The Security Strategist 11 August 2026 21 MIN

Defensible Prioritisation: A Story CISOs Can Stand Behind

“When you put the two against each other, prioritisation or data, it's very clear that it's a data problem."

Prioritisation is the way to tackle enterprise data challenges. It may seem like a simple solution, and it might be too. If you’re an enterprise overwhelmed by vulnerabilities in data, especially with the evolution of AI and automation, this conversation is for you. 

In the recent episode of The Security Strategist podcast, host Shubhangi Dua, Podcast Producer and B2B Tech Journalist at EM360Tech, sat down with James Walta, Vice President of Product Management at Brinqa. The agenda for this episode was to break down why enterprises are overwhelmed by vulnerability data. Additionally, Walta lays out a strategic plan of action to help enterprises prioritise vulnerabilities proactively rather than reactively. 

The discussion builds on the previous episode, where Brinqa CSO Brad Hibbert and host Richard Stiennon, Chief Research Analyst at IT-Harvest, talked about how AI is helping attackers with faster scanning, smarter exploit chaining, and machine-speed intrusions. 

Walta continues this conversation with EM360Tech’s Dua, focusing on prioritisation in exposure management strategies. He puts up a case noting AI will not rescue security teams from unorganisation unless the underlying data is ‘good’ and reliable.

Why Context is the Real Hold-Up

Walta noted that contextualisation is the real hold-up when it comes to prioritisation. What this means is that contextualisation, a practice that augments raw security data such as vulnerability scores, helps understand business risk. Without enough good data, it’s extremely difficult to comprehend the true reasons behind a fault.

“Prioritisation is only as good as the context behind it,” stated Walta. “The best prioritisation framework is gonna struggle without good context.”

He added that when it comes to automation practices in enterprises, this process is likely to fail without good data to drive the process or provide clarity. “We're not heading in any certain direction. It's adding more chaos to the conversation we're already battling with today."

The notion that AI-backed automation is the solution for security teams swamped by detection volume is not always true.

As per the VP of Product Management, AI is capable of speeding up fixes but only in situations when it relies on good risk management and data quality. Successful AI use cases are also backed by an understanding of asset ownership and business context. If this foundation is stripped, AI often hallucinates or fuels confusion

"If the internal data is incomplete or messy, AI doesn't magically fix that," Walta tells Dua. "In some cases, it can actually worsen things and amplify confusion by processing bad context faster."

Also Watch: How Should CISOs Prioritise Risk in the Age of AI-Powered Cyberattacks?

What is the Root Cause of Exposure Management Challenges?

Going back to the root of the issue in enterprise exposure management, Dua asked Walta where the gap between finding and fixing vulnerabilities really lies. Is it a data issue, prioritisation, or something else altogether? 

“When you put the two against each other, prioritisation or data, it's very clear that it's a data problem,” Walta tells Dua. “Prioritisation is only as good as the context behind it, at least the way that we need to be prioritising today. It's no longer just a CVSS score or just a definition of a vulnerability.”

Alluding to an example, he explained that the same vulnerability found on two different assets should never be treated the same. If it’s on a critical, externally facing system linked to a key business function, the risk and exposure are higher, pushing it to the top of the list. If found on a dev box or a non-critical test machine, the same CVE still needs attention, but it’s not urgent. Short-term fixes might work until a proper solution is available.

"None of those survives prioritisation without asset and business context," Walta said. "The best prioritisation framework will struggle without good context."

What Metric Should CISOs Focus on?

Are you enjoying the content so far?

The episode ends with a theme that echoes a previous point from Brinqa CSO Brad Hibbert: stop counting what you found and start measuring what you've closed.

Walta agrees but takes it further. Closure volume alone is still an incomplete measure. "It's not just about what you closed because it's not just volume," he said. "Measure if you're reducing meaningful impact. Are you fixing the right things?"

He suggests shifting the focus from activity metrics- how many vulnerabilities were found, how many were fixed— to outcome metrics. Did exposure on critical assets genuinely decrease? Are the enterprise's most important applications more secure than last quarter? 

Walta believes looking at it from a prioritisation perspective will show enterprises whether a security program is building resilience or just creating busywork.

Takeaways

  • Context is crucial for effective cybersecurity management.
  • The chaos in cybersecurity is amplified by AI-driven vulnerabilities.
  • Data quality is foundational for prioritisation and remediation.
  • Patching faster is not always the best approach; understanding risk is key.
  • Operational clarity can be achieved by unifying asset visibility.
  • Prioritisation must be based on business context and asset sensitivity.
  • AI can help but may also amplify confusion if data is poor.
  • CISOs should focus on outcome metrics rather than activity metrics.
  • Effective vulnerability management requires a clear understanding of ownership.
  • The conversation around cybersecurity must evolve to address real risk reduction.

Chapters

  • 00:00 Navigating Cybersecurity Chaos
  • 02:52 The Importance of Context in Cybersecurity
  • 06:07 Bridging the Gap: From Vulnerability Detection to Remediation
  • 09:09 Understanding Risk Over Speed
  • 11:46 Enhancing Data Quality for Better Decision Making
  • 14:57 Operational Clarity: Transforming Overload into Insight
  • 18:05 Measuring Success Beyond Vulnerability Counts

Visit brinqa.com for more information on how enterprises should prioritise vulnerabilities proactively.

Loading transcript…

Make security chaos work for you with AI-powered Exposure Management, built on data. The Brinqa platform delivers scalable, AI-driven exposure management that unifies every data source for a complete picture of risk. Separate false alarms from real risk by uniting Security and IT, accelerating remediation, and delivering a single, trusted source of truth for the business.

Sponsored insight

Liked what James had to say?

Get in touch with the team at Brinqa to continue the conversation.

Brinqa Featured partner

Ready to put Brinqa thinking to work in your stack?

Tell us about your goals. We will put you in touch with the right person on the Brinqa team.

Contact Brinqa