As artificial intelligence (AI) continues to revolutionize cybersecurity, traditional disciplines such as vulnerability and exposure management are facing immense pressure. Frontier AI models, for example, demonstrate how quickly advanced technologies can uncover and exploit software and firmware vulnerabilities.
Machine-speed remediation, however, is not yet trusted or permitted on sensitive systems. Most enterprises, especially those heavily invested in cyber-physical systems (CPS) and operational technology (OT) assets, are hesitant to allow autonomous decisions to be made that could have a negative impact on production, patient safety, and the business overall.
In this episode of the Nexus Podcast, Remedio CEO and founder Tal Kollender discusses why the shift from traditional detection to automated remediation of exposures such insecure configurations and vulnerabilities, will happen alongside the evolving role of AI as a defensive tool and capability for security teams.
“For most of the vulnerabilities that are being discovered, there is no patch, and they just opened another huge door for hackers,” Kollender said of the emergence of frontier AI models. “And now it's not only the chicken and the egg, we all know that they will find more vulnerabilities than they can fix.”
Attackers are not handcuffed by patch management cycles, regression testing, and other basics of vulnerability and exposure management and remediation. Configuration drift, where configurations no longer match a system’s or network’s intended behaviors, is also another key area ripe for exploitation, Kollender cautions. In the case of CPS, for example, default settings and credentials, legacy and insecure protocols, and human errors contribute to configuration drift.
She adds that automated remediation—with rollback or revert capabilities—allow defenders to quickly shut down misconfigurations and patching gaps without risking operational downtime.
Kollender, meanwhile, argues that boards, executive leadership, security, and operations teams must align on automated remediation in order to prevent disrupting critical workflows. This is one manner of demonstrating risk mitigation for the board and to meet the rigor of cyber insurance providers.
AI, meanwhile, hangs like a shadow over business operations. Security teams must look at their AI-powered cybersecurity usage, ensure governance is in place, as well as hardening of these systems.
Mimoso 0:13
Welcome back to the Nexus Podcast. We are live at Black Hat, and I'm happy to have Tal Kollender, the CEO and founder of Remedio, as my guest. Nice to meet you.
Kollender 0:23
Thank you so much.
Mimoso 0:24
How's Black Hat for you?
Kollender 0:26
Wow, actually, it's the best Black Hat we had so far. As you know, we will bootstrap up until you know last year, late last year. And this is the first time, you know, we have everything, you know, organized, meetings, and um things are just um I would say finally better.
Mimoso 0:43
Yeah, that's amazing. There's a lot of opportunities here, a lot of a lot of people here.
Kollender 0:47
100%.
Mimoso 0:48
So tell me a little bit about the company and obviously your your part in it. You've been there since the beginning.
Kollender 0:54
So yeah, so I the reason behind Remedio is today there are many solutions that are telling you what is wrong, and we are past this this generation of you know, like uh machine speed detection. Um, so we um so even seven years ago when I just started a company, it was all about machine speed remediation. I mean, let's fix everything because uh before it will be too late. Um and now after you know Mythos and and and other things that are coming up, I mean that's the most important thing for pretty much every company that I run into, and uh even those that I don't run into. So yeah.
Mimoso 1:35
That's a it's a great point because for a long time in security everybody was about detection and we want to know what's going on, but don't touch anything, don't fix anything. And that like you said, mythos and other other things are starting to change that conversation. I'm sure you're in the middle of them.
Kollender 1:49
Yeah, and and again, visibility is important. Um the power behind remedio is not only doing the entire uh fix, but it's also it's a safe remediation at scale. So we make sure that nothing breaks. Um and in case you want, you can always go back and reverse and make it, you know, roll it back to the to the previous state. Everything works, so that's pretty awesome. Yeah.
Mimoso 2:13
Do you still find any pushback or hesitation about the autonomous or automatically fixing issues?
Kollender 2:20
So let's start with the fact that all of our customers are using remediations, even from I don't know, from the POV days, okay? Like they they test it all the time and even the revert, uh, and they want to do it as much as they can and they do it alone, which is amazing. Um, and with thousands of remediations are done during our POVs. Uh, the one thing maybe that we have today is that sometimes we we are replacing some uh would say um previous technologies that used to be, you know, like the traditional VMs. Um and uh so yeah, sometimes we get, you know, um it's it's we need to understand that, I mean, also sorry, the customers, they need to understand that it's a new generation of not only, you know, showing you what is wrong and that uh maybe to prioritize it or to have more alert fatigue um or you know, backlog or whatnot. We really want to fix it and to be the one who uh um to be the ones who actually fix everything that we find.
Mimoso 3:21
Your company focuses on remedi and I'm sorry, on configuration errors, correct?
Kollender 3:26
Is that we started in a configuration and today from uh the one product that we had last year, today we are a platform. So everything from compliance um and golden image and create your own baseline for even AI governed, you know, that the chaos that we see among um among customers and organizations and and prospects, um, and the fact that they don't have a remediation solution and they don't really know what is installed. And even if they know what is installed, they don't know how it is configured. So it's the AI government for even application control. We tell you everything that is end of life, um, everything that you last used. I mean, and then you can easily uninstall it. Um, and of course, now we are finally introducing the patch management. So end-to-end configuration to patching, um, and of course, like making it smoothly, fast, and at scale.
Mimoso 4:15
So just to stay on the configuration part of it for a second, is there kind of like a commonality among the types of configuration errors that you're seeing and fixing? I mean, what what are companies struggling with when it comes to configurations versus vulnerabilities, for example, which is kind of straightforward?
Kollender 4:32
So there are different types of uh of configuration. Let's start with the ones that maybe everyone knows today. If you think about it, we have the the ones that are vulnerable but cannot be patched. Okay? Like TLS version one, SMB version one, um, and very old protocols, um and and other things as well. So this is one thing, and again, they they cannot be patched. You the only way to mitigate or to remediate is to disable it. But how can you disable it if you don't know what's the impact and what's you know what will happen? So that is the the first thing or the first group of of uh remediation. The other remediation is that maybe there is a patch, but the patch is not good enough or is going to break something. If we're talking about, you know, like um um the the the medical, uh I would say like the entire industry of uh healthcare and some uh OT environments and manufacturing, sometimes you don't want to chat to touch things that you might break. Uh so that there are workarounds that we are providing to the customer. Um there is another thing of configuration which is human error. People think that they are 100% aligned with their baseline. And when we run remedious on allegedly two devices that should have the same thing, we find glitches. Again, it's not that someone did it on purpose, it's because they thought that everything should be okay and good, and then oops, there is here and there uh things that you need to fix.
Mimoso 6:07
And that opens up a pretty significant exposure a lot of times, those human errors that are you know not intentional, not malicious, but there's still an issue to deal with.
Kollender 6:16
Every customer that we run into, the reason why they love it is because the ease of the fix and they see the return on investment. Now back to what you said, we just had um, and again, it is unfortunate, okay? Like, but um in the past couple of months we had um uh two prospects, they weren't even a customer. That once it happened to them, they said we need now remedious, uh, because they ran into us, they said yeah, we will do it, and then uh, but they they just kind of that they didn't have the time, which is okay. Yeah, um, and then they called us because they saw exactly the lateral movement that they were abusing the misconfigurations that not only that we show but that we fix. So they should have, you know, like um uh they should have closed them like if they had remedious and avoided the the the the run somewhere. But um yeah, I mean unfortunately um it didn't um they didn't and it didn't play that way and and but yeah now the customers happy customers and again like the amount of remediations that people do because this because of the safety, because of the assurance that nothing breaks, because of the fact that they can do revert um for everything, that makes perfect sense.
Mimoso 7:29
So, how much is AI changing that dynamic in terms of speed, in terms of these agents that are able to create new identities, for example, and just kind of propagate, you know, without proper visibility, uh do these people know what's going on? I mean, what are you running into? What kinds of questions or concerns are your customers bringing you?
Kollender 7:47
So first there is the uh uh shadow AI story. No one knows really. I mean, they think they know what is installed, but they are not really sure because they cannot really they don't want to to guarantee that um you know what is there. The other thing on top of that is is that at the end of the day, um you want to know that, oops, by default I just configured, you know, I just downloaded some skills file. And but did you ever check that on the skill you don't have the simple thing like bypass my EDR and it just does that? Because you just told him, you know, like in a simple language, simple English, even other languages, it will catch it and it will do it, and no one will detect it, and no one will be able to stop it. So AI is a mystery. So people um they have more things that they don't know rather than they know. And even if they buy the the enterprise licenses, you know, of you know, GPT and Claude and even Codex, they have this mystery of hey, but wait, why the sandbox is not enabled by default? I mean, why do I have you know clear text passwords stored, you know, in my in my on my I mean within my files? So all of those things, not only that we can show you and to govern them, but we can harden and streak them the way that um no one else can.
Mimoso 9:10
How often are companies aware of kind of the volume of issues that they have? Like how good is their visibility into their environments to see configurations, to see boxes that are still vulnerable that they maybe not have known about?
Kollender 9:24
That's a good question. Today they are more aware of the vulnerability that they haven't patched rather than the configuration drifts. But let me tell you something even more interesting. In the past few, um, in the past couple of months, we are working um to find zero days, not to find zero days like Anthropic or uh OpenAI or other companies. We are finding zero days in order to fix them. Because finding them alone is not enough. The whole world, you know, is a chaos, right? They are scared, they don't know what's coming next. And attackers, they are taking advantage of that and they abuse it. So we find them, we disclose them with the vendor, but the vendors already told us. I mean, they say maybe they say thumbs up, but they're not going to address it anytime soon. I mean, think about Microsoft. They just got, you know, thousands of things that they need to do, and they don't even have enough time to fix it every patch Tuesday. So what we do, we we find it, we understand it's a zero day, it is exploited. I mean, people can abuse it, so we already fix it. And once we get the 90-day window, we can even say this is this is an active zero day that can be abused in your network.
Kollender0:33
I mean, isn't that the big issue with the frontier models? I mean, sure, they're they're great at uncovering everything, developing exploits, and really shrinking that time for companies, but there's no discussion about okay, how do we implement this stuff and fix it? And that seems to be a huge gap, I'm sure you're seeing.
Kollender 10:51
Yes, and and and for most of the vulnerabilities that are being um uh discovered, there is no patch. And and they just opened another huge door for hackers. That's what they did. Um yes, the vendors did get the list um and they are taking care of it, but they are not even close to to close all of them. And the uh now it's not only the chicken and the egg, we all know that they will find more vulnerability that they can fix. Um, and it's all about you know the ha hackers to take advantage of it, and and and you see it. You see it all the time. Every single attack that that we hear on the news, and some of them that we don't even hear on the news, we know that there is um a uh usage of configuration drift. This is the way for attackers to move laterally, and it can be even AI configuration drift. I mean, like it's uh AI tooling, or it can be like a compliance or a hardening, or you know, people now see that the power is back to the endpoint, to the end user device, to the server. Like the I mean it used to be, you know, yeah, cloud, cloud first, and then browsers, and then but now it is people if they want to do more with it, they install the tools on their device. They use it, you know, from the its own version, another web server, another web version. So that's what we see, and yeah, that I mean, like attackers are taking advantage of it like every second.
Mimoso 12:17
Explain what you mean by configuration drift, just so that the listeners know.
Kollender 12:21
So, yeah, thank you for that. Um, configuration drift is anything between um again, like the human error that thought that everything is okay, um, to things that you know, like um computers. It's not that you switch your computer and get your golden image every day, and um it's you you know that you are hard and I mean it, you know, they they you change, I mean things. And um maybe you thought that you have the latest Chrome, but oops, you are um 10 versions before. Um, and by default your cryptocurrency is enabled on the on the browser, or even the um the the the uh you you because even if you don't have permissions, you just right-click on a folder and share the folder with everyone. So those are configuration drifts that usually attackers abuse. Um and and moving laterally, they just find um all they need is one device to get in, and then moving laterally is the easy part for them. Right. Uh so yeah, configuration drives anything from default settings, human error, and some things that you thought you did, but they weren't ever applied.
Mimoso 13:24
So let's talk a little bit about OT environments and obviously vulnerability and exposure management is very different there than your traditional enterprise. Um, what are some of the issues that that your customers are are bringing to you in in that respect about you know challenges they have with remediation?
Kollender 13:41
That's a very, very um that's a real challenge. Um, OT especially, as um maybe people thought that at one day um the OT will get um you know smaller, like maybe the all day of mainframe, but it's not. Um people need OT, people will continue to use OT. Um like people thought that oh, you don't need you know, like your end user device, that's it. Everything you know, you have EDIs or everything you know you just need a browser, but also or lean or thin computers, you don't it's not it's not it's not true. Um so with OT there is the there is the the the the risk of changing things um and updating things and fixing and because they are afraid because what works, you know, if it works, don't touch. Um and I definitely get it. Some OT, you know, it's all about you know money because if you are if you break my OT, then I'm not going to print money, and um, and some OT, or even if we'll take it to you know, some medical devices, and and if you do something, then maybe the entire hospital or um or an operation room, whatever we will stop working, and we don't want people to die. Um so OT is more sensitive because um it has um more I don't know if important, but um uh some software that um uh that you really don't that that is really uh sensitive for any change. So um because many vendors that develop uh um this software for software for the OT, they are the ones who are telling you, yeah, no, no, no, it works like that. Like, you know, like if you if you do something, then we we stop, you know, like um uh we stop the the the uh every like um everything that we that we promise you or we we don't give you any more um support. Um and and this is why people are afraid to touch. Um but if you think about it, you do want to improve it, you do want to protect it. And the way that they say today, oh no, just you know, like go go around and you know, like uh just close it around. No, it's not good enough. I'm sorry. Um, so this is why people um because of yeah, I believe because of stigmas mainly. Um but they um again, we see the change now, okay? But but yeah, people still have oh, it's OT, like it's the critical uh uh critical infrastructure of mine, we we cannot touch it. Um but we see that it is changing uh from I mean like um again mainly recently, of course.
Mimoso 16:17
What what's forcing that change, do you think?
Kollender 16:19
I believe people understand that if they have the alert fatigue and the um amount of millions of CVEs or millions of vulnerabilities, um i i it cannot really it it doesn't help, you know, knowing that you have every month more alerts. It helps when you have less, and then you need to talk to the board and then you need to explain to them what happens, and then you need kind of to even sometimes to convince them why security comes just before. And and again, you need to take the the right risks. Whether you take, I mean, it's okay sometimes, if it's okay, it's uh really a question mark, but sometimes in order to do something, you need to to have some you know downtime. I don't know, some upgrades for OS, you need to restart the device. So it's really important what you are doing now um before taking the next uh before before doing it and explain it. But as long as things are very much, I would say, um uh in in detail and and and explained properly, I mean, like I believe that everything is possible, but it's co it's a good communication. That's why what I believe in collaboration between the the you know, like the security, the infrastructure, and of course, later on, obviously, like to the senior managers and the board.
Mimoso 17:41
Sure.
Mimoso 17:42
You know, it's a good point you brought up earlier about kind of the the OEMs being involved in any updates and kind of like threatening about cutting off support or warranties or whatever. Uh with hospitals, for example, it's even worse. Like in the US, you have to go through the FDA for any security updates. Uh is it the same kind of situation that you're running into?
Kollender 18:02
I'll give you another example. Do you remember Stryker for a month back? Yeah. Um, so we have a few hospitals. Um uh we have a couple of dozens um uh customers, uh, hospital customer hospitals that are using our um solution. And when they heard about striker and they saw and they know what is it that they abuse, they hit on the remediate button of remedial. Um some of them just achieved, I mean, one of them achieved like he did like one million remediations in in in a couple of months, and a few others like tens of thousands and hundreds of thousands. And the reason why we see this because they trust the system, because we once you do something, you want to do it, and and and then you want, if needed, then you want to undo it. Um, but the power here is again um to give them the confidence of hey, you are doing something good that is okay, you are going to protect your um uh the hospital if you are going to do A, B, and C. Um, and at any given point, you can always undo it. But yet, you need to remember that I mean hospitals, it's for us, it's not money, it's life. Um, and if something goes down, it's it's it's someone is might might be, you know, like that. So what we're trying to do here, um, and they have less manpower, most probably, and they have also less money. So we always need to understand and to accommodate the um the conditions, even for for for the healthcare, which is very um the it's it's very challenging. Very challenging.
Mimoso 19:39
How do you make the case to either OT or hospitals about making kind of like these automatic changes? Are there are there trade-offs that are involved there, or is it just showing them and seeing what happens?
Kollender 19:51
They see the value immediately. Um because one of the things that we do, we even tell them, hey, this wasn't used in the past, let's say, 90 days. And this is something, let's say it's a project that they are working on for months or for years, and when they see that they can just use a button, boom, easy peasy. Like that's what they do, that's what they why they love us and how they use us all the time. It's all about the uh dependencies that we show them, the assurance of safe remediation at scale, and again, like the fact that they can always revert. So, um, and of course, like again, like it's I used to be a customer for many years, and I used to run into vendors that they uh gave me um a very, you know, like amazing demos and good things on, you know, on the paper and on their screens, and when it comes into you know full implementation in you know in my environment, you know, it was it wasn't even close to what I saw. And then I said that when when I become a vendor, I'm not going to do it. I mean, like everything that I say, I do. Like, we are not going to tell you one thing and do another thing because it's really important for me as a ca as a customer that I used to be. I mean, I don't want to sell dreams. I really want to tell them this is what will happen. Um, and again, because we don't like, let's say, false positive. So please, if you find something, okay, and I mean, like, I know that we cleaned almost everything, but if we you find something, raise a flag, we will clean it. And and again, it's also the partnership. Eventually, you can be the best vendor in the world, I mean, like, or the best product, but the the the relationship, again, we are still human beings, we're not robots yet, so um the relationship is not as good. So most probably uh maybe it will it will it will be okay the first year, uh later on, most probably they will replace you with another vendor, even if the product is not as good.
Mimoso 21:47
How often are uh organizations uh using this as like, okay, uh our configuration issues are seem to be a continuous practice. There's whether it's an admin making a mistake or Or a developer continuously making the same mistake, can they take this and go to them and kind of use it as an educational tool as w in addition to the remediation part of it?
Kollender 22:10
Yes, and I know that some of the customers are actively using it as um telling them um what to do and how to do it and kind of teaching them as part of the um uh you know tabletop or or other practice uh that they uh that the customer is going through. And another important thing, because you mentioned it, is uh uh the the fact that they can just go and um and not only do stuff but the risk reduction is real. They go to the cyber insurance and they show them here's what I did, and then they justify that they pay less for the insurance uh because of or thanks to the remediation.
Mimoso 22:45
And in terms of so uh what's a mature organization doing right when it comes to remediation? What are some success stories that you're seeing in terms of turning around best practices and so forth?
Kollender 22:57
I really love when customers are telling us we know we we know we have a chaos, or we know that we are not perfect. Um, we are happy to take it in order to, you know, not to be uh very protective about, you know, like, oh no, I know what I do, like don't touch, oh I don't want you to see, you know, like what's going on because I said that everything is okay, is okay internally. Um we really like the that the customers are open with us and this is how we build the best relationships. Um, because this is how we um we kind of work together as a team and we challenge them to do um and to take, you know, like more remediations. And of course, like everything starts, you know, like baby steps and then they go big. Um, but they uh they tend to trust Remedio um and the team behind Remedio. Um and they see the speed of you know the evolution that we've been through um in the past um less than a year, um and to see what we actually deliver. So yeah, I mean success stories are mainly about that the customers is are willing to make the change and to you know like change the mindset from visibility to fixed first mentality.
Mimoso 24:13
Yeah.
Mimoso 24:13
Okay, so the final question I like to ask people about the frontier models and everything that's been in the news lately. Um just your first impression when, for example, Mythos or OpenAI came out with just all these capabilities around finding vulnerabilities and developing exploits quickly. Did it catch you off guard? Did you think it was inevitable that something like this would be produced and all the fallouts since what's your reaction?
Kollender 24:38
Once I saw or under once I understood the power of the AI if we all remember, okay, like the movies on the 70s, that they just predict the future. All of them, they just predict the future. Think about it. So it was for me a matter of time until something like that will happen. And cyber is always, always um uh relevant. Um, and you see that even in the 70s, they have like these super duple screens that they do, and they, you know, they just you know to do something, you know, whether they're not even typing anymore, they just say it on the mind, like even, you know, like, or they just say something and it happens. And I believe that um it was just a matter of time. And um, and again, like I'm telling you, I'm afraid from the next generation because the robots are going to take control over the world, like can it? I mean, like I'm telling you, I see it, like it's going to happen. Give it, you know, a couple of decades, unfortunately. Um and and yeah, um, so I don't think we couldn't we could have controlled it. That I mean, absolutely, um uh it was uh something that again it happened, it caught us by surprise by surprise, but at any given point that it would happen. Maybe even if it was one year from now or five years from now, we we we would we would react like that.
Mimoso 25:59
Right. All right, Tom. Thank you so much for joining me. Appreciate it.
Kollender 26:02
Thank you so much, Michael.
Mimoso 26:03
Bye-bye.
Michael Mimoso is Director of Influencer Marketing at Claroty and Editorial Director of Nexus.