The Enterprise AI Show · 2026-06-17 · 26 min
Key moments - from our scoring
Substance score
30 / 100
Five dimensions, 20 points each
Brian Grace Lee explores what he calls the 'vulnerability gap' - the accelerating threat landscape created when AI tools like Anthropic's Mythos and OpenAI's GPT-5.5 Cyber enable faster, cheaper creation of security vulnerabilities alongside legitimate software development. With GitHub reporting that 20% of the world's software repositories were created in the past year, and tools like Project Lightwell (IBM/Red Hat) and Athena (Chainguard) emerging to address the scale, organizations face a critical inflection point. The episode frames this as both a software volume problem - where maintenance teams are overwhelmed by AI-generated code - and a velocity problem, where patching timelines of 40-50 days no longer align with disclosure windows of 14-30 days. Grace Lee examines the build-versus-buy calculus for vulnerability remediation, the role of collective industry partnerships, and the emerging need to compress patch-to-production timelines from weeks to days. Operators in infrastructure, security, and development should understand how Mythos, the broader 'AI Cyber' category, and regulatory disclosure requirements (US AI executive order, EU laws) will force organizational change.
The vulnerability gap is the widening disparity between the volume and velocity of security vulnerabilities being created by AI tools like Mythos and GPT-5.5 Cyber versus organizations' ability to find, patch, and deploy fixes. As hackers gain access to the same AI coding tools as developers, they can generate vulnerabilities faster and cheaper than ever before, while most companies still operate on 40-50 day patch-to-production timelines against disclosure windows that may compress to 14-30 days.
Project Lightwell (from IBM and Red Hat) and Athena (from Chainguard and partners) are industry initiatives created in response to the breaking point in open-source software maintenance. They aim to collectively secure open-source software by combining the efforts of multiple companies and communities, sharing the cost and burden of vulnerability detection and remediation rather than having individual organizations manage it alone.
GitHub data shows that 20% of all software repositories globally were created in the last year, creating an explosion of code that humans must maintain. When AI-generated code and bugs are added to this volume, developers and maintainers are distinctly disadvantaged compared to when they only dealt with human-created software, leading to burnout and inability to keep up with patches, prioritization, and architectural changes.
Organizations should evaluate: (1) their ability to identify vulnerabilities and track sources, (2) in-house skill sets to fix vulnerabilities, (3) organizational bandwidth - since increasing vulnerability velocity means more time away from building new value, and (4) cost, as using LLMs to remediate at scale can generate substantial monthly bills compared to current manual or community-based approaches.
Once a vulnerability is patched, there's typically a 14-30 day window before public disclosure, during which organizations must deploy fixes. However, most companies take 40-50 days to patch high-priority bugs from the time they receive the patch, meaning they remain exposed for 10-35 days after public disclosure when attackers can also see the vulnerability.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of concrete data points - patch-to-production averages, disclosure window SLAs, automation percentages - but they are buried under heavy repetition of the same 'volume and velocity' frame and substantial throat-clearing. The signal-to-noise ratio is poor for a 26-minute episode.
the average company for a lot of these things, that number is somewhere like 40 days, 50 days, 60 days, sometimes longer
maybe a year from now it's realistically like seven to ten days
The 'vulnerability gap' and 'Mythos moment' labels are the host's own coinage, and the fast-path pipeline idea is a mildly interesting operational suggestion, but the core thesis - hackers benefit from AI coding tools too - is already widely circulating and is not argued from first principles.
I'm starting to call and I'm starting to see more discussion around what I'm calling the vulnerability gap
you may have a sort of fast path type of pipeline that you build in parallel
This is a solo host monologue with no guests whatsoever. The host has a background in cloud infrastructure commentary but presents no verifiable practitioner credentials, and there is no external expert to evaluate.
while we talk a lot about, we used to talk a lot about automation back when we were doing cloudcast stuff
I'm your host, Brian Grace Lee
The episode names real recent announcements - Project Lightwell (IBM/Red Hat), Athena (Chainguard), Mythos (Anthropic at ~40 then ~150 companies), GPT 5.5 Cyber - and cites specific patch timelines and automation percentages, but most sourcing is vague ('I think GitHub published a study,' 'some numbers that come out') and the GitHub stat itself is ambiguously framed.
GitHub published a study here recently and they basically said about 20% of the world's software has been created this year
Project Lightwell from IBM and Red Hat, or Athena, which was announced this week from Chainguard
There is no interview, no guest, and no questions asked or challenged. The monologue is structurally rambling, with frequent 'anyways' resets and unfinished thoughts, and no mechanism exists to push back on or deepen any claim made.
So anyways, just kind of wanted to bring that up
And uh, so you know, the, you know, the downside to, you know, kind of the advantages
Computed from the transcript - who did the talking, and the words that came up most.
SUMMARY: As tools like Mythos create new AI-cybersecurity concerns, CIOs and CISOs need to be prepared for two challenges: Security Remediation and Patch to Production acceleration. SHOW: 1037 SHOW TRANSCRIPT: The Enterprise AI Show #1037 Transcript SHOW VIDEO: SHOW SPONSORS: Nasuni - Activate your data for AI and request a demo OutShift by Cisco - “Scaling Out Superintelligence” The Internet of Cognition architecture ShareGate - ShareGate Protect. Microsoft 365 Governance, we got this! SHOW NOTES: Project Lightwell (Red Hat and IBM) Athena (Chainguard) Anthropic Project Glasswing OpenAI GPT 5.5-Cyber THESIS: Major initiatives are forming to help enterprise organizations combat security vulnerability threats found or created using new AI-cyber tools such as Anthropic Mythos. What are the key considerations, and what additional steps do organizations need to take to be advantaged by these capabilities? Part 1 The Breaking Point and the Mythos Moment The scope of open source security and support Patches, disclosures and upstream open source Clearinghouses, EOs, Laws and Communities Remediation - Build vs. Buy Part 2 How fast can you get from Patch to Production?
Transcribed and scored by The B2B Podcast Index.
Narrator: Foreign.
Brian Grace Lee: Good evening, wherever you are, and welcome back to the Enterprise AI Show. I'm your host, Brian Grace Lee. And today I want to dive into a topic that's starting to get some buzz and we're starting to see some interesting announcements, as well as some global announcements around the idea of what's going to be the intersection between AI, these new AI tools, and security and security vulnerabilities, and how companies are going to be able to keep up with what could potentially be a very large volume and a very large velocity of security vulnerabilities that are going to start getting created. Unfortunately, because as much as your software developers have access to outstanding coding development tools and things that are going to help them build software faster, the hackers have just as much access to those tools, or at least they will be very, very soon. So, you know, we're recruiting this on June 16th. I know there's been some things in the news about the anthropic tools, both, um, Mythos and Fable. You know, this is going to be a space that's going to move very, very quickly. But I want to dive into kind of some things that are happening around the industry announcements in this space, as well as some discussion about, you know, some things to start considering in terms of making sure that your teams are prepared, your organizations are prepared, your infrastructure and environments are prepared for, uh, what could begin to be, again, a larger volume of vulnerabilities, a larger velocity, faster velocity of those vulnerabilities, and what that means downstream in terms of, uh, impacting your developers, impacting their day to day, impacting their ability to keep up with stuff. And then ultimately your, you know, your infrastructure teams and your operations teams in terms of trying to keep up, make sure that your teams are well prepared for security, for audits, for all the things that come from a legal and compliance perspective. And we're going to dive into that right after the break.
Narrator: Today's show is sponsored by Nasuni. There's a growing gap in AI right now between what's possible in theory and what successfully works at scale inside an enterprise. The difference comes down to unstructured file data. Many AI initiatives struggle because the file data they depend on is scattered, unstructured and disconnected from where and how work actually happens. Nasuni changes that. It brings your unstructured file data into a single secure foundation, so AI, both generative and agentic, can access it with the context, governance and performance it needs in production. Bring AI to where your unstructured data lives. See what it takes to activate your data for AI and request a demo@nasuni.com AI this episode is brought to you by Outshift, Cisco's incubation engine. AI agents today operate in silos, limiting their potential. Scaling up models isn't enough. We need to scale out like humans
Brian Grace Lee: did 70,000 years ago.
Narrator: Agents must share knowledge, goals and innovation to evolve. Outshift by Cisco is building the Internet of Cognition, transforming isolated AI systems into orchestrated superintelligence. This open infrastructure enables agents and humans to share intent to context and reasoning. The cognition evolution for agents is here. Learn more@outshift.com that's outshift.com Today's show is sponsored by Sharegate. You're out of time. Copilot needs to be deployed ASAP, but your tenant really isn't ready for it. Years of data, permissions and users lurk in its shadows, ready to be exposed by AI. Sharegate Protect sees it all. So you can find the exposure risks, fix them fast and deploy AI with confidence. Microsoft 365 Governance, they've got this. Learn more@sharegate.com protect
Brian Grace Lee: and we're back. And as I mentioned at the top of the show, I uh, want to dive into this thing. I'm starting to call and I'm starting to see more discussion around what I'm calling the vulnerability gap. And let me kind of frame this up for you. So Obviously, you know, LLMs have been around now for, you know, three, three and a half years. People have had uh, wide scale access to that. And you know, while we've talked a million times, kind of the growth that we've seen around it being used for software development and building software tools, building all sorts of things with it, whether it's vibe coding or professional coding, whatever it might be, that also means that those tools are being used by uh, hackers, people that are looking to do some bad things from a security perspective. And uh, so you know, the, you know, the downside to, you know, kind of the advantages of using these tools from a productivity perspective for developers is that the folks developing things that are going to create security vulnerabilities, things that will make your life difficult as a developer, have just as many tools as you do. And in fact they probably have almost more motivation now because it's cheaper to use those tools. And then this all sort of got put on steroids, uh, a few months ago as Mythos from Anthropic was released and kind of released not only out into the wild, well, released in terms of an announcement, partially released to a small number of companies, I think around 40 companies. It's now been expanded to about 150 companies. We've since seen, uh, OpenAI come out with GPT 5.5 Cyber. So, you know, not only have the, the ability to, to create security vulnerabilities and to do stuff, been out there with the LLM tools because they're essentially, you know, coding tools and they can decode software and do all sorts of things like that. But we're now starting to see a, uh, you know, a class of these models being built secure specifically around, you know, I'd be interesting sort of, sort of see if a name comes out of this. I'm calling it sort of AI Cyber. Another name may emerge out of this, you know, more vibe coding type of name. But anyways, you know, they're, they're there looking to not only, uh, help folks that are doing cybersecurity, but also can be kind of reverse engineered and be used to create problems for cybersecurity. So you're starting to hear more and more people talk about this idea of sort of a mythos moment in which the industry is going to have to come to this realization that the bad guys, if you will, now have faster and cheaper ways to create vulnerabilities. And this is ultimately, you know, it's ultimately going to cause two challenges for companies, right. The first challenge within this sort of mythos moment is really just an extension of kind of this breaking point that we're starting to get to around 20, 26. And it's all about kind of the breadth of software that's being developed, right? So if you look at some numbers and there's all sorts of stats that come out, but it jumped out at me. I think GitHub published a study here recently and they basically said about 20% of the world's software has been created this year. And that feels a little bit like when we were in the early days of the Internet where it was like, oh, all the world's information has doubled in the last two or three years. So 20% of all repositories in GitHub have now been created in this last year or the last six months. It just sort of goes to show that when, uh, these tools start to make it very, very easy to write software, to vibe code, to take on projects, to begin to build agents, you're going to see the byproduct of, uh, a lot, a lot of software being developed. And you know, for a long time we've said, hey, that's, that's a Fantastic thing, right? You know, software is eating the world. And we've talked about, uh, you know, companies that are good at building software and managing software essentially in a, in a more rapid way are able to, you know, create some really interesting business advantages, right? So, you know, if we go back to software's eating the world circa 2011, we would have thought of software as distinctly a business opportunity, right? It was going to be a thing that was going to change your business, disrupt business models, do all sorts of things. Right now as we get to 2026 and we're seeing massive amounts of software being built, which, you know, on the positive side, it's like, okay, new ideas are turning into technology, you know, new opportunities are happening for a whole new class of people that weren't necessarily professional software developers. The flip side of that is somebody or something has to maintain all that software, right? So whether it is, you, um, know, maintaining, you know, having to build things to make sure that it doesn't create, uh, hallucinations, whether it is just software maintainers who are getting overwhelmed by AI generated bugs and PRs and so forth and all sorts of things, really kind of getting to a breaking point where while it's, you know, in some cases considered great that we can develop a lot more software for lots of different reasons, whether they are business reasons or personal reasons, the folks who have to maintain that software, and in many cases the, those vibe coders aren't maintaining it. Maybe they're kind of doing the old throwing it over the wall. Somebody's maintaining that. And whether that is in individual projects or it's in massively used open source projects, the folks who are burdened with maintaining it, maintaining its software, maintaining its stability, maintaining its scalability, all those sort of things are pretty overwhelmed. And now you throw on top of it tools like mythos and GPT5 cyber, and just the wider spread of that and that breaking point is coming fairly quickly, right? So what ultimately kind of has happened is we're starting to see, and we've seen a couple of announcements here in the last couple of weeks. Whether it is Project Lightwell from IBM and Red Hat, or Athena, which was announced this week from Chainguard and several other companies, we may see more coming down the road to be determined. Again, we're recording this on June 16, 2026, but what we're seeing in response to that is we're seeing groups who are either multiple companies or collections of companies. We may see come out of communities basically saying, hey, the old model of software is going to be maintained mostly by humans. You're going to then have a subset of developers who have to keep track of not only maintaining the software, but dealing with prioritization, fixing bugs, dealing with new requests, looking at architectures that change. All those sort of things just aren't able to keep up when we're no longer dealing with just human developed software.
Narrator: Right.
Brian Grace Lee: Like we've heard for years and years that software developer maintainers were getting burned out just from dealing with human created software. Because more and more software is being created now. They are distinctly at a disadvantage when the machines are also contributing to the software. So anyways, we're seeing these projects come along and they've got very, very bold claims and really kind of noble concepts to go after like how do we, whether is as a collective or a group of people or individual companies, whatever it might be, how do we go about ensuring or better securing open source software?
Narrator: Right.
Brian Grace Lee: That's kind of the focus of both project, uh, Light. Well, as well as Athena. Now, you know, it's going to be sort of to be determined as to what the scope of that means because obviously we know that Open Source has thousands and thousands of projects. Some projects are far more widely used than others. I mean you could just go out to the CNCF landscape or go out to the Linux foundation or a number of other things and you're going to see which projects are more widely used than others or at least there's more dependency upon them. I don't know if I should say widely used because there's always going to be that, that uh, you know, that use case of that one tool that's used by billions and billions of people but nobody really knows about it because it's some little tiny project. But anyways, so you know, we're starting to see these, these groups that are saying, hey, you know, it's, I guess ultimately in the, in the race to sort of keep up with vulnerabilities. You can look at it one of two ways. You can look at it as if you're an individual company, you're an individual organization. If you try and take this on yourself, you've got three or four things that you really have to consider, right? Number one is how well are we going to be able to ident what's happening, right? What are going to be our sources of vulnerabilities? How well are we able to track them? The second is, you know, how much skill set do you have in house to go about fixing those things, right? You know, maybe you're going to Do a combination of things that you fix yourself as well as things that you're getting from, say, those open source communities, whatever that might be. The third thing becomes, you know, how much of your time do you really want to spend in that? Given that both the volume and the velocity of these vulnerabilities is likely going to increase and maybe increase by, uh, an order of magnitude. Multiple orders of magnitude.
Narrator: Right.
Brian Grace Lee: So how much of your organization do you want to spend on things that are not driving new value for your organization? And then finally, and maybe just as importantly, is how much spend are you willing to do on this? Because in the past, if you were doing it primarily manually or through some combination of sort of manual and hoping the open source community would do that, there's a certain amount of burden to that. If you're going to try and keep up with the pace of this, using LLMs to help you kind of combat that, you know, you're looking at a potentially, you know, large bill on a monthly basis. And I'm not trying to be, uh, you know, kind of, kind of put FUD out there, but, you know, we are starting to see from some of the early companies using mythos, that, you know, you can start to run up a fairly hefty bill doing this. And yeah, there are other, maybe cheaper ways to leverage LLMs, and you could do it locally and so forth, but there's going to be, you know, a certain amount of burden above and beyond what you do today if you try and take this on yourself. So the alternative becomes, well, maybe what I want is some sort of partnering relationship with somebody who's going to help with this remediation, right? And that partnership could be with one of these things with Lightwell or an Athena maybe. You're going to, you know, collectively work across your industry. You're going to create some sort of, you know, loose coalition of companies and you're going to sort of share those costs or share the burden. Maybe you're going to collectively say, hey, we all sort of use these same libraries or these same frameworks. Let's figure that out. So if not, you're going to start to look at, um, some of these services just as you do for lots of other things. Now, the things to start to take a look at is, uh, like I said, first and foremost, what's the scope going to be? Does the scope of the projects, the frameworks, the languages that they cover, how much overlap does that provide you on top of what you do? You're going to want to look at how Are they communicating what's happening? Is there a way for you to give them information about your environment? And hence you can get some sense of, you know, it's going to provide 100% coverage or 60% coverage. You want to have some sense of, like, you know, how much, how much work am I kind of getting from the service versus how much am I doing? Then you start to get into questions about, you know, how do all the disclosures work? Because we're not just dealing with, you know, software bugs where, you know, you submit a pr, it's out in the open, somebody decides to fix it based on some priority. They put the code back out there, it gets reviewed. It's kind of all out in the open. When we're dealing with security stuff now we're dealing with a whole nother level of kind of, how are things reported, how are things anonymized, how are things disclosed to whoever, um, you know, to the communities that are responsible of this, what sort of, you know, delays or, I don't want to say, you know, kind of formally get into embargoes, but, you know, in essence, there has to be a period of time in which the people who were affected by the bug can get the patch for it before it's put out into the open. So that, you know, the bad guys and the hackers can get access to seeing what's going on, because they obviously are able to create vulnerabilities really fast. And so if you're able to find a fix for something that's found before, you know, the bad guys get it, that's good. Right now all that's going to start getting a little bit cluttered and challenging because we're starting to see, uh, individual countries. So, for example, United States just had an executive order about sort of, uh, an AI clearinghouse. We're seeing laws within the eu, within different, uh, regions of the world, trying to address this. And again, they're all trying to address the same sorts of concerns, but they're all doing it a little bit differently. And so we're going to start to get into situations in which you're going to have to understand whether it's who you're working with, which groups you're working with, what's going to be their policy on reporting, being the reporter or seeing a report of what vulnerabilities might have come in. How visible is that? How anonymized is that? How long does it take? Is there some sort of SLA around? You know, once something's been reported to it being fixed because a lot of these fixes are going to come from AI, plus some amount of human intelligence for review and so forth. Then you're going to have a certain amount of time in which the information is going to be shared to a set of people, kind of in the know group if you will, as opposed to everybody. Because again what you want to do is you want to provide the patches, you want to provide people a reasonable amount of time to get those patches put in place. In the case of these open source organizations that are working on things, they're also making commitments, or at least it looks like they're making commitments to uh, provide the things that they fix from open source projects back to those open source communities, so they become an augmentation of those communities. And so all that sort of has to be understand, you have to understand the timelines of it, you have to understand the details of it. And so, you know, we're going to see a lot of people trying to sort through, you know, should I go into a, you know, do it myself and understand the pros and cons of that, uh, you know, understand, you know, when you're going to have to carry your own, you know, forks, when you're going to carry your own, you know, kind of company's version of something, you know, how well you understand the cost of how much AI is going to cost you to resolve things versus being able to buy into some sort of service. So we're going to get into a very much a build versus buy from a remediation partner perspective and you know, we'll see a lot kind of shape out with that. I expect we'll see quite a bit happen over the next three months and six months because again it is. The scope of this problem, as I mentioned early on, is kind of to get to a breaking point, right? So much software, so much software is being used to where again it went from in 2011 a business opportunity to now it's potentially coming a business liability or business dilemma in terms of owning so much software, maintaining so much software and so forth. And then the second part of it, which I don't think has really gotten a whole lot of discussion yet, but is going to be equally as important is if we think about that timeline I laid out from some vulnerability or some bug is found, the bug is resolved so that first, uh, SLA is met, then it is disclosed on a need to know basis for people and then there's going to be the publishing out of the public domain that's going to have an amount of time, and let's say that amount of time is anywhere between 14 days, 28 days, 30 days, maybe it's a little bit more than that. But as these things are moving faster, um, you know, that timeframe is probably gonna get compressed a little bit. And so the next ultimate question really becomes, let's suppose you subscribe to one of these services or you decide to go it on your own. What ultimately, and this is I guess kind of the key question, what is your timeline at least today for high priority bugs to get from patch received patch to getting that into production? Right, getting that back into production for the applications that are dependent upon it? And I think we're going to start to see a realization that, you know, you can look at stats and look at data that's out there. You know, the average company for a lot of these things, that number is somewhere like 40 days, 50 days, 60 days, sometimes longer than, you know, 90 days. And again, it all depends on the severity of what's going on. But if that number is in the 40 day time frame, let's say 45 day time frame, 50 day time frame, and the window that these services are putting things out are going to be in that 30 day timeframe against some sort of SLA. You know, if you're not able to patch it within that 30 day timeframe, you expose yourself quite a bit, right? And that timeframe may get to a point where maybe it's 30 days today, but maybe a year from now it's realistically like seven to ten days. Right. And again, understand complex organizations, that's gonna be difficult to do, but that timeframe might be coming and it might be coming faster than you think. And so it starts to open the question of, you know, how would you deal with that if, you know, your remediation partner or the people that, you know, your security teams internally said, hey, we need to get from 40 days, 45 days down to 7 to 10 days. How prepared are you to deal with that? Because if we're exposed for, you know, maybe a couple of days, maybe we can sustain ourselves. But if we're exposed for 30 days or 25 days, uh, you know, like kind of all bets are off, right? And I think that conversation is going to be happening when more and more organizations again over the next six months to 12 months as this Mythos concept, you know, these security vulnerabilities, these AI cybers and the threats and the cost of it and the velocity continue to grow. And so I think we're going to see A lot of interesting conversations of saying, you know, how fast can you get from patch of production? Do we fit inside of a red window, a yellow window or a green window? And unfortunately, I think a lot of organizations are going to be in that yellow and red window. And I think one of the first conversations that are going to happen is they're going to say, well, you know, we've gone through this before. We've, you know, we've dealt with, you know, log four shell or Heartbleed or some other one. And you know, there are certain things that you're going to be able to do just from a mitigation perspective. You don't have to do patching. You can rewire the network and reconfigure some things, um, and that'll all continue to take place. But on these wider scale things in which it's really, really widely deployed and you've got a lot of exposure and so forth, people are going to have to start coming up with new and novel ways of doing that. And one of them might be, you know, really going and evaluating their current system. Right. You're going to see, you know, people are using GitLab and GitHub and Artifactory and Nexus and you know, all the CICD pipeline tools and all the scanning tools and those might be adaptable to a much faster model. Maybe they're not doing as much automation as they need. Maybe they're not doing as much, you know, automated approvals, automated test writing, you know, looking at AI coverage, doing red teaming ahead of time. So a lot of those best practices are going to start getting introduced. I think we may also start to see the idea of sort of a think of it as like a Mythos pipeline versus your sort of standard pipeline that you have in place that has to go through, uh, change boards and maintenance windows. You may have a sort of fast path type of pipeline that you build in parallel. And we'll see what nuances that brings up. Obviously it'll bring up certain changes in what you do, but we're probably going to start to see that as a certain type of thing. And then the last piece of it really becomes, you know, you're going to look at a lot of automation within the build process of it. And then I think a lot of people are going to start questioning, you know, how well prepared are we from an automation perspective. You know, as we want to get to deploying this into production, how well can we make adaptations to our server infrastructure, our OS infrastructure, um, you know, the application stack, the technology stack, within uh, that whether it's at the host level, looking at middleware, looking at all sorts of services, but then also looking at, you know, how well do you automate your network, do you automate your storage, how well do you automate firewalls and other things that are going to be in the path to getting that out the door? And so, you know, while we talk a lot about, we used to talk a lot about automation back when we were doing cloudcast stuff. You know, when we still talk to a lot of organizations, you know, they're still at 25%, 30%, maybe 40% automated. And I think we're going to see again a big push to, you know, how to move those numbers up, you know, plus 50, plus 60%, you know, where can we, you know. And again, this is not a, you know, humans versus machines thing. This is a volume and velocity conversation. So anyways, just kind of wanted to bring that up. Like I said, I'm kind of thinking of it as the vulnerability gap. It's kind of a two pronged thing in this Mythos moment. It's, you know, the first piece is really about security remediation, vulnerability remediation. How well prepared are you? Do you have a partner to do this? Are you going to try and do it yourself? What's the scope of it? All those types of things. Do you have an active understanding of what your environment looks like? Do you do things like S boms, do you have inventory tracking and so forth? And then the second piece of it really going to be that patch to production, right? How quickly can you do that, how consistent can you do it, how automated can you do it? What are the steps in the process that today are taking a long time, that are taking you 30, 40, 60 days? How much of it's technology versus how much of it is people and process? And ultimately I think we're going to get to a point where at least some portion of your environments are going to have to get down in that seven to 14 day window, right? You want to be in that window that you're protected for as these services are putting them out and you're still in your sort of quiet period that you can be covered, right? There's no chance that uh, something coming out, something coming along is going to put you in exposed area in which the fix for that or you know, the details of that vulnerability, plus maybe the fix are out in the public domain, right? You want to be able to fix that before it gets out there and the hackers get visibility into what's going on. So it's going to be an interesting space. I think it's going to be interesting to see how the communities evolve around these services, how much partnership happens, how much collaboration happens between these groups. Um, uh, and I think ultimately it's something that if you are working in infrastructure in some way and security in some way, and even to a certain extent in the app development teams that have responsibility for building and maintaining applications and code bases, this is going to be sort of a flashing red light for the next some number of months until we start to get these things under control. Because right now the average numbers for a lot of organizations are still going to be outside those windows. They're going to be sort of red or at least yellow in a lot of situations. So anyways, just wanted to bring some visibility to folks about what's going on. We're going to dig into this more in some upcoming shows. As far as, you know, what are good ways to remedy this, what are some best practices, what are different people that have responsibility for things like networking and storage and data and so forth thinking as opposed to what the application teams are thinking. So dig into that on more shows. But thank you all for listening. Thanks for telling a friend. Uh, thanks for my flexibility on the weekend shows. I think this week I'm going to do my best to get one out Friday, but this one may be another Saturday or Sunday show and then some of the travel that I've been having going on is going to slow down a little bit, knock on wood. And uh, hopefully we'll get back to getting to that, that sort of Wednesday and Friday, which is kind of where we want to be going forward. So anyways, with that, thank you all for listening. Thanks for telling a friend. Thanks for helping us grow the community and, you know, rating the show everywhere you get it or sending us feedback. I know we're getting some great feedback from people and ton, uh, tons of suggestions for good topics and guests. So with that we'll wrap it up and we'll talk to you next week. Thanks for listening. Check us out@theenterpriseaishow.com for past shows, newsletters
Narrator: and all things enterprise AI.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.