Security Theater Podcast

Episode 2: Joe Silva & Kirk Havens

Joe Silva and NIQ strategist Kirk Havens on why vulnerability management is dead, what replaces it, and the agentic AI mess heading for your attack surface.

About the podcast — Hosted by former CISO-turned-CEO Joe Silva, this show delivers unfiltered stories, lessons, and laughs from the frontlines of cybersecurity leadership.

Overview

“Vulnerability management is broken” has become a vendor cliché. In this episode of Security Theater, Joe Silva and NIQ’s Kirk Havens take the claim apart and rebuild it. Their starting point: vulnerabilities are a lagging indicator, not the root problem, and the discipline has not kept pace with a roughly sevenfold rise in volume over the past decade while budgets and headcount stayed flat.

The conversation moves through why traditional patch SLAs of 60, 45, 30, and 7 days no longer hold once mean time to exploit has collapsed toward zero, whether “exposure management” is a real evolution or a repackaged prioritization schema, and why the fix runs upstream: tech debt, asset hygiene, and the organizational trust that lets a security team ask why a vulnerability exists instead of just re-ranking it faster.

They close on agentic AI and the warning that rapid, ungoverned adoption is already recreating the same boundary and sprawl problems the industry spent a decade failing to solve, this time across AI agents and the identities they carry.

It is part reframe, part field report, with hard-earned takes on leading remediation teams, translating risk to the business, and what finally forces the model to change.

Key Takeaways

  1. Vulnerabilities are a lagging indicator. Counting and re-ranking them faster does not fix the tech debt and hygiene gaps underneath.
  2. Volume has outrun capacity. Roughly seven times more vulnerabilities over the last decade, against patch SLAs built for a slower era.
  3. Time to exploit has gone negative in some cases. Exploitation can begin before a team has even scanned for the flaw.
  4. “Exposure management” can sharpen the executive narrative, but is often an automated version of the same prioritization, not a structural fix.
  5. Leading remediation works better without blame. Anchor on shared goals and ask why a vulnerability exists, not just how fast it can be closed.
  6. Agentic AI is the next sprawl problem. Ungoverned adoption recreates old boundary and identity gaps at machine speed.

Chapters

  • 00:00 — Cold open and introductions: Joe Silva and Kirk Havens
  • 01:16 — Is “vulnerability management is broken” actually true?
  • 03:11 — Legacy vuln management's overhead and the 7x volume spike
  • 06:59 — Exposure management: real evolution or new buzzword?
  • 08:57 — Agentic AI, IT hygiene, and going upstream
  • 13:10 — Building trust: moving past punitive security culture
  • 15:49 — The KRI trap and asking why vulnerabilities exist
  • 18:23 — Why vuln management lags behind detection engineering
  • 21:53 — “Murphy doesn’t care”: attacker speed vs. defender economics
  • 27:16 — Reframing security as operational and financial risk
  • 29:02 — Why Joe started Spektion; dropping blame in vuln conversations
  • 34:54 — Agentic AI's coming wave of security-boundary sprawl
  • 38:09 — The AI governance gap and agent sprawl at scale
  • 44:56 — The cloud cost/security parallel and agent identity gaps
  • 47:20 — Closing hot takes: what finally forces real change

Guest & host

The guest

Kirk Havens

Head of Security Strategy, NIQ

Kirk Havens is Head of Security Strategy at NIQ (NielsenIQ). With more than a decade in cybersecurity and senior security roles across global enterprise and financial services, he brings a practitioner’s view of where vulnerability management breaks down, why volume has outrun capacity, and what agentic AI will do to the attack surface next.

The host

Joe Silva

Co-founder & CEO, Spektion

Joe Silva is co-founder and CEO of Spektion and host of Security Theater. A former Fortune 200 CISO with a background in security and intelligence, he started Spektion to close the gap between what scanners flag and what is actually exploitable at runtime.

Share with friends: