Podcast Appearance! | The Evolution of Vulnerability Management | SecuritySpace Podcast
Big thanks to Nick for hosting me and letting me talk a little bit about the fun world of vulnerability management. Feel free to give it a listen and peruse Nick’s wide library of other conversations if you’re so inclined!
Some thoughts…
It’s been a while since I’ve been in that full-on vulnerability headspace. It’s fun to revisit and also a tiny bit traumatising. VM is still very much part of my job as Head of Cyber Security, but it’s easy to let it melt into the pot of all the other things you’re cooking with when you have to take responsibility for it all. It’s still a focus, but it’s very different when you can’t make it your entirety.
My approach now is to prioritise and focus what resources we have on ‘true threats’. Will I ever really be sure what is a true threat and what can be ignored? Probably not - but we do what we can with what we have. Bring in as much external data as you can, apply business logic to it, and prioritise from there. Simple! (not).
Since this conversation back in November of last year, there’s been swarms of information surrounding AI vulnerability discoveries, Mythos, Agents breaking out of sandboxes, fully autonomous threats etc. There’s enough here to keep any security professional on their toes. It expands and grows faster than it can be fully unravelled. I’m not sure where we’ll be when the dust fully settles, but we live in very interesting times.
One uncomfortable part of this and generally posting any moderately authoritative piece online with my opinions therein is how quickly outdated it could become. That, and I always fear the bigger, stronger vulnerability manager will come and tell me how they can’t believe that I’m still doing it that way.
Nevertheless, I hope some use can be extracted from any of the content I choose to share.

