Podcasts & episodes

The shift to exposure first vulnerability management
Vulnerability management is undergoing a fundamental shift. The old model of quarterly scans and CVSS-based patching is no longer just outdated. It is actively dangerous. In this episode, James and Katie explore the move to exposure-first security and why speed, accountability, and visibility are now the defining factors of modern defense. They break down how exploit velocity, new regulations, and supply chain transparency have rewritten the rules, and why frameworks like KEV, EPSS, CTEM, and NIST CSF 2.0 are becoming mandatory, not optional. The discussion connects prioritization, engineering practices, automation, and governance into one continuous program focused on reducing real attack paths instead of chasing endless vulnerability lists.

