Ep 113 ·
Enterprise Security Restructuring & The AI Vulnerability Boom with Alma Paul
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Topic
Finding and fixing what matters: prioritising by exploitability and business context rather than chasing every CVE the scanners report.
19 episodes · 6 questions answered
Where should you start when restructuring an enterprise security program?
Start with visibility: catalogue your assets so you know what you own, then build a risk registry and define a North Star for what a successful program looks like. Next, give guidance for a consistent risk model so anyone on the team analysing a risk reaches the same criticality. Finally, check whether you are actually leveraging the tools you already have, and whether anyone or any automation is acting on their alerts, before moving on to something new.
Alma Paul · Faire
How do you measure the health of a security program without vanity metrics?
Alma advises steering clear of vanity metrics such as the raw number of vulnerabilities reported in a year, which say nothing about how well the program is run. Good metrics tell a story over time: how much risk you have reduced and how much coverage you have gained. They also reveal where you miss targets, which helps you decide whether you need more automation or more engineers, and they should be flexible enough to let you pivot without being penalised.
Alma Paul · Faire
How should security teams prepare for the surge in AI-discovered vulnerabilities?
Alma's view is that finding vulnerabilities has never been the issue; fixing them has. A CVSS critical does not automatically mean critical for your organization, so add context: is there an exploit, is it remotely exploitable, is the service exposed to the internet? AI can help enrich, triage and group findings and identify compensating controls, but the fundamentals still hold: patching on a cadence, buy-in from teams who carve out time to remediate, and metrics that show progress.
Alma Paul · Faire
Should you shift from vulnerability management to detection and response?
No. Alma sees them as complementary layers of security rather than alternatives: a robust vulnerability management program addresses issues before they become problems, and detection and response catches what slips through, because no preventive control is 100%. Taking resources from vulnerability management to fund detection would just leave you needing a huge detection and response team, so she would rather deal with it upstream while building layers.
Alma Paul · Faire
How do you prioritise vulnerabilities when there are too many to fix?
Start with business context: what your worst day looks like and which assets are high-risk and high-value, then translate each vulnerability's risk score to your environment. Check whether an exploit or working proof of concept exists and whether the vulnerable service is exposed to the internet; if it is, she would probably call an incident right away, while a segmented-off service buys more time. Be deliberate about what you call critical, so other teams can trust that a critical genuinely needs attention.
Alma Paul · Faire
Should security teams adopt AI security tools?
Evaluate an AI tool like any other product: is it solving a problem your organization has, how well does it solve it, and does it deliver what it claims? Having AI in its name does not make it good. Alma sees real gains in areas such as detection and response and DLP, where context awareness could replace black-and-white regex matching, but warns against expecting AI to replace security engineers; use it to offload mundane, repeatable work.
Alma Paul · Faire
Ep 113 ·
Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.
Sana Talwar on product security at scale, reducing friction for developers, and defending AI integrations in the enterprise.
Ross Young on the CISO's dilemma — balancing security, innovation, and burnout — and building cross-functional champions.
Lily Chau on auto-remediation in AWS, overcoming stakeholder buy-in challenges, and prioritising security fixes.
Matthew Marji on building cybersecurity teams, evaluating communication skills in hiring, and aligning security with business.
Htet Naing Aung on supply-chain security, container-image signing, SBOMs, and using SCA tools in CI/CD pipelines.
François Proulx, Senior Product Security Engineer at Boost Security, on supply-chain security, threat modelling, and SBOMs.
Yotam Perkal on vulnerability management, supply-chain security, SBOMs, and prioritising the risks that matter most.
Kalyani Pawar on threat modelling, scaling security with checklists and champions, and celebrating small wins.
Divyanshu Shukla on red-teaming Kubernetes clusters, understanding attacker mindset, and exploiting common cluster weaknesses.
Steve Giguere on Kubernetes security, when monoliths beat containers, and vetting open-source dependencies with SBOMs.
Ariel Shin on balancing production speed with security, the advisory role of security teams, and the value of empathy.
Walter Haydock on vulnerability management, prioritisation strategies, and building a vulnerability programme that scales.
Ray Espinoza on cloud vulnerability management, leading with empathy, and transparent communication during incidents.
Garrett Smiley on measuring security debt, context-driven risk prioritisation, and using KRIs over KPIs for security teams.
Aakash Yadav on security debt, risk prioritisation, and building a pragmatic approach to reducing organisational risk.
Parul Khanna on information security, risk management, and bridging the gap between incident response and business priorities.
Nat Shere on preparing for cloud data breaches, incident response planning, and lowering MTTD and MTTR.
Aseem Shrey, security engineer at Rippling, on responding to ethical hacker reports, preparing for data breaches, and building a security career.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.