Why AppSec Needs an Agent Experience, Not Just a Dashboard

Techstrong TV (DevOps.com)
Techstrong TV (DevOps.com)Jun 5, 2026

Why It Matters

As organizations face vastly increasing attack surfaces and volume of findings, an agent-first architecture lets machines triage, correlate and remediate faster than human-only dashboards, reducing fatigue and operational cost while enabling scalable AppSec. This shift will reshape vendor integration strategies and how enterprises operationalize vulnerability data.

Summary

Detectify co-founder and CEO Rikard Karlsson recounted the company’s evolution from automated bug-bounty tooling to a focus on AppSec that blends dynamic testing and attack-surface discovery. He explained the new MCP server as an agent-centric layer designed to feed machine workflows and combine signals from multiple sources, arguing that security teams can no longer rely on human-only dashboards to manage the surge in software vulnerabilities. Karlsson stressed pairing deterministic scanners with stochastic AI agents to keep costs and noise manageable while enabling continuous, automated validation at scale. The approach emphasizes platformization and interoperability over one-stop-shop consolidation to preserve best-of-breed capabilities.

Original Description

AppSec was built for humans clicking through dashboards — but vulnerabilities now get weaponized in minutes, not weeks. In this TechStrong TV interview, Detectify CEO and Co-Founder Rickard Carlsson joins Alan Shimel to unpack the company's newly announced MCP Server and why he believes "agent experience" — AX — is becoming as important as UX in security. Rickard explains how Detectify's deterministic, hacker-built scanning engines now plug directly into AI coding agents, why a token-burning frontier model alone can't pen-test 300,000 domains, and what the death of the 30-day PCI patch window means for every security and DevOps team. Plus: long-running multi-agent systems, the next bottleneck after vulnerability discovery, and the case for best-of-breed over one-stop-shop platforms.
Chapters:
00:00 Introduction
00:30 Rickard's path from applied physics to AppSec
02:30 The Detectify origin story
04:30 Why Detectify is launching an MCP server now
06:30 Building for agent experience, not just UX
08:00 Deterministic tools that feed stochastic agents
09:30 From discovery to remediation at AI speed
11:30 The next bottleneck — securing agent-generated code
13:00 Long-running and multi-agent systems
14:30 Where to learn more about Detectify
Guest: Rickard Carlsson, CEO & Co-Founder, Detectify — https://detectify.com
Host: Alan Shimel, TechStrong Group
Subscribe to TechStrong TV for more interviews with the leaders shaping enterprise tech.
#AppSec #MCP #AIAgents #Cybersecurity #DevSecOps

Comments

Want to join the conversation?

Loading comments...