Chris Wallis on Attack Surface Risk and AI-Driven Vulnerability Discovery at KB4-CON 2026
Chris Wallis, CEO and co-founder of Intruder, joins Techstrong TV at KB4-CON 2026 to discuss how attack surface management is evolving as AI accelerates vulnerability discovery. The conversation covers exposed internet-facing software, zero-day response, Index Insights and how security teams can improve visibility and prioritization before attackers exploit newly disclosed vulnerabilities.
Transcript
Hey everyone, Alan Shimel back here at KB4CON in Orlando. Our next guest is Chris Wallis. He's the CEO and co-founder of Intruder, and let's welcome him.
Chris, welcome to Techstrong TV. It's great to have you on here. Thank you, Alan.
Great to be here. So I always loved interviewing co-founder, founder CEOs because I like to understand what made them sign up for this insanity. Yeah.
And I've seen themes over the years, but I'm going to let you explain your own personal- Journey ... journey on it. The story.
And if you don't mind, share it with the audience. Yeah. So I guess I spent most of my career working as a pen tester or ethical hacker.
Mm-hmm. Hacking into high street banks and household names in the UK, and some UK government systems as well. And a lot of the ways that I was doing that was frequently that they just left something online that shouldn't have been there.
That they already had vulnerability scanning tools that would detect all the misconfigurations and the- Yeah ... the software that needed updates, but then they would leave an admin panel facing the internet or a database just sitting there waiting for someone to log in, and that gives you just enough of a foothold to then do the breaking in. It just gives you a thread to pull on, and often that's the way that you then get in.
I then spent some time working inside a company using the tools they had available to detect all of this stuff, and I just felt like they weren't doing a good enough job of highlighting those things that we call attack surface issues. And I left that company to start Intruder about 10, 11 years ago. Really?
Yeah. So you're doing this Intruder now 10, 11 years. 11 years, yeah.
As of April. And now, yeah, 3,000 customers, most of those in North America, and smattered across the rest of the world as well, so. I love it.
" I think the real nudge was being in that seat, using the software that that company had available to them, and thinking even with my background as a penetration tester, 10 years experience, expert in the field, and I still found that software at times difficult to use, difficult to understand, complicated to configure, and just took a ton of time that it didn't need. And I thought if I'm struggling with this as an experienced person in this big company with all the resources, then what's every other company in the world doing? Like when they either don't have someone like me, can't afford someone like that, or they just can't defend themselves properly.
And I felt like there needed to be software that existed for that type of customer. So Intruder really specializes in the small to mid-size, mid-market companies who don't have the same resources as the big banks do with all the kind of people and tooling that they have, but they still have to defend themselves against the same threat, like ShinyHunters and all the others that are out there targeting every company, not just the big ones anymore. So yeah, they all need software that does what we do.
Absolutely. Let's get some housekeeping out of the way. For people who want to find out more about Intruder, what's the website?
io. io. Free trial available, so they can go one step further and sign up and receive pretty much most of the benefits the platform brings for 15 days.
And that's how most of our customers sign up. They just use the platform, love the platform, and then, yeah, customer comes out the back end. Excellent.
Before we jump into KnowBe4 and you guys are a sponsor here, I'd be negligent if I didn't bring up what's been going on lately in the world with Mythos and vulnerability discovery and the effect it's had in AppSec. It's like a wave, overlapping or overrunning so much of the industry that I've grown up in, right? Yeah.
What's been your take on that, Chris? It's a fascinating time, right? It's a really, really interesting time for cybersecurity, and I'm excited.
I think there's people who are looking at the downsides of this. " And some of that might be true, but I think anytime you have a big period of change, there's always opportunity as well, I think. Absolutely.
I'm super excited about the opportunity. We're bringing AI capabilities into Intruder, and we're maximizing all the value we can use from them to give to our customers. So we've just released AI pen testing, so that on top of the scan results that we already have, you can now deploy an AI agent to go and delve into the issue like a pen tester would, and provide a even higher quality of answer to the customer on how they're exposed.
So really exciting time for us and I'm really excited about what AI can do. Absolutely. Look, I've spoken to a lot of my friends in security about this over the last month or two, and to me, I think the fundamental change is for an industry that spent an awful lot of time finding vulnerabilities, we now have to spend a lot more time verifying true vulnerabilities and fixing them.
Yeah. Absolutely. There's a bunch of ways that it's impacting people, I think, and one of them is there's going to be even more vulnerabilities.
That's clear. Absolutely. We're seeing it already.
Exactly. We're already seeing it happen, and it's just going to continue. And it's not just Mythos.
I think Anthropic have done an amazing job of capturing the whole hype cycle here. But OpenAI have just released a cybersecurity model that's performed equally well, and there's other startups with models that are doing amazing things too. Yeah.
I think it's a really exciting time and yeah, really look forward to getting stuck into it. Absolutely. Hey, I want to now pivot and talk a little bit about KB4CON.
Mm. So I mentioned you guys are a sponsor. Is this your first time sponsoring?
First time sponsoring, first time here. I love it. I think it's a great conference, and yeah, having a good time- Very cool ...
so far, so we'll be back. Well, you heard it here first. He's already signed up for next year.
Chris, what made you guys look at this and say, "Yep, these might be our people"? I guess it was a partnership. So we also partner with some of the other sponsors here.
We work with the same types of customers, and they just gave us a tip-off really that the types of customers that are coming here, we all share. So it's the same buyer pool, the same type of customers who may not have the same resources as all the big banks do. So I think it's that kind of shared customer problems.
Even though we offer different solutions, it's the same kind of customers that need to defend themselves against- It's the same persona of the people coming here. Exactly. And I guess based upon your response, that's been verified.
Yeah. It's been really great. Really great conversations so far.
We had a line coming up to the booth yesterday at 4:00, which I've been doing this for 11 years, I've never seen a line- Right ... yeah, coming up to the booth. So yeah.
It's always nice. Yeah. As a CEO, you always want to see a line.
Exactly. Have the conversations been a lot about AI, agentics, and stuff like that? Definitely, yeah.
So because of our new release, we've just updated our messaging to include the AI piece, and it's actually really interesting to see the response. Yeah, people are really interested by it. One of the interesting conversations I had was not everyone's ready to pull the trigger on it, and then sometimes people say cybersecurity moves really fast, but actually, it often moves at the speed of compliance, which sometimes can be quite slow.
Slower speed. Exactly. Well, more so here than in the EU, certainly, right?
Yeah. We seem to have a hard time finding the will to get something done, where the EU- Exactly. And insurance companies as well are not known for being the fastest companies- No ...
on the planet. And it's those kind of compliance regulations, the conversation I had, the guy was loving what we were doing, but he said, "I still need to do my annual pen test," because that's what the compliance requirement is. And that's really challenging when you have a solution that is way better than the status quo, and yet people are kind of handicapped almost in kind of- Yeah.
100 years ago, I went to law school. Mm. Before I got into computers and I graduated, practiced law.
One of my law school professors, he was pretty well-known. He was out of Stanford. I didn't go to Stanford Law School, but he taught there years ago to a couple Supreme Court justices.
And he said that generally, legislation is always three to five years behind- Right ... the state of technology. Interesting.
And I think, unfortunately, it hasn't changed. Yeah. Here in the US, anyway.
So, yes, to be PCI compliant or be compliant with CCP, the California or what have you, they're still going to insist you do a yearly pen test- PCI ... report, even though, with AI, you're being pen tested every day, it seems. Yeah.
Exactly, and I think PCI is a really great example of exactly what I just said, which is they still have their quarterly scans that they mandate, and a- Mm-hmm ... quarterly scan hasn't been good enough by far for quite some time. No.
The mean time to exploit now is days. It's projected to- Going down to hours. Or minutes.
It'll be hours by the end of the year, and still, we have PCI saying that a quarterly scan is the requirement, so. Look, I've always believed, I've been in security 30 years, compliance is the lowest common denominator or least- Yeah ... common denominator, and unfortunately, there are far too many organizations that manage to that.
Like checkbox security, right? Yeah. " Mm.
But I don't know if that's the people who are here. No. I think it's sometimes just a case of resources, though.
If you have a certain amount of resources and you have to do something like the annual pen test, then your resources get taken up by that, and that can inhibit you from then- Because that mandates it, yeah ... even if you want the better solution, your budget's been taken by the inferior one. So, I think the desire is there.
Definitely the conversation I had yesterday, that the person really wanted to kind of modernize the solution, but was a little restricted by what he could do, essentially. Absolutely. Just want to look over here and make sure we've got everything covered.
You mentioned some of the other part, is it's all sort of this ecosystem, if you will. Yeah. Right?
How do you think AI makes for strange bedfellows, is one way of looking at it, right? Yeah. How do you think new combinations, new partners, new technologies, all start kind of playing in here as a result of this?
I think things are going to converge, what we're seeing. So, what even is a pen test anymore? I think in the past, a pen test was a human would come and do some stuff for a few hours, but AI is so capable, it can review the code, it can run a pen test, it can do other stuff as well, and I think things are just going to start to become, maybe we'll just call it security, a security review, instead of a SAS scan or a DAST scan or- Yeah, no, I don't know if we're going to be doing SAS, DAST, or what's the open source...
Oh, that dependency scanning, all that stuff. Yeah. All of that is going to just, AI's going to flatten that whole thing into just security testing.
Exactly. I think you'll call it a security test or continuous security review, and it'll generally would be one platform, and organizations won't have to buy five or six different tools, and yeah. There's a lot of sprawl at the moment in the security stack, so.
I don't know how much of that was by design, to tell you the truth. As I look back, as I've watched this kind of develop- Mm ... you had SAS, DAST, and you had a lot of companies that were doing, was it TSA is the, for open source?
Yeah. Software composition analysis, right? Right.
Software composites- Yeah ... SCA. Yeah.
I think all of that's being subsumed into it. The question is, some people call it the human in the loop. Others say, "Well, that's not going to scale.
" Yeah. But you may automate scanning. You're not going to automate necessarily security or being secure.
No. I think you'll never get 100%, right? But what we're really excited by is what we've seen so far from AI is how capable it is.
So, we've been testing our own solution on our own platform, and it's uncovered some issues that survived through- Really? multiple pen tests. There's stuff that humans didn't find, and the AI uncovered.
So, we're really excited by it. I think it's going to definitely level up everyone's security, and in the short term, kind of bring this amazing capable technology to the masses, really. So, it's an exciting time, I think, in cybersecurity.
I love it. io. io, yeah.
I want to make sure people get that. Hey, you can get more information on Chris and the company. Yeah.
io. Chris, thanks for popping in. Such a pleasure.
I know it's kind of lunch period here, but people will be at your booth. Yeah. You've got to go have some talks.
Hopefully another queue, yeah. All righty. Thanks so much for having me.
Chris Wallis, CEO and co-founder of Intruder, here at KB4CON 2026. We've got a lot more coverage. Stay tuned for our next one.