Joe Silva and NIQ strategist Kirk Havens on why vulnerability management is dead, what replaces it, and the agentic AI mess heading for your attack surface.
About the podcast — Hosted by former CISO-turned-CEO Joe Silva, this show delivers unfiltered stories, lessons, and laughs from the frontlines of cybersecurity leadership.
“Vulnerability management is broken” has become a vendor cliché. In this episode of Security Theater, Joe Silva and NIQ’s Kirk Havens take the claim apart and rebuild it. Their starting point: vulnerabilities are a lagging indicator, not the root problem, and the discipline has not kept pace with a roughly sevenfold rise in volume over the past decade while budgets and headcount stayed flat.
The conversation moves through why traditional patch SLAs of 60, 45, 30, and 7 days no longer hold once mean time to exploit has collapsed toward zero, whether “exposure management” is a real evolution or a repackaged prioritization schema, and why the fix runs upstream: tech debt, asset hygiene, and the organizational trust that lets a security team ask why a vulnerability exists instead of just re-ranking it faster.
They close on agentic AI and the warning that rapid, ungoverned adoption is already recreating the same boundary and sprawl problems the industry spent a decade failing to solve, this time across AI agents and the identities they carry.
It is part reframe, part field report, with hard-earned takes on leading remediation teams, translating risk to the business, and what finally forces the model to change.
The guest
Head of Security Strategy, NIQ
Kirk Havens is Head of Security Strategy at NIQ (NielsenIQ). With more than a decade in cybersecurity and senior security roles across global enterprise and financial services, he brings a practitioner’s view of where vulnerability management breaks down, why volume has outrun capacity, and what agentic AI will do to the attack surface next.
The host
Co-founder & CEO, Spektion
Joe Silva is co-founder and CEO of Spektion and host of Security Theater. A former Fortune 200 CISO with a background in security and intelligence, he started Spektion to close the gap between what scanners flag and what is actually exploitable at runtime.