Ep 113 ·
Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Alma Paul is a Senior Corporate Security Engineer at Faire. She is a specialist with a strong educational background, industry experience and in-depth knowledge of security tools, techniques and practices.
Ep 113 ·
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Start with visibility: catalogue your assets so you know what you own, then build a risk registry and define a North Star for what a successful program looks like. Next, give guidance for a consistent risk model so anyone on the team analysing a risk reaches the same criticality. Finally, check whether you are actually leveraging the tools you already have, and whether anyone or any automation is acting on their alerts, before moving on to something new.
Alma advises steering clear of vanity metrics such as the raw number of vulnerabilities reported in a year, which say nothing about how well the program is run. Good metrics tell a story over time: how much risk you have reduced and how much coverage you have gained. They also reveal where you miss targets, which helps you decide whether you need more automation or more engineers, and they should be flexible enough to let you pivot without being penalised.
Alma's view is that finding vulnerabilities has never been the issue; fixing them has. A CVSS critical does not automatically mean critical for your organization, so add context: is there an exploit, is it remotely exploitable, is the service exposed to the internet? AI can help enrich, triage and group findings and identify compensating controls, but the fundamentals still hold: patching on a cadence, buy-in from teams who carve out time to remediate, and metrics that show progress.
No. Alma sees them as complementary layers of security rather than alternatives: a robust vulnerability management program addresses issues before they become problems, and detection and response catches what slips through, because no preventive control is 100%. Taking resources from vulnerability management to fund detection would just leave you needing a huge detection and response team, so she would rather deal with it upstream while building layers.
Start with business context: what your worst day looks like and which assets are high-risk and high-value, then translate each vulnerability's risk score to your environment. Check whether an exploit or working proof of concept exists and whether the vulnerable service is exposed to the internet; if it is, she would probably call an incident right away, while a segmented-off service buys more time. Be deliberate about what you call critical, so other teams can trust that a critical genuinely needs attention.
Evaluate an AI tool like any other product: is it solving a problem your organization has, how well does it solve it, and does it deliver what it claims? Having AI in its name does not make it good. Alma sees real gains in areas such as detection and response and DLP, where context awareness could replace black-and-white regex matching, but warns against expecting AI to replace security engineers; use it to offload mundane, repeatable work.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.