Craig Adams is a seasoned cybersecurity product leader with over 20 years of experience building and scaling industry-defining tools. Having served as the Chief Product Officer at Rapid7 and Chief Product and Engineering Officer at Recorded Future, Craig has steered some of the most prominent teams in enterprise tech through massive evolutionary shifts. In this episode, we unpack how the age of AI has fundamentally rewritten the roles of product management, user experience, and software engineering. Craig challenges the "SaaS apocalypse" narrative, explains why AI-generated code will cause an exponential explosion of vulnerabilities, and argues why human information security teams will actually grow in size to handle the complex, agentic future of tech.
In our in-depth discussion, Craig shares:
00:04:01 - Why the traditional waterfall requirements document is dead in the age of AI.
00:05:40 - How the role of the software engineer is transitioning to architectural oversight.
00:06:19 - The core strategy differences between running B2B and B2C product management.
00:07:28 - The merging lines between PM and UX design systems.
00:08:58 - Why the role of the prompt engineer has already gone out of fashion.
00:10:06 - Walking the floor at RSA and the problem with copycat cybersecurity marketing.
00:12:03 - The shift from SEO to AEO (AI Engine Optimization) for scraping agents.
00:13:12 - The rise of sandbox-driven trial loops and the death of human-led software demos.
00:14:46 - Buying enterprise AI subscriptions purely on self-serve product value.
00:16:13 - Facing the "Mythos" vulnerability hype and how AI disrupts raw discovery.
00:19:23 - Why putting 5x more findings into a discovery bucket is an unsustainable model.
00:21:52 - Reframing the cybersecurity dilemma as an implementation problem.
00:22:59 - How AI is binarily decreasing the time to exploitation for attackers.
00:25:00 - A religious-level conviction that the number of human defenders will grow, not shrink.
00:27:35 - Why entry-level information security roles are in the center of the AI bullseye.
00:29:48 - The new reality of writing functional exploits using simple natural language prompts.
00:32:31 - Debunking the idea that AI-generated code will plateau software exposures.
00:33:32 - Shifting defender terminology to focus on "toxic combinations" rather than simple patching.
00:35:13 - Redefining SaaS software: Either you embed AI or you get replaced by it.
00:36:06 - Navigating the inequality between well-funded banks and under-budgeted municipalities.
00:39:49 - Why security teams who block AI usage will ultimately hinder their enterprise.
00:40:14 - Moving past the chatbot era of 2023 into true automated agency.
00:41:57 - The dramatic leapfrog analogy: Treating the adoption of AI like switching from mail to email.
00:44:23 - Dismantling the platformization myth of "one security platform to rule them all."
00:45:47 - The thesis behind why the next trillion-dollar tech giant will be a services organization.
00:48:00 - Predicting a renaissance of software-like margins inside the IT services industry.
00:49:56 - Automating lower-value tier-one analyst tasks to focus on higher maturity journeys.