
Fighting Fire with Fire: How CyberProof Is Automating Cyber Defense with Edy Almer
Cybersecurity has spent the last decade getting better at telling teams something is wrong. The next fight is getting AI to actually do something about it. In this episode, host John Richards talks with Edy Almer, CPO and VP of Product at CyberProof, about the shift from AI-assisted detection to AI-driven response, and why the biggest obstacle to full automation isn't the technology anymore — it's convincing organizations to trust it.Racing an Attacker That Doesn't Think Like OneEdy has spent his career across nearly every layer of the security stack — from endpoint at Symantec, to network policy at AlgoSec, to SIEM at LogPoint — before landing at a service provider willing to go all-in on agentic AI. That vantage point matters: a single enterprise sees its own incidents, but a provider like CyberProof sees patterns across dozens of large customers, which is exactly the kind of volume agentic tools need to prove themselves fast.The real work, Edy explains, hasn't been proving the models are accurate — CyberProof's internal harness moved past hallucination risk early. It's building a tiered system that decides, case by case, whether a response runs fully automatically, end-to-end agentically, or agentically with a human closing the loop. That tiering is what lets CyberProof push toward near-total automation — currently around 96–97% — without asking risk-averse customers to hand over the keys all at once.The conversation also digs into how AI is changing the attacks themselves. Drawing on Anthropic's research into misuse of its own models, Edy describes a shift away from the linear, traceable kill chains security teams are trained to detect, toward noisy, parallel, autonomous attack attempts that try many paths at once. Defending against that, he argues, means CyberProof has to automate its own defenses at the same speed and scale attackers are starting to use.Questions We Answer in This EpisodeWhy is organizational trust, not AI accuracy, the real bottleneck to automating security response?How does CyberProof decide when an incident gets full automation versus a human in the loop?What makes AI-driven attacks fundamentally different from traditional, human-led ones?How close is a modern SOC to running fully autonomously?Key TakeawaysAgentic security works best as a tiered system, matching full automation, agentic-plus-human-handoff, and human-led response to each customer's risk tolerance.The technology is often ready before the organization is; getting IT, legal, and executive sign-off is now the slower step.AI-generated attacks run multiple parallel, non-linear paths instead of one traceable chain, which breaks detection built around tracking a single attacker's steps.Public benchmarks aren't enough to validate agentic tools; CyberProof tests continuously against its own live customer use cases instead.As agentic AI keeps closing the gap between detection and response, the organizations that get ahead won't just be the ones with the best models — they'll be the ones that figure out how to trust them. Edy's take offers a clear-eyed look at what that actually takes.ResourcesEdy Almer on LinkedInLearn more about CyberProof's Agentic MXDRCyberProofLearn more about Paladin CloudGot a question? Ask us here! (00:00) - Welcome to Cyber Sentries (01:13) - Meet Edy Almer (01:37) - Edy’s Cybersecurity Journey (04:20) - The Landscape (07:53) - Adjusting to Improvements (10:46) - Elements to Be Aware of (13:43) - Big Gaps (22:33) - Attack Simulations (24:00) - What’s Next (27:10) - Stories Used (31:13) - Wrap Up














