Why AI Is Making Vulnerability Management Worse
Security UnfilteredSeptember 08, 2026
263
00:51:1293.73 MB

Why AI Is Making Vulnerability Management Worse

Joe talks with Dominik Richter, co-founder of Mondu, about how AI is changing security work, vulnerability management, and the expectations placed on technical teams. The conversation digs into why so many security workflows still produce noise instead of action, and why speed without quality creates more problems than it solves. They also explore what this means for hiring, junior talent, and the skills that will matter most as AI becomes embedded in day-to-day work.

00:00 The Evolution of AI and Its Impact
06:16 Challenges in Vulnerability Management
13:00 The Role of AI in Security
20:19 The Future of Work in an AI-Driven World
21:09 Enhancing Productivity with AI
29:41 The Evolving Role of Security Professionals
40:16 Navigating the AI Landscape in Security
48:52 Adapting to a Rapidly Changing Tech Environment

Affiliates
➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh
➡️ OffGrid Coupon Code: JOE

➡️ Unplugged Phone: https://unplugged.com/
Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout

*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

Tesla Referral Code: https://ts.la/joseph675128

Follow the Podcast on Social Media!

Instagram: https://www.instagram.com/secunfpodcast/
Twitter: https://twitter.com/SecUnfPodcast

Joe: How's it going, Dominic? It's great to finally get you on the podcast. You know, I was I was looking back and man, I I think that we were trying to plan this thing for like forever at this point. It's an embarrassing long amount of time. But I really appreciate you being patient with me. Dominik Richter: not at all. It's great to be here and thanks for inviting me. Joe: Yeah, yeah, absolutely. No, I I love I love having conversations with people that, you know, like live and breathe this sort of area, this sort of domain of just AI overall, you know. it's always so fascinating. I learned so much. Dominik Richter: speed at which it is changing too, honestly. I had the conversation just this week where we looked back at where we were a year ago, when like MCP servers are out there and people were just jumping on that and it was like that was completely hot. And now, you know, look at us a year later, so much has changed. So yeah. Joe: Yeah. Yeah, I mean a year ago agents were pretty new and they they weren't very like widely used, I feel. And now we're talking about looping agents. And you know, whenever whenever they talk about looping agents, I feel like some people, you know, the benefactors of looping your agents are just like conveniently leaving out, hey, this is also gonna like exponentially increase your costs. But Let's not worry about that. Dominik Richter: Yeah, no, don't worry, right? Like tokens are gonna be so much cheaper. you just ran out again. don't worry, it's gonna get cheaper. no, like a Joe: Yeah. Dominik Richter: year ago, I I think you're right, when we were talking about agents back then, I I was at Black Hat, I remember in August, and people were like, yeah, we have like this cool agentic system running. And I'm like, Okay, like can you show me? Like, what exactly are your agents doing? And it was a lot of hand waving, marketing, and pretty slides. And get on a call to test it out rather than actually seeing what the code does. I've grown up in this IT space from the command line, so I don't know. I I usually my my proof of concept is I can see that it's actually doing something and I'm not just watching pretty demo. So Joe: Yeah. Dominik Richter: yeah, there was very little of that a year ago. Joe: Yeah. No, I you know, I I spent the first, you know, ten, twelve years of my career, like on the other side of IT, I call it, where you're internal to security teams and whatnot. and now I'm a bit more on the consulting side. and during that time I can't tell you the amount of times where a vendor would get on the call The title of the call would be demo. Like demo would literally be in the title of the call. And we get Dominik Richter: Yeah. Joe: on there and it slides for an hour. And I'm sitting here like, guys, hey, like I thought we were gonna see the product, right? Like slides are great and all, but I don't want an hour of slides. Like, you know? And they're like, yeah, you know, it wasn't ready. We'll reschedule the call. So we reschedule it for a week out. more slides, you know, and I'm just sitting here like, Dominik Richter: Yeah. Yeah. Joe: hey man, you guys don't have anything. Like you can just tell me. You can just be up front, you know, be like, this is roadmapped, but like you don't have anything to show me. And it it was a very big name vendor. Like I think they're a public company, actually. if I said their name everyone everyone listening, watching watching would hear, right? They would know it. and I just couldn't believe it because like It was like we did like three, four iterations of this where like demo is in the title of the call, like Dominik Richter: Yeah. Joe: where I have my CISO on the call, you know, and I emailed them ahead of time, like, hey, we actually need to see the product, you know? And it's like, man, I cannot believe it. Dominik Richter: It it the time really matters. And I think that's the big one. Like if if you get your CISO for an hour onto a demo call and then all you see is slides, you can send me the slides async. Just freaking send them over. We're here to see it. We're here to have a conversation to actually see what's working. I I will Joe: Yeah. Dominik Richter: also not name a vendor, but we were just looking. we had a conversation with a partner last week. And the partner was telling us about this customer that came in and said, Well, you know, this big vendor product and the same space that we were, vulnerability space. Yeah, they they give you all the remediations. They do the same thing you guys do, because like we're very specialized on providing good quality remediations, operational considerations, all the good stuff, right? So the customer was like, no, I get this from vendor. And so we we actually have like real accounts with the vendor, like we're like other security companies too. You know, you have like a bunch of accounts with them, Joe: Right. Dominik Richter: they don't know it's you, but you're just like a regular paying customer. So we see what's in there, we go in there with the partner, we try it out, we look at it, like the actual bits and bytes, like what do I see on the screen when I look at the issue and I get the remediation and was basically, Well, there's your ticket, you have the C V E, you should go fix it, enjoy. It's like how is that a remediation? Joe: That's it's like the same thing that vulnerability management has been doing for like how long? You know, for like 10-15 years. It's the same thing. Here's you know, before it wasn't as automated, right? But now I hook in my vulnerability management system into ServiceNow or whatever my ticketing system is. I tell it where to send different tickets, and that's it, man. Like I I don't know. I I don't get it. you know, I Dominik Richter: It's Joe: just about every company has had this problem where, you know, tickets just get sent out, no one's following up with it, right? And I was working for a large automotive manufacturer, one of the German ones. So narrowed it down to three for ya. And you know, th hundreds of thousands of employees. Like Dominik Richter: Yeah, yeah. Joe: We w we had such a large AWS presence that like we started measuring, you know, the the size of our environment as a percentage in relation to AWS's like total infrastructure, right? Dominik Richter: Well Joe: because it's just insane. And you know, our our vulnerability management like status at that point was so bad. I mean it w years worth of backlog. And it literally took me Holding devs accountable on phone calls to their directors and VPs to saying, like, I'm not playing around. Like the this Dominik Richter: Yep. Yep. Joe: report, like you have seven days to fix it. At the seven day mark, this automatically gets sent to your VP. And your VP has to rationalize it to the CIO. And the CIO has to rationalize it to Germany. Like, that's the flow, right? And you're gonna be called out by name. on these monthly reports if you're the hold back, you know, the you're the blocker. Like and that's the same that's the same issue that like we've all been running into, you know, and like a lot of companies are like that. Dominik Richter: It's vulnerability management. so my my entire take is it's been stuck in a rut for the last 25 years. I started hacking more actively in the early nineties. I'm gonna age myself here, when I was like barely knew how to, you know, read and write. Joe: Hacking on DOS. Dominik Richter: Yeah, I actually I was. DOS was the first one, and then into the very early versions of Windows, and I basically grew up as Windows 311 was growing up. I grew up with it. it was a lot of fun. I I've mentioned this in other places, but like seeing the movie Hackers back then as a kid kind of was like really fucking cool. And so you got deep into hacking, not just because of Angelina Jolie, but because it all seemed kind of awesome. And so I have seen the you know, the other side of here's how vulnerabilities get reported. Here is how I report my pen test results. So I became a pen tester, broke into systems for a living, right? So I reported a lot these results. And I noticed that people were kind of getting the easy things wrong before I could even get to the hard things. And it feels like the industry has been stuck in that mode for over 20 years, 20, 25 years. There are some companies that do this well. They have good processes around it, they react very, very quickly to the findings that they have, they get them ironed out. And then there is a big group, the vast majority, that are still falling behind, that are complaining about the noise that they are getting in, the quality of findings that they are getting. And a lot of it is also due to the tools that we have seen in the security industry. So it's one of the problems that's been near and dear to my heart. It's something I've been trying to fix. Especially because I started to switch sides. I wanted to see what is it like? Like why are we running so slow on the fixing side? And after I experienced getting some of these tickets and bug reports that were uninformative or wrong, we can talk more about that with the AI stuff that's coming in. but being on the receiving end of it while also having other priorities, I started to see it as like a systems problem that needs to be solved. And so yeah, I've been working Joe: Yeah. Dominik Richter: on that ever since. Joe: Yeah. It it's It's a hundred percent correct how you describe it. You know, it's a it's a systems and a even like a process problem, you know, at least in my problem, or at least in my experience, right? Where, you know, me telling a dev that they have to fix something, their immediate pushback is, well, what takes priority, this you know, revenue generating feature or this bug, right? And if their director and their VPs don't see the value in resolving that vulnerability, then, you know, you're never gonna win that argument. But at least in my experience, if I go and get the buy-in from that high level first, and then they tell me like, you know, hey, you you have my permission, like go be a bully to this guy. It's fine. it really like opens the doors to me then because then I can I can literally and I have done this like at that very large company, which was Very interesting. And I later found out my CISO would get a lot of complaints about me. And he's like, You're complaining. You think that you're making a difference complaining to me about this, but all I hear is that Joe is doing his job and that you don't like he's doing his job. But like you don't report to me, Joe reports to me. I like what he's doing, you know, like that sort of thing. and I was literally reprioritizing their whole their whole queue. Right, because I was just like, Dominik Richter: Yeah, yeah. Joe: well, that doesn't matter if it gets breached, right? You're building this thing on faulty software. If you deploy it, it's gonna get breached. Do you really want to eat that risk? Because like I would literally just go back to them and be like, Okay, well, here's the accepted risk form. You have to sign your name here. And what this means is that you're prepared for your department to eat this amount of money if we lose control of the environment because of this mistake. that you're making. And it was like, Dominik Richter: Yeah. Yep. Joe: well because he's a dev, right? He doesn't want to make that that judgment call. I would even take it to his VP and the VP doesn't want to make that call, right? The VP doesn't want to sign off on it. So it's like okay Dominik Richter: Yeah. Yeah. Joe: guys, you have to sign you have to like either sign off or fix it in seven days. Make your make your choice. Dominik Richter: Yeah, they they want to keep it in purgatory, right? Like as long as they don't have to sign off and they are not responsible, they're like happy. But it's Joe: Yeah. Dominik Richter: good that you put the timer on in. And I will tell you this, Joe. Like, this is like you coming in. Like, if you were to come into my department and you told me these things and you had the analysis, the jobs, the quality behind it, I'll be like, Okay, like we can work through this, we can prioritize it Joe: Right. Dominik Richter: in, I'll get this tackled. what I'm seeing more, especially in the last year. Is that with some of these programs that are out there like Buck bounty programs, and like we have certain hacking programs as well. you see results coming in that do not meet this bar anymore. It's basically either, you know, three years ago I would have said it's the script kitty running the tools and just giving me the output from the tool. these days I'm saying, yeah, it's it's the freaking AI slop, like it's some AI tools running compiling like a big ass report and then keeping me busy with it just because it's easy for them to generate. Joe: Right. Yeah, it's it's funny, like whenever I go down that path, you know, like I always provide abundant information, evidence, proof. A lot of the times I'll write the command that I need them to push enter on from their keyboard, you know, like just to literally make it as easy as possible. So like when people make it difficult for me, it's like abundantly frustrating because it's like I could have made this so much more difficult for you and now I'm gonna like vocalize it to everyone. You know, and like you said, w the the quality and that that's that is something that I've heard from a lot of my customers is that the quality has actually dropped. The speed has increased, but the quality has dropped. And you know, at at my current company, I I was talking to the director of like offensive security and he talked about how he had to essentially beat Claude into submission for six months. for it to generate a report, like literally just take results, just you know, de de anonymize or anonymize results and put it into a report in the format that it should with the context and everything. because like, you know, me and him are alike where it's like the last thing I want to do is write a report. Like, you know, Dominik Richter: Yeah. Joe: I I can do all the technical stuff, but now you want me to create a report, you know? So like let's Let's offset that that arduous task to the AI. And he literally said he's like, I had to beat this thing into submission for literally six months and it like kinda gets me there, you know? Dominik Richter: Yeah, that's that's the thing. These are the tasks that I want AI to do, right? Like summarize this, compile this, get all the stuff together that I have. it's our time that is really, really valuable. So human time is very valuable. And if you have, you know, if you think about these buck bounty programs that are out there, for example, or like these hacking programs that are out there, like we have one too. the reason why we did this is because it is More scalable, easier to get somebody out there in the world to you know find a valid vulnerability, find a valid issue, report it back to us rather than me trying to hire 10 people and do it. Like, let's be honest, that's where the economics of many of these bug bounty programs started. But then AI is kind of turning it on its head these days when you have like AIs trying to generate and reason why they found something. And here's the thing: depending on how your AI is configured. you're going to deal with an incoming report that is confident, that has the proof, that has like a chain of commands, and that will argue with you. So when I use you know AI day-to-day, like I don't know, you're using something like Claude or Cortex and so on, encoding. those AIs are configured in a way where they are trying to be nice to you. in in the best way. So if if you have a problem with it, it's not gonna argue back. It's gonna fold like a lawn chair. But when you have the ingress report coming in with like, hey, I found this hacking thing and I know I'm gonna get paid at the end of it, they will try to argue with you that Joe: Hm. Dominik Richter: they're gonna be right. And maybe there's a percentage, like let's say five percent of people will just be like, well fine, I'm gonna pay you a couple of dollars and just make this thing go away. If that happens, then the AI gets more and more incentivized to do it. And so this is a problem where you have like a high rate of false positives and it's really drowning out human noise the the human findings. Like let's say somebody like you coming in and finding like a real thing. I'm getting your report in the middle of like a hundred other reports that I'm sifting through. And that is creating a real problem that we're seeing both with our customers as well as with ourselves. Joe: Hmm. It's crazy. Did did you look at anything with like Mythos five and Fable? the you know, the reason why I ask, because it's kind of like twofold, it's like it it's multifaceted, right? Because you know, it feels like in some ways AI is getting really smart, really capable, you know, able to do a lot of things that honestly would just take us forever. You know, like I had to create a slide deck earlier for a presentation, you know, that I'm gonna do. And I just gave the prompt. I gave my expectations, the goals, everything. It created the present the presentation in you know ten minutes, right? Like I mean, that's something that normally would take me like two weeks to put together. Honestly. I mean, it's like twenty slides long, but like literally it would take me probably two weeks, you know, and this thing coughed it up in ten minutes, made some adjustments, gave me a refined report, good. But you know, when it comes to those models, you know, it's like the US government is acting like it's a like it's a super cyber weapon, right? Like a super weapon of some Dominik Richter: Yep. Joe: sorts, right? Which it could it okay, theoretically it could be true. Right? I don't know. I haven't looked at mythos, I haven't played with it, nothing like that. Ninety nine percent of us haven't So it could be true. I also know the government like fairly well because I did some work with them earlier on in my career. And typically when something's a real threat like that, like they don't they don't like you know they don't not act the way that they did. Right? That like they rip it out and they make a ban on it immediately. Like it happens within an hour, you know? Dominik Richter: Yeah. Yep. Joe: So that's like totally reasonable in my mind. And then I look at people like Pliny the Liberator on on X, and he he's breaking these models, you know, just every single day, all day long. And so Dominik Richter: Yep. Joe: it makes me think it like brings me back to reality where it's like, well, maybe these models aren't all that, right? Like because you got you Dominik Richter: Yeah. Yeah. Joe: got anthropic CEO telling me I'm gonna be out of a job in six months, five times in a row, and I'm still employed. And that and you know, all these other factors in. So it's like, what's your take on it? Dominik Richter: Okay, I so this is gonna be a longer one because I have thoughts on Joe: Yeah, go ahead. Dominik Richter: all of that. Okay, so one is first of all, like these crazy hacks, vulnerabilities, exploits that are out there. this has existed for again the last couple of decades. These there is a black market for these. Anyone who finds them, by the way, who finds something this crazy, there's enough people that are not gonna submit it into your bug bounty program. They're gonna keep it and they're gonna monetize it through other channels. Let me put it this way. this has existed for a while. And then they get uncovered and we fix them and they become the priority findings that we all know and love, and that gets us into a panic and some level of news coverage. then the whole AI space starting to look into critical infrastructure and trying to break it. If you've been watching DEF CON for the last three years, I think it's been going on. this was one of the big topics where they started to run the big contest to find. vulnerabilities in core libraries, so C libraries, Java libraries, and so on, with the help of AI. They were doing this in order to find vulnerabilities that were real, that they could write a demo for and then suggest a remediation as well. So they were scored on all these different axes. that was great. So that I already saw that last year when it was still coming out, but it wasn't as hot because obviously, you know, you aren't a Trying to be a trillion dollar company trying to go to the stock market. So the marketing behind what we're seeing on mythos, of course, was a lot stronger, was using a lot more channels. Is that real? Yeah, there's a large part of it that is real, that we're seeing as well. The part that I think is more important here is that when these vulnerabilities do get uncovered, the time to exploit has basically gone down to zero days. So you need to react faster. The processes that you need to have in place today to fix something like this, it can't be the like, we're gonna wait 14 days for the P0 to get fixed because you know our processes take a while. That measure is just not good enough anymore. In my book, this is what we need to fix. It's basically our ability to take these and fix these. That's what needs to get a lot better. being out of a job to quickly address that point too. What I found, and and this is as a company, by the way, as a startup, where we switched every facet to be AI driven from marketing to UX, PM, engineering, everybody's jobs have changed, for sure, but I need good people more than ever. More than ever before. Like the quality is just Joe: Right. Dominik Richter: so much more important with AI in the picture. Joe: Yeah. And I feel like companies are slowly starting to realize that too. Y you know, where I I feel like a lot of big name companies like AWS for instance, you know, I mean they even admitted it. Where it's like, Yeah, we got rid of these people, replaced them with AI, and then we had a major outage, huge outage, and they're like, you know what, maybe maybe we went a little bit too aggressive with this thing, you know? so like I I feel like companies are starting to open their eyes to it where it's like, hey, this doesn't offset people yet, you know, maybe maybe not yet. but it definitely enhances them and you should be using it as a productivity increase, an efficiency increase. You know, like that test that literally would have taken me two weeks, took me 10 minutes, and now I'm prepared for the customer, you know, now I'm prepared to talk about it and Everything else like that, you know? Dominik Richter: It's it's the duality of this new world where certain things have gotten a lot easier and then other things are still difficult. So we it's not a panacea, right? Like it's not an automatic solution to everything. You need to feel out where it's good at. For example, we did a major version bump in our open source tooling in February, I wanna say. Yeah, it was February. And the some of the restructuring that I was doing there would have been would have taken me probably two weeks to do. So similar to your slide deck, but me two weeks, you know, sitting just on code, just restructuring it all and making sure that it all works in the end, because it is a very large code base. With AI, I was able to do it in an hour. So it was able to pull that task together and just work through it. It's because it is a fairly menial, you know, straightforward thing. It has a good pattern for it, so was able to execute that. And I compare it to something that I was doing last night where I was updating a couple of flows in the UI and the AI just jumped ship. I I don't know what caused it, but it just went overboard. started to change parts in the UI that it wasn't even supposed to touch, simply because it's It kind of exploded. It it ran into a pattern that it didn't recognize very, very well and it went overboard. For me to fix it was fairly easy because I knew what was going on and I caught it in the act and was able to stop it. My colleague who is a UX designer, she ran into the same into a similar problem three days ago. And so on Monday, I guess it was two days ago. but when she ran into it, she wasn't able to recognize the pattern. She wasn't able to understand what the AI was doing under the hood and then I was caught in a rut. And it burned through all her tokens for Joe: Ooh. Dominik Richter: the day. And then you're kind of done. So yeah. Joe: Hmm. Do you think do you think I mean obviously she didn't have the experience with that previously, right? But do you think though that like your mentality and your knowledge that you've developed over time as a hacker kind of from ground zero, right? I mean like basically hackers, that's like ground zero early nineties. do you think that that skill set enabled you to identify it as quickly as you did because you know I I ask because and I've said this for a while I I feel like I feel like hackers or security people overall have to be so knowledgeable about so many different systems. You know like I'll give you an example. I was troubleshooting an issue with a vendor and the vendor could not figure it out. Right. And and their net their next escalation point was the guy who wrote the code. And so like I was on on this call and I literally said to him, I was like, okay, so the database query that this button is ro is pushing has to be something like this. Like it there's there's just no other option with it. And they were like, we don't know. Get they get the dev, right? And the dev is like, yeah, that's actually exactly what it's doing. And I was like, okay, well, if it's doing that, it's gonna break like this. And he didn't even understand why it was going to break like that. You know, and I had to like break it down for him. And not that like I'm some super smart guy, but it's because like, hey, I have experience with like Microsoft SQL and Postgres databases, right? Like I have experience in the cloud and web apps and how they communicate all through all through the stack and everything. Like I've looked at those commands, I've troubleshot them myself. You know, I kind of understand what's going on behind the scenes, right? And that's something that you don't get as a UX designer. You know, that's something as you that you don't get as a network engineer or as a database engineer. You don't get any of those pieces, right? The security person has to know it because like, you know, half of our job is like, Well, if I want to break it, how am I gonna break it? You know. Dominik Richter: Yeah. I I felt that it was for me one of the hardest jobs I've ever done. So I'm I'm very much a developer too. I'm a coder. That's why I built the company too, you know, with my other co founders. I'm in code every single day. But I'll I'll be like very honest and frank. I think the like becoming really, really good at pen testing has been the hardest thing, tech wise that I've for sure done. Because as you say, you need to understand the stack, you need to understand how it works, you need to intimately understand it, right? You also need to understand how users are going to use it, because for some hacks, there's like certain paths where you're trying to push them or incentivize them into. Joe: Right. Dominik Richter: you need to understand how certain setups work. It's like last year again at DEF CON, another example. I was in this talk about network security and using VPNs, tunnels and everything else. to your advantage, you will have to understand how the network engineer set this entire thing up. So there is a person in your company that is specialized in this, and they set up these crazy, really int intricate networks where all these systems are securely connected, or is at least we assume securely connected. And then as a security engineer, you have to have that level and the level of how do I now break it? How do I abuse this in a way that I can, for instance, ping a system, one of your internal systems, and it's going to look like the ping comes from the outside world with the public IP. that's what the guy demonstrated there. It was really fun to see. but yeah, you have to know all these topics, and it's very difficult, and you have to have a lot of specialized knowledge for this. With AI coming into our lives, I think what I care about, like when I look at my team right now, PMs, engineers, UX designers, I'm looking for the skills that uniquely qualify what they do. So for example, my UX designer, they will recognize certain patterns in the UI that are bad because they've seen them over and over again. They know that you shouldn't apply it in this way, where in this context it doesn't make sense. It is now really, really easy for, for instance, one of my engineers to sit down and say, I want to create a UI for this flow. And they will set it up and AI will spin it up in minutes and it will be there. And the thing is, it's gonna look convincing. And then you start to use it, you start to get deeper into it, and you will start to realize that it doesn't feel right, or you can't do a bunch of tasks, or it feels overwhelming. this also happened when, for instance, my one of my PMs started to create new experiences with the help of AI. I was able to spin up all of these things. But he was Smart enough to realize that I'm getting these experiences that I want to have, but it doesn't fit together. Like something doesn't flow right, but I can't fix it. Like I don't know how to fix it. And so this is where again the combination of UX, PM, and engineers come together. Because again, PM and UX are both going to hit the wall at you know, cloud running into something where it will burn through tokens because some API doesn't have the right shape. PMs are going to run into something where structurally they they set up flows that don't work. And UX is going to run into the two opposite problems where they set something up that isn't valuable to the user, or like it's nice, but you know, it wasn't really the problem that they're trying to solve, or they're trying to connect some elements that aren't fully going to make sense. And in the middle of this giant cluster comes security, where all of this still needs to be. Secure. And so to me, it is that our jobs are switching, our jobs are changing. If your expectation is that, you know, like I learned programming, that I'm gonna be the programmer that I used to be the last 15 years, that is definitely going away. That job that you used to do, that is gone. Like, if not today, then in the next three years. So when people No, like some of these companies, they're very incentivized to sell us on their services when they say your job will be gone in four years. In my head, it's always like the job I used to do, that is gone. But there is a new job that I'm doing with the help of these tools that I need to get good at. I need to get really freaking good at. and that job hasn't even been fully understood yet. But that is the one that I'm training into. And I guess this segues into this whole space of, you know, how do we train the next generation? Because it's no longer that, you know, intro level programmer or intro level security engineer doing the simple tasks like aggregate this thing into a report, as you're saying. They no longer do that. They no longer have that to start to get their feet wet and start to get the understanding. So that's becoming a bigger issue in the industry. Joe: Hmm. Yeah, it's very true. You know, and I I've actually been meaning to like put together, you know, an an episode of me like actually discussing this because yeah, I see so much you know, so much negative posts online of like, I can't get into the space that I went to school for, or you know, whatever it is, right? Like someone someone posted the other day and I commented on it saying that like All the low level junior level roles don't exist anymore, and I just got a degree in something that I can't even get experience in to progress through and whatnot. Right. And you should they were specifically talking about security. Like there's no more entry level security roles. And my comment was there was never any entry level security roles. The entry level was help desk, but Dominik Richter: Yeah. Yeah. Joe: people don't want to admit it to themselves. that it is help desk because no one wants to do help desk but everyone should start at help desk in in my opinion right like that's where you should basically be starting you have to cut your teeth somewhere help desk is a great place it's a nice safe environment at a lot of companies where you can just mess up constantly every single day for like two months and then you figure it out now you're doing good and then you progress through your career but A lot of people do not want to admit that. They don't want to they don't want to go down that route, right? They they want that eighty-five thousand dollar a year job or that hundred thousand dollar a year job in security that they just got a degree for. And it's like, hey, I'm sorry to tell you, right? The investment that you made in your bachelor's degree of fifty thousand dollars, you're not going to take that and then jump into a security job. Because Everyone in security realizes it's like, hey, you can make mistakes at help desk. Like you can make a whole lot of mistakes at help desk. You cannot make any mistakes in security. And that's that's the difference, right? Like get all the issues out of the way first. And then when you get to security, if someone if someone you you pick up the phone, if someone's yelling at you, like it doesn't bother you. It doesn't phase you at all. Right? Like if a director picks up the phone and like yells at me, like doesn't bother me one bit. You know, like not one bit. But if you go back twelve years ago, same exact scenario, bothers me a whole lot. I have to go like take a walk, you know, because like I'm I'm anxious or whatever it is. You know, like that's a that's a literal thing. Like I used to get so stressed out, you know, picking up these phone calls from these angry customers, right? That like I I'd have to go and walk around the block just to relax, you know? And now it's like I could go back to back calls all day long with people yelling at me and it's just not gonna bother me one bit. Dominik Richter: Yeah. You need to get that thick skin for sure. Like, especially if you are in the security space, you're basically dealing with people that have quote unquote higher priorities because they have to ship some kind of feature, or they have to deal with operational issues, or they also want to get home at some point. right, like you need to convince them why your thing matters. In security, one of the things that I always found find hard, still do by the way. is to convincingly frame it to a customer who hasn't been hacked recently, where you're like, hey, these are problems. And it's it's in the back of their heads where they're like, we're not gonna get hacked anyway. We haven't been hacked in the last 10 years. Well it's because Joe: Hm. Yeah. Dominik Richter: you were doing these things well. And now the security landscape, by the way, like the especially the attacker and the hacker landscape has changed, where they're using more AI and automated tools to attack you. I feel that I think it started four or five years ago when the quality of ransomware had really increased significantly. not just in the hacks that they found, but also in the way that they were organized. they used more automation to run their attacks, set up good systems, quote unquote, good systems, you know, after they hacked you to encode, ransom you for the data. But also to have good support channels in place, where you can reach out if you have a problem decoding something. good billing, financial processing. it's crazy that I'm using these terms like it's a big fucking company, but it is. Like in a lot of places. Joe: It's organized crime. They have legitimate defenses and everything, apparently. Dominik Richter: Yep. Nobody's gonna pay them if if they can't decrypt their data afterwards. So the the level of quality that they need to deliver after you pay them is like it needs to be a hundred percent. So yeah, the bar for them became really, really high. the quality that they delivered became great. And I feel that on the defensive side, we haven't necessarily caught up to this. we need to become more proactive, we need to become faster in fixing these things. And with AI in the picture, you know. Mythos or no mythos, it doesn't matter. Ultimately, the discovery rate of vulnerabilities has significantly increased, the number of new vulnerabilities that are out there. The discovery rate of exploits has significantly increased, i.e., we know more of them are real. And so your rate of fixing and handling and prioritizing these issues and making them second nature for you needs to catch up to that. And this is where, for instance, we're coming in with the work that we're doing as a company right now. we believe that a lot of these traditional tools also haven't caught up to this reality, and they are part of the problem that the industry is ailing from, why people are stuck with tickets that don't matter. I've seen the finger pointing, right? Like security points the finger at I sent you the ticket. Operations points it back, that ticket is bullshit. because you know it's some dev library. it is ultimately, and this is what I meant with systems failure. It is Some of these tools spitting out low quality tickets. again, when you come in, you do this because you understand what the chain of exploitation is, and you know this is a valid P0. that is awesome because that is something that I can easily prioritize, hunt down, track down. We can find a solution with you. I can sit down, we can go for mitigations and so on. There's that is quality work, right? That I can do. But a lot of these systems that people bought, like Yeah, I'm just gonna pay a license, you know, I'm just gonna put it in place, gonna spit out some vulnerabilities, we're gonna do a process around this. It has unfortunately created a lot of noise in these organizations, and this was before AI even entered the frame, where low-quality tickets were created that didn't have that level of quality. It was either false positives, because security tools, by the way, overwhelmingly lean into false positives rather than false negatives. False negatives you can be held accountable for if you tell them, this thing is secure, and then it comes out that no it wasn't and you screwed me. that so they're leaning away from that as as a you know somebody who is building these tools, we're leaning more into false positives. But the rate at which these false positives are being created and low quality tickets that are being created from it, that has screwed the industry over. It has screwed your operations teams and your platform teams and your developers. If they see like two of these bullshit tickets coming on on Friday afternoon when they're trying to go home. Their level of putting up with that is going to drop rapidly. So they're not going to engage with that anymore. And then it will feel like, you know, there's another PC or well, who knows if it's real. Like we're going to do this other thing first. And so for us, it's it's become, and for me too, it's become all about trying to solve this process. So using AI, for instance, to understand why certain systems together matter to the organization. making sure that we validate some of these chains that exist, validate the remediations that are there, trying to get information on, for example, is this remediation going to screw somebody over? Because the the latest update from Microsoft's whatever tool, I'm not gonna I have a specific thing in mind, but it's it screws the customer over when they deployed the patch. But we can already see the reports for this coming in, right? Like I can see that this is happening. Can I provide you with that information? Because then your developers and your platform teams also appreciate you a lot more. And so yeah, this is something where we're really trying to help because this is what changed in the industry. So the old standards no longer count. there is a higher level of requirements and quality that we're now being held accountable to. Joe: Yeah, that it's it like go you know, it it it it goes with like just AI slop overall, right? I I I mean I think that was probably like the original the original like purpose of the call, right? But and of course Microsoft is like well known for it now. I'll say that because I'm probably like way too small for Microsoft to even care that I said that. And they already don't even want to hire me. So like there's that. But you know like I wonder I don't know. I I don't know how it how it gets to that. I feel like everyone rushed to it and now consumers are you know pointing out the flaws because it was so like overly hyped. you know, in the in the beginning, the hype is slowly dying down now. because it's it's becoming more realistic, right? Like how many times does Sam Altman have to tell me, you know, being a dev, being a hacker is not gonna get me anywhere in five years, right? Like I I at some point you stop believing them when you wake up and you still have a job. You know, that's the problem, right? The expectations were so abundantly high. And now they're not meeting that expectation, but it's still useful technology. It's still really good at what it does. You know, you still Dominik Richter: It is, yeah. Yep. Joe: have to beat it into submission, but like it still helps a lot. Dominik Richter: Yeah, this this point is what I'm really trying to drive home as well. Like it it's not a black and white. It does certain things incredibly well and it has definitely changed the space already. If you're a developer or if you're a security expert or anyone else in this organization, this will meaningfully change your life for sure. and also it is not just going to overnight replace all of our jobs. I'm continue to not see that. at least For the time being until we get to like true artificial intelligence, that level. But that's been promised to us over the last 30 years, I think more realistically 10 years, where AGI came in as the big topic that will replace all human work on this. if I were to trust any of these beliefs, I would probably be sitting in a space shuttle to on my way to Mars right now. leaning back and having some AI do all the work for me. I think the vision is, you know, having visions for this and having goals with this in mind, that is good. Like I do like it. I do like the idea that with the help of artificial intelligence we can, you know, if we play our cards right, we can go into a more utopian future where AI takes a lot of the boring work away from us. But in order to do that, like we A need some changes on the political level, which let's not get into that. we need changes in how we work day to day. And certainly the work that we do, while it is changing, and while we need to adopt, like that's for sure. That's what I meant with the job is going away. It's the old way of doing the job. Yeah, that is going away. That's gone. But there is a new way of doing it and just opening your eyes and leaning into that and figuring out what you need to do in order to be relevant, in order to solve problems that are out there. AI doesn't magically remove all the problems. It removes a whole bunch of busy work that we used to do. But it reminds me very much like you had these computers, i.e., people in the 60s sitting there punching the cards in and doing like a whole bunch of busy work around what could Computers used to do, or like old secretarial jobs that that still existed up until the 80s. That work is gone. Yes, certainly. And it's about figuring out what the new work is that we're doing right now. AGI does have the fear that it will replace all of that, you know, human mind work. certainly, but we aren't at AGI, at least for the time being. And so If you are somebody who's trying to get into this industry, don't try to use the old approaches. Like certainly do the help desk job that you mentioned. Like that's for sure. Like you need to develop that skin because at the end of the day, you're interacting with humans. So human-to-human interaction, that will remain. That's you doing it. And then for everything else that's connected to that, just be aware of the changing landscape, the changing tools, the changing requirements that we're now in, and figure out. What are the problems that I'm seeing with all of this in place? the tools have changed, the solutions are faster, but you know, also the problems have changed. And so what are the new problems these companies are trying to solve in order to deal with it? I mentioned one problem already. Hackers are getting a lot faster, they're getting a lot more efficient. we're dealing with highly complex infrastructure now. AI just makes it simpler to pull more complex things all together and and mesh them together. So now if you have this super complex system, how do you solve security for that? How do you eliminate slop that's coming in? How do you make the tickets more meaningful for people? How do you get your dev and platform team to be more efficient with the findings that you have? Those are all things that we just mentioned in this call alone. And these are all problems that companies are still trying to solve. They're just new problems to solve. Joe: And it's skills that people should learn to help themselves stand apart from everyone else. You know, like I I feel like a lot of people kind of lose sight as to you know what matters when you're trying to get hired for for a job, right? I mean like at the end of the day, like let's just like cut through it all, right? Like even though we love this thing, we still want to get paid for it. Because we have a mortgage, we have a family, or we have aspirations to do something else. The world requires you to have money to accomplish those things. If it didn't, why would we be doing it? Right. and so like at the end of the day, all this fear mongering of like, it's eliminating all these jobs, or you know, I'm not able to get in and all this other stuff. It's like, no, you should be looking for ways to stand apart. You know, like whenever I venture down something new, like for instance, you know, I'm working on my dissertation right now, right? When I a part of my analysis of getting my dissertation was not just is the topic in high demand in five years, it is does this set me apart in any way, shape, or form? What's the future job at the end of this dissertation look like? that I would then be qualified for that I wouldn't be able to get without it, or maybe the dissertation makes it a little bit easier for me to achieve it earlier on, right? Maybe I could achieve Dominik Richter: Yep. Yep. Joe: that job when I'm 45 or when I'm 50. But if I get the dissertation in my 30s and it immediately qualifies me for it overnight, that's probably worth it. You know, it kind Dominik Richter: Yeah. Yeah. Joe: of cuts down 10 years right there, right? And yeah, it's a weird It's a weird, you know, thing to try and think about that and project it out w and whatnot. But like you have to think about it like that because at the end of the day, to someone that doesn't know you, you're one of a million people that just applied for a job. What makes you stand out, you know? Dominik Richter: Yeah. Yeah, that's and and applying too, right? Like since you're now getting flooded with everybody else. like Joe: Yeah. Dominik Richter: when I just opened a position and there's like four hundred applications that came in so quickly. I I'm a tiny startup, by the way. Like now I have the problem, like I I wanna give everybody the attention, but I like I physically even can't. Like, what do Joe: You can't. Yeah. Dominik Richter: I do? So how do I find the people that stand out and that are gonna be right for this job? Because working in a startup, by the way, is also like that's it's whole thing. So I I wanna find somebody that this matches well with, somebody that that will like this and won't just be like, God, this is like you know, not what I wanted, and that I'm gonna quit in a couple of months, or that I'll have to fire in a couple of months. So, yeah, to your point, like you want to stand out somehow within the space. It reminds me a little bit of uni again. coming out of university, I remember getting like my first proper job. that was when cloud systems were still in the early days and we're starting to build them out. And I remember getting on this team with these cracks, like really fucking good people. Like they were they were seasoned, they were professionals. I came out of university thinking I was a hotshot because like I've coded since I was very, very little. I was a hacker and everything, right? And then I game came into this team and they were like, Are you some kind of idiots? You need to do it this way, this way, this way. Have you done this properly? Like they they put me down a whole notch. And but what I learned and the skills that I took out of university was to develop thick skin towards problems that I may not fully understand, but I understand what problems are and how to approach them and and be creative around that. So from the original just like pure knowledge that I got out of it, I probably didn't take a lot. Maybe this is different in other fields, right? Like I look at my brother who is a doctor. Maybe you come out of that and you know like a bunch of medication and stuff. Cool. But this isn't what it is for us in tech, because tech has just been moving too quickly. Like every five years, there's another major shift, right? Like AI right now, containers before that, with Kubernetes cloud before that. And everything that's connected to it. So that's never been the case. So if if you are entering the tech space, you have to deal with a constantly shifting environment, with with quickly being able to pick up these new stacks, being able to be effective in that and solve problems within that. I guess, yeah, that's that's probably one thing that for anyone that is still on the younger end and it's maybe in university or coming out of university, that's a recommendation. Like learn more about solving the problems rather than just purely trying to remember facts. Like I know a lot of Joe: Yeah. Dominik Richter: schools were about remembering facts. That's you it's not the primary job. Joe: Right. You have to learn how how to actually apply them, you know, how to actually use it in the real world. Well, you know, Dominic, we're we're a bit over our time. My fault, of course, 'cause I was I was running late. I've very demanding one year old and I had to unexpectedly watch her last minute. But you know, I really appreciate Dominik Richter: No worries. Joe: you coming on and I apologize, but we didn't even mention your company name. So You know, in closing, how about you tell my audience, you know, where they can find you, where they can find your company. I'll put the links in the description so anyone that wants to check it out, they definitely can. and yeah, you know, I appreciate you coming on. Dominik Richter: Yeah, my marketing's gonna have my head for this. so Joe: Yeah. Dominik Richter: company is called Mondu, M-O-N-D-O-O, Mondu. We are in vulnerability management. a couple of the things that I mentioned throughout this talk, how I believe that the industry has been in a rut for over 20 years. we have over exerted the focus on just vulnerability reporting, analysis, even the prioritization, most people get stuck at. We really, really care about getting people to fix more and the customers that do this effectively with us, by the way. The big thing for me is always when I see this curve of here's their remediation speed before we came in, and then it explodes and goes through the roof. it's because we are a company that really cares about the security analysis and how you make results meaningful and how you help people to fix them. So bring both sides together. You can find us on mondu.com. mondu.com. we cover anything from cloud Kubernetes to AI security these days as well. And yeah, if you have any questions, feel free to reach out. You can also find me on either LinkedIn or Discord or other channels. Happy to share them. And yeah. Joe: Awesome. Cool. Well, thanks, Dominic. I really appreciate you coming on. It was a fantastic conversation and thanks everyone for watching or listening this episode. I hope you enjoyed it. Please go check out Mondu at the links in the description of this episode. Thanks everyone.