Why Patch Management Is No Longer Frontline Defense with Brett Price - Ep 234
Brett Price is the Global CISO at Quint, a publicly owned company that builds hospitality and entertainment packages for major sporting events including Formula One, tennis, the NBA, the NHL, and MotoGP. He oversees cybersecurity, governance, and compliance across the parent organization and five international subsidiaries spanning Australia, the Netherlands, southern Spain, and Monaco. Brett brings a hands on view of what it takes to secure a global operation under GDPR, CPRA, and dozens of overlapping data privacy regimes while staying ahead of AI powered threats on every front at once.
Here’s a glimpse of what you’ll learn:
- Why Brett believes patch management alone is no longer enough to stop machine speed attacks
- How a Global CISO balances GDPR, CPRA, and data privacy law across five international subsidiaries
- What the Hugging Face sandbox incident taught the security industry about controlling agentic AI
- Why identity, not endpoint protection, is where Brett would put a small business's first security dollar
- How AI powered SOC tools are closing the gap for organizations without large security teams
- Why Brett thinks the good guys ultimately win the AI arms race, and what has to happen first
- The lesson Brett draws from the MGM breach about detecting abnormal admin behavior
- Why Brett expects AI to eventually remove the need for end user security awareness training entirely
In this episode…
Brett opens by walking through what a day actually looks like running cybersecurity for a company with five international subsidiaries in Australia, the Netherlands, southern Spain, and Monaco, describing the balancing act between board reporting, vendor management, vulnerability management, and a growing stack of global data privacy law. GDPR, CPRA, and country specific regulations all compete for attention, and Brett makes clear that governance is not a side function of the job, it is the job. He frames the current moment in cybersecurity as genuinely exciting rather than purely alarming, arguing that whether AI feels exciting or scary comes down entirely to perspective.
From there the conversation turns to AI as both the threat and the defense. Brett draws a direct line to the cloud adoption era, arguing that organizations rushed into the cloud without bringing security along, and that the same mistake is playing out again with generative and agentic AI. He points to the Hugging Face sandbox incident as a wake up call, noting that hundreds of CISOs came together through the Cloud Security Alliance to document what happens when agentic AI escapes its intended boundaries, and he raises China's reported use of autonomous agents against the Taiwanese government as evidence the threat is not theoretical. Brett is candid that AI vendors incorporating agents into their own products raises a new category of due diligence questions most organizations have not caught up to, and he floats a future where a lightweight AI agent on a phone could intervene in real time to stop elderly relatives from falling for scam calls.
The conversation closes on where Brett believes the smartest money goes for organizations of any size. He argues identity has become the new perimeter, favors managed detection and response over alerting alone, and pushes back on the idea that modern security is out of reach for small and mid sized businesses, comparing the market to needing an F150 rather than a Ferrari for most jobs. He delivers a hot take that patch management can no longer be treated as frontline defense, referencing rising zero day discovery rates and a 2026 DBIR report that put vulnerability exploits ahead of identity as the top attack vector, and argues defenses need to catch abnormal behavior in real time rather than relying on hardened software alone.
Resources mentioned in this episode
CyberLynx Website
Brett Price on LinkedIn
Quint Website
Darktrace Website
Abnormal AI Website
Sponsor for this episode...
This episode is brought to you by CyberLynx.
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.
Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.
Check out previous episodes:
Generals in the Command Post: AI Security and Human Identity with Erik Miller - Ep 233
Why UNICEF USA Is One of the Hardest Security Jobs with Andrew Nuxoll - Ep 232
Vibe Coding, Micro Businesses, and Fighting Fire with Fire with Alexander Tushinsky - Ep 231
Transcript:
Brett Price
Global CISO
Quint
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Brett Price, Global CISO at Quint. Brett, welcome to the show.
Brett Price: Thank you. Glad to be here, Matthew.
Matthew Connor: Glad to have you. Before we get too far in, a quick word from our sponsors.
Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com. That's cyberlynx.com.
Matthew Connor: And now, back to our show. Brett, for those who aren't familiar, can you tell us about Quint and your role there as Global CISO?
Brett Price: Sure. Quint is a global company. We're owned by a public company, which makes us public. We provide packages for entertainment, hospitality, and business. We partner with big companies you might be aware of: Formula One, top-notch tennis, the NBA, the NHL, MotoGP, companies like that. We run globally, and we create hospitality packages for customers around the world for any F1 race, MotoGP, tennis, all those things I mentioned. We provide packages for interested customers.
Matthew Connor: I love it. And that's a lot to deal with. As a Global CISO, what's a day in the life like?
Brett Price: In today's day and age, the threats are increasing daily. I think most organizations have seen a massive uptick in the amount and sophistication of attacks, thanks to AI and the massive amount of money that has flowed into the cybercrime industry over the last few years.
Matthew Connor: So what's that like for you? How do you deal with that? Do you sleep well at night? How does that work?
Brett Price: It's a lot of balance. There's governance you have to deal with, board reporting, vulnerability management, vendor management, identity and access management. We have to comply with GDPR because we're global, and now there are probably twenty states that have data privacy laws, like CPRA in California, plus a lot of countries with their own data privacy laws. So a lot of it is data privacy: making sure we're adhering to data subject rights, providing good service, and allowing people to practice their rights while making sure we're in compliance. Then there's vulnerability management, vendor support, and subsidiaries. We own five subsidiaries, so I oversee cybersecurity for those five subsidiaries in Australia, the Netherlands, southern Spain, Monaco, and a couple of others, making sure we're providing governance and enabling them to run their business securely. So it's a lot, but it's good. If you love what you do, you work harder at it.
Matthew Connor: That's right. Then you never work a day. It's interesting, because that is a lot. You're balancing a ton. Just keeping up with the compliance portion alone is a lot.
Brett Price: It's a lot to deal with. Everybody's pretty familiar with the tasks and the benefits when it comes to compliance.
Matthew Connor: That's great, we'll leave that for a moment. I get really excited when we start talking about cybersecurity, and I think in the modern day it's the most exciting time, both exciting and scary. I think it's just a matter of your perspective. If you're optimistic about it, it's exciting. If you're pessimistic about it, it's scary. I get excited about it because I think it's a really exciting time. We see some really cool stuff happening on the good-guy side, for the defenders. You see cool products like Darktrace using AI to help businesses stay secure and really leverage AI in the right way to defend against machine-speed attacks. At the same time, you see cool stuff from SentinelOne and CrowdStrike integrating AI into their AI SOC/SIEM products, allowing a smaller organization without a ton of SOC analysts to have much faster, greater insight and take action faster. So for me, that's really exciting because I think that's how we get the leg up on the bad guys. You've got to fight fire with fire, you've got to bring a gun to this gunfight, you just can't rely on old tools. But not everybody shares that view, and I'm curious where you stand on this.
Brett Price: I think absolutely, from a cybersecurity perspective, from a CISO perspective, we have to move at the speed of business and enable the business. If we're not capturing those opportunities, the business is going to be left behind. And I think as a human race, as individuals, if we don't get on board with artificial intelligence and understand it and learn it, we're going to get left behind, because it's moving way faster than cloud adoption. We're kind of falling into the same trap we did with cloud adoption, primarily because of the competitive advantage you get by moving to the cloud. We wanted to jump in and start building, saving money on infrastructure, building ephemeral networks, all these things, but at the time we didn't bring security along with us, and that kind of bit us. The AI revolution, or the evolution of artificial intelligence, is kind of the same thing happening. Either we want to jump in headfirst without bringing security and governance along with it, or we push it away and say it's too scary, and I think both of those are issues. As CISOs, we've got to stay ahead of that and identify those opportunities for the business. It's not only an IT function, it's a cybersecurity function too, because there's a lot of variables and a lot of new risk involved with artificial intelligence. From an IT perspective, there are a lot of advantages: we're helping the business become more productive and more efficient. From my perspective, it makes us smarter too, because we can learn from these generative AI solutions, and we'll talk about agentic AI in a second. From the generative AI perspective, there's a lot to learn, as long as we understand the basics, the fundamentals, and the security precautions around it, and we have to validate, like we always have, and that's kind of how we learn: we learn these new insights very rapidly, then go back and verify the data. I think that's a really good thing. The kind of scary thing is we went from worrying about data privacy and generative AI to agentic AI that makes decisions for you, and that happened so fast it makes everybody's head spin. So the challenge is staying on top of it, and I think we're doing a better job at that, and a better job at educating the public on mistakes that are being made. If we look at the Hugging Face incident, the Cloud Security Alliance did a really good write-up following that incident. Something like four or seven hundred CISOs got together to write a postmortem for the community, talking about not only what happened with OpenAI and Hugging Face, but the potential implications of not controlling your agentic AI as you start to develop those types of things. So it's very exciting, as long as you're keeping pace with developments and with the business, and enabling the business to really start to adopt and use these things in practice.
Matthew Connor: I think what's really interesting is how, as we develop these situations and these problems to be solved by using AI, it creates new problems. As we leverage agentic AI, well, now how do we control that? And what's really interesting and fun, and I'm not trying to be a Darktrace fanboy here, but they've got this "Secure AI" now, a product they've recently released to help you secure your AI agents and keep an eye on and monitor them. Using AI to secure AI makes perfect sense, and in true Darktrace fashion it's like, of course, obviously. I get excited because products like that give us a view of the future. For the good guys, it's great on the productivity side, and there's the insider threat, not the traitor inside, but the insider threat of accidental disclosure. I think that's the big threat with agentic AI: it getting out and divulging, or giving access to too much information, or information at all, and simply not having full control over that. When we see stuff like that, and I know we're early days in AI, it's very early days, I think it gives us a glimpse of the future. Going back to the cloud comparison, it took so long for security to catch up, for us to get security-minded, for the products to come along with it. Now everything's happening so rapidly, in tandem, on the defensive side. As cool new things are being developed to move the business forward and increase productivity, we're very quickly seeing industry leaders come out with industry-leading AI solutions to help on the security side. That's what's really exciting, because if we didn't have that, well, the bad guys are using AI too, and the whole thing gets out of hand and we're all just running and gunning with nothing on defense. That's why I really like stuff like that, and I'm looking forward to more products. I think they're spearheading a whole new breed of products that we're going to see more of. But when you see the Hugging Face incident, it's concerning, right? When an AI model can find its way out of the sandbox, it's like you put a bad guy in jail and they find their way out of the jail cell. That's alarming, not that the AI is the bad guy, but when anything escapes its container, it's concerning. So I think it's a really exciting time for products, and I'm curious what your take is, since these are very early days for this kind of thing.
Brett Price: Yeah, there's a few things to unpack there. One is, when we talk about OpenAI, and we talk about Anthropic, and we talk about Meta, and how those agents escaped their sandboxes and wreaked havoc, those tests were conducted to determine how far the agent would go. It had a specific task, it wasn't out to harm anybody or cause damage, it was out to perform a task, so those guardrails were let down, they didn't realize just how far outside it would get. But yes, it broke out of its sandbox and did some pretty cool things, and we learned a lot from it as an industry. I do appreciate the security vendors, especially the ones helping us gain control of some of these agents that we want to build, agents that are going to improve productivity and security, because we have to work at machine speed. Humans can't work at machine speed, but machines can. So those are definitely relevant. The thing that makes me a little nervous is it's not only the security vendors incorporating AI, everybody wants to incorporate AI into their products now, because it's a competitive advantage, in the private sector and the public sector. But are we doing our due diligence to make sure the AI solutions our vendors are providing are doing their due diligence? If they're incorporating agents into their products, are they making sure their agents have identities like real people, and are they controlled? Do they have guardrails, are they working within sandboxes and limitations on what they can access and how? Are we logging that? Are we using agents to monitor those agents? That's a little unnerving, but overall we're getting there, and we have to keep pace. I saw part of an article earlier where China hacked the Taiwanese government, I think it might have been today, and they used four autonomous agents to breach the government, exfiltrate data, and compromise credentials. So there are so many reasons we have to stay aware. Another thing I'll mention is that from a product perspective, that shouldn't allow us to relax and not understand what our agents are doing and how we need to develop them securely. Just because we have a product that says it's going to help secure your agents, you still need to really understand what's underneath the hood.
Matthew Connor: No, for sure. And I think the really fun part is looking to the future. Let's take a look at our elderly population. Right now they're under such attack by bad actors, and it's billions of dollars a year that they're losing, which is really sad because they have no way of regaining it. I look forward to the day where a lightweight AI agent, let's call it Siri, can be on your phone, and when grandma and grandpa get a call and someone says they're Microsoft tech support, or Apple, or Amazon, Siri can jump in and say, "Hey grandma, this is a scam, I'm going to hang up on them, you're fine, don't worry about it," and for it to be able to stay local, on the phone, and private, and still provide that assistance. I think that's the direction we're going, where we're going to have those safeguards. Taking it back to the business side, look at things like the MGM breach. MGM had the money, the know-how, the training, and yet a persistent, motivated threat actor was able to wait for just the right moment and exploit a new admin coming online. There's no way, going back to your point that humans can't act at machine speed, and this wasn't even machine speed, this was just good social engineering, but they moved very rapidly to execute it, it was impressive. With AI, though, you're monitoring your identity and network and can easily see: this new admin is doing way more than anybody, this isn't normal, I'm stopping this and calling an adult, because this isn't normal day-one admin behavior. AI is great at seeing what's abnormal and taking action. Things like that are really hard using traditional tools, traditional methods, and traditional training, those are just gaps in being human. But that's where it gets really fun to use AI, and ultimately I think by leveraging AI, currently and in the future, the good guys win. I think it will ultimately get so challenging for the bad guys. Now, granted, they've made a lot of money and can put up a good fight, especially as you look at things like Kimi K3 coming out, and now they can run it on fifty or sixty thousand dollars of hardware, on their desktop. For a home user, that's a lot, but for a multimillion-dollar organized crime syndicate, that's nothing, they're going to have lots of those. So then it becomes really challenging when they don't have the guardrails that, say, Claude does. So what do you do? I think the threats are real, the bad guys are well-funded and have access to formidable tools. But I think with the help of companies like Anthropic and Gemini, Google doing the right thing for the right reasons, I think ultimately we win. That's my hot take. I'm curious what your take is on the future of the battle, the war, let's say. I'm very much an optimist.
Brett Price: Oh boy, yeah, I guess there's a lot of things there. One is, yes, it saddens me that these threat actors are taking advantage of some of the individuals they do take advantage of. But I also think part of what we're running into right now, from an adversarial perspective, is it's not just nation-state, it's not just organized crime, it's now much easier for the traditional script kiddie who was trying to figure out how to run Metasploit and launch exploits. They're building ransomware kits now that are AI generated, they can write their own code, write their own exploits, and run their own agents. So I don't know if you can say there's a win-lose there. I think it's always going to be the cat-and-mouse game, because as we advance, so do they, especially with some of the highly funded nation-states, and we're all still human, humans are susceptible no matter what you do. So there's always going to be a challenge there. But I think education, and proper governance in place, and as the role of the CISO evolves, I think we're going to be a lot better off, because that education and governance will be there as the role gets elevated. So a lot of those things will be put in place. But like I said, they also have those agents, they can build those solutions like Anthropic and OpenAI, or use the open models and develop those. Another thing about what you said, protecting the elderly with something on their phone, I think that's a great call. As far as MGM and the hotels out in Vegas, I actually work closely with one of the CISOs, a really smart guy, he had it together and they got breached. It wasn't MGM, but it was one of the other ones. The AI is only as good as the data it's being trained on, so I think it'll be a while before it's effective enough to work through all the nuances and different circumstances that could arise in those situations. Again, like somebody getting a phone call and the AI agent understanding, hey, we need to cut this person off, that type of thing, there could be a lot of false positives early on, but it is definitely a good concept. I don't know what it looks like yet, because we've played this game before, it's just advancing at such an exponential, rapid rate now that it's hard to keep up. If we look back to when the "I Love You" virus came out, or when McAfee created the first commercial antivirus, we thought, okay, now we've got those guys, we have signature-based detection. Then it became anomaly-based detection, and we thought if we had a good perimeter we'd be protected, and then they started hitting us in our soft, creamy center. You have to think about the fact that there's also funding that has to take place. Not every organization can afford really expensive agentic AI solutions to help protect them, and the majority of organizations are mid-sized businesses. There was a time when we'd say mid-sized businesses didn't have to worry about security, that we're too small, they're not going to mess with us. Now they're just attacking everybody, and the more advanced these AI tools get, the more kids are looking at this stuff and saying, this is interesting, this is kind of easy, I can just take this IP address, throw this agent at it and see what happens. Oh wait, I got credentials, I can sell those somewhere. So it's a constant battle, and I think it'll stay that way for a while.
Matthew Connor: I couldn't agree more. I think the challenge is that smaller is easier, it's easier to hit and beat up on the little guy, and that's exactly what we're seeing from these threat actors. Smaller organizations don't have the same budgets. How many organizations spend fifteen billion dollars a year on cybersecurity like Chase does? Very few, right? And I get it, they're a huge target, but it just goes to show they're a much harder target and spend a lot more money on it than a small or mid-sized company. The bad guys have recognized that, why would you try to go after a Chase, you're going to bang your head on that wall and not make it through, it's so much harder to do, it's layer after layer of really good hardened defenses, they're using AI in every imaginable way, good luck. Sure, maybe bragging rights, but that's for the dozen elite hackers who might have a shot, versus the kid who's renting an exploit kit off the dark web for five dollars a successful exploit. Then they can go after every small and medium-sized business and let it run until it hooks a fish, and they get paid for that fish. That's a great model if you're into cybercrime. So I think there are a lot of expensive products out there, and the challenge is that not every car needs to be a Ferrari, it's not the right vehicle for every job. There are lots of very cool Ferraris, but there are also a lot of cool Ford F-150 pickup trucks, a lot of products out there. I think the challenge is a lot of companies have got it in their head that modern security is almost cost-prohibitive for small and medium businesses, and I don't think that's the case a lot of the time. There are some that are cost-prohibitive for sure, but I think the majority have really good models that make it very accessible for a business, short of a bootstrapped startup with no budget for anything. I think there are great security products for everybody along the way, and for me that's a really good sign of a healthy industry. This economy runs on small business. We've got a bunch of great huge businesses, but the backbone of the U.S. economy is still small business, and it's really important that we keep that secure. I'm really thankful that we have so many great security product manufacturers who have made it accessible to small businesses. Now, does it trickle down to them? The information, small businesses don't have the time to go through all of that, so it's harder to get in there. But I think as a whole it is happening more, because unlike five or six years ago, before COVID, small business was often under the illusion that they were too small to be a target, it doesn't matter. Now they've read enough in the news, they've seen enough, everybody knows somebody who's been hit, and it's very frequent. So I'm thankful that's at the front of everybody's mind now, that security is a real issue, are we safe, and not everybody's got a CISO in-house to help them. Smaller organizations struggle with that. So my long way of getting to a question for you: as a Global CISO, what's your advice to those smaller organizations who don't have the budget for even a CISO, who are smaller, up and coming? What can they do that's cost-effective? What should they be looking at, product-wise or policy-wise, that can help them defend themselves from the bad guys without breaking the budget?
Brett Price: Yeah, so when you're talking about small and medium enterprise, I think a lot of it is about awareness. We used to hear "too small," but the smaller companies are the ones that go out of business when they get hit too hard. I hate saying "go back to the basics," especially after reading the article about the Hugging Face incident and the postmortem, because the basics are no longer enough when you're fighting against agentic AI. But if we go back to cybersecurity in general, it is going back to the basics: awareness, governance, understanding that you need those governance policies in place, you need people to understand what the risk is, you need the training. Multi-factor authentication everywhere is not that expensive to implement anymore. If you're in the cloud, make sure you're configuring properly, that you're not leaving S3 buckets open, that your credentials are secure, that you're not over-privileging users, that you're following least-privilege and need-to-know principles. Those are all really important. A lot of times, even with advanced technologies, if attackers knock on your door and can't get in, they're going to move on to somebody else who's easier to break into. If they find your stolen credentials on the dark web, and we talk about not using your credentials everywhere, don't use your username and password at work and then use it for your bank and for Netflix, because that's how they get your credentials. But even if they do get them, if you have multi-factor authentication, chances are they're going to try to get in and can't, because they don't have that authentication code. There are ways around that too, SIM swapping with SMS multi-factor authentication, it's not completely secure. But for the mid-sized organization, if it's costing the adversary money and time to conduct these exercises, that hits them in the pocketbook, makes it harder and more expensive for them to get in, and chances are they'll move on.
Matthew Connor: Yeah, I think the area for small and medium business, identity is such a huge area. It's easy enough to secure the endpoints, and with email you can work on awareness training. A lot of people become very skittish about clicking on anything in their email, okay, fine. But I think the real challenge is identity, it's hard to monitor that as human beings. If I had to put any money into one thing, it would be identity, so you can quickly and easily identify when somebody's credentials have been compromised, or somebody's account has been accessed incorrectly or without authorization, and be able to identify that and take action very quickly. Because now, unlike a few years ago where compromised credentials might sit for weeks or months, now it might be minutes. So I think that's probably the best bang for the small-business buck, an identity product that will quickly protect them. If I had to say one thing to focus on, they've probably got some sort of antivirus, and getting a SentinelOne or a CrowdStrike is very affordable for any size business, so that shouldn't be a real issue. I think identity. I'm curious, as a Global CISO, even though you're not looking at it for a smaller business, what do you think of that idea? Where would you say is the best bang for your buck if you had to pick one product, or not necessarily a product, one area?
Brett Price: Managed detection and response.
Matthew Connor: Okay, I like it.
Brett Price: You can have a company monitor your firewalls, monitor your identity provider, those types of things, and alert you in near real time when there's some sort of nefarious activity on your network. They say identity is the new perimeter, so of course identity is very important. Like you said, having the tools to identify when someone accesses something they shouldn't, that's another reason we talk about identity, why we use least privilege. Do you need access to that? No, you don't, you're not going to get access to it. Or if you do need access, do you need full-write access to it? Getting really granular with identity within the enterprise really goes a long way, I think.
Matthew Connor: No, I couldn't agree more, and I think you hit the nail on the head. My only caveat is I'd want to make sure MDR can take very quick, decisive action, versus just alerting only, because I think the time to response has to be so much smaller now than ever before. I'd like to see AI working in there. I'd much rather have the occasional false positive, where you get locked out of your account for five minutes, that's a nuisance, it takes five minutes to resolve, than have the alternative, where we didn't know until the damage was done.
Brett Price: Yeah, a lot of the MDR products out there do have options to link to something like Microsoft Entra and disable accounts, so like you said, being reactive is important, how quickly can you disable an account if there's suspicious activity. With EDR being fairly cheap now, firewalls fairly cheap, malware detection, ransomware detection, all those things, I think for the smaller organization you can definitely get by without a lot of spend.
Matthew Connor: I love it. But it all comes down to education, awareness, and having somebody you can consult with: here's my small business, this is what we do, this is how we do it, can you identify where our weak spots might be and provide some recommendations on where to go.
Brett Price: Well said.
Matthew Connor: And I get excited about the future because I do think AI, and this is a bit of a hot take, will ultimately alleviate the need for awareness training for the end user. I think the accountants and the frontline workers should get to do their job, and security should ultimately be managed and handled by AI and by professionals purely. I look forward to the day where we're no longer trying to train accountants on the different attempts hitting their email, teaching them how to avoid things, because all of that is handled by AI automatically. And if an attack gets past the AI, you know what it's going to get past, the accountant, for sure. So it doesn't really matter, but I think that's where the future goes. I've got one more hot take, current vulnerability management, as long as I'm getting all my hot takes out. Vulnerability management used to be so important, just keep things patched and you were fine, but I think that day is no longer here, with the advent of these more advanced models. You look at Mythos coming out, you look at Kimi K3. I'll bet you anything it won't be long before we start hearing about vulnerabilities found by threat actors using Kimi K3 to find new vulnerabilities, zero-day exploits, and then exploiting them at machine speed. And I think that's the real threat, it's not that Anthropic is going to release something dangerous, it's that the bad guys will use an open-source model to find zero-day exploits. The hope is that the good guys using Mythos will patch them before the lesser models find those exploits. But because of this, here's my hot take, I don't think it's about patch management anymore. While we have to patch, we can't rely on manufacturers simply having a product that's hardened enough. We have to assume the bad guys are going to get through, and our defenses must be able to see when there's anomalous activity and take action, and say that's not right, Adobe shouldn't be encrypting stuff, I'm stopping this right now, or this is weird network activity, I'm stopping it right now. I think that's where we need to be focused, because it doesn't matter, you could spend thousands of hours a week on patch management for almost any size organization, and it's not going to do a lick of good if the bad guys are using zero-day exploits at machine speed. That's my hot take. What do you think?
Brett Price: I think, well, if you read the DBIR report this year for 2026, vulnerability exploits took the top spot over identity. Like you mentioned with Mythos, the ability to find zero days, and having those AI solutions be able to patch those zero days, again it's kind of a cat-and-mouse game. It's like, I have a Mythos solution going out across my entire environment, identifying known vulnerabilities and zero-day vulnerabilities and patching them at machine speed, and then you have organizations that aren't there yet, and they're using those same tools against you to identify zero days and exploit them. So that's the thing, but I think with us having that technology, and keeping up with the advancements, yes, it's surfacing a lot more. You saw Microsoft, a couple of Patch Tuesdays ago, release its largest deployment yet of six hundred plus patches, or vulnerabilities, and known exploitable vulnerability lists going crazy. But it's keeping pace with all that, and the fact is we continue to develop software, we continue to update software, so we're going to continue to have zero days, we're going to continue to have vulnerabilities. Will all of those companies writing the software and updates run a Mythos-type tool against those to make sure there are no zero-day vulnerabilities, and if there are, was it trained well enough to flag them? It's really interesting, like you said, very exciting, and we have to keep pace with it.
Matthew Connor: Couldn't agree more, Brett, super fun conversation, can't thank you enough for coming on. I think we had some really cool topics, I had a blast, I think it was really informative for everybody listening. But before we go, can you tell everybody where they can find out more about you and about Quint?
Brett Price: Sure. You can find me on LinkedIn. Quint.co is our website, you can find all of our partners and events on our partners and events page. I wish I could memorize my LinkedIn URL, but look up Brett Price, it's pretty easy to find on LinkedIn. I do some mentoring, and I usually don't say no to people when they ask me a question, because one of the biggest issues I've found in this industry is CISOs are pretty tight-lipped, they don't want to air their dirty laundry. But I'm pretty open and willing to talk to people whenever.
Matthew Connor: That's fantastic. We'll be sure to link your LinkedIn profile in the description. Brett, can't thank you enough, and until next time.
Brett Price: All right, thank you, Matthew. Take care.
Matthew Connor: You too.







