The ITSPmagazine Podcast

Customer Zero at Exabyte Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Jeremy Powell, CISO of Sumo Logic | Hosted by Sean Martin

Episode Summary

Seven exabytes a day, 100 percent first level triage through automation, and 25 hours a week back per analyst. Jeremy Powell has been running his own company's platform in production for close to a year and explains what it changes about the SOC, the board conversation, and the analyst's job.

Episode Notes

Most vendors at Black Hat USA 2026 have something to say about agentic AI. Jeremy Powell, CISO at Sumo Logic, spends this conversation on the harder proof, which is what happens when a company runs its own product in production at scale. Sumo Logic has been doing that for roughly ten to eleven months. Powell calls it customer zero, and it shapes how he answers almost every question here.

The Sumo Logic SecOps team ingests seven exabytes a day globally, which Powell puts at roughly half a billion 8K movies. Against that volume, the team reports 100 percent first level triage handled through automation and about 25 hours saved per analyst per week. Everything learned in production feeds back into the product organization in real time.

Security tooling is notoriously hard to use, especially in the enterprise, and Powell is candid that the realization drove a concerted engineering and product effort to fix it. One result showed up at Black Hat this week in the evolved version of Mobot, the conversational interface inside the product. Users can now prompt their way into an investigation, see the audit trail behind it, and get to an answer without configuring their way there first.

So how do you trust a decision an agent made? Powell points to an audit trail and a log trail behind every decision the SOC Analyst Agent produces, traceable back through every conceivable log to the root decision. He describes it as human on the loop rather than in the loop. People keep the decisions. Execution and delivery get automated.

That changes the shape of the job. Powell describes the SOC becoming something closer to an agile QA organization, where analysts assess the fidelity of what the agent did instead of grinding through first level alerts. On the question of whether automation costs analysts their jobs, he uses a phrase he borrowed from someone else: pay attention to the tension. His answer is that the work gets better and more interesting and the analysts get more capable.

The same logic carries up to the board. Powell argues a security leader's job at the executive level is to measure risk transparently and report it accurately, and that boards will build a trend line out of three data points. Telemetry becomes the raw material for informed risk decisions communicated in an executive-friendly way, with the full reasoning available on request. As he puts it, the auditor cares, and the board cares if you fail the audit.

This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight

GUEST

Jeremy Powell, CISO, Sumo Logic
LinkedIn: https://www.linkedin.com/in/executivembajeremypowell/

RESOURCES

Sumo Logic: https://www.sumologic.com/
Sumo Logic at Black Hat USA: https://www.sumologic.com/events/black-hat
Dojo AI agentic security and cloud operations: https://www.sumologic.com/blog/dojo-ai-agentic-security-cloud-operations
Building an AI-first SOC, the customer zero story: https://www.sumologic.com/blog/building-ai-first-soc-customer-zero
See Mobot in action: https://youtu.be/ZZLXaft7tYM

View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

Jeremy Powell, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, Black Hat USA 2026, agentic AI, SOC analyst agent, security operations center, human on the loop, first level triage, security automation, telemetry, exabyte scale, customer zero, Mobot, conversational interface, CISO, board reporting, risk communication, SIEM, AI governance

Episode Transcription

Customer Zero at Exabyte Scale | A Brand Spotlight at Black Hat USA 2026 with Jeremy Powell, CISO of Sumo Logic | Hosted by Sean Martin

[00:00:00] Sean Martin: Jeremy.

[00:00:10] Jeremy Powell: Hey.

[00:00:11] Sean Martin: How are you?

[00:00:11] Jeremy Powell: I'm great. How are you?

[00:00:12] Sean Martin: I'm doing good. I think we're at Hacker Summer Camp.

[00:00:16] Jeremy Powell: Hacker Summer Camp. 25,000 of our best friends. That's right. Together, yeah, in the AC.

[00:00:20] Sean Martin: Having some fun, slinging some wares.

[00:00:23] Jeremy Powell: Absolutely.

[00:00:24] Sean Martin: Hopefully helping some customers.

[00:00:25] Jeremy Powell: Yes.

[00:00:26] Sean Martin: Yeah?

[00:00:26] Jeremy Powell: Yes.

[00:00:27] Sean Martin: Understand the threat landscape and respond to the threats and the attacks that they face every day.

[00:00:32] Jeremy Powell: Mm-hmm.

[00:00:32] Sean Martin: Not an easy challenge.

[00:00:34] Jeremy Powell: Not at all. Yeah, not at all. I think this is always an interesting week in time where everybody sort of collectively gets together and they determine the next six to eight months, and that window's gonna collapse even more.

[00:00:50] Sean Martin: Right.

[00:00:50] Jeremy Powell: Right? Because of all the automation and just sort of the general hype around AI and how it's driving all this new innovation. So.

[00:00:58] Sean Martin: So you sit in the CISO seat at Sumo Logic.

[00:01:01] Jeremy Powell: I do.

[00:01:01] Sean Martin: So you're one of the peers here, also in a position to help your peers. Which is a cool spot. And so tell me a little bit about your role at Sumo Logic, some of the things you look over, and maybe some ideas of how your peers can benefit from what you experience every day.

[00:01:20] Jeremy Powell: Absolutely. So, been in the role for a little while now at Sumo Logic, been around Sumo Logic for over a decade, either as a partner or a consumer of the services. So I understand it from a technical perspective quite well. I think one of my initiatives this year is just around being able to run our own product at scale.

I think that there's no better way to prove to a customer or a prospective customer how we do what we do using our own tooling. It is literally the best way to prove that out, right? Are we effective? Can we scale? And the answer to that is absolutely yes, from a legendary perspective.

[00:01:58] Sean Martin: They call that eat your own dog food, right?

[00:02:00] Jeremy Powell: They do. They do indeed.

[00:02:02] Sean Martin: So, we were talking before we started recording, it's very difficult to get some of the tooling in place in an organization and set up and configured to actually do what it's supposed to.

[00:02:16] Jeremy Powell: Mm-hmm.

[00:02:16] Sean Martin: And even if you're successful at that, configuring it to actually succeed in line with business risk and business objectives.

[00:02:24] Jeremy Powell: Yep.

[00:02:25] Sean Martin: Super hard, right? So there's a technical part and then there's the config leading to the business part of it. What are you seeing in your own environment looking at the tooling that you have? How do you kind of look at that big picture as you build tools internally and use them yourself?

[00:02:43] Jeremy Powell: So I think it's a good question. And Sumo is recognizing something that I think a lot of peers in the industry are recognizing. Security tooling is notoriously difficult to use, especially in the enterprise. And I think the way that we're approaching this is that we've made that realization, and there is a concerted driving effort internally in engineering and product to make our product much easier to use.

That's gonna cast a wider net for potential customers. It's gonna make our existing customers' lives easier. One of the releases that we had this week at Black Hat is our evolved version of Mobot.

[00:03:20] Sean Martin: Okay.

[00:03:21] Jeremy Powell: Mobot is our conversational interface inside the product. And I think that this is definitely where a lot of interfaces are going, just from a general statement, but definitely from a security perspective. Can you interact with the product in a natural language way, in a very casual way, but still glean interesting insights out of all that data intelligence that we have, right?

And so now you can prompt your way into investigations inside of the product. You can see audit trails around that. You can get interesting insights. The agent itself inside of the product is able to put together different pieces of information to give you different outcomes, rather than just a very deterministic ask a question, get an answer, right?

We use this internally. We have an internal Mobot instance that our organization uses that's connected to multiple systems inside. Whether that's, are we having a client challenge from a technical or security perspective that we can help guide them through from either a professional services or support perspective, or also just even from an administrative perspective, "Hey, how is this customer doing from the account standpoint?"

We do that internally in Mobot, but we bring that conversational ability to our customers so that they can go and say, "Hey, I would love to understand what's going on here. How close am I to PCI compliance inside of my platform?" So we've turned that into a very easy, low barrier to entry to be able to get results in a fast way.

[00:04:49] Sean Martin: So you gave one example of getting into threat hunting.

[00:04:52] Jeremy Powell: Yeah, yeah.

[00:04:53] Sean Martin: To "am I PCI compliant."

[00:04:55] Jeremy Powell: Right.

[00:04:55] Sean Martin: Very different conversations, different people, different objectives.

[00:04:59] Jeremy Powell: Mm-hmm.

[00:04:59] Sean Martin: So, is the user base of what you're delivering changing? Has it changed over time?

[00:05:06] Jeremy Powell: I think it is. I think it's changing consistently, because we have users of Sumo Logic that do not have a security role at all in our customer base.

But our intelligence and the data layer, where we sit inside that data layer, is so pivotal to their organization, and it's just making it easier for them to get insights faster, right? I think one of the things that, again, you're gonna see a theme here this week, is how do we get to value fast?

[00:05:34] Sean Martin: Right.

[00:05:34] Jeremy Powell: You know, especially in the age of AI, when spend is off the charts all over the place and we're not doing control and governance around that in a way. I mean, you go down to the show floor, you're gonna see lots of vendors around AI governance, right? So I think it starts in a fundamental way.

We have a casual saying internally, it's like, let's use AI, but let's all be responsible adults about it. But I think there also needs to be a governance layer in that. And we think about that and how we've implemented these types of things. So the user is changing.

Sorry, I deviated from the question a little bit.

[00:06:00] Sean Martin: No, you're all right.

[00:06:00] Jeremy Powell: But the user is changing, and also I think as we focus and really hone in on the security capabilities of the product, to me as a CISO, I'll make this statement, and I always say this: is it all security data? All data is security data.

[00:06:21] Sean Martin: Right.

[00:06:21] Jeremy Powell: Doesn't matter what it is, right?

[00:06:22] Sean Martin: Yeah.

[00:06:22] Jeremy Powell: And so if you just make the product easier to use, then I think you're gonna win all over the place.

[00:06:28] Sean Martin: So, one of the things that I think as companies start to deploy, I don't know, broad scale, but certainly when you get into the security teams looking at tooling and leveraging AI and LLMs and different models, the consistency, the accuracy, and repeatability. Do you get the same, if that's the response, you get the same thing every time.

[00:06:55] Jeremy Powell: Right.

[00:06:55] Sean Martin: Right or wrong. And then transparency into that. So how do you respond to customers that say, "Really cool, but these are life or critical decisions we're making."

[00:07:07] Jeremy Powell: Mm-hmm.

[00:07:08] Sean Martin: We need to know that it is accurate.

[00:07:10] Jeremy Powell: Mm-hmm.

[00:07:10] Sean Martin: And it's gonna produce the same result every time.

[00:07:13] Jeremy Powell: So we prove that. You can see an audit trail and a log trail in every decision that our SOC Analyst Agent makes. I have an example of this at a scale that I think most organizations can't touch.

We, as a SecOps team, are ingesting seven exabytes a day globally. We are using our own tooling to get 100% first level triage with automation, and then be able to repeat that. So all of that, what you're asking is, how do I trust the decision that the agent has made?

Well, one, you become sort of an agile QA organization as a SOC team now. And I think that that's gonna be industry-wide. We've done it. We've seen a lot of our customers who are really bleeding edge. Like, we have a financial institution that's just an absolute wonderful customer. They operate, I think, like 45 billion dollars assets under management.

They have a long tenure, super mature from a cyber perspective. And they are using our exact tooling. They were part of the preview program. And what we're seeing is the same thing being played out at those types of organizations. It's how do you see the fidelity of what the agent is doing?

If you have questions about it, you're able to trace it back all the way to every conceivable log down to the root decision that it made. All that is, again, done with a QA process, and you put the decisions in the hands of the human. We call it human on the loop, not in the loop, because we wanna sit there and make those decisions, but the execution and the delivery of that is now automated.

[00:08:44] Sean Martin: Yeah. So how does, well, I wanna get to some of the outcomes for your own eating your own dog food.

[00:08:51] Jeremy Powell: Yeah, sure.

[00:08:51] Sean Martin: But we talk about the tooling being easy to use.

[00:08:57] Jeremy Powell: Mm-hmm.

[00:08:57] Sean Martin: We talked a little bit about different users now using it, but how does this new world change the way that you approach staffing and training your team?

[00:09:09] Jeremy Powell: That's a wonderful question, because inevitably you get the tension. I have a saying that I stole from somebody who's a lot smarter than me, called pay attention to the tension. And you're seeing perceived tension, or tension that's created around, is this automation gonna make me lose my job?

[00:09:26] Sean Martin: Right.

[00:09:27] Jeremy Powell: Which, hey, is a valid question, right? But here's the way that we're approaching it, and this is exactly what we are seeing from our customer base, partner base, and internally. We're making the work better and more interesting with this tooling. We're making our analysts more capable with this tooling.

And our customers are seeing the same thing. It's not about reducing headcount and replacing somebody with a tool. It's about enabling that headcount with something that can automate the execution and delivery. I've had some interesting conversations with the frontier model people of various companies for the last few months.

And they're essentially saying the same thing. It's delivery and execution's not the issue. It's about decision making. And so our tooling enables those resources to make better decisions and make the work more interesting.

[00:10:14] Sean Martin: It ultimately does come down to the decision, right? Even just building products.

[00:10:18] Jeremy Powell: It does.

[00:10:19] Sean Martin: If you have an indecision, you can miss something. If you make a bad decision, it can be detrimental. If you make a decision you have to remake, could be an issue. So what are some of the outcomes for your team where they make a decision and they know they don't have to revisit it?

[00:10:37] Jeremy Powell: Mm-hmm.

[00:10:37] Sean Martin: Right? Even like in healthcare, you don't want a readmission. So what are some of the outcomes? Start with the analysts in your team.

[00:10:44] Jeremy Powell: Yeah, sure. So we're saving generally per analyst about 25 hours a week. Straight up. That's a great metric, right? So doing a lot more with the same amount of people, more intelligence, better automation.

We are seeing 100%, 100% first line triage with the automation. And again, we've been in production with our own tooling for about 10, 11 months now. So, customer zero. And everything that we're doing is being fed back into the product organization in real time. We have an exceptionally agile engineering and product organization.

And so we feed that back on a regular basis as business partners. And to me, we can talk about cyber all you want. We can talk about the cool tech and all that stuff. But listen, we're business people, and we're here to enable the business to achieve its outcomes, because nobody in security's gonna have a job if the business is not running.

And so we are just a plank for those outcomes to be enabled for our customers and then us as well. But some other metrics around that, I think I mentioned this, but we're at seven exabytes of ingest today. Now, just wrap your head around how big that number is. That's half a billion 8K movies.

[00:11:59] Sean Martin: Wow.

[00:11:59] Jeremy Powell: Okay? And that's our ingest globally. Our own tooling, 100% first level triage. And we've seen that again at scales that are far smaller. And that's what I love about talking to a customer or prospective customer or just the industry in general. Like, guys, we're operating at what I would term a galactic scale.

And we are proving beyond the shadow of a doubt that the tech does what it's supposed to do. And we are showing how a security operations center is now becoming essentially an agile QA organization. Make good decisions based upon the very, very good telemetry that the tooling is handing you.

[00:12:35] Sean Martin: So I'm gonna switch, because we only have a bit left, I think. The other end of the spectrum, you're in your seat.

[00:12:41] Jeremy Powell: Mm-hmm.

[00:12:41] Sean Martin: In front of your ELT, maybe even the board.

[00:12:44] Jeremy Powell: Yeah.

[00:12:45] Sean Martin: What are some of the outcomes in those engagements and conversations at that level? Say, all this tech and investment we made, we made our team better. And?

[00:12:55] Jeremy Powell: And? So I think that this is one of the most important questions that CISOs have a hard time answering.

[00:13:02] Sean Martin: Right.

[00:13:02] Jeremy Powell: And the reason that I say this is that your job as a security practitioner at an executive level is to very transparently and accurately measure risk and report on it. Boards are very interested in risk at this point.

They're very interested in cyber. And boards are generally pretty smart people, right? You give them three data points, they're gonna come up with a trend line.

[00:13:23] Sean Martin: Yep.

[00:13:23] Jeremy Powell: And so when we say that as practitioners, we say, "Listen, I have to be able to very accurately communicate risk to you and what we're gonna do. If we make a decision not to do something, what does it cost? If we make a decision to do something, what does it cost in reputation dollars?" All those great things, right?

So what our tooling does is drive that outcome for a CISO. Now, am I as a CISO gonna be sitting in the SIEM? Probably not. You don't want me doing that, right? But what I can do is I can use the telemetry coming out of that to make very, very informed risk decisions. Very informed.

And we can communicate that using the tooling, the visualizations, or any of those types of things that are going on within the platform. And we can communicate that in a very executive-friendly way. Like, right out of the tool today. Again, conversational. Let's bring it out. Let's lower the bar of being able to drive an outcome for the business. And that's exactly what we're doing. So the tooling enables all of that. And oh, by the way, if you're really interested in it at the board level, which they're probably not, but we can actually show you exactly how we got to that decision.

[00:14:29] Sean Martin: Right. There's data to back it up. The auditor cares.

[00:14:31] Jeremy Powell: The auditor cares. Right?

[00:14:33] Sean Martin: Then the board will care if you don't pass the audit.

[00:14:35] Jeremy Powell: Absolutely.

[00:14:36] Sean Martin: Sure. Jeremy.

[00:14:37] Jeremy Powell: Pleasure.

[00:14:38] Sean Martin: Cool stuff, my friend. Thank you so much. Appreciate the chat. Hopefully we have many more. I wanna dig into all kinds of things. In the meantime, connect with Jeremy Powell, Sumo Logic, and I'm sure you're in a lot of the CISO forums and communities.

[00:14:55] Jeremy Powell: Yep.

[00:14:55] Sean Martin: So connect with them there as well. And stay tuned for more here on ITSPmagazine.