
The Missing Piece in Your Threat Exposure Strategy
Source: YouTube · HackerOne · published Aug 17, 2026 · 16:40
Josh Linder of Armis (by ServiceNow) explains how Armis and HackerOne together close the "last mile" of continuous threat exposure management (CEM)—getting from validated findings to confirmed fixes 0:39.
Key Takeaways:
• HackerOne's platform rests on three pillars—continuous monitoring of attack surface, human-validated findings, and remediation—with the human element staying essential 1:17.
• Armis aligns through discovery, analysis/prioritization, and remediation, bridging IT, OT, IoT, and medical device environments 3:00.
• CEM adds a "scope" phase and treats remediation broadly—patching, compensating controls, or risk-register acknowledgment—especially after the July 2024 outage made automated patching riskier 5:07.
• Tool sprawl floods teams with signals; Armis integrates ~400 signals with proprietary passive telemetry to reach ground truth 9:00.
• Exposure is now "ground to cloud"—risk spans on-prem, cloud, and third parties, requiring rules-based ownership assignment and risk registers 12:29.
• AI only helps with good data and processes—without validated discovery, automation just "makes bad faster" 13:39.
The talk closes with a simple mantra: quickly find it, track it, fix it, and continuously monitor for reemergence 15:39.
Sources:
- 0:39 Intro: remediation "last mile" and Armis–HackerOne partnership
- 1:17 HackerOne platform: continuous, validated, remediated
- 3:00 Armis discovery, prioritization, remediation
- 5:07 CEM phases and remediation options
- 9:00 Tool sprawl and 400-signal integration
- 12:29 Ground-to-cloud exposure
- 13:39 AI and data quality
- 15:39 Closing mantra
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Jay's perspective as a practitioner is always grounding. The things that held the fundamentals, the discipline, the human judgment. That's a useful counterweight to a year that has felt relentlessly fastm moving. And that word remediation, it keeps coming back. We've talked about finding vulnerabilities faster, validating them faster, understanding the backlog, but there's a critical last mile getting from a validated finding to a confirmed fix. And that requires more than a good platform. It requires coordination, clear ownership, and a workflow that doesn't fall apart under volume. Our next speaker, Josh Linder, team lead of channel engineering at Armis, is going to talk exactly about that and specifically how Hacker 1 and Armis are working together to close the loop across the full cont…