Cobalt Shares Hard Lessons From the State of Pen Testing Report

Cobalt Shares Hard Lessons From the State of Pen Testing Report

What happens when artificial intelligence starts accelerating cyberattacks faster than most organizations can test, fix, and respond?

In this episode of Tech Talks Daily, I sat down with Sonali Shah, CEO of Cobalt, to unpack what real-world penetration testing data is revealing about the current state of enterprise security. With more than two decades in cybersecurity and a background that spans finance, engineering, product, and strategy, Sonali brings a grounded, operator-level view of where security teams are keeping up and where they are quietly falling behind.

Our conversation centers on what happens when AI moves from an experiment to an attack surface. Sonali explains how threat actors are already using the same AI-enabled tools as defenders to automate reconnaissance, identify vulnerabilities, and speed up exploitation. We discuss why this is no longer theoretical, referencing findings from companies like Anthropic, including examples where models such as Claude have demonstrated both power and unpredictability. The takeaway is sobering but balanced. AI can automate a large share of the work, but human expertise still plays a defining role, both for attackers and defenders.

We also dig into Cobalt's latest State of Pentesting data, including why median remediation times for serious vulnerabilities have improved while overall closure rates remain stubbornly low. Sonali breaks down why large enterprises struggle more than smaller organizations, how legacy systems slow progress, and why generative AI applications currently show some of the highest risk with some of the lowest fix rates. As more companies rush to deploy AI agents into production, this gap becomes harder to ignore.

One of the strongest themes in this episode is the shift from point-in-time testing to continuous, programmatic risk reduction. Sonali explains what effective continuous pentesting looks like in practice, why automation alone creates noise and friction, and how human-led testing helps teams move from assumptions to evidence. We also address a persistent confidence gap, where leaders believe their security posture is strong, even when testing shows otherwise.

We close by tackling one of the biggest myths in cybersecurity. Security is never finished. It is a constant process of preparation, testing, learning, and improvement. The organizations that perform best accept this reality and build security into daily operations rather than treating it as a one-off task.

So as AI continues to accelerate both innovation and attacks, how confident are you that your security program is keeping pace, and what would continuous testing change inside your organization? I would love to hear your thoughts.

Useful Links

Thanks to our sponsors, Alcor, for supporting the show.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(2000)

Building Responsible AI for Public Services With AWS

Building Responsible AI for Public Services With AWS

How can governments and public-service organizations adopt AI quickly while protecting the people affected by their decisions? In this episode of Tech Talks Daily, I speak with Holly Ellis, AWS Direct...

1 Sep 22min

Making Industrial AI Deliver Real Operational Value With IFS

Making Industrial AI Deliver Real Operational Value With IFS

What happens when an AI system moves beyond generating answers and begins influencing machinery, maintenance schedules, technician dispatch, and safety? In this episode of Tech Talks Daily, I speak wi...

1 Sep 28min

Building AI Data Readiness With Kiteworks

Building AI Data Readiness With Kiteworks

Could your organization produce a complete record of everything its AI systems accessed, sent, or shared within one business day? In this episode of Tech Talks Daily, I welcome Tim Freestone, Chief St...

31 Aug 22min

Testing the Blast Radius of Agentic AI With NTT DATA

Testing the Blast Radius of Agentic AI With NTT DATA

What happens when an AI agent follows your documented process perfectly, but that process bears little resemblance to how decisions are actually made? In this episode, I speak with Bill Wilson, Execut...

30 Aug 29min

Building Legal Accountability for AI Agents With Norm AI

Building Legal Accountability for AI Agents With Norm AI

Who carries responsibility when an AI agent begins reviewing contracts, applying regulatory rules or making commercial decisions on behalf of an organization? In this episode of Tech Talks Daily, I sp...

29 Aug 25min

Moving Enterprise AI From Hype to Accountable Results With Freshworks

Moving Enterprise AI From Hype to Accountable Results With Freshworks

Has enterprise AI finally reached the point where impressive demonstrations are no longer enough? In this episode, I speak with Murali Swaminathan, CTO at Freshworks, about the growing pressure on AI ...

28 Aug 22min

Building Infrastructure That Can Govern AI Agents With Broadcom

Building Infrastructure That Can Govern AI Agents With Broadcom

What happens when an organization writes careful AI governance policies but its infrastructure cannot enforce any of them? In this episode of Tech Talks Daily, I speak with Sabina Anja, Chief Technolo...

27 Aug 25min

Turning Rising AI Cloud Costs Into Business Value With Unravel Data

Turning Rising AI Cloud Costs Into Business Value With Unravel Data

What does a rising cloud bill actually tell you about the value your business is creating? Eight years after our first conversation, I welcome Kunal, co-founder and CEO of Unravel Data, back to Tech T...

27 Aug 27min

Populärt inom Politik & nyheter

aftonbladet-krim
svenska-fall
p3-krim
rss-krimstad
en-runda-till
aftonbladet-daily
flashback-forever
politiken
rss-sanning-konsekvens
rss-vad-fan-hande
kungligt
rss-krimreportrarna
motiv
svd-ledarredaktionen
rss-frandfors-horna
rss-flodet
fordomspodden
spar
rss-expressen-dok
krimmagasinet