Abstract digital landscape representing connected data, cybersecurity, and evolving technology risks.

In Cybersecurity, Behavior is a Signal. Intent is the Full Story.

Share with your network!

For most of cybersecurity’s history, we built defenses around a simple assumption: people use technology, and technology follows their direction. 

That assumption is changing. 

AI is moving from something people use to something that acts. Autonomous AI agents are retrieving information, making decisions, and executing work across the enterprise. 

This creates what I believe will be the defining cybersecurity challenge of the next decade: how do we enable people and AI agents to work at machine speed without allowing risk to move at machine speed with them? 

At Proofpoint, we call this the agentic workspace. In this new world, AI is multiplying risk in two directions: outside the organization, by accelerating and scaling attacks, and inside the organization, by giving AI agents direct access to enterprise data and systems. 

Securing the agentic workspace requires two fundamental principles: Defend with Intent and Access with Intent. 

AI Accelerates Risk Outside the Enterprise 

The first major challenge is outside the enterprise.  

AI is increasing the speed, volume, and scale of attacks. Threats are becoming more targeted, adaptive, and harder to distinguish from legitimate business activity.  

This is dramatically changing the security clock. Today, it can take just 90 seconds to move from an initial compromise to enterprise data, the company’s crown jewels. This means the window for defenders to intervene is becoming incredibly short. Attackers are increasingly able to create and evolve attacks faster than traditional defenses can keep up.  

At the same time, everyone and everything is increasingly reachable. An attack can begin with something as ordinary as an email or a browser. 

People have always been the greatest attack surface because they sit at the center of how organizations communicate, access applications, and interact with data. AI makes that risk more acute by giving attackers new ways to target people at greater speed, scale, and precision. 

The priority cannot simply be reacting faster. It has to be making sure the threat never reaches you at all. 

That requires understanding what an interaction is trying to accomplish so you can stop the threat before it becomes an incident. This is Defend with Intent. 

Proofpoint Agentic Collaboration Security brings this idea to life. Built on the new Nexus Intent-Based Detection Model and Proofpoint Knowledge Graph, it applies multi-stage reasoning to understand the objective behind a message and the context surrounding it. 

Because Proofpoint operates across the email delivery chain, that reasoning can begin before delivery and continue in the inbox, while protection extends across collaboration tools and the browser. 

Our new system brings agentic capabilities to detection and investigation, with agents working together to continuously test defenses and identify weaknesses before sophisticated attacks can exploit them. 

AI Is the New Insider Risk 

The second major challenge is inside the enterprise. 

AI agents are creating a new path to enterprise data. As applications become headless, agents can access the data behind them directly, moving beyond the workflows designed for humans. 

That changes how we think about access. 

An agent can be authorized to access something and still be doing something it should not be doing.  

The question is no longer simply: Can this agent access this resource? 

It is: Why is it accessing it, what is it trying to accomplish, and should that action be happening in this context? 

That is Access with Intent: understanding what a human or an agent is trying to do, not just what it is allowed to interact with. 

AI Runtime Security and Data Security Are Two Sides of the Same Coin 

Once AI agents act on enterprise data, AI security and data security become inseparable. 

You cannot effectively secure AI runtime actions without understanding the data they can access. And you cannot secure data without understanding how AI is accessing, transforming, and acting on it. 

That is why we introduced Proofpoint Agentic Data and AI Security, bringing together AI runtime security, data security, identity-aware context, and autonomous security operations in one operating model. 

The Proofpoint Knowledge Graph provides the connective intelligence, continuously understanding AI and human activity, sensitive data, identity, access, behavior, and intent. Purpose-built agents can then detect risk, investigate activity, and remediate issues autonomously. 

This changes the economics of cybersecurity. The number of people in a security organization cannot grow at the same rate as the number of AI agents, identities, data interactions, and policy decisions inside an enterprise. 

Enterprises are also defining governance and policies as they adopt AI, and those requirements will continue to evolve. Our goal is to make rapidly evolving business intent executable. 

That is the thinking behind Semantic Business Policies. Organizations can express a policy in natural language, and Proofpoint can translate that requirement into runtime controls governing AI agents. 

Our Agentic Data and AI Security system gives customers a way to adopt AI safely while controlling the insider risk AI agents create: understanding the intent behind every action, protecting sensitive data from inadvertent loss, and continuously updating governance policies as requirements evolve. 

The system also integrates with dozens of data sources and AI platforms, major identity systems, including non-human identities, and frontier model providers through APIs for intent-based data loss controls. 

AI as a Force Multiplier 

As customers build autonomous SOCs, their security systems need to become autonomous as well. 

Security teams should not have to pull logs, run complex searches, and manually correlate multiple threads to determine whether an event involves a person or an agent, whether it is an attack, or how it got in. AI can help answer those questions faster. With autonomous remediation at scale, the system can investigate and act end to end. 

Our Satori Access layer provides an agentic interface into the Proofpoint platform, helping security teams understand what is being touched and by whom, and resolve issues before they become the next incident. 

For organizations that want Proofpoint to take more responsibility for protecting their data, Managed Data Guard provides a managed environment with visibility into data activity, attack-chain assessment, and posture hardening. 

The goal is simple: as customers build autonomous security operations, the systems protecting the enterprise need to operate at the same speed. 

The Destination: A Secure Agentic Workspace 

We’ve developed these innovations to make our customers’ environments safer and their lives better. 

This is the next evolution of the work we began with human-centric security. We started by understanding that people were the primary target of attackers and the primary actors interacting with sensitive data. 

Now the workspace includes both people and AI agents, and our mission has evolved with it: protect people, defend data and govern AI. 

I'm excited to share these innovations, which represent a leap forward, with our customers and partners as we navigate the new challenges of the agentic workspace together.