This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Scaling AppSec and Cloud Defense When AI Exploits Move at Machine Speed

Download resources

About this session

Mark Pilon, regional sales manager for Eastern Canada at Wiz (acquired by Google for $32 billion), argues that frontier AI models now discover and exploit vulnerabilities autonomously, much faster than security teams can triage manually, and that AI has also widened the attack surface by letting non-developers write and ship code. He contrasts scanning an environment blindly, which is costly and imprecise, with using internal context (ownership, data sensitivity, exposure and connectivity) to decide which of tens of thousands of technical vulnerabilities actually matter to a given organization. He walks through pairing an AI "attacker" agent that proves exploitability with an AI "fixer" agent that drafts remediation code for a human to approve, and cites customer results, including zero critical issues and a faster mean time to repair, from consolidating siloed AppSec, DevOps and CloudSec tooling into one contextualized platform. He closes arguing security must stop acting as a gatekeeping department and instead democratize visibility so every team shares responsibility, which reduces analyst burnout as attack surfaces keep growing.

Recent advancements in AI models mean frontier systems can now autonomously discover zero-days and exploit vulnerabilities at machine speed. Traditional security postures that rely on manual triage are collapsing under the weight of these automated, non-deterministic attack paths.
This session introduces a practical, four-pillar operating model for AI Threat Readiness. Attendees will learn how to reduce exploitable exposure, accelerate remediation, uncover risk through deeper analysis of code and AI systems, and use AI to detect, investigate, and respond to threats at machine speed.

Key takeaways

  • Do not scan blindly with frontier models to find vulnerabilities; it is expensive and produces more findings than any team can triage. Prioritize instead using your own environmental context (ownership, exposure, data sensitivity).
  • Break down the silos between AppSec, DevOps and CloudSec tooling; a vulnerability that looks low-risk in isolation can become critical once its position in a full attack chain is understood.
  • Pair an AI "attacker" agent that proves exploitability with an AI "fixer" agent that drafts remediation code, but keep a human responsible for approving every fix before it ships.
  • Track mean time to repair and the share of assets with zero critical issues as concrete measures of whether a contextualized, AI-assisted vulnerability program is working.
  • Treat security as a shared, horizontal responsibility rather than a gatekeeping department; giving developers and GRC staff direct visibility reduces burnout and speeds remediation.

Speakers

Mark Pilon
Mark Pilon
Regional Sales Manager, Eastern Canada · WIZ (a Google company)
Mark is a seasoned business leader with over 25 years of experience navigating the evolution of enterprise infrastructure. Working with industry disruptors like VMware and Nutanix, Mark has helped organizations adapt to the major technological… Read moreRead less

Mark is a seasoned business leader with over 25 years of experience navigating the evolution of enterprise infrastructure. Working with industry disruptors like VMware and Nutanix, Mark has helped organizations adapt to the major technological shifts that modernized the datacenter. Building on that foundation, he has spent recent years guiding organizations through the next evolution of IT—transitioning clients to hybrid cloud environments that enable agility and innovation across every major vertical in Canada, including the federal government. He now joins Wiz to enable organizations to navigate the security gaps across hybrid multi-cloud environments.

Resources

Photos

Tags

More from GoSec 2026

Also from Mark Pilon

On the same topic