Skip to main content
Episode 04/43 min

Ten Out of Ten Thousand: Pen Testing, Triage, and Fixes at Machine Speed

Dave Gerry

Chief Executive Officer · Bugcrowd

Dave Gerry

About This Episode

Jason Lee sits down with Dave Gerry, CEO of Bugcrowd, one of the largest offensive security platforms in the world, on what happens when attack, detection, and response all move at machine speed. Bugcrowd connects customers with a community of 700,000 security researchers, and 82 percent of the hackers on the platform are already using AI in their work.

They get into how AI has split pen testing into two worlds (fully agentic testing and human testing augmented by AI), why point-in-time assessments go stale the moment the report arrives, how a security leader triages ten meaningful vulnerabilities out of ten thousand findings when criticality can change in real time, why remediation remains the industry's hardest problem, what budget-constrained defenders can still do with fundamentals and good-enough open source models, why process failures beat tooling gaps as the real cause of security failure, hiring for motivation and coachability over pedigree, and why buyers should be choosing a partner, not just software.

Detection's the easy part. The hard part now is how do you pick the ten from the ten thousand that actually matter.

Dave Gerry, Bugcrowd

In This Episode

  • 01Detection is commoditized. The hard problem is triage: picking the ten vulnerabilities out of ten thousand findings that actually matter, then giving the people downstream enough context to fix them fast.
  • 02The clock has collapsed. Detection to working exploit is running about 22 hours, so remediation has to be measured in hours, not days, and a point-in-time attestation can be stale an hour after it lands.
  • 03Agentic pen testing changes the unit economics. The same testing budget can now cover thousands of assets continuously, with human testers reserved for the crown-jewel applications.
  • 04Prioritization itself has changed. Vulnerability chaining means a CVSS score alone is no longer the lens; you have to understand your estate, your architecture, and the context around each finding. AI does not care how boring the legacy system is.
  • 05Process is where programs actually fail, and fundamentals still move the needle most. Budget-constrained defenders can tap good-enough open source models with the right controls, but the answer is not more tools, it is adapting the process for an AI-first era.
Dave Gerry

About the Guest

Dave Gerry

Chief Executive Officer · Bugcrowd

Dave Gerry is the CEO of Bugcrowd, an offensive security platform that connects organizations with a global community of 700,000 security researchers. He has spent most of his career in application and product security, including six years at WhiteHat Security, and his work now focuses on combining human ingenuity with AI so organizations can test continuously, prioritize the vulnerabilities that matter, and fix them faster. He also sits on the boards of several university cybersecurity programs.

Follow the Show

The Blind Spot

Cybersecurity conversations on what happens after the risk is visible. Subscribe so you do not miss an episode.