Security1 distinct publisher2 min readPublished
A sitting insurance CISO argues the binding constraint is patch cadence rather than detection, and that automation has to compress the test cycle without waiving it. What the business gave up to allow that is missing from the published answer.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Thirty years contains sixty six-month periods. For the next six months to produce more vulnerabilities than the previous thirty years did, discovery has to run above sixty times its long-run average [18]. Palmer offers no dataset behind the claim [2], so treat it as a planning assumption from a sitting CISO rather than a count. Planning assumptions are still budgets. If you accept anything near that multiple, you cannot hire your way out of the queue, which is why the answer she gives is correlation and test automation [5].
Her own answer carries the counterweight. Palmer notes that many breaches start from vulnerabilities known for years, not days or weeks [7], and that a zero-vulnerability environment will never exist [16]. Those two pressures are different work. Hours-to-weaponise pressure lands on fresh CVEs in reachable systems [3]. The years-old bug usually survives because nobody owns the asset or nobody will approve the outage. Prioritisation by real exposure [5] serves both cases only if the forgotten asset ranks alongside the new CVE, and that ranking is a function of inventory quality, which the published answer does not address [22].
Help Net Security asked two questions in one: what changed in patch and compensating-control practice, and how the business was brought to accept the new maintenance windows [14]. The first half is answered in detail [5][6]. The published response names no window, no patch SLA by severity, and no change-control concession [15]. That is the half other CISOs cannot copy. Compressing a test cycle is procurement and engineering. Persuading an insurance business to absorb more frequent, less predictable downtime on revenue systems is negotiation, and the terms of that deal are the transferable artefact.
The SOC figure has the same shape. Four of five AI-enabled cases close without human escalation [12], which leaves one in five, or 20 percent, going to an analyst [19]. The interview asked for before-and-after numbers [17]. What came back was that ratio plus hours saved each day on searches, enrichment and summarisation [13]. Without case volume, four-of-five describes how often the automation is trusted, not how much analyst capacity was returned.
One commitment in the answer is worth holding her to: AI compresses the testing window prior to patching, it does not bypass it [6]. Keep that gate and this is disciplined patch acceleration with virtual patching as the shock absorber [8][11]. Lose it under machine-speed pressure and the compensating controls become the only thing between a fast deploy and a self-inflicted outage.
Ranked by verification strength, evidence, and original report placement.
Becky Palmer is VP and CISO at National Life Group and answered five questions in an interview with Help Net Security about defending against AI-driven attacks.
Palmer said the company is looking at opportunities to automate patch management with AI: correlating new vulnerabilities against its environment, prioritising by exposure, and driving the test-and-deploy cycle to compress patch cycle time.
Palmer said the benefits of AI will allow the team to compress the testing window prior to patching, not bypass it and increase business risk.
Palmer listed virtual patching using the web application firewall, intrusion prevention system and endpoint protection to block the specific exploit traffic as a compensating control the company relies on.
Palmer listed tightening access, restricting who and what can reach the exposed system and enforcing least privilege and stronger authentication around it, as a compensating control.
Palmer listed heightened monitoring, putting targeted detection on the vulnerable asset to see exploitation attempts immediately, as a compensating control.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Thousands of credentials survived five years of pentests inside Jira ticket comments1 distinct publisher
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One interview, no underlying data
Everything traces to a single conversation Help Net Security published, and inside it to one person's account of her own programme. The striking number arrives without a count, a date range, or a source; the SOC ratio arrives without a denominator. What is firmly established is what a sitting carrier CISO believes and has started doing — not the state of exploit development or of AI in the SOC.
One carrier, self-reported
Two things are described as actually running at National Life Group: agentic AI triaging SOC investigations, and a virtual-patching stack holding ground until fixes ship. The headline-adjacent piece — AI correlating disclosures against the estate and driving test-and-deploy — is still something the team is 'looking at'. That is one mid-size insurer, self-disclosed, with no vendor, no scale, and no second organisation anywhere in the reporting.
Headline outruns the practice
The overstatement sits in the superlative, not the security work. Thirty years compressed into six months implies discovery running at sixty times its historical rate, and nothing in the interview tests that; Help Net Security then puts it in the headline. Palmer is her own counterweight — she insists automation compresses the test window rather than waiving it, notes that many breaches exploit flaws known for years, and refuses to promise zero vulnerabilities. Read the practice and the gap nearly closes; read the framing and it does not.
Buyer-side, lightly stage-lit
Nobody in this piece is selling anything. Palmer names no vendor, and her procurement checklist — proof of value on my own data, protected instance, logged autonomy with a kill switch, total cost at real usage — is buyer-side scepticism rather than a favour to a supplier. The pull that does exist is softer: an interview series rewards a quotable superlative, and a CISO on the record has every reason to present her programme as ahead of the threat rather than behind it, which is roughly where the unanswered questions cluster.
Sure of the quote, not the claim
We can be close to certain about what was said and quite unsure about the world it describes. The answers are first-person, verbatim and dated, so the record of Palmer's position and her carrier's practice is solid. Whether AI-written exploits have genuinely collapsed weeks into hours, and whether four-of-five closure survives outside one team's chosen use cases, is untested by anyone in this reporting.