Daniel and Lee Rossey, CTO and Co-Founder of SimSpace, open with the explosion of AI agent companies and the growing comfort people have with giving these systems access to business tools, financial data, credit cards, and personal information. Lee warns that the benefits are real, but so are the risks: every company eventually faces compromise, and users should assume that any sensitive data they feed into these tools could someday get exposed. From there, the conversation moves into agent-to-agent communication, governance, AI guardrails, MIT Lincoln Lab, bootstrapping SimSpace, cyber ranges, critical infrastructure, and the future of cybersecurity jobs in an AI-driven world.
Key Discussion Points
Lee explains that AI agents can create real productivity benefits, but users need to be honest about the risk of putting sensitive information into systems that may eventually leak or be hacked.
He compares the early AI-agent era to the early days of social media, when people shared everything first and only later realized the privacy and security consequences.
Lee says the AI boom has created real opportunity but also massive hype, with nearly every company now claiming to use AI agents regardless of whether the product is truly differentiated.
He explains that the future is not single-agent AI but multi-agent systems, where agents communicate with other agents and act on behalf of people or companies.
Once AI agents begin acting on someone’s behalf, Lee says the key questions become governance, controls, role-based access, boundaries, and guardrails.
Lee predicts a growing market around monitoring AI agents, preventing data leakage, controlling access, and keeping autonomous systems inside trusted lanes.
He shares his experience at MIT Lincoln Laboratory, where he worked on applied research tied to national security, including cyber defense, offensive cyber questions, DARPA-style technology, and government cyber capabilities.
Lee explains how he and his co-founder Hutch, an F-15 fighter pilot, tested their chemistry and technology through early projects before spinning SimSpace out of the lab.
He describes SimSpace’s bootstrapped early years, using government contracts, credibility, speed, and long nights to compete against large defense contractors and well-funded companies.
Lee explains why cyber ranges and digital twins matter: they allow organizations to model realistic environments, test defenses, train teams, and validate whether systems can withstand attacks.
He says AI has accelerated the urgency of SimSpace’s work because major companies cannot simply replace cybersecurity teams with autonomous agents without testing, vetting, and proving those agents are safe.
Lee explains that modern cybersecurity must assume breach. The real question is not whether someone can get in, but how fast a company can detect, respond, recover, and limit damage.
He warns that AI is being weaponized across the cyber kill chain, from finding vulnerabilities to mapping networks, moving laterally, communicating back to attackers, and executing a final objective.
The conversation also covers critical infrastructure, including power grids, airports, industrial systems, and operational technology, where attacks may be less about money and more about strategic disruption.
Lee believes cybersecurity will remain a hot field, but the jobs will change as AI automates some tasks and creates demand for people who can secure, architect, test, red-team, and govern AI-driven systems.
Takeaways
AI agents can be powerful, but the more access they receive, the more important governance, trust, monitoring, and access controls become.
People should treat sensitive AI inputs like they treat financial data: only share what they are comfortable potentially being exposed if the system or company is compromised.
Cybersecurity is moving toward a world where automated adversaries face automated defenses, but Lee believes humans still need to stay in the loop for governance and control.
Bootstrapped companies can beat larger incumbents when they have credibility, speed, focus, and a willingness to take on technical debt temporarily to win the market.
Critical infrastructure security is a national security issue, because attacks on power, transportation, water, or industrial systems can be used to create disruption at a strategic level.
Closing Thoughts
Lee Rossey’s story shows what happens when deep national security research meets entrepreneurship. SimSpace was built from years of applied cyber work at MIT Lincoln Laboratory, but the company’s relevance has only grown as AI agents, automation, and critical infrastructure threats move into the mainstream. This episode is a warning and a roadmap: AI will transform cybersecurity, but trust cannot be assumed. It has to be tested, modeled, governed, and proven before autonomous systems are allowed to defend—or act for—the world’s most important organizations.
Today's Sponsors:
Start with Upwork, the one-stop platform to find, hire, and pay expert freelancers across marketing, editing, branding, development, operations, and more. Visit https://www.Upwork.com today to post your job for free and get matched with top talent ready to help your business grow.
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.