FIRESIDE CHAT : NOPSEC & MARSH

How Project Glasswing and Mythos Impact Exposure Assessment and the Future of Agentic AI Pentesting

Watch the full replay below

 

Attackers Now Weaponize Vulnerabilities in Hours. Most Security Teams Still Remediate in Weeks.

A vulnerability drops in the morning. By the afternoon it is being weaponized and scanned for across the internet. Your team, meanwhile, is working a remediation queue measured in weeks, and every day that gap stays open is a day an attacker could be moving through it. The AI doing the finding and the chaining is only getting faster, and the pressure from your board and your insurer to prove you can keep pace is only going up.

In this fireside conversation, NopSec CTO Michelangelo Sidagni and Marsh Senior Vice President and Cybersecurity Strategy Advisor Jim Aldridge look at what AI-accelerated offense is doing to the exposure window, and what the cyber insurance market's own data says about the controls that actually reduce risk.

What You'll Learn

Why the exposure window is widening, not shrinking: Michelangelo draws on twenty-five years in offensive security to explain what has changed. AI now finds and chains vulnerabilities faster than any human team can, compressing time-to-exploitation from days into hours or minutes, while remediation for critical issues still drags on for weeks.

What cyber insurance claims data reveals about real risk reduction: Jim shares how Marsh's Cyber Risk Intelligence Center correlates the controls clients report with the claims they actually file. One of the strongest signals in vulnerability management turned out to be proactive testing paired with prioritizing and fixing what those tests surface, ahead of patch cadence or automation on their own.

Why discovery is now a commodity and prioritization is the bottleneck: With millions of findings flooding the pipeline, the real question is not what is vulnerable but what is actually reachable and exploitable once you account for the mitigating controls you already run. Michelangelo also flags a fast-growing blind spot: the rogue AI agents and open API and MCP interfaces that are becoming the new exposed storage bucket.

Where more-frequent validation fits: Ian frames the stack as a health check. Scanners give you a point-in-time blood panel and the annual pen test is a periodic stress test, but AI agentic adversarial emulation works more like a monitor you can run any time, a frequent outside-in read on your posture between those bigger checks. NopSec's CTEM platform pulls the signals together into one prioritization engine so your team can act on what matters today.

Watch the Full Session

Stop letting the exposure window stay open longer than it has to. See how proactive validation and machine-speed prioritization close the gap between when a vulnerability appears and when it is actually handled.

Schedule a Product Demo Today >>

See how NopSec's Continuous Threat Exposure Management platform helps your team fix less and secure more.

Customer Bar Small

Schedule a Product Demo Today!

See how NopSec's end-to-end Cyber Exposure Management platform can organize your security chaos.
Schedule a Demo CTA