Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: How AI Gives Defenders the Edge in Cybersecurity

Onapsis
07/17/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


And creating code way faster, with more volume of code. There's a lot of concerns of whether the code is actually secure. Pacific has total capabilities like jewel-based assistance where you can actually generate code. Based on our analysis, it's very, very important that organizations run those new AI-generated code capabilities through security controls. Otherwise, you're pushing insecure or potentially malicious code into production, which can be very dangerous. I think, again, for this, a lot of like kind of threats and pessimism in one perspective. I think, as we know, there's also a recognition, I think, from last practitioners that AI can be actually be used for good, right? So I'm curious about, Juergen, and I think you were touching a little bit on it, like where do you see that AI can actually be used by defenders to really protect themselves against this new reality? Yeah, before I respond to that, I just wanted to add to your previous comment, right, that exposure window. I think that's an important topic for enterprises to realize with this new wave of zero days and vulnerabilities being identified by AI. Already in our 2025 M-Trends reports, we saw that the average exposure window is now negative seven days. What this means is that attackers are using vulnerabilities before a patch is even realized. That means you, as a CISO, will have to accept that you're going to have vulnerabilities, you're not going to be able to patch fast enough. That is one reason. The other reason is just simply that we expect, of course, a very significant number of vulnerabilities to be identified. And as we've already seen in the past several years, we're going to also deal with vulnerabilities in systems that can no longer be patched. Maybe the manufacturer no longer exists, the devices are end of support, end of life. Most enterprises deal with challenges like that. And I think this is a critical moment for us, again, as cybersecurity professionals, to realize, to go back to a lot of the foundations that we've been talking about for so long. Defense in depth, zero trust architectures, improving cyber defense capabilities. All of these things are going to be critically important. Obviously, patching and changing and updating your vulnerability management program is absolutely critical. Reducing your attack surface is critical. But also, all of the additional security controls that we've been talking about for all these years are going to be critical because you have to assume breach. You have to assume you're going to have issues that you're not going to be able to fix fast enough before a threat actor potentially identifies that. But I agree with you. Let's leave the doom and gloom a little bit behind us. And let's also talk about how AI helps the defenders. And by the way, I do believe that AI will give a greater advantage to the defenders than to the threat actors, right? It may seem at times like things are not in perfect balance, but I think over time, AI is a huge advantage for us as defenders.

TL;DR

  • AI-generated code is being produced faster than security teams can review it, creating serious risk of insecure or malicious code reaching production systems.
  • Mandiant's 2025 M-Trends report reveals the average vulnerability exposure window is now negative seven days — attackers exploit flaws before patches exist.
  • CISOs must adopt a breach-assumption posture, reinforcing defense in depth, zero trust, and attack surface reduction as non-negotiable foundations.

Summary

This short clip, drawn from a broader conversation between Onapsis and Mandiant practitioners, examines the dual role AI plays in modern cybersecurity — as both an accelerant for attackers and a force multiplier for defenders. The discussion opens with a pressing concern: AI-assisted code generation is producing larger volumes of code at unprecedented speed, but without adequate security controls, organizations risk pushing insecure or even malicious code directly into production environments. A key data point from Mandiant's 2025 M-Trends report underscores the urgency — the average vulnerability exposure window has turned negative, now sitting at minus seven days, meaning attackers are actively exploiting vulnerabilities before patches are even released. This reality forces CISOs to accept that perfect patch coverage is no longer achievable and that a breach-assumption mindset is essential. The conversation then pivots toward optimism, with the speaker arguing that foundational security principles — defense in depth, zero trust architectures, attack surface reduction, and robust vulnerability management — remain critically relevant and are now amplified by AI capabilities. The clip closes with a strong positioning statement: AI will ultimately confer a greater strategic advantage to defenders than to threat actors, even if the current moment feels unbalanced.

Chapters

0:00 - AI Code Generation Risks
1:01 - Negative Exposure Window Reality
2:00 - Foundational Defense Principles
2:46 - AI as a Defender's Advantage

Key Quotes

1:15 "Already in our 2025 M-Trends reports, we saw that the average exposure window is now negative seven days."
1:22 "What this means is that attackers are using vulnerabilities before a patch is even realized."
2:29 "All of the additional security controls that we've been talking about for all these years are going to be critical because you have to assume breach."
2:53 "I do believe that AI will give a greater advantage to the defenders than to the threat actors, right? ..."

FAQ

What does a negative vulnerability exposure window mean for enterprise security teams?

According to Mandiant's 2025 M-Trends report, the average exposure window is now negative seven days, meaning attackers are exploiting vulnerabilities before a patch has even been released. This means CISOs must accept that some vulnerabilities will be exploited before they can be remediated and should plan accordingly with breach-assumption strategies.

How can AI be used defensively rather than just as a threat vector?

The speaker argues that AI can act as a force multiplier for defenders — improving threat detection speed, automating response, and strengthening overall cyber defense capabilities. Over time, the belief is that AI will confer a greater strategic advantage to defenders than to threat actors.


Categories:
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Threat Intelligence
  • Vulnerability Management
  • Zero Trust
  • Security Operations
  • Thought Leadership
  • Executive Briefing
  • AI in cybersecurity
  • Vulnerability exposure window
  • Zero trust architecture
  • Defense in depth
  • AI-generated code security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: How AI Gives Defenders the Edge in Cybersecurity

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  Unveiling the AI-Driven Underworld of Automation's Rapid Rise

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Unseen Data: The Blind Spot in Your Protection Strategies

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      Unveiling the AI-Driven Underworld of Automation's Rapid Rise
                      https://www.truthinit.com/index.php/channel/2108/unveiling-the-ai-driven-underworld-of-automations-rapid-rise/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Unseen Data: The Blind Spot in Your Protection Strategies
                      https://www.truthinit.com/index.php/channel/2087/unseen-data-the-blind-spot-in-your-protection-strategies/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version