Machine-speed threats and the human response: a conversation on the state of cyber defense

Auteur zonder afbeelding icoon
Lars Hermind, Regional Sales Director North | ServiceNow
25 August 2026
3 min

Machine-speed threats and the human response: a conversation on the state of cyber defense

Lars Hermind, Regional Sales Director North at ServiceNow, on why periodic security no longer holds, and what replaces it.

What is the most pressing threat facing security teams right now?

Speed. For most of this field’s history, attackers and defenders worked on human timescales. Something was disclosed, teams assessed it, and a patch shipped in the next maintenance window. That rhythm is broken. Autonomous AI models can now read a codebase, find a flaw, and produce a working exploit in a single afternoon, and adversaries run these tools around the clock. When I talk with partners and customers across the Benelux, the concern I hear most is the software supply chain. A single poisoned open-source package can reach hundreds of thousands of applications before the security community even names it. We saw npm compromises this year, including self-propagating worms, spread across dozens of organizations in hours. For an attacker running automated bots, the supply chain is not a side door. It is the path of least resistance.

What trends are reshaping how organizations defend themselves?

The biggest one is a hard lesson the market is learning: discovery is not the same as risk. When a model can surface ten thousand vulnerabilities in an afternoon, more scanning does not bring clarity, it brings paralysis. A long list does not tell a team which five findings could actually end their week. So the conversation is shifting from counting flaws to understanding exposure. What can an attacker actually reach? And does the path end at something critical: a system holding regulated data, an operational technology asset on the plant floor, an identity with standing access to everything? Identity is the other shift. As organizations hand more work to AI agents, every agent becomes an identity, and most are ungoverned. Every excessive entitlement widens the blast radius of a compromise. Knowing what can access a resource now matters as much as knowing the resource is vulnerable.

How should organizations approach prevention, detection, and response in this environment?

If attacks run at machine speed, defense cannot rely on human-speed handoffs. AI changed the equation, and no patchwork of tools, or single organization, closes that gap alone. Three priorities work. Prevent, by catching risky code and unvetted dependencies before they enter the pipeline rather than after. Prioritize, by grounding every finding in real asset and identity context so effort lands where it counts. And remediate at scale, so a verified fix reaches the right owner, and automated workflows close the loop. The target is not a smaller backlog. It is zero exposure, all the time. Done well, that last part is what protects people. It frees teams from alert fatigue to focus on the judgment work only people can do. Getting there takes asset intelligence, access and identity context, and workflow on a common foundation, which is where much of the recent consolidation is pointed, including the depth of Armis and Veza now inside ServiceNow. It is also where the partner ecosystem earns its keep, turning that foundation into something a customer can actually operate.

Why does an event like Cybersec Netherlands still matter?

In-person events surface the real story, what actually worked, what quietly failed, the incident someone has not written up yet. Because none of this is settled. The tooling is moving faster than the playbooks, and no single vendor or partner holds the whole answer. Strategy, resilience, identity, and compliance are converging, and the people closest to each one learn fastest by comparing notes in the same room. The threats now move at machine speed. Our strongest defense is still, in part, a very human one: sharing what we are seeing before the next attacker does and building the partnerships that turn a shared warning into a real response.

Register for free for Cybersec Netherlands 2026

As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!