Designing Security for the Way Work Happens Today
Existing security tools are good at telling organizations what happened and being reactive. Elias Manousos, co-founder and CEO of Ent, believes the harder problem to solve is moving the industry back to prevention. He talks about going back to first principles where the key to preventing the risk before it becomes an incident lies in understanding intent behind the actions, be it human or agent. He shares the experiences that led to the founding of Ent, lessons from decades in cybersecurity, and the future of modern work.
For most of its history, security has been organized around a single question: what happened? Elias (Lou) Manousos believes the next evolution of security is understanding why it happened.
For decades, cybersecurity has improved at detecting attacks, investigating incidents, and collecting evidence. Organizations have more telemetry and visibility than ever before. Yet security leaders face the same challenge: by the time risk is identified, the incident has already happened.
Lou has spent much of his career helping organizations solve difficult security problems. Across threat intelligence, attack surface management, AI copilots, and enterprise security platforms, one theme has remained constant for Lou.
The goal is not simply to understand what happened.
The goal is to understand why it happened, and to prevent what happens next.
That belief ultimately became the foundation for Ent, the intent-aware Workspace Security platform designed to help organizations understand risk and move from reactive detection to preventive security.
When the technology finally caught up
The idea behind Ent started years before the company itself.
While helping build Microsoft's first security copilot, Lou found himself returning to a problem cybersecurity has struggled with from the start: prevention.
Security teams had become increasingly good at detecting attacks and investigating incidents after they occurred. But the question that stayed with him was whether AI could finally help stop threats before they happened.
"It got me thinking the real problem that we've been trying to solve in cybersecurity since the very start is one of prevention."
The vision was clear. The technology was not.
Five years ago, enterprises were still figuring out how generative AI fit into everyday work. Endpoints couldn't run sophisticated models locally. Response times weren't fast enough. Most users weren't ready to rely on AI as part of their security experience.
Then the landscape changed.
Local AI models became practical. Copilot installed hardware emerged. Sub-second inference became possible. More importantly, AI became part of everyday work.
"And that's when we realized this great idea that we had five years ago is actually doable now."
The technology had finally caught up with the vision. It was time to build.
The partnership behind the company
Long before Ent, Lou and Brandon had spent years building security products together through some of the industry's biggest shifts, from threat intelligence and attack surface management to AI-powered security.
Their partnership began when Brandon co-founded PassiveTotal, a community-driven platform that helped security teams use DNS intelligence to track adversaries.RiskIQ acquired the company in 2015, bringing Brandon into the organization and beginning a collaboration that would span more than a decade.

Together, they helped build RiskIQ into a leading threat intelligence company before joining Microsoft through acquisition. There, they worked on Defender Threat Intelligence, attack surface management, and one of the industry's earliest security copilots.
Those experiences gave them a front-row seat to how security was evolving and where it continued to fall short.
For years, both had helped organizations detect attacks, investigate incidents, and respond to threats. Ent was the chance to move beyond reactive security to more of preventive security.
"Brandon and I have been at this a long time, and we work really well together. That's what makes a great team."
What unites them isn’t just years of experience. It is the shared belief that security has to move beyond understanding what happened and get better at preventing what happens next.
Shift to the new control point
As AI agents become part of everyday work, security faces a new challenge.
Agents move faster than humans. They create more data, access more systems, and take actions on behalf of users at a speed and scale security teams have never had to manage before.
During early conversations with customers and industry leaders, Lou kept returning to a fundamental question: where should security operate in a world where humans and agents work side by side?
"We concluded that that control point will be at the endpoint or at the edge. That's the natural place where a human will task an agent."
That insight became one of Ent’s foundational ideas.
The endpoint isn't just another security layer. It is where work happens, where users take decisions and increasingly where agents receive instructions and act.
If organizations want to understand risk before it becomes an incident, Lou believes security needs to operate at the same place where intent originates.
Understanding why, not just what
Throughout his career, Lou built systems to detect attacks and respond to incidents. He kept hitting the same limitation.
Most security tools excel at telling what happened.
Few can explain why.
That distinction mattered long before AI entered the picture. Security teams have spent years trying to solve problems like insider risk, data loss, and human mistakes, where context matters more than the action itself.
As AI systems began acting on behalf of users, it mattered even more.
Whether the action comes from a person or an agent, intent provides the context that traditional security controls lack.
"Legacy security products are based on deterministic outcomes and look for the wrong things. They look at what happened and not why it happened."
For Lou, understanding intent wasn't simply another security signal. It became the foundation upon which Ent was built, and the opportunity to build the system Lou and Brandon wanted to for years.
"The system that we've always dreamed of building is one that can protect the entire end-user attack surface from any threat, whether that's an insider threat, intentional or unintentional data leakage, a phishing attack, unauthorized software, or malware, all classes of attacks in one unified endpoint."
The vision wasn't to solve one security problem. It was to create a platform capable of understanding and preventing risk across the entire end-user attack surface.
The future of intent-aware security
The security challenges organizations face today are evolving rapidly as AI reshapes work.
Work happens across more applications, data moves faster and across broader systems, and AI tools increasingly act on behalf of users.
Lou believes the next major transformation will happen at the operating system level.
Today, most AI systems function as applications layered on top of operating systems built for humans. As agents become more autonomous, that model will change. Future operating systems will increasingly be designed for both humans and agents working side by side.
As agents gain access to files, applications, memory, and enterprise data, organizations will need new ways to understand and govern their actions. Deterministic controls will struggle to keep pace with software that can reason, act, and make decisions on behalf of users.
This shift has profound implications for security.
This is where intent becomes critical.
Understanding what happened will matter. Understanding why will become the different between reacting and preventing.
As the boundaries between users and AI systems continue to blur, Lou believes the endpoint will remain the place where work, decisions, and risk converge.
Watch the full interview with Lou Manousos for a deeper discussion on the future of workspace security.
Resources
To learn more about Ent and our vision for securing human and AI-driven work, visit ent.ai.
To talk to us and see our product in action, schedule a demo.