Brinqa Prioritizes AI-Era Exposure Management
Mike Vizard talks with Brad Hibbert, COO and Chief Strategy Officer at Brinqa, about how AI-driven vulnerability discovery is widening the gap between finding and fixing security risks. Hibbert explains why organizations need to move beyond CVSS-based prioritization toward exposure management that accounts for exploitability, reachability, blast radius, attack paths, mitigating controls and business impact. The conversation also covers AI agents, MCP security, vulnerability chaining, automated remediation, shielding technologies, patch governance and why security teams must focus on reducing risk rather than simply counting patches.
Transcript
Hey guys, thanks for through. We're here with Brad Hibbert, who's COO and Chief Strategy Officer for Brinca, and we're having a little chat about what's going on with cybersecurity in the age of AI, because, well, there's a lot of things starting to roll downhill, and folks are starting to notice. Brad, welcome to the show.
Great. Thanks, Mike. Thanks for having me this morning.
I think the first thing people are starting to see is that, well, as more vulnerabilities are discovered, the fixes are in, but the patches themselves are starting to get large, and in some cases, very verbose. So from your perspective, what are the implications of that for folks as we look at this? Because I think they're just going to continue to get larger.
Yeah. We started tracking the volume of patches for the last number of years, and I think started doing write-ups a few months ago on our website just because we did see the volumes continue to increase. And for our clients, there's always been a disconnect or a chasm between the finding and the fixing, and that gap just continues to get bigger and bigger.
I think with Mythos or other AI models, their ability to find vulnerabilities quicker, I think, is certainly a challenge, right? So the number of vulnerabilities that organizations need to deal with has certainly gone through the roof. It doesn't mean they're all critical to your environment, we can get to that, but the number of vulnerabilities has certainly gotten a lot higher, and I think what Mythos showed the world is that AI can certainly find them faster, but it can also exploit them faster as well.
And so the time between discovery and exploitation has really shrunk down, putting a lot of pressure on teams to try to remove risk as quickly as possible. And as you mentioned, in some cases, those patches are difficult to get deployed. In other cases, the patches just don't exist yet.
So what is a team to do, right? And so those are some of the challenges that some of our clients come to us with, and they're looking for ways they can evolve their program to address this sort of modern challenge. I think some folks are hoping that Mythos, and now the latest version of ChatGPT, will have some restricted access, so maybe this tsunami of vulnerabilities will be held back.
But as far as I can tell, it looks like open source AI models aren't very far behind. So is this more a question of when rather than if? Yeah, I think you're absolutely right.
I think Mythos came out as more of a defensive model, right? Because it can help find but also weaponize the exploits very quickly. I think six weeks later, you saw that Daybreak came out from OpenAI, really more geared towards the defenders and the software builders to help them shift left and solve those problems.
But I do believe that these models are going to continue to mature. I think this is a persistent, elevated capability of the nefarious actors to have this type of AI intelligence in their hands, and you're going to see more models come out. And I would say within the next 12 to 18 months, whether it's a nation state or a well-funded cyber criminal organization or just the general hacker population, they're going to have these tools at their fingertips.
So I think this is something that's going to be persistent and just something that, again, as defenders, they're just going to have to elevate their game with respect to how they prioritize and how they remediate in the sort of modern threat world. We're also seeing the rise of AI agents, and for all intents and purposes, to me at least, they look like a new type of endpoint. In some cases, they can inherit the permissions and controls we apply to the end user that created them.
In other cases, though, it seems like they're semi-autonomous entities that maybe represent some type of new identity. But how are people approaching the security of AI agents? Yeah, it's a great question.
And of course, if you're like any other company, we leverage AI quite heavily within our development organization, for example, and even throughout the business. And I think we're certainly seeing that happen across our client base as well. When we talked about leveraging AI, not just from within a business perspective, but within their security program a couple of years ago, people just thought it was a nice conversation, but weren't really looking to act.
Now organizations are jumping in with both feet with respect to AI and AI agents, where you have different AI models talking to each other, and this has opened up some additional risks, right? It is infrastructure in many cases that you deploy, and like any infrastructure, you need to protect it. Wherein traditionally you would have things like SQL injection, you now have prompt injection, so there's a different type of attack that's happening.
And to your point, the big worry is just the amount of access that people are giving to these AI models, right? Again, it's great to feed the AI data because that's what it needs, but when you're giving it full rights to your Salesforce or to your GRC products or to your security tools, that opens up a wide range of privilege attacks, right? And a privilege attack vector.
So these are just things that people need to be aware of and ensure that they include that level of exploitability and prioritization within their exposure programs to address these things. The other thing we're starting to see is that these AI agents are talking to something called the Model Context Protocol, which seems to have been created to facilitate data access, but as far as I can tell, the specification, shall we say, is a little security light. Yeah.
So what do people need to think about here in terms of MCP and security? Yeah, I think it's going to get better. It's a new model, right?
To help different AI models and securely connect to enterprise tools, as you mentioned, right? And sources, like data sources and applications. But like any new standard, it does need to be built out.
We leverage it quite a bit. We offer that within our solution. Organizations that want to tap into our threat intelligence warehouse so their teams can make better prioritized risk-based decisions can tap into that.
But we've augmented MCP with additional capabilities around role-based access, right? Making sure that only the right personas can access that, making sure that the AI models are locked down to those personas, making sure that we're auditing everything that it's accessing, and that we have guardrails in place. So we have those things in place in our product as well as exposing that through the MCP interface itself.
So again, I think it's new. I think it is something that's going to mature over time, and certainly something that organizations are embracing to enable this sort of agentic world to continue to be elevated, so... Is it your sense that cybersecurity teams are being proactive about all this, or are they still kind of sitting on the sidelines waiting to see how it all evolves a bit before they start maybe investing more in various tools and platforms they might need?
Well, I think from my perspective, again, we are kind of a leader in exposure management. We've seen the interest. I guess exposure management's cool again because it's a big problem that they need to solve.
So I think people are trying to be proactive. I think CISOs are trying to be proactive when the board and when executive leadership read an article about Mythos, the first release that came out. " And then the reality of it is, there could be 30,000 out there, but it may not be impactful to you and your organization.
So I think that the whole shift away from just kind of stock ranking vulnerabilities from critical to low is kind of going away, and people have to take a look at what's really exploitable in your environment. And this is where people need to make that investment, right? So, out of the 30,000, for example, those new vulnerabilities, even if you have them in your environment, is it reachable by the bad guys, right?
Is it exploitable in your environment based on shielding technologies and mitigating controls that you have? And if it were to be exploited, what's the blast radius? And so I think where organizations are getting more proactive, and we're certainly seeing this with the inquiries that we're getting, is how they turn from a stack ranked CVSS approach to more of a real risk-based prioritization and a risk-based remediation approach within their exposure management programs.
And so I do think teams are trying to be proactive, but it's going to take a while for them to evolve every stage of that exposure life cycle. To your point about that, once I do rank them by severity and impact, are people moving towards some sort of automated patch management? Because right now we couldn't handle the number of patches we already had, and it took us weeks, months to kind of deploy them, and now we're going to have more vulnerabilities than ever, and we're supposed to be updating our patches.
But it seems like- Yeah ... this is going the wrong way. Yeah, I think there's two things on that.
I think one, from a prioritization perspective, I think people are going to move away from the stack rank, kind of high to low, because one of the things we didn't talk about was these tools like Mythos find them faster, they exploit them faster, but they're also getting more sophisticated, where they're chaining vulnerabilities together much more quickly as well. And so what I mean by that is you could have a low-level vulnerability, like a file pointer that gives you access to memory that you can overload and get a privilege. So there's this chaining of these vulnerabilities, and those vulnerabilities might not all be critical.
It could be three mediums, for example, that are linked together to result in a successful compromise. And so organizations need to move away from just looking at the top of the rank because all these mediums and lows that are kind of below that waterline aren't getting looked at, but they're the things that attackers could use. And so that's why I say that the prioritization has to become more sophisticated to look at what is the attack path, how can they leverage these vulnerabilities together to actually compromise a system?
And so that's the one thing. They have to get much more... It's not just about the business risk and the context and is it exploitable or not.
It's how can they be chained together, what mitigating controls you have in place, and doing this at scale with all this telemetry is very difficult to do, and why defensive teams need to use AI to help them with this prioritization effort. And then on the flip side of that, as you mentioned, on the remediation, I think just organizations have to embrace a two-step remediation process. Waiting for the patch isn't, as you mentioned, sometimes the patches are complex.
It takes time to validate, to test them, and so forth. Sometimes they're not available. So I think teams need to kind of move away from this kind of reporting on how well their team's doing by how many patches they deployed, more towards how much risk they're taking out of the environment.
And when they take risk out of the environment, you could be doing things other than deploying the patch. So you have to get, just like they're getting more precision on the prioritization side, more precision on the remediation side. If I know that a certain attack path is going through a certain protocol or a certain port, then I might have some tools in my arsenal here that I could deploy to activate a shielding technology in my firewall, or to disable a port.
So it's about removing the risk as much as you can before that patch can be deployed, right? So it's about getting more proactive with it, waiting for the patch, and I think organizations are going to move towards that with more automated remediation around those things that they can put in place that have less of an impact. But I do think they're going to also move towards autonomous remediation as well, where AI agents will start to do some of this risk removal, if you will, in certain scenarios.
So that's kind of what we're seeing our larger clients do, and certainly I think if you roll the clock forward a couple of years, I think you'll see that kind of be more pervasive across the broader market as well. So to your point, is the mindset changing? And I'm asking this question because a lot of times, organizations, especially IT folks, looked at a patch sometimes as the cure being worse than the disease.
And the issue was that this thing may break something and then they'd have a bigger problem. But as you kind of look at the level of risk now that certain vulnerabilities represent, are we kind of gotten to a point now where the vulnerability is a greater risk than the actual taking down of an application because, well, I might be able to fix that in a couple of minutes? Yeah, I think that's where that level of precision needs to come into play, and I think a lot of people think, well, if you start to automate things, not just patches, but these remediations, then you don't have appropriate governance controls in place to minimize the impact.
But I think this is where the security team and the operation teams need to get together, and they need to develop a cross-team playbook for what is that allowable level of risk that they're willing to take on, as opposed to waiting for these patch cycles every 30, 60, 90 days. And again, I think there's probably a lot more scenarios than teams are embracing today, where there is, again, I won't say a patch, but there is a mitigation that they could deploy to maybe not knock out the entire risk associated with the vulnerability, but a good portion of it, a good percentage of it. And so I do think that there's going to be a lot more openness to be more proactive with the remediation, based on the types of vulnerabilities that organizations are seeing.
Right. And to your point about automation, I think one of the things that a lot of organizations overlook is they get very excited about automating the deployment of the patch, but maybe they forget about the need to roll it back in case something goes wrong, and they don't quite have that whole workflow ironed out perfectly. Yeah.
So again, that's why the patches can... There's a reason that there's a delay between finding, even, again, many vulnerabilities that are within an organization today actually have a patch. So we always talk about the ones that don't have a patch yet in the zero days.
But many of them already have a patch, and the question is, well, if you have a patch, just roll it out. Why is there a delay? And there's certainly a reason to have that delay, right?
Like you mentioned, you have to test it. Having a patch on one application doesn't mean it's not going to break something in an adjacent application or business critical application. And so they have these steps for a reason.
They want to mitigate the risks of having sort of a spillover effect. And certainly, to roll those patches back also has an effect on production. And so again, I think there's always going to be that need to go through that validation process.
But again, I think that putting other controls in place and other mitigations and leveraging shielding technology more and more is going to be what organizations need to lean towards. So I think that's just going to be something they need to do. That gap between the number of vulnerabilities and the fixes is going to continue to get bigger unless we speed up the proactive remediation and either speed up the patches, which I think companies are starting to do.
I think about Mythos and the Glasswing project. A lot of these companies are now embracing AI to find the vulnerabilities in their code before they release it. So I think that ultimately, I think code is going to become much more secure over the next couple of years.
But again, there's always going to be the need to do a patch, and there's always something that slips through. And so the need to roll back the patches is impactful to the operation, and again, why I think that there's other ways that organizations need to look at how to reduce the risk. Again, it's not about deploying the patch, it's about how much risk can you take out of the organization.
That doesn't always mean a patch right away. It means giving your team time to patch by removing the risk ahead of time. " But either way- Yeah ...
Brad, last question. What's your best advice to security leaders here as they look at all of this? Because I think a lot of them right now are kind of having that feeling of being the deer in the headlights.
Yeah, and I think that a lot of customers come to us. The questions you always get is, when Mythos first came out, was, "Well, do I throw my hands in the air? " And of course, the reality of it is, it does.
As I said, the highlights in the media with the 30,000 new vulnerabilities, all those things are interesting and important, but really it is how do they really impact in your environment. Again, what's exploitable, what's reachable, what's the blast radius of these things in your environment? And from that perspective, I would say that organizations just embrace best practices, take a look at that exposure life cycle of discovery, prioritization, validation, mobilization, remediation, and you have to uplevel each of those different stages.
And there's certainly technology and partners that can help you do that. You just have to identify what are the areas and how do you want to prioritize those. And so there's help out there.
Just break it down into the manageable chunks and start working your way through evolving your program to take on the modern threat. All right, folks. You heard it here.
Hey, all this stuff is happening at machine speed now, with the one thing you can afford to do is give up the ship. Hey, Brad, thanks for being on the show. Great.
Thanks for having me. All right. And back to you guys in the studio.