SecurityWeek Interview Examines Governance Gaps and Agentic AI in Cybersecurity

A new SecurityWeek video interview explores whether cybersecurity governance and compliance practices are keeping pace with the rapid adoption of artificial intelligence, particularly systems capable...

A new SecurityWeek video interview explores whether cybersecurity governance and compliance practices are keeping pace with the rapid adoption of artificial intelligence, particularly systems capable of acting autonomously on behalf of security teams.

Brian “SchleiF” Schleifer speaks with Clint Bodungen, Arcovo’s director of AI/ML engineering and the founder of ThreatGen. Bodungen, who has focused extensively on industrial cybersecurity, discusses how security practices have changed over the past 20 years and why organizational processes frequently fail to reflect the realities faced by practitioners.

One theme of the conversation is the continuing importance of human behavior. Although emerging technologies introduce new risks and capabilities, the interview argues that people, rather than software alone, remain a central factor in many security failures. The discussion also considers how governance models can become disconnected from operational needs, potentially limiting the effectiveness of security and compliance programs.

MindStone Agent project

Bodungen also provides details about the MindStone Agent, an open-source agentic artificial intelligence project. According to the interview, the project is intended to give AI assistants persistent memory, an identifiable context, and continuity across interactions. These features are designed to support more consistent behavior than systems that treat each session as isolated.

The interview presents the project as an example of how agentic AI could extend beyond simple question-and-answer use cases. At the same time, persistent memory and autonomous action raise governance, identity, oversight, and security questions that organizations will need to address before deploying such systems broadly.

Ransomware response example

The discussion concludes with a real-world ransomware response scenario in which autonomous AI agents reportedly helped coordinate incident response, forensic work, recovery activities, and infrastructure migration with limited human involvement. The example illustrates the potential for agentic systems to assist with complex, time-sensitive operations, while also underscoring the need for appropriate controls and human accountability.

The full conversation is available through SecurityWeek TV and is promoted alongside the publication’s industrial cybersecurity conference programming.