Tanium sees the central security problem of the agentic AI era as one of visibility and speed: Enterprises can’t defend what they can’t see, and they can’t match machine-speed attacks with delayed, fragmented decisions.
Brandon Wolfe, Global Field CTO at Tanium, says the weaknesses begin in familiar places: unmanaged endpoints, separate IT and security systems, stale data, and patching processes built around fixed schedules. In this conversation with Frontier Enterprise, he explains what must change before enterprises can respond to agentic threats at the necessary speed.
Before adopting AI, how should enterprises address the endpoint visibility gaps identified by Tanium’s research?
I think Asia-Pacific is actually doing better than the global average. We conducted research in which 43% of IT leaders in the region said they believed they lacked visibility into about 10% of their estate. That could include unknown devices or completely unmanaged endpoints.
What has really happened, especially over the past few years, is a sprawl in where devices are located and who has oversight of them. Traditionally, many devices were on corporate networks. Organisations had data centres, and they knew their networks and subnets. Now, however, many more employees are working remotely, and organisations have more offices around the world. The issue is the expanded reach of where devices are located and the number of devices involved.
Traditionally, organisations used a hub-and-spoke approach, setting up servers to monitor specific networks. I think that model has been completely broken. The reality is that every organisation, no matter how secure, may have devices that people brought in without registering them with IT. These devices are sitting on the network and may not be malicious. However, we regularly see IoT devices and other devices without a traditional operating system sitting in a supply cupboard somewhere.
There’s also a big breakdown between the different management systems that teams use. Devices fall between the cracks, which is a major problem across IT operations, security operations, and the various operating systems involved.
One team might manage the laptop estate, while another looks after OT and IoT devices. Then there are Chromebooks, Apple devices, Macs, Windows devices, and their different versions, all distributed among the teams responsible for them.
Devices consequently fall between those teams. Nobody has visibility or ownership of them, and they effectively don’t exist to the company until they’re attacked.
As the network perimeter disappears, how should CIOs improve visibility across IoT and other devices?
The number one objective should be to consolidate visibility. Most organisations have five, 10, or 20 different teams managing different devices. They’re using different tools and platforms, and they often try to stitch these systems together, saying, “We’re going to have some sort of dashboard where we can see everything.”
However, the data still resides in multiple systems. The only way to achieve central visibility is to bring that data together, including information about devices that don’t traditionally sit in a configuration management database (CMDB).
I mention CMDBs because CIOs often think of them as where their estate lives. Anyone who has worked with a CMDB can tell you this. Personally, I can count on zero fingers the number of CIOs who have told me, “Our CMDB is complete, perfect, and great.”
CMDBs often cover laptops, desktops, and other traditional endpoints with operating systems that can be managed. Only recently have OT and IoT devices begun to be included.
Most CIOs, therefore, start with an incomplete picture, even when they’re working towards a complete CMDB. It’s important to consolidate visibility through a single platform rather than trying to piece together multiple platforms in one dashboard.
How has the agentic AI era affected patching?
The idea of Patch Tuesday is gone. Any organisation still relying on it exposes itself by signalling that it patches on a predictable schedule. Even weekly patching is no longer enough. The priority for an organisation is to be able to patch all its systems immediately.
This requires both the CIO and CISO because, traditionally, deciding what needs to be patched falls under the CISO’s purview, while determining how to patch it moves to the CIO. IT teams handle the patches, while security teams identify what needs to be patched.
This division has created communication gaps, with the teams using different tools and systems. The ability to patch is often not an intent problem but a decision-making problem because nobody wants to make the wrong decision.
Organisations know what they need to patch, but uncertainty about deploying those patches causes hesitation, and that hesitation leaves them exposed.
The only way to get ahead is to match agentic attacks with an agentic defence. As soon as patches become available, organisations should start deploying them, focusing on critical systems and high-risk edge infrastructure.
Microsoft, for example, pioneered Patch Tuesday but now releases patches daily and weekly. Organisations need to be able to deploy those patches as they become available.
Many organisations intend to stay ahead of the patching schedule. In reality, however, their patching systems rely on stale data and are inefficient and ineffective at deploying patches.
There should be a human in the loop to provide oversight and make corrections, but patching should be continuous. The moment agents on a system detect an anomaly or vulnerability, the relevant system should be patched immediately.
Ten years ago, the time between the disclosure of a vulnerability and its exploitation was around two months. Last year, it had fallen to about 25 days. This year, as of a few weeks ago, it was negative seven days.
Vulnerabilities were being exploited seven days before they were publicly disclosed, meaning attackers could already be inside by the time organisations became aware of an exploit. The only way to respond is to have agents on systems that can operate at the same speed, removing potential exposure before attackers have an opportunity to get in.
Why is patching often ineffective?
I think there is both a technology problem and a business problem. On the business side, the patching process often flows through multiple teams that use different systems and look at different data.
Some of that data may be near real time, while some may be days or weeks old. Disagreement over which data is correct creates hesitation, preventing people from taking action.
From a technology standpoint, the proliferation of different endpoints puts considerable pressure on organisations’ patching processes. Fifteen years ago, Windows was the predominant operating system, and managing Windows servers and laptops was much easier.
MacBooks were then introduced into the environment, followed by Chromebooks, mobile devices, IoT, and OT, leaving organisations with many different operating systems. Few patching tools or platforms can manage all these endpoints, so an organisation may have 10 teams managing 10 operating systems.
Some of those tools may work well, while others may rely on 10-year-old technology that wasn’t designed for the number of devices in use today.
Delivering patches is also difficult when people are working through remote networks or travelling. Many systems were built to patch devices on a corporate network, which no longer reflects where people work today.
How must enterprise security change in the agentic AI era?
I think agentic security has been democratised. Frontier models can be used by anyone, from good actors trying to defend systems to rogue nation-states.
An individual can now do in a couple of hours on a Chromebook what would previously have taken 40 people two months. There’s no putting that genie back in the bottle.
As the sports analogy goes, the best offence is a good defence. The only way to counter the speed of agentic attacks is to operate at the same speed on the defensive side.
How should enterprises rethink security when frontier models view IT infrastructure as a whole?
I think organisations ultimately need to focus on governance. Air-gapping everything can only provide so much protection, and adding complexity to these systems can introduce more risk.
Traditionally, IT and security have operated as separate departments under a CIO and CISO, with different budgets, priorities, and performance metrics. They now need to be approached as a single entity, which is how Tanium operates.
Whether someone works in IT, security, operations, or vulnerability hunting, everyone needs to use the same data and have access to the same workflow actions because these activities often cross team boundaries.
Organisations can respond effectively only by breaking down communication and technology barriers and giving everyone access to a real-time source of data. Adversaries already view the infrastructure as a whole rather than as a collection of separate systems.
Click Here For The Original Source.




