Tech Talks Daily

Cobalt Shares Hard Lessons From the State of Pen Testing Report

Jan 29, 2026
Sonali Shah, CEO of Cobalt and cybersecurity veteran across finance, engineering, product and strategy, discusses how AI is speeding up reconnaissance and exploitation. She highlights findings from Cobalt’s State of Pentesting on remediation times, low closure rates, and why large enterprises lag. The conversation centers on continuous, human-validated testing, risks in generative AI and LLMs, and practical steps to reduce programmatic risk.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

AI Accelerates The Attack Lifecycle

  • AI enables attackers to automate reconnaissance and find vulnerabilities much faster than before.
  • Sonali Shah warns AI agents can perform 70–80% of attack tasks with minimal human guidance.
INSIGHT

Faster Fixes But Flat Closure Rates

  • Median remediation for serious vulnerabilities improved from 112 to 37 days since 2017.
  • Yet overall closure rates remain around 55%, showing fixes still lag behind discovery.
INSIGHT

Tech Debt Slows Enterprise Remediation

  • Legacy systems and technical debt slow enterprises more than smaller firms.
  • Sonali Shah explains older code is costly and risky to modify, delaying remediation.
Get the Snipd Podcast app to discover more snips from this episode
Get the app