all the integrated test cases and give us the knowledge that we need to run fast and also ensure our entire pipeline going to production running very smooth. And that is a huge success for us. Yes, we definitely were not able to do that fast without you guys' expertise there to help us and really, really make the big success for us. Our team will be route there and completely agree with me on that.

Unknown Executive

executive
#77

That's awesome because one of the biggest barriers that we see when customers want to adopt our ASM technology is their Splunk environments, their existing SIEM environments. They're very sticky. They're very customized, lots and lots of dashboards, and they have a lot of fear of migrating those dashboards or even migrating how they search in one repository today to how they'll search in ours. Any -- I know you're about to join that -- join the journey, but you obviously did a POC. What do you think about those challenges? And how are you going to get those people on board with this?

Unknown Attendee

attendee
#78

Yes. I think from a deployment strategy, I think what worked really well for us is that we invested when we did Splunk in a data pipeline solution in Cribl. So that did make kind of moving the data over from one tool to another worked really well. Like we were -- we had full production visibility in our POC instance, I think, within the first 30 days of deployment. That said, we're a lot smaller than Schwartz in DirecTV, but I'm sure we have a lot of the same technical complexities. Yes. And I think what was interesting going from Splunk into SentinelOne is it allowed us to kind of rethink what we wanted to do from a metrics perspective. So from those legacy dashboards to legacy reports, what were we doing before? Shifting that whole paradigm. So I think we're -- honestly, we're going through that now with that reimagining effort, but going into it with open eyes. Yes.

Unknown Executive

executive
#79

Were either one of you putting your EDR data into your SIEM before -- so now you have a...

Unknown Attendee

attendee
#80

Bringing that data together is really what's the driving factor and being able to see a full attack lifeline go from endpoint up to the application layer through the network and having that all in a single pane of glass, potentially even through a single story line. I mean that just makes my job so much easier.

Unknown Executive

executive
#81

That's fantastic. How important is to you, the research and staying on top of the threats with the data? I know you are a student of the game, Michael, and you as well, [ Srishi ], but how important is the data that you get from SentinelOne in that regard?

Unknown Attendee

attendee
#82

Huge, absolutely huge. I mean just the talk before us with the merging with GTI, I'm super excited for that, having the Mandiant Intel baked in. We're not a Mandiant shop, so being able to get that -- or Mandiant GTI shop, I should say, but being able to get that baked into the product, I think, is awesome. I think SentinelOne has the right approach to staying on top of what really matters. And so yes, we couldn't be more excited for that. And for us, how do we stay on top of these threats. It's a lot of reading. I read a lot of news, but also, we work closely with our ISAC, big shout out to RH-ISAC, any members in the room. Fantastic organization. There's one thing I can't stress enough to follow offenders in the room, seek out who your local ISAC is and join it, they will be a force multiplier for you.

Unknown Attendee

attendee
#83

Yes. We -- actually, one thing I was thinking like we are actually multi-tenant. We're global, right? Although we're trying to have everything in one place as well in one dashboard, but then there are certain places sometimes the client will be like, can we ensure that this laptop or these machines or these [ pough workers ] actually have like a policy added to it. We have that flexibility that we can do per client per region if we have to. And that's like one of the things which gives us more -- we're not on AI SIEM yet or it doesn't mean we can be, but we definitely get that pushed data over. It can help us detect those customer needs at that time. And we can -- like maybe for us, it's maybe we might be saying, oh, suspicious, this is suspicious. But for our clients, it might be malicious. So we have to make sure it's put up according to their client policy and requirements. And that flexibility, we get that S1. Sorry, I'm used to calling an S1.

Unknown Executive

executive
#84

Yes, that's fine. That's all good. You can call us any nickname you want. That's fantastic. Yaron, you've been a customer for several years, and you continue to invest in us. Anything that stands out that you would want to share with the audience today?

Unknown Attendee

attendee
#85

Well, yes, I'm not a SOC analyst. So -- but I can fully agree with what Mike just said. Our SOC analysts were very, very, very, very happy when we had this opportunity to have all the data, which they needed to collect from one system to another or from another and running through the world wherever they need to pull that data to identify, okay, is that a real threat? Or what does it do? So -- and out of the sudden, I can recall discussion or a talk I had with one of our senior SOC analysts when we just rolled out the first phase, he was like, well, that's -- that just took me 5 minutes, what I just had to do in more than half an hour before, right? And I think that's the great opportunity SentinelOne provides you with all that Purple AI today, if you have like junior SOC analysts, our stock is around about 40 to 45 people right now, not only senior analysts, but also like junior analysts. And I think that approach to include AI, not to replace anybody because at the end, you need some human interferes. But at the end, that was a big winner. And at the beginning, they were like, no, that's our work. We need to do that because yes, we are the analysts, but I think they will adopt soon. So yes, that's a great thing. So as already mentioned, it's a great solution technically. And having this kind of a partnership is unique, I would say. So...

Unknown Executive

executive
#86

That's wonderful. It's been so great to hear about the partnership on the human level as well as with the solutions. And I know you're going to be on stage later talking about your cloud deployment. So we're going to hear a lot more about it. Just in closing, first of all, I want to thank you guys. We've talked about Purple. We've talked about the EDR. We've talked about hyperautomation and of course, our AI SIEM. I would -- just let me turn the mirror on yourself. If you had to give some advice to your younger self, what kind of advice would you give to your younger self, Angel?

Unknown Attendee

attendee
#87

I will probably teach my younger self to be more mindful of this. Like I don't have to be the one who have the answer for everything. Okay. Is more open-minded to have the team contribute together. And I think that is the most powerful thing we can come out and how we can innovate on top of that as well.

Unknown Executive

executive
#88

That's very insightful. That's very insightful. Yaron?

Unknown Attendee

attendee
#89

Well, the question kind of makes me feeling old. So, but at the end, I think I had quite a nice session last week with a colleague of mine, and he was like, it's kind of a life lesson. So if you drive 200 kilometers or miles per hour on the highway, you can't just look into the back mirror, right, or the rear mirror. So it's all about looking forward, don't care about what has been in the past, all this legacy stuff we still might have to handle, but just go ahead, use opportunities like new tools, AI, whatever else there is and go ahead and go for it, give it a try.

Unknown Executive

executive
#90

Fantastic. [ Tristy ]?

Unknown Attendee

attendee
#91

I would say I'm still struggling with this. I can't say trying to be perfect on everything. It's like everything has to be the way this is. And I think I'll go back and tell myself and still tell myself like it doesn't have to be perfect. And things can go the other way, and it's totally fine. You just learn from it.

Unknown Executive

executive
#92

Perfect. Michael.

Unknown Attendee

attendee
#93

Hold NVIDIA stock longer than I did. In all honesty, probably trusting my gut more. I think throughout my career, it's been 17 years now, my entire formal working career. And I've seen a lot, I've experienced a lot. And I think with that, just trusting your assumptions because they worked out more than anything.

Unknown Executive

executive
#94

We're glad you trusted your gut with SentinelOne.

Unknown Attendee

attendee
#95

That was definitely one of them.

Unknown Executive

executive
#96

Well, thank you all for being here today. This has been a lot of fun. Thank you for sharing your story.

Unknown Executive

executive
#97

Good afternoon, everyone. It's incredible to see this community of defenders, our customers, partners and friends gathered here in Las Vegas. You are the reason we're here. Every attack you stop, every risk you contain, that is our shared purpose. And our mission has always been unchanged to help you defeat cyber adversaries and enable true cybersecurity resilience. But the world is changing. And over the next 10 minutes, I want to show how we can adapt together in this changing world and how our platform will help you defend differently in the age of AI. So we're going to start with a little recap. We're going to start how things are changing for the attackers. And as you heard this morning from Steve Stone and Triya, the pace of innovation for our attackers have gone into hyperdrive. Attackers are using AI to discover zero days faster, to automate malware builds and even to start to generate new types of malware. One example of this comes from our very own Sentinel Labs. They recently discovered a new strain of ransomware called MalTerminal. And with MalTerminal, instead of having a static payload like traditional ransomware, it actually calls ChatGPT APIs once it's installed. They will send natural language commands like create code for this operating system for a reverse shell and now create code to encrypt this directory. With MalTerminal, every execution is unique and no 2 payloads are alike. This means that traditional detection methods, signatures, static analysis, heuristics will not work. Ultimately, it means that we're fighting adversaries who rewrite their playbook with every move, and they're doing so at machine speed. But attackers are not just using AI, they're targeting it. AI workloads are the hottest new attack surface. This reminds me a lot of the early days of cloud adoption. Back in 2015, you'd read the news headlines and every week, there will be an example of an Amazon S3 bucket left wide open to the Internet, exposing sometimes millions of sensitive data records. Well, thankfully, we've moved beyond open S3 buckets, but now we're seeing the advent of prompt injection attacks that trick AI systems into leaking data. One recent example of this is the Salesforce force leak vulnerability. With this vulnerability, an attacker can discover a publicly accessible Salesforce leave form and put in it a malicious prompt. And then when the Salesforce AI assistant processes that lead, it's directed to start sending out sensitive information via tiny image speaking. So with this type of prompt injection attack, all takes is one public exposed field, one malicious prompt and then you have the potential for massive data exposure. This is the new frontier. It's evolving faster than any technology wave before it. So what do we do? How do we defend in this new era? We go back to first principles and focus relentlessly on outcomes. Everything we do at SentinelOne can be tied back to 1 of these 6 outcomes. First, comprehensive visibility. This means all your data, endpoint, identity, cloud, now AI logs, unified and searchable at any scale. Second, hardened attack surfaces. This means fewer exposures anywhere an attacker might land. Third, detection of all threats. No blind spots, no noise, even against the latest AI-powered threats. Next, faster investigations and remediations because resilience comes from action, not just alerts. And then lastly, less administrative overhead because security tools should simplify your lives, not complicate them. This is the modern mandate. Fewer tools, faster action, stronger outcomes. So to achieve these outcomes, we've revamped the Singularity platform. It now consists of 7 integrated layers. First, our core platform. This is our new and improved auto scaling cloud-native architecture deployed in 10 regions worldwide, including our latest region launching next month in the Kingdom of Saudi Arabia. The reliability, scalability and resilience of our platform is job 0. And this is something that we're continuously focusing on and improving. The next layer, our data platform. This is petabyte scale search and performance, now powered by Obsero AI for intelligent log collection against any data source. Getting data in now takes hours, not weeks. And the Singularity graph automatically correlates this data for graph visualizations and analytics. On top of this, we have our detection platform, 10 different AI-powered detection engines and now nearly 2,000 out-of-the-box detection rules that chew on those logs going into our data lake. We're also now producing new detection logic with unprecedented speed and precision by using Agentic AI internally by our detection engineering teams. Next up, we have our analyst platform. This is our new singular operations center experience. This is the default experience for all new customers. It brings together unified asset inventory, unified alerts, unified exposures, plus modern dashboards and reporting to make triage and investigation easier. Next up, our attack surface protection products. This includes our core products around endpoint security, identity security, cloud security, plus our new prompt security suite for AI workload protection. At the very top here, we have our AI and automation tools. At the core of our platform's AI strategy are Purple AI and hyperautomation, working together to turn intent into instant action. The vision you saw here, which you actually saw both in Tomer's talk and in the innovation talk with Heather and Rachel is that Purple AI reasons, plans and acts autonomously, while hyperautomation deterministically executes response actions at machine speed. This allows defenders to focus more on strategy instead of just tax. Lastly, on the side here, we have our revamped Wayfinder managed threat detection and response services launching today. You heard about that a bit this morning. We're going to go in more detail in just a bit. But the key here is that we're merging human intelligence with artificial intelligence to more effectively find people. This platform, these 7 integrated layers is what let us outpace even AI-powered adversaries. It's an integrated platform that's learning its fast as adversaries evolve. Okay. Let's s out now. From AI-driven malware to AI-targeted attacks, there's one truth, speed and autonomy now define cybersecurity. And the Singularity platform is built on a philosophy that turns that truth into action. You can think about this philosophy as 3 concentric circles. First, at the outer ring, we will protect every attack surface, endpoint, identity, cloud and now AI. In the middle ring, we will use AI, data and automation to act faster and smarter. At the center, we have people. This is human expertise, yours, ours, our entire community of defenders because AI cannot win this battle alone. It must be guided by the wisdom of humans. We'll use these guideposts throughout the product talks today, so keep them in mind. So that's the story from evolving threats to outcomes matter that matter to the platform and philosophy built to deliver against those outcomes. The same forces transforming our attackers are also transforming cyber defense. And SentinelOne is leading that AI defense transformation. We're not just reacting to the age of AI. We're defining how to defend within it with the #1 platform for autonomous security. Lastly, before I move on, I think you'll hear thank you a lot throughout the day today. But I want to give my personal thank you to our customers. Your partnership and trust is what makes SentinelOne what it is. You don't just use our platform, you shape it and now I'm going to hand off to my very talented [ TAM ] leaders to walk you thorough the details that how we can defeat adversaries together.

Braden Preston

executive
#98

Hi everybody, I'm Braden, and I'm really excited to be here with all of you today. And I'm especially excited to share with you our vision for endpoint and identity. In a few moments, I'm going to bring a special guest onto the stage, but I'll introduce him when the time comes. We're at a kind of pivotal point in cybersecurity. We've established a new front lines in cybersecurity. And I think that together, we are redefining them. Today, every vulnerable endpoint can quickly cascade into a breach. But these endpoints don't exist without a human or a nonhuman or an agentic AI entity, identity interacting with it. And I believe that we're uniquely positioned to deliver the necessary security and the protection in this convergence of the space, these 2 mission-critical attack vectors, endpoint and identity. So when we think about this, I'm confident that with the right platform, unified, autonomous, empowered by AI, we're going to continue to stay ahead of attackers. And in my next 30 minutes or so, I'm going to walk you through how we help you stay ahead, how we help you defend better, how we help you outpace threats and how we help you get more out of your teams. Today's endpoint isn't just a desktop sitting within the 4 walls of your office. And defending that is a tale as old as time. A lot of vendors are trying to solve it in the same old ways using the same old methods, not realizing that the attack surface is changing. They're not addressing the core source of the problem. That endpoint within those 4 walls, it expands. That endpoint can now be a mobile device. It can be a server in the cloud. It can be a developer's laptop sitting at home. It's a critical OT or an IoT system. It's a point-of-sale device. And at the same time, attackers are shifting their focus. They're not just trying to install and detonate malware on a system, right? They're focused on identity abuse. They're stealing credentials. They're using those credentials and elevating their privileges. They're moving laterally. And that's why our job cannot just be about detecting malware anymore either. We need to ensure that we're protecting every device, every identity and every connection in between them. So I'm going to start with the story. And I'm sure it's a story that you've all heard before. Hopefully, none of you have experienced it yourself, but I'm sure you've heard it. An employee is on his way to work, really busy, really busy morning already at home, and he gets an urgent text message from his Chief Financial Officer. She needs them to approve an invoice ASAP. It sends in caps in the text, ASAP as soon as possible. So he knows it's important. There's a link in the text message. So he's going to be a hero. He's going to get to the office. He's going to have it approved. He's going to be the guy that saves the day. He clicks the link, Sees the login page, enters his user name and password, get some weird air message, doesn't think about it, maybe he lost connection or something on his mobile device. He'll figure it out when he gets back into the office. What he doesn't know, but I'm sure all of you do, that, that was a fake login screen. He's entered his real user name and password and just basically handed them to an attacker. Now you have a bad guy looking a lot like an employee in your network. That attacker proceeds to move laterally, elevates its privileges, moves laterally again and lands on its objective, its target asset, compresses and steals credit card information or ransoms the entire environment. The company has been compromised, and it all started with a text message. That's why our mission is simple. We prevent every attack and respond with speed and intelligence. The endpoint is and will continue to be our focus, and we're not letting up. With the integration of identity, the advancements in our protections and the ability we can meet you where your infrastructure is, deploy in the cloud, deploy on-premise, deploy in hybrid environments in FedRAMP. We have a really exciting future ahead. But before I talk about that future, let me talk about a few of the recent releases that we've had. First and most recently, we released day 0 support for macOS Tahoe. We pride ourselves on being able to support the latest operating systems as soon as they come out, allowing your users to upgrade, make sure that you can stay protected while your employees stay more efficient. We also really understand that we can't just rely on process and registry telemetry to identify these advanced attacks. So we just released enhanced network visibility. This provides advanced visibility on the network but from the host using that same agent that's already installed. It captures what the operating system misses. It catches DNS running on nonstandard courts, and it flags evasive network behavior. We also understand that, that visibility shouldn't be just for our SaaS customers. On-premises and self-hosted customers need that same visibility, too. So we've enhanced our endpoint data gateway that allows you to maintain control of that data. You can now ship on-premises endpoint telemetry to our Singularity AI SIEM or any hack compatible platform like a Cribl or a Splunk. We've also made management easier with tag-based exclusions. We've given you control over live security updates and allowing you to control the local agent upgrades. But our ability to stop threats is why you continue to come back. You heard Steve Stone talk about the threat landscape this morning, and he threw out a stat. We stopped over 3 unique ransomware attacks per day. That means that by the time we all leave Vegas this week, there is a very good chance we would have stopped ransomware at least one of your organizations. And we're only doubling down. We're enhancing our static and behavioral AI detections to detect unknown threats, both known and unknown. In the past year alone, we released over 2,500 new detections to keep you protected. These include things like privilege escalation, protecting against credential attacks, blocking malicious drivers. The list goes on and on. We don't just react. We anticipate encounter. When you're responding, milliseconds matter, and that's why we rely heavily on AI and automation. We're able to automatically kill and quarantine files so the infection can spread. We can also automatically roll back a system to its last known good state. So you maintain continuity of operations throughout your response actions. All that telemetry that I talked about before, we stitch all these events together in a single storyline, so you know exactly what happened and how far an attack may have spread if it wasn't prevented. And by combining endpoint and identity, we allow endpoint detections to trigger instant remediation, and identity alerts can trigger policy adjustments or isolation. But what's the ultimate accelerator? You might have heard of Purple AI. Purple AI allows us to detect earlier, to respond faster and to stay ahead of attackers. With Purple, you don't need to learn new query languages and feels like every vendor has their own. You don't need to have to memorize a 3-page query in order to type it into your system. You just ask a question. Hey, Purple, was anybody running malicious power shell or suspicious power shell in my environment? Is anybody trying to exploit this MITRE tactic or technique? Please write me an e-mail of your findings. Oh, I have a team in South America. Can you translate that to Spanish or Portuguese? Purple is not just answers. It provides context, and it's not just fast, it's smart. In fact, our customers that use Purple AI on average, are able to manage 61% more endpoints. This ensures that your entire fleet remains protected. And we also believe that it's not just a nice to have. It's foundational. And that's why Purple AI Foundations is included in Singularity Complete. No extra SKUs, no per query charges and no limits. This is necessary to fulfill our vision of empowering every single analyst. And speaking of AI, Prompt security provides us a way to redefine data loss prevention. What do you do when the data leak isn't a file, but it's a conversation between a human and an AI or an AI agent and its tools. That's why you need AI-aware DLP to monitor every AI interaction because that could lead to a potential data leak. We do LLM traffic inspection to monitor the flow of data between users and AI and intercept potentially leaky prompts. It's not just mistakes that we're worried about either user mistakes. We need to defend against the list activity as well. So we stopped prompt injection and other jailbreaks. And finally, you need to have visibility in your environment. And that's why prompt is able to discover shadow AI. So find all the AI that's in use within your environment, sanctioned or unsanctioned and put the proper controls in place so that you can make your employees more efficient while keeping yourself safe and compliant. This is how you harness AI confidently, unlocking innovation while keeping your data secure. So the next time you're asked, are you down with DLP, you can confidently say, yes, you know me. Thank you. I thought if I got one laugh, it would be worth it. We got more than one. All right. So now I want to bring this to life. I'm going to welcome on stage Travis Baguso, Senior Security Engineer from Hawaiian Airlines. Travis. Travis, thanks for being here. So I know you and I talk quite often, but I'm really excited that we're going to be able to share a lot of the innovation that your team is doing leveraging SentinelOne. Before we get into that, I kind of want to start at the beginning. Can you talk a little bit about when you were looking to replace legacy security vendor, what were you doing? And why did you choose SentinelOne.

Travis Baguso

attendee
#99

Thanks for the introduction. In 2018, we were then customers of a legacy provider. And we were in the market not only to improve our defensive posture, but we also wanted a product that would provide us the telemetry to be able to make use of our threat intelligence feeds and other intel that we were receiving for small items like being able to retroactively look for IOCs in the environment going back an entire year to be able to detect or see living off of the land activity before anything serious comes to fruition. One thing I would like to also mention is when Ranger now Network Discovery was released, not only was it critical for that to meet certain regulatory requirements, but after using the product or using that capability, we were able to detect other rogs on top of the network like vendors connecting to a docking station, knowing, of course, they weren't supposed to, to endpoints being on top of wireless networks that are reserved for certain applications and, of course, kind of to bypass security controls. So that's kind of a short intro to our origin story with SentinelOne, where we then became customers in 2019.

Braden Preston

executive
#100

And thank you for that. And I'm sure you still face challenges today, and maybe some of our audience can relate to them. Can you talk about some of the challenges you face, maybe unique to your industry, but maybe not?

Travis Baguso

attendee
#101

So much like the manufacturing and the health care industry, the transportation industry where the airlines fall under is no exception to its uniqueness. There are several applications from vendors specific to airlines that don't like process injection for that enhanced modern capability. There are certain applications that have extremely high readwrite, execute and delete these text files with one line of critical data that happens with thousands -- hundreds of thousands of transactions. And of course, with the agent monitoring everything that's going on, this, of course, will increase CPU memory resource utilization on top of the endpoint. A credit to my colleague, Steven Arroyo Sandoval, that has helped the organization -- my organization along the way to help addressing a lot of these issues. One of the -- and for the incident responders for the SOC folks in the room, one uniqueness for my industry is that our -- well, it's unique to others, but it's -- our workforce is globally dispersed. We have pilots, flight attendants, also employees flying for business that can log in, in one location and show up in another merely hours, even in 30 minutes later. For example, we have an employee or a flight attendant checking their e-mail coming out of Honolulu right before a flight to Haneda in Japan. And of course, on our airplanes, we have Starlink, so they are able to connect. They could check their e-mail, an employee or a flight attendant could check their e-mail an hour later. And of course, once you hit a certain point over the Pacific, satellites are going to change. So now their activity will look like it's coming out of Honolulu that instant, it shows up like it's showing up in Japan. Now for the incident responders, we, of course, see this, hey, that does not look right. Unusually, it screams compromised account where one log in here, another log in suspiciously almost across the world. So that would be one of the uni unique items for the -- for our organization. One of the things that we did do is when custom detections were released, what we now call [ SAR ] rules and credit to Gregory Santee and Emily Koh, who spearheaded this effort within Hawaiian Airlines is using custom detections to reduce the noise so we can stay on top of the signals that we're receiving and address some of these items that are unique to geographically dispersed organizations. And to that, we were able to zone in and stay on point and reduce the mean time to respond for events.

Braden Preston

executive
#102

It's interesting. In our industry, we refer to the impossible traveler problem as a classic example of like an identity-based attack, something log in from different areas. But in your world, it's a possible traveler problem.

Travis Baguso

attendee
#103

Every day.

Braden Preston

executive
#104

And I'm glad to hear how customization has helped you with Star rules. That ease of use is something that we take very seriously. And I think one of the ultimate ease of use things we have is Purple AI. Can you talk about how Purple has advanced your team?

Travis Baguso

attendee
#105

So when we were able to start -- or to begin using Purple AI, one of the great benefits is, especially with alerting and events is the summary that it provides. For a lot of the seasoned analysts out there, it does -- it can even take just as quick as a few minutes to be able to figure out, hey, what happened, who's the 5Ws, where and why? But with Purple, we get an upfront summary of everything that is going on, on top of the exit telemetry provided on top of the platform. Has this been seen elsewhere? And then being able to use Purple to now expand on that blast radius, where else has this been seen in the environment? Or are there any indications of this about to happen elsewhere in the environment. That would be one of the use cases. And everybody has heard it before, Purple AI, being able to build these queries, sometimes -- especially for you, junior analysts, power queries may be a little bit intimidating, but it does provide that customization to be able to see what you specifically need for your use case. We can use Purple. We've used Purple AI to help build these queries and then from there, build that base query, modify it to our specific use cases to be able to provide that extra telemetry, summary or any -- or the conclusion to be able to then action as needed. Those would be -- and that would be one of the other ways we've used Purple. And hey, if you want a quick spot check like seeing if anything is being explored in the environment, even something as simple as, hey, what are the last Chrome extensions that have been installed in the environment in the last 7 days, it creates that query, provides you the results, you can then export it. And of course, you get those extension IDs and you can cross-reference what those extensions actually are and be, hey, that -- yes, that extension doesn't -- that definitely doesn't belong in the environment. And then you can work with your respective teams or we've worked with our respective teams to be able to action that to make sure that our environment stays as pristine as possible. As we all know, it's an ongoing effort. It's job security, but Purple AI has definitely helped us along that route.

Braden Preston

executive
#106

Cool. Yes. I just have one more quick question for you. I mean I talk about it, maybe it's a bit self-serving, but I think we're seeing a lot of convergence or consolidation happening, whether it's attack services or tools or platforms. How is that consolidation playing with you and your teams?

Travis Baguso

attendee
#107

So one of the things I like about SentinelOne is every time a new feature is released, a lot of -- before this would scream another agent. Now, everything is being combined into one platform, one unified platform. Having that extra agent, especially with the new capability that you're going to get, it just causes friction with your other IT teams having to justify and explain, oh, another security agent, in their mind, oh, it's another security agent on top of our systems that could take up memory system resources or potentially causing issues. Now -- especially with identity, having everything combined into one unified platform, all you need to do is either upgrade -- upgrade the agent to enable the capability, but it's already there for us. There's no extra having to install something else, go through the -- well, you have to go through a change, of course, but it's not the long process of trying to introduce a new agent to your environment. Everything is already there, and that definitely has helped the use or the acceptance of a security platform being broadly used in the environment.

Braden Preston

executive
#108

Awesome. Well, I really appreciate you coming out. And more importantly, I appreciate you being a long-time customer of ours, partner of ours. Your feedback has directly made our product better, and I hope we can continue this relationship for a long time.

Travis Baguso

attendee
#109

Of course.

Braden Preston

executive
#110

All right. Travis, thanks so much. All right. So Travis just told you how we're currently protecting his environment, all the things that he's using. But what are we going to continue to do for you over the next 12 months? I'm going to give you just a few of the highlights that are coming. We do have a dedicated road map session tomorrow that I hope you're all able to attend on endpoint and identity. But here's just some of the highlights. First, we're going to be releasing application control. Application control will allow you to set default deny policies and only run the software that you approve to run on an endpoint. This helps you increase compliance and make sure that you stay protected. Second, I talked about that network visibility earlier that we've already released and you have available. We're going to be building really advanced network-based detections, but on the host for you. So being able to identify communications with C2, advanced lateral movement, or people trying to hide their communications on the network, attackers trying to hide their communications on the network. You're also going to see a lot of improved management capabilities. Just a few are around exclusion hygiene or hit counts for your exclusions, auto exclusions, so you don't have to write these things anymore. We're going to identify what's happening in your environment and give you the exclusion, so you don't have to worry about it. Again, ensuring that your operations remain efficient as we protect you. Those are just a couple of the highlights, and I really do encourage you to join our road map session tomorrow, but we'll go deep on both the endpoint and the identity road map. Speaking of identity, we know that attackers don't just stop with that initial intrusion on the device. In fact, we know that they want your credentials. Identity attacks have surged over 70% in the last year alone. And now more than half of the attack, or techniques, that are defined by MITRE are identity focused. To protect against these types of attacks, most organizations are forced to manage different disparate tools. So you have console hopping that introduced mistakes that introduces risk. That's why I'm really excited to introduce to you today our new Singularity Identity Solution. Our new Singularity identity simplifies identity protection at the identity layer. If you're familiar with our identity products today, you know that we have 3 separate use cases that we support. Identity detection and response, identity for identity providers, identity for IDPs. And number three is identity for security posture management. That is now all going to be delivered into a single SKU. One thing to buy, making purchase so much easier. It's also going to be delivered in that same agent. Travis talked about this, a single agent that gives you protection across all of those use cases, making it easier to deploy. And it's all managed by the Singularity platform, one platform. Making it easy to use. So for you, our customers, makes it, again, easier to deploy, easier to use and more powerful protection delivered in that single agent. And we're not stopping there. We've recently introduced policy-based conditional access. It's currently in beta. Policy-based conditional access gives you granular control over policies and for your identity behaviors. You're able to define risk-based rules that in the moments we see suspicious activity happening, we can stop it. For you, the security teams, this means continuous adaptive protection, and the confidence that identity attacks are stopped in real time and on your terms. The convergence of endpoint and identity is the new front line. And that's why we're always thinking about not just the device, not just the endpoint. But the human and nonhuman identities that are interacting with it. The AI agents that may be running or query, and we protect against all of it. So let me go back to that story that I talked about at the beginning. I think it's plainly obvious because you're at a SentinelOne conference that, that was not a SentinelOne customer. Because if that was a SentinelOne customer, as Ely mentioned earlier, we protect across the entire attack surface. That initial mobile phishing text, that phishing text, Singularity mobile stops it. Stolen credentials, elevating privileges, moving laterally, Singularity identity stops it. Data exfill, ransomware, singularity endpoint security stops it. Again, we protect against across the entire attack surface. The attacker doesn't stop at the initial intrusion device, and neither do we. One final point here is that it's technology and people together that stop threats. Our AI and automation makes human analysts better, and makes them smarter and it makes them faster. And we're going to continue to innovate in this area so that you can stay protected and have the most effective, efficient protection available. And we're building more than features. We're delivering a unified autonomous platform where endpoint and identity and mobile, they're not separate domains. Where telemetry fuels intelligent decisions. Where response is instant, and where people, the analysts, you, are always in control. Thank you very much for your time today. I really appreciate you listening to me. I'm hoping that I get to see all of you throughout the rest of this conference, go to our road map session, go deep on our detections, they're all going to have sessions tomorrow. Thank you very much. Have a great rest of the show.

Operator

operator
#111

Please welcome Senior Director of Product Management for Singularity AI SIEM, Adriana Corona.

Adriana Corona

executive
#112

Everyone. I'm so excited to be here. And last year was a highlight for me. But I'm even more excited this year because we get to talk about all the progress we made since then. And it was actually here at [indiscernible] that last year, we introduced the autonomous security maturity model. And it wasn't just a product vision and it wasn't a product road map. It was actually a new way of thinking about how security teams can transform how they work over time. And since then, it's gotten really wide adoption. It's changed the way that the industry thinks and talks about AI-driven security. Also since then, we've just been really hard at work just building it. So today, it's going to be more about what it's like in practice. On my team, our mission is for security practitioners to love their work. And that means for us, when we talk about real AI innovation, what we mean is how are we impacting how security practitioners are working? Are we making it more efficient, but hopefully, more enjoyable as well. And that is why I won't just be here alone on stage today. We're going to bring out the practitioners, the experts and the customers who are driving this transformation with us. We're going to hear from our own customer zero, our SOC team. And we're also going to hear from a customer about their journey from a legacy tool to AI SIEM. But before we bring them on the stage, let's just recap briefly what is this maturity model all about. The maturity model is a road map to help organizations chart their course toward a more autonomous future. And it starts with some levels of manual and rule-based approaches, followed by AI assisted, then partial autonomy and finally, high autonomy. And what you're seeing at each stage is more advanced AI and automation that will save you time, and it's doing more of the work on behalf of the analyst, so that your security teams are freed up to be more proactive and more strategic. What we want is a future where the SOC analyst is actually supervising, monitoring the work that is done by the AI systems. And our vision, for security operations, is to elevate the human analysts. We're not here to replace the human analyst. In fact, we believe that it should be a symbiotic partnership between the human and the AI systems that we're building. And we've been doing this for over a decade, by the way. In fact, if you are a current customer of Hyperautomation and Purple AI, you may not realize this, but you can already operate at that Level 3, or the partial autonomy. You're way beyond the manual and rules-based approaches. And really, what we're trying to do is shift the balance of power back to the analyst. That way, the analyst can focus on the critical tasks. I really liked how Rachel put it. If you heard her in the innovation session. She said, you focus on the strategy, let the AI take care of the chaos. And that's really the vision that we're working toward. But I also want to mention this in action. What does autonomous security look like in action? Starting with extended visibility. For us, that means a streamlined AI-powered data pipeline that actually eliminates 80% of the noise before it even reaches your team. That also means 100x faster querying than a legacy SIEM. And teams adopting this model for working, they're already seeing results. They're detecting faster, in fact, 63% faster. They're responding 55% faster. But the most important part, and we've been reiterating this throughout the day, is the core. At the core of this model is what matters the most, the analyst expertise. And like I mentioned, the goal is not to replace the human analyst. The goal is to arm and empower the human analyst. We're amplifying human intelligence. Now let's talk about this in practice. I mentioned that's going to be the theme of today. Autonomous security, it's not just a theory, a vision, or a model. It's actually a new way of working. And it's actually how we're already operating today. So you'll even see some examples of that in action on this stage. So how do we actually get to that Level 4, or the autonomous -- highly autonomous security? It's not just a collection of products. It's actually a strategy that we've built in multiple layers. So let's build it together right now. It starts with the foundation of full data visibility. You can see that as the foundational layer here, and it fuels the entire system. That's where we have a single intelligent data stream that is now powered by observo.ai and with built-in intelligence. And if the data is actually the fuel, agentic AI and automation, that's the brain of the system, where AI SIEM is your security workbench, Purple AI is your smart analyst that's responding and investigating, and Hyperautomation is executing the actions. Both of those layers are reinforced by the topmost layer. That's where we actually have governance and control, where we can protect your endpoints, your identities, your cloud assets and now with the introduction of Prompt, also your AI applications. But the most important thing is that all of these layers are there to elevate and amplify the most critical ingredient that we mentioned earlier, the human analysts and the human expertise. So these are the ingredients. Let's talk about them each one at a time, starting with that foundational layer of data. So we knew, because our customers have so much data, that actually it's cost prohibitive. Our customers already could not afford the visibility that they need. And so for us, solving that fundamental data problem was just not negotiable. We knew we had to go beyond simple ingestion, and we needed an intelligent data streaming platform that could deliver data faster but also at a lower cost. And now over the summer, you may have noticed like splashes in the news in the market about acquisitions in this data pipeline space. And the only thing I will mention about that is that while the competition was focused a lot on the headlines, we were just heads down on technical evaluations. So we did a deep technical evaluation over months of 11 vendors. And after that evaluation, Observo AI was undeniably the top, the winner. It was the only platform capable of actually powering that foundational data stream that's going to power our autonomous SOC. And as you heard earlier today from Gurjeet and Tomer, Observo AI is now available. We're also hoping that customers will want to use our integrated beta, and this is the integration of Observo AI into our AI SIEM. What you get with that integration is actually out-of-the-box pipelines that are already optimized for SIEM, and they're actually feeding data directly into the core of our AI SIEM. You're also going to get better visibility and transparency, with really easy-to-use dashboards for health monitoring of your data pipelines. So you'll be able to see data volume by source. Even if there's anomalies in the data volume, you'll be able to see the cardinality of different data properties and measure things like CPU or memory utilization. And we know that the challenge with data is actually not just the volume of data. The challenge is that the types of data have also fundamentally changed from high cardinality fields, to millions of assets, and a very diverse ecosystem of cloud logs. So that's just the new normal. And what that means is that legacy SIEMs are being rendered obsolete. And that's why I'm also very excited to announce that we're releasing an industry-leading improvement to the query scalability on our platform. And I'll tell you what that means in practice. What you're getting is a 20x improvement in high cardinality concurrent queries. And just to give you an example of what that might mean. Imagine that you're searching like show me every instance for each user of a failed login event. Now in a very large enterprise, the user property, that actually can have millions of fields, millions of values, and you've all maybe experienced this in your own organizations. So that means a query like that would be very, very slow, or it would have a huge memory footprint. But more than likely, what happens is it times out, or it fails. But with our new introduction of scalability, our AI SIEM will be able to answer that same question within minutes or seconds. And that's even with the highest cardinality data even over months and even under peak loads. So that combination of AI SIEM, powered by Observo AI data pipelines, and our 20x improvement in query scalability, that brings massive advantages. Starting with Observo AI acting as the smart filter. It filters out the noise and optimizes the data for use downstream with AI SIEM. It also prepares it for our index-free architecture. And it's that architecture that allows us to have really fast, high cardinality queries at scale. And of course, both of those elements actually compound benefits. You have better, smarter, faster data being fed into your AI SIEM, and you're able to query it at scale faster than on any platform. And those two things lead to faster response and the ability to automate response faster. And great. Of course, when we talk about response -- when we talk about autonomous security, right, you can't talk about it without talking about action, without talking about response. That's where Singularity Hyperautomation comes in. Now we believe that complex automation should not be done only by advanced programmers or dedicated specialist teams. And that's why we built an easy-to-use no-code canvas. It's embedded directly in the platform. It empowers your teams to build flexible automations with confidence, even really complex automations. That really frees your analysts to focus on what matters because they're not doing that manual work anymore. And the combination of Purple AI with Hyperautomation, it's there to fundamentally up-level your teams. So they can worry about what they do best, things like targeted threat hunting, being proactive, being strategic. Of course, it goes without saying, we're building out-of-the-box agentic actions and workflows. Those will do the work for you. But at the same time, we're empowering builders and partners. Those who are ready to push the limits of what's possible with agentic AI. And as Heather and Rachel announced earlier, we're so excited that as of today, our open source Purple AI MCP server is available on the GitHub and you can use it now. And I'll tell you a little bit about how to think of this MCP server by analogy. In the past, you'd use maybe brittle, API calls, one-off API calls when you needed the context of your full ecosystem. An example would be like trying to learn a new concept by reading a book line by line. That's the old way. The new way is like having access to the author of the book that you can ask questions of at any moment. That's the new way with Purple AI MCP server. So imagine creating your own agents using a framework like maybe Amazon Bedrock or Google Agent development kit. Then imagine using whatever foundation model you want, maybe OpenAI or Anthropic, maybe something that you've built yourself. Then imagine giving that access to Purple AI MCP server, which actually grants access to the full context of the Singularity platform to make decisions. So instead of imagining, let's go through an example. In this example, what we're going to go through is trying to secure your software supply chain. So here, we have a developer, let's call him Alex. He's about to make a bug fix. So he's merging code to fix a bug, or at least that's what it looks like to us. What we don't realize is it's not Alex at all. It's an adversary trying to inject malicious code knowing that your CI/CD pipeline has automated merging. But the good news is you can have an action triggered with GitHub actions that calls our Purple AI MCP server and asks questions in real time. Questions like what device is Alex using? Is that device showing any signs of infection? Does it have open EDR alerts? Does it have any critical vulnerabilities that are not -- that haven't been patched? And if the answer is yes to any of these questions, you just actually block the merge. So what that means is you stop the attack before it began. And now I want to point out that's different than the traditional sense of when we talk about shifting less in security because it's not just scanning code. What we're doing is actually validating the integrity of the developer's environment in real time when it matters the most. And that's just one of many examples of what's possible with Purple AI MCP server. The possibilities are limitless. And I'm sure we appreciate that example. But what I'm most excited about is seeing it in action. So we're going to bring out our own SOC team to talk about how we've been transforming security operations at SentinelOne using exactly these techniques. So please help me welcome to the stage, Carter Church. He is the master mind. He's the architect behind the autonomous transformation of SentinelOne's own SOC team. Welcome, Carter. Well, I have to say I've been hyping you up. So we better get to it really quickly because everyone is anxious to hear how have we been transforming our SOC?

Carter Church

executive
#113

Let's do it. Yes. So our own security team, the ones on the front line here at SentinelOne, we've been on a journey to build a truly autonomous defense. We've used our own products, things you're all familiar with that we've talked about all day, AI SIEM, Purple AI and hyperautomation, to build a framework that's saving our analysts thousands of hours, and fundamentally changing the way that we approach security.

Adriana Corona

executive
#114

And what can you tell us about SentinelOne's environment?

Carter Church

executive
#115

Yes, it's really complex. We aren't just a typical enterprise. We're a prime target for the world's most sophisticated adversaries. And every day, we ingest and analyze an enormous volume of very granular telemetry. And that data is the ultimate prize. By compromising a security vendor, a threat actor gains access not only to high-value targets, but also to the various systems that we use to defend against them. It's the ultimate supply chain attack. So all this means that having the capability to tame today's data explosion isn't optional, right? It's a strategic imperative that directly impacts global security and trust. And so all of this requires more than just standard enterprise tools. It requires foundational scale. For SentinelOne, we operate a massive hybrid cloud infrastructure. We generate petabytes of security telemetry. We ingest events from thousands of unique sources. And so before we could even think about some of these things, we had to solve this data problem first, right? This is exactly why AI SIEM is the cornerstone of our operations. The performance and scalability you mentioned earlier, Adriana, are just critical for us. It means that our analysts can run massive complex queries across petabytes of high cardinality data and get answers in seconds, not hours. So having a powerful data foundation isn't just some nice to have. It's truly the only way that we can hunt at the speed and the scale that our adversaries operate.

Adriana Corona

executive
#116

And while being able to search at scale and quickly is obviously essential, but that doesn't actually stop any attack. For that, you have to respond. So what's the next step for you.

Carter Church

executive
#117

Yes, it's a good question. So all that data is just fuel for the Hyperautomation engine that I'm about to show you. When we think about traditional automation solutions, they typically involve building individual workflows for every single alert based on its type. But long term, that approach just doesn't scale and creates a lot of technical debt. And so instead, we started by defining these broad functions that could be reused across a variety of alert and response scenarios. And this meant that instead of just building new workflows for every single new alert that we onboard, we could just reuse these already existing functions. But after this, we had a realization. So once we had these functions, we needed something that could understand which of them to call for each unique alert coming in. We needed something that could look at each alert, like an intelligent engine that could look at an alert based on all of its fields, not just on some alert type, but on all of the details that make that alert unique, and then determine the exact enrichments or actions that specific alert needs for response. And so we built that. A Singularity Hyperautomation workflow that loops over an alert that gathers context from sources like previous alerts and relevant playbooks, and even telemetry from AI SIEM. This all feeds into a model that decides exactly which of these enrichments to call and what parameters to pass.

Adriana Corona

executive
#118

That's incredible. And I want to reiterate something you just said because it's the model that's deciding what action to take. It's working on its own to make those decisions. I also know you were one of the earlier adopters of the Purple AI MCP server. So how have you been using that.

Carter Church

executive
#119

Yes, we're pretty lucky. So Purple AI's new MCP has been one of our most exciting integrations so far. With this, we can leverage all of the intelligence of Purple AI in our own customizable and automated response. And this means we can do things like build, or query, or summarize, or even do AI SIEM data lookups for the analysts before they even begin their human response. And so it's just been a total game changer for us. We love it.

Adriana Corona

executive
#120

One thing that I find inspiring and fascinating is that our own SOC team, they were facing the same challenges that I hear every day from our customers. So being burdened by alert fatigue and a lot of manual actions to see the transformation in our own team has been incredible. But I'm sure if everyone here has also faced that challenge, I'm sure you're all very interested in the results. So can you tell us what's been the outcome of that transformation?

Carter Church

executive
#121

Yes, absolutely can. So this system saves a ton of time. We're saving over 100 hours a week of manual analyst effort. And that's time that we can give back to our analysts directly, right, for all the things that you talk about, with being able to do kind of higher order and more complex tasks. On a per ticket basis, we're reclaiming over -- or sorry, we're performing about 75% of all regular investigation steps. But most importantly, when an analyst comes in, all the information is already there, ready for them to do a final check, not to kick off an extensive investigation. This is the difference between 30 minutes of manual analyst effort on a ticket and 30 seconds of due diligence.

Adriana Corona

executive
#122

30 minutes to 30 seconds is incredible. Now I just wonder what it's like to be a SOC analyst at SentinelOne today? When I show up and the majority of the work is already done and the system sometimes even escalates to me what to do. I know you're going to give us an example of an action.

Carter Church

executive
#123

Yes, we've got an example right now kind of going on the screen. So in this case, analysts would have come in and seen a weird Okta alert for a user resetting their password from an anomalous location. And all the analysts in the room know that we could spend countless hours investigating that and comparing and cross-referencing context from so many disparate sources. But instead, our system surface all the relevant details, including the fact that this employee had no recent approved work travel to this location. But we didn't stop there. We can integrate with Slack. So we reached out to the employee on Slack and asked them, "Hey, are you aware of this? Have you been traveling? And of course, they responded, no, I have no idea what this is. So what may have otherwise just set in a queue, until an analyst came in and performed some manual investigation, was immediately investigated and worked. And those findings meant that it was prioritized for response first.

Adriana Corona

executive
#124

That's incredible. And I have to say the first time I've seen people like watch some of this in action and see it come to life and work. Their response is usually like that head explosion emoji, because it is remarkable how much time you're saving. And it's great to see the technology spring to life here.

Carter Church

executive
#125

Right. Yes. So it's just really cool. Honestly, it's been such a cool system. What you can see on screen right now is what we would actually reach out and surface to an analyst. And so this is as an analyst, you're coming on to something that's already been investigated. Where this information has already been brought to you. And again, it's your job to make that final determination.

Adriana Corona

executive
#126

That's amazing. Thank you so much for being here and sharing this, Carter.

Carter Church

executive
#127

Thanks so much for having me. And for those who want a much more technical deep dive into how this all works, we have a dedicated session tomorrow at 2:15. So hope to see you all there. Thanks again.

Adriana Corona

executive
#128

I'll definitely be there. I'm sure it's going to be very popular.

Carter Church

executive
#129

Let's do it.

Adriana Corona

executive
#130

Thank you, Carter.

Carter Church

executive
#131

Thanks so much Adriana.

Adriana Corona

executive
#132

Well, I have to say that I feel very lucky because at SentinelOne, we get to build tools for security practitioners. But we also have incredible security practitioners in-house, like Carter, like our SOC team, also our MDR analysts and investigators. Some of them are in the audience here. Our detection team, our threat hunting team, our incident response team, these are all examples of people in the front lines at SentinelOne, who we consider to be our customer zero. And sometimes they're the very first users of our new features. We're also very lucky because we have a thriving beta and UX Insiders program. And if any of you have participated in that, that means you've gotten early access. So from ideas to prototypes, sometimes you're the first to use a feature. So I also want to thank any of you who have participated and helped us learn and helped us be better. And needless to say, we really try to keep the practitioner and focus here when we're making decisions. So in that spirit, I'd love to bring a customer up to talk to us about their experience and journey. Please help me welcome Rod Goldsmith from YKK. He is a cybersecurity leader. Welcome, Rod.

Rod Goldsmith

attendee
#133

Thanks for having me.

Adriana Corona

executive
#134

So you all may not know this, but you're probably a customer of YKK because YKK is the leading manufacturer of zippers and fastening products.

Rod Goldsmith

attendee
#135

That is very true. We actually produce enough zippers to go around the world 80 times per year. We are located in 72 countries. And outside of zippers, we actually produce products such as buttons and a competitive product to what most people know as Velcro as well.

Adriana Corona

executive
#136

Wow. And I know when we first met, you weren't running AI SIEM at all yet. You were actually on a legacy endpoint tool. So just curious what was that tipping point or what was the pain you were feeling that made you realize the legacy tools just weren't -- they were a roadblock? They weren't working?

Rod Goldsmith

attendee
#137

Yes. Pretty much our legacy vendor were not really focused on innovation too much. So we had a legacy tool that wasn't giving us the security value that we needed. We had agents deployed, but we didn't know if the agents were working. So it's really like a back and forth trying to see if that value was really there for us. So after doing a gap assessment, identifying all the critical gaps that we had, we look for a solution that could give us a better outcome and SentinelOne was that product for us.

Adriana Corona

executive
#138

That's great. And I know you were also -- you've been a customer for about 18 months, that's right. You were looking for a data platform as well in SIEM. You also kind of skipped over any of the legacy players. You went straight for AI SIEM. So I'm just curious, how is it going so far?

Rod Goldsmith

attendee
#139

Well, the change for us has been immediate. We've seen the value immediately. We have a fundamental visibility of a lot of critical resources now. So I'm very happy about that. Our Internet-facing devices are critical applications. We have all of that rolled into a central platform. So that value for us has been critical, critical, very critical.

Adriana Corona

executive
#140

And your team is also using Purple AI. What have you seen? Have you seen any time savings? Has it changed the way you've been working?

Rod Goldsmith

attendee
#141

Yes. So our team is very lean and our security program is very new as well. So Purple AI has helped us a lot in just having that real-time information on those alerts. Our analysts are able to have more trust in what they're seeing. And for the sort of episodes where there's a question to what we are seeing, we have expertise on site as well to help with that sort of that gap fill, too.

Adriana Corona

executive
#142

Yes. And we were talking about AI and automation earlier, not just Purple AI. I was actually kind of surprised by your response because you said you think autonomous security is inevitable. So I'm just wondering why do you think it's inevitable?

Rod Goldsmith

attendee
#143

Well, threat actors are using AI at a very constant and increasing pace. They're finding a lot of use cases. So it's going to be hard for humans to keep up with that level of volume that's coming in. So having automation to help us minimize those alerts, minimize that noise and see what's really out there is going to be crucial for our long-term security posture.

Adriana Corona

executive
#144

That's great. And we've also been emphasizing throughout the day the importance of human expertise. So how do you think that fits into your SOC and your team?

Rod Goldsmith

attendee
#145

Yes. Like I was mentioning a moment ago, AI is perfect. It's not going to be a silver bullet for everything, but having that expertise on site for when there are those rare occasions of something being questioned, we can have that extra level of comfort knowing that we are -- we can believe what we're seeing or if we need to take other actions, we can do that as well.

Adriana Corona

executive
#146

Great. And what do you think -- looking forward, what do you think is your biggest opportunity to use AI or to use automation?

Rod Goldsmith

attendee
#147

Well, I'm very excited about Hyperautomation. I was looking into that before coming to this conference, but that was also a big reason for me being here as well to get more ideas on how we can make use of that. So I love the information that Carter Church presented to us today. And also, I think his name is Sean Stugart yesterday as well. I gave a lot of good information, too. So very excited about that. And I think that will help us be more efficient, maintain a lean team and also push our posture ahead.

Adriana Corona

executive
#148

Yes. Like you mentioned, seeing what Carter's achieved with our SOC. I think we're also excited to see what our customers are going to do with the same types of techniques, especially now with the MCP server release.

Rod Goldsmith

attendee
#149

Yes. Looking forward to making use of that, too.

Adriana Corona

executive
#150

Well, I want to thank you for being such an active participant in our community and helping us learn from you as a customer. Thanks for being here, Rod.

Rod Goldsmith

attendee
#151

Thank you.

Adriana Corona

executive
#152

Well, if there is one thing I hope that you take away from the last 30 minutes, it's that autonomous security, it's not a theory, a vision or a road map. It's actually real. It's a new way of working, and it's a way that we're already operating today at SentinelOne, and the way our customers are operating as well. So let's just recap what we've announced over the last 30 minutes. Firstly, Observo AI integrated with AI SIEM, and we're looking for customers who want to be first to test it out. We also increased the query scalability by 20x for high cardinality queries. And like I mentioned earlier, by the way, this is an industry-leading update. And finally, we launched Purple AI MCP server. So that's going to help everyone here who's ready to embrace agentic AI approaches to start using that for your own workflows. Now we believe that using AI is not actually just about doing more with less, which I think is a common misconception. We think it's about doing more but with more intelligence. So we imagine a future where automation is reducing the noise and automating a lot of the mundane tasks, so that it frees up your security teams to do what they do best. And we also believe in a future where that human expertise, it's not just at the center, or the core. It's actually the driving force of security operations. And so far, what we've been talking about is how SentinelOne is using AI to build tools for security practitioners. But now it's time to talk about that other side of the coin. Over the last 2 years, as I'm sure everyone is well aware, businesses have been racing to adopt AI in their organizations. So for everyone here who has seen that change and that revolution, you've also noticed that double-sided coin. Where on the one side, it is the incredible promise of using AI to accelerate your teams and your organization. But on the other side, there's a hidden risk. Because the very AI models that our businesses have grown to depend on, they are now our new and most critical attack surface as well. And the dangerous truth is that in this race for innovation, very often securing AI has been treated as an afterthought. But at SentinelOne, we believe that's actually a false choice. The only way forward is with an end-to-end platform where we're using AI, not just in the front line, but we're also providing the tools for governance and control to secure and protect the AI that our businesses have grown to depend on. And after the break, we're going to hear from Itamar Golan, and he's going to walk us through that next frontier of securing AI. Thank you very much. [Break]

Itamar Golan

executive
#153

I messed up my ankle, so I'm sitting today if that's ok. Nice to meet you. I'm back. We talked already about AI. AI is everywhere. Everybody using it. It's baked into almost everything we do. So that's a no-brainer. I want to skip that slide and talk with you about something else. AI is moving so fast, but as AI adoption accelerates, there is one question, I think, we don't ask enough. Are we building all of this innovation on a secure foundation? Question mark. Because in the rush to move fast and deliver more and build more, many organizations have made a silent trade-off. They've chosen convenience and speed over security. And that choice has created something new, a new attack surface where the most sensitive data lies and where traditional security tools simply can't see. So what does this new attack surface look like? It's not theoretical. It's not a future concern. It's happening right now. We hear it from customers every day, all the time. They ask us questions like, how do I stop my source code from leaking into AI model? How do I know that the AI agent I'm using is not poisoned? How do I protect my AI apps from prompt injection or jailbreaks? Those aren't science fiction scenarios. They are the new front lines of cybersecurity. We've all seen the headlines. Even the biggest tech companies already suffered from data leaks. Some employees, I'm seeing my employees doing it all the time, pasting sensitive data into AI models. But it doesn't stop there. Researchers have shown that a single carefully crafted prompt can hijack an entire AI system, tricking it into ignoring its own safety rules and doing things it was never designed to do. Those aren't isolated mistakes. They are symptoms of a deeper problem, a lack of security at the very core of AI adoption. The role though is starting to wake up. New governance and compliance frameworks taking shape. Take the OS Top 10, for example, by the way, co-authored by members of the prompt team, a framework designed to help organizations embrace the power of AI and find the most critical threats of AI. And luckily, it's not alone. We have also the NIST, AI risk management framework, along with others around the world, helping enterprises build the foundation for responsible secure AI adoption. It's clear now. The world luckily, isn't just excited about AI anymore. It's becoming accountable for it. And it's not just frameworks. Regulators, although it takes them time, they are catching up too. From the EU AI Act to California's new AI law and many others, by the way, on the horizon that I'm familiar with, governments are beginning to set real boundaries around AI can be used. That means security risk and compliance teams now have to answer some really tough questions. Questions like, how do I stop my sensitive data to get into AI application? Which AI applications my employees are using? And most importantly, do I have enough visibility and policies to enforce in place? The good news, I'm not only talking about challenges and problems and issues. We are already solving this. Our AI security problem has helped dozens of organizations around the world to embrace confidently AI. And today, I couldn't be more excited to share some big news with you guys. Prompt security offerings will be available on the SentinelOne price list as early as next week. And thank you, guys. And that includes prompt for employees, prompt for AI code assistance, prompt for homegrown AI applications and prompt for agentic AI. Now we will dive into those. We can start from prompt for employees. That solution gives organizations across the company complete security visibility and governance over how AI tools are being used, empowering employees to use AI safely without slowing them down. And that's the key. Some employees, by the way, and the data shows that are using today more than 50 different AI applications on a weekly basis. That's crazy, often without IT, or security even known. Many of those tools, by design, train on the data they receive, which means that an innocent copy paste can easily become part of the next AI model. That is fueling the rise of shadow AI, in my opinion, quickly becoming one of the most serious threats for enterprise security. It all starts, like always, in security with visibility. You cannot protect what you can see. Prompt instantly detects and monitors every AI tool used across the company, revealing shadow AI, spotlighting the riskiest apps and users, and giving security teams the clarity and confidence to act. Out of the box, it supports more than 15,000 AI applications. Next is data privacy. Prompt automatically prevents data leaks in real time with privacy enforcement. So sensitive information never leaves the organization no matter what tool or prompt is being used. And because security isn't just about control. It's also about education. I'm a huge believer of education. Prompt delivers real-time employee awareness through gentle in context coaching. When someone, when your employee takes an unsafe action, prompt doesn't just block it. It explains why, helping them to learn, to adjust and build safer habits over time. Next, prompt for AI code assistance. With that organization can embrace tools like GitHub Copilot and Cursor and Tab9 and Windsurf, unlocking developer productivity without compromising on data security or compliance. I must tell you, AI code assistant is not a trend. It's a revolution. Gartner predicts that by 2028, 90% of the developer will use AI code assistant, delivering an increase of more than 30% in development velocity. So it's no surprise that this is becoming the benchmark, the baseline for any modern development team. But with that comes a whole new set of challenges. Sensitive data like API keys, secrets, PII can be unintentionally exposed. And in some cases, end up even use the next model behind them, the LLM behind the scenes. And on the other side of the equation, I'm not talking only about the input on the output, AI-generated code can introduce new vulnerabilities and risky dependencies straight into your code base. That's where prompt steps in. It automatically reacts and sanitizes code in real time, preventing the exposure of any sensitive data before it ever leaves the environment, so developers can work faster, safer and with complete confidence. I want to move to prompt for homegrown application, our third use case. There you go. Almost any organization these days is already building some applications, some software powered by AI. Whether it's a simple support chatbot, or a complex AI agent, AI is key for any business to stay relevant and competitive. But like previously, that introduced a whole new set of risks. Things like prompt injection, jailbreak, adversarial attacks, data leaks and many more. Those didn't exist before the age of AI and traditional tools simply not built to handle them. Prompt makes it easy to protect AI apps from all of those threats I've just mentioned. With Prompt, app developers get real-time protection right at run time, and it takes only one single line of code to set up. We also address data protection. If you are building an AI app and connecting it directly with third-party LLMs, we make sure nothing is leaky. Put simply, we ensure your AI apps do not disclose information they aren't supposed to even when prompted to do so, no pun intended. Next is content moderation. We want your AI application to speak only about what they are supposed to speak about. Therefore, Prompt continuously monitors AI outputs to block inappropriate, harmful or off-brand content before it reaches users. This helps preserve trust brand reputation and user safety. And now although this is in early availability, I want to give you a sneak peek into our solution for Agentic AI. Agentic AI, of course, represents a major shift. Those systems no longer just analyze data. They are taking action, powered by the model context protocol aka MCP. Agentic AI can execute tasks, trigger workflows and interact directly with your environment. Prompt for Agentic AI. With Prompt for Agentic AI, organizations gain real-time visibility, risk assessment and control at the machine level. Prompt for Agentic AI is currently in early availability, and we cannot wait to show you more about our MCP gateway. This will be the first comprehensive solution to secure, monitor and govern Agentic AI in real time. Our mission, like I said before, is to help you embrace AI's incredible promise with confidence. We want to give you the tools to innovate boldly, knowing that you have the right partner to secure your AI journey. But don't take our word for it. Customers around the globe are also -- are already embracing AI with the confidence that they are doing so in a secure and compliant way. If you want to get a quick recap of all that I've mentioned today, please make sure to scan the QR code behind me. It will take you straight to a 5-minute overview and demo, and you can schedule some time with us directly. Lastly, I want to make sure that we Prompt with SentinelOne are taking this revolution to the next frontier, securing AI itself. Thank you very much.

Operator

operator
#154

Please welcome Senior Director of Cloud Security, Nick Davis.

Nick Davis

executive
#155

Hello, everybody. All right. Well, there's still some energy left in the day. This is great. The reality of cloud security is changing. Cloud adoption has not stopped. It is still driven by multi-cloud architectures and containerized workloads, even further now driven by generative AI innovation. And the pace of change in that environment is absolutely staggering, as I'm sure you saw from asmr just now. But what we see as exciting attackers see as a new opportunity to exploit our environments. So this ever-changing, ever-expanding attack surface is a real challenge, right? As cloud adoption increases, so does complexity. And with complexity comes issues. I feel like every day, I'm reading a new article about an attack, or breach, that slipped through the cracks. And so as we try to wrap our arms around this cloud security challenge, we also need to face another practical reality, which is that attacks aren't starting in the cloud. You heard Braden talk about this a little bit earlier, but most attacks are starting with a compromised endpoint, or a stolen identity. Attacks are, however, increasingly ending in the cloud. And that makes sense, right? The cloud is where most of your crown jewels live. It's where your critical assets are hosted. And so as threats move laterally from endpoints to identities, up to cloud infrastructure and applications. Treating cloud security as an isolated attack surface just doesn't cut it anymore. To put it more simply, I think you and your teams are caught between two really key challenges. On the one hand, you have an endless backlog of risks to prioritize and fix. And on the other hand, you have attacks that strike with little to no warning and demand immediate response. To meet the first challenge of endless risks, we've built unified exposure management. This is all about an attacker's perspective on your environment so that you can understand a little bit more about what their valuable target is and you can focus on fixing the issues that really matter. Unified exposure management is how we prevent attacks before they ever happen in the first place. The best way to win a fight is to avoid it. But we all in this room know that not every fight is avoidable. Eventually, an attacker can, and will, come knocking. And so that is why we've also built cloud runtime protection. Do you have what it takes to defend your cloud infrastructure in real time against a multitude of threats, known and unknown? We'll come back to that question in a minute. But for now, let's focus a little bit more on exposures. I'm sure none of you in this room have a lack of exposure findings, whether it's vulnerabilities, or misconfigurations or exposed secrets. But I think some of you may have a lack of clarity, a lack of clarity on what to fix and why you should fix it, maybe even how to fix it? So this is why we've unified exposure management across all of the attack surfaces, all the way from the enterprise to the cloud because you need to see how these things work together, and get that attacker's eye view of the landscape to cut off their attack path and to cut off that foothold. So how does this work? I think if I put myself in your shoes, typically, I think a lot of you are working backwards. There's a couple of key questions to ask. And it starts with what is that valuable mission target in an attacker in your environment that attacker is interested in? How might they get access to that target? Where does it live? Let's go back here for a second. There's a second question that you need to answer as well, which is once you know what the mission target is, you have to ask yourself, where is an attacker going to land, right? What is that first foothold, or initial access that they might have in your environment, that they can then launch their campaign against you and find that mission target. So let's work backwards ourselves today. We'll start with mission target. I'm sure some of you can probably guess what the most common mission target is in your environments, but I won't hold you in suspense. It is almost always data. Data has always been valuable to attackers, but today, that is more true than ever before. The value of data is skyrocketing in the age of generative AI. Your organizations are collecting more and more data, and the value and sensitivity of that data is also increasing. So to understand mission target, we need to understand where is my sensitive data stored, how sensitive is it? And how might it be exposed or accessible within the environment? This is why we're super excited to announce data security posture management today. Data security posture management will automatically discover your data stores across all 3 major cloud providers, classify your data and protect it in real time. This continuous protection gives you an always up-to-date understanding of where that data is and how it might be accessible in your environment. And don't worry, I'm not trying to sell you anything new. This is available to all of our CNS Pro customers. It's in beta today and will launch generally available very soon. So that's mission target, the data. But we still have to solve the second half of the problem, which is how might attackers leverage different interconnected vulnerabilities and exposures to reach that mission target. So we also today are announcing Cloud Attack Paths. This will help us close the loop and connect the dots between initial access and mission target. Cloud Attack Paths leverages dynamic graph analysis and advanced analytics to tie together multiple different exposure findings like vulnerabilities and misconfigurations, with multiple different assets and entities across your surfaces. And we can detect both pre-compromise and compromised attack paths so that your teams can investigate and understand the root cause and the blast radius of said attack path quickly and easily. So 2 major new capabilities for cloud security. Let's talk a little bit about how these things work together to allow your security teams to level up and prevent attacks before they can even start. When you enable DSPM, will automatically begin detecting data stores and classifying sensitive data. You'll see that sensitive data in a number of places like in misconfigurations where you can see that a sensitive data S3 bucket doesn't have versioning enabled. You'll also see sensitive data context in the inventory. This is where you'll see a real-time view of all of your data stores, what we've discovered, which ones are being actively protected and which ones we found sensitive data in. When we find that sensitive data, we support a number of different data classifiers out of the box, whether it's social security numbers, credit cards or cryptographic keys. And we'll show you redacted evidence and samples of that sensitive data so you can get an understanding of the shape and breadth of that data in these data stores. Of course, this is also available on your graph. So you can ask questions like show me data stores with sensitive data and what other resources might be related to those data stores. And because all of this is in the graph, we can fully operationalize this mission target context with cloud attack paths. Like I mentioned earlier, cloud attack paths are continuously evaluated, and we can find and detect issues like a publicly accessible EC2 instance leading to sensitive data access in S3. As you can see, we have a publicly accessible EC2 instance with a pretty severe vulnerability. And if an attacker exploits that, they then gain access to an IAM role. And that IAM role will give them access to sensitive data where they can do data exfiltration, ransomware or usually both. Attack paths include remediation steps that you can follow. They also include MITRE TTP mappings. You get both your own internal context and attacker context in one place. So what do I do from here? Well, you can manually follow our remediation guidance to cut off this attack path before it becomes an issue or better yet, leverage hyperautomation to automatically orchestrate response on your behalf. So this is just the beginning of unified exposure management, a proactive approach to stopping critical cloud threats before they ever happen. But no, there is no tall enough wall and there is no deep enough moat. So attackers can and will get in. It is unfortunately today inevitable. This is why protecting those resources and those workloads at run time is equally important. What happens when these attackers get in? They will. This is where cloud workload security takes center stage. We are incredibly proud of our ability to block attacks at run time at machine speed, and we've been working incredibly hard on evolving workload protection over the last year, focusing in 3 main areas: number one, improved correlation. Cloud workload security does not stand alone. We tightly integrate cloud workload security alerts with other security signals from the control plane and from the data plane, leveraging platform detections. This means that you get less noise, more precision, better context-driven alerts. And speaking of alerting, none of that is possible without best-in-class detection engines. We've introduced multiple AI-driven detection engines, everything from behavioral AI to drift detection to help you see what's happening not just at the host, but at the container layer and beyond, again, bringing all of that together. And finally, the absolute foundation of workload protection is performance. These security controls do you know good if you can't deploy them in your environment and if you can't build trust with your infrastructure and application teams. That's why our EBPF-based agent provides maximum protection with minimal resource impact, allowing your applications to run smoothly, while defenses work for you behind the scenes. So let's take a look at what this looks like in practice. Before we do, I do want to tell you a little bit about the future. I'll share more at another time. But just to tease it, right? This space is changing. The attacker landscape is changing, the way attackers are coming after your cloud resources and your applications is changing. And over the last year, we've seen the line between infrastructure and application blur more and more and more. Attackers don't think about the operating system versus the application. Their attacks move seamlessly up and down the stack, whether they start in the application and end at the host or vice versa, it doesn't matter as long as they can get their mission target done. So we're moving to a future where workload protection detects, not just host and container layer activity, but understands your applications, how they behave, how they access data, how they interact with other services, all together in a single pane of glass. The future of cloud workload protection is seamless, intelligent, autonomous defense of the applications themselves, and we're laying the foundation of that today. All right. I'll leave you with one final demo before we switch up the session here a little bit. I'd like to show you workload protection in action. We'll start with a completely fresh console and a vulnerable application. Now if you're anything like me or some of our threat hunt challengers out there, you'll drop a malicious payload into this vulnerable application, and you'll get access to the host, right? We've -- now we've downloaded a malicious script. We've executed on the host. And immediately in SentinelOne, you will see Christmas lights appear. Let's take a quick look at the web shell detection that fired. First and foremost, you'll get immediate Purple AI summary for human readable intelligence. But beyond that, of course, you need all of that cloud and container context, understanding where this happens, what tags might have existed, what the application was running in that Kubernetes deployments and more. On top of just the actual infrastructure and application context, it's important to understand why we thought this was such a terrible threat. That's why we also include for all of our detections, AI-based or otherwise, human readable indicators of exactly what we thought was strange about this activity. And of course, we have our storyline technology, building out a graph of all of the host container and application activity, so you have a full understanding of what's happening in the environment. Now when it comes to investigation, we are incredibly proud that SentinelOne has the best workload telemetry collection on the market, collecting far more raw data for you to use and ask questions of than anyone else, whether it's process, network, file or other types of information, it's available at the tips of your fingers in our cloud scale event search systems. So that's called workload security, but I think you've heard enough from me. Let's hear from people on the front lines who are actively protecting cloud environments every single day. And for that, I'd really like to invite my friend. Jörn and my partner in crime [ Cam ] on to stage to tell us a little bit more.

Unknown Attendee

attendee
#156

Wow, what a great set of keynotes so far.

Unknown Attendee

attendee
#157

Jörn, thank you so much for being here with us today. I've been waiting for this. I can't wait for everyone to hear your insights from the cloud security journey at Schwarz. But I feel like a good place to start is at the top. So can you just share a little bit about yourself and your role at Schwarz?

Unknown Attendee

attendee
#158

Sure. Thanks for having me again. I already explained a bit who am I or who I am. It's Jörn [ Kraft ] being the team leader of Endpoint Application security at the Schwarz Group. Schwarz Group is one of the top retailers in the world. You now see the logo, which is Schwarz Digits. That's kind of our digitalization brand or branch we have. So Schwarz IT is part of that. So we are the internal service provider for the entire Schwarz Group. Yes. Well, my team is 11 people. I already mentioned that earlier, 4 people are full time on protecting our 450,000 endpoints. And yes, that's our team. That's our job, and I'm happy to share some insights today because I hope it's useful for everybody in here just to see what happens in companies, the day. So that's the input I always love about this kind of conventions or conferences.

Unknown Attendee

attendee
#159

Totally to hear it firsthand, and we're going to get into that. So I think Nick gave us a really good backdrop of the cloud security landscape today, the prolific adoption, the increasing complexity, the rapid evolution of attacks and defenses. So with that backdrop, can you just help us understand what is cloud security at Schwartz really like?

Unknown Attendee

attendee
#160

Well, I would start with less a technical thing than an organizational thing. For us, coming from a kind of historically grown enterprise, we had the policy on-prem first. So that was kind of what we did the past years. Cloud was always like, let's see, not yet. But yes, there was a mind shift because, obviously, without cloud, that's not working anymore. So what we did is we started to educate our people, right? Because our mission or our aim is to complete a cloud transition for the entire infrastructure by 2030. So it seems like it's 5 years, but well, it's 5 years only, right? And at the end, we implemented kind of like educational part. So we tried to educate if it's system owners, if it's engineers, if it's employees, which might be responsible for specific software, just to tell them, hey, that's the difference between on-prem, what you know since years and cloud workloads and especially what's the difference about protecting, right? So that was the first thing. And the second thing, what we implemented is kind of a cloud transition teams, which driven internal consultancy for every system owner, which has to do a transition from on-prem to cloud with their applications, right? So that helped to, yes, get people wrapped up. And I think that's the main part about the preparation for a cloud transition before you start technical stuff.

Unknown Attendee

attendee
#161

Yes, absolutely. So a key theme of this cloud session has been that you really do need both unified exposure management and runtime security to secure your entire cloud attack surface end-to-end. So Jörn, what are some of the big initiatives that you're focused on to secure Schwartz's cloud environment end-to-end?

Unknown Attendee

attendee
#162

Yes. Well, technically, we -- it started somewhere else, right? So as soon as somebody announced, hey, we have to do the full cloud transition until -- by 2030, a lot of people were, I would say, concerned, how can we get there? And there was also excitement because a lot of systems or products have been like SaaS-ready or name it. And it happened that system or product owners were going ahead by best means, no harm. So they started to go to the cloud, right? And at a specific point that kind of got a bit tricky at the end because everybody was, as I mentioned, as best means or by best means. So they did whatever they thought is right, right? At the end, we reached a point where that was kind of chaotic. So that was the point where we decided to implement kind of a staging platform, if that makes sense. So if you're a product owner, which wants to order or to install any cloud services. You can go to that platform. It's called One Digital Journey, right, ODJ. So you can go there, you can add any tooling you want. So if it's Azure, if it's GCP, if it's our own public cloud stack. So you can decide what you need or what you obviously need or want. But the way more important thing is that we created a security baseline for that, so a guardrail. So that means every cloud project, which is provisioned by this platform will get predefined set of, if it's specific DevOps tools or if it's security tools. So that was something the security department, cybersecurity and our cloud service teams were deciding what is the baseline. So we just ensure that every single cluster, every single node at the end pops out with what you have defined as a product owner or a system owner, but also the predefined security guardrails, right? So as an example, you deploy Kubernetes nodes for your application. You go there, you click, I want to have that and that service or tooling. And right after it has been provisioned by the cloud service provider, the SentinelOne pots are being automatically deployed by pipeline, right? So rest assured, you can scale whatever you want. You can select whatever you want, but there's always the security measures in place because that was the part where we had a lot of cloud workloads already installed without having a proper protection or different protection thing is installed or provisioned. So that's the core where I see technically, we quite made a good job.

Unknown Attendee

attendee
#163

Yes. What a great story from a company that owns their own public cloud, right? I think other than maybe AI, cloud is the most prolifically adopted technology, at least in my lifetime. And it sounds like at Schwarz, which I'm sure is true for most of you in this room that, that prolific adoption simply led to a lack of security standards across so many silos in your organization. But at Schwarz, you all have addressed that with the One Digital Journey or ODJ program, where you really have centralized and standardized those cloud security controls. But I think what is really brilliant is that process approach that you took because you didn't slow down adoption. And I think that's the balance that everyone in this room that we have to balance every day is there are the security controls, but also making sure we don't get in the way of innovation and adoption. So I appreciate you sharing that. But hey, we're going to get a little more technical for a moment. You're in backstage, you were telling me about the over 3,000 Kubernetes nodes that you currently have deployed with SentinelOne. Can you just help us understand what it's like to manage cloud security or container security at that scale?

Unknown Attendee

attendee
#164

Well, as usual, it's complex. But at the end, having this baseline, I was just talking about that, so to ensure everything comes out of the box at the end, like predefined, that's kind of a main thing. I mentioned earlier in the customer panel that we set a lot of centralization. Even we have like 35 countries and a lot of people who would love to do something, we try always to get their input to get our products better because more people have more knowledge at the end. And yes, that's the point where we started. And I think that's the point where -- that's something we want to keep on, right? So as an example, we plan for 2026, we plan to roll out another additional 15,000 case nodes to our stores. This is because we want to provide edge cloud services there. So talking about that process and talking about security by design, and that's I think everybody wants to achieve here, we have been implemented or included in that design process from the very beginning on, right? So we have a quite of a complex operating system environment. If you talk about case nodes, we have Thales, we have Ubuntu, we have Flatcar. So having a majority, you know which is installed everybody, that really helps. And at the end, that was the point where we have been implemented from the beginning. We designed what kind of Kubernetes nodes will be used there. And yes, they are kicking it off, I think, beginning of next year. And that's quite of an exciting project there. So we love to see security by design. We are praying that for years, and I think there's a lot of players in here in that room for the same purpose. But now that worked out, and that's quite a really good feeling because if they now deploy 5 nodes, 500 nodes or 15,000 nodes, we don't care. At the end, yes, there's more workloads protected. There's more maybe detections also for the SOC side. But from an operational side and from the efforts we have to put in, that's a game changer.

Unknown Attendee

attendee
#165

Diversity and complexity sounds like Kubernetes to me. But hey, we're going to switch gears a little bit and talk about arguably the most important topic in cybersecurity, and that's people. People are the backbone of everything we do in cybersecurity. I think you've heard that a few times today. You're going to hear a few more because it's true. People are the backbone of everything we do in cybersecurity. So Jörn, let's talk about your people. How have your team and the teams you partnered with? How have they responded to the tools and processes that you've implemented?

Unknown Attendee

attendee
#166

Well, for my team, it was a quick win, right? So at the end, it was like cheers, we made it because now my team can focus on the more complex parts like going into troubleshooting for specific issues which might appear. I mean, we are all real-life security guys. So we know there will be, at a specific point, some issues or some performance topics. So we can focus on that besides or instead of chasing any system owners to secure their workloads properly because we have this security baseline. And talking about system owners or yes, system owners, I think everybody can agree here if you deploy security software or any other software in a scale, you will also always run into cost concerns and performance stability concerns, right? Talking about cost concerns, I'm really happy that our management covers our back because at the end, seriously, yes, obviously, if you deploy any additional workload to any kind of system that will increase resource usage, and talking about cloud workloads, yes, that will increase costs. So there's no discussion, right? So they need to charge it to customers. If I now talk about customers, I talk about internal customers, so the customers which are consuming that services. So we have that kind of agreement and back up from the management. Talking about system owners and performance concerns or stability concerns, I don't know how many hours we spent upfront when we had this situation where we had existing cloud workloads, which has not been protected by what I just mentioned, our baselining. And then it comes to, hey, there's a deadline, we need to deploy the SentinelOne protection on your workloads until then. They were like what to do. But I think there's a point, and we adopted that from our legacy environment. So we kind of joined forces. We are not working security versus product owner or system owner. We work together. We are kind of consultants for them. We tell them, hey, you have a test stage, you have a queue stage. Well, test stage might not reflect one-on-one what happens in production. But I think the broad environment, having a test stage is very useful and required. So we went into that discussion, we were consulting them. We were just teaming up with them. And then we were able to show, okay, test stage worked, go for productive first stage, whatever, how many stage that are -- that those are. And yes, at the end, it turned out that our initial rollout, I think it was 800 nodes at that time. It worked out nearly flawlessly, so -- and that's a big benefit.

Unknown Attendee

attendee
#167

Awesome. Now Jörn, I got one more question for you. We're having this conversation a year from now. I'm talking with future you, future Jörn. What does current Jörn, hope future Jörn says about cloud security at Schwarz?

Unknown Attendee

attendee
#168

Well, if I start to talk to myself within the next year, I would go for, first of all, talking about that 15,000 and some more because there are other projects, additional Kubernetes workloads or nodes we want to deploy. I would be very happy if we could keep our pace. So go fast, having the stability we have and still don't lose the agility like you mentioned earlier, right? So that would be a top point of what I would -- what would make me happy and everybody else. The second part would -- and we saw a lot of great keynotes today about AI. We definitely should be able to protect advanced workloads a bit more or not more, we need to protect them. We need to go forward. And I think the third point would be and that's kind of -- should not be an advertisement, but, well, as we mentioned, we run our own public cloud, so the Sovereign European Cloud. So -- and that was the announcement with SentinelOne and Schwarz recently in August, I think, that we joined forces. We have a great partnership there. So -- and the aim is to provide all those security services we like adopted for ourselves, but also provide them to potential SentinelOne customers, stacked customers out there. So spreading the security thought and spreading the security itself also to our customers, external customers. That's it.

Unknown Attendee

attendee
#169

Jörn, I think this conversation and your insights have really brought to life everything that Nick covered, the importance of exposure management, of course, the importance of runtime security. But I think you really highlighted how you've been able to achieve that with the partnership with SentinelOne. So again, Jörn, thank you so much.

Unknown Attendee

attendee
#170

Thank you for having me, and was blessed to be here, and the entire event is really, really great. So thank you for that opportunity.

Unknown Attendee

attendee
#171

Awesome. Thank you.

Unknown Attendee

attendee
#172

Thank you.

Unknown Executive

executive
#173

Okay. Can we get one more big round of applause for Jörn, please? Okay. It is really not every day that you get to hear from a security leader responsible for securing their own cloud provider. I think that is pretty cool. All right. I'm not going to keep you very much longer. I want to wrap this up. But I do want to bring this back to sort of our key themes from the day, right? It's been a long day, and I just want to remind us about this. We've talked about a lot of stuff today, exposure management, runtime security. And really, unified exposure management is about complete attack surface protection, end-to-end regardless of if it comes from the enterprise, or the cloud, where it starts and where it ends, we want to provide complete protection. And the only way for us to do that is to harness data, AI and automation, whether it's finding sensitive data in your environment or computing attack paths, these are our core capabilities. And of course, humans are at the center of everything that we do, like you've heard time and time again this week. It is SentinelOne's human expertise that enables us to build the products that we do to protect your environments. And most importantly, it is you, the humans that our platform aims to enable and aims to protect. So with that, I want to say thank you. And I want to say that we've saved the absolute best for last. I would love to invite my friends and our threat services leader to the stage, Hackim Farrell.

Hackim Farrell

attendee
#174

Good afternoon, beautiful people. So I think the word on the street is we announced some pretty cool services this morning, right? This morning, we heard from Steve how the threat landscape continues to accelerate. We also heard how AI is redefining the playbook for adversaries and defenders alike. But here's the truth. The challenge has evolved. The tools that once kept us safe are no longer enough. At SentinelOne, we have an unmatched approach to protection. So customers cannot only stay ahead of adversaries today, but also into the future. Our ethos is clear. True resilience comes from when you fuse the best of threat intelligence, AI and human expertise. That's why today, we are launching Wayfinder Threat Detection & Response. Thank you. Thank you. So Wayfinder is the next generation of services that delivers proactive, adaptive defense so that every organization can stay ahead of modern adversaries so that they can move faster, see farther and act smarter against modern threats. These new services are a manifestation of our mission here at SentinelOne. In every service level, customers get the benefit of comprehensive threat intelligence, the power of Purple AI and our human experts around the globe. This combination gives you the strategic advantage of not only eliminating blind spots, but also reducing the noise, transforming your organizations from reactive firefighting to proactive adaptive defense. This is the future of resilient, effective threat management amidst relentless change. These new services. So let's dive deeper into these new services, starting with threat intelligence. First, we know the attackers are not standing still, right? The threat landscape continues to evolve at record speed. Now defenders need threat intelligence that is relevant and ready for action. That's why our partnership with Google is such an absolute game changer. Let's take a closer look at how this sets the foundation for a new standard of threat intelligence. This new standard is what we call Applied Intelligence. It's not about more feeds, it's about speed of actionable insights. Unlike legacy vendors that bolt-on feeds to their platform. At SentinelOne, we bring this to life. Google Threat Intelligence provides SentinelOne with access to Google's unrivaled global visibility. We're not overwhelming teams with low fidelity signals. Every indicator of compromise is jointly vetted and validated by SentinelOne experts and Google Threat researchers alike. Automation ensures that intelligence moves at the pace of attackers, but every signal is checked before it enters our customers' environments. Together, this trusted partnership closes critical gaps that others will simply miss. The spectrum of opportunistic cyber criminals to complex nation-state actors like PurpleHaze is just too complex for any single source. This multifaceted approach that we have taken of combining multisource intel with the richest in SentinelOne Telemetry is what makes a difference. We're talking about open-source intelligence, SentinelLABS forward leaning research, feedback from our customers and partners. This is what exposes adversary tactics that others will simply miss. This is what helps those organizations move from reactive to proactive, reducing alert fatigue and strengthening their security posture. With Wayfinder Threat Detection & Response, we've integrated Google Threat Intelligence in every one of our MDR tiers, which means organizations get access to Google's unmatched global visibility. Every Wayfinder customer benefits from the full force of world-class threat intelligence and expertise at scale. Threat intelligence for us sits at the core of our Wayfinder services. Still, we know intelligence alone is not enough. It's how we bring it to life with AI and human expertise that makes a difference. Warwick, why don't you take us through how SentinelOne differentiates itself in this area?

Warwick Webb

attendee
#175

Good afternoon. That's right. So my name is Warwick Webb. I lead Managed Detection & Response Services here at SentinelOne. The core mission of our team is to detect and respond to evil. It's as simple as that. But how do we deliver on this commitment to our customers? Well, it starts with detecting attacks early in the kill chain. Our MDR team leverages the advanced threat detection capabilities of the Singularity platform. Singularity endpoint, identity and cloud workload protection, along with detection coverage for third-party identity providers, cloud service providers, e-mail security platforms and network infrastructure. But we're not just reacting to alerts. We are proactively hunting for emerging threats and new and novel attack techniques powered by the latest Google and SentinelOne Threat Intelligence. And those hunt findings are all surfaced directly within the Singularity platform, enriched with all the latest threat intelligence so that our experts and your team have the context they need to make informed decisions. So that's Wayfinder Threat Detection. But we don't just detect threats on behalf of our customers. Our MDR team leverages the full power of the Singularity platform to respond at machine speed. Our AI and hyperautomation delivers scale. Wayfinder hyperautomation workflows automatically respond to alerts that don't require human attention. Meanwhile, Purple AI contextualizes and summarizes the remaining alerts in real time, making sure that our defenders get actionable insights fast. From there, our experts step in. They provide oversight and guidance. They review and validate the analysis performed by Purple AI, dive deeper as needed and perform the necessary containment and remediation actions to protect our customers. It really is a virtuous cycle, right? The actions performed by our analysts serve as valuable training data for our AI models, which in turn, service force multipliers for our human experts. Now I've talked a little bit about our always-on managed threat hunting and managed detection and response services. But we also have a world-class incident readiness and response team that is there for you when you need the most, leading the response to complex cyber attacks, performing detailed forensic investigations and delivering comprehensive incident reporting, including root cause analysis and lessons learned. So with that in mind, it's important to note that, that same team also partners with your organization to ensure that they are battle-tested and ready for action with a wide range of breach readiness services from incident response workshops to attack simulation exercises. But now let's talk a little bit about the people that are powering Wayfinder. Our global team delivers security expertise at scale to thousands of organizations from small businesses and schools to large enterprises and government agencies. Whether it's threat research, hunting or rapid response, we are the first in and the last out. Our SentinelLABS team is on the bleeding edge of threat research, identifying new and novel attack techniques in order to accelerate our detection and response capabilities. Our hunters, analysts and investigators are delivering 24/7 threat detection and response across all modern attack surfaces. Our threat advisers partner closely with our customers from initial onboarding to ongoing engagement and guidance. And of course, our IRR team is there when you need the most. Together, this global team of experts, combined with the power of the Singularity platform, provide organizations with a full turnkey detection and response program from a single trusted partner. So what is this? The best part about this? You have an elite team of practitioners available to your organization as a core capability of the Singularity platform. So what does that mean for you? First, turnkey onboarding. Traditional managed service providers can take days or even weeks to onboard, not Wayfinder. Our service is up and running in just a few clicks within the Singularity platform. No rules to tune, no threat intelligence feeds to integrate, just to find your notification preferences and authorized response actions. And you've got a 24/7 team up and running protecting your environment. Second, transparency and context. Our Wayfinder services are not a black box. Our threat hunting dashboards provide details of IOCs and TTPs that we are actively hunting for in your environment. And our MDR dashboard provides full visibility into all the work performed by our analysts, including all alerts actioned and all incidents responded to, along with our performance on key service level objectives. And finally, extended visibility across the modern enterprise. Our team leverages Singularity endpoint, identity and cloud workload protection. But as you integrate additional telemetry with the SentinelOne platform, our team leverages that additional visibility to more effectively detect and respond to threats on your behalf. Look, we believe that effective defense and depth requires advanced technology paired with human expertise. AI and curated threat intelligence delivers scale and speed. but it's the collaboration and partnership of human experts that turns great technology into meaningful security outcomes. But don't just take my word for it. Let's hear from Sara Griffith, CISO of Euronet on how her team partners with us to stay one step ahead of adversaries. Welcome. Great. So Sara, thank you for being here.

Sara Griffith

attendee
#176

Thanks for having me.

Warwick Webb

attendee
#177

Maybe we can start just if you could share a little bit about Euronet. I mean even for those who aren't familiar maybe with the name, it's likely that you've probably like made it easier for them to make a purchase or perform some other financial transaction.

Sara Griffith

attendee
#178

Perfect. So I'm Sara Griffith. I've actually been with Euronet for 20 years. So what we are, we're a publicly-traded financial transaction processing company and global payments processor. So we have 190 entities that we own and we have offices in 50 countries. We operate in 200 countries globally, but 90% of our 12,000 employees are outside the U.S. So we serve consumers, banks, fintechs and some governments. So we do everything from ATM transaction processing. We run ATMs for hundreds of banks. We also do debit and credit card processing, POS transaction processing, or money transfer processing, digital wallets, you name it. So a lot.

Warwick Webb

attendee
#179

Sounds pretty important. Well, look, my first question I want to ask you is that when -- I know you've been a partner of ours for several years. And when Euronet was first evaluating SentinelOne, I know you looked at both our products, but also our services. And I'm just curious why it was important to you to really evaluate both of these areas together and why you ended up selecting SentinelOne?

Sara Griffith

attendee
#180

Sure. So at Euronet, we have a pretty rigorous evaluation process when we're looking at new vendors or even major renewals. And we -- our team set all the criteria because as most of you know, there's thousands of vendors out there. And we set a bunch of criteria. We want to look at who are the vendors in the space, who's innovative. What -- we had some things we were missing from our prior MDR vendors. And so we set that and one thing that was a nonnegotiable is we had to have managed services. I mean that was some -- not only did we want that 24/7 support to support us globally all over the world, but we also -- obviously, the detection capabilities and aperture of what you guys are looking at is extremely critical to us. But we also wanted a managed services team that wasn't outsourced. I know there were some vendors that use outsourcing and maybe those teams were looking at CrowdStrike and SentinelOne and various platforms and they weren't -- we didn't know if they were going to learn our environment or know the tool really well to dig into alerts. So that was important for us. But in the end, we chose SentinelOne, the user interface, obviously, the telemetry, the visibility to that and the alerts, reporting, filtering, et cetera. So I guess when we also nerted it down to our top 2 prospects when we were looking at SentinelOne, they scored the highest we did ethical hacking on the efficacy of what they were detecting, which was -- that was probably the #1 thing for us. But yes, and in the past, like several people have said, everything was a black box. So we were hoping those vendors in the past were looking at our most critical alerts. But even with one of them, we knew some alerts have been changing or going down and we questioned what's your aperture. They had been bought out by someone and they admitted to us their aperture had changed. And -- but we couldn't see that. We couldn't see what they were looking at. So it was critical to us to have that visibility.

Warwick Webb

attendee
#181

And that's such an important point, and it's something that I talked about a few minutes ago. We really see transparency as a prerequisite for trust, right, which is why with our managed services, you can see everything that our analysts are doing. And I'm just curious from your perspective, how has that visibility really helped you kind of -- you and your team gain confidence in the work that we're doing your behalf?

Sara Griffith

attendee
#182

Yes. I mean it's huge. I mean we've gained -- our team gained trust with SentinelOne and our employees over the years. But obviously, we love the user interface and the capabilities and transparencies, but it was better than any prior vendor we had. Like I said, we could see what your team was doing. We could see what they're looking at. We could see the notes in the platform. If the managed services team escalated stuff to our teams or depending on different escalation layers like you mentioned, we could see and communicate with them and open cases if we need to or at least have that visibility. So to us, that was key. Like I said in the past, we just relied on we hoped they were looking at everything that was critical, but now we can actually see it in the platform. So that was big. And the 24/7 eyes on alerting, I think for me, and I can speak for all of our technical security team around the globe, we don't have that expertise. And we don't know the platform as well as you guys know it. So that helps us sleep better at night, knowing there's eyes on in addition to the AI and everything working in the background, looking at these alerts and helping us prioritize what do we need to focus on or prioritize or contain, et cetera, if it wasn't automated.

Warwick Webb

attendee
#183

That's great. So you also have a dedicated threat adviser from SentinelOne that meets regularly with your team, providing regular updates on service delivery, operational metrics, briefings on emerging threats. How does that sort of ongoing engagement really improve the effectiveness of our partnership?

Sara Griffith

attendee
#184

Yes. I mean, at least for me, when I'm not -- I used to be in the beginning, the first few years involved in the day-to-day alerting and implementation and everything. But even when we would have to go -- we'd have our executive team asking or the Board, I mean, having that communication with your team at least on a monthly basis, that gives us the summaries that we used to have to go pull down Excel spreadsheets and look at what alerts we were getting from prior vendors and try to analyze that ourselves. Now we have all of that summarized for us by SentinelOne, nice dashboards. We can take that and discuss it, whether it's myself with executives or the Board, but -- or our teams that are in different geographic locations or in different business segments, they can discuss it with management. What are we seeing there? So is this something affecting just this geography or this entity or what kind of malware are we getting? Why are we getting targeted? But also from the managed services team, they also educate us on here's other threats or emerging threats we're seeing around the globe, not just at Euronet. So that's really important for us, and it's been really valuable. So...

Warwick Webb

attendee
#185

Right. Great. Well, and we've talked a lot about threat detection and response. But breach readiness is also critical, right? Left of boom, being ready. And I know that our incident readiness and response team has had the opportunity to perform several breach readiness exercises with your team at Euronet. So just curious about your experience with those engagements and how they've really helped prepare your team for whatever comes next.

Sara Griffith

attendee
#186

Sure. So I'll call it [ DFR ] , I don't know. But since we've had our contract, we had these [ DFR ] hours that obviously are there for forensics or incident response and knock on wood, if you don't need it. There are these ancillary services that the [ DFR ] team provided that we've taken advantage of for sure. So typically, you'd have to pay a third party, but we, for instance, had them review our global incident response plan, go through it in detail, tell us -- they're the experts in incident response. Are we missing anything? Is there anything in our workflows or our processes that we should enhance or improve? So we've used them for that. Even more recently, about a year ago, those of you that are publicly traded know this, but the SEC has new cybersecurity disclosure requirements. So we even took a addendum where we had our legal team and help draft part of that instant response plan. And we wanted to make sure, hey, can you look at this and tell us, do you think we're addressing everything that we would need for instant response to address the SEC requirements. So that was the service we also used. I know our technical teams have also done some playbooks and instant response tabletop exercises, which is always beneficial, and you always learn a lot, and it's good to have a third party do that. And even if you go with cyber insurance renewals, that's also something that always comes up you. Your breach readiness, have you done tabletop exercises. So those are just some of the services we've used that have been very beneficial. And typically, you might have to go pay a third party for and if you're not using their forensics, at least you have these other services you can use.

Warwick Webb

attendee
#187

Fantastic. Well, we've talked a lot about our partnership as it pertains to threat detection and response and services. But obviously, Euronet's relationship with SentinelOne extends far beyond that. So I'm just curious in your experience, how would you describe your overall partnership with SentinelOne over the years?

Sara Griffith

attendee
#188

Sure. And I'm not saying this because I'm sitting up here, I'm not getting paid for this. But I mean, honestly, SentinelOne has never wavered at all in consistently building their relationship with me and others on the team. A lot of vendors or your sales team or sales engineers, they get you to sign the contract and then they pass you over the implementation team, and you might hear from them again at renewal. And I can -- shout out to Justin and Stuart if they're in the room. But over the last 4 years, they're consistently staying in touch, seeing how we're doing. They attend some of our customer success calls. We have these biweekly calls with the customer success team. We have the monthly calls with the managed services team. And I think everyone just goes out of their way to build that trust and relationship with us, and that's not the norm. I mean I think most CISOs probably know some vendors a little better, some you never hear from once you buy their product. So I would say it definitely goes above and beyond what a lot of vendors in cybersecurity do. So we really appreciate it. And I know at one point, there was a -- your regional sales director when he would meet with me at a meeting or something or run into me and we'd have a meeting, I always got a personal e-mail from him with follow-up steps and everything that we addressed and anything that we are asking for enhancements and just a personal e-mail, which that's huge. You don't see that a lot. And you have opportunities to meet with Tomer or your product development leads at Black Hat or RSA, and they really listen to our feedback and they've taken our suggestions, and I know we've even talked about. So we appreciate that. And when you're looking for a long-term partner in a vendor, that's really important. Those relationships are key. So I'm not just saying that you guys really do an excellent job, and it's been a great relationship.

Warwick Webb

attendee
#189

Well, we're humbled by that feedback. We definitely don't take it for granted, and we're going to continue to really work to keep and earn your trust every day. So thank you so much, Sara, for coming up here to talk today. Appreciate it. All right.

Sara Griffith

attendee
#190

Yes, thank you.

Unknown Executive

executive
#191

All right. Thank you, Warwick, and thank you so much, Sara, for joining us on stage. Let's give them another round of applause. So as we face another inflection point in the threat landscape, we're challenged to evolve our defenses to be even faster, smarter and be relentlessly focused on reducing complexity. The great thing is you don't have to face these challenges alone. We're with you, protecting every attack surface from endpoint to cloud to identity to data, closing critical gaps before they are found. We will supercharge your organization with industry-leading tools like our threat intelligence partnership, AI and automation. Data gives us insights. AI will provide us scale and automation will give us the speed to act, giving you the advantage over your adversaries each and every time. Now most importantly, whilst technology may power our defenses, it's our people, our analysts, our hunters, our responders, our partners, that bring human expertise. Together, these set the foundation for resilient defense, comprehensive protection, intelligent automation and human mastery. With Wayfinder threat detection and response, we paved the way for modern security. Now let's redefine what's possible together. Thank you.

Unknown Attendee

attendee
#192

And now welcome back Chief Product Officer, Ely Kahn.

Ely Kahn

executive
#193

What a journey. You all made it. Thank you for staying here for us. Over the last 2 hours, we've covered every frontier from endpoint to cloud, from AI-powered defense to managed response. And through it all, there was one truth that stood out, SentinelOne is redefining what it means to defend in the age of AI. And to recap, this morning, we started out with how things are changing in the age of AI. Adversaries are moving at machine speed and new AI attack services are appearing overnight. And just to showcase how quickly things are changing, I've been sitting in backstage for the last couple of hours going through Slacks and e-mails. And our friends at Google Threat Intelligence just published a blog while we're all sitting here, talking about a new strain of malware called Prompt flux that calls the Gemini, Google Gemini APIs every hour to fully rewrite its code. Polymorphic malware is here. The future is now. But then we went through endpoint identity security, and Braden showed us the unified vision, one agent, one platform, one AI brain to protect both devices and users. Nick then walked us through cloud security innovations and showed us some of the new features launching today, Cloud Attack Paths and Data Security Posture Management. The key message is that with this new visibility in analytics, we can help you stop breaches before they start by giving you an attacker's eye view into your cloud environment. All right. Then Adriana and Carter pulled back the curtain on autonomous security. They showed us that autonomous security is not some far off distant vision or future. It's here now. With AI SIEM plus Purple AI plus hyperautomation, today, we can offer you faster detection, faster investigations and automated remediations. And then Itamar showed how we're securing the next frontier, AI itself. Prompt security is the most comprehensive platform for both securing AI systems and securing the data that goes into them. This means that we're ensuring that AI for security is also coupled with security for AI. Finally, Hack and Warwick brought it home. They showed us the new Wayfinder threat detection and response service. It's really a fusion of 3 things: Google Threat Intelligence; Agentic AI capabilities; plus human expertise and judgment. That's the key partnership in the age of AI, machine precision guided by human wisdom. And you can see here with SentinelOne, you don't just get tools, you get teammates. So to summarize, across all these stories today, the pattern is clear. With SentinelOne, we will protect every service, endpoint, identity, cloud and AI. We will harness AI data automation to outpace adversaries and we'll empower people because human expertise is still the core of cybersecurity. That's the singularity difference, technology that learns, adapts and acts, powered by people who care, think and create. So as I leave you here today, remember this, please. The age of AI does not belong to attackers. It belongs to defenders bold enough to innovate faster. Every attack you stop, every risk you contain, that is our shared purpose. And together, we're proving AI can protect the future. So thank you. Thank you so much for being part of OneCon 2025, and thank you for trusting SentinelOne with your business. Enjoy the rest of the conference and keep defending boldly. Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete SentinelOne, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to SentinelOne, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.