
Ten Out of Ten Thousand: Pen Testing, Triage, and Fixes at Machine Speed
Show notes
A point-in-time security assessment can be out of date the moment the report arrives. When new vulnerabilities can move from detection to exploitation in hours, the harder problem is no longer finding more. It is knowing which ones matter and fixing them fast enough.
In this episode of The Blind Spot, Jason Lee sits down with Dave Gerry, CEO of Bugcrowd, to discuss what happens when attack, detection, and response all move at machine speed. They cover how AI is changing penetration testing, why continuous testing matters, how security leaders can prioritize ten meaningful vulnerabilities out of ten thousand findings, and why remediation remains the industry's hardest problem. They also get into the security fundamentals that still matter for budget-constrained teams, why outdated processes create more risk than a lack of tools, how to hire for motivation and coachability, and what boards should understand about the day-to-day reality of operating through constant change.
About the host
Jason Lee is Managing Director at Z Cyber. For more than 20 years he has worked the part most people skip past: what happens after the risk is visible, across infrastructure, AI, and GRC.
About the guest
Dave Gerry is CEO of Bugcrowd, an offensive security platform that connects organizations with a global community of security researchers. His work focuses on combining human ingenuity with AI to help organizations test more continuously, prioritize the vulnerabilities that matter, and improve how they respond.
About Z Cyber
Z Cyber is the security team that builds, runs, and improves your program through an Executive Security Advisor and Glance, its AI-native GRC platform.
Links
Z Cyber: https://www.ztekcyber.com
The Blind Spot: https://www.ztekcyber.com/resources/the-blind-spot
Apply to be a guest: https://www.ztekcyber.com/resources/the-blind-spot/apply
Get started with Z Cyber: https://www.ztekcyber.com/get-started