Arcovo’s Bodungen on broken governance and MindStone agent
Arcovo AI/ML chief Clint Bodungen blames governance failures for cybersecurity breakdowns, unveils open-source MindStone Agent and describes AI agents used in a ransomware response.
In an exclusive podcast interview conducted recently, Clint Bodungen, director of AI/ML engineering at Arcovo and founder of ThreatGen, said broken governance, rather than technology, drives many cybersecurity failures. He introduced MindStone, an open-source agentic AI project, and described a ransomware response that used autonomous AI agents with limited human oversight.
Bodungen argued governance frameworks often do not match operational reality, creating gaps between policy and the personnel who must apply it. He stated, “the biggest vulnerability is people, not technology.” He traced changes over roughly two decades in defensive tools and attacker behavior, citing increased automation and scale in attacks.
MindStone is an agentic architecture designed to give AI assistants persistent memory, identity and continuity across tasks. Persistent memory lets an assistant retain context between interactions. A consistent identity helps agents coordinate multi-step processes without repeated handoffs that slow responses.
Bodungen recounted a ransomware case where multiple autonomous agents handled separate response tasks. The agents coordinated containment, ran forensic analysis, managed recovery steps and executed infrastructure migration. Human operators monitored and validated key decisions while the agents performed routine and repeatable actions.
He framed MindStone and similar agentic systems as tools to augment operational teams by maintaining continuity that short-lived conversational assistants do not provide. He added that changes in governance and operations are needed to ensure safe and effective deployment of these tools.
Bodungen’s experience in industrial cybersecurity informed his remarks about operational pressures and defender needs. The interview is connected to sessions at the ICS Cybersecurity Conference in Nashville that focus on industrial control systems security.








