CXO Spotlight · 2026-05-20 · 45 min
Key moments - from our scoring
Substance score
60 / 100
Five dimensions, 20 points each
Nidhi Aggarwal, Chief Product Officer at HackerOne, unpacks the seismic shift in cybersecurity created by AI-driven vulnerability discovery. HackerOne manages 2 million security researchers and distributes $81 million annually in bounties to enterprises including Goldman Sachs and the Department of Defense. The core tension: autonomous AI agents are now discovering zero-day vulnerabilities at machine speed - the window from CVE disclosure to active exploitation has collapsed from 23 days last year to just 20 hours - while OpenAI's release of a cyber-specific model has CISOs scrambling. Aggarwal articulates why traditional security assumptions (sparse attacks, time for remediation, reactive postures) are obsolete and proposes a framework for CISOs: embrace continuous threat detection and remediation as architectural patterns, deploy AI agents across code and pipelines before adversaries do, adopt "vulnerability ops" (similar to DevOps), pursue bug-class elimination rather than whack-a-mole patching, and implement foundational controls (zero trust, network segmentation, phishing-resistant MFA) that neutralize theoretical vulnerabilities before they become real exposure. She argues that defense itself is now offensive strategy. Relevant for Fortune 500 CISOs, security leaders rethinking budgets, and boards questioning cybersecurity ROI in the AI era.
The zero-day clock - measured from CVE disclosure to active exploitation - collapsed from 23.2 days in 2023 to 20 hours by early 2024, meaning organizations now have hours instead of days or months to respond and remediate.
HackerOne combines agentic AI capabilities for discovery and validation with 2 million ethical researchers to identify not just theoretical vulnerabilities but real exploitable exposure, then prioritizes and guides remediation - providing validated, actionable vulnerabilities CISOs actually need to fix rather than overwhelming them with scanner noise.
Frame it around three layers: securing board attention (reference glasswing, Mythos, and Claude finding zero-days), shifting to continuous detection and remediation processes (moving from reactive to proactive), and emphasizing that a breach at their organization would make the Wall Street Journal, making cybersecurity a board-level business risk, not a technical cost center.
Yes, agentic systems now rank at the top of the leaderboard, but HackerOne separates individual hackers (with or without AI tools) from teams of developers building agents; human researchers with access to the latest AI models remain more powerful than agents alone because they apply adversarial creativity and business logic understanding that pure AI misses.
Deploy AI agents for continuous discovery across code and pipelines (matching machine-speed attacks), adopt vulnerability ops to automate the entire detection-validation-remediation loop (eliminating handoffs between teams), and implement foundational controls like zero trust, network segmentation, and phishing-resistant MFA that neutralize vulnerabilities before they become real exposure.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains several genuinely useful data points - most notably the zero-day exploitation window collapsing from 23.2 days to 20 hours, and the Mozilla vulnerability breakdown - but a substantial portion of runtime is consumed by the host restating what the guest just said and corporate-speak framing about 'continuous loops.' Insight-per-minute is dragged down by padding and cheerleading.
last year the time was 23.2 days. And yesterday morning I checked, it was 20 hours. That's the massive change.
out of the 122 vulnerabilities that were found, um, 14 were ah, high and um, critical. Um, and two of them could be validated inside of a sandbox. Both of them would have been stopped by existing security controls.
There are a few genuinely fresh angles - that biologists and physicists outperform traditional security researchers at jailbreaking AI models, and the concrete example that 122 AI-found vulnerabilities still resulted in zero true exposure due to existing controls - but the overarching thesis (AI accelerates both attack and defense, you need continuous testing and human+AI teaming) is widely circulated in the security space.
when we do uh, sometimes the AI uh testing we see a lot more like biologists and physicists testing and being more Successful at jailbreaking uh, the models than the traditional security researchers
out of the 122 vulnerabilities that were found, none of them represented true exposure. That's the power of defense.
Nidhi Aggarwal is a credible, high-caliber practitioner: PhD, HP Labs, McKinsey, founder of QwikLabs (acquired by Google), six patents, and now CPO at a major security platform with actual platform data to cite. She is not a career podcaster or generic thought leader - she speaks from direct operational experience and proprietary data.
I co founded QwikLabs with my uh, co founders and Qwiklabs was a cloud configuration management platform that allowed non technical people to configure the cloud very quickly
we were using the power of uh, AI scale. And that's the same theme that carries into HackerOne
The episode is unusually data-rich for a B2B podcast: platform metrics with release-correlated timelines, concrete vulnerability counts from a named product (Mozilla/Claude), exploitation window figures with a specific date reference, and named customer categories. Minor deductions for a few hand-wavy passages and some approximation language ('approximately 20%').
the volume of reports increased by 76%, just, uh, the raw volume. And that was closely aligned, uh, with the release of, uh, opus 4, uh, point 6
last year the time was 23.2 days. And yesterday morning I checked, it was 20 hours.
The host constructs decent scenario-based questions (the 'I am a CISO' framing is effective) and occasionally surfaces good follow-ups, but consistently spends more time summarizing and validating the guest's answers than probing or challenging them. The episode ends with a generic career-advice question, and there is no meaningful pushback on any claim throughout.
So if I am a CISO and my entire infrastructure just got X rayed by something, I cannot control what is structurally different about this moment?
I felt great. First of all, this is really, really valuable
Computed from the transcript - who did the talking, and the words that came up most.
Nidhi Aggarwal, Chief Product Officer at HackerOne, explains why the zero-day clock dropped from 23.2 days to 20 hours in a single year, why the entire CISO playbook is being rewritten around continuous defense, and what she is hearing from the CISOs at 20% of the Fortune 500 who are losing sleep over Mythos and autonomous AI hackers.Nidhi is one of the most uniquely qualified people to answer these questions. She co-founded a cloud platform that Google acquired. She holds six US patents. She has built products at McKinsey, HP Labs, and VMware. She now steers the AI roadmap at the platform that pays out $81 million a year to ethical hackers, manages over 2 million security researchers, and just watched an autonomous AI climb to number one on their own leaderboard.
Transcribed and scored by The B2B Podcast Index.
Chirag Khanjo: Now she's steering the AI roadmap at the platform that pays out $81 million a year to hackers and manages over 2 million security researchers and just watch an autonomous AI climb to number one on their own leaderboard.
Nidhi Aggarwal: Last year the time was 23.2 days. And yesterday morning I checked, it was 20 hours. That's the massive change. You don't have months, you don't have days, you have a few hours. And that clock is just ticking down relentlessly the same.
Chirag Khanjo: And then OpenAI released a cyber specific model and I find 250 CISOs were editing a war plan in the real time because they just heard that. So if I am a CISO and my entire infrastructure just got X rayed by something, I cannot control what is structurally different about this moment? That should change how as a ciso, I should think about this.
Nidhi Aggarwal: I always joke. Our um, customer list is if you think about somebody or if they had a security incident today would be on the front page of Wall Street Journal tomorrow. Like that's the kind of customer list
Chirag Khanjo: and it's almost like offense. This defense feels like offense to me.
Nidhi Aggarwal: Right? This defense is offense. Right. So be proactive rather than reactive. Even before Mythos and now with Mythos, right, they're more worried about, uh, the problem just exacerbating. Between January to March, report submissions went up by quite 3x compared to October to December of last year. So there was a 300% increase in the same time the duplicate reports, which means that the vulnerabilities that were being found, uh, went up from 22% to 47%.
Chirag Khanjo: I'm rethinking my security program with board and everyone. Like you said, I have the retention. How should I propose and put a proposition together that this is the right way to look at cybersecurity. Now what would that be? Welcome to CXO Spotlight. I'm your host Chirag Khanjo and today we are answering one of the most urgent question in cyber security right now. What happens when AI becomes the best hacker on the planet and the biggest target at the same time? To unpack this, one of the most uniquely qualified people in the world is here. Nidhi Agarwal, Chief product officer at HackerOne. She co founded a cloud platform that Google acquired, holds six US patent and has built products at McKinsey, HP Labs and VMware. Now she's steering the AI roadmap at the platform that pays out $81 million a year to hackers and manages over 2 million security researchers. And just watch an autonomous AI climb to number one on their own leaderboard. So this is going to be a fun conversation and super relevant one. Let's go. Welcome Nidhi, welcome to the show.
Nidhi Aggarwal: Thank you so much Chirag. Thank you for having me.
Chirag Khanjo: Awesome. Nidhi, you co founded a cloud platform that Google acquired later and you have been at several companies and you in fact built NLP tools uh for $1 trillion asset manager. That is not a typical path to running a product at a cybersecurity company. Tell us what pulled you into cybersecurity. What was the motivation?
Nidhi Aggarwal: Happy to uh and yes my path is very atypical but my path has really been shaped by one core question. How do you take very powerful tech and make it usable at scale? Uh so I started on the technical side PhD in computer science, uh, uh virtualization um at HP Labs and my thesis was also about uh, how do you build high availability systems using commodity components. So it started with that mindset of right, how do you take things that are commodity and make them usable and highly available. And uh, what I became interested in there uh, especially during my uh um when I was filing my patents was uh there was so much great tech at HP Labs. I was surrounded right I had the honor and privilege of working with some very talented uh scientists and researchers and the translation into real enterprise impact was uh not keeping pace with the right the ideas and the research uh that was being generated. Uh so I became very interested in that question uh, of what was the blocker uh and that led me to McKinsey, um, which um, like let me see the other side where I was advising large companies on cloud and data. These were the very early days of cloud. Um and I kept seeing the same gaps in the organizations very strong tech but low adoption M because it wasn't accessible right. At McKinsey we were at that time talking about uh, uh well uh, is the cloud safe, is it secure and how should we adopt it? Um so AWS was very early. So I uh co founded QwikLabs with my uh, co founders and Qwiklabs was a cloud configuration management platform that allowed non technical people to configure the cloud very quickly for their use cases. And it just so happened that uh, uh training, the developer training became its major use case uh where you could do hands on uh training on the platform. And surprisingly AWS became our first and largest customers. That's not what we were expecting because we went to them for a partnership and we thought like they know how to configure their Cloud it will be useful for other uh, uh tech companies and they were struggling with how to get their non technical departments to use uh, their own cloud. And so we launched our uh product at the first re inventory and with this um, use case. And from there it scaled broadly, it was worldwide and was eventually acquired by Google when they were struggling with the same problem. And I have focused on bringing data and AI into production in enterprise settings, uh, including at Tamer where we used AI and uh, human uh in the loop to integrate data at scale. Um these were again very early days, 2014 and it was at the scale of think 300 ERP systems. To answer a fundamental question. How many suppliers do you have? How many customers do you have? And we were using the power of uh, AI scale. And that's the same theme that carries into HackerOne where we are at a similar inflection point in security. AI is advancing very quickly but the real opportunity is in turning that into something enterprises can trust and operationalize at scale to drive measurable risk reduction by combining AI with human expertise so that you have the machine speed and scale but you have the human creativity, judgment and accountability to be able to drive real results. Real risk reduction, yeah.
Chirag Khanjo: For a lot of uh, our audience. I want to first do the level set about HackerOne. Right. For people who hear HackerOne and think bug bounties as the first thing. Right. What is it actually today? Because almost $81 million in bounties paid last but Goldman Sachs and Department of Defense is on your client list. That's not a side hustle for freelance hacker. It's a big deal. So can you first do a level set of who is and what is HackerOne?
Nidhi Aggarwal: Sure. Uh, HackerOne is a continuous threat exposure management platform that combines the power of agentic uh capabilities to drive uh, discovery, validation and remediation with the unique insights from the ethical researchers and humans in the loop who provide the creativity, judgment and accountability. And how this works in practice is say for example AI can provide the continuous testing for uh certain types of vulnerabilities. But our ethical researchers will provide the creative adversarial validation for the kinds of vulnerabilities that require uh, say business logic or like uh, kind of uh knowledge, the context and how real exposure uh manifests itself in a uh production environment where AI can uh, probably sometimes only look at the theoretical vulnerability. But that's where the adversarial creativity and what we do then is in our platform we are able to take all these different types of vulnerabilities and Use validation agents and uh, um, suite of agents that will validate whether this vulnerability is actually something that represents a true exposure. And can we use that combination of validation agents and our team of um, analysts who are highly specialized and experts in these kinds of vulnerabilities to say what vulnerabilities should uh, organization really care about? Because there can be a hundred thousand vulnerabilities. You've got like no CISO wants more vulnerabilities. They've got enough of them through their scanners. What they want is validated exposure. This is why Bug bounty was really powerful. Because what bug bounty told uh, the CISOs was this is a vulnerability that can actually be exploited out in the wild. And that's why those vulnerabilities went to the top of the heap for remediation on engineering's backlog. And that's the capability we are scaling now using AI in our platform, the Continuous Threat Exposure Management platform. And then we help them validate, prioritize it using again combination of AI and human. And given all of the context, we help find remediation, effective remediation guidance for the organizations. And one of the most powerful things right beyond this combination of AI and humans is we have worked with these enterprises. You mentioned Goldman Sachs, you mentioned Department of Defense. I always joke, uh, our customer list is if you think about somebody, if they were had um, a security incident today would be on the front page of Wall Street Journal tomorrow. That's the kind of customer list. It's a huge responsibility and it's a huge privilege that we work with these customers. We have um, approximately 20% of fortune, uh, 500 and uh, um, as our customer list, uh, 40% of fortune, uh, 50 and those kind of customers, we have a lot of context on how they think uh, about vulnerabilities, how do they manage them? Right. What are the kind of uh, uh, vulnerabilities and remediations that matter to them and a lot of insight into as they've been running these programs with us. Right. What kind of vulnerability reports have they seen in the past? So what actions should they take when a new vulnerability uh, comes uh, to fore? And that's something our customers value. Right. Some of our customers have gone on record and said some of our capabilities, our AI capabilities are like a teammate that remembers every report. So um, right, so hackerone of today, uh, combines the best of its history of bug bounty and the agentic capabilities with the latest models to help the customers have this continuous discovery, validation, prioritization and remediation loop. So that we are an end to end fine to fix uh loop for our customers.
Chirag Khanjo: Super, super. So I think we understand what HackerOne is but I want to talk about something which kept you busy all through last two weeks. We will not talk about the remediation yet. I want to first talk about the problem because it's important to understand the problem. Um, here is the way I see it. An AI just found out like zero day vulnerabilities in two weeks that the security teams could not find in a decade. Every major operating system, every major browser, uh the same week and then OpenAI released a cyber specific model and I find 250 CISOs side of you know kind of on were editing a war uh plan in the real time because they just heard that. So if I am a CISO and my entire infrastructure just got X rayed by something I cannot control what is structurally different about this moment. That should change how as a CISO I should think about this.
Nidhi Aggarwal: So m. One big thing that has changed is that entire security architecture or the defense was built on an assumption that we had time to remediate. Uh, there was assumption ah that between uh, when a vulnerability is disclosed to when it can be exploited. There was time. Um, the uh CISO of sysdig actually built uh something called a zero day clock and that is uh monitoring uh right. How much time we had on average between a CVE disclosure and exploitation and last year. Right. Even when we had right AI tools. Um last year the time was 23.2 days and yesterday morning I checked it was 20 hours. That's the massive change. So you don't have months, you don't have days, you have a few hours and that clock is just ticking down relentlessly for the time between discovery and exploitation. And that's the time you have to now move for remediation. So that's a fundamental change now uh, with models that are being released but even before remediation.
Chirag Khanjo: Think of this Nidhi that you met me at a uh, at a conference or you are the company that has been helping me. I trust your advice because of the wonderful background you have and I am a chief information security officer. I opened my laptop and I heard about Mythos and I heard about glasswing and now I know some exclusive companies got access to it and they were able to expose so many bugs that were not found forever. My first reaction is how do I prepare myself and even know where the problem is. Then I will plan remediation. Right. So how do you start advising them on here is how you should think about this. What's that part?
Nidhi Aggarwal: So one thing is proactively start looking for whatever models you have access to. So if you're part of Mythos Preview, if you have Project glasswing, you should already be pointing it at uh, uh, your uh, source code libraries. But even if you don't proactively look at your vulnerability backlogs, proactively pointed to your software and start looking for those vulnerabilities and start validating which ones are real exposure and start retooling your organization to say, how do we now start building for a world where we are going to have a much larger attack surface, we are going to have much more capable attackers and how do we prepare for defense in this world that is more continuous? So the start really rethinking the assumptions of the attack is going to be sparse to attack is going to be continuous, attack is going to be tense, vulnerabilities are going to be tense. So once you break those assumptions, what does your org need to look like? Uh, so that's the way to fundamentally rethink right now. And you're going to have a, this is the time to have a conversation with your execs because right now you have their attention as a ciso, right now you have the attention of your board. Uh, so you have to be the person who has to now go back and say, here were the fundamentals of how the entire industry work. These were the assumptions we made. Those assumptions are no longer valid and we now need to move at the same speed.
Chirag Khanjo: Correct. And I think a side aspect of that is very interesting to me, which is, which is like only probably HackerOne can understand it because you're so close to the sort of the hacker community which helps this, right? You have over 2 million human hackers on your platform and AI just showed that they can do it 85 times faster than humans do. That means that the future of HackerOne security and cyber security overall is agentic and human together. Right? And is that the right way to think? Like even on your leaderboard now there is an AI, not just human, right? So is that, how is this the new world that we should adapt to now?
Nidhi Aggarwal: So first I'll clarify, right, Something Our ethical researchers have already adopted models. So they are actually building harnesses and using the latest models to submit reports. So it is not an either or that there are human hackers and there are agentic, uh, technologies. And even when we see the right, uh, some uh, agentic capabilities are on the top of the leaderboard. So actually we had to separate it out and say these are the one person, human with AI or without AI. Right. These are the hackers and these are businesses where you have 70, 100 developers, uh, who are developing this technique, uh, or these agents. So it's not apples to apples uh, comparison in that sense.
Chirag Khanjo: That's the mind shift I want to want it to come out because that's how they need to start thinking differently. Right?
Nidhi Aggarwal: Yeah.
Chirag Khanjo: In fact, there is a third layer to it which I would love to come out, which is not just agents, not just people, but even that half a million vulnerability data set that you have, that data itself, uh, should come together, right?
Nidhi Aggarwal: Yes. And so the ethical researchers are usually the people who are adopting, uh, this tech and they are trying to find the vulnerabilities as well. So uh, a ethical researcher with the latest AI is more powerful.
Chirag Khanjo: Absolutely. Yeah.
Nidhi Aggarwal: Right. So AI is powerful, but AI with the creativity of an adversarial ethical researcher who has that mindset of how do I, right, uh, have the right prompting, how do I tune it in a way that I can really think through the uh, system vulnerabilities or the edge cases or the real risk. That is a much more powerful way to still find the kinds of vulnerabilities that AI will miss. Because you will find all the vulnerabilities that AI can find and then you will find the risks you are still exposed to.
Chirag Khanjo: And as we are on the topic of vulnerability and remediation, um, let's give some solutions to the target community of CISOs and their teams. Right. Um, they are dealing with this. It is super current for them. I want to understand if you, you explained it really well that Haya, how I should perceive the mythos and everything that is happening. Uh, but tell me, as a part of security program, I am, I'm rethinking my security program with board and everyone. Like you said, I have the retention. How should I propose and put a proposition together that this is the right way to look at cybersecurity? Now? What, what would that be?
Nidhi Aggarwal: Uh, I'm going to proactively apologize for a slightly longer answer because this is not, uh. Right. Uh, there's no silver bullet. Right. First of all, when you have to rethink entire assumptions, you have to really rethink the entire model. Right. And we have to, like I said earlier, we are going to be in a continuous detection phase. So we have to be in a continuous loop of validation and remediation. So that's the first one. So one is just embrace AI for defensive speed, right. Like just require AI agent adoptions. So your security teams cannot operate at human speed against machine speed attacks. So um, like all of your security functions have to empower your staff to match the pace of adversaries. Um, so that's just a given, right? So and that's something now you have all the agency to proposed to the board. There should be no right resistance to that. And then point all of the agents to your codes and pipe like your pipelines and deploy them, the LLMs and coding agents to review your own code and dependencies. And that's the kind of right so that you are ahead of the adversaries. Uh, so you should be detecting it first and kind of like right this is what you Talked about the 250 CISOs, uh, staying up all night, right. One of the big recommendation they had, uh, which makes absolute sense is kind of like we adopted DevOps, we need to have vulnerability ops or wall ops because in that continuous mindset uh, we need that pipeline which has the autonomous discovery of zero day vulnerabilities and the autonomous remediation pipeline so that it's not a handoff between different teams as it happens today between like the team uh that discovers it and then the team that hands off for validation, then the team that hands off to the engineers and then there is some arbitration of which ones they can fix and fit in their backlog. And some days, months later maybe some patch will be done. We just don't have the time for that. Uh, it is much more continuous. It's a architectural uh, shift in thinking about security. So you have to become much closer, right? All the teams have to work much closer. So go ahead please.
Chirag Khanjo: No, please, please go.
Nidhi Aggarwal: The second thing is about right this is we are not going to solve this problem by fixing one thing at a time. We can't play whacker mode. Uh, we'll have to really think about right design level changes, we'll have to think about bug class elimination. And that's uh, something where AI can actually help us. Because if we find one type of vulnerability somewhere, we can now direct AI to say go find me this type of vulnerability everywhere across my attack surface. And then we can use the same capability to uh, because AI is really good at speed and scale. So then we can also scale it as now here's the remediation that we have tested and is uh, effective. Uh now go and do this and test it whether it is actually effective and retest it. Um, did it stay uh, fixed. So that kind of Design level, thinking and thinking through the architectural patterns that lead to those kind of vulnerabilities. Uh, we will have to make some foundational shifts. We will have to have real hardening of our environments. The basics that sometimes, to be honest with security, the CISOs will empathize with this. The budgets weren't there and a lot of CISOs will come and tell you that uh, we've been asking uh, for this and now suddenly, uh, Methos will uh, bring attention to this. But just implementing the network segmentation zero trust architectures and uh, having the phishing resistant mfa, you have to just build the defenses because that's where the, if you find the uh, theoretical vulnerabilities in your software, but your uh, security controls stop on some of them, that will actually reduce your risk. And this was something I, uh, see often. Um, in the first instance where uh, we saw uh, that Claude could find vulnerabilities in Mozilla if we looked under the hood, um, out of the 122uh, vulnerabilities that were found, um, 14 were ah, high and um, critical. Um, and two of them could be validated inside of a sandbox. Both of them would have been stopped by existing security controls. That's a powerful thing that even though 122 vulnerabilities were found, none of them represented true exposure. That's the power of defense.
Chirag Khanjo: Interesting.
Nidhi Aggarwal: And that's something we should realize even in this right Mito's moment, that defense can be very effective.
Chirag Khanjo: And it's almost like um, offense. This defense feels, feels like offense to me.
Nidhi Aggarwal: Right. This defense is offense. Right. So be proactive rather than reactive.
Chirag Khanjo: Yeah. Uh, you know what? I uh, felt great. First of all, this is really, really valuable because I do this chat with CISOs all the time. Why is this valuable? Because as you were explaining it, I was making a mental model of, um, if I'm sitting in front of the board, how do I structure or layer this conversation? Because they think at abstract level. Right. Um, and if I go technical at them, that's, I lose the room very quickly. And cyber security has been plagued by that forever, especially the whole technology industry. So the way I understood, in a very simple terms is that this is your moment. Like number one is this is your moment because you have the attention. Everybody understand what is glasswing? What is my thoughts? It is so relevant. So I got the attention. Now everybody's listening to me. And once everybody's listening to me, the simplest thing I'm asking that you are telling that they should do is that define a process which changes the uh, thing completely. Which is like a, you know, like an agile process of just keep saying this word of continuous and continuous rather than one time. And once you do that you explain the tool of AI is now your tool, not something you're protecting against. So this mental model fits for me so beautifully because it is simple to understand and they can go back and coach their board. And the last thing which was a kind of a bow that you put on top of it was that now I need money to go and execute this because of the risk and it can end up on Wall street tomorrow. Right. And that's what makes total sense to me. So it's like ah, a fear uh solution and then value at the end. And it connects for me. Completely connects for me. Um, all right, let's talk something which is very important. Once somebody understands that there is a vulnerability, there is a remediation. Right? I um, want to understand what should I have a team. So we have a team like cyber security would have a team. And I now not only need to think about my program, my process or my tools, I'm also thinking about the people that I have in my team. Right. Can you talk a little bit about the new role of um, this team that CISO have and how should that evolve for the future?
Nidhi Aggarwal: So first thing is, right, this new team that the CISOs have, you have to think about the fact that they have to be much more closer to uh, this engineering mindset of. Because now for the first time like the ciso, org was always sometimes right seen as the org that says no or the org that uh, stops the business from doing their work. And uh, uh especially in the last few years what was truly happening was uh, everybody wanted to move fast with AI in terms of adoption and growth and innovation. And uh, I can tell you from the uh, chief Product Officer lens, right, uh, um, if I was trying to balance the how fast do I ship products versus rate, how much uh do I pay down the security, um right. Debt. That's no longer the case. Right. Security and speed uh have right have become first class constraints or like uh, they are aligned with the business value prop now. So uh, CISOs, right, their urgency is very aligned with the business urgency. Now that's another thing that has massively changed with this world of continuous discovery um, that the CISOs are going to be faced with. So now they're advocating for the same speed, now they're advocating for similar kind of tools and they're advocating for uh, similar ah, kind of mindsets for the type of people they need, that the engineering org needs or that the product org needs. So that alignment is the clearest, um, kind of signal for what type of people, uh, you need to hire in a csoar. And that's a wonderful thing. That's a great opportunity because now there is an opportunity to partner with the business and say, you guys want to move fast. We want to move fast because it's moment.
Chirag Khanjo: This sounds just like the it moment of how IT CIOs had to get closer to business with this whole agile thought process. Uh, this is that moment for cybersecurity, right?
Nidhi Aggarwal: Yeah, uh, exactly right. Because security has the imperative to move as fast as the business wants to move and probably faster in some cases.
Chirag Khanjo: M what patterns? I'm very curious because you have an advantage of sitting across from so many CISOs, right? Especially now your calendar has been wall to wall because of Python's drop and everything. Um, what's the one thing that keeps coming up? What are the patterns that you're seeing that are coming up very often in these CISO conversations?
Nidhi Aggarwal: So, um, actually I first start with some data we are seeing on our HackerOne platform because one of the advantages we have is we actually see a broad trend in data on our platform, uh, before we even go talk to the CISOs. Uh, so across our platform, the volume of reports increased by 76%, just, uh, the raw volume. And that was closely aligned, uh, with the release of, uh, opus 4, uh, point 6. So that meant that, uh, right, first the ethical researchers were using the models, the agents were being deployed, uh, and they were reporting vulnerabilities. So that volume just increased. And that's something we all have to be mindful. And that's top of mind for our CISOs. So that's one of the things, right? Ah, we keep hearing from the CISOs that they're just getting more and more, uh, vulnerabilities disclosed to them even before Mythos and now with Methos, right, They're more worried about the problem just exacerbating. The second thing we saw was that especially for the open, uh, source code bases that we have on our platform, um, between January to March, uh, the submissions, the report submissions went up by 3x compared to October to December of last year. So there was a 300% increase in the same time the duplicate reports, which means that the vulnerabilities that were being found, uh, went up from 2.22percent to 47%. So which meant that there was a lot more. Right. Uh, Duplicates in that reporting. And uh, right at the same time the number of high and critical findings went up. So that means, right, this conversation about AI slop is more nuanced than it seems on the surface. Yes, AI is finding more vulnerabilities. Yes, you are going to find more false positives or right, uh, AI slope. But AI is also finding more high and critical vulnerabilities. So that's the um, scenario and landscape. And now what the CISOs are worried about, what I keep hearing is one, they're worried about the volume of vulnerabilities because their ability to keep up with the volume of vulnerabilities that was already coming in was really low. Because the problems they're facing is the cost of attack is going down rapidly. Meanwhile the attack surface is going up dramatically. And their ability to keep up with, right, just managing the current, um, risk was already underwater. And now the gap has just massively increased and is going to keep on increasing. So that is their main worry and they keep coming to it is like, how can AI, right? What are the tools that can help us? And the answer is AI. Because the AI, uh, that is creating the problems is also the solution because AI can help at right? AI is really good at dealing with speed and scale and right now reasoning. But you, AI alone won't be the answer. You will need human judgment, creativity, accountability at the right times. You cannot have humans be the bottleneck, um, in this continuous, um, defense. But you will have to have the human judgment be, uh, available async and continuously improve what the AI, um models or AI agents are doing.
Chirag Khanjo: Yeah. You know what I find very interesting in this Nidhi, that when you were giving those numbers, uh, one of the number is very interesting in terms of the 70% increase in reporting of the bugs and everything and the vulnerabilities. And a lot of that reporting is done by humans, um, along with who are working with agents. And it's such a valuable insight that people might be glossing over that these researchers are actually adopting AI the fastest in the world. And that is why they're able to use AI to discover vulnerabilities faster than CISOs have adopted AI or even built an ability to build to look at the insight. Right? So if I am a ciso, I am looking for help and my help solution is I need to use AI. I need to use AI to defend from AI. That's the nature reaction and probably the right reaction. But then who tells me what to do? Right? Those people who have spent years in finding vulnerabilities if you put AI in their hands, they are finding it fastest already. They are the ones who can help you. Right. So that sort of completes the puzzle for me and I love that insight. All other were scary insights but this was like a savior insight for me that oh, somebody else is working very hard in using AI to figure out vulnerabilities. So sort of the silver lining in the changing world.
Nidhi Aggarwal: Right. And a lot of times right. These ethical researchers have spent so much time understanding the environment uh that they sometimes understand the um, tech architecture better than some of the new people um at the customers orgs and uh, they're able to provide very effective remediation guidance. Um so it's fascinating ah uh, what expertise um the ethical researchers have built over time.
Chirag Khanjo: Yeah, I love how we're geeking out. I have one question though, um, which is before the I asked you two questions which are like more personal than this work related, this question is that um, somebody who's building the product uh for security and you're the chief product officer, you always have that nirvana vision, right? I know where the industry is going and there will be a time where there will be like a whole protection layer and it will be semi autonomous. What is the future looking like? Um, can you make a ciso's dream? Like what is the dream that we are working towards in the near future?
Nidhi Aggarwal: Uh so the dream, if I have to talk about right is one, there is a layer of continuous testing uh that is constantly uh, dynamically uh uh uh testing your entire attack surface uh to figure out right. It's almost like think of it like uh a self healing system uh which is right one it is constantly uh checking your temperature and figuring out uh where right. Uh are you most uh vulnerable. Um, it's right has that heat map of here's where I'm finding, sensing some uh, ah trouble or whatever. And then once it does that uh, then you can actually direct more specialized attention to those areas. This is where the uh, ethical researchers or humans with AI um can come in and really focus their attention. And one thing I wanted to emphasize there was the diversity of thought will really matter in this AI world because unlike deterministic software, AI will have like different use cases. Uh right. It will have, it can be morphed to be used in different ways. So unlike traditional security testing you will need that diversity of thought. We already see that on our platform. Right. When we do uh, sometimes the AI uh testing we see a lot more like biologists and physicists testing and being more Successful at jailbreaking uh, the models than the traditional security researchers because they uh, have that knowledge. So um, you do that and then right those kind of uh, uh, so you have this loop, continuous loop of where you are constantly uh, right, the AI is constantly better, getting better and the right human researchers are constantly getting better with better uh, AI and all of these discovery mechanisms then are feeding into your continuous pipeline of validation so that you are really focusing your attention on the exposure that matters. And you're prioritizing them according to your environment. And because a uh, CVSS in the same environment like for one environment might not be the same risk in a different environment. So it's very contextualized for you. Right? All the risk, it's not according to one standard uh, like CVE score. It's contextualized for uh, like the CISO of a retail company different and not even the retail company for you personally. And with that contextualization you have remediation guidance that is contextualized for you for your environment based on your historical patterns, based on your design. And it's not limited uh to that one vulnerability. It actually contextualizes to your entire vulnerabilities, right set and that bug class elimination. And it suggests that, so that then you can propose a uh, design change. You can propose, you can see the anti patterns, you can see the like how did this vulnerability enter your system? And you can eliminate the source rather than playing the whack a mole patching game. And this loop is self reinforcing.
Chirag Khanjo: Yeah, that's the, this is the nirvana state. You know what, I feel like that um, you made a lot of uh, ciso's dream a little bit here and now they're going to call you and say that uh, you made me dream, now build it for me.
Nidhi Aggarwal: So Chirag, the thing we have to realize kind of like how we are amazed at the pace of what AI models can do. What I described, it might sound like a dream. It's more possible than we think. Right? Uh, we're already building it because the same models that give us this uh, oh my God, we're going to have this uh, vulnerability apocalypse are the same models we can use to build the defense. And so um, we should be more optimistic about what we can do to defend ourselves because all of this can be built, right? It doesn't require new scientific research. It requires us building, connecting and having that uh, process. We don't need to invent new things to build this.
Chirag Khanjo: Yeah, that's so cool. Uh, my last question is for the community that we are in for, the community of cyber security, um, who you have seen for a long time, you're working in it, you're building for it, right. As a, as a chief product officer, um, a lot of them are struggling to figure out their way that what should they learn? Young kids, you know, coming out of STEM have started their career in cyber security or in the middle of it. Right. What advice would you give them? Where should they focus their skills on as your give back to the community?
Nidhi Aggarwal: Yes, I would actually say. Right. Uh, I have been really amazed at the, the right, the one, the resiliency. But do just the sort uh, of forward looking mindset of the cyber security ethical researcher community. Um, like I said, they adopt the tech and they just like they're, they're that tinkerer, innovator mindset and you have to have something like really the unique way of thinking uh, to be able to go right. Bypass all their defenses. And uh, so my advice to them would be keep on doing that because that learning mindset, because they learn new things, right. The environment changes and the company hardens their defense and they still figure out a way that's the best kind of mindset. And we've seen some amazing stories of uh, um, like folks who didn't know anything about uh, hacking. They learned, they tinkered, they were learners and then they became earners and then some of them are top uh, researchers. So I would say lean more into that. And now with AI you have more uh, opportunities to learn even faster. And so lean into your curiosity, lean into your right that bent uh, of mind that thinks creatively, that thinks differently. Uh, you never were right of the kind of people who were following the straight lined path and that's what made you effective. Now you have uh, the world is opening up to that possibility even more. Um, so lean more into your strengths. And that would be my advice because um, I hear of amazing stories every day, the, the inspiring stories of the ethical researchers and it gives me inspiration. Um, so my advice would be keep doing what you're doing and do more of it.
Chirag Khanjo: Yeah, fantastic. I felt it, I felt the candidness come through and the excitement come through and that's been the story of this whole conversation. We are at the end. But I really enjoyed how you did not pull any punches. This was candid, honest and value giving. Um, so thank you so much for making time and sharing your knowledge and I wish you Nidhi and Hacker1 the best in your journey. Thank you.
Nidhi Aggarwal: Thank you so much for having me. I really enjoyed the conversation as well. And thank you for asking all the hard questions.
Chirag Khanjo: Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.