So Lee, I, I'm glad to have you on today because I was recently at this event in San Francisco. It was an AI event. It was maybe 2, 3 weeks ago. Every single person at this event was selling the same thing, AI agents, which I think is quite funny, right? Because I'm like, what problem are you solving? And they're like, we have AI agent. I'm like, well, that's like every, you know, there's 400 vendors selling the same thing. But it got me thinking though about how we are giving so much to this technology. Like I have friends that have Claw Code running. They're like, it's running my business. It has all my credit cards. I'm doing this. And I can't help but think like, is this dangerous?
Quick answer is probably. Yeah. There's always risk to that. It's, We were joking a little bit earlier, it's no different than when social media first came out and we're blasting everything about our lives and everything on there. And then eventually starting to worry about, okay, well maybe I put a little bit too much. Yes, it, like any technology, there's gonna be benefits that are gonna come out of it, it's gonna help you and all that kind of stuff. But there's absolutely a risk of the data, your information, and all that kind of goes with it leaking out at some point. And we've seen it, every company around that someone has been hacked. So just assume that any data that is being used or put into it has the potential to get out. So as long as you're comfortable with the data that's going into it potentially leaking, going through. But this brings up a larger challenge with agents and AI in general. First of all, I agree with you. I was at RSA, which is the previous thing. Every single booth had AI and agents. You could be a coffee maker and you are building AI agents of some sort.
And it's, there is a lot of excitement. There's a lot of promise, but you know what? Sometimes when there's a lot of money in a thing, there's also a lot of hype and there's a lot of distortion. And so the challenge is always sifting through the noise. There's going to be some great, awesome companies, great advancements, but there's also a lot of noise. And so need to go through this. So back to your cloud point, there's going to be a lot of benefits. Some companies are going to be awesome. Some companies are going to turn out to be not as safe, not as secure. Data is going to get out there. And in these early days, we always look at the benefits, but things are not always as tight and secure as they can be. They'll get there, but they're probably not as safe and secure at this point. There's probably going to be some articles and some news things in whatever, months, year, about all data leaking out from some Cloudkill thing. And you know, that's going to happen. But you know, it's this balance with the— with this rapidly moving tech, which by the way, I am all for.
You know what though, I, I think People are getting so comfortable with LLMs specifically, and I think that's kind of entering, you get comfortable with any LLM, you then get this other AI app and you think it's the same thing. Because I know a lot of people putting all their financial information, personal, I mean, they're, they're putting so much information into all these different spheres that they wouldn't even tell somebody else. Is there, what should people be thinking about? Before they do that?
Fair question. At a minimum, think about the, a little bit about the company, is it reputable, does it have some trust and safety in it? But I think to your underlying aspect, it's a lot of, it's a multi-agent world. It's not agents, single agent. There's lots of agents and agents talking to agents. And the agents that are acting on your behalf for your financings are talking to other ones. So to some degree, you're empowering and allowing agents to talk to other ones. And now the question is, how much trust is on some of those setups that are going with you. This does bring up a larger cybersecurity trend of what's going on. By the way, I think it's all good. You want to allow the agents to assist, to support, to augment what you're doing, especially for cybersecurity. But there's going to be a day where they're going to start acting on your behalf, and Cloud Code is one of those examples. And once something starts acting on your behalf and empowering and having access to your data, now the question is governance and controls and bounds. So it's almost back to the role-based access control, if you will.
How do I make sure that it does what I want it to, but put some lanes so it stays in there, some guardrails, if you will, to do that? So there's a whole new set of companies that are starting up that are all about guardrails, safety, trust concerns, and those are going to merge and kind of put it into. So A, yes, there's good stuff there, but I think there's going to be a whole side market about controlling, monitoring, looking for data leakage, keeping these agents in their lanes so that you can actually trust the data you're putting into it. Do you remember like online banking years ago? Yes, you used to go to the banks itself and all that. And it's like we were putting all our data in it. The big boys, they did their work, the big banks, to kind of put the data in it to make sure it's safe and secure because you don't want to lose trust in a new technology. So in other words, if you started putting all this stuff in, I'm going to pick a bank, Bank of America, JPMorgan, and all your data was leaked, well, that's not a good thing for them and their business.
I think there's going to be a similar one where if you're going to want to actually put data and allow them to act on your behalf, it's in their interest to make sure that you trust them and it's safeguarded and running. So my long-winded answer is we're in the early days, there will be sloppiness and mistakes and leaks, but I think it's going to actually be good long-term.
I forgot that you have the agents talking to other agents. And you have like, they're on this social media platform and they're going to be doing currency out of it. What a fascinating world. But you were 15 years at MIT Lincoln Lab.
Yeah.
I always have wanted to go to MIT. I want to see what happens in the lab. Can you tell me anything about your experience there?
Yeah. So this was, first of all, it was awesome. It was great.
Um, and I built Founder Story from a $50 microphone. And the most important thing is I didn't do it alone. For years, I've been using Upwork to hire marketing, editing, branding, you name it. In fact, the editor who cut this very episode and the team behind all of Founder Story branding found them on Upwork. The quality of people is top notch and paying people is simple. Upwork is a one-stop platform to find, hire, and pay expert freelancers across development, data, marketing, operations, and more. With Business Plus, you can access the top 1% of talent on Upwork, and with AI-powered shortlisting, you'll get matched to the right freelancer in under 6 hours. No endless searching required. It's free to sign up and posting a job is easy. Visit upwork.com right now and post your job for free. Free. That is Upwork.com to connect with top talent ready to help your business grow. That's U-P-W-O-R-K.com, Upwork.com.
We are part of the university that is tied to applying advanced technology to national security problems. So yes, it's part of MIT, but it's applying it to, again, national security. So it was really cool because I'll call it applied research. It was one of the most threatening issues that are potentially hitting the US, whether it's air defense or missile defense or space control. The lab grew out of World War II. We're trying to build radars to be able to find, well, bombers coming over to knock us out to do that. And I was part of the group building up the cybersecurity side of it. So how does potentially cyber impact national security from both a defensive and an offensive standpoint? To do that. And it was actually really exciting because it was during the early days of cyber and you got a chance from a Lincoln standpoint, working on some of the premier agencies and government things on what is the bleeding edge on technology, shops like DARPA that are developing advanced tech and the intelligence agencies, what's really coming down the road in terms of development capabilities, effects. And after 15 years of being there, building, testing, quantifying, measuring, advancing them, we eventually spun out as a company to do that.
Because A, we're having a great impact on the lab and the nation, but then it was, how do we work this to solve not just whatever, the Department of War problems or the NSA intelligence problems, but helping the banks. I live here in Boston, helping the city, helping the— Cyber was becoming a much bigger issue than just a national security issue. And you see it, it's in every day, it's in every conversation that you start having. Over here. And part of it, there were glimpses of a lot of the AI things that are, that we're seeing now back at the lab that now are becoming prominent and, and forefront.
So walk me through the moment. I mean, you were in the research field, you were in the university type field, you were working on these projects, and then you said, you know what, I'm going to be an entrepreneur. What was that switch?
Yeah, so at some point, like anybody, you're going to make that jump and say you're building some good stuff. You're pushing the limits. The technology is mature enough. I met Hutch, the other co-founder. He was an F-15 fighter pilot off at MIT for many years doing research, but also flying F-15 fighter planes. So he had this nice balance between academics, but also war fighting and fighting. And we did a project together in 2014, and it was really the incubator, if you will, for the startup. For the spinout. So he was at Cyber Command, I was at the lab, we were applying a lot of the technology, we were running a series of events, and it was to kind of see is do we have the right team chemistry? Is the tech ready enough to effectively spin out? So anytime you're talking about going from a secure lab environment to jumping out of their own, by the way, we bootstrapped. So it wasn't, oh, are you gonna raise a bunch of money to do that? We did it like any startup. It's gonna be hard and difficult and you're gonna get kicked in the balls, right?
You're gonna take a few punches, every other day. Our journey was just that, it was bouncing alive. But once you start having the right people, the technology is good, we got a chance to vet it, we made the plunge. And I'm not saying it was the easiest ride, but we grew the company and we were successful so far.
Bootstrap, you don't hear a lot about that in technology. Seems like everyone in technology, even if they're making the worst idea to the greatest idea, they've somehow raised money. And what was that like for you then, being able to bootstrap? Like, what did you do in those early few years that enabled you to obviously continue now, I mean, for over a decade?
Yeah, so, um, a, um, because we've been building this stuff, we've been working with the government, the military, uh, for years, we had some credibility that tied with it, both from Hutch, from the, uh, uh, working on some of the stuff, and myself at the lab. So we were able to spin out of Lincoln, spin out of the lab, and build off with some government contracts right off the bat. So we're doing a lot of the work we're doing at the lab and transition. But the goal was never to be just military, is to work with the very large banks, to work with the commercial side. So we used some government funding for the company to start building up the technology, working with the commercial companies. To start actually going through. So yes, we bootstrapped, but the challenge there was always cash flow. It's always been cash flow, which is sure, you have an effort, it takes a while for money to be able to move. And we've had our ups and downs, don't get me wrong. We were always leaning a little bit forward in terms of money coming in versus pushing the tech because here we are, 3 dudes in a basement.
Okay, it was 5 of us. We brought in a bunch of people from The Lab, but you're always pushing in terms of how many people can I hire? To be able to build a platform and the tech fast, knowing that there's a bunch of well-funded companies, defense contractors, all that stuff. So it was all about speed. It was how fast can we build it out? There was a big— when Cyber Command was building up their team-based setup, they had these innovation competitions, and our view was screw it, we're going to beat out Lockheed, Mantech, all defense contracts, and we did. We beat all the tech company out there. We pushed the tech fast. Now don't get me wrong, we knew we were incurring tech debt. We knew we were incurring all kinds of stuff on the way to do that, but it was like, screw it, we'll fix those things later. Let's win the whole thing, which we did. And then let's basically patch up and kind of work through that. So speed was paramount and you know, it was a lot of long nights, but it was also that balance between payroll.
You said something that I think is so critical. You, when you have a job or you do something before being a founder, you build relationships that then turn into the business that you're gonna do because you've been solving pro— because you really know the industry. And then on top of that, it's like, it's like creating, it's like marketing yourself before you start. So you have some customers, you have some early revenue, you already kind of start to know an avatar that you can go after before you, you know, expand to other products and services. 'Cause I've seen people do too many, like they try and be everything to everyone, they do too many things and then they exhaust all of their funds. What do you think as a bootstrapped tech founder that you, besides the speed part, but what do you do differently that maybe another company does that has well, that was well funded?
Yeah, I would say that we had the advantage, to your point, we have been doing this for 10+ years at a national lab. We knew we had a business for the government. We knew we could actually commercialize into them. The real question is, is it a commercial business? And we started off saying, we're gonna be 80% funded by the government, 20% commercial. And over the years, we want to flip it. We want to be a commercial worldwide success, not just a government thing. And the working with the early banks, working with the other ones, was a stress test to figure out, is cyber ranges, the ability to kind of create very realistic environments for training and testing— I'll get to the testing in a second— with all the AI solution and Agentic and all that kind of stuff, how do you create effectively a digital twin that models the environment? We knew that was going to be a fit in the military. And, and then the question is commercial. Honestly, this is where in the early days the market is are finally catching up with our solution. So we were actually working with very large enterprises for the last 10 years.
In the last year, customers are coming to us. Why? Because now the need for Agentic and AI and the ability to kind of have trustworthy, robust, reactive— back to your cloud code. If you're going to have an agent that's going to act on your behalf, that's going to actually do all your things and you want to trust it, Picture being a very large enterprise. You can pick any company, JP Morgan or Bank of America or Apple, are you, or a regular things. Are you really going to replace all your cybersecurity staff and tech with a bunch of agents acting on your behalf without properly vetting and testing and going through? So not only do you want to have these AI agents that are augmenting the humans, that's the easy part. Do a lot of analysis, triage, pull all the data up. But the moment you allow it to start taking action on your behalf and responding and reacting and going through, how do you vet it? How do you trust it? How do you actually make sure it stays in its guardrails? So the same cloud code conversation we're having, now apply that to cybersecurity agents for the biggest companies in the United States and worldwide.
And how do they go through that?
So Lee, when you heard about ChatGPT being a thing, was that maybe 2023, I believe, or 2022? I can't remember at this point, but when you saw like, wow, ChatGPT is a thing, millions of people are using it, then it became hundreds of millions of people, and then you had Gemini, and then you had Claude, and you have, you know, all these other things. Did you look at each other as, as co-founders and you're like, wow, like we, it was great that we were at the forefront, it was amazing, but like, this is our time?
Yes, but it was also like all that, it was tech 50 years in the making. Even all the AI and the LLMs and all that, it was stuff that was going around. It's once compute and memory got abundant that these models started really kicking off. So that tech had been brewing for many, many, many years, but it was really the compute that made it powerful to be able to run these models on very large-scale setups to be able to do that. So once that started happening is, to your point, it was the inflection for the business about the autonomy, the agency they're running through. And it really is impressive at what the tech can do. And if you ask me, where are we going to be in 20 years from now? I don't know. That does wait, like right now you're almost looking at horizons of 3 to 5 years. 20 years, it's a guess, but it is moving fast. It is disrupting, which is really exciting. You know, there's only a few times, I'm a little bit older, you're, I don't know, but it's exciting to see the transformations that we are going through.
And again, Cloud Code is one example. But you can apply AI to every single field, whether you're a lawyer or a coder or cybersecurity or you name it, it is disrupting. And it's one of those things that every business, whether you're an agency, government agency, a company or anything else, are trying to figure out how to transform along with it. Some are going to crush it and do well. By the way, a bunch of them are going to die. It was almost like when cloud came around for the on-prem world, if you remember that, there was a whole bunch of new companies, AWS, Azure, the other ones, they did well. There was a lot of other companies that were in the noise or around there. Back to your point at the beginning about going to a conference and there's a bazillion companies, you know, in 3 to 5 years it's going to consolidate down to some key ones. But early on it was, it was, everybody was jumping into it.
It's like, yeah, we're in this race. We're in this race. I was telling someone the same thing. I'm like, look, just do something and you got like 1 to 2 years. That's it. Like you either, you got to exit it. You got to do something with it because, because so many people are doing the same thing or an LLM could just copy you and do the same thing. But I'm like, hey, if you can make it and you can do it, I'm like, you got to do it now though, because if you wait, I think it's going to be useless. Now for you though, you have something interesting that I've, I've had a lot of experiences with engineers. Throughout the years, and I always say like the hardest people to sell anything to are engineers, but you hold degrees in electrical engineering and modern languages. Does this mean that you are the best engineer at communication?
No, I, I grew up in Italy is the quick answer. I grew up in Italy, so I went to Italian school, so I knew languages. I like languages. So yes, I wanted to, I did engineering. Um, but I also like some of the languages and the other stuff. Ironically, I like DJing and a lot of the music side too. So all the, that's been going on for 20, 30 years. So if you look around the side, there's all the decks and all that. But the engineer was my backup safety job if the DJing and everything else didn't work out. But that's, that's a little bit, that's a little bit of a side thing. But I think, um, to one of the other questions, AI, you know, I think every, back to your thing about getting into the thing now, every shop, every company is trying to figure out how defensible their business is. In the age of AI to do, and we're no different. What is the defensible moat where, and differentiator, where what's unique about what we have that can't be replaced by AI and code overnight? And you can see this with every company, every SaaS company that's out there, is what happens if their business is eaten away by AI doing some of the stuff?
And so there's a broader struggle that every company is going to go through here to figure out what is really defensible that AI can't just auto-code away. I'm using words loosely there, to be able to do that.
So, you know, Claude, I don't know if it's Mythos, I hope I'm saying that correct, like, and then, you know, they were afraid to launch it, so they're working with the government because it could like hack everything, and then hackers, I think it was a week ago, supposedly like good hackers hacked into it to prove that they could hack into it, and now they've seen it. Yeah. How, what are you thinking about all this?
It was inevitable and also expected from the standpoint of what are they really finding? Humans write code, code is buggy, AI is finding the bugs in the code. We've had 50+ years of code. There's a lot of legacy systems. And what it's doing is looking through all the code and finding vulnerabilities. Mature cybersecurity shops assume breach, assume that there's a 0-day or vulnerability that will be found. It's a good defense is never about, is my wall super high or do I find every vulnerability? Assume an adversary will get in. That's been something that's been true for 20, 30 years. It's all about how fast you detect and respond and recover. So a good shop will recognize that there will be vulnerabilities. There are vulnerabilities. There will be. The rate at which vulnerabilities are being discovered and, and from discovery of vulnerability to exploitation, which is finding that using that flaw to be able to actually get into it, we're down to like whatever, hours. It's trivial. It's just assume somebody's going to get in to be able to actually go through that. Sophisticated players have always recognized that's the threat. I think the challenge with AI is it's getting weaponized across the kill chain, not just the finding vulnerabilities, the discovering and mapping of the networks, the carrying out the payloads, the speeding it through to do that.
So for any cyberattack, You gotta find the way to get in. You gotta move around inside to be able to find the interesting stuff. And then you have to communicate back and forth to be able to control it and then eventually carry out your goal, which is destroy stuff, steal data, have an impact. The Mythos is just about the getting in. All that does is get you in. But there were 20 other steps that you had to kind of go through to really carry out your, your goal. I think AI is weaponizing again to be able to carry out every step, but it's also applied on a defensive side to improve and speed things up as well. So it will be, in my mind, an agentic or an automated adversary against an automated defense, but with the humans in the loop governing, controlling, measuring. You don't want the bot v. bot world just running open-ended without some governance and control. And making sure that things are doing what they're supposed to.
And so I know this isn't related to what you all do as a company, but I'm sure you have an opinion here or some experience. So I've heard a lot about vulnerabilities in things like the grid, power, operational technology, water systems. I've heard, you know, all these different things that could potentially be issues where countries can hack into other countries. We had a, about a year ago, we had a guest on who was talking about what they're doing when it comes to AI plus quantum and trying to stop those potential hacks in the future. I know it's not right now, but it, you know, could be near in the future, possibly, they say. So how exposed do you think countries are and how exposed do you think the average American is?
Yeah, um, two different parts. So yes, it's a problem. It's always been a problem. Um, traditionally it was OT, the operational technology industrial system, which is really your power plants, your, your, your airports, your electric grid. Um, all of that critical infrastructure that we rely on has traditionally been isolated. It's a lot of industrial systems that are going on in there. And it's been a problem for a while. It is getting attention. AI will be able to help in terms of looking for stuff and also getting in. But because it is getting interconnected. To hit to the punchline, why do adversaries go after a target? Usually it's either for money, go in, steal data, ransom, do that. In the critical infrastructure side, it's usually more for strategic value. In other words, why would you want to take out a power company? Why would you want to take out the electrical grid? It's probably not to just ask for some money. It's because you want to use it at the right time to inflict pain at a national level on somebody. So I look at those tactical, I want to make money things, criminal gangs, versus I want to inflict pain on you and disruption.
And, um, Ukraine is a good example of that. So Russia, Ukraine, why were they going after the power companies with cyber and all that? Mainly to, to have an effect on those. So From a US standpoint, is there a threat that is trying to kind of get in and inflict pain on us in terms of our day-to-day life? Likely. And people are trying to defend upon that. But that's more of a long-term, that's more of a war footing, if you will, than a money-gaining setting to be able to do that. So yes, it's a challenge, but it's also an area that this is actually one that we actually do help them out with, which how do you apply cybersecurity and allow you to be able to defend the setup? When keeping the system running is paramount, and that many times these are older systems. So when you think about your power plant, it's not created last week and it's all brand new shiny stuff. Some of these things are very small little programmable devices that have been in the field for 20, 30 years. They don't have much of a processor. So there are companies, there are people who are trying to add a layer of security, observe what's happening, see it go through.
So, so a bit, So there's an effort to be able to secure these up is the quick answer.
Do you think cybersecurity as a field, if people look at what kind of a job do I want to do or what field do I want to get into, do you think this could be maybe the hottest industry for the next few years when it comes to jobs and technology?
Yes and no. It's been hot. Cybersecurity has been important. There's been a job shortage for many, many years. And with a lot of these things, you talk about AI replacing and getting rid of a lot of jobs. And to some degree, that's true across the board. But I would say even in cybersecurity, many of the jobs are going to get automated and eliminated, but it creates a whole bunch of new jobs. And so the number of jobs I think is going to be the same, but they're going to be different. In other words, now you're going to have to have a whole bunch of cybersecurity guys that think about AI, multi-agent systems, complex systems, securing these architectures. Back to your cloud code example. Cool. I have all these things out there. It's probably not guys looking for— I need a series of jobs that are going to secure, architect, test, red team, model all these threats. So yes, it is hot, but it's going to be a slightly different set of jobs for cybersecurity now applied to the increased use of AI.
Let's just say scenario. Yeah. 10 years down the line. It seems like you're probably around 30 years old, 35.
Uh, keep going up. I'm in the 50s.
10 years down the line, there's no jobs. We don't even have to work anymore. It's like Star Trek. We can just choose whatever we want to, we want to do. I would like to be a DJ. What would you want to do?
Are you serious about that one?
Hypothetic. Yeah. I would love to be a DJ. I think it sounds so fun to be out there. Like, I want to experience the feeling of walking out and you see like 50,000 people and you're just DJing, or maybe I should just be the hype man to the DJ, but I always just feel like DJ would be a cool job.
I think it would. Um, so I don't think everybody's going to be just sitting at home now.
Hypothetical. Let's just say hypothetically you could do anything at Star Trek. Maybe you could even be in space. What would you want to do? You don't have to worry about money. Money doesn't matter anymore.
I do like the idea of space, um, whether it's Mars or any other things. I, I do like those concepts over there for that. So the adventure, the new, uh, is, is an exciting topic. Whether we're going to be there in 10 years, who knows? But that, that is exciting. You can joke about, you know, travel around the world and all that kind of stuff, or sailing and all those, but space is the final frontier if you want to use the Star Trek analogy. And I think that would be actually pretty cool. I very, very excited. I know Elon Musk and company, they're pushing really hard to get there. Are they going to get there in 10 years? Eh, don't know. But long-term, yeah, there's going to be— it's going to be into Palantir in my mind, and it's going to be really exciting. And it's exciting to see not only that, but AI applied to industrial systems, robotics, all that kind of stuff. I think the AI is going to be more than just code. All the robots and all the machines and all the cars is moving really quick. And, and we're going to start seeing a lot more of that as well.
Let's go to space. Yeah. If, if I, if I still know you in 10 years, uh, let's go to space. I'm thinking it could be a one-way ticket. So I'm hoping that it's not. I hope they, I hope there's a return flight, but I'm, I'm interested in space too. But I mean, hey, SimSpace, you know, I mean, like, it was inevitable that you like space since it's in the, in your company name, but co-founder and CTO of SimSpace. Lee, great time today. Love the conversation. I think a lot of people are going to learn a lot. There's so much going on, and I super appreciate the impact that you're having on the world, because I can see it's going to be incredibly positive. And thank you for joining us. Thank you.
Thank you so much. It's actually been great chatting, and hopefully I didn't get too animated on this, but, uh, really, really enjoy chatting.
Daniel and Lee Rossey, CTO and Co-Founder of SimSpace, open with the explosion of AI agent companies and the growing comfort people have with giving these systems access to business tools, financial data, credit cards, and personal information. Lee warns that the benefits are real, but so are the risks: every company eventually faces compromise, and users should assume that any sensitive data they feed into these tools could someday get exposed. From there, the conversation moves into agent-to-agent communication, governance, AI guardrails, MIT Lincoln Lab, bootstrapping SimSpace, cyber ranges, critical infrastructure, and the future of cybersecurity jobs in an AI-driven world.
Key Discussion Points
Lee explains that AI agents can create real productivity benefits, but users need to be honest about the risk of putting sensitive information into systems that may eventually leak or be hacked.
He compares the early AI-agent era to the early days of social media, when people shared everything first and only later realized the privacy and security consequences.
Lee says the AI boom has created real opportunity but also massive hype, with nearly every company now claiming to use AI agents regardless of whether the product is truly differentiated.
He explains that the future is not single-agent AI but multi-agent systems, where agents communicate with other agents and act on behalf of people or companies.
Once AI agents begin acting on someone’s behalf, Lee says the key questions become governance, controls, role-based access, boundaries, and guardrails.
Lee predicts a growing market around monitoring AI agents, preventing data leakage, controlling access, and keeping autonomous systems inside trusted lanes.
He shares his experience at MIT Lincoln Laboratory, where he worked on applied research tied to national security, including cyber defense, offensive cyber questions, DARPA-style technology, and government cyber capabilities.
Lee explains how he and his co-founder Hutch, an F-15 fighter pilot, tested their chemistry and technology through early projects before spinning SimSpace out of the lab.
He describes SimSpace’s bootstrapped early years, using government contracts, credibility, speed, and long nights to compete against large defense contractors and well-funded companies.
Lee explains why cyber ranges and digital twins matter: they allow organizations to model realistic environments, test defenses, train teams, and validate whether systems can withstand attacks.
He says AI has accelerated the urgency of SimSpace’s work because major companies cannot simply replace cybersecurity teams with autonomous agents without testing, vetting, and proving those agents are safe.
Lee explains that modern cybersecurity must assume breach. The real question is not whether someone can get in, but how fast a company can detect, respond, recover, and limit damage.
He warns that AI is being weaponized across the cyber kill chain, from finding vulnerabilities to mapping networks, moving laterally, communicating back to attackers, and executing a final objective.
The conversation also covers critical infrastructure, including power grids, airports, industrial systems, and operational technology, where attacks may be less about money and more about strategic disruption.
Lee believes cybersecurity will remain a hot field, but the jobs will change as AI automates some tasks and creates demand for people who can secure, architect, test, red-team, and govern AI-driven systems.
Takeaways
AI agents can be powerful, but the more access they receive, the more important governance, trust, monitoring, and access controls become.
People should treat sensitive AI inputs like they treat financial data: only share what they are comfortable potentially being exposed if the system or company is compromised.
Cybersecurity is moving toward a world where automated adversaries face automated defenses, but Lee believes humans still need to stay in the loop for governance and control.
Bootstrapped companies can beat larger incumbents when they have credibility, speed, focus, and a willingness to take on technical debt temporarily to win the market.
Critical infrastructure security is a national security issue, because attacks on power, transportation, water, or industrial systems can be used to create disruption at a strategic level.
Closing Thoughts
Lee Rossey’s story shows what happens when deep national security research meets entrepreneurship. SimSpace was built from years of applied cyber work at MIT Lincoln Laboratory, but the company’s relevance has only grown as AI agents, automation, and critical infrastructure threats move into the mainstream. This episode is a warning and a roadmap: AI will transform cybersecurity, but trust cannot be assumed. It has to be tested, modeled, governed, and proven before autonomous systems are allowed to defend—or act for—the world’s most important organizations.
Today's Sponsors:
Start with Upwork, the one-stop platform to find, hire, and pay expert freelancers across marketing, editing, branding, development, operations, and more. Visit https://www.Upwork.com today to post your job for free and get matched with top talent ready to help your business grow. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.