Attack surface management has served the vulnerability management program for years, and it now has a second job, governing the asset sprawl that AI makes sprawlier by the day.
Read more about ASM Has a Silent C, and It Stands for Change Management
Attack surface management has served the vulnerability management program for years, and it now has a second job, governing the asset sprawl that AI makes sprawlier by the day.
Read more about ASM Has a Silent C, and It Stands for Change ManagementRunning a pentest through an AI model can cost a few cents per asset or a few thousand dollars, depending entirely on which phase you spend it on. In this post I provide a quick walkthrough of all five phases.
Read more about The Anatomy of a Pentest: Where Does AI Change the Game?I sat down with Gadi Evron, CEO of Knostic and CISO-in-Residence for AI at the Cloud Security Alliance, to talk about why the assumptions behind most security programs are breaking, and what defenders do now that agents changed the game.
Read more about Life Finds a Way: Securing the Enterprise When Everyone Is a DeveloperMost organisations don’t know what’s on their external attack surface. Richard Stiennon joins our CEO Rob Gurzeev to unpack why attackers always find what defenders miss, and how AI is making that gap harder to close.
Read more about Thinking Like an Attacker: How to Strengthen Modern Cyber Defence StrategiesStar Wars as a security case study: the Empire’s real failure wasn’t missing the exhaust port, it was never testing whether it mattered.
Read more about The Force Awakens Your Attack SurfaceThe instinctive reaction to Mythos is: we need to patch faster. That instinct is understandable. It is also exactly the wrong frame. The real question isn’t how many CVEs are in your queue. It’s how many of your exposed assets can actually be exploited right now, by anyone with an API key and an afternoon.
Read more about Mythos, MOAK, CTEM and the End of CVE ChasingModern security frameworks often fail by surfacing endless vulnerabilities without context. This blog explores how the CTEM framework’s Validation stage provides ‘permission to ignore’ theoretical risks, allowing teams to focus engineering resources exclusively on confirmed, evidence-based, and exploitable threats.
Read more about Permission to Ignore: Leveraging the CTEM Framework to Focus on Real RiskContinuous Threat Exposure Management (CTEM) shifts security metrics from measuring activity to prioritizing impact. This refocuses reporting on urgent, validated issues and continuous testing coverage. By tracking remediation hours and material exposure reduction, organizations can effectively manage risk without creating unnecessary noise or alert fatigue.
Read more about From Activity to Impact: How CTEM Refocuses Security KPIsCTEM reframed security around what attackers can actually reach and exploit. But Gartner didn’t provide an execution playbook. This blog breaks down what each stage demands in practice – and the anti-patterns that derail most programs.
Read more about Taking the Guesswork Out of CTEMSecurity teams are under constant pressure to find and fix vulnerabilities faster, but traditional approaches to security testing often create delays. In this blog, we explore why active security testing, despite its perception for being slow and resource intensive, is the key to achieving faster and more confident fixes. You will learn how accurate testing results drive smarter remediation decisions, how fully automated testing at scale overcomes common operational challenges, and why reducing your window of exposure requires moving beyond passive scanning. If your organization is struggling with long remediation cycles and hidden risks, this is the blueprint for accelerating your security outcomes.
Read more about Faster Fixes: Solving the Security Testing Trade-off