Tim Grieveson
Welcome back to the second episode of the All Things Cyber podcast. Stephane, it's great to be sitting down with you again to talk about attack surface management and supply chain security.
Recently I saw the ThingsRecon research release, and one statistic immediately caught my attention. You analyzed around 777,000 internet-facing assets and found more than 800,000 high and critical severity issues. What does that tell us about the state of organizations today?
Stephane Konarkowski
When we look specifically at web applications, we find that, on average, every application has at least one security issue. Of course, that doesn't mean there's only one issue. Each application can have multiple findings across different severity levels.
The important thing to understand is that you shouldn't look at the application in isolation. Everything connected to that application also matters. A certificate, a DNS configuration, a third-party integration, or another connected asset can introduce additional risk. Looking at the application alone never gives you the full picture.
Tim Grieveson
One statistic that really stood out to me was that roughly one in three internet-facing certificates are misconfigured. That's more than 30 percent. That feels like an incredibly high number.
Stephane Konarkowski
It surprised me as well. That figure includes production systems, development environments, and anything publicly exposed on the internet. Not every certificate misconfiguration is critical or requires immediate action, but seeing that around 30 percent are misconfigured is still significant. It shows just how much technical debt organizations accumulate over time.
Tim Grieveson
Another number that surprised me was that around two-thirds of domains contained multiple weaknesses. That level of exposure is staggering.
We've known for years how important proper domain configuration, encryption, and certificate management are, yet organizations still seem to struggle with these basics. Why do you think that is?
Stephane Konarkowski
The internet is a complicated place, and organizations simply have too many things to manage. The real challenge isn't just finding issues. It's deciding which ones deserve attention first. Prioritization is everything, and that's where context becomes critical.
Not every issue needs to be fixed immediately. Some findings can safely wait, while others affect applications that contain an organization's crown jewels or provide attackers with a direct path to them. Those are the issues that deserve immediate attention. Without context, it's almost impossible to make the right decisions.
Tim Grieveson
So how does ThingsRecon help customers understand that context?
As a CISO, Chief Risk Officer, or CIO, one of the hardest questions is deciding where to invest limited time, budget, and resources. How do you know what should be addressed first?
Stephane Konarkowski
Most organizations already know where their crown jewels are.
What they don't know is everything connected to those critical assets.
That's where we help. We provide visibility into the proximity between exposed assets and the organization's most important systems. Often, the real risk isn't the critical asset itself, but everything surrounding it. Those hidden connections create the context needed to understand the true attack surface.
It's not enough to know where your most important applications are. You also need to understand everything connected to them, including assets you may not even know exist. That's where meaningful visibility begins.
Tim Grieveson
Do you think technologies like AI are contributing to this problem?
We're seeing more business users building solutions without deep technical or security knowledge. Applications are becoming easier to purchase, easier to deploy, and easier to connect using nothing more than a company credit card.
I often describe this as application sprawl or tool sprawl. Organizations are adding more and more technology without necessarily understanding what they're introducing into the environment.
Do you think that's making the problem worse?
Stephane Konarkowski
Absolutely.
People are constantly testing new technologies. They'll install a plugin, connect a service, or experiment with a new component for a few days, and then simply forget it's there.
Looking at the data we've collected, we see countless small modules and components spreading across applications. Some organizations rely heavily on these technologies, but every new component increases complexity.
The more things you add to an application, the harder it becomes to maintain visibility.
When multiple teams are working on the same application, each introducing new functionality, it's essential to understand exactly what's being added and where those components connect. Most of them send information somewhere else.
Tracking technologies are a perfect example. They collect information while users interact with an application, and that data is almost always sent to external services.
Tim Grieveson
That raises an interesting question.
From your perspective, how do organizations ensure that the third parties receiving that data are handling it appropriately?
As businesses build more connected applications, they're sending potentially sensitive information to an increasing number of external providers. How do you gain confidence that those providers are doing the right thing with that data?
From my experience, organizations are under increasing pressure to enable the business rather than slow it down. There's a huge drive toward seamless integration between applications, which means we're seeing far more APIs, microservices, and interconnected platforms than ever before.
The challenge is that you don't always know where those APIs are connecting or how many integrations exist. What looks like a harmless plugin can have significant security implications. Where is the data flowing? Is it encrypted? Is it leaving the country? Does it introduce privacy concerns?
For me, one of the biggest challenges has always been understanding where data comes from, where it goes, and the likelihood of it being compromised.
Stephane Konarkowski
And those questions rarely belong to just one team.
You're talking to legal, procurement, IT, security, privacy, and many other stakeholders. How do you explain cyber risk to each of those groups in a way that's meaningful to them?
Tim Grieveson
It's difficult because every team is working toward the same business objectives, but each speaks a different language.
In previous organizations, I've worked alongside infrastructure teams, platform teams, privacy specialists, legal, HR, marketing, and IT. Everyone contributes to growing the business and delivering value to customers, but communicating cyber risk across those groups is one of the hardest parts of the job.
That's why having a complete view of where data exists, how it flows, and how it's protected is so valuable.
The challenge becomes even greater when those integrations involve third parties. Whether it's an offshore development team or an external software provider, understanding those relationships and, as you describe them, those connections and their proximity to the business, becomes essential.
That's where many of the important conversations happen.
Stephane Konarkowski
As digital ecosystems become more complex, security teams naturally have to collaborate with more people across the organization.
Tim Grieveson
Absolutely.
The role of the CISO has changed dramatically over the years.
It used to be a highly technical role. Today, I need to understand regulations, communicate with marketing, speak with legal, discuss governance, compliance, audit, and risk, while still being able to have technical conversations with engineering teams.
At the heart of all those discussions is one simple objective: understanding what assets we have, what data flows through them, and whether they're adequately protected.
Perhaps most importantly, everyone needs to share a common language.
There's little value in explaining protocols, technical specifications, or vulnerabilities to a board of directors. The board wants to understand business risk, business impact, and what an exposure actually means for the organization.
Stephane Konarkowski
We feel that shift from our side as well.
The information we provide has to support those conversations. It can't simply be technical data anymore. As technology vendors, we have to understand who our customers are speaking to inside their organizations and provide information that's useful beyond the security team.
When we deliver intelligence, it has to help answer the business question, "So what?"
Tim Grieveson
And that question has become much harder to answer.
The regulatory landscape continues to evolve, the threat landscape keeps expanding, and geopolitical instability has introduced entirely new considerations.
Organizations aren't just asking how to protect themselves anymore. They're asking where their suppliers are located, what code they're using, whether that software originates from sanctioned or high-risk regions, whether data is crossing jurisdictions it shouldn't, and how threat actors might exploit those relationships.
I'm also seeing attackers shift their attention.
Instead of targeting only large enterprises directly, they're increasingly looking at the supply chain because they understand how critical suppliers have become to modern businesses.
Stephane Konarkowski
Exactly.
The size of those connected organizations doesn't really matter anymore. If they're connected to your business, they'll naturally become part of the attacker's analysis.
That's why understanding your entire extended digital ecosystem is becoming so important.
Tim Grieveson
You've worked with organizations across financial services, insurance, consulting, petrochemicals, and many other industries.
Have you seen anything during that work that genuinely surprised you?
Stephane Konarkowski
Not necessarily one specific surprise. What I've seen is a consistent pattern across every industry.
Organizations need better ways to understand and communicate risk across their digital environments.
One of the biggest lessons from our research is that you can't evaluate assets individually anymore. Every asset exists as part of a chain of relationships.
You might focus on fixing one exposed asset, but if it's connected to something else that's equally important, addressing only the visible issue may not improve your overall security posture.
At the same time, organizations continue adopting new technologies, AI services, chatbots, plugins, and integrations at an incredible pace. Every new connection expands the digital environment, making it even more important to understand exactly what is being introduced.
Whenever we present customers with what we've discovered, there's almost always an element of surprise. We consistently uncover assets, relationships, or dependencies they simply didn't know existed.
Tim Grieveson
So you've never had a conversation with a customer where they already knew everything you were about to show them?
Stephane Konarkowski
No. That's practically impossible.
Even for us, discovery is constantly evolving because technology keeps changing. New types of assets appear, new ways of connecting systems emerge, and applications communicate with each other in ways we haven't seen before.
Our job is to stay curious. Whenever we discover something new, we want to understand how it works, why it's there, and what role it plays within the environment.
That's true across every industry. Organizations are adopting technology so quickly that they often don't have time to fully understand the security implications before moving on to the next innovation.
Tim Grieveson
Do you think that means security itself needs to change?
Traditionally, we've focused on locking everything down and controlling every asset. But today's environments are far more distributed.
Shouldn't security now be about enabling the business through a risk-based approach? Rather than simply working through CVEs in priority order, shouldn't we first understand how assets are connected and what those connections mean?
Just because you've remediated a vulnerability doesn't necessarily mean you've reduced business risk.
That vulnerability may not even be exploitable. It might have very little impact on the organization, or the cost of fixing it could outweigh the benefit if other compensating controls already exist.
Do we need a fundamental shift in how we think about securing the attack surface?
Stephane Konarkowski
I think we do.
In the past, most of our infrastructure lived inside the organization, so locking everything down made sense. Today we're pushing more services, applications, and data outside the traditional perimeter.
That completely changes how security should operate.
Instead of restricting people, we need to enable them while making sure we understand what they're building and how it's connected. Documentation and visibility become much more important.
The more you enable people to work securely, the more they'll work with you. If security becomes a barrier, people will simply find ways around it without your knowledge.
Tim Grieveson
That's something I experience every day as a CISO.
We're constantly being asked to do more with fewer resources, while attracting and retaining skilled people becomes increasingly difficult.
At the same time, we're dealing with an overwhelming volume of security data and trying to decide what actually deserves attention.
How does ThingsRecon help security teams prioritize all of that? How do you help them identify what they should fix first?
Stephane Konarkowski
It comes back to one word: context. Context is what drives effective remediation.
Security teams already receive enormous reports containing thousands of findings, and those reports only continue to grow. Our goal is to reduce that noise by helping teams understand the actual business context behind every issue.
What's the risk? What's the potential impact? How is this asset being used? How close is it to something critical? Vulnerability intelligence is valuable because it helps us understand which vulnerabilities deserve attention, but there will always be more CVEs than any team can realistically address.
The important question isn't how many vulnerabilities exist. It's which ones matter today.
If a vulnerability exists on an application that's unlikely to be exploited, it probably shouldn't be your first priority. On the other hand, if a vulnerability is actively being exploited and it's connected to one of your crown jewels, that immediately becomes a priority.
Our objective is to reduce the noise and help remediation teams focus on the issues that genuinely matter. Those teams are just as overwhelmed as security teams. By understanding connectivity and proximity, we provide the context they need to decide not only what to fix, but how to approach remediation. Different risks require different remediation strategies. Context helps determine the right one.
Tim Grieveson
So what you're really saying is that ThingsRecon provides a remediation plan that's enriched with contextual intelligence gathered from multiple sources, rather than simply producing another list of vulnerabilities.
Stephane Konarkowski
Exactly. Because we understand the relationships between assets, the recommendations can't be generic or static.
Every environment is different. We look beyond the individual finding to understand everything surrounding it, then provide the level of information teams need to make informed remediation decisions.
In other words, context exists on both sides: the technical finding and the business environment around it.
Tim Grieveson
It wouldn't be an All Things Cyber podcast if we didn't talk about AI. How is ThingsRecon using AI today? Is it part of the product itself, and what problems is it solving?
Stephane Konarkowski
AI allows us to work at a scale that simply wouldn't be possible using people alone. We build models that specialize in different types of assets and different forms of analysis. Together, they operate as an agentic platform, continuously learning, sharing findings with a central coordinating layer, and highlighting what matters most.
The goal isn't to replace human expertise. It's to make it more effective. We train these models to think more like experienced analysts, but they still need human oversight. AI is extremely powerful, yet it still requires people to validate, guide, and improve its decisions.
Tim Grieveson
So it's really a partnership between people and AI. That leads to an obvious question. Do you think AI will eventually replace security professionals?
Stephane Konarkowski
Not today. From what we've seen, AI still needs guidance. We have to teach it, refine it, and continuously improve it.
Many AI systems still require careful prompting and supervision. They're incredibly useful, but they're not independent experts. For us, AI is an accelerator, not a replacement.
Tim Grieveson
You're already using AI to help process the enormous amount of data you're collecting and to improve discovery across the platform. You're also using it to help customers understand and visualize that information.
I think I also read that you're using AI internally for training and knowledge sharing. Is that right?
Stephane Konarkowski
At the moment, it's probably more accurate to say that our engineers are training the AI than the other way around. Over time that balance will evolve, but today AI supports many different parts of the business. We use it in several ways across the organization.
From a security perspective, though, it's important to think carefully about how AI itself is connected to your environment. Just like any other technology, AI becomes another asset that needs to be secured. That's why we've taken a controlled approach. We don't simply allow AI systems unrestricted access to everything. We put controls around how they're connected, what they can access, and how they're used.
Tim Grieveson
So rather than introducing AI first and figuring out the governance later, you've done it the other way around. You've built the policies, the strategy, and the security controls before deciding where AI should be used.
Stephane Konarkowski
Exactly. You should think of AI as another member of the team.
Like any new employee, it needs clear rules. It needs defined responsibilities, permissions, and boundaries. You need policies that determine what it can connect to, what information it can access, what it's allowed to do, and just as importantly, what it isn't allowed to do. AI should extend the capabilities of the team, not replace it.
Tim Grieveson
I completely agree.
From a security perspective, AI brings enormous opportunities. It can enrich security data much faster, automate repetitive work, help analysts visualize complex information, and improve the efficiency of day-to-day operations.
At the same time, we also have to acknowledge the risks. We're already seeing AI used to create highly targeted phishing campaigns, automate attacks, and make social engineering significantly more convincing.
Like any technology, it's about using it responsibly. It's encouraging to see ThingsRecon taking that balanced approach.
Stephane Konarkowski
Exactly. It's about being cautious. If your AI platform is running in the cloud, would you really upload your organization's crown jewels without thinking carefully about the consequences?
AI is fantastic for experimentation, testing, and working with non-sensitive information. But when you're dealing with critical assets or highly sensitive data, you need appropriate controls.
The answer isn't to avoid AI. The answer is to embrace it while making sure the right safeguards are in place.
Tim Grieveson
Let's finish with one final question. There are a lot of companies operating in this market. What do you think makes ThingsRecon different?
Stephane Konarkowski
The biggest difference is depth. Many solutions stop at the surface. They identify exposed assets and provide a snapshot of what's visible.
We believe that's only the beginning. Real understanding comes from looking beneath the surface and discovering how everything is connected. When you go deeper, you begin uncovering relationships that can expose an entire ecosystem rather than just a single asset. That's the difference in our approach.
Tim Grieveson
So your focus isn't simply on identifying assets. You're looking at the assets, their connections, their proximity to critical systems, the data flowing between them, and the way they're configured. Then you place all of that into the context of the business instead of producing another high-level security posture assessment.
Stephane Konarkowski
Exactly. Our goal is to understand how everything works together. That's the mindset we've built into the product. We continuously try to understand how technologies interact so we can explain those relationships clearly to customers and help them understand the context around their environment. Ultimately, that's what leads to better security decisions.
Tim Grieveson
Steph, as always, it's been a pleasure. Thanks for joining me today, and I'm looking forward to our next conversation.
Stephane Konarkowski
Likewise. Looking forward to it. See you next time.

