May 26, 2026 · 58 min · 10 segments
Hosts David Simon and William Ridgway welcome Skadden…
Nicola Kerr-ShawPanelist
Bill RidgwayHostSo just to jump into it, first, we're gonna be talking about something that's really gotten the most sophisticated cyber and legal teams increasingly focused on vulnerability management and vulnerability s- discovery tools and what they really mean for cybersecurity, for governance, for legal risk, for boards, and everything else.
The question here really is, you know, what are these tools gonna mean? Because they really can materially compress the timelines around vulnerability discovery, exploitation, remediation, disclosure, and it's gonna mean that organizations have to think about handling multiple incidents at a time, about some of the relatively new reporting obligations that apply, and how organizations are gonna have to operate through a period of disruption over the coming year and what it means to be legally prepared there.

Exactly right, and we've certainly had a lot of conversations with various companies dealing with this.

Historically, as we know, cybersecurity programs, they were built around a set of assumptions about how quickly vulnerabilities were discovered, prioritized, and exploited, and organizations really built their entire systems around that reality.

You talk about patch cycles, change management processes, downtime windows, escalation procedures, and whatnot.

It's that attackers increasingly may be able to operate at machine speed using the tools that they may have, while many enterprise remediation and governance processes, they still operate at human speed.
Exactly, and so that's why we're so delighted we're joined here today, as I mentioned a, a moment ago, by our partner, Nicola Kerr-Shaw, from London, who advises clients across Europe on cyber incidents, privacy, AI, and regulatory response, and before joining, was thinking about these issues as the leader of the global program on these topics for the largest French bank and one of the largest banks in the world.
Thinking about this from the perspective of a major financial, where a lot of these tools probably were being thought about much before all of us were.

I think what strikes me about this issue is that it cuts across technical operations, governance, and legal obligations simultaneously, that cust- companies are increasingly realizing this isn't just a security team issue anymore.

It has implications for disclosure timing, board oversight, incident response, and regulatory expectations.
Many different of the frontier labs have something like this, and we thought we'd just talk a bit about why is this such a big deal.
What we think really caught people's attention wasn't simply the sort of AI-assisted research.
It was that this vulnerability discovery tool and this ability to discover and exploit these vulnerabilities at scale would dramatically change what cybersecurity means, both from a defensive perspective and also from sort of an offensive perspective.

David, as you know, the, the trade-off oftentimes was this balance against the security risk against operational downtime, and that's certainly not irrational.
So just to jump into it, first, we're gonna be talking about something that's really gotten the most sophisticated cyber and legal teams increasingly focused on vulnerability management and vulnerability s- discovery tools and what they really mean for cybersecurity, for governance, for legal risk, for boards, and everything else.
The question here really is, you know, what are these tools gonna mean? Because they really can materially compress the timelines around vulnerability discovery, exploitation, remediation, disclosure, and it's gonna mean that organizations have to think about handling multiple incidents at a time, about some of the relatively new reporting obligations that apply, and how organizations are gonna have to operate through a period of disruption over the coming year and what it means to be legally prepared there.

Exactly right, and we've certainly had a lot of conversations with various companies dealing with this.

Historically, as we know, cybersecurity programs, they were built around a set of assumptions about how quickly vulnerabilities were discovered, prioritized, and exploited, and organizations really built their entire systems around that reality.

You talk about patch cycles, change management processes, downtime windows, escalation procedures, and whatnot.

It's that attackers increasingly may be able to operate at machine speed using the tools that they may have, while many enterprise remediation and governance processes, they still operate at human speed.
Exactly, and so that's why we're so delighted we're joined here today, as I mentioned a, a moment ago, by our partner, Nicola Kerr-Shaw, from London, who advises clients across Europe on cyber incidents, privacy, AI, and regulatory response, and before joining, was thinking about these issues as the leader of the global program on these topics for the largest French bank and one of the largest banks in the world.
Thinking about this from the perspective of a major financial, where a lot of these tools probably were being thought about much before all of us were.

I think what strikes me about this issue is that it cuts across technical operations, governance, and legal obligations simultaneously, that cust- companies are increasingly realizing this isn't just a security team issue anymore.

It has implications for disclosure timing, board oversight, incident response, and regulatory expectations.
Many different of the frontier labs have something like this, and we thought we'd just talk a bit about why is this such a big deal.
What we think really caught people's attention wasn't simply the sort of AI-assisted research.
It was that this vulnerability discovery tool and this ability to discover and exploit these vulnerabilities at scale would dramatically change what cybersecurity means, both from a defensive perspective and also from sort of an offensive perspective.

David, as you know, the, the trade-off oftentimes was this balance against the security risk against operational downtime, and that's certainly not irrational.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.