The Prioritization Problem: Why More Findings Don’t Mean Less Risk

Security teams have more visibility than ever, but knowing what actually matters is harder than ever. Watch Bishop Fox experts as they break down the prioritization problem and how to focus limited resources where they have the greatest impact.

Security teams have never had more visibility into their environments. Vulnerability scanners, attack surface management platforms, cloud security tools, application security testing, AI-powered analysis, and threat intelligence feeds are generating an unprecedented volume of findings. 

Yet despite all that visibility, one question continues to surface: What actually matters most? 

Watch Bishop Fox's Cosmos team in a fireside chat on Continuous Threat Exposure Management (CTEM) and how they help organizations cut through the noise, validate what attackers can actually exploit, and focus security efforts where they'll have the greatest impact. 

Drawing from their experience helping organizations continuously understand and reduce their external attack surface, our experts will share observations from the front lines, discuss how AI is increasing both the volume and complexity of security findings, and explore why effective prioritization requires more than simply collecting more data. 

In this conversation, we'll discuss:

  • Why more visibility doesn't always translate into better security outcomes
  • How the Cosmos team approaches CTEM to identify and validate real-world risk
  • Common exposure patterns and prioritization challenges they see across organizations
  • How offensive security testing helps separate exploitable risk from background noise
  • How AI is reshaping both attack surfaces and the volume of security findings

Whether you're responsible for attack surface management, vulnerability management, cloud security, or enterprise risk, you'll leave with practical insights into how Bishop Fox's Cosmos team approaches CTEM to help organizations prioritize what matters most—and reduce risk with confidence.


Richard Brown headshot

About the speaker, Richard Brown

Senior Managing Operator

Richard Brown is a Senior Managing Operator at Bishop Fox, where he leads a team focused on emerging threats, customer notification, exploit development, automation, and operational innovation. He partners across the organization to enhance attack surface intelligence capabilities and deliver actionable security insights to customers.

With more than 15 years of experience in cybersecurity, consulting, and law enforcement, Richard has specialized in threat intelligence, offensive security, and investigative analysis. His background as a detective in the Intelligence Division of the St. Louis Metropolitan Police Department helps shape his attacker-focused approach to identifying and understanding threats.


Brad Alaska BF Headshot

About the speaker, Brad Alaska

Senior Managing Operator

Brad Alaska is a Senior Managing Operator on the Bishop Fox Cosmos team focusing on attack surface management. He came to Bishop Fox through the Department of Defense Skillbridge program. He served as a non-commissioned officer in the United States Air Force for 11+ years as an Aerospace Propulsion Maintenance Technician and a Cyber Warfare Operator. During his tenure in the Air Force, Brad earned a B.S. degree in Computer Science from Park University and is currently a candidate for a M.S. degree in Cyber Security at Western Governors University. Brad holds several cybersecurity certifications including GIAC Python Coder (GPYC), GIAC Web Application Penetration Tester (GWAPT), and GIAC Research and Advanced Penetration Tester (GXPN).


Matthew Lapinski

About the speaker, Matthew Lapinski

Sr. Managing Operator

Matthew Lapinski is a Senior Managing Operator at Bishop Fox, where he manages a global team of Adversarial Operators delivering the Cosmos Attack Surface Management service. Splitting his time between leadership and hands-on exploitation, he investigates and exploits vulnerabilities for Fortune 500 clients and helps them translate findings into business risk strategies.