* [![perspectives](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://origin-www.paloaltonetworks.com.au/perspectives)
* Why Culture Is the First Line of Defense in the Age of Agentic AI

# Why Culture Is the First Line of Defense in the Age of Agentic AI

![Why Culture Is the First Line of Defense in the Age of Agentic AI](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/06/age-of-agentic-ai-featured.jpg)  
**By [Wendi Whitmore](https://origin-www.paloaltonetworks.com.au/perspectives/author/wendi-whitmore/ "Posts by Wendi Whitmore")** | **7 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Why Culture Is the First Line of Defense in the Age of Agentic AI\&body=Check out this article https%3A%2F%2Forigin-www.paloaltonetworks.com.au%2Fperspectives%2Fwhy-culture-is-the-first-line-of-defense-in-the-age-of-agentic-ai%2F "Share in Email")
* ![copy-icon](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://origin-www.paloaltonetworks.com.au/perspectives/why-culture-is-the-first-line-of-defense-in-the-age-of-agentic-ai/?pdf=download&lg=en&_wpnonce=83197ae001 "Click here to download") MEET THE AUTHOR  
  ![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/05/wendi-whitmore.jpg)  
  Wendi Whitmore is the Chief Security Intelligence Officer at Palo Alto Networks, where she leads efforts to transform complex cyber threats into actionable intelligence. With over 20 years of experience, Wendi has built and led incident response and threat intelligence teams that have helped organizations respond to some of the most significant breaches in history. Previously, she led Palo Alto Networks Unit 42 and held executive roles at IBM, CrowdStrike, and Mandiant. Wendi began her career as a Special Agent with the U.S. Air Force. She serves on cybersecurity advisory boards for Duke University and the University of San Diego, and was an inaugural member of the Cyber Safety Review Board launched by the United States Department of Homeland Security.Wendi Whitmore is the Chief Security Intelligence Officer at Palo Alto Networks, where she leads efforts to transform complex cyber threats into actionable intelligence. With over 20 years of experience, Wendi has built and led incident response and threat intelligence teams that have helped organizations respond to some of the most significant breaches in history. Previously, she led Palo Alto Networks Unit 42 and held executive roles at IBM, CrowdStrike, and Mandiant. Wendi began her career as a Special Agent with the U.S. Air Force. She serves on cybersecurity advisory boards for Duke University and the University of San Diego, and was an inaugural member of the Cyber Safety Review Board launched by the United States Department of Homeland Security....

[Learn more](https://origin-www.paloaltonetworks.com.au/perspectives/author/wendi-whitmore/)

## IN THIS ARTICLE

The arrival of agentic AI rewrites the rules of engagement for cybersecurity. As new tools and workflows create novel attack surfaces, the velocity and sophistication of AI-driven threats now demand a response that transcends technology alone. This new reality calls for a profound shift in our thinking toward a security-conscious culture, one where trust and empowerment form our first line of defense.

Every part of a business must embrace security as its own critical responsibility. This means ensuring our employees are well equipped and empowered to make sound, secure decisions. It means fostering an environment where people feel comfortable speaking up when they spot something that doesn't seem right. And, critically, it means ensuring every leader across the business knows how to communicate and collaborate effectively if the worst happens and a breach occurs.

## The New Battlefield: Agentic AI and Our Widening Vulnerabilities

In my years specializing in computer crime investigations, including my time as a Special Agent with the Air Force Office of Special Investigations, I've seen firsthand how the frontlines of the cyber conflict shift. Today, it's clear that networks worldwide are the primary arena for those who wish to do harm --- whether it's nation-states aiming to steal vital secrets or disrupt our critical infrastructure, or cybercriminals looking to cripple business operations for their financial gain.

Agentic AI magnifies this challenge considerably. When we talk about agentic AI, we're essentially describing AI that has been given its own "arms and legs" to take independent action --- a powerful way to visualize it, as our [CEO, Nikesh Arora, often describes](https://www.cnbc.com/2025/03/25/palo-alto-networks-ceo-describes-cybersecurity-risk-with-agentic-ai.html). This reality propels us into what I can only describe as an "arms race." We must continuously ask ourselves one question: Will our defenses be nimble and smart enough to keep pace with those on the offensive, or will attackers gain the upper hand? At the heart of this race is the speed with which attackers can use agentic AI to devise entirely new capabilities and coordinate their efforts with astonishing efficiency. It's also the speed with which we, as defenders, must detect these actions and respond effectively.

We can no longer think of our defenses like a fortress with a simple, hard outer wall. The attack surface --- all the ways attackers can try to get in --- is now much more fluid. It encompasses our mobile devices, our cloud computing environments, and what remains of our traditional networks. We need clear visibility and the ability to identify malicious actions at every conceivable point --- from one computer to another, as well as between applications and the various layers of our digital infrastructure.

## The Erosion of Trust: AI-Powered Deception

One of the things that concerns me about advanced AI is how cleverly it can be used for manipulation, adding another layer of complexity to our work. Attackers are already using AI in numerous ways, particularly in crafting social engineering schemes that are more convincing than ever. Language barriers, for instance, which once might have provided subtle clues of an attack, have been virtually eliminated.

This capability now extends alarmingly to voice and video. It's possible for attackers to take a mere 5--10-second snippet of someone's voice and then replicate it with frightening accuracy, making it incredibly difficult to detect fraudulent calls to a help desk or other deceptions that rely on voice. The rapid advancement into deepfake video capabilities further blurs the line between what's real and a manipulated imitation. Figuring out if you're talking to a colleague or an AI-generated fake will get tougher and, I suspect, become a more common challenge.

This means we cannot solely rely on the ways we've traditionally verified identity. If an attacker's aim is to compromise someone's identity to access sensitive information, then it's paramount that all the subsequent steps in our processes are even more secure. Every transaction involving our important data --- how it's accessed, changed or moved --- must have robust verification at every single stage.

## Beyond Technology: The Enduring Power of Data, Process and People

With the cost of data breaches now averaging nearly $5 million^1^ for organizations, being strong on cybersecurity is, without a doubt, a real business advantage. In my experience, success in this demanding environment hinges on having access to the right information at the precise moment it's needed to detect an attacker's activity. Then, almost instantaneously, we must determine: Is this a legitimate action, or is it something malicious?

Organizations that do this well have great people and effective technology. They also ensure that the visibility their technology provides is centralized. This allows their systems to automate much of the initial work of detection, freeing up their skilled employees to focus on investigating the most complex and nuanced situations. Conversely, a jumble of different security tools that don't talk to each other effectively creates inherent hurdles for our defenders --- hurdles that attackers are all too quick to exploit.

One of the most pressing challenges I see organizations grappling with today is "Shadow AI." I hear frequent questions from CIOs and CISOs: "How can I ensure we're using AI in our organization safely? How do I even get a handle on what AI applications are being used across different departments? And, what company data might be fed into them?" The larger and more distributed the organization, the more complex this becomes. This makes a clear, centralized AI strategy --- complete with approved applications and strong measures to prevent data leakage --- more critical than ever. We need the ability to specify which AI applications are approved for use and ensure employees aren't inadvertently introducing new, unsanctioned applications into our environment.

However, even with these strategies, significant challenges remain. Stopping sensitive company data from accidentally being fed into public AI tools is something we're continuously working on. Ensuring our internal defenses can match the sophistication of AI-powered attacks is another ongoing effort. And, critically, we must address the challenge of how much we can trust the outputs of AI systems, which still often require human oversight and validation to guard against problems like "hallucinations" or simple inaccuracies.

## Culture: The Ultimate Human Firewall

When I look at the kinds of cyber dangers we're dealing with now, they're faster, more intricate and happening on a bigger scale than ever before. We're seeing nation-states borrow techniques from cybercriminal groups, and attackers exploit vulnerabilities across global supply chains within minutes of them becoming known. This situation highlights a simple truth I've come to learn through years on the frontlines: Technology by itself, no matter how advanced, isn't a magic bullet.

My ultimate advice, therefore, goes beyond just technology. It's about acquiring the latest tools and having brilliant people concentrated solely on the security team. Fundamentally, it's about cultivating a pervasive, deeply ingrained security culture within every organization.

What does this culture look like in practice?

* **Shared responsibility:** From the legal department to operations, finance to HR, every single part of the business must recognize and internalize that security is their responsibility too.
* **Empowerment:** Our employees must be well-positioned and genuinely empowered to make secure decisions in their daily work. They need to feel it's both safe and encouraged to raise their hand when they see something that doesn't look right.
* **Communication and preparedness:** Our leaders across the business must clearly understand their roles and responsibilities. Crucially, they must know how to communicate effectively with one another and with security teams if a breach occurs. The more we practice and test our responses to various scenarios, the better prepared and more secure our organizations will inevitably be.

In this era, where agentic AI is relentlessly speeding up the pace of cyber challenges, I believe a deeply ingrained security culture --- one built on a bedrock of trust, shared responsibility and continuous vigilance --- is our most resilient and adaptable line of defense. It's about fostering an environment where every individual understands their vital role in protecting the organization. By doing so, we transform our entire workforce into an active, engaged, and ultimately formidable part of our collective security solution.

This article was adapted from Wendi's appearance on the [IBM AI in Action podcast](https://www.ibm.com/think/podcasts/ai-in-action/ai-against-ai-based-cybersecurity).

*** ** * ** ***

^1^[Cost of Data Breach Report](https://www.ibm.com/reports/data-breach). 2024. IBM.

* [AI](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=ai)
* [Business Transformation](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=business-transformation)
* [Staying Ahead of Evolving Threats](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://origin-www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://origin-www.paloaltonetworks.com.au/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://origin-www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://origin-www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://origin-www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://origin-www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
