Tech Talks Daily

Cobalt Shares Hard Lessons From the State of Pen Testing Report


Listen Later

What happens when artificial intelligence starts accelerating cyberattacks faster than most organizations can test, fix, and respond?

In this episode of Tech Talks Daily, I sat down with Sonali Shah, CEO of Cobalt, to unpack what real-world penetration testing data is revealing about the current state of enterprise security. With more than two decades in cybersecurity and a background that spans finance, engineering, product, and strategy, Sonali brings a grounded, operator-level view of where security teams are keeping up and where they are quietly falling behind.

Our conversation centers on what happens when AI moves from an experiment to an attack surface. Sonali explains how threat actors are already using the same AI-enabled tools as defenders to automate reconnaissance, identify vulnerabilities, and speed up exploitation. We discuss why this is no longer theoretical, referencing findings from companies like Anthropic, including examples where models such as Claude have demonstrated both power and unpredictability. The takeaway is sobering but balanced. AI can automate a large share of the work, but human expertise still plays a defining role, both for attackers and defenders.

We also dig into Cobalt's latest State of Pentesting data, including why median remediation times for serious vulnerabilities have improved while overall closure rates remain stubbornly low. Sonali breaks down why large enterprises struggle more than smaller organizations, how legacy systems slow progress, and why generative AI applications currently show some of the highest risk with some of the lowest fix rates. As more companies rush to deploy AI agents into production, this gap becomes harder to ignore.

One of the strongest themes in this episode is the shift from point-in-time testing to continuous, programmatic risk reduction. Sonali explains what effective continuous pentesting looks like in practice, why automation alone creates noise and friction, and how human-led testing helps teams move from assumptions to evidence. We also address a persistent confidence gap, where leaders believe their security posture is strong, even when testing shows otherwise.

We close by tackling one of the biggest myths in cybersecurity. Security is never finished. It is a constant process of preparation, testing, learning, and improvement. The organizations that perform best accept this reality and build security into daily operations rather than treating it as a one-off task.

So as AI continues to accelerate both innovation and attacks, how confident are you that your security program is keeping pace, and what would continuous testing change inside your organization? I would love to hear your thoughts.

Useful Links

  • Connect with Sonali Shah
  • Learn more about Cobalt
  • Check out the Cobalt Learning Center
  • State of Pentesting Report

Thanks to our sponsors, Alcor, for supporting the show.

...more
View all episodesView all episodes
Download on the App Store

Tech Talks DailyBy Neil C. Hughes

  • 5
  • 5
  • 5
  • 5
  • 5

5

200 ratings


More shows like Tech Talks Daily

View all
This Week in Startups by Jason Calacanis

This Week in Startups

1,299 Listeners

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch by Harry Stebbings

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch

548 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,657 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,095 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

630 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,024 Listeners

Super Data Science: ML & AI Podcast with Jon Krohn by Jon Krohn

Super Data Science: ML & AI Podcast with Jon Krohn

306 Listeners

NVIDIA AI Podcast by NVIDIA

NVIDIA AI Podcast

347 Listeners

Y Combinator Startup Podcast by Y Combinator

Y Combinator Startup Podcast

235 Listeners

Practical AI by Practical AI LLC

Practical AI

209 Listeners

Big Technology Podcast by Alex Kantrowitz

Big Technology Podcast

512 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Business Breakdowns by Colossus | Investing & Business Podcasts

Business Breakdowns

354 Listeners

Bloomberg Tech by Bloomberg

Bloomberg Tech

68 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

675 Listeners

Consulting the Future by Neil C. Hughes

Consulting the Future

0 Listeners

Startup Builders & Backers by Neil C. Hughes

Startup Builders & Backers

0 Listeners

IT Infrastructure as a Conversation by Neil C. Hughes

IT Infrastructure as a Conversation

0 Listeners

AI at Work by Neil C. Hughes

AI at Work

0 Listeners

The Business of Cybersecurity by Neil C. Hughes

The Business of Cybersecurity

0 Listeners

Business Technology Perspectives by Neil Hughes

Business Technology Perspectives

0 Listeners

Conversations from the Show Floor by Neil C. Hughes

Conversations from the Show Floor

0 Listeners