Cobalt Shares Hard Lessons From the State of Pen Testing Report

Cobalt Shares Hard Lessons From the State of Pen Testing Report

What happens when artificial intelligence starts accelerating cyberattacks faster than most organizations can test, fix, and respond?

In this episode of Tech Talks Daily, I sat down with Sonali Shah, CEO of Cobalt, to unpack what real-world penetration testing data is revealing about the current state of enterprise security. With more than two decades in cybersecurity and a background that spans finance, engineering, product, and strategy, Sonali brings a grounded, operator-level view of where security teams are keeping up and where they are quietly falling behind.

Our conversation centers on what happens when AI moves from an experiment to an attack surface. Sonali explains how threat actors are already using the same AI-enabled tools as defenders to automate reconnaissance, identify vulnerabilities, and speed up exploitation. We discuss why this is no longer theoretical, referencing findings from companies like Anthropic, including examples where models such as Claude have demonstrated both power and unpredictability. The takeaway is sobering but balanced. AI can automate a large share of the work, but human expertise still plays a defining role, both for attackers and defenders.

We also dig into Cobalt's latest State of Pentesting data, including why median remediation times for serious vulnerabilities have improved while overall closure rates remain stubbornly low. Sonali breaks down why large enterprises struggle more than smaller organizations, how legacy systems slow progress, and why generative AI applications currently show some of the highest risk with some of the lowest fix rates. As more companies rush to deploy AI agents into production, this gap becomes harder to ignore.

One of the strongest themes in this episode is the shift from point-in-time testing to continuous, programmatic risk reduction. Sonali explains what effective continuous pentesting looks like in practice, why automation alone creates noise and friction, and how human-led testing helps teams move from assumptions to evidence. We also address a persistent confidence gap, where leaders believe their security posture is strong, even when testing shows otherwise.

We close by tackling one of the biggest myths in cybersecurity. Security is never finished. It is a constant process of preparation, testing, learning, and improvement. The organizations that perform best accept this reality and build security into daily operations rather than treating it as a one-off task.

So as AI continues to accelerate both innovation and attacks, how confident are you that your security program is keeping pace, and what would continuous testing change inside your organization? I would love to hear your thoughts.

Useful Links

Thanks to our sponsors, Alcor, for supporting the show.

Episoder(2000)

Who Is Winning The AI Race? The Clarivate AI50 Report Has The Receipts

Who Is Winning The AI Race? The Clarivate AI50 Report Has The Receipts

What does it really mean to lead in AI when the headlines are loud, the claims are endless, and the real signals are often buried under hype? In this episode, I sit down with Ed White from Clarivate t...

26 Mar 31min

How IFS Nexus Black Is Turning Industrial AI Into Real World Results

How IFS Nexus Black Is Turning Industrial AI Into Real World Results

What does it really take to move AI from impressive demos into the hands of the people who keep the world running every day? In this episode of Tech Talks Daily, I sat down with Kriti Sharma, CEO of I...

25 Mar 29min

Boku and the Future of Agentic Commerce and Payments

Boku and the Future of Agentic Commerce and Payments

How are global payment systems quietly shifting beneath our feet, and what does that mean for businesses trying to grow across borders? In this episode of Tech Talks Daily, I sat down with Stuart Neal...

25 Mar 28min

How DDN And NVIDIA Are Rethinking AI Infrastructure For The Rubin Era

How DDN And NVIDIA Are Rethinking AI Infrastructure For The Rubin Era

What does it really take to turn a massive AI infrastructure investment into actual business value? In this episode, I'm joined by Alex Bouzari, founder and CEO of DDN, for a conversation that gets ri...

24 Mar 32min

How GoTo Sees The Reality Of AI Adoption In The Workplace

How GoTo Sees The Reality Of AI Adoption In The Workplace

Are employees really ready for AI in the workplace, or are we moving faster than people can realistically keep up? In this episode, I'm joined by David Evans, Chief Product Strategist at GoTo, to expl...

23 Mar 32min

How TheyDo And PwC Are Rethinking Customer Experience At Scale

How TheyDo And PwC Are Rethinking Customer Experience At Scale

How can companies be drowning in customer data and still struggle to make better decisions? In this episode, I speak with Jochem van der Veer, CEO and co-founder of TheyDo, about a problem that many b...

22 Mar 24min

How Permutable AI Is Turning Unstructured Data Into Trading Insight

How Permutable AI Is Turning Unstructured Data Into Trading Insight

What happens when financial markets stop reacting to data and start reacting to narratives in real time? In this episode, I'm joined by Wilson Chan, CEO and founder of Permutable AI, to explore how ar...

21 Mar 21min

How Legrand Turned Customer Feedback Into Action Across A Global Business

How Legrand Turned Customer Feedback Into Action Across A Global Business

What does customer experience look like inside a company most people associate with switches, infrastructure, and engineering rather than surveys, empathy, and brand perception? In this episode, recor...

20 Mar 29min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
forklart
stopp-verden
popradet
lydartikler-fra-aftenposten
det-store-bildet
nokon-ma-ga
rss-gukild-johaug
fotballpodden-2
dine-penger-pengeradet
aftenbla-bla
rss-ness
rss-espen-lee-usensurert
hanna-de-heldige
rss-dannet-uten-piano
e24-podden
frokostshowet-pa-p5
rss-penger-polser-og-politikk