The ITSPmagazine Podcast

10,000 Alerts a Day, 75% Cleared With Evidence Analysts Can Check | A Brand Briefing at Black Hat USA 2026 with Seth Summersett, Co-Founder and CEO of Embed Security | Hosted by Sean Martin

Episode Summary

One security team was working through more than 10,000 alerts a day before roughly 75% of them stopped needing a human first look. Seth Summersett explains how that number held up under a competitive bake off, and why the evidence behind each decision mattered more than the decision itself.

Episode Notes

Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant.

The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs.

What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts.

The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts.

Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently.

There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years.

GUEST

Seth Summersett, Co-Founder and CEO, Embed Security
LinkedIn: https://www.linkedin.com/in/summersett/

RESOURCES

Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

Embed Security: https://www.embedsecurity.com

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation

Episode Transcription

10,000 Alerts a Day, 75% Cleared With Evidence Analysts Can Check | A Brand Spotlight at Black Hat USA 2026 with Seth Summersett, Co-Founder and CEO of Embed Security | Hosted by Sean Martin


 

[00:00:00] Sean Martin: Seth, how are you?


 

[00:00:10] Seth Summersett: I'm doing well.


 

[00:00:11] Sean Martin: Good to see you.


 

[00:00:12] Seth Summersett: Thanks for having me.


 

[00:00:12] Sean Martin: We're in Vegas. It's Black Hat, hacker summer camp week. Lots of fun stuff going on here.


 

[00:00:19] Seth Summersett: For sure.


 

[00:00:19] Sean Martin: I think there might be a little AI floating around.


 

[00:00:22] Seth Summersett: Just a tad. Every so often you run by it.


 

[00:00:23] Sean Martin: Just a tad bit. Well, we had a chance to chat with you the other day and we're excited to tell the Embed Security story here today. You are doing some really cool stuff, great backgrounds, leading to some great outcomes, so we're going to talk about that today. A few words about yourself. I know you're going to be a little humble, but I'm going to push on you a little bit.


 

[00:00:46] Seth Summersett: Fair enough.


 

[00:00:47] Sean Martin: You've done some interesting things. You've been in some cool places. So give us a little background of what you've been up to, and then we'll get into a bit about what Embed Security does.


 

[00:00:57] Seth Summersett: Sounds great. So myself, 25 years in security now. I started out, I spent about a decade at the NSA doing NSA things. That was great. Got to travel around the world and do all kinds of stuff, meet great people. Lots of fun stuff I can't talk too much about.


 

[00:01:14] Sean Martin: The NSA things.


 

[00:01:15] Seth Summersett: Exactly. Since then I left there and I went to Mandiant. I spent about a decade at Mandiant. Joined there when it was about 40 or so people, and got to go through that whole journey and experience all of that, which was awesome.


 

[00:01:31] Sean Martin: I see a lot of stuff in there.


 

[00:01:32] Seth Summersett: Definitely a lot of stuff. A lot of clients, a lot of firsts, super smart people. So it was great to be part of that. And I got to be part of all different parts of the company. I did malware reverse engineering. I did consulting on IR. I got to ship kernel drivers in the products, all kinds of stuff. So it was just great experience there across all things. And I finished up there as the head of innovation and custom engineering, which was a lot of just really smart people doing cool, fun stuff all across the company. So that was great.


 

[00:02:08] Sean Martin: Very cool. And you had a stint somewhere else?


 

[00:02:11] Seth Summersett: Yeah, I spent a couple years at Meta supporting a whole bunch of business unit level CISOs, basically.


 

[00:02:19] Sean Martin: So right back to the CISO level again. And so you have a co-founder, maybe two co-founders, right?


 

[00:02:27] Seth Summersett: I have a co-founder, yeah. Jeffrey Johns.


 

[00:02:29] Sean Martin: Yes, that's right. Equally accomplished, accredited, accomplished person and data scientist, if I'm not mistaken.


 

[00:02:39] Seth Summersett: He is.


 

[00:02:40] Sean Martin: And so the two of you together, you come together to do some really good things here. So tell us what the catalyst was for coming together to build Embed Security.


 

[00:02:52] Seth Summersett: Yeah, so Jeff and I worked together at Mandiant as part of the innovation and custom engineering team, like I was saying. And he had a whole data science team that was doing cool stuff there for me at Mandiant. And one of the organizations we worked with was the managed service that we had there at Mandiant. And we got to see on a daily basis just the pains that they would go through, and the way that that functioned on a very human driven scale. And so we did some stuff for them back a decade ago, but shortly before founding Embed Security, Jeff and I got together and we were like, hey, there's a great opportunity here to solve this problem that we're very passionate about, right? Which is, how do we help security operations teams operate more efficiently?


 

[00:03:41] Sean Martin: So what were some of the things? I mean, because it's a big bucket of inefficiencies and stress and burnout, and stuff still gets through, right? All these different things. So what are some of the scenarios that really drove you to say, this is what we want to tackle?


 

[00:03:57] Seth Summersett: Yeah, I think it really comes down to the burnout that you see, right? Just the repetition of the types of work that they do, and how they don't get to spend as much time on the stuff that they really enjoy, that they find fun. And so it was, hey, how can we help them stay more focused on that and not have to worry about all this other stuff? And so that's where it was like, hey, there's a real opportunity here to take a good chunk of this stuff off of their plate, and not eliminate security analysts, and they're not needed anymore, but just change their role, change their job, change what it is they're focused on.


 

[00:04:34] Sean Martin: Yeah. So for a number of years now, the human element has surfaced.


 

[00:04:41] Seth Summersett: Yeah.


 

[00:04:42] Sean Martin: And it's been, I don't know, used and abused to some degree. I think you put your brand behind it, and even your time and energy behind supporting the health of the community. I think you sponsored the health program at BSides. Maybe you can elaborate on that a little bit.


 

[00:05:05] Seth Summersett: Yeah. We work with Dr. Sarah at BSides for the last two BSides that we've been to. She has a calming kit, and a whole program around helping security analysts learn to deal with the stresses and pressures of working in a SOC. When you're under all that pressure and there's an IR going on and you have to solve these problems as fast as you can, that can be a lot of pressure for folks. And so we work with her because we believe this is very important.


 

[00:05:32] Sean Martin: Yeah, so I love that. And so when you're having conversations with organizations, who's it with? Is it the analyst? Is it the SOC manager? Is it the security leaders? Is it the CISO?


 

[00:05:48] Seth Summersett: Yeah. From a sales cycle it tends to be the CISO, or maybe the director of security operations. But the person using our product day to day is the security analyst most often.


 

[00:06:01] Sean Martin: Okay. And so I presume you get a chance to talk to a lot of them. What's top of mind for them? Is it, give me more tooling, give me more information, take stuff off my plate? What are they looking for?


 

[00:06:16] Seth Summersett: It's definitely take stuff off of my plate, but it's take stuff off of my plate in a way that I can trust it. So they don't just want an answer of this is good or this is bad. They want to know why we think it's good or bad. They want to be able to dig in further. They want to be able to prove to themselves that the AI is doing what they think it should be doing. And so it's much more than just take this off of my plate so I don't have to think about it.


 

[00:06:40] Sean Martin: Right.


 

[00:06:41] Seth Summersett: It's take it off my plate, I don't want to have to think about it, but I want to know that I can trust what's happening.


 

[00:06:46] Sean Martin: It still has to happen. And it still has to be trusted that it got the result that I would have gotten, or perhaps even better.


 

[00:06:54] Seth Summersett: Exactly.


 

[00:06:55] Sean Martin: So give me some scenarios where you've helped individuals, or you've helped multiple individuals as part of a team, accomplish something that wasn't possible just with humans sitting at a keyboard.


 

[00:07:09] Seth Summersett: Yeah. It most frequently comes down to volume. So think about, you get phishing emails forwarded in, right? And you've got two analysts at your organization and you get a hundred a day. You're not going to be able to get through all of those. So they're kind of selectively picking which ones they should look at, and then they feel bad because they can't get to all of them. That's an area where we can come in and really help. But we can do that across not just email. We can do it with identity, we can do it with SIEM, we can do it with endpoint. And so as your SIEM over alerts or your EDR is over alerting, we can help handle that, so you feel like, hey, I understand the full risk profile that I have here.


 

[00:07:55] Sean Martin: So where do you fit into, I'll call it the security operations stack? Do you sit alongside of SIEM, with SIEM on top? What's that environment look like?


 

[00:08:06] Seth Summersett: We describe it as we sit downstream from your existing security investments. So you don't have to rip and replace anything. You already have a ton of products that do detection, right? I mean, there are already SIEMs, there are already EDRs, there's already all this stuff. So we're not trying to be one of those or be a better one of those. We're trying to take those signals in and help you process through all of them already.


 

[00:08:27] Sean Martin: And what are some results? I think the ultimate is respond faster, close tickets more quickly. What are some examples of results that you've achieved for some of your clients?


 

[00:08:41] Seth Summersett: Yeah. One of our largest clients did a large bake off between us and several of our other competitors, and we dispositioned roughly 75% of their alerts for them, to where they didn't have to look at them and they didn't have to pay attention to them as the primary. And so basically what they did was, they looked at all of them and they said, okay, you guys are extremely accurate, and so 75% of these we don't even have to pay attention to. So that's a huge thing when you consider they're looking at more than 10,000 alerts a day. And so if we can take 75% of those off their plate.


 

[00:09:19] Sean Martin: Right. So presumably one way of validating accuracy is to handpick a few and actually do it manually and compare it against the results. I'm going to guess AI driven technology in Embed Security is such that usually it means we do some cool stuff, you don't get to see it, you have to trust us. So how do you negotiate and build that trust beyond just manually checking things and spot checking?


 

[00:09:51] Seth Summersett: Yeah, that's a great question. So we have what we call chain of evidence. So we do that from the very beginning, right? I've been in security for 25 years. Jeff's been doing the ML for 25 years. And so we knew from the very beginning trust was going to be a big part of this. We've had AI and ML in security for a long time, but it's been very black box, where you just get an answer and then the analyst is like, okay, well why did it say this? And you have to go back and figure it all out. So from the very beginning we were like, hey, we don't want people to have to do that with this product. And so we have chain of evidence as part of that, so you can easily see everything that we've done, all the questions we ask, how we came to the decision that we came to. And so you can look at it from that perspective. The other way that folks do it is they'll sometimes go backwards in time, right? They've already dispositioned a whole bunch of alerts. They can have us disposition those and they can say, okay, how does it compare?


 

[00:10:38] Sean Martin: Interesting. So no question, AI enables individuals and teams to do things on their own, and it'd be very tempting, I would think, for security operations teams to try to do some of this themselves. And certainly they know their environment, and they might say, we know our environment perhaps better than somebody else. I'm presuming it's baked into the decades of work that you've done, but how do you show them that we can actually do this beyond just the validation that you mentioned earlier, to say it's this knowledge of years, decades, and the data science behind it? It's not just writing an agent, right? So describe that scenario to me, in having that conversation to help them understand what's really at risk if they try to do it themselves.


 

[00:11:34] Seth Summersett: Yeah. It's a conversation we have frequently with folks, because it is appealing to try to do this yourself, right? LLMs make things very simple. You can get a demo up and running really quickly and you can show yourself, hey look, this does this really well. But that's just the tip of the iceberg, right? And so we try to show people, hey, we're not saying don't build it yourself, but these are all the things you need to consider, right? Do you have evaluation loops where, if I make a change, I can know if that change makes it better or worse? You don't want to look at that one alert at a time, right? You want to look at that hundreds of thousands of alerts at a time, to know what the impact of that change is. Do you have governance in place? Do you have organizational knowledge in an automated way? There's just so many things that folks need to consider beyond just getting a demo up and running. So it becomes an engineering problem at a certain point. And do you want to own that engineering problem or not?


 

[00:12:29] Sean Martin: Right. And depending what industry they operate in, they might be audited on all that stuff as well.


 

[00:12:34] Seth Summersett: Exactly, right.


 

[00:12:35] Sean Martin: And then you have to prove this is how I did it and why I did it that way, and it's consistent and accurate all the time. It's very challenging.


 

[00:12:43] Seth Summersett: Right.


 

[00:12:43] Sean Martin: As we wrap, Seth, maybe one final word to two different audiences. Because I think the security operations leaders have a challenge with their own teams, kind of getting them to be efficient and effective, but also healthy, right? And then there's the analyst. So maybe two words of advice, one word of advice each, and just to kind of say, here's what we can do to help you.


 

[00:13:13] Seth Summersett: Yeah. I think from the leader's side, what we can get to them is consistency, right? There are a lot of folks that are like, hey, I get inconsistent results depending on the analyst that takes a ticket, that kind of thing. And as a leader, you really want to know, what is my full risk profile? And if you're only looking at 10% of your alerts, you're not really looking at that full risk profile, right? So that's what we're really trying to help with there. From the analyst side of the page, hey, we're trying to help create an environment where you can have a full, long, lengthy career here in security operations and not burn out after two to three years because you're constantly doing the same things. And we're really here to try and help you focus on the things that I think are most interesting and where I want to spend most of my time, and where they probably want to spend most of their time as well, which is on the interesting alerts and the interesting parts of compromise.


 

[00:14:01] Sean Martin: Yeah, fantastic. Sounds good, Seth. Pleasure chatting with you. Love what you're doing there.


 

[00:14:07] Seth Summersett: Thank you.


 

[00:14:08] Sean Martin: And I'm going to guess a lot of the analysts love what you're doing there too, if it gives them a chance to breathe.


 

[00:14:12] Seth Summersett: Yeah.


 

[00:14:13] Sean Martin: A chance to breathe. So thanks everybody for listening and watching. Connect with Seth and the team at Embed Security, and stay tuned for more here on ITSPmagazine.