Recursive Security Revolution: Cisco and Splunk Push Defenders to Improve Faster
Cisco and Splunk are pioneering a 'recursive security' model where offensive agents continually challenge defensive agents, and observability captures what happens to improve future responses.
The approach involves authorized testing of defenses, capturing the consequences, evaluating weaknesses, proposing changes, testing them within approved limits, and deploying improvements. This cycle is meant to operate at customer premises all day long, taking into account unique conditions such as identities, applications, dependencies, and business priorities.
Sunil Potti, Cisco's Senior Vice President and General Manager of Security, Observability, and Data Platform, sees this model as the next phase of security. He emphasizes that human oversight is essential in defining objectives, permitted actions, escalation thresholds, and consequential changes requiring approval.
Vikram Chatterji, Senior Director of Agent Resilience at Cisco/Splunk, explains that observability provides evidence about agent behavior, tool use, policy compliance, failures, and outcomes across the full AI system lifecycle. The Galileo technology supports Splunk Agent Observability, connecting agent evaluation and runtime controls with operational visibility.