Fresh out of the studio with John Morgan, Senior Vice President and General Manager of Splunk Security at Cisco. The conversation unpacks the AI inflection point reshaping security operations — from the explosion of machine data (set to more than double in three years) to the rise of the agentic SOC, where AI agents handle detection, investigation, and response while humans focus on high-stakes decisions. John breaks down why attackers armed with AI now exploit zero-days in hours instead of weeks, why security must start with observability (including the challenge of "shadow AI"), and how CISOs are evolving from technical gatekeepers into board-level business enablers. His parting message: the entire world is learning AI together — get to it with his perspective on what great looks like for Splunk Security moving forward.
"The volume is increasing quite a bit. We expect in the next three years it’s gonna double. Attackers do not have a governance of regulatory and compliance restrictions on them. They just go at it and see what works. And so the volume, sophistication, speed of attacks—the only way to defend against it is to automate your responses to it. One thing that folks outside of the industry don’t maybe get is just how large the attack surface is. And how hard it is to stop—attackers need to just find one way in, and you’re trying to defend all ways in." - John MorganEpisode Highlights:
[00:00] Quote of the Day by John Morgan from Splunk Security
[00:50] John's path from technologist to cybersecurity leader
[01:35] Leading Splunk Security: the mandate and mission
[02:20] Why Cisco and Splunk have a disproportionate AI advantage
[03:18] It's not the technology — it's the human beings
[04:26] Why more data demands better curation and context
[05:00] AI as both signal generator and attack surface creator
[06:12] Where the bottleneck sits: ingestion, analysis, or response
[07:10] Splunk at the intersection of observability and security
[08:29] The evolving CISO role: gatekeeper to board-level risk officer
[10:22] Defining the agentic SOC and where it's heading
[12:00] Alert fatigue and how agentic approaches change the dynamic
[13:56] Singapore Airlines: real customer outcomes from AI security
[14:47] The AI arms race: who has the structural advantage
[16:11] What a mature AI-native security platform looks like
[17:19] How AI is changing detection from rules-based to correlation
[18:35] Advice to CISOs: observe, trust, automate
[19:41] The one question John wishes more CISOs would ask
[20:22] The next five years — and why five years is too slow
[21:20] Closing
Profile: John Morgan, GM and SVP, Splunk Security, Cisco
LinkedIn: https://www.linkedin.com/in/johnmorganinc/
Podcast Information: Bernard Leong hosts and produces the show. The proper credits for the intro and end music are "Energetic Sports Drive." G. Thomas Craig mixed and edited the episode in both video and audio format. This episode is recorded in Poddster Singapore.
Here are the links to watch or listen to our podcast.
Analyse Asia Main Site: https://analyse.asia
Analyse Asia Spotify: https://open.spotify.com/show/1kkRwzRZa4JCICr2vm0vGl
Analyse Asia Apple Podcasts: https://podcasts.apple.com/us/podcast/analyse-asia-with-bernard-leong/id914868245
Analyse Asia LinkedIn: https://www.linkedin.com/company/analyse-asia/
Analyse Asia X (formerly known as Twitter): https://twitter.com/analyseasia
Sign Up for Our This Week in Asia Newsletter: https://www.analyse.asia/#/portal/signup
Subscribe Newsletter on LinkedIn
https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7149559878934540288