Trending Topics

Neena Sharma, Head of Customer and Product Marketing at Filigran: “AI should make your analysts unstoppable, not replace them”
Security teams have never had more visibility into potential cyber threats. From vulnerability scanners and threat intelligence feeds to attack surface management tools, organisations are collecting unprecedented volumes of security data. Yet despite this wealth of information, many continue to struggle with a more fundamental challenge: knowing which risks genuinely matter and acting on them before attackers do.
As cyber threats grow in both volume and sophistication, the industry is increasingly shifting its focus from simply identifying vulnerabilities to continuously validating which exposures pose the greatest risk. This emerging approach, known as Continuous Threat Exposure Management (CTEM), aims to help organisations move beyond reactive security by prioritising the threats that are most likely to be exploited in their own environments.
As Head of Customer and Product Marketing at Filigran, Neena Sharma helps shape the company’s strategic direction as it evolves from a threat intelligence platform into a broader threat management and CTEM provider. With more than two decades of experience spanning cybersecurity and enterprise technology, she has worked with organisations including Akamai Technologies, Tata Consultancy Services and BAE Systems, translating complex security challenges into practical strategies for businesses.
In this interview with TechFinitive, Sharma explains why many organisations are facing an “exposure gap” rather than a visibility problem, where AI is already delivering tangible benefits for security teams, why human expertise remains essential despite growing automation, and how CISOs can prepare for a future where continuous exposure management becomes a core pillar of cybersecurity.
Your latest research suggests that organisations have no shortage of visibility into cyber threats, yet many still struggle to act on that intelligence. Why has turning threat intelligence into meaningful action become such a persistent challenge, despite years of investment in security tools?
As the report shows, the gap isn’t a lack of data — it’s a lack of usable, actionable intelligence. Three data points explain why turning threat intelligence into action remains so hard:
1. Threat intelligence isn’t effectively prioritising risk. More than half of the security teams (52%) agree that organization’s threat intelligence is not very effective at helping them prioritize which security risks require immediate attention. This is because while there is an abundance of threat intelligence, it’s not contextualized or prioritized against specific threat exposure and stays mostly at the tactical level. This is worse among Senior IT security decision-makers (59%) than practitioners (48%), and particularly acute in EMEA (57%) and APAC (58%) versus North America (43.5%).
2. Intelligence isn’t embedded where action happens. 55% of security professionals say threat intelligence is not a core capability within their SOC, and even where it’s used, less than half teams describe it as “operationally embedded” (regularly used but not fully integrated) — with just a small fraction achieving full integration into detection and response workflows.
3. Tooling fragmentation is drowning signal in noise. Security teams are struggling with correlating data across multiple tools and aligning technical risk scores with actual business impact.
The report argues that many organisations are suffering from an “exposure gap” rather than a visibility gap. How should security leaders rethink their cybersecurity strategies to close that gap, and what practical changes can they make without completely overhauling their existing security stack?
Visibility into threats is no longer the problem. We’ve solved that. The problem is turning that visibility into continuous resilience, and that’s where organizations are consistently falling short. Closing the “exposure gap” means shifting from collecting more intelligence to validating and prioritizing the intelligence organisations already have. There are three actions that security leaders can already take: first, establish formal Priority Intelligence Requirements (PIRs) so threat data is filtered against what actually matters to the business, something 95% of respondents agree they would benefit from. Second, treat threat intelligence as something that must be continuously validated against real exposure rather than acted on at face value. And third, rationalise and consolidate the tooling that already exists rather than adding more. Our survey findings suggest the fix is less about new technology and more about disciplined prioritization, validation, and integration of what’s already deployed, elevating threat intelligence from a technical feed into a strategic decision-making function, which 93% of respondents agree their organization could do more to achieve.
AI is increasingly being positioned as the answer to cybersecurity’s growing complexity. In your view, where is AI already making a measurable difference in threat exposure management, and where do you think expectations have run ahead of reality?
Right now, actual AI penetration is modest: only around 25% exposure management processes are AI-driven and it’s embedded in pockets of the workflow, more as assistive-AI but not running the show end-to-end. Areas where we are really seeing the benefits of AI are prioritisation, where AI is dramatically better than humans at processing thousands of vulnerabilities and surfacing the ones that are actually exploitable in your environment. That’s not a future promise, that’s happening now. Second, correlation – connecting threat intelligence signals across disparate sources to build a coherent picture of what’s coming at you. And third, speed – compressing the time between detection and response in ways that manual processes simply cannot match. Our research shows 84% of organisations are getting hit by risks they already knew about, AI directly attacks that problem by closing the gap between knowing and acting.
Areas where AI hype has mostly run ahead includes autonomous remediation – the idea that AI can not only identify a risk but fix it, end to end, without human involvement. We’re not there yet, and frankly, in high-stakes security environments, you don’t want to be there without serious guardrails. The second is context, AI is still surprisingly poor at understanding the business context behind a risk. Is this vulnerability critical because of what it sits next to in your environment? Does remediating it break something else? Those judgement calls still need a human.
That’s actually a core design principle behind XTM One, with human-in-the-loop by design. AI should make your analysts unstoppable, not replace them. The moment you remove human judgement from the equation entirely, you’ve created a different kind of risk.
One of the more striking findings is that security teams spend around 42% of their time investigating risks that ultimately prove to be low priority. What does this tell us about the way organisations currently approach vulnerability management, and how can they reduce alert fatigue without introducing new blind spots?
What this finding really exposes is that most organizations are still operating on a volume-first model – ingest everything, flag everything, investigate everything. The assumption baked into that model is that more coverage equals more security. But what it actually produces is alert fatigue, analyst burnout, and a prioritization problem that never gets solved.
The root cause is disconnection. Vulnerability scanners don’t talk to threat intelligence platforms. Threat intelligence doesn’t feed into attack simulation. And without that connected loop, analysts have no reliable way to distinguish between a vulnerability that is theoretically severe and one that is actually exploitable in their specific environment, right now. So they investigate both and everything else in between.
Our research reinforces this – 97% of security teams struggle to determine whether exposures are actually exploitable. That’s not a skills gap. That’s a structural gap. Teams are being asked to make high-stakes prioritisation decisions without the context they need to make them well.
The shift that needs to happen is from volume-first to context-first vulnerability management. That means connecting your threat intelligence to your exposure data, layering in exploitability analysis, and using AI to continuously run that prioritisation loop – so that when an analyst picks up a case, they already know it matters.
Your research highlights significant regional differences in CTEM maturity, with countries like Germany and the United States leading the way. What lessons can organisations in the UK and across Europe learn from these more mature approaches, and are there cultural or organisational barriers that technology alone cannot solve?
The regional differences in our research are fascinating. United States as expected leads the way while Germany has pleasantly shown greater maturity. The organizations leading on CTEM maturity share a common trait: they’ve moved from treating cybersecurity as a compliance function to treating it as a continuous operational discipline, something that runs in the background always, not something you revisit at audit time. For example, you will notice their less reliance on periodic pentesting and more on continuous validation and assessment. Technology alone cannot solve this. What we consistently see in less mature markets is a cultural gap: security teams that are still fighting for budget, still justifying their existence to the board, and still operating in reactive mode because that’s what the organisation rewards.The lesson for the UK and European organizations isn’t to buy more technology, it’s to change the relationship between security and the rest of the business, so that exposure management has executive sponsorship, clear ownership, and a seat at the strategic table.
Looking ahead over the next three to five years, do you see Continuous Threat Exposure Management becoming as fundamental to cybersecurity as endpoint protection or SIEM, and what emerging trends should CISOs be preparing for now?
Going by the current pace of change within the cybersecurity space, especially with the frontier AI models, no one can predict the future in five years. What frameworks like CTEM are validating is that we need a more proactive approach to cybersecurity and it’s only logical to continuously assess and improve your security posture. There is no other way going forward.
There are three emerging trends that CISOs should be preparing for now. First, agentic AI with human in the loop and as an orchestration layer that continuously runs the CTEM cycle, surfaces prioritized actions, and compresses response time from days to minutes. The organizations building that capability now will have a structural advantage within two years. Second, attack surface expansion: cloud, OT, AI systems themselves, the perimeter is dissolving faster than most security architectures are evolving, and CTEM needs to expand with it. Third, and perhaps most underestimated, is AI as an attack vector, as organizations embed AI into their operations, adversaries will target those AI systems directly, creating an entirely new category of exposure that traditional vulnerability management wasn’t built to handle.
The CISOs who will lead in this environment aren’t the ones waiting for the market to mature – they’re the ones building the foundations now, so that when agentic AI and unified exposure management become table stakes, they’re already operating at that level.
More interviews
- Reuben Koh, Director, Security Technology & Strategy, APJ at Akamai Technologies: “The most significant challenge leaders face in today’s digital landscape is the impact of AI on cyberattacks”
- Faryam Asif, Chief Technology Officer at Shufti: “In the AI era, knowing who you’re dealing with is becoming just as important as protecting your systems from attack.”
- Chris Newton-Smith, CEO of IO: “Regulations are rarely applied in exactly the same way across different organisations”
- Marco Eggerling, International CISO at UiPath: “The single highest return investment most organisations can make right now is achieving identity hygiene”
