Cisco and Splunk Unveil 'Recursive Security' AI-Powered Defense Approach
Cisco and Splunk are collaborating on 'recursive security,' an approach where offensive and defensive AI agents continuously test, evaluate, and improve security controls. Recursive security is based on the idea that defenders can improve their systems by learning from attackers.
Sunil Potti, Cisco's Senior Vice President and General Manager of Security, Observability, and Data Platform, explained the concept during an interview at Splunk's .conf26 conference in Denver. He described recursive security as 'the next phase of security' and emphasized its potential to improve defenses by compressing the time it takes for security teams to learn from incidents and implement improvements.
The idea is that defenders can build a continuous cycle of testing, evaluation, and improvement into their systems, similar to how attackers continually adapt and evolve. This approach would involve creating a feedback loop where defensive agents investigate and respond to authorized tests, and then use the results to inform future improvements.
For this to work effectively, Potti emphasized the importance of observability in security systems. Observability refers to the ability to monitor agent behavior, outcomes, tools, memory, and multi-agent interactions across development and production environments. This information would help identify weaknesses in defenses and provide valuable insights for improvement.