Interviews
Rami Habal, Founder and CEO of Magnitude – Interview Series

Rami Habal, Founder and CEO of Magnitude is a veteran cybersecurity and AI product executive with a career spanning enterprise security, machine learning, consumer technology, and venture-backed startups. Before founding Magnitude, he served as an Entrepreneur in Residence at Ballistic Ventures and spent more than four years at Abnormal Security, including roles as Chief Product Officer and Chief Customer Officer. Earlier, Habal led the multi-device experience for Amazon Alexa, ran product at Reverb, and was one of the earliest employees at Proofpoint, where he helped build and commercialize security products as the company grew from a startup toward its eventual IPO. His career also includes experience in venture capital, mobile technology, APIs, and product strategy, giving him a broad background at the intersection of cybersecurity, AI, and enterprise software.
Magnitude is an AI-native cybersecurity company focused on transforming third-party risk management (TPRM) from periodic compliance reviews into a continuous security function. Its multi-agent platform uses specialized AI agents to assess vendors and products, continuously monitor vulnerabilities and other risk changes, map fourth-, fifth-, and deeper-party dependencies, automate vendor communications, and help manage remediation. Rather than relying primarily on questionnaires and point-in-time assessments, Magnitude is designed to reason against an organization’s own policies and provide evidence-grounded decisions with traceable sources and reasoning. The broader goal is to give security teams continuous visibility across increasingly complex software and supplier ecosystems while allowing human analysts to concentrate on higher-value judgment calls.
After helping build products at Proofpoint, Amazon Alexa, and Abnormal Security, what convinced you that now was the right moment to found Magnitude? Was there a specific realization or customer pain point that made you believe autonomous third-party risk management needed to become its own company?
I knew that after my time at Abnormal, I wanted to start a company. What I did not know was which problem was worth building a company around. Throughout my career, I have been drawn to applied machine learning products that address broad, universal needs, such as email security at Proofpoint, voice computing with Alexa, and behavioral security at Abnormal. I wanted to find another problem with that same kind of reach to help enterprises.
Then agents arrived. Having worked through the previous wave of machine learning, I could see that this was not just another product feature. It was a platform shift, and those do not come along very often.
While I was an entrepreneur-in-residence at Ballistic Ventures, I started speaking with CISOs about where that shift could have the greatest impact. Third-party risk came up repeatedly. Historically, it made sense for TPRM to sit inside the GRC function because vendor risk moved slowly enough for periodic reviews to keep pace. But that assumption was breaking down. Everyone agreed it was a major problem, but most organizations were still managing it with once-a-year questionnaires, spreadsheets, periodic reviews, and extensive manual work. The reaction was consistent: third-party risk management is critical, but we still do not have a good way to solve it.
That was the realization behind Magnitude. I knew the traditional model was no longer working, and we needed a technology capable of changing the operating model entirely, not simply making the old spreadsheet-driven process a little faster. From the beginning, my view was that every supplier would eventually have a swarm of agents continuously evaluating the risks surrounding it. Magnitude grew from that belief.
You describe the arrival of the “Mythos era,” where AI can identify and weaponize vulnerabilities faster than humans can react. What changes have you observed over the past year that convinced you this shift is already underway rather than being a future concern?
The biggest change I’ve seen is how quickly these attacks now happen. A year ago, much of the conversation was still about what AI might eventually enable an attacker to do. Now we can see those capabilities taking shape in real time. AI can help an attacker examine a much larger software ecosystem, discover weaknesses that might previously have been unknown, and attack those weaknesses at a scale that would be difficult for a human team to match.
In the Mythos era, AI systems have demonstrated the ability to surface more than 2,000 previously unknown flaws across software ecosystems, and the median time from vulnerability discovery to weaponized exploit is projected to fall under one hour by the end of 2026. While the time between discovery and weaponization continues to shrink, that creates a gap between how quickly exposure can appear and how quickly traditional review cycles can respond.
We’re also seeing the incident pattern move in the same direction. In our analysis, the frequency of supply-chain attacks increased from roughly 13 incidents per month in 2024 to 41 per month in 2026. We’ve noticed that activity is rising alongside major improvements in frontier models. I would not claim that every model release directly causes more attacks, but the trend is difficult to ignore. The tools are becoming more capable as the pace of attacks accelerates.
What really confirms this change for me is the conversations I’m having with security leaders. They are no longer talking about third-party risk as something that can be handled through an annual review and revisited at renewal. They feel exposed in the months between those reviews because their vendors, software dependencies, and downstream suppliers are constantly changing.
That is what the Mythos era means to me. The window to understand and respond to risk is narrowing, while the potential impact of a single compromised supplier is widening. A periodic compliance process simply was not designed for that environment.
Many enterprises are rapidly deploying AI agents throughout their organizations. How should security leaders rethink governance when those agents increasingly interact with external vendors, APIs, and downstream dependencies?
The first thing security leaders need to recognize is that even an AI agent built inside the company may not be entirely internal. It could rely on an outside platform, a third-party skill via MCP, a service such as Google Drive, or other technology the organization does not directly control. And each of those providers may have suppliers of its own.
It is no longer enough to approve the agent itself. Leaders need to understand what information it can access, what actions it can take, which outside services it depends on, and when human approval is required. They also need to understand how those dependencies can change over time as the agent gains new capabilities, connects to new systems, or begins relying on additional downstream providers. Those controls also cannot be set once and forgotten. As an agent gains new capabilities or connections, its governance needs to adapt accordingly.
The goal should not be to slow down AI adoption. It should be to give companies enough visibility to use agents confidently. Governance has to become an ongoing security practice, rather than a one-time approval completed when a new tool is introduced.
Third-party risk management has traditionally relied on questionnaires and periodic reviews. Why do you believe that model fundamentally breaks down in an AI-driven environment?
The problem with the traditional TPRM model is that it provides a snapshot of what a vendor said was true at a specific point in time. A company may complete a questionnaire when it is first approved and then not be reviewed again until renewal, which could be years later. In the meantime, its technology, security practices, AI models, data use, and suppliers may all change. We can barely predict what will change over the next few weeks, so relying on a years-old assessment no longer makes sense.
There is also a question of how trustworthy the information is. A reported answer entered by someone trying to move a deal forward is not the same as a fact supported by an independent audit, a signed company filing, or another verifiable source. Security leaders need to know not only what the answer is, but where it came from and whether it is still current.
Finally, questionnaires usually stop at the direct vendor. They rarely show the Nth parties, even though those hidden 4th- and 5th-party relationships can create real exposure. Attackers now know that an enterprise’s weakest link isn’t the enterprise, it’s one of these downstream vendors. And attacking those vendors can ultimately give them access to the enterprise. It’s simply cheaper and easier.
That is why I do not think the answer is simply to use AI to complete questionnaires faster. In that model, there will always be gaps. The model itself has to change, from periodic, self-reported snapshots to a continuous, real-time, evidence-based understanding of risk as deep as a company’s supply chain goes.
Magnitude introduces the concept of an autonomous AI workforce for security teams. Where do you see the balance between AI-driven decision making and human oversight, particularly for high-impact security decisions?
Autonomous does not have to mean unaccountable. The way I think about it is that AI should handle the critical but repetitive work that consumes so much of a security team’s time, while people remain involved when a decision requires judgment, context, or carries significant business consequences. The fact is that no security team has enough resources today to handle the current charter. AI can help fill that gap.
The quality of the AI matters enormously. When it is done well, AI is a force multiplier. It gives a team more capacity and helps people focus on higher-value work. When it is done poorly, it has the opposite effect because someone has to double-check every output. For high-impact security decisions, the system should be high quality and be able to show what evidence it used and how it reached its recommendation, creating an auditable record.
The right level of oversight will also vary by organization. A large company with an established security team may use AI more like an autopilot, with people supervising the work and stepping in for exceptions. A smaller organization may choose to automate more of the program because it lacks the staff or budget to build a large team. In either case, there should be clear points where an issue is escalated to a person.
Ultimately, the organization should be able to decide how much human involvement it wants based on the importance of the decision. The goal is not to remove people from security. It is to help them make better use of their time, make faster business decisions, and reserve human attention for the decisions where it adds the most value.
Your team brings together expertise from AI, cybersecurity, and consumer-scale platforms. How has that combination influenced the way you’ve designed Magnitude compared to traditional cybersecurity products?
Each of our backgrounds taught us something different about what an AI security product has to do well. In cybersecurity, an answer is only useful if you can trust it, trace it back to evidence, and act on it. From our work in AI and machine learning, we learned that the real opportunity is not simply to summarize information, but to turn expert work into a system that can perform that work consistently. Building platforms such as Alexa and Pandora taught us to think about reliability and usability at a very large scale.
Those lessons led us away from the traditional cybersecurity model of producing another dashboard or another stream of alerts for an already stretched team to investigate. We designed Magnitude to carry out the work: gather and verify information, assess suppliers, monitor changes, connect new information to business risk, and help move issues toward resolution.
Behind the scenes, that involves multiple specialized AI agents working together. But the customer experience should remain straightforward. Security teams should not have to become AI experts to understand what the system found, why it matters, or what action to take.
The result is a product designed to operate continuously across thousands of suppliers while still meeting the standard required for high-impact security decisions. It is not AI added onto an older workflow. It was built from the beginning around the idea that AI can perform much of the workflow itself, while giving people the evidence, visibility, and control they need.
One of the biggest concerns surrounding AI in cybersecurity is that it empowers both defenders and attackers. Do you believe the advantage currently lies with defenders or adversaries, and what will determine who stays ahead over the next few years?
I think the advantage today tilts toward adversaries, particularly in supply chain attacks. I would not say defenders are hopelessly behind. The call to action for defenders is to stop treating this like a future problem and move faster now. Both sides have access to many of the same AI tools, but the economics and time-to-market currently favor the attacker.
AI makes it cheaper and easier to test more attack paths, launch more attempts N-levels deep, and repeat that process at scale. When an attacker compromises a widely used supplier or software component, one successful attack can spread to hundreds or even thousands of companies.
Defenders have the harder job because they must understand and protect a large network of vendors, software components, and downstream suppliers, and it also takes time for enterprises to react, procure software that helps, and operationalize those tools, which creates a window attackers can exploit.
What determines who stays ahead will be whether defenders can change that equation. They need to move beyond occasional reviews and manual follow-ups toward continuous monitoring and faster action. Automated governance and defense systems that continuously monitor for changes, link them to business risk, and can respond quickly will make attacks harder to scale and more expensive to repeat.
Cybersecurity has always been a cat-and-mouse game. AI does not change that, but it does increase the speed and the stakes. Defenders need systems that can learn, adapt, and act at the same tempo attackers are beginning to operate.
AI supply chains are becoming increasingly complex, with organizations relying on numerous foundation models, SaaS vendors, and autonomous agents. Which emerging risks do you think enterprises are still underestimating?
The most underestimated risk is the technology sitting behind the product a company believes it has approved. Even an internally built agent may depend on outside platforms, plug-ins, contractors, or software components. Those hidden relationships create Nth-party risk, the suppliers behind a direct supplier.
Most enterprises still have very little visibility into that deeper layer. They may know who they signed a contract with, but not every outside service, software component, or subcontractor that ultimately supports the product.
The other issue is how connected these systems have become. A weakness in one plug-in or supporting service may not stay isolated to that provider. It can create a path into a larger platform and then affect many organizations that rely on it. That means a relatively small supplier can become a much larger source of exposure.
So the risk leaders should be asking about is not simply, “Which AI model are we using?” It is, “What does this system depend on, what do those providers depend on, and how would a problem anywhere in that chain reach us?” Until companies can answer those questions, they will continue to inherit risks they cannot see.
Looking beyond today’s large language models, what technological developments over the next five years do you expect will most significantly reshape enterprise cybersecurity and risk management?
I do not think the defining change will be one new model. It will be the move from AI that answers questions to AI systems that can continuously observe what is happening, connect information from different sources, and take action.
The next generation of models will not be just a little better; they will be much more capable. But the bigger shift will come from specialized agents working together across security operations. Today, vendor reviews, threat information, business risk, and remediation are often managed in separate tools and by separate teams. Over time, those functions will start to come together.
I expect security systems to become far more connected, bringing threat information, business context, company policies, and response actions together rather than managing them in separate tools. It could recognize that a supplier has been exposed to a new threat, understand which parts of the business may be affected, and help start the response without waiting for several manual handoffs.
That will change risk management from a series of periodic exercises into a continuous operating capability. The strongest risk programs will be built around enterprise context, reliable evidence, and the ability to turn information into trusted action.
If you could offer one piece of advice to CISOs and enterprise leaders preparing for the next generation of AI-powered threats, what would it be and what actions should they prioritize today?
My advice would be to stop managing supply chain risk as a once-a-year exercise. Risk changes continuously, and your approach needs to keep pace. The environment is living and breathing. It’s too connected, and it changes too quickly for a series of separate reviews and tools to keep up.
How you protect this emerging attack surface is with a single AI-native control plane for continuous, autonomous governance and defense for all your external risk.
The place to start is with the parts of the business that matter most. Identify the suppliers and outside services supporting those critical operations, understand where the hidden dependencies are, and establish clear ownership for what happens when risk is found. Then automate as much of the ongoing monitoring and routine response as possible, while keeping people involved for decisions with major business consequences.
The goal is not simply to collect more information. It is about continuously connecting what you know, deciding what matters, and taking action before a supplier issue becomes a company-wide problem.
Thank you for the great interview, readers who wish to learn more should visit Magnitude.












