Snir Ben Shimol on Modern Vulnerability Management and AI-Driven Security with ZEST Security | AWS re:Invent 2025
ZEST Security CEO Snir Ben Shimol highlights the importance of vulnerability management, exploitable risk understanding, and effective remediation strategies in today’s cybersecurity landscape. He discusses the role of AI in streamlining operations, the need for collaboration between teams, continuous scanning, regulatory compliance, and the growing impact of cloud-native security controls.
Transcript
Hey everyone. We are live here at AWS Reinvent, continuing our coverage of Day one Lot going on a lot of ai, a lot of agentic ai. You know what?
I don't hear a lot about Cloud. AWS reinvent used to be all about cloud. Now we're talking ai, but we're gonna talk some security.
One of my favorite topics I want to introduce you to, and I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right. Sne Ben Shimo, Shimo. Almost, I wanna say Shlomo and I keep Shimo, but he likes to be called Ben.
Ben, what's, thank you for coming on to Text Drug tv. It's great to have you on here, man. Thank you for having me.
So from the name, I'm gonna guess you, maybe you have some Israeli roots. Yeah. But You live, you're a New Yorker, New Jersey, like me.
So I guess that makes us kind of almost related, but, um, tell us about your journey. How, how did you come here? Yeah, definitely.
So, currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know. Uh, I'm Israeli originally. So we started a journey in the military.
Uh, I'm not 8,200. You're not 82? No.
My 1200 Is a few. Not 8,200, But actually 8,200 is quite big. Yes.
To the place that I used to serve. I used to serve in more of a secret service. Okay.
The Prime Minister office, which is, uh, more boutique, more unique, uh, harder to get into if you're 8,200. Don't hate me, but we're better. Okay.
Hey, he said it, not me. Well, go ahead. So, yeah, we, um, basically moved to the states after, um, managing a lot of cybersecurity, public company research division, building from scratch.
Really, really passionate about research, anything related to vulnerabilities, attacks, uh, offensive security defense. And, uh, I found myself in, in New York as like one of the big companies. I build their product.
They couldn't sell their product to the ciso. And I was blown away because such a great product, we need to explain the value. And when I moved to the states, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer.
You need to be really close to the team. You need to close to the security executives and explain to them what's going to come next. The thing with security is like check if you playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two.
In year three. So when I moved to the states, one of my biggest goal was to educate them right in like, what's coming up next to build a strategy in the right way. I used to be a CISO as well and managing security organization.
Mm-hmm. Over 100 people. Um, um, very quickly, um, after that build a startup, uh, uh, couple of really good friends, uh, named Cider Security very quickly sold it.
I know That well. Sure. Yeah.
So really quickly, uh, we had a huge success. We sold it to Palo Alto Network. Mm-hmm.
Spot of Prisma Cloud. And, um, I ended up loving the cyber, uh, security in startup. I'm like, wow, I can do, I can build, I can do whatever I want versus enterprise.
That was a little bit slower. Yeah. So I decided to take some time off after the exit, and my co-founder, uh, who I didn't know is going to be my co-founder called me.
His name is Uri based in Boston. And he's like, Hey, so I have something interesting for you. I got to a point you manage vulnerability management and cloud security for Akamai from Cambridge.
Sure. And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment. I'm like, great, Julie, you accepted the risk.
Everyone can accept risk. He's like, no, no, no, no. Actually remediate.
Actually, it's like, excuse me. Look, vulnerability management is never happened, never happened, never happened. Vulnerability management is a list of problems everyone have.
And you just wait for, you know, s****y defense and bad things will happen, but it is what it is. Right? And it's like, no, I was able to do something about it.
Uh, it sounds very promising. I opened a plane, went to Boston, and I spent a few days with Uwe. And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity.
And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved. We can actually win the vulnerability battle. Call me skeptical, but okay.
I'm listening everyone. You got my attention. So after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone works.
We're skeptical. What we ask him, it's like, Hey, if we can come in and take your backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from Wiz, from AWS inspector for, and we talk about AWS later on while we are here, but all this crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data. You can sift through it.
You don't have enough people in the team to review it. And then you have walk workflows. But you cannot automate vulnerability management because it's deterministic.
Every CV is different, every vulnerability is different and the environment is different. So how can you automate? You can't.
This is why we're failing. And I ask him like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle. It's like, that sounds good.
That sounds great. That's great prioritization. And then I, then they told me, what about remediation?
I was like, okay. So once we have that 10 or 5%, I know, and we practice that and we identify it, take that five to 10% and simulate remediation and give you that one, two or three steps that you need in order to, to reduce Back to the buck. Exactly.
That's exactly what we're saying in our website. Mm-hmm. And they say like, that's amazing.
If I have something like that, I will, I will buy it. We, uh, close the seed round in a month really quickly. We just took the money, great investors, and we build ze security, which is the current company we're at today.
Very excited about it. So that's basically the story of, Of you and Ze security. Yeah.
And Uwe. So let me give you a little background. I, I've been in cyber, we didn't call it cyber, we called it security.
I've been in security 30 years. Information security InfoSec. Yep.
Exactly. And, uh, I actually, I've co-founded a couple companies, one of which was called still secure back in 2001. And we in 2003 came out with a vulnerability management product.
And back then it was very different. Back then you had to convince people to do a scan once a year. Mm-hmm.
It was like pulling teeth. But when you, but it was job security for the security guy. 'cause you would do the scan, you'd deliver like a telephone book of vulnerabilities.
Let's say I give it to 'em for Christmas or New Year's, you know, you're from New York. It was like painting the Veno Bridge. You know how they paint Theno Bridge?
They start on one end, it takes 'em a whole year To finish, To finish. And then when they're done, you know what they do, they go back and start again on the other Best job security ever. That was vulnerability management.
It was almost by design that you didn't get to zero vulnerability. So then people got smarter. They said, look, we don't need to get to zero vulnerabilities.
We should only worry about the vulnerabilities that are exploitable, reachable real. You know, I had, I had a friend, I don't know if you've ever heard of this guy, giddy Cohen, Skybox security. Yeah, of course.
Giddy just started a new company too. I know. Um, you know, and that was one of when I first saw his attack maps is what he called them, right?
Mm-hmm. That was a revelation. I was like, wow, this is great.
Now I only have to worry about 20%, 25%, Which is a couple of millions. It's still A couple of still job security. Yeah.
But unfortunately, it's been almost by design that we never get to zero vulnerabilities. And as a matter of fact, even you mentioned, we were talking off camera about black hat. I was a black hat in August.
I was talking to a friend of mine, uh, two friends who actually just, uh, just starting a new company. They just raised money now. And, um, their, their thing is, look, forget all these vulnerabilities.
There's only a handful that are real mm-hmm. That are responsible for incidents and just focus in on those. That's good.
If I knew exactly which ones to focus in on, you know, that's like the old, there's an old joke. A plumber comes and says, the lady says, I don't have heat. The plumber says, let me look.
He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench and the heat starts working. The lady says, oh my God, what do I owe you? He says, $250.
She says, $250. All you did was bang your wrench on the pipe. He said, oh no, that was free.
Knowing where to bang my wrench on the pipe is $250. I love that. Yeah.
I I'm going to use that. Tell you Got it is awesome. It's yours.
Wow. But that's the thing about vulnerabilities, right? If you know which of the ones that are exploitable are dangerous, you can mitigate.
But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities? So what we, and um, I don't know if we to get to zero. Okay.
I don't think we need to get to zero. Yeah. But we definitely need, like, why do the, the world need is important since you start talking about scanning today, scanning is mandatory.
Yes. You have requirements, right? You have continuous regulators.
You have auditors More than that. If you want to provide services as a SaaS company to customers, you need to have an SLA. Yep.
And what happened in 2025, these regulators, uh, re requirements are stop asking you for visibility. Because visibility, everyone knows everyone have that list of vulnerabilities, right? Mm-hmm.
Everyone can scan. Everyone scanning today, even SMBs, they require to. Yeah.
But now the regulators starting to ask, because again, I will, I will give some more information because I think it's important. Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization. Absolutely.
I think it's higher than 60. I think it's close to 80. I'm, I'm just basing on ENT report and Verizon report.
Yep. The time to exploit this vulnerability were reduced in the past three years in 90%. Now it's less than a day.
Last year in 2024 was less than three days before that it was five. So we got to less than A day. I remember it was 30, 45 days.
Exactly. It keeps going down. So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA and god forbid something happened.
You miss your SLA, your regulators will come after you, especially if you're a highly regulated environment. Yep. Most of our customers are biotech, financial services, health, and even SaaS company that provides services to this health care Today.
Look, it's, it's about who your third parties are. Yeah. Right?
It's not who you are. It's who they are. So, you know, and further down the List, and they want to get these deals, it's like, yeah, I cannot get these deals because I cannot commit.
Or they're committing. But now they need to deliver, uh, seven days or six days critical vulnerability in production remediation. Absolutely.
It's the whole SOC two and all of these Other Yeah. Audits. And what we actually realize is there is a need like not in zero vulnerability.
There is a need in remediation. Yeah. And how we do what we do is basically, you cannot automate, but you can AI it.
So we using different type of LLA models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score. It doesn't matter if they're being exploited in the wild or not exploited in the wild, they're in your environment.
Yeah. And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more the most advanced scanners, these tools that you're paying million dollars to, they're giving you this list of vulnerabilities with attack path, with what will happen if, but they're not correlating that with your environment. No.
So you have an open SSH vulnerabilities, right. That open SSH vulnerability have requirements for exploitation. You need to run the service with specific permission.
That asset that is vulnerable need to live in specific environment, environment terms. Without them, this vulnerability can never be exploited. And to understand that you need to send someone to do this test.
Yeah. That's exactly what our Gen TKI, uh, uh, capabilities are. Wait, I needed to say it.
You said it. We but you made a long time till you mentioned it. Look, exactly.
We're here at AWS reinvent. I don't hear them talking about cloud. I hear them talking about agentic ai.
So talk to me about how your agent is working to do this. Uh, we actually announce, uh, we are going to have an announcement, uh, early next year, but in a reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers. AWS investing a lot in security.
Yes, they are. And we call it native security controls. So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way.
And they have a lot of native capabilities around resources. You can build policies around services. You can have security policies without paying money, just using the native capabilities of the cloud.
If you will look in these native security capabilities and you will correlate that information. The hard work that your cloud architect actually infuse into your cloud correlate that with your vulnerability backlog that you need to solve. You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface.
But because you're not marrying these two together, you, you dunno, that means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by this amazing AWS cloud native controls that you have. So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, micro-segmentation in your cloud, and understand if this remote code execution vulnerability can actually exist. Even if you take into consideration these policies, most of them are not exploitable.
Right. That's the idea. I love it.
It's great. You already, you, you don't have a problem. You already solved the problem.
Right. And you don't know that you solved it. You know, some, some part of me sits here and says, did it take AI agents agent AI to reach this level?
Like, it's always bothered me to tell you the truth, why we didn't do better with this problem. Right. I I was working on it 2003 22 years Ago ago.
It's a technology limitation. It's not a need limitation. We always have that need.
I think we've always had the need. I I always thought we didn't have the will. Right.
People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize. But this makes it easier more, it, it's, I don't want to say automated, but it, it's just, it's easier to, to do this. You can win.
I love it. Yeah. I, I agree.
We, we are giving a lot of, I I I'm really proud of it, but we are giving more life years to our security engineering. Yeah. Every time we talk to a team and the team sounds tired and unmotivated mm-hmm.
This is the team we want to work with, the teams that have this backlog of vulnerabilities that every day of their life is chasing down this Vulnerability. Look, this is a whole big problem. You, you've been in security long enough, you know this.
Right? The, the depression of, because for those of us who've been in security a long time, we have a lot of people insecurity who are, they suffer from depression. They, it, the, the, the, the issue is, it's like what does winning look like in security?
That is, I didn't get breached today. Mm-hmm. Right.
Did I not get breached? 'cause I was the zebra in the herd and the lion ain't someone else today. Or because I did a good job, or I convinced my CISO and the board how to manage risk, what, you know, what's acceptable risk or not.
And, and so anything that I think Im improves that is, is an amazing thing. I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic. Um, what has been, so there are security people here, but there's everyone here.
There's C-I-O-C-I-S CSOs. Is that, do people understand, like the security people obviously do, but does the CIO do the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders? Mm-hmm.
I don't think they care. No. I think at the end of the day it's Part of the problem too.
I like, it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared. Right. When you walk in a large enterprise, you like many times you can't do that.
You don't know what the security team in the trenches actually going through. Even not the ciso not talking about the CEO and the CO what I, what I actually, um, what what what I like to surface is if your security team, if your vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem. Yeah.
It's going to bubble up in audits. It's going to bubble up the way you look in front of your customers that asking you about what you do about this, what you do about that, it's going to bubble up when you have a red team or penetration test. It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on?
And we're getting these emails, right? So the management team needs to look good and needs to act good. And it start from the vulnerability made start from the team.
So what I'm, I'm basically telling this COO and CIO is like today you have a backlog of do you have vulnerabilities? It's like, yes. Do you want to eliminate at least 90% of this vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business?
It's like, yes, of course. It's like I can guarantee you that with agenda AI infuse into your exposure management program, your C program, you don't need to hire 200 security engineer. You can walk with your existing team, maybe add some more people if you want to, but you can win.
If you infuse AI into that operation, you can open less ticket. But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction. And that's what they like, they, they sync numbers.
Right. But at the end of the day, I'm helping the vulnerability management team. Yeah.
And if they do a better job, the COO, the CFO even will be happier. They don't understand that. But it's okay.
That's my job to make sure that both sides agree to embrace our technology. This will get, like these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays, right?
Yeah. Always. But then there's always another holiday.
You know, Ben, we're running low on time. I want to just make sure we hit a couple of things for people out there who, like what they're hearing, what's the website to go to here? io.
io. Very Z-E-S-T-Z-S-T Zes, like the Lemon Zes. Yeah.
io. And we're very transparent about what we do and about our technology and we have our customers use cases there. Everything you need to know.
It's in the website if you want to see it live. If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself. And we also have a, um, a free, we just announced a few months ago a free remediation assessment really, which is not a risk assessment.
We're not showing you your problems. Right. We are basically showing you the probability of your remediation operation.
How can you remediate more with less? And it, it takes I think seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time. So Absolutely.
Yeah. io. Yeah.
Hey, I think you're onto something, man. Good for you. Thank you so much.
I really enjoyed the conversation. I enjoyed having you on here. We'll have you on again, Z Security io.
Go check it out. Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have. So go check it out for yourselves.
I'd love to hear what you say about it. Enjoy the rest of reinvent. I will.
Thank you. All right. We're live.
We'll be back with more. Stay tuned.