| The following interviews have been edited for clarity and brevity. Bugcrowd CEO Dave Gerry Q: Your company is basically doing what the government is trying to do through Gold Eagle: harness a large, distributed community of independent researchers to identify vulnerabilities. What have you learned about where the model succeeds and fails? A: We’ve been trying to build this as a community for over a decade, so this is a really exciting moment where the government is really starting to pay attention [to] the coordination of how vulnerabilities are disclosed. For the first time, this is being viewed and treated like vulnerability coordination is the speed problem that it is — not just a reporting or paperwork or process problem. I think what we’re seeing is how you start to deduplicate or deconflict all of the work that’s being done across all of these different agencies [and] across private partners. We shouldn’t be scanning the same infrastructure multiple times across multiple different partners or multiple different agencies. Let’s focus on getting the vulnerability data into a centralized location, and then [having] the right partnership around: “Okay, how do we actually prioritize this? How do we actually make sure that we’re getting this in a position to be fixed?” When we’re talking about measuring the patch management cycle, and how quickly you have to do this, we need to start measuring this in hours, not in days or weeks. Q: You’ve reported being overwhelmed by AI-generated vulnerability reports. What do you think a credible plan looks like for managing the volume of discoveries that surface? A: AI has done a great job of finding vulnerabilities at a machine speed and at a scale that we’ve never seen. As you pointed out, triage is absolutely now the bottleneck for the industry around how you validate that it’s a true finding. The hard part no longer is finding the vulnerabilities. It’s separating the 10 vulnerabilities that matter outside of the 10,000 that maybe don’t matter as much. The first piece is: How do you make sure you prioritize what’s coming in as quickly and as efficiently as possible? I think the piece that we still have not solved as an industry is the vulnerability-remediation piece. Q: CISA reauthorization is expiring in September. Can you explain how the business model of coordinating this kind of vulnerability information-sharing depends on this legal framework and safe harbor? A: The safe-harbor component of this is really important, and that is one of the things in the announcement that was not explicitly called out. If there was a very hard read of what was published, it could look as if there’s not safe harbor for some of this work being done when security researchers are using AI tools or assisted by AI. We’ve spent over a decade really working with policymakers, working with industry, working with the researcher community to make sure that there is safe harbor for good-faith security research. We need to make sure that the safe-harbor protections that exist today are, one, extended from assisted reauthorization, but then also, two, that they become a core tenet of what’s going to happen within Gold Eagle. Method Security CEO Sam Jones Q: Do you anticipate that AI-driven vulnerability discovery will outpace the governance structures that manage what gets found? How do you ensure that discovery doesn’t radically outpace remediation? A: Vulnerability discovery will always outpace. Ultimately, it’s just, frankly, so much easier. I think the hard part is prioritizing what actually matters on a national scale, and different forms of AI can help with that. And then, on the actual technical remediation front, we do need to implement, possibly mandate, certain software-delivery mechanisms that actually make remediation an automatable task. For the world’s best software systems, this is possible today … but, for a lot of the production systems that matter, it’s not code that can be centrally secured automatically. There needs to be some regulation there, most likely, or [a] mandate. Otherwise, it will have to send people on-site everywhere, and that will not keep up with the pace of AI. Q: You have a single product team that serves both Fortune 500 companies and the Department of Defense. What can you tell us from your experience about whether private-sector and national security infrastructure should be handled together or separately? A: The thing that is not well understood in cyber is that we really have one national attack surface, and it doesn’t care about public versus private. So, cooperation between different institutions is paramount, but we need to look at it like one attack surface. This newsletter is published by WP Intelligence, The Washington Post’s subscription service for professionals that provides business, policy and thought leaders with actionable insights. WP Intelligence operates independently from The Washington Post newsroom. Learn more about WP Intelligence. |