The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Business of Cybersecurity
The Business of Cybersecurity artwork

Closing the AI Vulnerability Remediation Gap With Cobalt

The Business of Cybersecurity · 2026-07-25 · 28 min

0:00--:--

Key moments - from our scoring

Substance score

54 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber13 / 20
Specificity & Evidence11 / 20
Conversational Craft9 / 20

The episode explores the growing mismatch between AI's ability to discover vulnerabilities and organizations' capacity to fix them. Allman explains that frontier models like Mythos are exceptionally efficient at vulnerability discovery - Cobalt's pen testing report found AI and LLM tests surfacing high-risk findings at 2.7 times the rate of traditional methods - but only 38% were resolved. The core problem: companies are bolting AI and LLMs into legacy systems without understanding the integration risks, and they depend on third-party vendors for remediation on those dependencies. Allman advocates for continuous testing integrated into development pipelines, moving away from annual compliance pen tests toward daily automated scanning and monthly or quarterly human-led assessment. He emphasizes that the traditional entry-level analyst career path - tier one to tier three progression - has essentially disappeared over the past decade due to automation and AI, with organizations now recruiting experienced professionals from other fields and augmenting them with AI tools rather than developing junior talent. For CISOs, his core message is unequivocal: AI is not a delegable technology. Leaders must become masters of it, commanding it directly rather than handing it to subordinates, because critical CISO responsibilities can no longer be efficiently outsourced in an AI-driven security landscape.

Key takeaways

  • →Yesterday's medium-risk vulnerabilities can become today's exploitable threats when AI chains multiple weaknesses together, shifting the remediation timeline from weeks to hours or real-time.
  • →The traditional cybersecurity career ladder from junior analyst to senior practitioner no longer exists; automation has removed tier-one roles and organizations now hire experienced professionals from other fields, then augment them with AI tools.
  • →CISOs must become hands-on masters of AI technology rather than delegating it, as many of their core responsibilities cannot be efficiently outsourced in an AI-driven environment.
  • →Continuous vulnerability remediation integrated into CI/CD pipelines with human-in-the-loop validation is replacing annual compliance pen tests as the standard practice for managing discovery velocity.
  • →The vulnerability remediation gap stems not from discovery limitations but from third-party dependencies; organizations have limited control over when vendors release patches for integrated LLMs and commercial AI models.

Guests

Gunter Allman

Topics in this episode

Large Language Models (LLMs)Penetration testingMythosFrontier modelsAI vulnerability discoveryCobaltsecurity operations center (SOC)Vulnerability remediation gapCISO responsibilitiesCI/CD pipeline integration

Questions this episode answers

Why are AI tools discovering vulnerabilities 2.7 times faster but only fixing 38% of them?

Companies are bolting LLMs and AI into legacy systems without fully understanding integration risks, and they depend on third-party vendors to fix vulnerabilities in those integrated technologies - creating a remediation bottleneck independent of their control.

What is the impact of AI on entry-level cybersecurity careers?

The traditional tier-one to tier-three analyst progression has disappeared over the past decade due to automation and AI; organizations now recruit experienced professionals from IT, product management, or other fields and augment them with AI tools rather than developing junior talent internally.

How should security teams prioritize vulnerabilities when AI accelerates discovery speed?

Organizations must shift from traditional risk ratings (critical = 24 hours, high = 3 days, medium = 1 month) to real-time response, because medium-risk and above vulnerabilities can now be exploited within hours; remediation or preemptive blocking must become automated and near-instantaneous.

What should CISOs understand about using AI to improve security outcomes?

CISOs must become masters of AI technology and command it directly rather than delegating it, because critical responsibilities cannot be efficiently outsourced in an AI-driven environment, and deeper interaction with AI systems makes them more powerful and effective.

What practical workflow changes help keep pace with AI-accelerated vulnerability discovery?

Move from annual pen tests to continuous cycles of monthly or quarterly testing paired with daily or weekly automated scanning, integrate penetration testing and remediation into development pipelines, and maintain human-in-the-loop validation to catch vulnerabilities earlier in the development process.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode has a handful of non-obvious claims - vulnerability chaining elevating low/medium risk, frontier model discovery costs, and the 24-hour remediation window - but is padded with broad industry observations and repeated throat-clearing. The ratio of actionable insight to generic commentary is moderate at best.

frankly anything that's medium and above may be exploited within the next hour. Right. As soon as you've learned about this
I can take three or four of these medium or low risk vulnerabilities, figure out how to chain them, uh, to get the full control of the system

Originality

10 / 20

There are a couple of genuinely contrarian points - CISOs must personally master AI rather than delegate it, and the tier-1 pipeline was already being destroyed by automation long before current AI hype - but most of the content recycles familiar industry narratives about burnout, continuous testing replacing annual pen tests, and AI augmentation.

commanding AI and being in command of AI, uh, is now a critical, um, skill, uh, and a requirement for being a successful ciso
we're seeing professional IT people or product managers or program managers, um, make that transition to cybersecurity, to fill in that gap by augmenting them with the AI systems

Guest Caliber

13 / 20

Gunter Allman is a genuine practitioner with CTO and CISO experience at a real pentest-as-a-service company, and he demonstrates hands-on credibility with offensive security knowledge. However, he is partly acting as a spokesperson for Cobalt's own research report, which slightly undermines objectivity, and he is not a widely recognised tier-one industry figure.

I've worn many hats. You know, today I wear a CTO hat. You know, I've worn a CISO hat. Uh, and I've worn the hat of having to apologize for many, many events where consultants have got things wrong.
my company's 13 years old and the platform has a decade worth of developments

Specificity & Evidence

11 / 20

A few concrete data points exist - the 2.7x high-risk finding rate, 38% resolution rate, and the ~$25,000 per-vulnerability discovery cost - but all originate from Cobalt's own proprietary report with no external validation, and the rest of the episode leans heavily on 'what we're seeing' and 'many organisations' without named examples, metrics, or timelines beyond the guest's own platform.

AI and LLM tests surfaced high risk findings at 2.7 times the rate of the wider data set, but only 38% were resolved
maybe per vulnerability is maybe $25,000 per vulnerability to go discover, uh, on average, and that ignores all the Ones that tried but didn't, was unsuccessful

Conversational Craft

9 / 20

The host does his homework by citing specific report statistics in the opening question, which is above average, but the follow-up questions are largely leading or soft ('you must have a few war stories'), and no claim made by the guest is meaningfully challenged or probed for evidence. The episode functions more as a promotional platform than a genuine interrogation.

when your state of the pen testing report set off my tech Spidey sensors. When I learned that it had found AI and LLM tests surfaced high risk findings at 2.7 times the rate of the wider data set, but only 38% were resolved
you must have a few uh, war stories onto your belt after you throughout your career

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B74%
  • Speaker A26%

Most-used words

vulnerabilities25today20seeing20security18vulnerability16tools15space14better12tier12speed11remediation11code10side10become8cybersecurity8ciso8

Episode notes

In this episode of Business of Cybersecurity, I speak with Gunter Ollmann, CTO at Cobalt, about AI powered vulnerability discovery, the widening remediation gap, continuous pentesting, legacy application risk, and the future of cybersecurity careers. Advanced security models such as Mythos can gather and apply techniques published across security research, Black Hat, DEF CON, and other industry sources. Gunter says this makes them particularly effective at reviewing large code bases and trying known attack methods against potential targets. The result is faster vulnerability discovery, but finding additional weaknesses does not automatically make a company safer. Cobalt’s 2026 State of Pentesting Report found AI and LLM tests produced high risk findings at 2.7 times the rate of its wider data set. According to Cobalt, 32% of AI and LLM findings were rated High Risk, while only 38% were resolved. Gunter sees two reasons for the gap. Companies are adding AI features to existing applications without fully understanding how the new components affect security.

Full transcript

28 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest. What happens when AI can find and exploit vulnerabilities faster than your security teams can fix them? Well, the good news is that defenders never had better tools at their disposal. But the bad news is attackers have access to many of them, too. But my guest today is the CTO at Cobalt, and he's going to join me to explain why yesterday's medium risk vulnerability could become tomorrow's emergency. And together, we'll explore why AI is quietly removing the first rung from the cybersecurity career ladder and discuss why every CISO now needs to understand AI well enough to command it, rather than simply delegate it. We got a lot to get through on this episode of Business of Cybersecurity. We've got a few surprises in there as well, but enough scene setting for me. Let me introduce you to my guest right now. So thank you for joining me on the show today. Can you tell everyone listening a, uh, little about who you are and what you do?

Speaker B: So my name is Gunter Allman. Uh, look, I've been in the cybersecurity space for a long time. It's really hard to describe, but I sort of class it up. I spent most of my career trying to figure out how to be better at the bad guy stuff than the bad guys. And in between, I have to sort of figure out how to, uh, stop, you know, detect and stop people like myself. So, you know, there's a brief summary, but, you know, I've worn many hats. You know, today I wear a CTO hat. You know, I've worn a CISO hat. Uh, and I've worn the hat of having to apologize for many, many events where consultants have got things wrong.

Speaker A: Well, I would imagine that that challenge between, of beating the bad guys, that good guys versus bad guys battle, uh, is even harder now because recently, of course, Mythos and other adv AI security models, we quickly learn that they can discover vulnerabilities at, ah, extraordinary speed. Speed that neither, uh, of us have seen in our lifetime. But what are these systems genuinely good at today and, ah, where do they still fall short compared to experienced security professionals like yourself?

Speaker B: Well, I mean, if you take something like Mythos, These frontier models, as they sort of call them. Right. Um, in many ways they are very good at distilling that the entire Internet's worth of knowledge down to something. And so what we've been seeing is that these frontier models like Mythos, are super efficient uh, at um, applying all that security knowledge, all those mythical techniques, everything that's being published at BlackHat or DeathCon or a major security conference, and then effectively trying out all those techniques against these targets. Uh, and so what we've seen is that these tools which are based on large language models, are really good at things like source code reviews. And so we're seeing this explosion in discovery of vulnerabilities in large code bases, uh, and that's going to continue for quite some time. Problem though is I think we're um, still trying to figure out as an industry how much it costs, uh, and how much is a vulnerability actually worth, you know, investing into to go find it.

Speaker A: And one of the reasons I was excited to get you on the podcast today is when your state of the pen testing report set off my tech Spidey sensors. When I learned that it had found AI and LLM tests surfaced high risk findings at 2.7 times the rate of the wider data set, but only 38% were resolved. So uh, why is remediation failing to keep pace with vulnerability? Discovery has got to be my first question. And on behalf of every security leader listening to us today, what should they be doing about this?

Speaker B: Sure, I mean I think the numbers reflect two things. So one, it reflects that um, these technologies are ah, being bolted on uh, and included in the software, the applications, the products that uh, these companies have been producing for quite some time and they're still figuring it out. Um, in some ways it reminds me very much of 15, 20 years ago where everyone started patching uh, on a TCP IP stack onto their physical device and now we end up with the IoT uh, and OT type technologies. that time you had engineers, electrical engineers and mechanical engineers strapping on a TCP IP stack and attaching to the Internet and trying to figure out all those vulnerabilities. And so we're seeing the same thing now where they're dropping in the these LLMs, it does all these fantastic AI features, but they haven't really figured out how the integration really works. And it's exposing vulnerabilities and problems that they always had. So that's one side. The second side is because they're bolting on someone else's product technology when a vulnerability is Found, um, they are dependent on that third party to go fix and resolve these things. Uh, and so it means that uh, the timeline for remediating is now dependent on their supplier, uh, and these largest models, uh, that they're integrating on and connecting, um, they're very big and very sophisticated. And perhaps your vulnerability in your application, the way that you've implemented is a little further down the stack, uh, for remediation or even addressing by those third parties. So there's a lot to unpack in that space. Um, it will get better, um, but I think it's probably going to get worse before it gets better because of the volume of these things. But to your second part of the question, what should the CISOs really be working on? Um, I think there's a couple of areas. One area is uh, really building out the processes internally for continuous, uh, testing and evaluation of these technologies. Uh, what we're seeing successful organizations do is that they are building in their penetration testing and their remediation, uh, of those vulnerabilities into their development pipelines. Uh, and instead of as an industry, we're moving away from just once a year, annual pen test report that you flash your mount for compliance, uh, into a continuous cycle of monthly quarterly testing and daily, uh, or weekly automated scanning and remediation. I think that's the biggest trends that we've seen in resolving this. And the third part of that is, um, we're seeing more organizations now flip to having more humans actually involved in the loop. So this human in the loop has come back, come back stronger than ever. Um, and there's more eyes on glass as it were, uh, to use an older term there, to actually uh, inspect the pipelines, inspect and evaluate the code that's being written in the integrations. Um, so they're catching these things earlier.

Speaker A: And I think there has been a concern that leaders could be tempted to use AI to eliminate entry level cybersecurity roles. But the flip side of that, thankfully many are arguing that this could damage the industry's talent pipeline and those entry level roles there. So what are companies misunderstanding about the role that analysts and pen testers of varying levels should play alongside AI? It feels like quite a balance and quite complex on the right thing to do. But how do you see this conundrum?

Speaker B: Well, it's actually been a deep concern of mine for over a decade. Uh, the AI assistance that we're talking about today, um, this trend has been going on for longer than that. Whether it was machine learning and classifier systems and all the smart Automation. What we've seen is in this classic term of three, uh, tier architecture of humans. Tier three being your super experienced and tier one your entry level. Um, for the last ten years, we've seen the tier one analysts disappear from security operations centers, not because of latest generation of AI, um, but because of automation, smart automation and then machine learning. And now AI is accelerating. Um, honestly I worry very much about what that new career path really looks like. I think the biggest things that we've been seeing have been, um, this trend over the last decade that uh, you know, every organization now needs to have a CISO. The first thing on every CISO's hit list is they need to have a SOC, a Security Operations Center. And to make a SOC work, you actually even to start it up, you need to have senior experienced people on there. And so there is a draw around the world for that top talent. Meanwhile, um, um, that, that first tier, that evolution, the first tier has gone away. I'm seeing exactly the same thing happening in the offensive security space as well. So those junior pen testers, the folks that if you were doing a pen test, you had a team of five people and you had a couple of juniors sort of learn the trade, um, the automated tooling, the latest tools that you run from your laptop or doing your pen test, um, have replaced the need for those folks. Right, and so what does that mean? So one angle is that traditional career path of starting from that junior position and rotating up, um, just honestly does not exist anymore. Um, the technologies around, uh, saying that I can have a junior person and I give them access to AI and that elevates them to a tier two. Um, we're not actually seeing that in reality. I, uh, think it's a story and uh, something that we would like to see. Um, but we're not seeing that. What we're actually seeing is that as those tier threes are becoming rarefied, um, uh, organizations are looking for other senior and experienced people in other fields, uh, and then giving them those tools, the AI tools, to augment them so they learn the cybersecurity piece instead. So we're seeing professional IT people or product managers or program managers, um, make that transition to cybersecurity, to fill in that gap by augmenting them with the AI systems. So it's very interesting. Uh, it honestly worries me a lot. I speak to a lot of CISOs in this space. Um, I think we're all committed to figuring out how we can get more juniors and help them on that path. But that traditional matter of Moving from tier one to tier two to tier three, um, it feels like that is permanently gone. We have to look for another routes in the space. Wow.

Speaker A: I'm curious, if AI does continue to dramatically increase the number of vulnerabilities being discovered, do you think or could security teams end up less secure because those senior practitioners become overwhelmed with alerts, validation and remediation? We already hear stories of burnout in the industry, but what do you see here?

Speaker B: Well certainly burnout is a high factor. What we're seeing in this space, um, a couple of things there. One is um, it's not like those vulnerabilities are uh, brand new. Those vulnerabilities have been there from time. We've just become better and better at uncovering the vulnerabilities. Ah and year on year finding new techniques of how to uh, locate and actually exploit those vulnerabilities. So I think AI is making that job a lot easier, a lot more efficient. Um, but on the flip side, uh, the ability for in house security teams and engineering teams to locate the cause of the vulnerability and actually go fix the vulnerability has increased exponentially in pace with that. Uh, and so our ability to resolve, fix and roll out fixes has never been better. Um, there's still a gap, uh, the adversarial side plays uh, a key part in there. But I am expecting and seeing evolution in two ways. So one way is that if it's inside your organization's power to fix, uh, patch, uh, or to again use an old term virtually patch something, um, then the tools are evolving rapidly and are going to be very, very good in that space. But it brings back to your earlier question. Uh, you're dependent on third party development or third party tools and so you're dependent on their cycles for remediation and fixing these things. Uh, and um, that is a gap still today in the remediation space. And so I'm working with a lot of um, if you like, some of the traditional players, uh, the ids, the ips, the edr, all these three letter detect respond type technologies where they are now becoming at the forefront of uh, prevention. For many years the industry is focused on we'll detect it and detect the threats and then we'll have some time to go remediate it. Now if these tools are not only finding a vulnerability but also creating the exploit for that vulnerability at the same time, uh, that zero day is now today. Uh, and so the need to remediate and if you can't remediate, but the ability to block it uh, has now become a prerequisite for success. And so that space between exploit availability and you have to move from detecting it to blocking it is now shrinking down to. Today it's shrinking down to 24 hours. Uh, is the ideal space. So a lot of exciting times, a lot of new technologies that have to be built, uh, but workflows uh, are changing. And perhaps that brings it back to the question about the Tier one analyst. Um, human uh, in the loop is great for checking and making sure that the processes work, but they're also the speed bump in responding against these threats. And so finding that balance, I think uh, is going to be a continuous yin yang situation as it always has been, I guess.

Speaker A: Yeah, I love that analogy of a speed bump of sorts as well. 100% with you there. And you are someone with decades of experience reviewing source code like right here.

Speaker B: It's like.

Speaker A: I'd also found that older uh, larger applications often contain the most unpleasant security vulnerabilities. What I'm trying to say is this is not your first rodeo. Um, so as companies race to add AI features to those legacy systems, what, what risks are they unwittingly creating that many security teams could be overlooking? Uh, you must have a few uh, war stories onto your belt after you throughout your career.

Speaker B: But definitely a few war stories. But yes, I mean the larger the code base, the longer it's time it's taken to develop that tool and technology. It's a bit like you've inherited a hundred year house. How uh, often do you go into the basement to check the boiler and things like that? There's a lot of things in those sort of cobwebs and yes, you use that house knowledge, you can update all the windows and uh, all those things. Um, but the foundations are with a lot of the changes and the reality is uh, and I think um, two things that sort of call out. One is uh, the larger and the older the applications, um, the more vulnerabilities there are. And these are not new vulnerabilities, these are just vulnerabilities that have always been there. Um, in many cases it's just been difficult to figure out how to exploit them. And we touched a little bit about the frontier models where they excel is um, actually figuring out how to chain together lots of vulnerabilities and to, to navigate um, that kill chain for exploitation. And so what we're seeing in this space, many of those old vulnerabilities may have been classed as low or medium risk because no one knew how to exploit them. Now what we're seeing with these models is that I can take three or four of these medium or low risk vulnerabilities, figure out how to chain them, uh, to get the full control of the system. So we're seeing that sort of really sort of grow in this space. Um, the flip side of this though is I see it myself. Uh, my company's 13 years old and the platform has a decade worth of developments. Um, in traditional senses you would have been talking about to redevelop that is a two year mission for 50 engineers, et cetera, et cetera. Today though, I can access that source code that I've written over the last 10 years, get an LLM, um, a Frontier model to understand it, and then draw out what the changes need to be and actually refactor and rebuild the code within weeks. Uh, that's not to say go build a brand new product, but instead of me trying to read every line of code, understand why the hell someone made the decision like this and what this thing connects to. The AI systems, ah, are fantastic at that, uh, today. And to be able to then pass that through to a smart engineering team and give them access to those same AI tools means that we're more able to get down to the basement, uh, uncover these things and start fixing these things than we ever were before.

Speaker A: And we're talking about what the good guys are doing here. But on the flip side, attackers are also using AI to find vulnerabilities and operate faster. That's something we're all seeing now. But what practical changes should listeners, especially in companies, uh, what should they be making to their pen testing, their vulnerability management and remediation programs to better keep speed or keep pace with machine speed discovery. Because that's the challenge now, right?

Speaker B: Uh, correct, to be clear, all the pen testing tools that you can get a hold of today, uh, the best ones all have AI in them of some flavor or whatever. And so this is not something new. And that just mean that uh, today's pen test compared to three years ago, pen test, like for like, much better, higher quality and findings because of the tools and the evolution of folks there. I, um, think the change that we're seeing on the adversarial side though is that these advanced models, ah, are very good at finding stuff, um, but they are very expensive. So when you saw things like the Mythos releases, glasswing programs and this, you're sort of seeing that maybe per vulnerability is maybe $25,000 per vulnerability to go discover, uh, on average, and that ignores all the Ones that tried but didn't, was unsuccessful. And so the realm for the elite space has become a dollar amount. Right. And so in this space, um, as an organization your ability to find the vulnerabilities that your traditional adversary can find um, is on par. So nothing has really changed on these. Maybe the timing around these uh, has changed. But your ability for your adversary with a lot of money to go find the vulnerabilities that you can't find, um, because they have the money to actually find these things, uh, has flipped into the adversary sides. But this is organized crime. State actors and state players that now have access to these types of tools that are better than what the tools that are available for many organizations, um, on the defensive side or how should we responding? I think the key one I called out is that time between discovery and remediation. Remediation, uh, and if not remediation to preemptively block, uh, has shrunk down to real time. And so um, organizations need to be thinking about how they move from. I think we've spent 20 plus years talking about, we talk about risk in high, medium and low and critical. And we've translated these things one way or the other. Say that a critical vulnerability is you got 24 hours to go fix it. A high risk you have three days, a medium you've got about a month. And low risk, yeah, whatever, once a year types. And we've built that into our sort of informal thinking. Now what we have though is that frankly anything that's medium and above may be exploited within the next hour. Right. As soon as you've learned about this, the tools may be able to exploit. And so that process for uh, understanding reverse engineering the vulnerability, reverse engineering the exploits, um, building the uh, signature, the detection that has to be rolled out to your multi layered defense now has to become automated, uh, and has uh, to be resolved uh, in record speed. I think that's the part that's changing for many organizations. The other side about it's a vulnerability in your own codes that could be found. Honestly it's a little different. Um, those big adversaries with these tools are probably less, they care less about finding vulnerabilities in your specific code because it may only apply to you as opposed to if I'm going to spend that money, I'll find a vulnerability in something that affects many thousands of people. Uh, those vulnerabilities in your codes you are in more control and you should be still automating your CI CD pipelines and rollouts and making those more Efficient, but actually you've got a little bit more time compared to those bigger, broader vulnerabilities in third party software.

Speaker A: And if we do have a CISO listening today who wants to better leverage AI, but do so in a way without weakening their security team or cutting off their future talent pipeline, any actions that you'd advise that they can take now after this podcast, and improve security outcomes while also developing the next generation of practitioners too.

Speaker B: I think one key, one takeaway is hub, uh, in the loop is really important. Um, you've got a bit of balance. When does the human loop become their speed bump? But uh, what uh, we're seeing is that um, AI is not a point and shoot technology. You can't just say, here's my problem, go figure it out and let it go to this part. Um, the more interaction, the more you learn with your AI systems, the better and more powerful it becomes. Uh, and in one way, um, I think a responsibility of the CISOs is that uh, with all the AI technology, um, unlike other technologies, the CISO actually has to become a master of this technology, um, has to truly understand it and has to be as capable, if not more capable than the tiers below them, which is very different from the past. Not, um, only for helping them scale, but also many, uh, of the roles and responsibilities of the CISO can't be efficiently delegated, uh, in the world of AI. And so commanding AI and being in command of AI, uh, is now a critical, um, skill, uh, and a requirement for being a successful ciso.

Speaker A: And I think that is a powerful moment to end on. And for anybody listening, they're wanting to find out about cobol. It's quite clear that you are focused on combining talent and technology with speed, scalability and expertise. We covered a lot today, including that report as well. For anyone listening wanting to find out more about anything we talked about, where would you like me to point?

Speaker B: Well, two ways. So the Cobalt IO website, you know, lots of blogs, lots of releases and the things there. And you know, uh, I'm also broadcasting. So if everyone wants to, you know, find me on LinkedIn, then you'll see, uh, me pointing to the latest, coolest things that are going out there, uh, things to worry about, things to, uh, take comfort in, and the latest security knowledge.

Speaker A: Fantastic. Uh, I'll include links to everything, including some of your broadcasts as well. I'm going to be checking those out. I'd encourage everyone listening to carry on this conversation. I think it's something that impacts every organization around the world, but thank you for sitting down with me today, bringing it all to life in a language everyone can understand. Really appreciate your time.

Speaker B: Um, thank you for giving me the opportunity. Neil.

Speaker A: I think my guest highlighted one of the biggest challenges facing cybersecurity leaders today. Yes, AI is helping defenders find vulnerabilities, understand old code and fix problems faster, but it's also giving well funded attackers the ability to discover and chain weaknesses at machine speed. And I think he also raised an uncomfortable question that the industry cannot afford to ignore. If automation removes junior roles, where will the next generation of experienced security leaders come from? And my other big takeaway was his advice for CISOs. AI is no longer something leaders can simply hand to a technical team and hope they do their best. They need to understand it. They need to use it and question it and know when the human in the loop becomes either the last line of defense or or just the first line, the speed bump that slows everything down. I'd love to hear your thoughts. Is AI making your cybersecurity team stronger or are we creating new risks by automating away the people who would be tomorrow's experts? Let me know techtalksnetwork.com lots for you to look at there. Meet me on the road at an event or send me an audio message. But thank you for listening today and I'll be back again real soon on the Business of Cyber Security podcast.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 512. Is SpaceX Over or Undervalued, Why Consensus Kills, How Chewy Beat Amazon, and the GameStop Saga from a Board Member (Larry Cheng)The Full Ratchet (TFR) · on Mythos86 / 100
  • Less about Models; More about ArchitecturePractical AI · on Large Language Models (LLMs)85 / 100
  • Microsoft Fabric: The Platform That Turns Data into Competitive AdvantageLeading IT - APAC Insights · on Large Language Models (LLMs)85 / 100
  • Rethinking Security Analytics with In-Place Intelligence, CEO of Vega, Shay SandlerShift AI Podcast · on security operations center (SOC)82 / 100
  • Episode 7: AI & the Power of a "Thin Core"Architecting the AI Enterprise · on Large Language Models (LLMs)82 / 100
  • #194 Brian Donohue: Intercom threw their playbook out the window when AI got good - A case study on questioning your mental models.The Way of Product with Caden Damiano · on Large Language Models (LLMs)82 / 100

More from The Business of Cybersecurity

All episodes →
  • Securing Every AI Agent Action With Delinea69 / 100
  • Mimecast CISO On Why AI Has Become A Cybersecurity Risk60 / 100
  • Orange Cyberdefense On The New FCA Cyber Reporting Rules76 / 100
  • Deepfakes, AI Agents, and the Collapse of Traditional Identity Security66 / 100
  • When Identity Becomes The Front Line Of Cybersecurity71 / 100
All The Business of Cybersecurity episodes →