The Missing Piece in Your Threat Exposure Strategy

The Missing Piece in Your Threat Exposure Strategy

HackerOne
16:40
Aug 17, 2026
cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Josh Linder of Armis (by ServiceNow) explains how Armis and HackerOne together close the "last mile" of continuous threat exposure management (CEM)—getting from validated findings to confirmed fixes 0:39.

Key Takeaways:
• HackerOne's platform rests on three pillars—continuous monitoring of attack surface, human-validated findings, and remediation—with the human element staying essential 1:17.
• Armis aligns through discovery, analysis/prioritization, and remediation, bridging IT, OT, IoT, and medical device environments 3:00.
• CEM adds a "scope" phase and treats remediation broadly—patching, compensating controls, or risk-register acknowledgment—especially after the July 2024 outage made automated patching riskier 5:07.
• Tool sprawl floods teams with signals; Armis integrates ~400 signals with proprietary passive telemetry to reach ground truth 9:00.
• Exposure is now "ground to cloud"—risk spans on-prem, cloud, and third parties, requiring rules-based ownership assignment and risk registers 12:29.
• AI only helps with good data and processes—without validated discovery, automation just "makes bad faster" 13:39.

The talk closes with a simple mantra: quickly find it, track it, fix it, and continuously monitor for reemergence 15:39.

Sources:

  • 0:39 Intro: remediation "last mile" and Armis–HackerOne partnership
  • 1:17 HackerOne platform: continuous, validated, remediated
  • 3:00 Armis discovery, prioritization, remediation
  • 5:07 CEM phases and remediation options
  • 9:00 Tool sprawl and 400-signal integration
  • 12:29 Ground-to-cloud exposure
  • 13:39 AI and data quality
  • 15:39 Closing mantra

Transcript Preview

Jay's perspective as a practitioner is always grounding. The things that held the fundamentals, the discipline, the human judgment. That's a useful counterweight to a year that has felt relentlessly fastm moving. And that word remediation, it keeps coming back. We've talked about finding vulnerabilities faster, validating them faster, understanding the backlog, but there's a critical last mile getting from a validated finding to a confirmed fix. And that requires more than a good platform. It requires coordination, clear ownership, and a workflow that doesn't fall apart under volume. Our next speaker, Josh Linder, team lead of channel engineering at Armis, is going to talk exactly about that and specifically how Hacker 1 and Armis are working together to close the loop across the full cont…

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready
Watch on YouTube