What's Up with Tech?

Stop Drowning In Security Alerts

Evan Kirstel

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 27:54

Interested in being a guest? Email us at admin@evankirstel.com

AI isn’t just changing cybersecurity tools, it’s changing the pace of the entire fight. When attackers can scale campaigns with automation and operate at machine speed, the old rhythm of annual pen tests and quarterly reviews stops making sense. We sit down with Hom Bahmanyar Global Enablement Officer at Ridge Security, to talk about what security teams are up against right now and how continuous security validation can turn an endless backlog of findings into a short list of exposures that truly matter.

We dig into the problem every enterprise security team feels: information overload. Vulnerability scanners generate massive reports, but severity scores don’t reliably predict what gets exploited in the wild. Our focus shifts to a more practical approach to vulnerability management and exposure management, prioritizing issues based on exploitability in your specific environment and whether the weakness is actually visible to a threat actor. That perspective helps reduce alert fatigue and aligns remediation work with real-world risk.

From there, we explore how agentic AI and autonomous security testing change the workflow. Hom explains why being model agnostic matters, especially for organizations that must run in air-gapped environments and rely on open source or open weight models. We also talk about why remediation is the bottleneck, how compensating controls like firewalls can buy time while patching catches up, and what early results can look like when teams start validating continuously, including uncovering previously missed SQL injection.

If you care about continuous security validation, AI-powered penetration testing, and keeping pace with modern cyber threats, subscribe, share this episode with a teammate, and leave a review. What part of vulnerability triage or remediation slows your team down the most?

Everyday AI: Your daily guide to grown with Generative AI
Can't keep up with AI? We've got you. Everyday AI helps you keep up and get ahead.

Listen on: Apple Podcasts   Spotify

Support the show

More at https://linktr.ee/EvanKirstel

SPEAKER_01

Hey everybody. Really intriguing and important discussion around cybersecurity today, talking about how security teams can continuously test their defenses as threats become faster, smarter, and increasingly automated through AI with Ridge Security. Home, how are you?

SPEAKER_00

Very good. Thank you. How are you?

SPEAKER_01

I'm well. Thanks so much for joining. Uh really uh important topic today. Before that, maybe introduce yourself and your background. And how do you describe Ridge Security these days?

SPEAKER_00

Yeah, Hom Paminyar. I'm Global Enablement Officer here at Ridge Security. Uh, Ridge Security is a leader in AI-powered continuous security validation and uh exposure management. We were founded in 2020. We have a uh a global reach across all continents with um customers in various industries such as financials, healthcare, government agencies, telecom, etc.

SPEAKER_01

Amazing work. Let's talk about security teams, something you know a lot about as you work with them every day. They're buried in alerts. Um, you know, what is the problem that you're solving around this continuous security validation challenge?

SPEAKER_00

Sure. Um, you know, um information overload is one of the key pain points that we hear from our customers. We've been hearing for the past few years. Um the uh uh there's just too much data, there's too much telemetry from variety of different security solutions that have been deployed by our customers. So to take one concrete example, uh, if you look at vulnerability assessment tools, they detect um uh uh and report a very large number of vulnerabilities. But um at the end of the day, the customers tell us that um they have a hard time identifying which vulnerabilities uh they should be prioritizing first, you know, which ones require immediate action, in other words. So um we've learned that uh uh vulnerability score, you know, the score that's uh assigned uh by the standards body to the vulnerability, that's not really the best way to prioritize vulnerabilities because you know we see some vulnerabilities that are exploited in the wild and they have a medium score, you know, counterintuitive there. So um security validation puts the emphasis on prioritizing the vulnerabilities or misconfigurations based on whether they are exploitable or not. So you'd be surprised to see that um uh out of large number of vulnerabilities that are reported by scanners, typically a very small percentage of them are exploitable in a given customer's environment. Um, the other thing that we emphasize in addition to exploitability is um uh whether the vulnerabilities are visible to threat actors, you know, to the attackers, to the adversaries, uh, in order for them uh uh to be prioritized. So if you have a vulnerability that is both exploitable and visible, then we prioritize that very highly. We say, you know, this is uh just a matter of time before attackers can get to this. So this is high priority, it should be uh remediated soon. So um we also say that, we also emphasize to our customers that this prioritization should be done on a continuous basis. So it's not enough to do this exercise, you know, every once in a while, because the IT environment continues to evolve uh, you know, all the time on an ongoing basis, and the attack surface continues to expand. So to recap, if you want to stay ahead of the adversaries, it's really important to um uh uh to perform continuous security validation so the exposures are detected and mitigated before they are um uh discovered and exploited by the adversaries.

SPEAKER_01

Great points. Uh and how is continuous security validation uh you know different from what we've known with pen testing and vulnerability scanning for you know a decade?

SPEAKER_00

Sure. You know, they're all related. So um vulnerability scanning basically uh lays the foundation. Uh vulnerabilities are discovered across the assets, and then uh penetration testing, which is uh part of what we do at rich security, uh takes those vulnerabilities and then it goes through the process of validating them. In other words, it it uh tries to identify whether those vulnerabilities are uh um are uh exploitable or not and whether they are visible or not. So um uh if you don't do that latter part of validation, then you just end up, as I was saying earlier, with a very, very large body of vulnerabilities. And then it's just humanly impossible to uh uh uh to basically patch all vulnerabilities. So uh then you end up uh, you know, in many cases, we have seen our customers just uh by default go with the score of the vulnerability. And as I was mentioning earlier, the score is not really the best way to do this because it doesn't reflect what the attackers out there are uh are doing.

SPEAKER_01

Interesting. Speaking of attackers, the AI, of course, is changing everything, both how cyber attacks uh work as well as how cyber defense works. But what are you seeing in the marketplace right now uh in in this battle?

SPEAKER_00

Right. You know, um the uh the threat landscape, uh we've uh it's been evolving at such a rapid pace. We've never seen anything like this before. You know, like if you look at the past couple of years, uh, and it just seems to continuously speed up. Um so uh I want to unpack this a little bit more. You know, what exactly is the role of AI here? So uh to begin with, um, we see AI has been uh uh adopted uh across many industries. Um why are they doing that? Um basically they are able to automate or semi-automate variety of workflows. And again, this is across all industries, you know, financial institutions, banks, healthcare uh organizations, government agencies, retail, you know, they're all using AI. So um, so uh when this happens, as a result of this, we see that the attack surface continues to grow. So, what do I mean by that? Basically, the entry points uh uh uh for the attackers continues to grow. Um, so that's the first angle. The second angle uh of uh the impact of AI on threat landscape has to do with the adversaries, you know, the threat actors. So um uh we see an incredible surge of AI-driven attacks now. So the advertisers uh adversaries are using AI to scale their uh their actions, you know. Um uh they're they're also uh operating at machine speed instead of at human speed. So so what we see now is a uh larger number of um attacks and a lot more efficient attacks uh thanks to AI. Um so the um uh the skill set required for the attackers has been going down because AI is doing a lot of the work for them. So that was the second angle, you know, from the adversary's perspective. The third angle, which I find very uh uh interesting, you know, very uh uh uh exciting actually, is uh in the context of the AI models, you know, AI models uh offensive security capability. So we see huge uh advances there. Um uh actually uh uh uh you probably heard that in April we saw Claude Mythis, which is a model from Anthropic, identify thousands of zero-day vulnerabilities. And uh it was able to do this across a wide range of products. For example, you know, many uh uh, you know, all well-known browsers, operating systems. Um, and uh some of these zero-day vulnerabilities that were discovered were quite old. You know, some of them had uh yeah, they had survived decades of human review, uh, and then suddenly they were caught by mythos. So um now I want to mention one thing. These vulnerabilities have existed in in software forever. Uh, but now what we see is the speed and the ease uh of finding them, uh uh uh which then leads to exploiting them, has changed significantly. So the offensive security work that used to take a specialist team, you know, a team of um human specialist uh uh weeks to complete now can be done in hours using AI models. So um uh so let me just recap one more time the three key points. So first is that across all major industries, attack surface continues to expand as they continue to uh uh to make AI part of their workflow. Uh, second point is that AI-driven attacks are happening now at um uh uh at machine speed. You know, they're happening at scale, at machine speed, not at human speed. And the third point is major innovations, major advances in AI models, uh offensive security capabilities.

SPEAKER_01

Wow, what a great, great summary of where we are. And as these offensive AI tools become more capable, as you described, and really off the shelf in in many cases, are organizations testing their defenses often enough? I mean, you know, the annual or quarterly assessments clearly aren't uh enough.

SPEAKER_00

Correct, correct. You know, now the situation is like this organizations are suddenly facing a flood of new vulnerabilities. Um, you know, uh of course they were always used to uh vulnerability scanners generating huge reports, but now suddenly the number of vulnerabilities has started to skyrocket for them. Um so to us, that means that more than ever before, security teams really need the help of solutions such as ours in order to properly prioritize those findings, you know, those vulnerabilities, the software flaws. Um, so that means from the large number of reported vulnerabilities, we want to help uh uh you know various organizations to identify the ones that are exploitable in that particular organization specific environment, and then uh as uh you know help them to uh basically take an action on them. So um uh we've been innovating to harness the power of LLMs, you know, models in our uh upcoming Agenic AI offensive security platform, which is um going to launch in a few weeks from now. Um and using that, we want to empower our customers to put their attentions on the vulnerabilities that really matter. So um one important factor in the harness is that it shouldn't be tied to one particular model, you know, to one particular uh, you know, one specific LLM. Uh, for example, we see some enterprises have um uh have been moving in the direction of adopting one particular vendor's model for their organization. You know, they're standardizing on one particular uh vendor, perhaps they get a uh uh some sort of a discount, and then all employees are expected to just use that model. On the contrary, we also see some organizations that are choosing different models for different purposes, you know, um, so they have the freedom to use whatever makes sense for each specific job. You know, they use you know, model from vendor X for one and model from vendor Y for another. So our Agenic AI offensive security platform is designed to be model agnostic. Uh, we let our customers decide which model they want to use. Now, I should also mention one uh one other fact here. There are a uh uh a number of customers, you know, typically government customers, sometimes financial customers, they they have to operate in an air-gapped environment. And as a result of that, they cannot use any of the frontier models. So they have a requirement to basically uh run the model locally. So that means that the you know, a lot of times they're looking at open source, open weight models. So again, our harness has the flexibility to work with uh various open source and open weight models. And we've been testing with some of the most popular uh open source models. And uh we plan to share the benchmarks publicly because we know that uh a lot of times when customers are trying to examine solutions such as ours, they pay a lot of attention to the benchmarks. They want to make sure that the model that uh they use actually has the capability. Um, you know, give us what we need, give us uh uh our Agenic AI platform what is needed in order to maximize the number of vulnerabilities that we can detect. Um, you know, recently I was working with a bank overseas. Uh they had a requirement to use a locally run uh model, and they're very particular. They said we are not allowed to use frontier models as much as they want to, but they're not allowed to use frontier models. And they were giving us the names of a couple of open, open source, open weight models that they are uh leaning towards. Um, you know, they're kind of um the winners among the uh the large number of uh models that they've been looking at. So um now, in case you're wondering, an open weight model basically refers to an AI model where its um its train parameters, that's what we call weights, are publicly available for others to use. So that they're quite popular. Um so um there is one other aspect of how um uh organizations uh should act in the presence of this uh you know ever-evolving thread landscape I was mentioning earlier. Um, and that is remediation. You know, it is it has become clear now that um remediation has become the bottleneck more than ever before. Remediation was always the bottleneck now with AI model advances in detecting a huge number of vulnerabilities. Uh more than ever before, it's obvious that remediation is uh uh has fallen behind. So there's a lot of good work also going on there. Um uh you know, for us, that's also very important. Uh, you know, uh uh one thing I want to mention is that uh when it comes to remediating a vulnerability, it doesn't necessarily mean that it has to be patched. Of course, that's the long-term solution. But the short-term solution that we always recommend to our customers is what's known as uh basically uh uh you know utilizing compensating controls. You know, for example, use a firewall to prevent access for the time being to that vulnerability while you're working on a long-term solution, which involves patching, uh, yeah, patching the app or the OS, etc. Um, also, we are working actively with um uh uh you know with other vendors, for example, with uh major next and firewall vendor, in order to do an integration between our products so that we make it easier for our joint customers to uh to basically block those vulnerabilities um uh short term while they're working on long-term uh fixes.

SPEAKER_01

Wow, you have a lot going on to say the least. Uh let's talk a little bit about autonomy and automation. What does that mean in the context of a continuous security validation platform and why does it matter? Why is it important?

[Ad] Everyday AI: Your daily guide to grown with Generative AI

SPEAKER_00

Great question. You know, we we hear these terms. For many years, everybody was talking about automation. Now everybody's talking

(Cont.) Stop Drowning In Security Alerts

SPEAKER_00

about the transition from automation to autonomy. So before I uh start focusing on these terms, let me um uh just talk a little bit about another transition that has been going on. This is a transition uh from traditional uh IT uh to uh you know what's known as agenic AI. Uh so traditional IT has been uh around for many years, and it is by definition very deterministic. Uh whereas uh now we are in the era of Agenic AI. Uh, the underlying technology there is probabilistic. So I don't want to go into too much technical detail about this, but I just want to share some of the high-level attributes of these. You know, traditional IT systems, they have a highly predictable behavior. And what they generate is very static in nature. Basically, what you give them as input, uh, they do, they use some logic which is uh deterministic, and then they generate some output accordingly. Very, very deterministic, you know, very static in nature. Agenic AI systems, uh, in comparison, they actually learn and they adapt depending on the environment that they're running in. So you can think of it as that environment basically becomes the context for them. Um, so they they learn from that environment and then they adapt to it. The information that they have, they adapt it to that environment, and then they generate a dynamic output. So very, very different way of looking at things, you know, solving problems. So um again, traditional IT systems have been very static, agenic AI systems are very adaptive. So, how are Agenic AI systems adaptive adaptive? What makes them adaptive? Um, one key attribute is that they are autonomous. So they're able to autonomously communicate with the environment. They can autonomously decide what tools to use to probe their environment. And then at the end of the day, they would learn from the environment. So they can absorb what we refer to as environmental feedback quite well. So um, so at the at the core of Agenic AI systems is autonomy, because it's uh it's the autonomy that enables the series of agents to uh communicate with their environment using whatever tools, learn, and then adapt the knowledge that they have. You know, for example, the knowledge of variety of attacks uh uh that is all captured in an LLM, you know, in an AI model, uh adapt that to, for example, a particular asset, for example, a particular Windows server or Linux server that is being tested right now. So um, so in order to see that adaptive uh approach, autonomy is uh is critical. Um so if you run uh one AI agent in two different environments, you're likely uh to see two different outputs. Why? Because it's uh the AI agent is able to adapt what it knows to the environment where it is placed and then learn from it and dynamically produce a response that is relevant to that particular environment. So now let me take a moment to uh uh to basically tie everything together. You know, what does all of this have to do in the context of uh continuous security validation? So we have our upcoming product, which by the way is uh is called Riggen. Um uh that's a multi-agent system. It has a series of specialist agents. Uh a specialist agent, each specialist agent can act autonomously. Each specialist agent has access to a vast um uh series of tools, and it autonomously decides what tools make sense for it to use in order to solve the problem that is given to it. So um in addition to that, each agent has access to a vast knowledge in the model. So I'm referring to the um uh this knowledge that I'm talking about is basically the uh the vast uh uh body of attack methods and techniques and tactics that have been used by real-world hackers. And all of that information is captured somewhere in the model. So this information basically is part of the model, and the specialist agent is able to absorb uh you know thousands and thousands of attack types and attack techniques, uh uh uh uh far more than a human tester can uh can do, and then um then apply this vast knowledge to one specific asset and using the autonomous um uh uh behavior that it has to decide what tools to use to communicate with that asset, to put all that vast knowledge in the perspective of that one asset and see whether any of those vulnerabilities are there or not. So the important thing is that it does it in an adaptive way. It doesn't, you know, like it is quite feasible for it, for our product regen to also discover what. Vulnerabilities that had never been seen before. That means zero-day vulnerabilities. So that's a key attribute of an autonomous AI platform such as Ridgen.

SPEAKER_01

Brilliant. So let's boil it down. What does this all mean for overwhelm security teams? Any feeling for how it can reduce noise, reduce impact, overwhelm stress to those real teams on the front lines?

SPEAKER_00

Sure. So using the product such as Ridgen, basically the uh the overloaded security uh team members can um can use these solutions um uh you know as their sidekick. You know, like our product, Riggen, actually has a prompt interface. So we envision the security expert to uh to talk to it using uh using natural languages. You know, for example, they can use English here, they can use Polish in Poland, et cetera. And then they can tell it that, you know, can you do penetration testing on such and such website or on such and such device? And they can also tell it specifically, again, in natural languages, can you focus primarily on this class of vulnerabilities? You know, because I heard that such and such vulnerabilities are being exploited in the wild. Am I impacted or not? And then the agent will autonomously go on its own, do the work, and then uh uh there is a chat box that is open. Uh so the uh the security engineer can communicate with the agent uh throughout that process. It can give it additional instructions if needed. For example, if there's a multi-factor authentication that is used on the uh on the asset, the agent will say, I need uh I need a token. And then the security engineer would read the token off his or her uh mobile device and then type it into the chat box, and the agent will pick up where it left off and will continue to do its work, and then at the very end, generate a professional-looking report. So it's a very different way of doing things, and we are so excited about helping our customers to um to basically find their way, uh, you know, find the signal among uh uh so much noise that that that uh they're in. And um, you know, it's just an exciting uh uh uh uh opportunity, exciting time, and we're just very happy to be part of this.

SPEAKER_01

Brilliant. Um so you know, real-world stories are notoriously difficult to come by given the secrecy involved, but any anecdotes or stories that you can share or maybe anonymize on some of the gaps or weaknesses organizations discovered once they start down this new approach?

SPEAKER_00

Right. You know, even though we haven't released this product yet, you know, Ridge and hasn't been released yet. It's slated to be released in a few weeks from now. Uh, but we made it available, uh, you know, like an early availability for some customers, uh, some of our existing customers. And um uh some of them were, you know, gave us um amazing feedback. They said that, you know, uh they were able to find, for example, uh one of them was a bank, uh, some SQL injections that had gone uh uh undetected in the past. They were very happy to see that just by deploying a rig gen in their environment, they were uh able to detect a number of SQL injections that for who knows for how long they had gone undetected uh in the past. And again, we look forward to more stories like this. Again, the product hasn't released yet, so I'm sure that we will have more stories like this afterwards.

SPEAKER_01

I bet. Um we have Black Hat coming up. What are you hoping to see or learn or share uh at Black Hat this year on you know everyday enterprise security?

SPEAKER_00

Yeah, glad you brought that up. Actually, we plan to uh to announce uh our product uh uh during Black Hat. You know, it's a great audience uh uh there, you know, uh all the ethical hackers and you know, variety of security companies are present there. So we'll be announcing the availability of product there, and then we will be, of course, walking the floor. Um uh we feel that right now we are at the front of uh uh you know innovation. So we're walking with the floor to see what everybody else is doing. And you know, um we are also, as I mentioned earlier, we are working with other security vendors, such as you know, next firewall vendors, to do integration. We will continue that work. At the end of the day, our focus is what do we need to do to make our customers successful? So Black Hat is a great opportunity to meet with other vendors so that we can join forces to uh to make our customers successful.

SPEAKER_01

Well, congratulations on all the success so far and look forward to hearing reports uh from Black Hat and from the field. Thanks. Thanks so much for joining, home.

SPEAKER_00

Excellent. Thank you very much, Evan.

SPEAKER_01

And thanks everyone for listening and watching. Also, check out our TV show, uh Tech Impact.tv on Bloomberg and Fox Business. Thanks, everyone.