Cybersecurity is entering a new era, moving beyond its experimental phase due to the increasing complexity of software systems and the limitations of human analysis. This shift is being driven by the capabilities of large language models (LLMs), which offer a scalable and cost-effective way for defenders to assess, prioritize, and act on threats.
Juan Andrés Guerrero-Saade, VP of Intelligence & Security Research and Senior Technical Fellow at SentinelLABS, presented these ideas in a keynote address at LABScon 25. He described LLMs as a "lossy compression of human knowledge" that can provide a vast and inexpensive source of evaluative power. This mechanized intelligence can reduce the reliance on scarce human expertise, thereby lowering the cost of analysis and transforming how defensive operations are conducted at scale.
Guerrero-Saade argued that the industry should integrate these AI capabilities rather than treating them as add-ons. He advocated for a move away from purely adversarial design principles, drawing on concepts from cybernetics. Instead, he suggested a future where human expertise and artificial evaluative power work collaboratively to achieve better security outcomes.
The future of cybersecurity, as envisioned in the talk, points towards a more standardized, automated, and sustainable industry. This evolution aims to move beyond defending existing product categories or familiar workflows towards a more integrated approach to security. The keynote is considered essential viewing for those interested in how AI could reshape the practice, cost, and structure of cybersecurity itself.
Guerrero-Saade's background includes overseeing intelligence production and AI applications for security at SentinelLABS. He is also a Distinguished Resident Fellow for Threat Intelligence at the Johns Hopkins SAIS Alperovitch Institute. His research has been featured in exhibits at the International Spy Museum and he is a member of OpenAI’s Frontier Risk Council. He founded the threat intelligence conference LABScon and co-hosts the "Three Buddy Problem" podcast.
LABScon is described as a unique venue for original research shared among peers, with an invite-only audience of researchers. This format allows speakers to focus on technical findings without extensive introductions. Talks are typically 20 minutes with a 5-minute Q&A, and workshops are 90 minutes. While primarily focused on threat intelligence and vulnerability research, LABScon maintains an open mind to other relevant topics. The LABScon 25 conference was hosted by SentinelOne's research arm, SentinelLABS.






