Beyond Prediction: Resilient Defenses for the Post-Certainty Era

Gaurav Saxena (Engineering Head and Site Leader · SentinelOne)

Nullcon Goa 2026 · Day 1

Overview

In an era where the cybersecurity landscape is constantly shifting, defined by sophisticated adversaries leveraging AI and machine learning, traditional rule-based defenses are proving increasingly inadequate. Gaurav Saxena, Engineering Head and Site Leader for SentinelOne in India, presented a compelling vision for cybersecurity in his Nullcon talk, "Beyond Prediction: Resilient Defenses for the Post-Certainty Era." The core premise of his discussion challenges the long-held assumption that all threats can be predicted and prevented, instead advocating for a proactive embrace of resilience as the foundational principle for modern security architectures.

Watch on YouTube

Visual summary for Beyond Prediction: Resilient Defenses for the Post-Certainty Era by Gaurav Saxena
Visual summary for Beyond Prediction: Resilient Defenses for the Post-Certainty Era by Gaurav Saxena

Key moments

  1. 0:00 Introduction: Beyond Prediction, Resilient Defenses
  2. 2:00 The end of predictability: AI as adversary
  3. 2:45 Three pillars of resilience: Absorb, Adapt, Recover
  4. 3:55 Pillar 1: Absorb - Designing for containment and blast radius
  5. 5:15 Pillar 2: Adapt - Mutating security with evolving threats
  6. 6:50 Pillar 3: Accelerate recovery as a first-class control
  7. 8:10 Key capability: Real-time telemetry with context

Beyond Prediction: Resilient Defenses for the Post-Certainty Era

Speakers: Gaurav Saxena, Engineering Head and Site Leader, SentinelOne

Conference: Nullcon

YouTube: https://www.youtube.com/watch?v=ujdK2pADn9w

Overview

In an era where the cybersecurity landscape is constantly shifting, defined by sophisticated adversaries leveraging AI and machine learning, traditional rule-based defenses are proving increasingly inadequate. Gaurav Saxena, Engineering Head and Site Leader for SentinelOne in India, presented a compelling vision for cybersecurity in his Nullcon talk, "Beyond Prediction: Resilient Defenses for the Post-Certainty Era." The core premise of his discussion challenges the long-held assumption that all threats can be predicted and prevented, instead advocating for a proactive embrace of resilience as the foundational principle for modern security architectures.

Saxena argues that the "post-certainty era" demands a fundamental shift in mindset: breaches are inevitable, and perfect prevention is an unattainable ideal. Instead, organizations must design systems that can absorb attacks, adapt to evolving threats, and recover rapidly from compromise. This paradigm shift moves beyond mere defense-in-depth, proposing a holistic, architectural approach where security is woven into the very fabric of software and infrastructure, rather than being bolted on as an afterthought.

This talk is particularly pertinent for security leaders, architects, and engineers grappling with the limitations of existing security models. It offers a framework for designing and implementing systems that can withstand the unpredictable nature of contemporary cyber threats, ensuring business continuity even in the face of compromise. By focusing on engineering principles that prioritize operational resilience, Saxena provides a roadmap for building robust security postures that can endure the challenges of an increasingly complex and hostile digital environment.

Background

▶ Watch: Introduction: Beyond Prediction, Resilient Defenses (0:00)

Historically, cybersecurity strategies were largely predicated on the ability to predict and prevent known threats. This approach manifested in the design of firewalls with static rule sets and security solutions focused on identifying and blocking malicious signatures. The underlying assumption was that by understanding past attack patterns, organizations could erect impenetrable barriers. As Saxena highlights, "The old assumptions used to be predict whatever you can and plan for it and makes rules around that." This led to standalone systems with fixed rule sets intended to cover all foreseeable attack vectors.

However, the rapid evolution of technology has rendered this predictive model largely obsolete. The advent of AI-augmented tool sets for attackers, coupled with easily accessible GPU computes and an explosion of interconnected machines, has dramatically lowered the barrier for sophisticated breaches. Attackers no longer rely on fixed patterns; they mutate their tactics on the fly, exploit novel vulnerabilities, and leverage advanced techniques to bypass static defenses. Saxena emphasizes this by stating, "When AI is your adversary, then who is fighting for you?" This question underscores the critical challenge: traditional defenses, designed to counter predictable threats, are ill-equipped to face an intelligent, adaptive, and constantly evolving adversary.

The problem is further compounded by the increasing complexity of modern IT environments, encompassing diverse elements like cloud workloads, SaaS applications, and intricate supply chains. Breaches are no longer isolated incidents but can cascade across multiple domains, from identity to data, leading to widespread disruption. The speaker points out that "you are getting breached today and the breach which is happening today will be used 6 months down the line." This delayed realization, coupled with the interconnectedness of modern systems, necessitates a move beyond simple prevention to a more dynamic and resilient security posture that can effectively manage the inevitable.

Key Findings

▶ Watch: Three pillars of resilience: Absorb, Adapt, Recover (2:45)

Gaurav Saxena's talk outlines a new security equation centered on resilience, defining it not as the absence of failure, but as the ability to "get hit, but still function." This resilience is built upon three foundational pillars and supported by critical capabilities, challenging organizations to rethink their defensive strategies from the ground up.

The three pillars of enterprise resilience are:

  1. Absorb: The capacity to contain and limit the impact of a breach. This involves designing systems with the explicit assumption that breaches will occur, focusing on minimizing their blast radius.
  2. Adapt: The ability of security systems to mutate and evolve in real-time alongside changing risks and attacker behaviors. This moves beyond static rule sets to dynamic policy enforcement based on behavioral baselining.
  3. Recover: The swift and automated restoration of systems and services post-incident. Recovery is treated as a primary control, not an afterthought, enabling organizations to quickly reestablish trust and operational integrity.

Complementing these pillars, Saxena identified several essential capabilities that modern security architectures must possess:

  • Real-time Telemetry with Context: High-fidelity, low-latency telemetry from all attack surfaces (identity, endpoint, cloud, data), stitched together in runtime to provide understandable, actionable insights.
  • Signal-Centric SOC Workflows: A shift from overwhelming log data to clear, actionable signals that inform specific response actions, enabling Security Operations Centers (SOCs) to prioritize and mitigate effectively.
  • Autonomous Response: Systems capable of responding at machine speeds, where AI counters AI, without requiring manual intervention for initial containment and mitigation.
  • Security as a Run-time Control: Embedding security directly into the software development lifecycle and operational runtime, rather than layering it on top, ensuring it functions as an integral part of the system.
  • Rethinking Defense in Depth: Moving from disconnected layers to a deeply integrated, horizontal defense that unifies protection across all attack surfaces (endpoints, identities, cloud).

Finally, the talk highlighted critical resilience gaps that organizations frequently underestimate: the identity gap, runtime security for AI systems, software supply chain trust issues arising from disparate tools, and the recovery readiness gap. These findings collectively advocate for an architectural transformation, shifting from merely plugging in security tools to fundamentally architecting systems for inherent resilience.

Technical Deep Dive

▶ Watch: Pillar 1: Absorb - Designing for containment and blast radius (3:55)

The technical core of Saxena's presentation revolves around the detailed implementation of the three pillars of resilience: Absorb, Adapt, and Recover, alongside the crucial capabilities that enable them. This represents a paradigm shift from a reactive, perimeter-focused defense to a proactive, intrinsic security architecture.

Absorb: Designing for Containment

The first pillar, Absorb, fundamentally acknowledges that "breaches will happen and breaches happen every day." The technical implication is to design systems for containment and to minimize the blast radius. This goes beyond traditional network segmentation to encompass a more granular approach across various attack surfaces:

  • Identity: A breach of one identity should not lead to a full domain takeover. This requires implementing just-in-time, just-enough privileges (JIT/JEP), ensuring users and services only have the minimum necessary access for a limited duration. Advanced Identity and Access Management (IAM) solutions with adaptive authentication and continuous verification are critical.
  • Workloads: Compromised workloads should not grant infinite lateral movement capabilities to an attacker. This necessitates strong micro-segmentation at the application and workload level, denying paths between different security tiers and critical assets. Technologies like network policy enforcement in Kubernetes or cloud-native security groups play a vital role here.
  • Supply Chain & SaaS: Breaches in third-party services or the software supply chain should not result in widespread production outages. This demands rigorous vetting of third-party vendors, continuous monitoring of API integrations, and robust isolation mechanisms for SaaS applications. The goal is to ensure that a compromise in one component does not cascade into a systemic failure.

The technical implementation involves creating intricate network policies, leveraging identity-aware proxies, and employing containerization or serverless architectures that inherently limit the scope of compromise. The focus is on ensuring that even when a foothold is gained, the attacker's ability to move, escalate privileges, and exfiltrate data is severely constrained.

Adapt: Mutating with Risk

The Adapt pillar emphasizes that security must be as dynamic as the adversary. Attackers don't come with fixed playbooks; they exploit the "first window of opportunity" and then "traverse from there and mutate." To counter this, security systems must also mutate and evolve in real-time.

  • Behavioral Baselining: A crucial technical shift is baselining for correct and predicted behavior rather than just malicious activity. Modern systems build profiles of normal user, device, and workload behavior. Any deviation from this baseline is viewed with suspicion, enabling the detection of novel or polymorphic attacks that might bypass signature-based defenses. This leverages machine learning and AI to continuously learn and refine what constitutes "normal."
  • Dynamic Policy Mutation: Security policies should not be static. They must be able to evolve and grow like a tree based on real-time risks. This means policies are automatically reconfigured in response to detected anomalies or changes in the ecosystem. For instance, if a user account shows anomalous login activity, their access policies might be automatically restricted or additional authentication factors enforced.
  • On-Premise Pluggable Solutions: For environments where external model feeds are not feasible, security solutions must be capable of evolving on the premise. This implies local machine learning models that can adapt to the unique behavioral patterns and threat landscape of a specific environment without constant external updates, enhancing resilience in air-gapped or highly regulated systems.

Technically, this involves continuous monitoring agents, advanced analytics platforms, and orchestration engines that can ingest vast amounts of telemetry, analyze behavioral patterns, and trigger automated policy adjustments or reconfigurations.

Recover: Accelerating Restoration

The Recover pillar transforms recovery from an afterthought into a first-class control surface. Breaches will happen, and some systems will be "injured," but the goal is to "accelerate your recovery" at machine speed.

  • Rebuild from Golden Images: The ability to rapidly rebuild compromised workloads from golden images or immutable infrastructure is fundamental. This ensures that even if an attacker has thoroughly compromised a system, a clean, trusted state can be quickly restored, eliminating persistence mechanisms.
  • Automatic Secret and Credential Rotation: Upon detection of any breach, even a slight indication, systems should automatically rotate secrets and credentials. This prevents attackers from reusing compromised credentials for lateral movement or future access. This requires robust secret management solutions integrated with detection and response platforms.
  • Reestablishing Identity and Trust Networks: The ability to instantly reestablish trusted identities and network connections at machine speed is critical. This involves automated identity verification, re-provisioning of access, and re-segmentation of networks to isolate compromised segments and restore clean communication paths without human intervention.
  • Automated Backups and Recovery Workflows: Recovery plans must be integrated into system design from the outset, with backups that automatically feed into recovery processes. This ensures that data integrity is maintained and restoration is swift and reliable, minimizing downtime.

Implementing this requires robust backup and disaster recovery solutions, automated incident response playbooks, and tight integration between security tools and infrastructure management platforms.

Essential Capabilities and Resilience Gaps

Beyond the pillars, Saxena detailed critical capabilities:

  • Real-time Telemetry with Context: Emphasizes high-fidelity, low-latency data collection from across all attack surfaces (identity, endpoint, cloud, data). Crucially, this telemetry must be "stitched in runtime" and presented in an "understandable and digestible way," moving beyond raw logs to correlated, contextualized alerts that provide a clear narrative of an attack.
  • Signal-Centric SOC Workflows: Advocates for SOCs to focus on "clear signal[s]" rather than being overwhelmed by "noise" from Security Information and Event Management (SIEM) systems. This means leveraging analytics to distill vast amounts of data into actionable insights, providing "what kind of ticket what kind of attack is in."
  • Autonomous Response: Stresses that responses must occur at "machine speeds, not at human speeds." This is the "AI against AI" concept, where automated systems detect and neutralize threats without manual intervention, particularly critical in scenarios like financial fraud where human-speed responses are too slow.
  • Security as a Run-time Control: Argues that security should be "built as part of... your software which you are developing at the developing stage," rather than a layered add-on. This implies DevSecOps practices, secure-by-design principles, and security controls embedded directly into application logic and infrastructure code.
  • Rethinking Defense in Depth: Moves beyond disparate layers to a "deep and horizontal" defense. This means a unified approach where "endpoints, identities, these all attack surfaces are have been unified" in the face of modern threats, requiring a single, integrated security fabric that covers all interfaces and weak points.

Saxena also highlighted key resilience gaps:

  • Identity Gap: Modern attacks frequently target identity, yet it's often underestimated or treated as a mere IM admin task.
  • Runtime Security for AI Systems: AI models often operate with elevated privileges, making them prime targets. Securing the runtime environment of these models is critical.
  • Software Supply Chain Trust: The integration of "multiple softwares which are actually protecting you" can create interfaces that are "causing some kind of breaches, exposures which is happening because they don't gel very well together." This points to the need for consolidated, architecturally integrated security solutions rather than a patchwork of tools.
  • Recovery Readiness Gap: Organizations often lack planned, automated recovery processes after a breach, leading to compounded damage.

The overarching technical message is a call to shift from a "tools" mindset to an "architecture" mindset, where resilience is an inherent design principle rather than a feature added post-hoc.

Demo / Proof of Concept

▶ Watch: Pillar 3: Accelerate recovery as a first-class control (6:50)

The transcript for "Beyond Prediction: Resilient Defenses for the Post-Certainty Era" does not mention a live demonstration, proof of concept, or any specific tool walkthroughs. The presentation primarily focused on conceptual frameworks, architectural principles, and strategic shifts required for modern cybersecurity resilience, rather than showcasing a particular technology in action.

Defensive Implications

▶ Watch: Key capability: Real-time telemetry with context (8:10)

Gaurav Saxena's talk provides a critical framework for defenders to re-evaluate and strengthen their security postures in the "post-certainty era." The implications are profound, demanding a shift from a purely preventative stance to an architectural approach centered on resilience.

Firstly, defenders must internalize the principle that breaches are inevitable. This isn't a defeatist attitude but a pragmatic recognition that allows for the design of systems that can absorb impact. This translates to implementing robust micro-segmentation across networks, workloads, and even data layers, ensuring that a compromise in one area does not grant unfettered access to others. Organizations should prioritize Just-In-Time (JIT) and Just-Enough Privileges (JEP) for all identities, human and machine, drastically limiting an attacker's lateral movement capabilities. Continuous auditing of access policies and regular reviews of blast radius potential are essential practices.

Secondly, the call to adapt means moving beyond static, signature-based defenses. Defenders should invest in behavioral baselining technologies that profile "normal" activity for users, devices, and applications. This requires advanced analytics and machine learning capabilities that can detect anomalies indicative of novel attacks, rather than relying solely on known threat indicators. Security policies must become dynamic, automatically mutating in response to detected risks. This could involve automated quarantine of suspicious endpoints, adaptive access controls that tighten security based on risk scores, or real-time reconfiguration of network access rules. The goal is to build a defense that can learn and evolve alongside the attacker.

Thirdly, accelerated recovery must become a first-class security control. Defenders need to develop and rigorously test automated recovery playbooks. This includes ensuring that critical workloads can be rapidly rebuilt from trusted golden images, that secrets and credentials are automatically rotated upon detection of compromise, and that identity and trust networks can be re-established at machine speed. Investing in immutable infrastructure, robust backup and disaster recovery solutions, and orchestrating these processes to minimize human intervention will drastically reduce downtime and the long-term impact of a breach.

Furthermore, defenders must address the identified resilience gaps. The identity gap necessitates a strong focus on advanced identity protection, including multi-factor authentication everywhere, continuous authentication, and identity threat detection and response (ITDR) solutions. Runtime security for AI systems requires specific controls to monitor and protect the elevated privileges and data access of machine learning models. The software supply chain trust issue implies a need for a consolidated, integrated security platform rather than a fragmented collection of tools, reducing interface vulnerabilities. Finally, the recovery readiness gap underscores the urgency of proactive planning and testing for post-breach recovery scenarios.

In essence, the defensive implication is a mandate to shift from a "tools" mentality to an "architecture" mentality. Security teams should work closely with development and operations to embed security controls directly into the design and runtime of systems (DevSecOps), ensuring that security is not an afterthought but an intrinsic property of the resilient enterprise. This involves unifying telemetry from all attack surfaces, building signal-centric SOC workflows, and empowering autonomous response capabilities to fight AI with AI.

Key Takeaways

  • Breaches are Inevitable; Resilience is Paramount: Organizations must shift from an unattainable goal of perfect prevention to designing systems that can absorb, adapt, and recover from cyberattacks.
  • Three Pillars of Resilience: Modern security architectures must be founded on the principles of Absorb (containment and blast radius reduction), Adapt (dynamic, mutating defenses), and Recover (accelerated, automated restoration).
  • Contextual Telemetry and Autonomous Response: Effective defense requires real-time, high-fidelity telemetry stitched with context from all attack surfaces, enabling autonomous, machine-speed responses to counter AI-augmented threats.
  • Security as a Core Architectural Principle: Security should be embedded into the software's runtime and development lifecycle (DevSecOps), rather than being a layered add-on, fostering deep and horizontal defense.
  • Address Critical Resilience Gaps: Organizations must proactively address vulnerabilities in identity management, runtime security for AI systems, software supply chain trust, and establish robust recovery readiness plans.
  • Shift from Tools to Architecture: The focus should move from merely plugging in disparate security tools to fundamentally architecting systems with inherent resilience, unifying defenses across endpoints, identities, and cloud environments.

About the Speaker(s)

Gaurav Saxena is the Engineering Head and Site Leader for SentinelOne in India. In his role, he is responsible for leading engineering efforts and overseeing site operations for the cybersecurity company. His expertise lies in designing advanced engineering solutions that prioritize resilience in the face of evolving cyber threats, a core theme reflected in his Nullcon presentation.

Reviews

Dr. Zero (Offensive Security Researcher) — HARD PASS

A vendor keynote dressed in framework clothing. Saxena delivers SentinelOne's product pitch repackaged as architecture philosophy, hitting every buzzword checkpoint — absorb/adapt/recover, AI vs. AI, signal-centric SOC, DevSecOps — without a single original claim, concrete data point, or implementation detail that couldn't have been lifted from a Gartner deck. This is a marketing talk with a conference badge on it.

Heather Calloway (CISO) — WEAK

Saxena's framework is coherent and the instinct — resilience over prediction — is right. But this is a vendor keynote dressed as architectural vision, and it never crosses the line from compelling narrative to actionable guidance. Security leaders already know breaches are inevitable; what they need is specificity about where their programs fall short and what to do Monday morning.

→ Top-rated talks at Nullcon Goa 2026

All talks from Nullcon Goa 2026