Enterprise Security Weekly (Audio) Can AI help critical infrastructure, the state of the cyber market, and weekly news - Mike Privette, Kara Sprague - ESW #451
12 snips
Mar 23, 2026 Kara Sprague, CEO of HackerOne, expert in vulnerability disclosure and AI-driven triage. Mike Prevett, founder of Return on Security, market intelligence analyst tracking cybersecurity funding and trends. They discuss how AI can triage and validate vulnerabilities in legacy critical infrastructure. They also cover the current cybersecurity market, funding shifts, AI’s role in tools and teams, and industry-wide changes.
AI Snips
Chapters
Transcript
Episode notes
Pen Test Found Kitchen Door Protecting Critical Plant
- Adrian recounts an OT pentest where the data center door was a simple swinging kitchen-style door controlling critical aluminum smelting equipment.
- He notes physical/operational fragility: shutting equipment off can take weeks to recover.
Combine AI Validation With Human Researcher Judgment
- Use AI to augment human researchers rather than replace them: automate triage and validation but keep human judgment to prioritize exploitability.
- Kara details HackerOne's validation agent plus community edition to scale validation while preserving researcher discernment.
Human Researchers Deliver Superior Exploit Signal
- Human bionic researchers plus AI produce far higher-fidelity vulnerability signals than scanners alone, with ~20–25% of HackerOne reports being exploitable.
- Kara contrasts 4 million scanner findings a year (mostly noise) versus platform reports with much higher exploitability rates.
