IT Tech Pulse Exclusive Interview with Lee Rossey CTO and Co-Founder of SimSpace
Stay updated with us
Sign up for our newsletter
Lee Rossey, Co-Founder & CTO of SimSpace, explains how defense-grade cyber testing, AI-driven simulation, and continuous validation help organizations strengthen security readiness in the era of agentic AI.
You spent 15 years at MIT Lincoln Laboratory building the Cyber System Assessments Group into a nationally recognized center of excellence – what was the defining moment that made you leave that legacy behind and co-found SimSpace in 2015?
SimSpace was founded as a natural extension of the work we were doing at MIT Lincoln Lab (MITLL). I joined MITLL in 2000, and at that time, cybersecurity wasn’t even a recognized term — it was still referred to as information operations — but the bedrock principles were much the same as they are today. We worked closely with all major branches of the military to develop technologies that could be used to simulate the operational readiness of everything from air and missile defense to space control, and most of the technologies we developed at MITLL were then adapted for frontline deployment by shops such as DARPA; there weren’t many outfits in the private sector that were developing these technologies.
One of the most influential aspects of MITLL that continues to underpin the work we do at SimSpace is the strong emphasis on measurement and evaluation. We needed an in-depth technical understanding of the challenges facing the military at that time, but we went beyond the theoretical and really pushed these technologies to their limits. The emphasis was always on creating rich, highly realistic testing environments to provide us with the datasets we needed to solve the most challenging technical problems facing the national security community.
By 2015, the work we were doing at MITLL had become considerably more sophisticated. The technology was advancing rapidly, and the teams working on these problems had matured alongside them. At that time, it made sense for us to spin off our efforts into a new company, which is how SimSpace began, and the cultural emphasis on measurement, evaluation, and testing still strongly informs how we operate today.
SimSpace is now powering USCYBERCOM’s Persistent Cyber Training Environment and serving militaries and enterprises globally – how does your defense-grade background directly shape the way SimSpace approaches commercial cybersecurity today?
When we started out, we tested weapons systems for US Cyber Command, then shifted to training when Persistent Cyber Training Environment became a customer. Our focus has always been on testing, but our initial commercial focus was training.
There’s an adage in the military that says you should “train like you fight,” and this principle is central to everything we do at SimSpace. Take fighter pilots, for example. Air Force pilots undergo countless hours of highly realistic simulator training before engaging in live training exercises, but the best way for fighter pilots to learn and improve is by getting in that cockpit and experiencing how the aircraft handles during a high-pressure situation. At SimSpace, we create those high-fidelity environments for our clients so they can safely and confidently develop technologies and implement defenses that reflect the true threats facing their organizations.
Securing the nation’s nuclear munitions stockpile is very different to protecting proprietary financial information, for example, but the fundamental principles of operational readiness apply equally to both. Everything begins with a detailed understanding of the actual risks facing an organization and gathering the data necessary to design effective security protocols. When we started SimSpace, one of the biggest challenges facing enterprises in the private sector was the lack of data to adequately test security systems. Companies simply did not have access to the kind of datasets their technologists needed to truly evaluate their defenses or develop new technologies to improve their preparedness. This remains a major problem for many enterprises today, especially for our clients in highly regulated industries such as finance and healthcare, which is why hyper-synthetic data (HSD) will be a critical growth area in cybersecurity over the next several years.
Your State of Agentic Cybersecurity report reveals a striking paradox – 78% of security leaders feel confident in their defenses, yet real-world simulation scores are falling as low as 30%. What does that gap tell you about how organizations are misunderstanding what “readiness” actually means?
There is a significant disparity between security leaders’ perception of their agentic defenses and the operational reality of what those technologies can accomplish today. In the past, security practitioners had years to adapt to new technologies. Now, they have months, if not weeks, which fundamentally changes the nature of “readiness” in any organization. It’s no longer enough for security leaders to be proactive about securing their networks; they must be preemptive in their defenses, which means testing for novel threats that have never been seen before.
Many organizations are deploying agentic cybersecurity solutions to production environments without fully understanding their true capabilities, which can create considerable vulnerabilities in itself. One of the biggest challenges is understanding the human element. It’s important to evaluate technical weaknesses in a network to understand potential attack vectors, but how human security operators respond to an intrusion is an entirely different animal. We have found that while there is often a discernible decrease in defensive readiness when implementing new technologies, this decline typically reverses with frequent testing. This is why we advise our clients that agentic cybersecurity is as much a cultural challenge as it is a technical problem.
The report finds that 44% of organizations test biannually or even less – yet AI threats operate 24/7 continuously. How dangerous is that mismatch, and what’s the minimum testing frequency you’d consider responsible in today’s threat landscape?
Infrequent testing is one of the most critical vulnerabilities we see across the enterprise. Teams need to test so frequently because the landscape has evolved so much (think Mythos / Daybreak), to the point that the latest AI models are making it so AI attacks can move laterally within seconds. Even the most sophisticated technical capabilities are of little use if organizations are only testing their defensive posture twice a year, and conventional training programs are just hopelessly inadequate in today’s risk environment.
No two organizations will have precisely the same testing needs as one another, even within the same industry, vertical, or sector. That said, many organizations can benefit from rigorous quarterly testing, with monthly evaluations being preferable in many situations. The more confidently human operators can respond to emergent threats, the safer their organizations will be.
You’ve pointed out that most AI agents being deployed today are assistive, not fully autonomous – yet organizations aren’t rigorously testing even those. Why do you think enterprise leaders are placing so much trust in human-in-the-loop oversight rather than building structured validation frameworks?
Part of the reason why enterprise leaders are placing so much trust in “human-in-the-loop” oversight, rather than building structured validation frameworks, is due to hesitancy about the capabilities of agentic cyberdefenses and, to a lesser extent, the need for individual accountability. Agentic solutions can be remarkably powerful, but they cannot be held responsible in the event of a major intrusion event.
There is little doubt that truly autonomous cyberdefense is coming, but we’re still some time away from that level of automation. For the time being, understanding and preparing for how human security operators can interact with agentic solutions is still a priority, so the organizational preference for human-in-the-loop oversight isn’t necessarily the incorrect approach. The bigger risk is how human security teams respond to novel threats that have never been seen before in real crisis situations, which is why regular testing is so crucial.
SimSpace positions itself as the “AI Proving Grounds for cybersecurity” – a compelling phrase that sets you apart from traditional cyber range vendors. Can you walk our readers through what a real proving ground session looks like and the kind of outcomes teams walk away with?
SimSpace provides three core offerings to our clients: building and training agents using hyper-synthetic data, validating and testing those agents, and operationalizing agents alongside human security teams.
When building and training agents or validating and testing agents for our customers, we begin by creating a digital replica of the client’s IT environment. This includes everything from specific operating systems and server architectures to endpoint tools and simulated benign network traffic. Attacks are then simulated in this replica environment to demonstrate what a likely breach scenario would look like, from simulated ransomware attacks to lateral movement intrusions. Log data from the simulated attack is exported to train agent models and measure model performance, and this process is repeated over time to provide customers with real data on their most urgent vulnerabilities.
Building and training agents using hyper-synthetic data helps customers accelerate time-to-value and optimize agentic performance. This is important because Squeaky clean data is insufficient in training agents for real-world scenarios, and organizations can train with real customer data without risking customer PII. Validating and testing agents gives security leaders confidence that the most critical vulnerabilities facing their networks are mitigated, and increases trust in AI functionality and agentic decisioning. Perhaps most importantly, teams using SimSpace walk away knowing how they responded to real-time intrusion scenarios, how various technologies worked together, and specific actions they can take to improve.
For the security engineers and IT professionals reading this today – many of whom are being asked to integrate AI tools into their SOC with limited time and budget – what’s the single most practical step they can take right now to start closing the readiness gap?
The most effective steps security practitioners can take when integrating agentic solutions into their SOC is to truly understand the threats facing their networks, and to evaluate their readiness through frequent training. Hugging Face just happened, and Mythos and Daybreak are still on people’s minds. The best fighter pilots in the world log thousands of hours of flight time to understand the pressures facing them and their aircraft in combat situations, and cybersecurity professionals should view their practice in the same way.
It’s also important for operators to be realistic about the current capabilities of agentic cyberdefenses. AI technologies are developing rapidly, but for the time being, there is simply no substitute for human expertise.
As we move deeper into 2026, autonomous agentic AI is shifting from concept to deployment – where do you see the biggest trust crisis emerging between security teams and AI agents, and how should the industry prepare before it becomes a breach headline?
One of the biggest risk factors facing many organizations is overconfidence in agentic capabilities, and deploying unproven technologies to production. It’s vital that security leaders understand the limitations of agentic cyberdefenses, as well as how their teams interact with these agents under pressure.
It’s only a matter of time until we see another major breach make the headlines, especially as agentic cyberdefenses assume greater control over mission-critical functions, and confidence in agentic decisioning remains a significant concern in today’s risk environment. It’s crucial to understand likely attack vectors, but it’s just as important to understand why agents made the decisions they did during an intrusion event.
Thank you,Lee Rossey, for taking the time to share your insights with us.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.
Lee Rossey co-founded SimSpace in 2015 after leading cyber range and red team programs at MIT Lincoln Laboratory and advising the Department of Defense on national cyber infrastructure. As CTO, he built SimSpace into the AI Proving Grounds, where human operators and AI agents train and test together in realistic replicas of production environments.
Allied governments, militaries, commercial and enterprises worldwide trust SimSpace as the AI Proving Grounds where human operators and AI agents train and test together in a realistic replica of their production environments to outperform and outsmart any adversary in any terrain.To learn more, visit: www.SimSpace.com.